Heterogeneous platform digital authentication method
By generating ECC algorithm key pairs and encryption platform unique IDs in the service center, combined with hardware-level identity authentication and hashing algorithms, the problems of complexity and security reduction in key management in the prior art are solved, and a high-security heterogeneous platform digital authentication method is realized.
Patent Information
- Application Number
- CN202510301641.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-03-14
AI Technical Summary
In the prior art, key management is complex and easy to be stolen, and security gradually decreases under high computing power attacks. Software storage keys are easily extracted or tampered with maliciously, resulting in a reduction in the security of the authentication system and affecting the reliability and integrity of the platform and data.
The heterogeneous platform digital authentication method is adopted, and the service center generates ECC algorithm key pairs and publishes digital certificates. The platform obtains a unique ID in the factory and stores it after encryption. It performs identity authentication before working, authenticates through the root authentication center, and uses a hash algorithm to ensure data integrity.
It realizes a security authentication mechanism based on high-strength encryption algorithms and hardware-level identity authentication, improves system security, enhances platform credibility, guarantees data integrity, and prevents malicious attacks.
Smart Images

Figure CN120110684A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of platform digital authentication, and in particular to a heterogeneous platform digital authentication method. Background Art
[0002] In the field of modern information security, digital authentication technology plays a vital role in software and hardware authentication, data protection, and intellectual property protection. With the development of the Internet of Things, cloud computing, and edge computing, more and more devices are connected to the network, making identity authentication and data security a key issue.
[0003] Currently, most existing authentication technologies rely on symmetric encryption or asymmetric encryption based on the traditional public-private key system, but there are still many shortcomings when dealing with complex hardware environments and distributed architectures. For example, symmetric encryption schemes require sharing keys between devices and servers, which makes key management complex and easy to steal, while traditional asymmetric encryption methods gradually lose security when facing high-computing power attacks. In addition, many existing authentication systems store keys on the software side, which poses a risk of being maliciously extracted or tampered with, affecting the overall security of the system.
[0004] In summary, the existing technology has technical problems such as complex key management and easy theft, gradually reduced security under high computing power attacks, and easy malicious extraction or tampering of keys stored on the software side, which reduces the security of the authentication system and further affects the reliability and integrity of the platform and data. Summary of the invention
[0005] The purpose of this application is to provide a digital authentication method for heterogeneous platforms to solve the technical problems in the prior art that key management is complex and easy to be stolen, security gradually decreases under high computing power attacks, and keys stored on the software side are easily maliciously extracted or tampered with, resulting in reduced security of the authentication system, further affecting the reliability and integrity of the platform and data.
[0006] In view of the above problems, the present application provides a digital authentication method for heterogeneous platforms, including: using a service center to generate an ECC algorithm key pair and issuing a digital certificate, wherein the digital certificate and private key are held by the manufacturer; each platform obtains a unique ID in the factory state, and sends the unique ID to the service center, the service center uses the public key in the digital certificate to encrypt the unique ID, destroys its own public key, and stores the ciphertext ID and the plaintext ID in the database to form a platform identity binding record; before the working state software runs, the service center reads the plaintext ID of the platform to be authenticated, and calls the corresponding ciphertext ID from the database, and packages the read plaintext ID and the called ciphertext ID into a verification request package; the verification request package is sent to the root authentication center for authentication, and the plaintext ID, ciphertext ID, authentication result, hash algorithm and hash value are encapsulated as a response package and fed back to the service center, the hash value is a hash value generated based on the plaintext ID, ciphertext ID, and authentication result, and the hash value is used to verify the data integrity of the response package; after receiving the response package, the service center performs a comparison and verification of the platform identity binding record in the database to generate an authentication result.
[0007] The technical solution provided in this application has at least the following technical effects or advantages: by realizing the technical goal of a security authentication mechanism based on a high-strength encryption algorithm and hardware-level identity authentication, the technical effects of improving system security, enhancing platform credibility, ensuring data integrity and preventing malicious attacks are achieved.
[0008] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented according to the contents of the specification, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are specifically cited below. It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easy to understand through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] In order to more clearly illustrate the technical solutions in the present application or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only exemplary, and for ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0010] Figure 1 A flowchart of a digital authentication method for a heterogeneous platform is provided for this application;
[0011] Figure 2A flow chart of sending the verification request packet to a root certification center for authentication in a heterogeneous platform digital authentication method of the present application. DETAILED DESCRIPTION
[0012] This application provides a digital authentication method for heterogeneous platforms, which solves the technical problems in the prior art that the key management is complex and easy to be stolen, the security gradually decreases under high computing power attacks, and the software-side storage keys are easy to be maliciously extracted or tampered with, resulting in reduced security of the authentication system, further affecting the reliability and integrity of the platform and data. The technical goal of achieving a security authentication mechanism based on high-intensity encryption algorithms and hardware-level identity authentication is achieved, achieving the technical effects of improving system security, enhancing platform credibility, ensuring data integrity, and preventing malicious attacks.
[0013] Below, the technical solutions in the present application will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments of the present application. It should be understood that the present application is not limited to the example embodiments described herein. Based on the embodiments of the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present application. It should also be noted that, for the convenience of description, only the parts related to the present application are shown in the accompanying drawings, rather than all of them.
[0014] Please see attached Figure 1 , this application provides a heterogeneous platform digital authentication method, which specifically includes the following steps:
[0015] S1: Generate an ECC algorithm key pair using a service center and issue a digital certificate, wherein the digital certificate and private key are held by the manufacturer.
[0016] Specifically, the service center is a central system responsible for managing and processing authentication requests, and is used to generate and maintain key information required for encryption. The ECC algorithm is elliptic curve cryptography, which is a public key encryption algorithm based on the mathematical structure of elliptic curves. A key pair refers to a pair of interrelated encryption keys, in which the public key is used to encrypt data or authenticate identity, and the private key is used to decrypt data or generate digital signatures. To generate an ECC algorithm key pair using the service center, first, a secure elliptic curve is selected through the service center, and relevant elliptic curve parameters are set, such as the equation that defines the curve and the position of the base point. The elliptic curve parameters determine the security and calculation rules of the ECC algorithm. Next, a private key is randomly generated through the service center. The private key is an integer within a predefined range. Then, the public key is calculated using the private key. The calculation method is to multiply the base point of the elliptic curve by the value of the private key to obtain a new point, and the coordinates of the point are the public key. Finally, the generated public and private keys are stored by the service center, and the public key is used for encryption and verification in subsequent processes. The private key is strictly confidential and is only allowed to be used by the device or authorized agency.
[0017] After the key pair is generated, the service center will issue a digital certificate. A digital certificate is an electronic document used to prove the ownership of a public key. It is issued by a certification authority (CA) and contains the holder's information, public key, the issuing authority's signature, and the validity period of the certificate, ensuring that both parties can exchange encrypted information securely while preventing man-in-the-middle attacks.
[0018] Digital certificates and private keys are held by the manufacturer, which means that the device manufacturer is responsible for maintaining the security of the key. The manufacturer refers to the manufacturer or certification body of the device, and needs to ensure that the private key will not be leaked, because if the private key is stolen, the attacker can forge the device identity or decrypt the data that should be protected, so as to ensure that the device's identity authentication process is trustworthy and secure.
[0019] S2: Each platform obtains a unique ID when it leaves the factory and sends the unique ID to the service center. The service center encrypts the unique ID using the public key in the digital certificate, destroys its own public key, and stores the ciphertext ID and plaintext ID in the database to form a platform identity binding record.
[0020] Specifically, each platform refers to different hardware devices or computing platforms, including servers, smart terminals, IoT devices, embedded systems, etc. Each platform needs to be authenticated in the security system to ensure its legitimacy and credibility. Since different platforms may have different computing capabilities and communication protocols, compatibility and scalability need to be considered when designing the authentication mechanism to ensure that different types of platforms can be securely connected to the system.
[0021] The factory state refers to the state of each platform just after production and not yet put into use. In the factory state, the hardware and software configurations of each platform are in the default state, and no personalized settings or user binding have been performed. The factory state platform needs to go through the initialization process to ensure that it can securely connect to the network and accept remote management.
[0022] A unique ID is a unique identifier for a device, which can be a numeric value or a string, used to distinguish different device platforms. The unique ID can be generated based on hardware characteristics, such as the physical address of the device, the manufacturing serial number, or a random identifier generated by an encryption algorithm. The role of a unique ID is to ensure that each platform can be uniquely identified, thereby preventing identity conflicts or forgeries.
[0023] Each platform obtains a unique ID when it leaves the factory. Each platform transmits its unique ID to the service center through a network connection to prevent it from being intercepted or tampered with during transmission. It is protected by using secure communication protocols such as TLS (Transport Layer Security Protocol) or other encryption methods. After receiving the unique ID, the service center will further process the information to ensure its authenticity and security.
[0024] The service center uses the public key in the digital certificate to encrypt the unique ID to improve security and ensure that even if an attacker steals the stored ciphertext data, he cannot directly obtain the unique ID of the device.
[0025] After encryption is completed, the service center will destroy its own public key to enhance security and prevent malicious abuse of the public key. The role of the public key is to encrypt data, and after data encryption is completed, the public key is no longer needed, so destruction can reduce potential attack risks. Even if an attacker invades the service center, he cannot use the public key to further encrypt data or forge authentication requests.
[0026] The service center then stores the ciphertext ID and the plaintext ID in the database, which means that both the encrypted unique ID and the original unique ID are retained for comparison in the subsequent authentication process. The ciphertext ID is used to improve the security of data storage, while the plaintext ID is used for fast indexing and matching. The choice of database usually needs to consider security, storage efficiency and access speed. For example, a distributed key-value database can provide efficient storage and retrieval capabilities, while supporting multi-node synchronization to improve reliability.
[0027] Ultimately, the process forms a platform identity binding record, that is, the device's unique ID, encrypted unique ID, and related identity information are stored in the service center's database and used as the basis for subsequent authentication and management. This identity binding mechanism ensures the authenticity of the device, prevents identity forgery, and provides a trusted data source for subsequent authentication processes.
[0028] S3: Before the working software runs, the service center reads the plaintext ID of the platform to be authenticated, and calls the corresponding ciphertext ID from the database, and packages the read plaintext ID and the called ciphertext ID into a verification request package.
[0029] Specifically, before the working software of each platform is officially run, identity authentication is required to ensure that its identity is consistent with the database record to ensure the legitimacy and security of the working software. Working software refers to the software required by the platform during normal operation, which may include system startup, network connection, secure access and other functions.
[0030] The platform to be authenticated refers to a platform that is about to enter the working state and needs identity authentication, such as a smart gateway, a connected car, or an industrial control device. During the authentication process, the service center will read the plain text ID of the platform to be authenticated to confirm whether the identity of the platform to be authenticated has been registered and retrieve the corresponding information from the database.
[0031] The database is a system for storing device identity information, which contains the plaintext ID and ciphertext ID of all registered devices. The service center searches for the corresponding ciphertext ID in the database based on the plaintext ID read and extracts it. The ciphertext ID is an encrypted version of the device identity, generated by a public key encryption algorithm and cannot be read directly to protect the platform identity information from being tampered with or forged.
[0032] The plaintext ID read and the ciphertext ID called are both the identity information of the platform. Then the plaintext ID read and the ciphertext ID called are packaged into a verification request package, that is, the service center combines these two data together for identity verification. Packaging refers to encapsulating multiple data items in a specific format for transmission and processing in the network. The verification request package is a structured data packet containing the plaintext ID and the ciphertext ID. After the service center generates the request package, it will send it to the authentication center, which will further verify the identity of the device.
[0033] S4: Send the verification request packet to the root authentication center for authentication, and encapsulate the plaintext ID, ciphertext ID, authentication result, hash algorithm and hash value into a response packet and feed it back to the service center. The hash value is a hash value generated based on the plaintext ID, ciphertext ID and authentication result, and the hash value is used to verify the data integrity of the response packet.
[0034] Specifically, sending the verification request package to the root certification center for authentication means that in the authentication process, the service center needs to submit a verification request package containing the plaintext ID and the ciphertext ID to the root certification center for identity verification. The verification request package contains the plaintext ID and the ciphertext ID of the device. The root certification center is responsible for verifying the matching of these IDs to determine whether the device is legal. Among them, the root certification center will use the stored private key to decrypt the ciphertext ID to restore the original unique ID, and then compare it with the plaintext ID to determine whether the platform is authentic and valid. If the comparison is successful, it means that the identity of the platform is credible, otherwise the device may be at risk of forgery or tampering, and the root certification center will reject its authentication request.
[0035] After completing the authentication, the root authentication center needs to generate a response package and encapsulate the plaintext ID, ciphertext ID, authentication result, hash algorithm and hash value. The response package is a data structure that contains all the key data of the authentication process for subsequent verification by the service center. The authentication result is a sign of success or failure of the authentication, indicating whether the platform has passed the authentication. The hash algorithm is used to calculate the hash value, and the hash value is used to ensure the integrity of the data.
[0036] The hash value is a fixed-length string calculated by the hash algorithm after combining the plaintext ID, ciphertext ID and authentication result. It is used to ensure that the data has not been tampered with during transmission. The hash algorithm is a mathematical function that maps the input data to a fixed-length hash value. It is irreversible and unique. Therefore, even if the input data changes slightly, the hash value will be completely different.
[0037] The hash value is used to verify the data integrity of the response packet, which means that after receiving the response packet from the root certification center, the service center will use the same hash algorithm to recalculate the hash value and compare it with the hash value in the response packet. If the two are the same, it means that the data in the response packet has not been modified during transmission. Otherwise, it means that the data may have been tampered with and the service center needs to reject the response packet.
[0038] S5: After receiving the response package, the service center performs a comparison and verification of the platform identity binding record in the database to generate an authentication result.
[0039] Specifically, when the response packet is returned from the root authentication center, it contains key information such as plaintext ID, ciphertext ID, authentication results, etc. The service center needs to compare this data with the identity binding records pre-stored in the database. The identity binding records stored in the database are uploaded by the manufacturer when the platform leaves the factory and contain the unique identity information of the platform. Therefore, the comparison process can ensure whether the currently authenticated platform is consistent with the identity information at the time of leaving the factory. After the comparison and verification is completed, the service center will generate the final authentication result based on the comparison results and determine the subsequent processing flow. If the comparison is successful, it means that the identity of the platform is legal and the relevant functions of the platform can continue to be used. If the comparison fails, it means that the identity information of the platform does not match the record in the database. It may be that an illegal platform is trying to impersonate a legal platform, or the data has been tampered with during transmission. The service center will reject the access request of the platform and may trigger a security alarm.
[0040] Furthermore, the present application also includes: after parsing the response packet, using the parsed hash algorithm to calculate the hash value based on the plaintext ID, the ciphertext ID, and the authentication result to generate a verification hash value; judging whether the verification hash value is the same as the hash value, if the verification hash value is different from the hash value, generating a tampering exception and reporting the tampering exception.
[0041] Specifically, parsing the response package means that after the service center receives the response package returned by the root certification center, it needs to disassemble the data structure and extract each key field. The response package contains multiple data items, including plaintext ID, ciphertext ID, authentication result, hash algorithm and hash value. The parsing process involves data format identification, field extraction and data storage. After the parsing is completed, the service center will use the hash algorithm obtained by the parsing to calculate the hash value of the plaintext ID, ciphertext ID and authentication result to generate a verification hash value. The hash algorithm can convert input data of any length into an output value of fixed length, so that even if the input data changes slightly, the output hash value will change significantly.
[0042] After calculating the verification hash value, the service center needs to compare it with the hash value in the response packet to determine whether they are consistent. If the verification hash value is the same as the hash value in the response packet, it means that the data has not been modified during transmission and the authentication result is valid; if the two are different, it means that the data may have been tampered with or attacked during transmission, and the authentication result cannot be trusted.
[0043] If the verification hash value is inconsistent with the hash value in the response packet, a tampering exception is generated and reported. Tampering exception is a security event, indicating that the authentication data has been tampered with or forged, and the security mechanism needs to be triggered for processing. The reporting method can be to send an alarm message to the administrator or record a log for subsequent analysis.
[0044] Furthermore, the present application also includes: when the verification hash value is the same as the hash value, a data tamper-free result is generated; and the plaintext ID, ciphertext ID, and authentication result are called to perform a secondary comparison of the platform identity binding record to complete the comparison verification.
[0045] Specifically, when the verification hash value is the same as the hash value, it means that the data has not been changed during transmission, so the result that the data has not been tampered with can be generated. The verification hash value is calculated by the service center through the hash algorithm based on the parsed plaintext ID, ciphertext ID and authentication result, while the hash value is calculated and attached by the root certification center when generating the response package. If the two are the same, it means that the entire data stream remains consistent and has not been tampered with.
[0046] After confirming that the data has not been tampered with, call the plaintext ID, ciphertext ID and authentication result to perform a secondary comparison of the platform identity binding record to complete the final comparison verification. The purpose of the secondary comparison is to ensure that the identity of the platform is consistent with the identity binding record in the database to prevent possible forgery or replay attacks. This step requires accessing the database, extracting the plaintext ID and ciphertext ID stored when the platform leaves the factory, and matching them with the currently parsed data. If the match is successful, it means that the identity of the platform is credible and the subsequent authentication process can continue; if the match fails, it means that the platform identity is abnormal, and it may be an illegal platform trying to impersonate a legitimate platform.
[0047] Further, if Figure 2 As shown, S4 of the present application includes: S41: the root authentication center uses a pre-stored private key to decrypt the ciphertext ID to obtain the original unique ID; S42: the root authentication center uses a built-in DNA extraction module to extract its own hardware unique ID, and compares it with the original unique ID. If the comparison results are consistent, an authentication result is generated with the verification result being true.
[0048] Specifically, the root authentication center is responsible for verifying the authenticity of the platform and ensuring that the platform's identity information has not been tampered with. The root authentication center is composed of a highly secure hardware platform (such as FPGA, TPM or HSM) that can perform key operations such as encryption, decryption and identity verification. After the platform submits an authentication request, the root authentication center needs to use a securely stored key to decrypt it to verify the uniqueness of the platform.
[0049] The pre-stored private key refers to the private key that is pre-stored in the root certification authority. The private key is used in pairs with the public key, is only stored in the root certification authority, and cannot be accessed or tampered with by the outside.
[0050] The root authentication center uses the pre-stored private key to decrypt the ciphertext ID, and uses the private key to reverse the ciphertext data to restore the original plaintext information, thereby obtaining the original unique ID. Since the ciphertext ID is encrypted by the public key, only the corresponding private key can complete the decryption process, ensuring the security of the platform identity information. The decryption process involves the elliptic curve cryptography (ECC). During the decryption process, the root authentication center performs mathematical operations to convert the ciphertext back to the original data to verify the validity of the platform identity. The original unique ID refers to the unencrypted unique identifier assigned to the platform at the factory, which is used to distinguish different platforms.
[0051] The root authentication center is implemented based on FPGA, trusted platform module (TPM) or dedicated hardware security module (HSM), and has multiple security function modules built in to support identity verification, encryption and decryption, and integrity verification. Since the main responsibility of the root authentication center is to ensure the uniqueness of the platform identity, it is able to read and verify the hardware identity information of the platform to prevent counterfeit or illegal platforms from accessing the system. The DNA extraction module is a dedicated module inside the root authentication center that is used to extract the unique hardware identification information of the platform. DNA extraction refers to a hardware feature extraction method based on a physically unclonable function (PUF). PUF uses tiny physical differences produced during the semiconductor manufacturing process to give each hardware unique characteristics. The DNA extraction module can read hardware features and convert them into a unique hardware ID for identity authentication.
[0052] The root certification center uses the built-in DNA extraction module to extract its own hardware unique ID. Among them, the hardware unique ID is a naturally generated and unchangeable identification code for each platform during the manufacturing process. It can be extracted in multiple ways, such as reading the fuse information stored in the chip, the identity code calculated using PUF technology, or a random sequence generated based on the characteristics of the hardware circuit. The hardware unique ID is used to distinguish different platforms and cannot be tampered with by software.
[0053] The hardware unique ID is compared with the original unique ID stored in the database to determine whether they are consistent, thereby confirming the authenticity of the platform identity. The comparison process is completed through hash operations or direct numerical comparisons. If the comparison results are consistent, it means that the platform identity is legal, and the root certification center will generate an authentication result with a true verification result and return it to the service center, indicating that the platform has passed the identity authentication. The authentication result is the final output of the platform authentication process and determines whether the platform can operate normally.
[0054] Furthermore, the present application also includes: stopping the operation if the comparison results are inconsistent.
[0055] Specifically, the hardware unique ID is compared with the original unique ID stored in the database. If the comparison results are inconsistent, it means that the platform identity information may have been tampered with, or the platform is a counterfeit platform. At this time, the root certification center will generate a false authentication result and return it to the service center. The service center will terminate the authentication process and prevent the platform from continuing to run to prevent illegal platforms from accessing the system.
[0056] Furthermore, the present application also includes: the private key pre-stored in the root certification center is generated through a physically unclonable function, and the private key is only solidified in the encrypted storage area of the root certification center, and external reading and writing are prohibited.
[0057] Specifically, the root authentication center is the core component of the identity authentication system, responsible for storing and managing key keys used for platform authentication. The pre-stored private key refers to the private key generated and stored when the root authentication center is initialized, which is used to decrypt the received data and verify the signature. The private key exists in pairs with the public key and must be kept confidential to ensure the security of identity authentication. The pre-storage of private keys means that the pre-stored private keys are generated before the platform is put into use and will not be modified during normal operation. Physical Unclonable Function (PUF) is a security technology based on the physical characteristics of hardware to ensure the uniqueness and non-replicability of private keys. PUF uses tiny physical differences generated during the semiconductor manufacturing process to make each chip have unique electrical characteristics that cannot be imitated or copied by software. Based on PUF technology, the root authentication center can randomly generate private keys at the hardware level without storing them in vulnerable storage platforms.
[0058] The private key is only stored in the encrypted storage area of the root authentication center, which means that after the private key is generated, it will be stored in a dedicated security area inside the platform, and will not be stored in ordinary memory or external storage media. The encrypted storage area is the internal storage unit of the hardware security module (HSM), trusted platform module (TPM) or FPGA, which has anti-tampering, anti-copying and self-destruction mechanisms to ensure that the private key will not be illegally read or modified.
[0059] Prohibiting external reading and writing means that once the private key is stored in the encrypted storage area, it cannot be accessed, read or modified by external systems. Even if the platform's software or operating system fails, the private key cannot be extracted to prevent hackers or malware from stealing the key.
[0060] Furthermore, the present application also includes: the root authentication center is FPGA, and the root authentication center has built-in ECC algorithm module, DNA module, and verification module, the ECC algorithm module is used to perform encryption, decryption and signing operations, the DNA module is used to extract the unique ID of the FPGA through hardware primitives, and the verification module is used to compare the consistency of the decrypted hardware unique ID and the original unique ID.
[0061] Specifically, the root authentication center is responsible for the final authentication of the platform identity. The root authentication center uses FPGA as the hardware platform. FPGA is a programmable logic device that can be flexibly configured according to different needs. Compared with fixed logic chips, it has reconfigurability, high performance and low power consumption. During the identity authentication process, FPGA is responsible for performing key computing tasks, including encryption, decryption, identity verification, etc. Since FPGA can process multiple computing tasks in parallel, it can improve authentication efficiency when facing large-scale platform identity authentication.
[0062] The root authentication center has built-in ECC algorithm module, DNA module and verification module, each of which has its own specific functions. The ECC algorithm module is used to perform encryption, decryption and signing operations. ECC (Elliptic Curve Cryptography) is a modern encryption algorithm. Compared with the RSA algorithm, it requires a shorter key length and less calculation while providing the same security, so it is suitable for resource-constrained platform environments. Through the ECC algorithm module, the root authentication center can efficiently encrypt and decrypt platform identity information and ensure the authenticity of the data through digital signatures.
[0063] The DNA module is used to extract the unique ID of the FPGA through hardware primitives. The unique ID of the FPGA is similar to each person's fingerprint. Each FPGA has unique hardware features when it leaves the factory. These features can be extracted through the DNA module to ensure the uniqueness of the platform identity. Hardware primitives are a low-level hardware feature that generates different bitstream information through subtle differences in circuit technology, thereby forming a unique platform identity.
[0064] The function of the verification module is to compare the consistency of the decrypted hardware unique ID and the original unique ID. During the authentication process, the root authentication center will decrypt the original unique ID from the ciphertext ID, and extract the hardware unique ID of the current FPGA through the DNA module, and then the verification module will compare the two IDs. If the two IDs are exactly the same, it means that the identity of the FPGA has not changed and it can pass the authentication normally; if they are inconsistent, it means that the platform identity may have been tampered with or forged, and a security alarm needs to be triggered.
[0065] Furthermore, the present application also includes: the hash value in the response packet is generated by the hash algorithm, and after the plaintext ID, the ciphertext ID, and the authentication result are concatenated according to preset rules, the hash value is generated based on the hash algorithm.
[0066] Specifically, the response packet refers to the data packet returned by the root authentication center to the service center after completing the identity authentication, which contains key information for authentication. The hash value is an important field in the response packet, which is generated by the hash algorithm and can ensure data integrity. The hash value is a fixed-length data summary generated by mathematically transforming the input data. Any slight change in the input data will cause a change in the hash value. Therefore, in the authentication process, the role of the hash value is to prevent the data from being tampered with during transmission or storage.
[0067] The generation of hash values depends on the hash algorithm. Different hash algorithms generate different hash values with different lengths and characteristics. In the identity authentication process, it is very important to choose a suitable hash algorithm because the anti-collision and computational efficiency of the hash algorithm will affect the security and performance of the authentication system.
[0068] Before generating the hash value, the plaintext ID, ciphertext ID and authentication result are concatenated according to the preset rules. The plaintext ID is the unique identification information of the platform, which is stored and transmitted in plain text; the ciphertext ID is the unique identifier after encryption, which is used to prevent identity information leakage; the authentication result is the result of the root authentication center's authentication of the platform, usually a sign indicating the success or failure of the authentication. In order to ensure the consistency of the hash calculation, it is necessary to concatenate these data according to the preset rules. The rules can be fixed-order string concatenation, binary encoding format or other structured methods.
[0069] Furthermore, the present application also includes: the ciphertext ID and plaintext ID are stored in a database in the form of key-value pairs.
[0070] Specifically, the ciphertext ID refers to a unique identifier processed by an encryption algorithm, that is, the unique ID of the platform is encrypted before storage to generate an irreversible ciphertext format. The role of the ciphertext ID is to protect the identity information of the platform. Even if the database is attacked or leaked, the true identity of the platform will not be directly exposed. The encryption algorithm can use asymmetric encryption, symmetric encryption or hash algorithm, and different algorithms have different security and computational overhead. Compared with plaintext storage, ciphertext storage can effectively reduce the security risks brought by data leakage.
[0071] Plain text ID refers to the original unique identifier of the platform, that is, the unique ID that has not been encrypted. Plain text ID is used for fast indexing and search, and it is more efficient to query plain text data directly than to query encrypted data. Although plain text ID is stored in the database, its access rights are usually strictly restricted, and only authorized systems or modules can read it to prevent data from being illegally obtained or tampered with. The role of plain text ID is to provide benchmark information for identity binding, which is convenient for comparison and verification during the authentication process.
[0072] Storing in the form of key-value pairs means that the database uses a key-value data structure to store information, that is, each ciphertext ID is used as a key (Key), and the corresponding plaintext ID is used as a value (Value), forming a one-to-one correspondence. The advantage of the key-value pair storage structure lies in efficient query and indexing capabilities, which is especially suitable for large-scale data storage scenarios. Compared with traditional relational databases, key-value databases can provide faster reading speeds and adapt to dynamic expansion needs. When storing, the ciphertext ID is used as the only index key to ensure that the data in the database will not be repeated, while the plaintext ID is used as associated data to provide the original identity information of the platform.
[0073] A database is a system used to store, manage, and query data. It can be a relational database (such as MySQL, PostgreSQL) or a non-relational database (such as Redis, MongoDB). In the scenario of identity management on various platforms, the database needs to have high concurrent processing capabilities, strong consistency guarantees, and high availability to support identity storage and verification requests from a large number of platforms. The design of the database will consider data redundancy, distributed storage, and access control to ensure data security and scalability. Table 1 shows the most recent platform encryption record.
[0074] Table 1: The most recent platform encryption record
[0075]
[0076]
[0077] Furthermore, the present application also includes: the database is a distributed key-value database, and the database supports multi-node synchronous verification.
[0078] Specifically, a database is a system used to store, manage, and retrieve data. The database is used to store the identity information of the platform, including ciphertext IDs and plaintext IDs. The choice of database affects the access speed, reliability, and scalability of data. Therefore, when it comes to large-scale platform management, it is necessary to select a suitable database type. A distributed database is a data storage method characterized by the fact that data is not stored on a single server, but distributed across multiple physical or logical nodes. Compared with a centralized database, a distributed database has stronger scalability and can cope with large-scale data storage needs while improving data disaster recovery capabilities.
[0079] A key-value database is a database that stores data in the form of key-value pairs. It uniquely identifies data through keys and stores specific content through values. Ciphertext IDs are used as keys and plaintext IDs are used as values, which are stored in the database. Unlike relational databases, key-value databases have fast query speeds and are suitable for large-scale, high-concurrency scenarios. In particular, in identity authentication systems, they can quickly find the identity information of the platform and improve authentication efficiency.
[0080] Distributed key-value databases combine the characteristics of distributed databases and key-value databases, providing large-scale storage capabilities while ensuring efficient data query. In large-scale platform authentication systems, a single node database may not be able to withstand high concurrent access, so a distributed architecture is needed to store data on multiple nodes to improve stability. Even if a node fails, it will not affect the normal operation of the entire database.
[0081] Multi-node synchronization verification means that the data in the database is kept consistent across multiple nodes, that is, when the data of one node changes, the data of other nodes will also be updated synchronously to ensure data consistency and reliability. In the identity authentication scenario, if the database of a node records the latest authentication status of the platform, but other nodes are not updated synchronously, it may cause authentication errors. Therefore, multi-node synchronization verification can prevent security risks caused by inconsistent data.
[0082] To sum up, the digital authentication method for heterogeneous platforms provided in this application has the following technical effects: realizing the technical goal of a security authentication mechanism based on high-intensity encryption algorithm and hardware-level identity authentication, and achieving the technical effects of improving system security, enhancing platform credibility, ensuring data integrity and preventing malicious attacks.
[0083] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
[0084] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application belong to the scope of the present application and its equivalent technology, the present application is also intended to include these modifications and variations.
Claims
1. A digital authentication method for heterogeneous platforms, characterized in that: The method comprises: Generate an ECC algorithm key pair using the service center and issue a digital certificate, wherein the digital certificate and private key are held by the manufacturer; Each platform obtains a unique ID when it leaves the factory, and sends the unique ID to the service center. The service center encrypts the unique ID using the public key in the digital certificate, destroys its own public key, and stores the ciphertext ID and plaintext ID in the database to form a platform identity binding record; Before the working software runs, the service center reads the plaintext ID of the platform to be authenticated, calls the corresponding ciphertext ID from the database, and packages the read plaintext ID and the called ciphertext ID into a verification request package; Send the verification request packet to the root authentication center for authentication, and encapsulate the plaintext ID, ciphertext ID, authentication result, hash algorithm and hash value into a response packet and feed it back to the service center. The hash value is a hash value generated based on the plaintext ID, ciphertext ID and authentication result, and the hash value is used to verify the data integrity of the response packet; After receiving the response packet, the service center performs a comparison and verification of the platform identity binding record in the database to generate an authentication result.
2. A digital authentication method for heterogeneous platforms as claimed in claim 1, characterized in that: After receiving the response packet, the service center performs the comparison and verification of the platform identity binding record in the database, including: After parsing the response packet, the parsed hash algorithm is used to calculate the hash value based on the plaintext ID, the ciphertext ID, and the authentication result to generate a verification hash value; It is determined whether the verification hash value is the same as the hash value. If the verification hash value is different from the hash value, a tampering exception is generated and a tampering exception is reported.
3. A heterogeneous platform digital authentication method as claimed in claim 2, characterized in that: The comparison and verification of the platform identity binding record in the execution database includes: When the verification hash value is the same as the hash value, a data tamper-free result is generated; The plaintext ID, ciphertext ID, and authentication result are called to perform a secondary comparison of the platform identity binding record to complete the comparison verification.
4. A heterogeneous platform digital authentication method as claimed in claim 1, characterized in that: The step of sending the verification request packet to a root certification center for authentication includes: The root certification center uses the pre-stored private key to decrypt the ciphertext ID to obtain the original unique ID; The root authentication center uses the built-in DNA extraction module to extract its own hardware unique ID and compares it with the original unique ID. If the comparison results are consistent, an authentication result is generated with the verification result being true.
5. A heterogeneous platform digital authentication method as claimed in claim 4, characterized in that: The root authentication center uses a built-in DNA extraction module to extract its own hardware unique ID and compares it with the original unique ID, including: stopping operation if the comparison results are inconsistent.
6. A digital authentication method for heterogeneous platforms as claimed in claim 4, characterized in that: The private key pre-stored in the root certification center is generated through a physically unclonable function, and the private key is only solidified in the encrypted storage area of the root certification center, and external reading and writing are prohibited.
7. A heterogeneous platform digital authentication method as claimed in claim 1, characterized in that: The root authentication center is an FPGA, and the root authentication center has built-in ECC algorithm module, DNA module, and verification module. The ECC algorithm module is used to perform encryption, decryption and signing operations, the DNA module is used to extract the unique ID of the FPGA through hardware primitives, and the verification module is used to compare the consistency of the decrypted hardware unique ID and the original unique ID.
8. A digital authentication method for heterogeneous platforms as claimed in claim 1, characterized in that: The hash value in the response packet is generated by the hash algorithm. After the plaintext ID, the ciphertext ID, and the authentication result are concatenated according to a preset rule, the hash value is generated based on the hash algorithm.
9. A digital authentication method for heterogeneous platforms as claimed in claim 1, characterized in that: The ciphertext ID and plaintext ID are stored in the database in the form of key-value pairs.
10. A heterogeneous platform digital authentication method as claimed in claim 1, characterized in that: The database is a distributed key-value database, and the database supports multi-node synchronization verification.
Citation Information
Patent Citations
Blockchain copyright protection system and method based on double chains
CN111538963A
Novel equipment license construction and use method
CN113536397A
Security encryption method for information creation rule base in hard disk data storage
CN117708899A
Running method of trusted execution environment, computer architecture system and encrypted hard disk
CN117910057A
Encryption circuit, encryption method and server
CN119598528A