Data processing method and device, computing equipment and storage medium

By obtaining and utilizing the initial power-on value and power-on tendency value of the readable and non-writable storage unit of SRAM, the problem of power-off in the prior art requires power outage, and the safety authentication is achieved under constant power state, and the reliability of the device fingerprint is improved.

CN120162773APending Publication Date: 2025-06-17HUAWEI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311735515.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-15
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The existing equipment security authentication process based on SRAM PUF requires power outage of SRAM, resulting in service interruption, and the stability and reliability of SRAM are difficult to maintain under different environmental conditions.

Method used

By obtaining the initial power-on value and power-on tendency value of the readable and unwritable storage unit of the target SRAM, device authentication is performed based on these values ​​to avoid power-off of the SRAM and improve the reliability of the device fingerprint.

Benefits of technology

It realizes equipment safety authentication when SRAM is constantly powered, avoids business interruptions, and improves the stability of equipment fingerprints and the accuracy of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162773A_ABST
    Figure CN120162773A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method and device, computing equipment and a storage medium. The method comprises the following steps: acquiring a power-on initial value of a target storage unit of a target SRAM (Static Random Access Memory) of first equipment, wherein the target storage unit is a readable and non-writable storage unit in the SRAM; acquiring a device fingerprint of the first device; obtaining a power-on tendency value of the target storage unit based on the equipment fingerprint; and authenticating the first equipment according to the power-on initial value and the power-on tendency value. Therefore, the SRAM can be authenticated under the condition that the SRAM is not required to be powered off, so that the service operation in the SRAM is prevented from being influenced after the SRAM is powered off.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and particularly to a data processing method, apparatus, computing device, and storage medium. Background Art

[0002] With the rapid development of networks and intelligent devices, the security of data has become the focus of people's attention. To ensure the security of data, it is very important to perform security authentication on devices.

[0003] Currently, since the Physically Unclonable Function (PUF) can generate a unique identifier or key that cannot be replicated by using the inherent characteristics of the hardware in a device, which can be called a device fingerprint, PUF is widely used in the security authentication process of devices.

[0004] Static Random-Access Memory (SRAM) is usually a common memory in intelligent devices, with high speed and reliability. Due to the random differences in the threshold voltages of transistors, during the power-on process, the initial power-on values of different SRAM memory cells in SRAM are random and unstable, so that device fingerprints can be generated using PUF. However, in the current process of performing security authentication on a device based on SRAM PUF, the device needs to be powered off, resulting in the interruption of the services running in SRAM. Summary of the Invention

[0005] Embodiments of this application provide a data processing method, apparatus, computing device, and storage medium, which can implement security authentication of a device without powering off the SRAM in the device, thereby avoiding the interruption of the services being performed in SRAM.

[0006] In a first aspect, embodiments of this application provide a data processing method, which is applied to an authentication node, and the method includes:

[0007] Obtain the initial power-on value of a target memory cell of the target SRAM of a first device, where the target memory cell is a read-only and non-writable memory cell in the SRAM;

[0008] Obtain the device fingerprint of the first device;

[0009] Obtain the power-on tendency value of the target memory cell based on the device fingerprint;

[0010] Authenticate the first device according to the initial power-on value and the power-on tendency value.

[0011] According to this solution, by obtaining the power-on initial value of the target storage unit of the target SRAM of the first device and determining the power-on tendency value of the target storage unit from the device fingerprint of the first device, the first device is authenticated based on the power-on initial value and the power-on tendency value. Since the target storage unit is a read-only and non-writable storage unit, during the authentication process of the first device, it is not necessary to power off the target SRAM, thus avoiding affecting the service operation in the SRAM after powering off the SRAM.

[0012] In a possible implementation, the target storage unit includes multiple storage units in the target storage range of the target SRAM.

[0013] In this way, by using the power-on initial values of multiple read-only and non-writable storage units to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0014] In a possible implementation, the target storage range includes multiple storage ranges in the target SRAM.

[0015] In this way, by using the power-on initial values of the read-only and non-writable storage units in multiple storage ranges to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0016] In a possible implementation, the target SRAM includes at least two SRAMs among multiple SRAMs in the first device.

[0017] In this way, authenticating the first device based on the storage units in multiple SRAMs can improve the accuracy of authenticating the first device.

[0018] In a possible implementation, authenticating the first device based on the power-on initial value and the power-on tendency value includes:

[0019] When the power-on initial value and the power-on tendency value are consistent, the authentication of the first device passes.

[0020] In a possible implementation, authenticating the first device based on the power-on initial value and the power-on tendency value includes:

[0021] Verify different target storage ranges in the target SRAM respectively. When the power-on initial value and the power-on tendency value of the target storage unit in the first storage range are consistent, confirm that the verification of the first storage range passes. The first storage range is any storage range in the target storage range;

[0022] When the number of the first storage ranges that pass the verification is greater than or equal to the first preset value, the authentication of the first device passes.

[0023] In this way, by using the power-on initial values of multiple read-only and non-writable storage units to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0024] In a possible implementation, authenticating the first device according to the power-on initial value and the power-on tendency value includes:

[0025] Verify different SRAMs respectively. When the power-on initial value and the power-on tendency value of the target storage unit in the first storage interval of the first SRAM are consistent, confirm that the verification of the first storage interval passes. The first storage interval is any storage interval in the target storage interval, and the first SRAM is any SRAM in the target SRAM;

[0026] When the number of the first storage intervals that pass the verification in the first SRAM is greater than the first preset value, the first SRAM passes the authentication;

[0027] When the number of the first SRAMs that pass the authentication is greater than or equal to the second preset value, the first device passes the authentication.

[0028] In this way, by combining the number of the first storage intervals that pass the verification and the number of the first SRAMs to authenticate the first device, the reliability of authenticating the first device can be improved.

[0029] In a possible implementation, obtaining the power-on initial value of the target storage unit of the first device includes receiving the power-on initial value of the target storage unit of the target SRAM of the first device sent by the first device;

[0030] Obtaining the device fingerprint of the first device includes obtaining the device fingerprint from the fingerprint storage center.

[0031] In a second aspect, an embodiment of the present application provides a data processing method, which is applied to a first device. The first device includes an SRAM, and the SRAM includes a read-only and non-writable target storage unit. The method includes:

[0032] Obtain the power-on tendency value of the target storage unit;

[0033] Generate a device fingerprint according to the power-on tendency value of the target storage unit.

[0034] According to this solution, by using the power-on tendency value of the read-only and non-writable target storage unit as the basis for generating the device fingerprint, in this way, it can be ensured that during the process of authenticating the first device through the device fingerprint, the SRAM does not need to be powered off, thus avoiding affecting the business operation in the SRAM after the SRAM is powered off.

[0035] In a possible implementation, the power-on response time of the target storage unit is less than a preset time, where the power-on response time is the time required for the target storage unit to flip from a first value to a power-on tendency value when powered on, and the first value is opposite to the power-on tendency value.

[0036] In this way, the target storage unit is determined through the power-on response time, so that the power-on tendency values of the storage units with strong stability can be screened out to construct the device fingerprint, and the reliability of the device fingerprint is also improved.

[0037] In a possible implementation, the SRAM includes multiple storage ranges, and the device fingerprint is generated based on the power-on tendency values of the target storage units in at least two different storage ranges.

[0038] In this way, the device fingerprint is generated through the power-on tendency values of the target storage units in multiple storage ranges, which can improve the reliability of the device fingerprint.

[0039] In a possible implementation, the first device includes multiple SRAMs, and the device fingerprint is generated based on the power-on tendency values of the target storage units in at least two different SRAMs.

[0040] In this way, the device fingerprint is generated through the power-on tendency values of the target storage units in multiple SRAMs, which can improve the reliability of the device fingerprint.

[0041] In a possible implementation, the method further includes:

[0042] Obtain the power-on initial value of the target storage unit;

[0043] Send the power-on initial value of the target storage unit to the authentication node.

[0044] In this way, by sending the power-on initial value of the read-only and non-writable target storage unit to the authentication node, the authentication node can authenticate the first device through the power-on initial value of the target storage unit. Since the target storage unit is in a read-only and non-writable state and serves as the basis for generating the device fingerprint, in this way, it can be ensured that during the authentication of the first device through the device fingerprint, the SRAM does not need to be powered off, thus avoiding affecting the service operation in the SRAM after powering off the SRAM.

[0045] In a possible implementation, the method further includes:

[0046] Send the device fingerprint to the fingerprint storage center.

[0047] In a possible implementation, the number of target storage units is greater than or equal to a third preset value.

[0048] In a third aspect, an embodiment of the present application provides a data processing device, which is applied to an authentication node. The device includes:

[0049] A first acquisition module, configured to acquire the power-on initial value of a target storage unit of the target SRAM of a first device, where the target storage unit is a storage unit in the SRAM that is readable but not writable;

[0050] A second acquisition module, configured to acquire the device fingerprint of the first device;

[0051] A third acquisition module, configured to acquire the power-on tendency value of the target storage unit based on the device fingerprint;

[0052] An authentication module, configured to authenticate the first device according to the power-on initial value and the power-on tendency value.

[0053] According to this solution, by acquiring the power-on initial value of the target storage unit of the target SRAM of the first device and determining the power-on tendency value of the target storage unit from the device fingerprint of the first device, the first device is authenticated according to the power-on initial value and the power-on tendency value. Since the target storage unit is a storage unit that is readable but not writable, during the process of authenticating the first device, it is not necessary to power off the target SRAM, thereby avoiding affecting the service operation in the SRAM after powering off the SRAM.

[0054] In a possible implementation manner, the target storage unit includes multiple storage units in a target storage range of the target SRAM.

[0055] In this way, by using the power-on initial values of multiple storage units that are readable but not writable to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0056] In a possible implementation manner, the target storage range includes multiple storage ranges in the target SRAM.

[0057] In this way, by using the power-on initial values of the storage units that are readable but not writable in multiple storage ranges to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0058] In a possible implementation manner, the target SRAM includes at least two SRAMs among multiple SRAMs in the first device.

[0059] In this way, authenticating the first device according to the storage units in multiple SRAMs can improve the accuracy of authenticating the first device.

[0060] In a possible implementation manner, the authentication module is configured to pass the authentication of the first device when the power-on initial value is consistent with the power-on tendency value.

[0061] In this way, by using the power-on initial values of multiple read-only storage units to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0062] In a possible implementation, the authentication module is configured to:

[0063] Verify different target storage ranges in the target SRAM respectively. When the power-on initial value and the power-on tendency value of the target storage units in the first storage range are the same, confirm that the verification of the first storage range passes, where the first storage range is any storage range in the target storage ranges;

[0064] When the number of the first storage ranges that pass the verification is greater than or equal to the first preset value, the authentication of the first device passes.

[0065] In this way, by using the power-on initial values of multiple read-only storage units to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0066] In a possible implementation, the authentication module is configured to:

[0067] Verify different SRAMs respectively. When the power-on initial value and the power-on tendency value of the target storage units in the first storage range in the first SRAM are the same, confirm that the verification of the first storage range passes, where the first storage range is any storage range in the target storage ranges and the first SRAM is any SRAM in the target SRAMs;

[0068] When the number of the first storage ranges that pass the verification in the first SRAM is greater than the first preset value, the authentication of the first SRAM passes;

[0069] When the number of the first SRAMs that pass the authentication is greater than or equal to the second preset value, the authentication of the first device passes.

[0070] In this way, by combining the number of the first storage ranges that pass the verification and the number of the first SRAMs, the authentication of the first device is performed, so that the reliability of authenticating the first device can be improved.

[0071] In a possible implementation, obtaining the power-on initial value of the target storage unit of the target SRAM of the first device includes receiving the power-on initial value of the target storage unit of the target SRAM of the first device sent by the first device;

[0072] Obtaining the device fingerprint of the first device includes obtaining the device fingerprint from the fingerprint storage center.

[0073] Fourthly, an embodiment of the present application provides a data processing device, which is applied to the first device. The first device includes an SRAM, and the SRAM includes read-only target storage units, and includes:

[0074] A fourth acquisition module, configured to acquire the power-on tendency value of the target storage unit;

[0075] A generation module, configured to generate a device fingerprint according to the power-on tendency value of the target storage unit.

[0076] According to this solution, by using the power-on tendency value of the non-rewritable target storage unit as the basis for generating the device fingerprint, in this way, it can be ensured that during the authentication of the first device through the device fingerprint, the SRAM does not need to be powered off, thus avoiding the impact on the services running in the SRAM after the SRAM is powered off.

[0077] In a possible implementation manner, the power-on response time of the target storage unit is less than a preset time, and the power-on response time is the time required for the target storage unit to flip from a first value to the power-on tendency value when powered on, and the first value is opposite to the power-on tendency value.

[0078] In this way, the target storage unit is determined through the power-on response time, so that the power-on tendency values of the storage units with strong stability can be screened out to construct the device fingerprint, and the reliability of the device fingerprint is also improved.

[0079] In a possible implementation manner, the SRAM includes multiple storage intervals, and the device fingerprint is generated at least based on the power-on tendency values of the target storage units in the target storage interval among the multiple storage intervals.

[0080] In this way, by generating the device fingerprint through the power-on tendency values of the target storage units in multiple SRAMs, the reliability of the device fingerprint can be improved.

[0081] In a possible implementation manner, the first device includes multiple SRAMs, and the device fingerprint is generated at least based on the power-on tendency values of the target storage units in two different SRAMs.

[0082] In this way, by generating the device fingerprint through the power-on tendency values of the target storage units in multiple SRAMs, the reliability of the device fingerprint can be improved.

[0083] In a possible implementation manner, the device further includes:

[0084] A fifth acquisition module, configured to acquire the power-on initial value of the target storage unit;

[0085] A sending module, configured to send the power-on initial value of the target storage unit to the authentication node.

[0086] In this way, by sending the power-on initial value of the target storage unit that is readable but not writable to the authentication node, the authentication node authenticates the first device based on the power-on initial value of the target storage unit. Since the target storage unit is in a readable but not writable state, as the basis for generating the device fingerprint, in this way, it can be ensured that during the authentication of the first device through the device fingerprint, the SRAM does not need to be powered off, thus avoiding the impact on the services running in the SRAM after the SRAM is powered off.

[0087] In a possible implementation manner, the apparatus further includes:

[0088] A sending module, configured to send the device fingerprint to the fingerprint storage center.

[0089] In a possible implementation manner, the number of target storage units is greater than or equal to a third preset value.

[0090] In a fifth aspect, an embodiment of the present application provides a computing device, including: at least one memory for storing a program; at least one processor for executing the program stored in the memory. When the program stored in the memory is executed, the processor is configured to execute the method provided in the first aspect, or execute the method provided in the second aspect.

[0091] In a sixth aspect, an embodiment of the present application provides a computing device, characterized in that the device runs computer program instructions to execute the method provided in the first aspect, or execute the method provided in the second aspect. Exemplarily, the device may be a chip or a processor.

[0092] In an example, the device may include a processor, which may be coupled to a memory, read instructions in the memory, and execute the method provided in the first aspect, or execute the method provided in the second aspect according to the instructions. Wherein, the memory may be integrated in the chip or the processor, or may be independent of the chip or the processor.

[0093] In a seventh aspect, an embodiment of the present application provides a computer storage medium, in which instructions are stored. When the instructions run on a computer, the computer is caused to execute the method provided in the first aspect, or execute the method provided in the second aspect.

[0094] In an eighth aspect, an embodiment of the present application provides a computer program product containing instructions. When the instructions run on a computer, the computer is caused to execute the method provided in the first aspect, or execute the method provided in the second aspect. Description of the Drawings

[0095] Figure 1It is an architecture diagram of a system for authenticating a device based on SRAM PUF provided by an embodiment of the present application;

[0096] Figure 2 It is a schematic diagram of an Internet of Things application scenario provided by an embodiment of the present application;

[0097] Figure 3 It is a schematic diagram of a process for authenticating a device based on SRAM PUF in a related technology provided by an embodiment of the present application;

[0098] Figure 4 It is a schematic diagram of a process for a data processing method provided by an embodiment of the present application;

[0099] Figure 5 It is a schematic diagram of a process for determining a preset time provided by an embodiment of the present application;

[0100] Figure 6 It is a schematic diagram of the numerical change in a storage unit in SRAM provided by an embodiment of the present application;

[0101] Figure 7 It is a schematic diagram of a process for multiple flip tests provided by an embodiment of the present application;

[0102] Figure 8 It is a schematic diagram of constructing a device fingerprint provided by an embodiment of the present application;

[0103] Figure 9 It is another architecture diagram of a system for authenticating a device based on SRAM PUF provided by an embodiment of the present application;

[0104] Figure 10 It is a schematic diagram of a process for a data processing method provided by an embodiment of the present application;

[0105] Figure 11 It is a schematic diagram of a process for an authentication method of a device provided by an embodiment of the present application;

[0106] Figure 12 It is a schematic diagram of the structure of a data processing device provided by an embodiment of the present application;

[0107] Figure 13 It is a schematic diagram of the structure of another data processing device provided by an embodiment of the present application;

[0108] Figure 14 It is a schematic diagram of the structure of a computing device provided by an embodiment of the present application. Detailed implementation

[0109] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will describe the technical solutions in the embodiments of this application with reference to the accompanying drawings.

[0110] In the description of the embodiments of this application, words such as "exemplary", "for example", or "for illustration" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary", "for example", or "for illustration" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary", "for example", or "for illustration" is intended to present relevant concepts in a specific manner.

[0111] In the description of the embodiments of this application, the term "and / or" merely describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, B exists alone, and both A and B exist simultaneously. In addition, unless otherwise specified, the meaning of the term "plural" refers to two or more. For example, multiple systems refer to two or more systems, and multiple terminals refer to two or more terminals.

[0112] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly indicating the technical features indicated. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The terms "include", "comprise", "have" and their variants all mean "including but not limited to", unless otherwise particularly emphasized in other ways.

[0113] The following explains some terms in this embodiment. It should be noted that these explanations are for the convenience of those skilled in the art to understand and do not constitute a limitation on the scope of protection required by this application.

[0114] PUF: Utilize the inherent physical structure of the hardware to uniquely identify it. This unique identifier can be called the device fingerprint, and any input excitation will output a unique and unpredictable response.

[0115] SRAM PUF: A method that utilizes the instability and randomness of the storage cells in SRAM to generate the device fingerprint of the device where the SRAM is located.

[0116] Data remanence: After writing specific data into the storage cells in SRAM and then powering off and powering on again, some storage cells may undergo unstable state changes, that is, remanence, which is used to extract the device fingerprint.

[0117] Flip: Flip means that after powering on the SRAM, data is written into the storage cells in the SRAM. Then, after powering off the SRAM and powering it on again, the data in the storage cells changes. For example, after powering on the SRAM, "0" is written into all the storage cells, and then after powering off the SRAM and powering it on again, the data in some of the storage cells becomes "1", then these storage cells have flipped.

[0118] Read-only storage cells: Storage cells that can be read from but cannot be written to.

[0119] Power-on tendency value: Due to the manufacturing process of the SRAM affecting the circuit characteristics of the SRAM, when the SRAM is powered on, the storage cells will automatically store 0 or 1, which is the power-on tendency value of the storage cells.

[0120] Currently, in many fields, when devices communicate with each other, the security of the devices is a key factor in ensuring data security. For example, in the field of mobile Internet, during the communication between network element devices and mobile devices, the network element devices authenticate the mobile devices, which can enhance the security and credibility of the mobile devices and prevent illegal users from accessing the data in the Internet and causing data leakage. Another example is in the field of the Internet of Things. Before accessing devices such as sensors, cameras, and smart home devices, authenticating the devices can ensure the security and reliability of the devices.

[0121] The solution for device authentication based on SRAM PUF has been widely used. Figure 1 It is the architecture diagram of the system for device authentication based on SRAM PUF provided by the embodiments of the present application. As Figure 1 shown, the system includes multiple devices 101 and a device fingerprint storage center 102. Multiple devices can communicate with each other. Each device includes an SRAM 111. Among them, some of the multiple devices can be used as authentication nodes to authenticate the remaining devices. As Figure 1 shown, multiple authentication nodes 112 can all authenticate the remaining devices 113.

[0122] As Figure 2 shown, in the Internet of Things scenario, multiple devices can include servers, gateways, and user devices, etc. Among them, the user devices are used to collect data, and the servers are used to receive, save, and process the data collected by the user devices. As Figure 2As shown, the user device can be a smart bulb, a smart door lock, a wearable watch, a camera, a laptop, a mobile phone, etc. Among them, the user device includes user devices that cannot be directly connected to the Internet. Therefore, the gateway is used to connect some user devices and the server. In addition, the gateway can also be used to connect different user devices to enable communication between different user devices. The above user devices are only for illustrative purposes, and the user device can also include other sensors, wearable devices, etc., which are not specifically limited herein.

[0123] In Figure 2 this, the gateway, the server, etc. can all be used as authentication nodes to authenticate the user device.

[0124] In the mobile Internet scenario, the multiple devices can be terminal devices, network element devices, etc. For example, the terminal device can be but is not limited to various personal computers, laptops, smartphones, tablets, and portable wearable devices. Exemplary embodiments of the terminal device involved in this solution include but are not limited to computing devices running iOS, android, Windows, Harmony OS, or other operating systems. The type of the terminal device in the embodiments of the present application is not specifically limited. The network element device can be but is not limited to a router, a switch, etc.

[0125] Among multiple devices, the devices communicate with each other via a network. The network can be a wired network or a wireless network. Exemplarily, the wired network can be a cable network, an optical fiber network, a Digital Data Network (DDN), etc., and the wireless network can be a telecommunication network, an internal network, the Internet, a Local Area Network (LAN), a Wide Area Network (WAN), a Wireless Local Area Network (WLAN), a Metropolitan Area Network (MAN), a Public Service Telephone Network (PSTN), a Bluetooth network, a ZigBee network, a Global System for Mobile Communications (GSM), a Code Division Multiple Access (CDMA) network, a General Packet Radio Service (GPRS) network, etc. or any combination thereof. It can be understood that the network can use any known network communication protocol to implement communication between different client layers and gateways. The above network communication protocols can be various wired or wireless communication protocols, such as Ethernet, universal serial bus (USB), firewire, global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), new radio (NR), Bluetooth, wireless fidelity (Wi-Fi), etc.

[0126] Exemplarily, based on Figure 1 the system shown, such as Figure 3As shown, in the related art, the solution for device authentication based on SRAM PUF includes a fingerprint extraction process and an authentication process. Among them, the fingerprint extraction process includes the following processes:

[0127] S11. Determine the initial values of the memory cells in the SRAM through the residual magnetism method. Here, when powering on for the first time, the initial value tendencies of different memory cells are different. Specifically, write data to all the memory cells in the SRAM, for example, it can be the value 1 or the data 0. Then, power off the SRAM. Finally, power on the SRAM again to determine the initial value of each memory cell in the SRAM. For example, write the data 1 to all the memory cells in the SRAM. After powering off and then powering on the SRAM again, the initial values of some memory cells become the value 0. Then, the initial values of the memory cells whose initial values have changed tend to be 0, and the initial values of the memory cells that have not changed tend to be 1.

[0128] S12. Generate the device fingerprint of the device according to the initial values of each memory cell in the SRAM. The device fingerprints of the device can be uniformly stored in the device fingerprint storage center. Here, in order to ensure the security of the device fingerprint, the initial values of all memory cells can be encoded through the Bose Ray-Chaudhuri Hocquenghem (BCH) code to obtain the SRAM PUF. Further, the SRAM PUF can be encrypted and then saved to the device fingerprint storage center.

[0129] The authentication process refers to authenticating the device based on the SRAM PUF. Among them, the authentication process includes the following steps:

[0130] S21. The authentication node determines the initial values of all the memory cells in the SRAM of the device when powered on. Specifically, the authentication node can send an authentication request to the device to notify the device that the authentication node needs to authenticate the device. After receiving the authentication request, the device needs to power off and then power on the SRAM again to determine the initial values of each memory cell when powered on.

[0131] S22. The authentication node determines to obtain the device fingerprint from the device fingerprint storage center.

[0132] S23. Authenticate the device according to the device fingerprint of the device and the initial values of all the memory cells in the device when powered on.

[0133] In the above process of device identity authentication based on SRAM PUF, it is necessary to obtain the power-on initial values of all logical storage chips in the SRAM, so as to authenticate the SRAM based on the pre-constructed device fingerprint. However, during the authentication process, extracting the power-on initial values of all logical storage chips in the SRAM requires powering off the SRAM, resulting in the interruption of the services running in the SRAM. Frequent authentication requests will affect the performance and security of the SRAM.

[0134] In addition, the power-on initial values of the SRAM are vulnerable to interference from noises such as temperature and voltage. Therefore, under different conditions such as different processes, temperatures, and voltages, the device fingerprints extracted from the same SRAM at different times need to be consistent. In the solution for implementing device identity authentication based on a single SRAM, when the environment such as temperature and voltage changes, the SRAM cannot maintain high stability and reliability. Therefore, the solution for implementing device identity authentication based on a single SRAM lacks flexibility and increases security risks.

[0135] Based on this, the embodiments of the present application propose a data processing method, device, computing device, and storage medium. The method authenticates the first device by obtaining the power-on initial value of the target storage unit of the target SRAM of the first device, and determining the power-on tendency value of the target storage unit from the device fingerprint of the first device, so as to authenticate the first device according to the power-on initial value and the power-on tendency value. Since the target storage unit is a read-only and non-writable storage unit, during the authentication process of the first device, it is not necessary to power off the target SRAM, thus avoiding the impact on the service operation in the SRAM after powering off the SRAM. This is only a brief description of the method, and for the detailed content of the method, please refer to the following description.

[0136] Figure 4 It is a schematic flowchart of a data processing method provided by an embodiment of the present application. As Figure 4 shown, the data processing method provided by the embodiments of the present application can be applied to the devices in the Figure 1 system shown. As Figure 4 shown, the data processing method provided by the embodiments of the present application includes S401 to S402.

[0137] S401, the first device obtains the power-on tendency value of the target storage unit.

[0138] The first device may be Figure 1 any device in the system shown. The first device includes an SRAM, and the SRAM has a read-only and non-writable storage unit, that is, the target storage unit.

[0139] The storage units in the SRAM have power-on tendency values. Powering on the SRAM can determine the power-on initial value of the target storage unit.

[0140] In some embodiments, the power-on response time of the target storage unit is less than a preset time. The power-on response time refers to the time required for the storage unit to flip from a first value to a power-on tendency value when powered on.

[0141] In the embodiments of the present application, before obtaining the power-on tendency value, it is also necessary to determine the target storage unit from multiple storage units. The power-on response time of the target storage unit is less than the preset time. Therefore, before determining the target storage unit, it is necessary to determine the preset time. Specifically, SRAM has the characteristic of data retention. If the SRAM is powered off and then immediately powered on again, the data in the storage unit will return to the data before power-off. On the contrary, if the power-off time of the SRAM is long enough to cause the data remaining in the storage unit to mismatch with the transistors in the storage unit, some of the storage units will return to the data before power-off, while some other storage units will flip to the data opposite to the data before power-off. The mismatch of transistors in the storage units with strong tendency will generate a strong bias, which cannot be overcome by data retention. Therefore, the storage unit that first flips to the opposite value is regarded as the storage unit with strong tendency. The purpose of performing the data remanence test on the SRAM is to find the storage units with strong tendency. By selecting a specific power-off time interval T (i.e., the preset time), a certain number of storage units with strong tendency can be screened out, thereby improving the robustness of the device fingerprint. In addition, different storage units with strong tendency have different tendency initial values. If it is necessary to identify the storage units whose initial value tends to be "1", then write "0" (a value opposite to "1") to all the storage units in the SRAM. After power-on, the storage units with strong tendency will first flip to "1".

[0142] It can be understood that the data stored in the storage unit in the embodiments of the present application is the value "0" or the value "1".

[0143] As a possible implementation, as Figure 5 shown, in S401, the following steps S501 to S507 may be included.

[0144] S501, power on the SRAM and write a value.

[0145] The value includes "0" or "1", and in the embodiments of the present application, "0" and "1" are opposite values. For example, as Figure 6 shown in part 6(a), write the value "0" to all the storage units in the SRAM.

[0146] S502, power off the SRAM.

[0147] S503, after the T time period, power on the SRAM again.

[0148] S504. Determine the number of memory cells in the SRAM that have flipped.

[0149] Take the example where all memory cells are written with "0" when the SRAM is powered on for the first time. After a time period T, power on the SRAM again and count the number of memory cells with the value "1". As Figure 6 shown in part 6(b), since some memory cells tend to have the value "1", the transistor mismatch in the memory cells with a strong tendency will generate a strong bias, which cannot be overcome by data residue. Therefore, after the time period T, when the SRAM is powered on again, the memory cells that tend to have the value "1" flip to the value "0".

[0150] S505. Determine whether the number of memory cells that have flipped is greater than or equal to a third preset value. If so, execute S506; if not, execute S507.

[0151] S506. Store the number of memory cells in the SRAM that have flipped.

[0152] S507. Calculate T = T + ΔT and jump to S501.

[0153] For example, the initial data remanence interval time can be set to 100 ms. If the number of flipped memory cells is less than the preset third preset value, increase the interval time successively, i.e., T = T + ΔT, until the number of flips is greater than or equal to the third preset value, and store the interval time T at this time. T will be used as the preset time.

[0154] Since the tendencies of different memory cells are different, the memory cells with weak tendencies may be unstable under different external environments (such as power-off interval time, temperature, or voltage and other environmental conditions), that is, in different power-on processes, the power-on tendency values may be different. To ensure the stability of the device fingerprint, the power-on tendency values of the target memory cells with strong tendencies can be extracted as the basis for constructing the device fingerprint. Therefore, to improve the accuracy of determining the tendency of the target memory cells, the embodiments of the present application perform the flip test process on the SRAM multiple times, so as to determine the target memory cells with strong tendencies according to the preset time. Among them, the flip test process includes the following process: power on the memory cells in the SRAM and write the first value to all memory cells, and then power off the SRAM. After waiting for the preset time, power on the SRAM again. In this way, according to the preset time, the target memory cells are determined, so as to ensure that the number of bit positions of the data for constructing the device fingerprint is greater than the third preset value, ensure the integrity of the device fingerprint construction, and further improve the accuracy of authenticating the device.

[0155] For example, as Figure 7 shown, the multiple flip test process includes the following steps S701 to S707.

[0156] S701, Power on the SRAM to write a value into the storage cell.

[0157] Among them, the value can be the value "0" or the value "1". In the embodiments of the present application, the value "0" and the value "1" are opposite data. For example, as Figure 6 shown in part 6(a) of the figure, after powering on the SRAM, the storage cells in the SRAM can be powered on, so as to write the value "0".

[0158] S702, Power off the SRAM.

[0159] S703, After a preset target time period, power on the SRAM.

[0160] For the determination process of the target time period, please refer to the detailed description of S401, which will not be elaborated here.

[0161] S704, Determine the interval, logical address, and initial value to which the storage cell that has flipped belongs.

[0162] S705, Determine whether the number of test times is greater than a preset number threshold. If so, execute S706. If not, execute S707.

[0163] S706, Count the number of flips of the storage cell.

[0164] Up to the current flip test process, it is necessary to count the number of times the storage cell has flipped. For example, if the current time is the 20th flip test process, then it is necessary to count the total number of times the storage cell has flipped in the 20 flip test processes.

[0165] S707, Power off the SRAM and jump to S701.

[0166] In this way, the number of flips of each storage cell can be counted. The more times a storage cell flips, the stronger the tendency to the second value, that is, the power-on tendency value of the storage cell is the second value. The reliability of the device fingerprint constructed by the power-on tendency value of the storage cell is stronger. After each flip test process, count the number of times of each storage cell in each interval.

[0167] Exemplarily, generate a frequency statistics table of the storage cells, which is used to record the interval to which the storage cell belongs, the identity identifier of the storage cell (such as the logical address of the storage cell), the power-on tendency value of the storage cell, and the number of flips of the storage cell.

[0168] During multiple flip tests, as a possible implementation, in S701, the data written to the storage cells in SRAM can be "0" or "1". As another possible implementation, during part of the flip test process, in S701, the value written to the storage cell is "0", and during another part of the flip test process, in S701, the value written to the storage cell is "1". For example, there are 50 flip test processes. Among them, during 25 flip test processes, in S701, the value written to the storage cell is "0", and during the remaining 25 flip test processes, in S701, the value written to the storage cell is "1".

[0169] In some embodiments, since the sizes of the storage cells in SRAM are different, in order to improve the efficiency of counting the number of flips and ensure that the storage cells with flips are stable, the SRAM can be divided into several intervals. During each flip test process, only one interval among several intervals is selected to read the values, the values in the storage cells within this interval are recorded, and the flip test process is repeated multiple times for this interval. In this way, the flip test process is performed multiple times for each interval, so as to determine the storage cells with the power-on initial value tending to "1" and the storage cells with the power-on initial value tending to "0".

[0170] Each time, a logical address interval of a specific area is selected for reading (such as reading 4KB of memory each time), and the storage cells tending to "1" and tending to "0" within this interval are recorded. The above operations are repeated 50 times for each interval, and the logical addresses, power-on initial values, and occurrence times of each storage cell are counted. The more times the same power-on initial value appears, the more stable the storage cell is. Sorting from high to low, according to the number of bits required to construct the device fingerprint, the power-on tendency value of the storage cell with the most occurrences is selected as the basis for constructing the device fingerprint.

[0171] In this way, through the division of intervals and the selection of storage cells, the number of values for constructing the device fingerprint is increased, and the possibility of device fingerprint conflicts or repetitions is reduced.

[0172] According to the number of flips of each storage cell, target storage cells are determined from multiple storage cells in SRAM, and then the device fingerprint is constructed through the power-on tendency values of the target storage cells. As a possible implementation, during multiple flip test processes, since the more times a storage cell flips, the stronger the robustness of the constructed device fingerprint. Therefore, the number of flips of the storage cells can be sorted, such as sorting from large to small, and according to the number of flips, target storage cells are determined, where the number of target storage cells is greater than or equal to N. Here, N is the number of bits of the device fingerprint.

[0173] It should be noted that during multiple flip tests, the more times the target storage unit flips, the stronger its stability, and the higher the robustness of the device fingerprint constructed using the power-on tendency value of the target storage unit. Exemplarily, in 100 flip tests, write "0" to storage unit 1 and storage unit 2. Storage unit 1 flipped 89 times, and storage unit 2 flipped 99 times. Then, both storage unit 1 and storage unit 2 tend to 1, and the strength of storage unit 2 tending to "1" is greater than that of storage unit 2 tending to "1". And the ranks of the number of flips of storage unit 1 and storage unit 2 after arrangement are less than N (the number of flips is sorted from largest to smallest). Therefore, storage unit 1 and storage unit 2 are target storage units.

[0174] S402, generate a device fingerprint according to the power-on tendency value of the target storage unit.

[0175] Use the power-on tendency value of the target storage unit as the basis for constructing the device fingerprint. For example, if there are 6 target storage units and the power-on tendency values are 1, 1, 0, 1, 0, 1 respectively, then the device fingerprint includes the power-on tendency value 110101.

[0176] In some embodiments, the target storage unit can also be determined according to the number of flips of the storage unit during the flip test. For example, as Figure 8 shown, the number of bits of the device fingerprint is 10. Among them, after multiple flip tests on the SRAM, after sorting the number of flips of all storage units from largest to smallest, the number of flips of storage unit 1, storage unit 2, storage unit 7, and storage unit 8 is relatively large. Therefore, storage unit 1, storage unit 2, storage unit 7, and storage unit 8 are all target storage units. Among them, the power-on tendency values of storage unit 1 and storage unit 2 are "1", and the power-on tendency values of storage unit 7 and storage unit 8 are "0". Therefore, the values used to construct the device fingerprint include "1", "1", "0", "0".

[0177] Here, it can be understood that the target storage unit determined according to the number of flips includes storage units that are readable but not writable.

[0178] In this way, through multiple flip tests, storage units with high stability can be determined, and thus a device fingerprint can be constructed through the power-on tendency values of storage units with high stability to improve the robustness of the device fingerprint.

[0179] In some embodiments, the device fingerprint further includes the logical address of the target storage unit used to construct the device fingerprint and the range to which the target storage unit belongs. Exemplarily, as Figure 8The device fingerprint generation process shown, where storage unit 1 and storage unit 2 belong to interval 1, and storage unit 7 and storage unit 8 belong to interval 2. Then, the generated device fingerprint is shown in Table 1.

[0180] Table 1

[0181]

[0182] It should be noted that, as a possible implementation, the arrangement order of the logical addresses is arranged according to the order of the values in the storage units indicated by the logical addresses. For example, if the power-on initial value of the storage unit corresponding to logical address 1 is arranged first, then logical address 1 is also arranged first in the logical addresses. Therefore, the arrangement shown in Table 1 is only for illustrative purposes and does not constitute a specific limitation. The specific arrangement of logical addresses also needs to be determined according to the arrangement order of the power-on tendency values of multiple target storage units.

[0183] As a possible implementation, the constructed device fingerprint can be stored in the device fingerprint storage center. Here, the device fingerprint storage center can be a device with storage functions such as a server. For example, as Figure 2 shown, in the Internet of Things scenario, the device fingerprint storage center can be deployed in the server.

[0184] As another possible implementation, the device fingerprint can be stored in each device. For example, as Figure 2 shown, in the Internet of Things scenario, the device fingerprint can be stored in the gateway, the server, etc.

[0185] In some embodiments, the first device may include multiple SRAMs. In this way, it is possible to construct a device fingerprint based on multiple SRAMs, realizing the heterogeneous fusion and unified invocation of the physical characteristic features of multiple SRAMs, increasing the difficulty of cracking the device fingerprint, and thus improving the accuracy and security of device identity authentication. Exemplarily, as Figure 9 shown, the system includes multiple devices 901, where some of the multiple devices 901 can be used as authentication nodes 912, and the other part can be used as terminal devices 911. Among them, the authentication node 912 can authenticate the terminal device 911 based on the device fingerprint. The device 911 includes k SRAMs, where k is a positive integer. Based on the k SRAMs of the device, k device fingerprints can be generated. Among them, as Figure 9As shown in the figure, SRAM 1 corresponds to device fingerprint 1, SRAM 2 corresponds to device fingerprint 2, and so on. SRAM k corresponds to device fingerprint k. For example, the values used to construct device fingerprint 1 in SRAM 1 are 10...0, and the range includes range 1 to range m. Among them, the logical addresses of the storage units used to construct device fingerprint 1 in range 1 are 1 and 2. The logical address of the storage unit used to construct device fingerprint 1 in range m is 599. The values used to construct device fingerprint k in SRAM k are 0...1, and the range includes range 1 to range m. Among them, the logical address of the storage unit used to construct in range 1 is 4. The logical address of the storage unit used to construct SRAM PUF k in range m is 428.

[0186] For the construction process of each device fingerprint, please refer to the description of device fingerprint construction in S401 and S402, which will not be elaborated here.

[0187] Here, the above is only an exemplary description. The logical address of the storage unit can also be represented in other forms, subject to the actual situation. The above examples are only for clearly describing the solution.

[0188] In this way, the heterogeneous fusion and unified invocation of the physical characteristics of multiple SRAMs can increase the difficulty of cracking the SRAM PUF, improve the accuracy of device authentication, and avoid the problem of low authentication security caused by a single authentication factor.

[0189] Next, another data processing method provided by the embodiments of the present application will be described in detail.

[0190] Figure 10 It is a schematic flowchart of the data processing method provided by the embodiments of the present application. This embodiment can be applied to a device acting as an authentication node. Among them, the device acting as an authentication node can communicate with the first device. The first device includes an SRAM.

[0191] As Figure 10 shown, the data processing method provided by the embodiments of the present application at least includes the following steps S1001 to S1004.

[0192] S1001, obtain the power-on initial value of the target storage unit of the target SRAM of the first device, where the target storage unit is a storage unit in the SRAM that is readable but not writable.

[0193] The SRAM includes multiple storage units, among which the multiple storage units include storage units that are readable but not writable, that is, the target storage units. Before the authentication node authenticates the first device, it is necessary to obtain the power-on initial value of the target storage unit in the target SRAM. For example, the authentication node can send an authentication request to the first device. After the first device responds to the authentication request, it sends the power-on initial value of the target storage unit to the authentication node.

[0194] In some embodiments, the target storage unit includes multiple storage units within a target storage range. Specifically, the SRAM can be divided into multiple ranges, and each range includes multiple storage units. Among them, during the authentication process of the first device by the authentication node, the values in the storage units within the target storage range can be read. Before the authentication of the device is completed, the storage units in the target storage range are in a readable but non-writable state. In this way, the storage units in the target storage range can retain the power-on initial values of the storage units, and the power-on initial values will not be overwritten by newly written data.

[0195] It can be understood that the power-on initial value of the storage unit is the value that the storage unit tends to have. The strength of the tendency of the storage unit to "0" and "1" is caused by random physical factors during the manufacturing process, and the random physical factors are unpredictable and uncontrollable. After the SRAM is manufactured, the circuit driving capabilities in the SRAM are different. Therefore, the power-on tendency values of different storage units are different.

[0196] S1002, obtain the device fingerprint of the first device.

[0197] The authentication node can read the device fingerprint of the first device. For example, when the authentication node establishes communication with the first device, it can determine the identity identifier of the first device, and thus read the device fingerprint of the first device according to the identity identifier.

[0198] As a possible implementation, the device fingerprint of the first device can be pre-stored in the authentication node, such as stored in a memory, and the authentication node can read the device fingerprint of the first device from the memory of the authentication node.

[0199] As another possible implementation, as shown in the figure, the device fingerprint of the first device can be pre-stored in the device fingerprint storage center. For example, Figure 1 as shown, the authentication node can obtain the device fingerprint of the first device from the device fingerprint storage center. Specifically, the authentication node can send a security authentication request to the device fingerprint storage center. Among them, the security authentication request includes the identity identifier of the first device, so that the device fingerprint storage center can determine the device fingerprint of the first device according to the identity identifier of the first device.

[0200] The device fingerprint is pre-constructed. For specific details, please refer to Figure 4 the detailed description of constructing the device fingerprint in the embodiments, which will not be elaborated here.

[0201] S1003, obtain the power-on tendency value of the target storage unit based on the device fingerprint.

[0202] The authentication node analyzes the device fingerprint to determine the power-on tendency value of each target storage unit.

[0203] S1004. Authenticate the first device based on the power-on initial value and the power-on tendency value.

[0204] Among them, the device fingerprint is used to indicate the power-on tendency value of the target storage unit in the SRAM of the first device. The power-on tendency value of the target storage unit indicated in the device fingerprint is consistent with the power-on initial value of the target logic unit, and the first device passes the verification.

[0205] In some embodiments, the device fingerprint includes the logical address of the target storage unit. The authentication node analyzes the device fingerprint to determine the logical address of the target storage unit in the SRAM. According to the logical address of the target storage unit in the SRAM, determine the power-on initial value of the target storage unit. According to the power-on initial value of the target storage unit and the power-on tendency value of the target storage unit indicated in the device fingerprint, determine whether the first device passes the authentication. Among them, when the power-on initial value of the target storage unit is consistent with the power-on tendency value of the target storage unit, the first device passes the authentication.

[0206] In some embodiments, the target storage unit is multiple storage units within the target storage range in the target SRAM. Among them, the storage units in the target storage range are in a read-only and non-writable state.

[0207] For example, as Figure 8 shown, the device fingerprint of Device 1 is composed of the power-on tendency values of units such as Storage Unit 1, Storage Unit 2, Storage Unit 7, and Storage Unit 8. Among them, the power-on tendency value of Storage Unit 1 is 1, the power-on tendency value of Storage Unit 2 is 1, the power-on tendency value of Storage Unit 7 is 0, and the power-on tendency value of Storage Unit 8 is 0. During the process of authenticating the device, as Figure 11 shown, the authentication node obtains the device fingerprint of Device 1 from the device fingerprint storage center. In Device 1, Range 1 of the SRAM is in a read-only and non-writable state, that is, Range 1 is the target storage range. According to the logical addresses of the storage units indicated in the device fingerprint, obtain the respective power-on initial values of Storage Unit 1, Storage Unit 2, Storage Unit 7, and Storage Unit 8 in Range 1. The authentication node determines that the value corresponding to logical address 1 indicated in the SRAM PUF is 1, the value corresponding to logical address 2 is 1, the value corresponding to logical address 7 is 0, and the value corresponding to logical address 8 is 0. After comparison, the respective power-on initial values of Storage Unit 1, Storage Unit 2, Storage Unit 7, and Storage Unit 8 are consistent with the values indicated in the device fingerprint, and Device 1 passes the authentication.

[0208] As a possible implementation, the target storage range includes multiple storage ranges. When the power-on initial value and the power-on tendency value of the target storage unit in the first storage range are consistent, the first storage range passes the verification. When the number of the first storage ranges that pass the verification is greater than the first preset value, the first device passes the authentication. The first storage range is any storage range within the target storage range.

[0209] For example, the first preset value is 2, and ranges 1, 2, and 3 are in a read-only and non-writable state. Then ranges 1, 2, and 3 are all in a read-only and non-writable state. The authentication is performed on ranges 1, 2, and 3 respectively, and ranges 1, 2, and 3 all pass the authentication. Then the number of the first storage ranges that pass the authentication is greater than 2, so the first device passes the authentication. The authentication process for each range can refer to Figure 8 the method for range authentication in

[0210] In some embodiments, the first device may include multiple SRAMs, and the target SRAM includes at least two SRAMs. The authentication node can authenticate the first device according to at least two SRAMs, thereby improving the reliability of device authentication.

[0211] Exemplarily, as Figure 9 shown, device 1 includes k SRAMs. Thus, device 1 has k device fingerprints. The authentication node can authenticate the first device through the k device fingerprints. Thus, multiple SRAMs are combined to authenticate the device, which can improve the reliability of device authentication based on device fingerprints.

[0212] As a possible implementation, determine the number of the first SRAMs in the first device. The first SRAM is the target SRAM in which the power-on initial value of the target storage unit in the target storage range is consistent with the power-on tendency value of the target storage unit indicated by the device fingerprint; when the number of the target SRAMs is greater than the preset second preset value, the first device passes the security authentication. The target SRAM is determined by comparing the power-on initial value of the storage unit in the target storage range in the target SRAM with the device fingerprint. The specific process can refer to the detailed description of S1004 and will not be elaborated here.

[0213] For example, the SRAMs through which device 1 passes the authentication include SRAM1 to SRAM8, and the second preset value is 5, that is, the number of the SRAMs that pass the authentication is greater than 5, so device 1 passes the authentication. Here, the method for the SRAM to pass the authentication can refer to Figure 8 the detailed description of authenticating the target storage unit in

[0214] As another possible implementation, different SRAMs are verified separately. When the power-on initial value and the power-on tendency value of the target storage unit in the first storage range of the first SRAM are the same, it is confirmed that the verification of the first storage range passes. The first storage range is any storage range in the target storage range, and the first SRAM is any SRAM in the target SRAM. When the number of the first storage ranges that pass the verification in the first SRAM is greater than the first preset value, the first SRAM passes the authentication. When the number of the first SRAMs that pass the authentication is greater than or equal to the second preset value, the first device passes the authentication.

[0215] It should be noted that the first preset value and the second preset value are preset, and developers can set them according to the situation. In this regard, the embodiments of the present application do not make specific limitations.

[0216] According to the embodiments of the present application, by partitioning the SRAM and selecting that the storage units in the target storage range are in a state where data cannot be written. In this way, during the process of the SRAM not being powered off, the storage units in the target storage range will not be written with new data, that is, the power-on initial value of the storage units in the target storage range will not be overwritten by new data. Furthermore, without the need to power off the SRAM, the authentication node can obtain the power-on initial value of the storage units in the target storage range of the SRAM, and then authenticate the device based on the power-on initial value of the storage units in the target storage range of the SRAM and the device fingerprint of the device, realizing the authentication of the SRAM without powering off the SRAM, and thus avoiding affecting the service operation in the SRAM after powering off the SRAM.

[0217] Based on the same concept as the method embodiments of the present application, the embodiments of the present application also provide a data processing device. The authentication device of the device includes several modules, and each module is used to execute each step in the data processing method provided by the embodiments shown in the present application Figure 10 The division of the modules is not limited here. Those skilled in the art can clearly understand that in actual applications, each step in the data processing method provided by the embodiments of the present application can be allocated to different modules according to needs, that is, the internal structure of the device is divided into different modules to complete all or part of the functions described above. Each module in the embodiment can be integrated in a processing unit, or each unit can exist physically alone, or two or more modules can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the modules are only for the convenience of distinguishing each other and do not limit the protection scope of the present application. The specific working process of the modules in the above device can refer to the corresponding process in the foregoing method embodiments and will not be elaborated here.

[0218] Exemplarily, the authentication device of the device is used to execute the data processing method provided by the embodiments of the present application. Figure 12 It is a schematic structural diagram of the data processing device provided by the embodiments of the present application. As Figure 12 shown, the data processing device provided by the embodiments of the present application is applied to an authentication node, and the device includes:

[0219] A first acquisition module 1201, configured to acquire the power-on initial value of the target storage unit of the target SRAM of the first device, where the target storage unit is a storage unit in the SRAM that is readable but not writable;

[0220] A second acquisition module 1202, configured to acquire the device fingerprint of the first device;

[0221] A third acquisition module 1203, configured to acquire the power-on tendency value of the target storage unit based on the device fingerprint;

[0222] An authentication module 1204, configured to authenticate the first device according to the power-on initial value and the power-on tendency value.

[0223] According to this solution, by acquiring the power-on initial value of the target storage unit of the target SRAM of the first device, and determining the power-on tendency value of the target storage unit from the device fingerprint of the first device, the first device is authenticated according to the power-on initial value and the power-on tendency value. Since the target storage unit is a storage unit that is readable but not writable, during the process of authenticating the first device, it is not necessary to power off the target SRAM, thus avoiding affecting the service operation in the SRAM after powering off the SRAM.

[0224] In a possible implementation manner, the target storage unit includes multiple storage units in the target storage area of the target SRAM.

[0225] In this way, by using the power-on initial values of multiple storage units that are readable but not writable to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0226] In a possible implementation manner, the target storage area includes multiple storage areas in the target SRAM.

[0227] In this way, by using the power-on initial values of the storage units that are readable but not writable in multiple storage areas to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0228] In a possible implementation manner, the target SRAM includes at least two SRAMs among multiple SRAMs in the first device.

[0229] In this way, authenticating the first device according to the storage units in multiple SRAMs can improve the accuracy of authenticating the first device.

[0230] In a possible implementation, the authentication module is used to authenticate the first device when the power-on initial value and the power-on tendency value are the same.

[0231] In this way, by using the power-on initial values of multiple read-only memory cells to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0232] In a possible implementation, the authentication module is used to:

[0233] Verify different target storage ranges in the target SRAM respectively. When the power-on initial value and the power-on tendency value of the target storage cells in the first storage range are the same, confirm that the verification of the first storage range passes. The first storage range is any storage range in the target storage ranges.

[0234] When the number of the first storage ranges that pass the verification is greater than or equal to the first preset value, the authentication of the first device passes.

[0235] In this way, by using the power-on initial values of multiple read-only memory cells to authenticate the first device, the accuracy of authenticating the first device can be improved.

[0236] In a possible implementation, the authentication module is used to:

[0237] Verify different SRAMs respectively. When the power-on initial value and the power-on tendency value of the target storage cells in the first storage range in the first SRAM are the same, confirm that the verification of the first storage range passes. The first storage range is any storage range in the target storage ranges, and the first SRAM is any SRAM in the target SRAMs.

[0238] When the number of the first storage ranges that pass the verification in the first SRAM is greater than the first preset value, the authentication of the first SRAM passes.

[0239] When the number of the first SRAMs that pass the authentication is greater than or equal to the second preset value, the authentication of the first device passes.

[0240] In this way, by combining the number of the first storage ranges that pass the verification and the number of the first SRAMs, the authentication of the first device is performed, so that the reliability of authenticating the first device can be improved.

[0241] In a possible implementation, obtaining the power-on initial value of the target storage cells of the target SRAM of the first device includes receiving the power-on initial value of the target storage cells of the target SRAM of the first device sent by the first device.

[0242] Obtaining the device fingerprint of the first device includes obtaining the device fingerprint from the fingerprint storage center.

[0243] Based on the same concept as the method embodiment of the present application, the embodiment of the present application also provides another data processing device. The data processing device includes several modules, and each module is used to execute Figure 4 each step in the data processing method provided in the embodiment shown. There is no limitation on the division of modules here. Those skilled in the art can clearly understand that in practical applications, each step in the data processing method provided in the embodiment of the present application can be allocated to different modules according to needs, that is, the internal structure of the device is divided into different modules to complete all or part of the functions described above. Each module in the embodiment can be integrated in a processing unit, or each unit exists physically alone, or two or more modules can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each module are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working process of the modules in the above device can refer to the corresponding process in the foregoing method embodiment and will not be elaborated here.

[0244] Exemplarily, the data processing device is used to execute the data processing method provided in the embodiment of the present application, Figure 13 which is a schematic structural diagram of the data processing device provided in the embodiment of the present application. As Figure 13 shown, the data processing device provided in the embodiment of the present application includes:

[0245] A fourth acquisition module 1301, configured to acquire the power-on tendency value of the target storage unit;

[0246] A generation module 1302, configured to generate a device fingerprint according to the power-on tendency value of the target storage unit.

[0247] According to this solution, by using the power-on tendency value of the non-writable target storage unit as the basis for generating the device fingerprint, in this way, it can be ensured that during the authentication of the first device by the device fingerprint, the SRAM does not need to be powered off, thus avoiding the impact on the services running in the SRAM after the SRAM is powered off.

[0248] In a possible implementation manner, the power-on response time of the target storage unit is less than a preset time, and the power-on response time is the time required for the target storage unit to flip from a first value to the power-on tendency value when powered on, and the first value is opposite to the power-on tendency value.

[0249] In this way, the target storage unit is determined through the power-on response time, so that the power-on tendency values of the storage units with strong stability can be screened out to construct the device fingerprint, and the reliability of the device fingerprint is also improved.

[0250] In a possible implementation, the SRAM includes multiple storage ranges, and the device fingerprint is generated based at least on the power-on tendency value of a target storage unit in a target storage range among the multiple storage ranges.

[0251] In this way, generating the device fingerprint based on the power-on tendency values of the target storage units in multiple SRAMs can improve the reliability of the device fingerprint.

[0252] In a possible implementation, the first device includes multiple SRAMs, and the device fingerprint is generated based at least on the power-on tendency values of the target storage units in two different SRAMs.

[0253] In this way, generating the device fingerprint based on the power-on tendency values of the target storage units in multiple SRAMs can improve the reliability of the device fingerprint.

[0254] In a possible implementation, the apparatus further includes:

[0255] A fifth acquisition module, configured to acquire the initial power-on value of the target storage unit;

[0256] A sending module, configured to send the initial power-on value of the target storage unit to an authentication node.

[0257] In this way, by sending the initial power-on value of the read-only and non-writable target storage unit to the authentication node, the authentication node can authenticate the first device based on the initial power-on value of the target storage unit. Since the target storage unit is in a read-only and non-writable state and serves as the basis for generating the device fingerprint, in this way, it can be ensured that during the authentication of the first device through the device fingerprint, the SRAM does not need to be powered off, thereby avoiding affecting the service operation in the SRAM after powering off the SRAM.

[0258] In a possible implementation, the apparatus further includes:

[0259] A sending module, configured to send the device fingerprint to a fingerprint storage center.

[0260] In a possible implementation, the number of target storage units is greater than or equal to a third preset value.

[0261] Based on the same concept as the method embodiment of this application, an embodiment of this application further provides a computing device. This computing device is also the authentication device of the device. The computing device can be a server or a terminal device. Among them, the terminal device can be a mobile phone, a tablet computer, a wearable device, a smart TV, a Huawei Smart Screen, a smart speaker, a vehicle-mounted device, etc.

[0262] Figure 14 It is a schematic structural diagram of a computing device provided by an embodiment of this application.

[0263] As shown Figure 14 in FIG. 1400, the computing device 1400 includes a processor 1401, a memory 1402, and a communication interface 1403.

[0264] The processor 1401 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0265] Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0266] Exemplarily, a computer program may be stored on the memory 1402, and when the processor 1401 executes the computer program, the steps in the above method embodiments are implemented. Alternatively, when the processor 1401 executes the computer program, the functions of the various modules in the above device embodiments are implemented. Exemplarily, the computer program may be divided into one or more modules / units, and the one or more modules / units may be a series of computer program instruction segments capable of performing specific functions. The one or more modules / units are stored in the memory 1402 and executed by the processor 1401 to complete the present application. For example, the computer program may be divided into multiple modules, such as the modules in the device described above.

[0267] The communication interface 1403 is used for sending and receiving data. For example, it sends the data processed by the processor 1401 to other computing devices, or receives data sent by other computing devices, etc.

[0268] Of course, for simplicity, Figure 14 only some of the components related to the present application in the computing device 1400 are shown, and components such as buses, input / output interfaces, etc. are omitted. In addition, according to specific application scenarios, the computing device 1400 may further include any other appropriate components. Additionally, the computing device may be a desktop computer, a notebook, a palm computer, a cloud server, and other computing devices. Those skilled in the art can understand that Figure 14 this is merely an example of the computing device 1400, and does not constitute a limitation on the computing device. It may include more or fewer components than shown in the figure, or combine certain components, or have different components. For example, the computing device may further include an input device, an output device, a network access device, a bus, etc. Exemplarily, the input device may be a microphone array and may also include, for example, a keyboard, a mouse, etc. Exemplarily, the output device may output various information to the outside and may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.

[0269] In addition to the above methods, apparatuses, and computing devices, embodiments of the present application may further provide a computer program product, which includes computer program instructions. When the computer program instructions are run by a processor, the processor is caused to execute the steps in the methods of various embodiments of the present application described in the "Methods" section of this specification above. Among them, the computer program product may be written in any combination of one or more programming languages for computer program code to perform the operations of the embodiments of the present application. The programming languages include object-oriented programming languages such as Java and C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. Among them, the computer program code may be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer program code may be executed entirely on a user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0270] In addition, embodiments of the present application may further provide a computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are run by a processor, the processor is caused to execute the steps in the display control method according to various embodiments of the present disclosure described in the "Methods" section of this specification above. The computer-readable storage medium may adopt any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, include but not be limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. It should be noted that the content included in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice within the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0271] The method steps in the embodiments of the present application can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.

[0272] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0273] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0274] It should be understood that the sequence numbers of the steps in the above embodiments do not imply the order of execution, and the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0275] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the specific details disclosed above are only for the purposes of illustration and easy understanding, rather than limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0276] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended terms, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the phrase "and / or", and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with it.

[0277] It should also be noted that in the devices, equipment, and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure.

[0278] The above description has been given for purposes of illustration and description. In addition, this description does not intend to limit the embodiments of the present disclosure to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions, and sub-combinations thereof.

[0279] It can be understood that the various numerical numbers involved in the embodiments of the present application are only for the convenience of description and do not limit the scope of the embodiments of the present application.

Claims

1. A data processing method, characterized in that, Applied to an authentication node, the method includes: Obtaining the power-on initial value of a target storage unit of a target SRAM of a first device, where the target storage unit is a storage unit in the SRAM that is readable but not writable; Obtaining the device fingerprint of the first device; Obtaining the power-on tendency value of the target storage unit based on the device fingerprint; Authenticating the first device according to the power-on initial value and the power-on tendency value.

2. The method according to claim 1, characterized in that, The target storage unit includes multiple storage units in a target storage range of the target SRAM.

3. The method according to claim 2, characterized in that, The target storage range includes multiple storage ranges in the target SRAM.

4. The method according to any one of claims 1 - 3, characterized in that, The target SRAM includes at least two SRAMs among multiple SRAMs in the first device.

5. The method according to any one of claims 1 - 4, characterized in that, The authenticating the first device according to the power-on initial value and the power-on tendency value includes: When the power-on initial value and the power-on tendency value are consistent, the first device passes the authentication.

6. The method according to claim 3, characterized in that, The authenticating the first device according to the power-on initial value and the power-on tendency value includes: Verifying different target storage ranges in the target SRAM respectively. When the power-on initial value and the power-on tendency value of the target storage unit in the first storage range are consistent, it is confirmed that the first storage range passes the verification, and the first storage range is any storage range in the target storage range; When the number of the first storage ranges that pass the verification is greater than or equal to a first preset value, the first device passes the authentication.

7. The method according to claim 4, characterized in that, The authenticating the first device according to the power-on initial value and the power-on tendency value includes: Verifying different SRAMs respectively. When the power-on initial value and the power-on tendency value of the target storage unit in the first storage range in the first SRAM are consistent, it is confirmed that the first storage range passes the verification, the first storage range is any storage range in the target storage range, and the first SRAM is any SRAM in the target SRAM; When the number of the first storage ranges that pass the verification in the first SRAM is greater than the first preset value, the first SRAM passes the authentication; When the number of the first SRAMs that pass the authentication is greater than or equal to a second preset value, the first device passes the authentication.

8. The method according to any one of claims 1 - 7, characterized in that, The obtaining the power-on initial value of the target storage unit of the target SRAM of the first device includes receiving the power-on initial value of the target storage unit of the target SRAM of the first device sent by the first device; The obtaining the device fingerprint of the first device includes obtaining the device fingerprint from a fingerprint storage center.

9. A data processing method, characterized in that, Applied to a first device, the first device includes an SRAM, and the SRAM includes a target storage unit that is readable but not writable, including: Obtaining the power-on tendency value of the target storage unit; Generating a device fingerprint according to the power-on tendency value of the target storage unit.

10. The data processing method according to claim 9, characterized in that, The power-on response time of the target storage unit is less than a preset time, where the power-on response time is the time required for the target storage unit to flip from a first value to the power-on tendency value when powering on, and the first value is opposite to the power-on tendency value.

11. The data processing method according to claim 9, characterized in that, The SRAM includes a plurality of storage ranges, and the device fingerprint is generated based at least on the power-on tendency value of a target storage unit in a target storage range among the plurality of storage ranges.

12. The data processing method according to any one of claims 9 - 11, characterized in that, The first device includes a plurality of SRAMs, and the device fingerprint is generated based at least on the power-on tendency values of target storage units in two different SRAMs.

13. The data processing method according to any one of claims 9 - 12, characterized in that, The method further includes: Obtaining an initial power-on value of the target storage unit; Sending the initial power-on value of the target storage unit to an authentication node.

14. The data processing method according to any one of claims 9-12, characterized in that, The method further includes: Sending the device fingerprint to a fingerprint storage center.

15. The data processing method according to any one of claims 9-11, characterized in that, The number of the target storage units is greater than or equal to a third preset value.

16. A data processing device, characterized in that, Applied to an authentication node, the apparatus includes: A first obtaining module, configured to obtain an initial power-on value of a target storage unit of a target SRAM of a first device, where the target storage unit is a non-writable and readable storage unit in the SRAM; A second obtaining module, configured to obtain the device fingerprint of the first device; A third obtaining module, configured to obtain the power-on tendency value of the target storage unit based on the device fingerprint; An authentication module, configured to authenticate the first device according to the initial power-on value and the power-on tendency value.

17. A data processing device, characterized in that, Applied to a first device, the first device includes an SRAM, and the SRAM includes a non-writable and readable target storage unit, including: A fourth obtaining module, configured to obtain the power-on tendency value of the target storage unit; A generating module, configured to generate a device fingerprint according to the power-on tendency value of the target storage unit.

18. A computing device, characterized in that, Including: At least one memory, configured to store a program; At least one processor, configured to execute the program stored in the memory. When the program stored in the memory is executed, the processor is configured to execute the method according to any one of claims 1-8, or is configured to execute the method according to any one of claims 9-15.

19. A computing device, characterized in that, The computing device runs computer program instructions to execute the method according to any one of claims 1-8, or is configured to execute the method according to any one of claims 9-15.

20. A computer storage medium, in which instructions are stored, and when the instructions are run on a computer, the computer is caused to execute the method according to any one of claims 1-8, or to execute the method according to any one of claims 9-15.

21. A computer program product containing instructions, which when run on a computer, causes the computer to execute the method according to any one of claims 1-8, or to execute the method according to any one of claims 9-15.

Citation Information

Cited By

  • SRAM-PUF pre-selection method and device, medium and product

    CN122417107A