Wireless communication module verification method and device, electronic equipment and storage medium
By implementing the verification method in the wireless communication module, determining the processor manufacturer information and controlling it, the problems of poor module security and risk of mutual brushing substitution are solved, and effective identification and control of module components are achieved.
Patent Information
- Application Number
- CN202510308326.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-10
AI Technical Summary
The security of wireless communication modules in smart terminals is poor, and there is a risk of mutual brushing or substitution, because terminal manufacturers may use application processors and baseband processors from different module manufacturers, resulting in module manufacturers being unable to identify and control the components used by customers.
By implementing the verification method in the wireless communication module, the application processor and the baseband processor initiate dialing request and response results, the target processor is determined, and synchronized with the verification server, the device information is sent to verify the target device information, and then the processor manufacturer information is determined and the management is controlled.
It effectively improves the security of wireless communication modules, reduces the risk of module components being refreshed or replaced, and ensures that module manufacturers identify and control the components used by customers.
Smart Images

Figure CN120128925A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a method and apparatus for verifying a wireless communication module, an electronic device, and a storage medium. Background Art
[0002] In intelligent terminals such as smart phones, a system-on-chip (SoC) often integrates an application processor (AP) and a baseband processor (BP). For wireless communication module manufacturers, software versions and technical solutions mainly include these two parts. Terminal manufacturers may separately select APs and BPs from different module manufacturers in the same product. In such different scenarios, module manufacturers cannot identify the versions of APs and BPs used by customers, resulting in customers or competitors being able to improve and develop functions based on the components of module manufacturers, leading to poor module security and risks of cross-flashing or substitution. Summary of the Invention
[0003] This application provides a method and apparatus for verifying a wireless communication module, an electronic device, and a storage medium to solve the problem of how to improve module security.
[0004] In a first aspect, this application provides a method for verifying a wireless communication module, which is applied to a wireless communication module. The wireless communication module includes an application processor and a baseband processor. The method includes:
[0005] Based on a dialing request initiated by the application processor and a dialing return result returned by the baseband processor in response to the dialing request, determine a target processor for initiating authentication from the application processor and the baseband processor;
[0006] When synchronization between the target processor and a verification server is successful, send device information of the wireless communication module to the verification server, so that the verification server determines target device information that passes verification based on the device information; wherein, first device information of a target manufacturer is pre-stored in the verification server;
[0007] Based on the target device information, determine manufacturer information of the application processor and the baseband processor to control the application processor or the baseband processor of a non-target manufacturer.
[0008] Optionally, based on a dialing request initiated by the application processor and a dialing return result returned by the baseband processor in response to the dialing request, determining a target processor for initiating authentication from the application processor and the baseband processor includes:
[0009] Determine whether the first identifier is carried in the dialing request initiated by the application processor, and determine whether the second identifier is carried in the dialing return result returned by the baseband processor in response to the dialing request; wherein, when the application processor of the target manufacturer initiates a dialing request, the first identifier is carried in the first preset flag bit, and the baseband processor of the target manufacturer carries the second identifier in the second preset flag bit of the dialing return result;
[0010] If the first identifier is carried in the dialing request, determine that the application processor is the target processor;
[0011] If the first identifier is not carried in the dialing request and the second identifier is carried in the dialing return result, determine that the baseband processor is the target processor.
[0012] Optionally, when the synchronization between the target processor and the verification server is successful, send the device information of the wireless communication module to the verification server, so that the verification server determines the target device information that passes the verification based on the device information, including:
[0013] When the handshake synchronization between the target processor and the verification server is successful, obtain the public key returned by the verification server;
[0014] Encrypt the device information of the wireless communication module with the public key and send it to the verification server, so that the verification server decrypts it with the private key and determines the target device information that passes the verification according to the device information.
[0015] Optionally, determine the manufacturer information of the application processor and the baseband processor based on the target device information, including:
[0016] Obtain the protocol hash value preset between the wireless communication module and the verification server;
[0017] Decrypt the data packet based on the protocol hash value to obtain the target device information; wherein, the data packet is encrypted by the verification server based on the protocol hash value for the target device information;
[0018] If the target device information indicates that both the application processor and the baseband processor match the first device information, determine that the manufacturers of the application processor and the baseband processor are the target manufacturers;
[0019] If the target device information indicates that the application processor matches the first device information, determine that the manufacturer of the application processor is the target manufacturer;
[0020] If the target device information indicates that the baseband processor matches the first device information, determine that the manufacturer of the baseband processor is the target manufacturer.
[0021] In a second aspect, the present application provides a method for verifying a wireless communication module, which is applied to a verification server. The method includes:
[0022] Obtain the first device information of the target manufacturer stored in advance;
[0023] When synchronization with the target processor initiating authentication is successful, obtain the device information of the wireless communication module; wherein, the wireless communication module includes an application processor and a baseband processor, and the target processor is determined from the application processor and the baseband processor based on a dialing request initiated by the application processor and a dialing return result returned by the baseband processor in response to the dialing request;
[0024] Determine the target device information that passes the verification based on the device information and the first device information;
[0025] Send the target device information to the target processor, so that the target processor determines the manufacturer information of the application processor and the baseband processor based on the target device information, and controls the application processor or the baseband processor that is not the target manufacturer.
[0026] Optionally, determining the target device information that passes the verification based on the device information and the first device information includes:
[0027] Perform query verification of the device information in the first device information; the device information at least includes an International Mobile Equipment Identity (IMEI), baseband processor version information, and application processor build number information;
[0028] If the International Mobile Equipment Identity belongs to the filing information in the first device information, verify the baseband processor version information and the application processor build number information;
[0029] If both the baseband processor version information and the application processor build number information pass the verification, use the manufacturer information as the target device information;
[0030] If the application processor build number information does not match the first device information, when the manufacturer information of the baseband processor is the target manufacturer, use the baseband processor version information as the target device information;
[0031] If the baseband processor version information does not match the first device information, then when the manufacturer information of the application processor is the target manufacturer, the build number information of the application processor is used as the target device information.
[0032] Optionally, sending the target device information to the target processor includes:
[0033] Obtain the protocol hash value preset by the wireless communication module and the verification server;
[0034] Encrypt the target device information based on the protocol hash value to obtain a data packet;
[0035] Send the data packet to the target processor.
[0036] In a third aspect, the present application provides a wireless communication module verification device, which is applied to a wireless communication module. The wireless communication module includes an application processor and a baseband processor. The device includes:
[0037] A first determination module, configured to determine a target processor for authentication from the application processor and the baseband processor based on a dialing request initiated by the application processor and a dialing return result returned by the baseband processor in response to the dialing request;
[0038] A first sending module, configured to send the device information of the wireless communication module to the verification server when the synchronization between the target processor and the verification server is successful, so that the verification server determines the target device information that passes the verification based on the device information; wherein, the first device information of the target manufacturer is pre-stored in the verification server;
[0039] A second determination module, configured to determine the manufacturer information of the application processor and the baseband processor based on the target device information, so as to manage the application processor or the baseband processor that is not the target manufacturer.
[0040] In a fourth aspect, the present application provides a wireless communication module verification device, which is applied to a verification server. The device includes:
[0041] A first acquisition module, configured to acquire the first device information of the target manufacturer pre-stored;
[0042] A second acquisition module, configured to acquire the device information of the wireless communication module when the synchronization with the target processor for authentication is successful; wherein, the wireless communication module includes an application processor and a baseband processor, and the target processor is determined from the application processor and the baseband processor based on a dialing request initiated by the application processor and a dialing return result returned by the baseband processor in response to the dialing request.
[0043] A third determination module, configured to determine target device information that passes verification based on the device information and the first device information of the device;
[0044] A second sending module, configured to send the target device information to the target processor, so that the target processor determines the manufacturer information of the application processor and the baseband processor based on the target device information, and controls the application processor or the baseband processor of a non-target manufacturer.
[0045] In a fifth aspect, the present application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0046] The memory is used to store a computer program;
[0047] The processor is configured to implement the wireless communication module verification method according to any embodiment of the first aspect or any embodiment of the second aspect when executing the program stored on the memory.
[0048] In a sixth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the wireless communication module verification method according to any embodiment of the first aspect or any embodiment of the second aspect.
[0049] The above technical solutions provided by the embodiments of the present application have the following advantages compared with the prior art: In the method provided by the embodiments of the present application, based on the dialing request initiated by the application processor and the dialing return result returned by the baseband processor in response to the dialing request, the target processor for initiating authentication is determined from the application processor and the baseband processor; when the synchronization between the target processor and the verification server is successful, the device information of the wireless communication module is sent to the verification server, so that the verification server determines the target device information that passes verification based on the device information; wherein, the first device information of the target manufacturer is pre-stored in the verification server; the manufacturer information of the application processor and the baseband processor is determined based on the target device information, so as to control the application processor or the baseband processor of a non-target manufacturer. This method can verify the device information of the wireless communication module, determine the manufacturer information of the application processor and the baseband processor in the wireless communication module, so that for the target manufacturer, the partial functions of the wireless communication module can be restricted and controlled through the application processor or the baseband processor of its own factory, ensuring the security of the wireless communication module and reducing the risk of the components of its own factory being refreshed or replaced. Description of the Drawings
[0050] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.
[0051] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0052] One or more embodiments are exemplarily illustrated by the pictures in the corresponding accompanying drawings. These exemplary illustrations do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, unless otherwise stated, and the drawings in the figures do not constitute a scale limitation.
[0053] Figure 1 System architecture diagram of a wireless communication module verification method provided for an embodiment of this application;
[0054] Figure 2 Flow schematic diagram of a wireless communication module verification method provided for an embodiment of this application;
[0055] Figure 3 Flow schematic diagram of a wireless communication module verification method provided for another embodiment of this application;
[0056] Figure 4 Schematic diagram of verification initiated by an AP provided for an embodiment of this application;
[0057] Figure 5 Schematic diagram of verification initiated by a BP provided for an embodiment of this application;
[0058] Figure 6 Structural schematic diagram of a wireless communication module verification device provided for an embodiment of this application;
[0059] Figure 7 Structural schematic diagram of a wireless communication module verification device provided for another embodiment of this application;
[0060] Figure 8 Structural schematic diagram of an electronic device provided for an embodiment of this application. Detailed implementation manners
[0061] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Apparently, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0062] The following disclosure provides many different embodiments or examples for implementing different structures of this application. To simplify the disclosure of this application, components and settings of specific examples are described below. Of course, they are only examples and are not intended to limit this application. In addition, this application may repeat reference numerals and / or letters in different examples. This repetition is for the purpose of simplification and clarity and does not in itself indicate the relationship between the various embodiments and / or settings discussed.
[0063] To solve the technical problem of how to improve the security of the module in the prior art, this application provides a method, device, electronic device, and storage medium for verifying a wireless communication module, which can limit some functions of the wireless communication module through the application processor or baseband processor of the factory, ensuring the security of the wireless communication module and reducing the risk of components of the factory being refreshed or replaced.
[0064] The first embodiment of this application provides a method for verifying a wireless communication module. This method can be applied to a Figure 1 system architecture as shown. The system architecture includes at least a wireless communication module 101 and a verification server 102. A communication connection is established between the wireless communication module 101 and the verification server 102.
[0065] This method can be applied to the wireless communication module 101 or the verification server 102 in this system architecture. Next, the method for verifying the wireless communication module will be described in detail based on this system architecture.
[0066] When applied to the wireless communication module, the wireless communication module includes an application processor and a baseband processor. As Figure 2 shown, the method for verifying the wireless communication module includes:
[0067] Step 201: Based on the dialing request initiated by the application processor and the dialing return result returned by the baseband processor in response to the dialing request, determine the target processor for initiating authentication from the application processor and the baseband processor.
[0068] When the wireless communication module makes a network connection, the AP will initiate a dialing request, and the BP will respond to the dialing request and return a dialing result. The target processor for initiating authentication can be determined from the AP and the BP based on the dialing request and the dialing result. The target processor can be the AP or the BP.
[0069] In one embodiment, based on the dialing request initiated by the application processor and the dialing result returned by the baseband processor in response to the dialing request, determining the target processor for initiating authentication from the application processor and the baseband processor includes: determining whether a first identifier is carried in the dialing request initiated by the application processor, and determining whether a second identifier is carried in the dialing result returned by the baseband processor in response to the dialing request; wherein, when the application processor of the target manufacturer initiates a dialing request, the first identifier is carried at a first preset flag bit, and the baseband processor of the target manufacturer carries the second identifier at a second preset flag bit in the dialing result; if the first identifier is carried in the dialing request, the application processor is determined as the target processor; if the first identifier is not carried in the dialing request and the second identifier is carried in the dialing result, the baseband processor is determined as the target processor.
[0070] In this embodiment, the dialing request is a general term and can include the dialing during mobile network registration or the connection request during WIFI connection, without limitation. The target manufacturer can be, for example, manufacturer A. Manufacturer A can preprocess the AP and BP of its own factory. The AP of manufacturer A carries the first identifier when initiating a dialing request, such as adding AUTH_FIBO at a specific flag bit (the first preset flag bit), and the BP of manufacturer A carries the second identifier in the dialing result, such as adding AUTH_READY at a specific flag bit (the second preset flag bit). If AUTH_FIBO is carried in the dialing request and AUTH_READY is carried in the dialing result, it indicates that both the AP and BP in the current wireless communication module are components of manufacturer A, and the AP can initiate authentication. If AUTH_FIBO is carried in the dialing request and AUTH_READY is not carried in the dialing result, it indicates that the AP in the current wireless communication module is a component of manufacturer A, and the BP is a component of another manufacturer other than manufacturer A, and the AP can initiate authentication. If AUTH_FIBO is not carried in the dialing request and AUTH_READY is carried in the dialing result, it indicates that the BP in the current wireless communication module is a component of manufacturer A, and the AP is a component of another manufacturer other than manufacturer A, and the BP can initiate authentication. If AUTH_FIBO is not carried in the dialing request and AUTH_READY is not carried in the dialing result, it indicates that neither the AP nor the BP in the current wireless communication module is a component of manufacturer A, and this scenario is not considered in the embodiments of this application.
[0071] By determining whether the first identifier and the second identifier are carried at the specific flag bits, the target processor for initiating authentication can be determined.
[0072] Step 202: When the synchronization between the target processor and the verification server is successful, send the device information of the wireless communication module to the verification server, so that the verification server determines the target device information that passes the verification based on the device information. The first device information of the target manufacturer is pre-stored in the verification server.
[0073] In one embodiment, when the synchronization between the target processor and the verification server is successful, sending the device information of the wireless communication module to the verification server so that the verification server determines the target device information that passes the verification based on the device information includes: when the handshake synchronization between the target processor and the verification server is successful, obtaining the public key returned by the verification server; encrypting the device information of the wireless communication module with the public key and sending it to the verification server, so that the verification server decrypts it with the private key and determines the target device information that passes the verification according to the device information.
[0074] In this embodiment, the target processor and the verification server first perform a handshake. When the handshake is successfully synchronized, obtain the public key from the verification server, encrypt the device information of the wireless communication module with the public key and send it to the verification server for verification. The device information can be, for example, the International Mobile Equipment Identity (IMEI), the baseband processor version information (BPVersion), and the application processor build number information (build number), etc. The first device information of the target manufacturer is pre-stored in the verification server, such as customer information, cooperation methods, shipped product names, etc., corresponding to information such as IMEI, BP Version, build number, etc., and is archived and mapped to establish a database for mapping. The verification server can use the private key corresponding to the public key to decrypt to obtain the device information, and then verify whether the device information belongs to the first device information in the archive, and take the part that belongs to the first device information as the target device information that passes the verification.
[0075] Step 203: Determine the manufacturer information of the application processor and the baseband processor based on the target device information, so as to control the application processor or the baseband processor of a non-target manufacturer.
[0076] This method can verify the device information of the wireless communication module, determine the manufacturer information of the application processor and the baseband processor in the wireless communication module. Thus, for the target manufacturer, the partial functions of the wireless communication module can be restricted and controlled through the application processor or the baseband processor of its own factory, ensuring the security of the wireless communication module and reducing the risk of the components of its own factory being refreshed or replaced.
[0077] In one embodiment, determining the manufacturer information of the application processor and the baseband processor based on the target device information includes: obtaining the protocol hash value preset between the wireless communication module and the verification server; decrypting the data packet based on the protocol hash value to obtain the target device information, where the data packet is encrypted by the verification server based on the protocol hash value for the target device information; if the target device information indicates that both the application processor and the baseband processor match the first device information, determining that the manufacturers of the application processor and the baseband processor are the target manufacturers; if the target device information indicates that the application processor matches the first device information, determining that the manufacturer of the application processor is the target manufacturer; if the target device information indicates that the baseband processor matches the first device information, determining that the manufacturer of the baseband processor is the target manufacturer.
[0078] In this embodiment, the protocol hash value preset between the wireless communication module and the verification server is, for example, FIBO_SEC. The verification server encrypts the verified target device information through FIBO_SEC to obtain a data packet, and the wireless communication module decrypts the data packet using FIBO_SEC to obtain the target device information. If the target device information obtained from the decryption result indicates that both the AP and the BP match the first device information, for example, the obtained information is the manufacturer information "Manufacturer", it can be determined that the manufacturers of both the AP and the BP are the target manufacturers, and all functions of the wireless communication module can be used normally without control restrictions. If the target device information obtained from the decryption indicates that the AP matches the first device information, for example, the target device information is the build number, it can be determined that the manufacturer of the AP is the target manufacturer and the manufacturer of the BP is a non-target manufacturer. Then, the functions of the AP in the wireless communication module can be used normally, and restrictions can be imposed on the BP side through the AP, such as restricting the BP from flashing the AP. If the target device information obtained from the decryption indicates that the BP matches the first device information, for example, the target device information is the BP Version, it can be determined that the manufacturer of the BP is the target manufacturer and the manufacturer of the AP is a non-target manufacturer. Then, the functions of the BP in the wireless communication module can be used normally, and restrictions can be imposed on the AP side through the BP, such as restricting the AP from flashing the BP.
[0079] In this embodiment, by further verifying the target device information through the verification server, it can be verified whether the AP and the BP are components produced by the target manufacturers, avoiding the problem that when maliciously cracking the dialing request and the dialing return request and adding an identifier at a specific flag bit, it is impossible to correctly identify whether the AP and the BP are components of the target manufacturers, improving the verification security. Moreover, through encrypted verification, the software function inclusion is enhanced, and the security and software function control ability of the wireless communication module are improved.
[0080] When applied to the verification server, the wireless communication module verification method, as Figure 3 , includes:
[0081] Step 301, obtain the first device information of the target manufacturer pre-stored.
[0082] The first device information of the target manufacturer is pre-stored in the verification server, such as customer information, cooperation method, product name shipped, etc., corresponding to information such as IMEI, BP Version, build number, etc., and is archived and mapped to establish a database for mapping.
[0083] Step 302, when synchronized successfully with the target processor that initiates authentication, obtain the device information of the wireless communication module; wherein, the wireless communication module includes an application processor and a baseband processor, and the target processor is determined from the application processor and the baseband processor based on the dialing request initiated by the application processor and the dialing return result returned by the baseband processor in response to the dialing request.
[0084] Step 303, determine the target device information that passes the verification based on the device information and the first device information.
[0085] In one embodiment, determining the target device information that passes the verification based on the device information and the first device information includes: querying and verifying the device information in the first device information; the device information at least includes the International Mobile Equipment Identity, baseband processor version information, and application processor build number information; if the International Mobile Equipment Identity belongs to the recorded information in the first device information, then verify the baseband processor version information and the application processor build number information; if both the baseband processor version information and the application processor build number information pass the verification, then use the manufacturer information as the target device information; if the application processor build number information does not match the first device information, then when the manufacturer information of the baseband processor is the target manufacturer, use the baseband processor version information as the target device information; if the baseband processor version information does not match the first device information, then when the manufacturer information of the application processor is the target manufacturer, use the application processor build number information as the target device information.
[0086] In this embodiment, the device information based on the wireless communication module is queried and verified in the first device information. If the International Mobile Equipment Identity (IMEI) belongs to the recorded information in the first device information, the Baseband Processor Version Information (BPVersion) and the Application Processor Build Number Information (build number) are verified. If both the BP Version and the build number pass the verification, the Manufacturer Information (Manufacturer) is used as the target device information. If the build number does not match the first device information, it is determined whether all BPs used by the customer are from the target manufacturer, that is, it is queried whether the customer only uses BPs from the target manufacturer. When the manufacturer information of the baseband processor is from the target manufacturer, the BP Version is used as the target device information. If the BP Version does not match the first device information, it is determined whether all APs used by the customer are from the target manufacturer, that is, it is queried whether the customer only uses APs from the target manufacturer. When the manufacturer information of the AP is from the target manufacturer, the build number is used as the target device information.
[0087] Step 304: Send the target device information to the target processor so that the target processor determines the manufacturer information of the application processor and the baseband processor based on the target device information, and controls the application processor or the baseband processor from non-target manufacturers.
[0088] This method can verify the device information of the wireless communication module by pre-storing the first device information of the target manufacturer in the verification server, determine the target device information that passes the verification, and enable the target processor to determine the manufacturer information of the application processor and the baseband processor based on the target device information. Thus, partial functions of the wireless communication module can be restricted and controlled through the application processor or the baseband processor of this factory, ensuring the security of the wireless communication module and reducing the risk of components of this factory being refreshed or replaced.
[0089] In one embodiment, sending the target device information to the target processor includes: obtaining the protocol hash value preset by the wireless communication module and the verification server; encrypting the target device information based on the protocol hash value to obtain a data packet; and sending the data packet to the target processor.
[0090] In this embodiment, the wireless communication module and the verification server preset a protocol hash value such as FIBO_SEC. The verification server encrypts the target device information that passes the verification through FIBO_SEC to obtain a data packet and sends the data packet to the target processor, thereby improving the security during the data transmission process.
[0091] In a specific embodiment, the steps of the wireless communication module verification method are as follows, including:
[0092] Step S0, Prerequisite: An internal configuration verification server is set up to record customer information, cooperation methods, product names for shipment, corresponding IMEIs, BP versions, build numbers, etc., and perform archiving mapping to establish a database for mapping.
[0093] Step S1, After the device is powered on, when the mobile network registration is successful or the WIFI connection is successful, and the module has the ability to connect to the network, perform the solution verification.
[0094] Step S2, When the network is connected, the system will send a dialing request.
[0095] 1. Add a specific flag bit AUTH_FIBO to the dialing request (or WIFI connection request). If the Modem receives a dialing request with this flag bit, it will carry the specific flag bit AUTH_READY in the dialing return result. In this scenario, the AP side initiates an authentication request.
[0096] 2. If the AP sends a dialing request with the specific flag bit AUTH_FIBO and the Modem does not carry the specific flag bit AUTH_READY in the returned dialing result, the AP side initiates an authentication request in this scenario.
[0097] 3. If the AP sends a dialing request without the specific flag bit AUTH_FIBO and the Modem does not detect AUTH_FIBO, it will carry the specific flag bit AUTH_READY in the dialing return result. In this scenario, the BP side assembles a packet to initiate an authentication request to the verification server. The scenario where neither the AP nor the BP is the target manufacturer is not considered.
[0098] Step S3, The schematic diagram of the AP initiating the verification is as Figure 4 , The AP initiates the verification process. The AP obtains information such as the device IMEI, BPVersion, and build number, and then accesses the verification server. After successful synchronization with the verification server, the verification server sends the public key to the terminal, and the terminal encrypts the information such as IMEI, BP Version, and build number with the public key and transmits it to the verification server. The schematic diagram of the BP initiating the verification is as Figure 5 , Similarly, on the BP side, after obtaining the IMEI, BP Version, build number, etc. information, it sends them. This will not be elaborated here.
[0099] Step S4: After the verification server uses the private key to decrypt the data packet, it queries and verifies the IMEI / BP Version / build number to confirm whether it belongs to the target manufacturer's shipping record IMEI (this information is used as a preliminary judgment and is not used as a restriction for AP and BP version function judgment). In addition, whether it belongs to the shipping record BP Version and build number information.
[0100] Step S5: Verify device information
[0101] 1. If the BP Version and build number are verified, the Manufacturer information and FIBO_SEC (protocol hash value) are encrypted and returned;
[0102] 2. If the build number does not match, check whether the customer only uses the target manufacturer's BP. If so, encrypt the BPVersion information with FIBO_SEC (protocol hash value) and return it. Otherwise, return AUTH_FAIL.
[0103] 3. If the BP does not match, check whether the build_number corresponds to the customer using only APs from the target manufacturer. If so, encrypt the build number information with FIBO_SEC (protocol hash value) and return it. Otherwise, return AUTH_FAIL.
[0104] 4. If the build number and BP Version do not match, AUTH_FAIL is returned directly.
[0105] Step S6, the terminal side unpacks the packet. Whoever initiates the authentication request unpacks the packet and uses FIBO_SEC (target manufacturer) for decryption. If the decryption result is consistent with the Manufacturer, the AP and BP match and the device functions can be used normally. If the decryption result is BP Version, the BP function can be used normally, and the functions or solutions optimized by the AP and BP will restrict the AP on the BP side. If the decryption result is build number, the AP function can be used normally, and the functions or solutions optimized by the AP and BP will restrict the BP on the AP side.
[0106] Step S7, for specific development functions, control can also be implemented on the verification server to improve software function management.
[0107] The wireless communication module verification method can verify both AP and BP versions. It not only performs string judgment within the software, but also improves encryption capabilities, enhances verification security, and improves software function management capabilities.
[0108] Based on the same inventive concept, a second embodiment of the present application provides a wireless communication module verification device. When applied to a wireless communication module, the wireless communication module includes an application processor and a baseband processor. As Figure 6 , the device includes:
[0109] A first determination module 601, configured to determine a target processor for initiating authentication from the application processor and the baseband processor based on a dialing request initiated by the application processor and a dialing return result returned by the baseband processor in response to the dialing request;
[0110] A first sending module 602, configured to send device information of the wireless communication module to the verification server when synchronization between the target processor and the verification server is successful, so that the verification server determines target device information that passes verification based on the device information; wherein, first device information of a target manufacturer is pre-stored in the verification server;
[0111] A second determination module 603, configured to determine manufacturer information of the application processor and the baseband processor based on the target device information, so as to control the application processor or the baseband processor that is not the target manufacturer.
[0112] This device can verify the device information of the wireless communication module, determine the manufacturer information of the application processor and the baseband processor in the wireless communication module. Thus, for the target manufacturer, partial function restriction control of the wireless communication module can be performed through the application processor or the baseband processor of its own factory, ensuring the security of the wireless communication module and reducing the risk of its components being refreshed or replaced.
[0113] When applied to the verification server, as Figure 7 , the device includes:
[0114] A first acquisition module 701, configured to acquire first device information of a target manufacturer pre-stored;
[0115] A second acquisition module 702, configured to acquire device information of the wireless communication module when synchronization with the target processor for initiating authentication is successful; wherein, the wireless communication module includes an application processor and a baseband processor, and the target processor is determined from the application processor and the baseband processor based on a dialing request initiated by the application processor and a dialing return result returned by the baseband processor in response to the dialing request;
[0116] A third determination module 703, configured to determine target device information that passes verification based on the device information and the first device information;
[0117] A second sending module 704, configured to send the target device information to the target processor, so that the target processor determines the manufacturer information of the application processor and the baseband processor based on the target device information, and controls the application processor or the baseband processor of a non-target manufacturer.
[0118] The device can verify the device information of the wireless communication module by verifying the first device information of the target manufacturer pre-stored in the verification server, determine the target device information that passes the verification, and enable the target processor to determine the manufacturer information of the application processor and the baseband processor based on the target device information. Thus, the device can restrict and control some functions of the wireless communication module through the application processor or baseband processor of its own factory, ensuring the security of the wireless communication module and reducing the risk of its components being refreshed or replaced.
[0119] As Figure 8 shown, an embodiment of the present application provides an electronic device, including a processor 111, a communication interface 112, a memory 113, and a communication bus 114. Among them, the processor 111, the communication interface 112, and the memory 113 complete mutual communication through the communication bus 114.
[0120] The memory 113 is used to store a computer program.
[0121] In an embodiment of the present application, when the processor 111 executes the program stored on the memory 113, it implements the wireless communication module verification method provided in any one of the foregoing method embodiments.
[0122] The communication bus mentioned in the above terminal may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity, only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.
[0123] The communication interface is used for communication between the above terminal and other devices.
[0124] The memory may include a Random Access Memory (RAM), and may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the foregoing processor.
[0125] The above-mentioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0126] The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the wireless communication module verification method provided in any of the foregoing method embodiments.
[0127] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0128] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a general-purpose hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution or the part that contributes to the related technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0129] It should be understood that the terms used herein are for the purpose of describing particular example embodiments only and are not intended to be limiting. Unless the context clearly dictates otherwise, the singular forms "a", "an", and "the" as used herein may also include the plural forms. The terms "comprising", "including", "containing", and "having" are inclusive and thus specify the presence of the stated features, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not to be construed as necessarily requiring them to be performed in the particular order described or illustrated, unless the order of performance is explicitly stated. It should also be understood that additional or alternative steps may be used.
[0130] It should be understood that the specific embodiments described herein are merely for explaining the present application and are not used to limit the present application. In the description, suffixes such as "module", "component", or "unit" used to denote elements are only for the convenience of describing the present application and have no specific meaning in themselves. Therefore, "module", "component", or "unit" may be used interchangeably.
[0131] The above are only specific embodiments of the present application, enabling those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features claimed herein.
Claims
1. A wireless communication module verification method, characterized in that: Applied to a wireless communication module, the wireless communication module includes an application processor and a baseband processor, and the method includes: Based on the dialing request initiated by the application processor and the dialing return result returned by the baseband processor in response to the dialing request, determining a target processor for initiating authentication from the application processor and the baseband processor; When the target processor is successfully synchronized with the verification server, the device information of the wireless communication module is sent to the verification server, so that the verification server determines the target device information that has passed the verification based on the device information; wherein the verification server pre-stores the first device information of the target manufacturer; The manufacturer information of the application processor and the baseband processor is determined based on the target device information, so as to manage and control the application processor or the baseband processor of a non-target manufacturer.
2. The method according to claim 1, characterized in that: Based on a dialing request initiated by an application processor and a dialing return result returned by a baseband processor in response to the dialing request, determining a target processor for initiating authentication from the application processor and the baseband processor, including: Determine whether the dial request initiated by the application processor carries a first identifier, and determine whether the dial return result returned by the baseband processor in response to the dial request carries a second identifier; wherein, when the application processor of the target manufacturer initiates the dial request, the first identifier is carried in a first preset flag position, and the baseband processor of the target manufacturer carries the second identifier in a second preset flag position of the dial return result; If the dial request carries the first identifier, determining that the application processor is the target processor; If the dial request does not carry the first identifier, and the dial return result carries the second identifier, the baseband processor is determined to be the target processor.
3. The method according to claim 1, characterized in that When the target processor is successfully synchronized with the verification server, sending the device information of the wireless communication module to the verification server so that the verification server determines the target device information that has passed the verification based on the device information, including: When the target processor and the verification server have successfully completed handshake synchronization, obtaining a public key returned by the verification server; The device information of the wireless communication module is encrypted by the public key and sent to the verification server, so that the verification server can determine the target device information that has passed the verification based on the device information after decryption based on the private key.
4. The method according to claim 1, characterized in that: Determining the manufacturer information of the application processor and the baseband processor based on the target device information includes: Obtaining a protocol hash value preset by the wireless communication module and the verification server; Decrypting the data packet based on the protocol hash value to obtain the target device information; wherein the data packet is obtained by the verification server encrypting the target device information based on the protocol hash value; If the target device information indicates that both the application processor and the baseband processor match the first device information, determining that the manufacturers of the application processor and the baseband processor are the target manufacturers; If the target device information indicates that the application processor matches the first device information, determining that the manufacturer of the application processor is the target manufacturer; If the target device information indicates that the baseband processor matches the first device information, the manufacturer of the baseband processor is determined to be the target manufacturer.
5. A wireless communication module verification method, characterized in that: Applied to a verification server, the method comprises: Acquire pre-stored first device information of the target manufacturer; When synchronization with the target processor that initiates authentication is successful, the device information of the wireless communication module is obtained; wherein the wireless communication module includes an application processor and a baseband processor, and the target processor is determined from the application processor and the baseband processor based on the dialing request initiated by the application processor and the dialing return result returned by the baseband processor in response to the dialing request; Determine the target device information that has passed the verification based on the device information and the first device information; The target device information is sent to the target processor, so that the target processor determines the manufacturer information of the application processor and the baseband processor based on the target device information, and manages and controls the application processor or the baseband processor of a non-target manufacturer.
6. The method according to claim 5, characterized in that Determining the verified target device information based on the device information and the first device information includes: Performing query and verification in the first device information based on the device information; the device information at least includes an international mobile equipment identity code, baseband processor version information, and application processor build number information; If the international mobile equipment identity code belongs to the filing information in the first device information, verifying the baseband processor version information and the application processor build number information; If both the baseband processor version information and the application processor build number information are verified, the manufacturer information is used as the target device information; If the application processor build number information does not match the first device information, then when the manufacturer information of the baseband processor is the target manufacturer, the baseband processor version information is used as the target device information; If the baseband processor version information does not match the first device information, then when the manufacturer information of the application processors is the target manufacturer, the application processor build number information is used as the target device information.
7. The method according to claim 6, characterized in that Sending the target device information to the target processor includes: Obtaining a protocol hash value preset by the wireless communication module and the verification server; Encrypting the target device information based on the protocol hash value to obtain a data packet; The data packet is sent to the target processor.
8. A wireless communication module verification device, characterized in that: Applied to a wireless communication module, the wireless communication module includes an application processor and a baseband processor, and the device includes: A first determination module is used to determine a target processor for initiating authentication from the application processor and the baseband processor based on a dialing request initiated by the application processor and a dialing return result returned by the baseband processor in response to the dialing request; A first sending module is used to send the device information of the wireless communication module to the verification server when the target processor is successfully synchronized with the verification server, so that the verification server determines the target device information that has passed the verification based on the device information; wherein the verification server pre-stores the first device information of the target manufacturer; The second determination module is used to determine the manufacturer information of the application processor and the baseband processor based on the target device information, so as to manage and control the application processor or the baseband processor of a non-target manufacturer.
9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; The processor is used to implement the wireless communication module verification method described in any one of claims 1-7 when executing the program stored in the memory.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the wireless communication module verification method as described in any one of claims 1 to 7 is implemented.