Memory anti-counterfeiting authentication method, electronic equipment and storage medium
By generating a random challenge code and a memory SPD unique identifier combination, and using the I3C bus for signature and verification, the problem of real-time memory hot-swap attacks in the existing technology is solved, real-time memory legality verification and attack detection are realized, and memory security and reliability are improved.
Patent Information
- Application Number
- CN202510837684.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-20
AI Technical Summary
The existing technology cannot detect hot-swap attacks in running memory in real time, resulting in hardware security and stability problems.
By generating a random challenge code and the SPD unique identifier combination of the target memory, signing and verification are performed, encrypted communication is used using the I3C bus to detect the legitimacy of the memory in real time and prevent hot-swap attacks.
Real-time legality verification and attack detection of memory are realized, ensuring memory security and reliability, reducing deployment costs, and suitable for high-performance computing needs in complex systems.
Smart Images

Figure CN120354460A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and particularly to a method for memory anti-counterfeiting authentication, an electronic device, and a storage medium. Background Art
[0002] With the continuous expansion of the scale of data centers and servers, hardware security issues have become increasingly prominent, especially the authenticity identification of memory modules.
[0003] In related technologies, the static parameters (such as serial numbers) of the memory Serial Presence Detect (SPD) chip are read through the bus, and the memory is periodically verified. However, this method relies on the static parameters during initialization and cannot detect hot-plug attacks on the memory during runtime in real time. Summary of the Invention
[0004] This application provides a method for memory anti-counterfeiting authentication, an electronic device, and a storage medium to at least solve the problem in related technologies that hot-plug attacks on the memory during runtime cannot be detected in real time.
[0005] This application provides a method for memory anti-counterfeiting authentication, including:
[0006] Generating a random challenge code and sending it to the target memory through a communication bus;
[0007] Receiving the signature response returned by the target memory, where the signature response is generated by the target memory using a private key to calculate the challenge code and the unique identifier of the serial presence detect chip of the target memory;
[0008] Verifying the signature response, and triggering a security response mechanism when the verification fails.
[0009] This application also provides a memory anti-counterfeiting authentication device, including:
[0010] A processing module, configured to generate a random challenge code and send it to the target memory through a communication bus;
[0011] A receiving module, configured to receive the signature response returned by the target memory, where the signature response is generated by the target memory using a private key to calculate the challenge code and the unique identifier of the serial presence detect chip of the target memory;
[0012] A verification module, configured to verify the signature response, and trigger a security response mechanism when the verification fails.
[0013] This application also provides an electronic device, including: a memory, configured to store a computer program; a processor, configured to implement the steps of any of the above memory anti-counterfeiting authentication methods when executing the computer program.
[0014] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned memory anti-counterfeiting authentication methods are implemented.
[0015] The present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of any of the above-mentioned memory anti-counterfeiting authentication methods are implemented.
[0016] Through the present application, since each time the memory is authenticated, a different random challenge code is generated, the random challenge code is combined with the SPD unique identifier of the target memory, and the combined result is signed and verified. The SPD unique identifier can ensure the legality of the target memory, and the random challenge code can detect hot-plug attacks initiated by attackers through replay and other means. Therefore, the technical problem in the related art that hot-plug attacks on the memory during operation cannot be detected in real time can be solved, and the security and reliability of the target memory can be effectively ensured. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0018] Figure 1 It is a schematic internal structure diagram of a server provided by an embodiment of the present application;
[0019] Figure 2 It is a schematic flowchart of a memory anti-counterfeiting authentication method provided by an embodiment of the present application Figure 1 ;
[0020] Figure 3 It is a schematic flowchart of a memory anti-counterfeiting authentication method provided by an embodiment of the present application Figure 2 ;
[0021] Figure 4 It is a schematic data flow transmission diagram provided by an embodiment of the present application;
[0022] Figure 5 It is a schematic structural diagram of a memory anti-counterfeiting authentication device provided by an embodiment of the present application;
[0023] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts belong to the protection scope of the present application.
[0025] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variation thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0026] As the scale of data centers and servers continues to expand, hardware security issues have become increasingly prominent, especially the authenticity identification of memory modules. Counterfeit memory modules can not only affect the performance and stability of the system, but also pose security risks such as data leakage.
[0027] In the related art, the static parameters (such as serial numbers) of the memory Serial Presence Detect (SPD) chip are read through the I2C bus, and the Baseboard Management Controller (BMC) performs periodic verification on the memory. However, this method relies on the static parameters during initialization and cannot detect hot-plug attacks during runtime in real time. Moreover, the baseboard management controller only supports the Inter-Integrated Circuit (I2C), and the data transmission rate is low, which cannot meet the requirement of real-time encrypted data transmission.
[0028] The present application proposes a memory anti-counterfeiting authentication method, which combines a random challenge code and the SPD unique identifier of the target memory, and signs and verifies the combined result. The SPD unique identifier can ensure the legitimacy of the target memory, and the random challenge code can detect hot-plug attacks initiated by attackers through replay and other means, and can effectively resist hot-plug attacks on the memory during runtime.
[0029] In order to enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0030] In combination with the specific application environment architecture or specific hardware architecture on which the execution of the memory anti-counterfeiting authentication method depends, the specific application environment architecture or specific hardware architecture is described herein. Refer to Figure 1 , Figure 1 FIG. is a schematic structural diagram inside a server provided by an embodiment of the present application, including a baseboard management controller 11 and a target memory 12. The number of target memories 12 can be multiple, and the baseboard management controller 11 and each target memory 12 can be connected through a communication bus 13.
[0031] The baseboard management controller 11 can monitor the hardware status of the server and facilitate the management of the server. The target memory 12 is the hardware that needs to be verified in the server. Counterfeit memory will not only affect the performance and stability of the server, but may also pose security risks such as data leakage. At the same time, during the operation of the server, the target memory may also be at risk of being attacked. Therefore, it is necessary to authenticate the target memory 12 through the baseboard manager 11 to confirm whether the target memory has been tampered with or whether the operating state of the target memory is normal. Data transmission is achieved between the baseboard management controller 11 and the target memory 12 through the communication bus 13, thereby completing the authentication of the target memory 12.
[0032] Figure 2 FIG. is a schematic flow chart of a memory anti-counterfeiting authentication method provided by an embodiment of the present application Figure 1 , such as Figure 2 shown, an embodiment of the present application provides a memory anti-counterfeiting authentication method, and the method is described in detail as follows:
[0033] S201: Generate a random challenge code and send it to the target memory through the communication bus.
[0034] The random challenge code is randomly generated each time memory anti-counterfeiting authentication is performed, and is used for dynamic anti-counterfeiting authentication of the target memory to prevent replay attacks. The size of the random challenge code can be 128 bits. The random challenge code can be generated by the baseboard management controller in the server, and the baseboard management controller is used to authenticate the target memory.
[0035] The target memory is the memory that needs to be anti-counterfeiting authenticated. The target memory includes an SPD chip, which is the core component of the target memory. The basic information of the target memory, such as type, capacity, manufacturer, etc., is stored on the SPD chip.
[0036] The SPD chip has a unique identifier (Serial Number, SN). The unique identifier is the unique serial number in the SPD chip during the production of the target memory, and is used to identify the uniqueness of the target memory. The legitimacy of the target memory can be determined by verifying the unique identifier of the SPD.
[0037] The communication bus is used to implement data transmission between the baseboard management controller and the target memory, and encrypt the transmitted data. In the embodiment of the present application, the communication bus is an Improved Inter-Integrated Circuit (I3C). I3C can implement AES-128 real-time data stream encryption based on the HDR-DDR mode, ensuring the confidentiality during the data transmission process. Moreover, I3C has a higher transmission rate, with a latency less than 10 milliseconds and a throughput that can reach 5 Mbps, capable of meeting the high-performance computing requirements. Further, the I3C protocol supports multiple devices to access simultaneously, and can be conveniently extended to the anti-counterfeiting authentication of multiple memory modules to meet the requirements of complex systems.
[0038] S202: Receive the signature response returned by the target memory.
[0039] The signature response is used to authenticate the target memory. The signature response is generated by the target memory using the private key to calculate the challenge code and the unique identifier of the serial presence detection chip of the target memory. The signature response can be calculated by the Elliptic Curve Digital Signature Algorithm (ECDSA) and the Secure Hash Algorithm (SHA-256).
[0040] The specific generation process of the signature response includes: the target memory receives the random challenge code sent by the baseboard management controller, splices the random challenge code with the unique identifier to obtain the first splicing result, calculates the hash value of the first splicing result, and encrypts the hash value of the first splicing result using the private key to obtain the signature response. Among them, the unique identifier is used to verify the legitimacy of the target memory, that is, whether the target memory has been replaced; the random challenge code is used to verify the hot-plug attack during the operation of the server. That is, by generating different challenge codes each time, it can prevent attackers from pre-copying the legitimate unique identifier and then replaying the legitimate unique identifier for hot-plug attacks.
[0041] The baseboard management controller can further verify the signature response by receiving the signature response sent by the target memory to determine the status of the target memory.
[0042] S203: Verify the signature response, and trigger the security response mechanism when the verification fails.
[0043] After receiving the signature response, the baseboard management controller can decrypt the signature response and compare it with the unique identifier and random challenge code stored in the baseboard management controller to verify the signature response.
[0044] The process of verifying the signature response includes: the baseboard management controller obtains the random challenge code from the cache and the unique identifier from the fingerprint database, splices the challenge code and the unique identifier to obtain a second splicing result, calculates the hash value of the second splicing result, and decrypts the signature response using the pre-exchanged public key to obtain a decryption result. The decryption result corresponds to the hash value of the first splicing result. Compare the hash value of the second splicing result with the decryption result. If they are the same, it indicates successful verification; if they are different, it indicates failed verification.
[0045] Among them, the fingerprint database is pre-constructed, and the fingerprint data stores the unique identifier of the SPD and the public key for data transmission between the baseboard management controller and the target memory. When the target memory is not tampered with or replaced, the decryption result, the hash value of the first splicing result, and the hash value of the second splicing result should all be the same. Therefore, by comparing the hash value of the second splicing result with the decryption result, the target memory can be verified. When the verification is successful, the server maintains normal operation and records normal status logs. When the verification fails, a security response mechanism is triggered.
[0046] The security response mechanism can include: generating an alarm log, recording the unique identifier of the target memory and the verification failure timestamp; prohibiting data access to the target memory that fails authentication; isolating the physical storage channel where the target memory is located, etc.
[0047] Optionally, the baseboard management controller can be docked with a remote management system to send alarm information to the cloud or other management platforms through the network for subsequent response and handling by operation and maintenance personnel. For example, the baseboard management controller can send alarm information through Redfish to notify the remote management system.
[0048] The alarm log can be generated based on the standard log record protocol (Syslog). Syslog is a log processing tool that can collect, synchronize, filter, etc. log messages. The log messages can come from various components of the server, including the alarm log generated by the baseboard management controller.
[0049] By reusing Redfish and Syslog in related technologies, the memory anti-counterfeiting authentication method provided by the embodiments of the present application can be smoothly integrated into the existing system architecture, and at the same time, it also supports seamless transition with the existing infrastructure, having strong applicability.
[0050] Optionally, in the memory anti-counterfeiting authentication method provided by the embodiments of the present application, the status of the target memory can also be managed, including transmitting the status data of the target memory through the bus, and the baseboard management controller receiving the status data. When the status data is abnormal, a security response mechanism is triggered.
[0051] Among them, the status data may include the temperature, voltage, access mode, etc. of the target memory. Abnormal status data, such as too high temperature of the target memory, too high working voltage, abnormal access mode, etc. When the baseboard management controller detects abnormal status data, it can record an exception log and send an exception message for the operation and maintenance personnel to process.
[0052] Furthermore, in the memory anti-counterfeiting authentication method provided by the embodiments of the present application, I3C can implement AES-128 real-time data stream encryption based on the HDR-DDR mode, that is, the I3C protocol can encrypt the data transmitted between the baseboard management controller and the target memory through a communication key. For example, data such as public keys and unique identifiers transmitted during the authentication process, as well as target status data such as temperature, voltage, access mode, etc., can ensure the integrity and confidentiality of the data transmission process.
[0053] The memory anti-counterfeiting authentication method provided by the embodiments of the present application includes generating a random challenge code and sending it to the target memory through a communication bus; receiving a signature response returned by the target memory, where the signature response is generated by the target memory using a private key to calculate the challenge code and the unique identifier of the serial presence detection chip of the target memory; verifying the signature response, and triggering a security response mechanism when the verification fails. By combining the random challenge code and the SPD unique identifier of the target memory, and signing and verifying the combined result, the legality of the target memory can be ensured through the SPD unique identifier, and hot plugging attacks initiated by attackers through replay and other methods can be detected through the random challenge code, effectively resisting hot plugging attacks on the memory during operation.
[0054] Figure 3 is a schematic flow of the memory anti-counterfeiting authentication method provided by the embodiments of the present application Figure 2 , such as Figure 3 shown, the embodiments of the present application provide a memory anti-counterfeiting authentication method, and the method is described in detail as follows:
[0055] S301: Expand the functions of the bus protocol corresponding to the communication bus.
[0056] The function expansion is used to establish a bottom-layer communication architecture that conforms to anti-counterfeiting authentication. The function expansion may include: the baseboard management controller enables the bus master mode, so that it can allocate a dynamic address for the serial presence detection chip of the target memory; expand the bus protocol module, so that the bus protocol supports hot plugging event capture; expand the bus protocol, define anti-counterfeiting special instruction codes, and the anti-counterfeiting special instruction codes are used to trigger the authentication process.
[0057] Specifically, the bus master mode is a core operating mode defined in the I3C protocol. In the bus master mode, the baseboard management controller has the ability to actively manage the communication bus, can communicate with the target memory at high speed, and assigns addresses to the SPD of the target memory, that is, configures dynamic address assignment (DAA) for the SPD. Among them, the baseboard management controller can manage and authenticate multiple target memories at the same time, and assigns dynamic addresses to the SPD to ensure accurate identification of each corresponding target device on the communication bus.
[0058] The expansion of the bus module can include developing a Linux kernel I3C slave device driver (expansion of the i3c-slave-core module). The i3c-slave-core module is the core framework of the I3C slave device driver provided in the kernel, responsible for handling the underlying communication of the I3C bus. By expanding the bus protocol, the communication bus can support hot-plug event capture, that is, when the target memory is inserted or removed, the baseboard management controller can detect this change through I3C and take corresponding measures.
[0059] The expansion of the bus protocol can include defining an anti-counterfeiting dedicated instruction code (Common Command Code, CCC) in the I3C protocol to trigger the authentication process. In the related art, the authentication of the target memory needs to be performed periodically. In the embodiments of the present application, the authentication process can be triggered in real time through the CCC.
[0060] S302: Perform secure initialization on the baseboard management controller and the target memory.
[0061] The secure initialization is used to establish an identity authentication system for the target memory. The secure initialization can include: broadcasting a dynamic address assignment command through the communication bus when the baseboard management controller starts up, and assigning a dynamic address to the serial presence detection chip of the target memory; calling the key management service of the baseboard management controller to obtain the preset certificate of the memory. According to the preset certificate, the baseboard management controller and the target memory establish a secure communication channel based on the key exchange protocol and exchange public keys; establishing a fingerprint database in the storage area of the baseboard management controller, and the fingerprint database is used to record the unique identifier of the serial presence detection and the public key.
[0062] Specifically, when the baseboard management controller starts up, the baseboard management controller enables the bus master mode, broadcasts a dynamic address assignment command through the I3C bus, triggers the slave device (i.e., the target memory) on the I3C bus to enter the dynamic address assignment mode, and coordinates to complete the assignment of the unique address.
[0063] The Baseboard Management Controller may include a Key Management-IP (KM-IP) to provide services such as local key generation, storage, and secure invocation for the Baseboard Management Controller. The Baseboard Management Controller may obtain a pre-set certificate of the target memory through the key management service. The pre-set certificate is a device identity certificate pre-generated by the memory manufacturer for verifying the legitimacy of the target memory. The pre-set certificate may include information such as the public key of the target memory and the digital signature of the manufacturer. The Baseboard Management Controller may establish a secure communication channel with the target memory based on the pre-set certificate and exchange public keys according to a key exchange protocol. The key exchange protocol may be, for example, the Elliptic Curve Diffie-Hellman (ECDH) key exchange protocol. The key exchange protocol allows both communication parties to negotiate a shared key, i.e., the public key in the embodiments of the present application, on an insecure communication channel. This public key is used for the subsequent verification process of the signature response. The embodiments of the present application do not specifically limit the generation method of the public key, which may be generated based on a random code or a combination of the unique identifier of the target memory and a random code. Among them, the public key generated based on the key exchange protocol is temporary and will be regenerated each time it is started, so it can ensure the forward security of message transmission, that is, the leakage of the current public key will not affect historical messages.
[0064] When establishing a fingerprint database in the storage area of the Baseboard Management Controller, the storage area may be a storage medium with data not easily lost after power-off, such as flash memory, Electrically Erasable Programmable Read Only Memory (EEPROM), etc. The fingerprint database is used to record the unique identifier of the SPD and the public key exchanged through the password exchange protocol.
[0065] S303: The Baseboard Management Controller receives an interrupt signal sent by the communication bus and obtains the unique identifier of the Serial Presence Detect based on the interrupt signal.
[0066] In the embodiments of the present application, I3C may provide an in-band interrupt communication mechanism to send a CCC message to trigger the authentication process. The in-band interrupt mechanism allows the slave device (target memory) to actively send an interrupt signal to the master device (Baseboard Management Controller) without the need for the master device to poll, so as to notify the master device that a specific event has occurred, thereby triggering the authentication process. By the way of actively triggering the authentication process through I3C, the efficiency and timeliness of authentication can be improved.
[0067] Optionally, in addition to being actively triggered, the authentication process may also be triggered by the periodic polling of the Baseboard Management Controller to avoid the target memory not being authenticated for a long time.
[0068] S304: Verify the target memory.
[0069] The process of verifying the target memory is as Figure 2 described in the embodiment and will not be elaborated here. Among them, if the verification is successful, execute S305; if the verification fails, execute S306.
[0070] S305: Record the normal state.
[0071] When the verification of the target memory is successful, it indicates that the target memory has not been replaced or tampered with. At this time, the target server maintains the operation of the support field and records the normal state log, ending the authentication process.
[0072] S306: Trigger the security response mechanism.
[0073] When the verification of the target memory fails, it indicates that the target memory has been replaced or tampered with. At this time, trigger the security response mechanism, including generating an alarm log, prohibiting data access to the target memory that fails the authentication, isolating the physical storage channel where the target memory is located, etc.
[0074] The memory anti-counterfeiting authentication method provided by the embodiment of the present application can provide a basis for memory anti-counterfeiting authentication by extending the I3C bus protocol and performing security initialization on the baseboard management controller and the target memory. By using the I3C bus to realize data transmission between the baseboard management control before and the target memory, a higher data transmission rate can be achieved, meeting the high-performance computing requirements. Moreover, the I3C protocol supports multiple devices to access simultaneously, and it can be easily extended to the anti-counterfeiting authentication of multiple memory modules to meet the requirements of complex systems. At the same time, the I3C bus can encrypt the transmitted data stream in real time, ensuring the confidentiality of the data transmission process. The memory anti-counterfeiting authentication method provided by the embodiment of the present application is compatible with the existing SPD chip design, can enhance the security performance without additional hardware investment, and reduces the overall deployment cost.
[0075] The pseudo-code of the runtime authentication of the memory anti-counterfeiting authentication method provided by the embodiment of the present application is as follows:
[0076] def i3c_mem_auth():
[0077] while True:
[0078] event = wait_for_i3c_ibi(I3C_CCC_MEM_AUTH) # Trigger authentication through I3C in-band interrupt, I3C_CCC_MEM_AUTH represents the CCC message for triggering the authentication process.
[0079] mem_id = event.addr # Record the dynamic address mem_id of the target memory
[0080] challenge = os.urandom(16) # Generate a 128-bit random challenge code challenge
[0081] i3c_transfer(mem_id, WRITE, challenge) # Send the random challenge code to the target memory via I3C
[0082] sig = i3c_transfer(mem_id, READ, 64) # Receive the signature response sig, which is generated based on the ECDSA-SHA256 algorithm
[0083] if verify_signature(sig, challenge, mem_id): # Query the fingerprint database to verify the target memory
[0084] set_health_status(mem_id, "OK") # If the verification is successful, update the target memory status
[0085] else:
[0086] send_alert(REDFISH_EVENT, "MemoryAuthFail", mem_id) # If the verification fails, trigger an alert
[0087] execute_policy("ISO_MEM_BANK", mem_id) # Execute the preset isolation policy, such as shutting down the memory bank
[0088] During the above memory authentication process, the data flow transmission process can be as Figure 4 shown Figure 4 A schematic diagram of data flow transmission provided by an embodiment of the present application, including a baseboard management controller and a target memory, and the data between the baseboard management controller and the target memory is transmitted through a communication bus.
[0089] The data flow transmission process in the memory anti-counterfeiting authentication process specifically includes: the target memory initiates an in-band interrupt through the communication bus, sends a CCC message to the baseboard management controller to trigger the authentication process; the baseboard management controller receives the CCC message, generates a random challenge code, and sends the random challenge code to the target memory; the target memory receives the random challenge code and generates a signature response based on the random challenge code, and sends the signature response to the baseboard management controller; the baseboard management controller receives the signature response and verifies the signature response according to the unique identifier obtained from the fingerprint database.
[0090] In the memory anti-counterfeiting authentication method provided by the embodiment of the present application, the data message transmitted between the baseboard management controller and the target memory may further include a message authentication code, which is used to prevent malicious tampering and ensure the legality of the data.
[0091] In a possible implementation manner, each message transmitted during the generation and authentication process of the signature response may include a Message Authentication Code (MAC). Specifically, the MAC value of the message can be calculated based on the session key generated by the key exchange protocol, and the MAC value is added to the end of the message, and then the message containing the MAC value is sent to the baseboard management controller or the target memory. After receiving the message, the baseboard management controller or the target memory separates the original message and the MAC value, calculates the MAC value of the original message using the same session key, compares the received MAC value with the calculated MAC value. If they are the same, the verification process continues; if they are different, the security response mechanism is triggered and the tampering event is recorded.
[0092] By adding the message authentication code, it is possible to prevent the message from being tampered with during transmission, providing a trusted data basis for subsequent memory anti-counterfeiting authentication.
[0093] The memory anti-counterfeiting detection method provided by the embodiment of the present application can be applied not only to the memory module management of data centers and servers, but also widely to the management of Internet of Things devices, smart homes and building automation, industrial automation and intelligent manufacturing, telecommunications infrastructure management, automotive electronics and autonomous driving systems, medical devices and health monitoring, aerospace and defense systems, and renewable energy management systems. By real-time monitoring and verifying the identity information of devices, it can significantly improve the security and reliability of these fields, optimize energy utilization efficiency, reduce operating costs, and ensure the stability and efficient operation of the system.
[0094] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner.
[0095] Figure 5 It is a schematic structural diagram of a memory anti-counterfeiting authentication device provided by the embodiment of the present application. As Figure 5 shown, the embodiment of the present application also provides a memory anti-counterfeiting authentication device 50, including: a processing module 51, a receiving module 52, and a verification module 53.
[0096] The processing module 51 is used to generate a random challenge code and send it to the target memory through the communication bus;
[0097] A receiving module 52, configured to receive a signature response returned by a target memory, where the signature response is generated by the target memory using a private key to calculate a challenge code and a unique identifier of a serial presence detect (SPD) chip of the target memory;
[0098] A verification module 53, configured to verify the signature response and trigger a security response mechanism when the verification fails.
[0099] In a possible implementation, the apparatus further includes an initialization module, configured to:
[0100] Perform a function extension on a bus protocol corresponding to a communication bus, where the function extension is used to establish a bottom-layer communication architecture conforming to anti-counterfeiting authentication;
[0101] Perform a security initialization on a baseboard management controller and a target memory, where the baseboard management controller is used to perform an identity authentication on the target memory, and the security initialization is used to establish an identity authentication system for the target memory.
[0102] In a possible implementation, the initialization module is further configured to:
[0103] Enable a bus master mode for the baseboard management controller, so that a dynamic address can be assigned to an SPD chip of the target memory;
[0104] Perform a module extension on the bus protocol, so that the bus protocol supports hot-plug event capture;
[0105] Perform a protocol extension on the bus protocol, and define an anti-counterfeiting dedicated instruction code, where the anti-counterfeiting dedicated instruction code is used to trigger an authentication process.
[0106] In a possible implementation, the initialization module is further configured to:
[0107] Broadcast a dynamic address assignment command through the communication bus when the baseboard management controller starts, to assign a dynamic address to an SPD chip of the target memory;
[0108] Invoke a key management service of the baseboard management controller to obtain a preset certificate of the memory. According to the preset certificate, the baseboard management controller and the target memory establish a secure communication channel based on a key exchange protocol and exchange public keys;
[0109] Establish a fingerprint database in a storage area of the baseboard management controller, where the fingerprint database is used to record the unique identifier of the serial presence detect and the public key.
[0110] In a possible implementation, the initialization module is further configured to:
[0111] The baseboard management controller receives an interrupt signal sent by the communication bus and obtains the unique identifier of the serial presence detect based on the interrupt signal.
[0112] In a possible implementation, the receiving module 52 is used to:
[0113] Receive the challenge code sent by the baseboard management controller by the target memory;
[0114] The target memory splices the challenge code and the unique identifier to obtain a first splicing result;
[0115] The target memory calculates the hash value of the first splicing result, and encrypts the hash value of the first splicing result using the private key of the target memory to obtain a signature response.
[0116] In a possible implementation, the verification module 53 is used to:
[0117] The baseboard management controller obtains a random challenge code from the cache and obtains a unique identifier from the fingerprint database;
[0118] The baseboard management controller splices the challenge code and the unique identifier to obtain a second splicing result;
[0119] The baseboard management controller calculates the hash value of the second splicing result, and decrypts the signature response using the pre-exchanged public key to obtain a decryption result, and the decryption result corresponds to the hash value of the first splicing result;
[0120] Compare the hash value of the second splicing result with the decryption result. If they are the same, it means the verification is successful; if they are different, it means the verification fails.
[0121] In a possible implementation, the communication bus is an I3C bus, the bus protocol is an I3C protocol, and the I3C protocol can encrypt the data transmitted between the baseboard management controller and the target memory through a communication key.
[0122] In a possible implementation, the verification module 53 is further used to:
[0123] Generate an alarm log, record the unique identifier of the target memory and the verification failure timestamp;
[0124] Prohibit data access to the target memory that fails authentication;
[0125] Isolate the physical storage channel where the target memory is located.
[0126] In a possible implementation, the memory anti-counterfeiting authentication device 50 is further used to:
[0127] Transmit the status data of the target memory through the communication bus, and the status data includes at least one of the following: temperature, voltage, access mode;
[0128] The baseboard management controller receives the status data, and when the status data is abnormal, triggers a security response mechanism.
[0129] For the description of the features in the corresponding embodiments of the memory anti-counterfeiting authentication device, reference can be made to the relevant description of the corresponding embodiments of the memory anti-counterfeiting authentication method, which will not be elaborated here one by one.
[0130] Figure 6 This is a schematic structural diagram of the electronic device provided in the embodiment of the present application. As Figure 6 shown, the electronic device 60 provided in this embodiment includes: at least one processor 601 and a memory 602. Optionally, the electronic device 60 further includes a communication component 603. Among them, the processor 601, the memory 602, and the communication component 603 are connected through a bus.
[0131] In the specific implementation process, at least one processor 601 executes the computer-executable instructions stored in the memory 602, so that at least one processor 601 executes the above-mentioned memory anti-counterfeiting authentication method embodiment.
[0132] For the specific implementation process of the processor 601, reference can be made to the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.
[0133] In the above embodiment, it should be understood that the processor may be a central processing unit (Central Processing Unit, abbreviated as: CPU), or other general-purpose processors, digital signal processors (Digital Signal Processor, abbreviated as: DSP), application specific integrated circuits (Application Specific Integrated Circuit, abbreviated as: ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0134] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0135] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.
[0136] An embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored. Wherein, the computer program is configured to execute the steps in any of the above embodiments of the memory anti-counterfeiting authentication method when running.
[0137] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media that can store computer programs such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical discs.
[0138] An embodiment of the present application also provides a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, the steps in any of the above embodiments of the memory anti-counterfeiting authentication method are implemented.
[0139] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above embodiments of the memory anti-counterfeiting authentication method are implemented.
[0140] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0141] The above has introduced in detail a memory anti-counterfeiting authentication method, an electronic device, and a storage medium provided by this application. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and modifications can still be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A memory anti-counterfeiting authentication method, characterized in that Including: Generating a random challenge code and sending it to the target memory via the communication bus; Receiving the signature response returned by the target memory, where the signature response is generated by the target memory using a private key to calculate the challenge code and the unique identifier of the serial presence detect chip of the target memory; Verifying the signature response, and triggering a security response mechanism when the verification fails.
2. The memory anti-counterfeiting authentication method according to claim 1, wherein Before generating a random challenge code and sending it to the target memory, the method further includes: Functionally expanding the bus protocol corresponding to the communication bus, where the functional expansion is used to establish a bottom-layer communication architecture compliant with anti-counterfeiting authentication; Performing security initialization on the baseboard management controller and the target memory, where the baseboard management controller is used to authenticate the identity of the target memory, and the security initialization is used to establish an identity authentication system for the target memory.
3. The memory anti-counterfeiting authentication method according to claim 2, wherein The functionally expanding the bus protocol corresponding to the communication bus includes: The baseboard management controller enables the bus master mode, so as to be able to allocate a dynamic address for the serial presence detect chip of the target memory; Performing module expansion on the bus protocol, so that the bus protocol supports hot-plug event capture; Performing protocol expansion on the bus protocol, defining anti-counterfeiting dedicated instruction codes, where the anti-counterfeiting dedicated instruction codes are used to trigger the authentication process.
4. The memory anti-counterfeiting authentication method according to claim 2, wherein The performing security initialization on the baseboard management controller and the target memory includes: Broadcasting a dynamic address allocation command via the communication bus when the baseboard management controller starts up, and allocating a dynamic address for the serial presence detect chip of the target memory; Invoking the key management service of the baseboard management controller to obtain the preset certificate of the target memory, and based on the preset certificate, the baseboard management controller and the target memory establish a secure communication channel and exchange public keys based on the key exchange protocol; Establishing a fingerprint database in the storage area of the baseboard management controller, where the fingerprint database is used to record the unique identifier of the serial presence detect and the public key.
5. The memory anti-counterfeiting authentication method according to claim 1, characterized in that, Before generating a random challenge code, the method further includes: receiving an interrupt signal sent by the communication bus, and obtaining the unique identifier of the serial presence detect based on the interrupt signal.
6. The memory anti-counterfeiting authentication method according to claim 1, wherein The signature response is generated by the target memory using a private key to calculate the challenge code and the unique identifier of the serial presence detect chip of the target memory, including: The target memory receives the challenge code; The target memory splices the challenge code and the unique identifier to obtain a first splicing result; The target memory calculates the hash value of the first splicing result, and encrypts the hash value of the first splicing result using the private key of the target memory to obtain the signature response.
7. The memory anti-counterfeiting authentication method according to claim 1, wherein The verifying the signature response includes: Obtaining the random challenge code and the unique identifier; Splicing the challenge code and the unique identifier to obtain a second splicing result; Calculating the hash value of the second splicing result, and decrypting the signature response using the pre-exchanged public key to obtain a decryption result, where the decryption result corresponds to the hash value of the first splicing result; Compare the hash value of the second splicing result with the decryption result. If they are the same, it indicates successful verification; if they are different, it indicates failed verification.
8. The memory anti-counterfeiting authentication method according to claim 1, wherein The security response mechanism includes: Generate an alarm log to record the unique identifier of the target memory and the verification failure timestamp; Prohibit data access to the target memory that fails authentication; Isolate the physical storage channel where the target memory is located.
9. An electronic device, characterized in that, Including: A memory for storing computer programs; A processor for implementing the steps of the memory anti-counterfeiting authentication method according to any one of claims 1 to 8 when executing the computer program.
10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the memory anti-counterfeiting authentication method according to any one of claims 1 to 8 when executed by a processor.
Citation Information
Patent Citations
Anti-replay authentication method and system
CN109218251A
Server memory anti-counterfeiting authentication method and device, electronic equipment and storage medium
CN116644485A
Memory replacement prevention method, circuit and device, terminal and storage medium
CN117632798A
Memory security verification method and device, equipment and medium
CN118821103A
Field-replaceable unit (FRU) secure component binding
US20210349836A1