Equipment authentication method and system, electronic equipment and storage medium
By setting unique information for each slave device and using an authentication method that dynamically updates nodes and random parameters, the problem of insufficient security in existing device authentication methods is solved, and the security and authentication complexity of the device are improved.
Patent Information
- Application Number
- CN202510815653.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-08-15
AI Technical Summary
In the existing equipment authentication methods, the authentication method based on the cryptographic algorithm cannot effectively prevent reverse engineering and program decompilation, resulting in reduced equipment security.
By setting unique first, second and third information for each slave device, the master device generates authentication instructions and compares them to ensure that the authentication mechanism of each slave device is unique, and dynamic update nodes and random parameters are used to increase the complexity of the authentication process.
It enhances the safety of the equipment, prevents the single device from affecting the safety of the entire system after being compromised, and improves the complexity and security of the authentication process.
Smart Images

Figure CN120498847A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular to a device authentication method, system, electronic device and storage medium. Background Art
[0002] In a master-slave communication scenario, after a slave device leaves the factory, the master can only update the slave through a publicly available communication port. Furthermore, before updating important information, the master typically authenticates the slave to determine its trustworthiness. Currently, common authentication methods rely on cryptographic algorithms, but this approach only ensures that the keys between devices are unique. This creates significant vulnerability to attacks such as reverse engineering and program decompilation, thereby reducing device security. Summary of the Invention
[0003] In view of this, an object of the present invention is to provide a device authentication method, system, electronic device and storage medium to improve the security of the device.
[0004] In order to achieve the above objectives, the technical solutions adopted in the embodiments of the present invention are as follows:
[0005] In a first aspect, the present invention provides a device authentication method, applied to a master device, wherein the master device is communicatively connected to at least one slave device, each slave device stores different first information, and each slave device has different second information and third information, the method comprising:
[0006] Generate an authentication instruction based on second information of the slave device to be authenticated; wherein, when the first information is ciphertext, the second information is a key; when the first information is a key, the second information is ciphertext;
[0007] Sending the authentication instruction to the slave device to be authenticated, so that the slave device to be authenticated obtains an actual result based on the second information in the authentication instruction and the first information stored in the slave device, and feeds the result back to the master device;
[0008] Obtaining an expected result based on third information of the slave device to be authenticated, and comparing the expected result with the actual result; wherein the third information is plain text;
[0009] If the actual result is consistent with the expected result, it is determined that the authentication of the slave device to be authenticated is successful; otherwise, if the actual result is inconsistent with the expected result, it is determined that the authentication of the slave device to be authenticated is failed.
[0010] In an optional embodiment, the ciphertext includes a plurality of encryption authentication procedures, and the key includes a plurality of authentication passwords;
[0011] In a case where the first information is ciphertext and the second information is a key, the step of generating an authentication instruction based on the second information of the slave device to be authenticated includes:
[0012] Determining an authentication identifier and a random parameter according to a current update node of the slave device to be authenticated;
[0013] According to the authentication identifier, a target authentication password corresponding to the current update node is obtained from all authentication passwords of the slave device to be authenticated, and an authentication instruction is generated based on the authentication identifier, the random parameter and the target authentication password.
[0014] In an optional embodiment, the ciphertext includes a plurality of encryption authentication procedures, and the key includes a plurality of authentication passwords;
[0015] In a case where the first information is a key and the second information is ciphertext, the step of generating an authentication instruction based on the second information of the slave device to be authenticated includes:
[0016] Determining an authentication identifier and a random parameter according to a current update node of the slave device to be authenticated;
[0017] According to the authentication identifier, a target encryption authentication program corresponding to the current update node is obtained from all encryption authentication programs of the slave device to be authenticated, and an authentication instruction is generated based on the authentication identifier, the random parameter and the target encryption authentication program.
[0018] In an optional embodiment, when the first information is ciphertext and the second information is a key, the slave device to be authenticated obtains an actual result based on the second information in the authentication instruction and the first information stored in the slave device and feeds it back to the master device in the following manner:
[0019] The slave device to be authenticated obtains an authentication identifier, a random parameter, and a target authentication password according to the received authentication instruction, and obtains a target encryption authentication program from all encryption authentication programs stored in the slave device according to the authentication identifier;
[0020] The slave device to be authenticated uses the target authentication password to decrypt the target encrypted authentication program to obtain a target authentication program, and executes the target authentication program based on the random parameters to obtain the actual result and feed it back to the master device.
[0021] In an optional embodiment, when the first information is a key and the second information is ciphertext, the slave device to be authenticated obtains an actual result based on the second information in the authentication instruction and the first information stored in the slave device and feeds it back to the master device in the following manner:
[0022] The slave device to be authenticated obtains an authentication identifier, a random parameter, and a target encryption authentication program according to the received authentication instruction, and obtains a target authentication password from all authentication passwords stored in the slave device according to the authentication identifier;
[0023] The slave device to be authenticated uses the target authentication password to decrypt the target encrypted authentication program to obtain a target authentication program, and executes the target authentication program based on the random parameters to obtain the actual result and feed it back to the master device.
[0024] In an optional embodiment, the plaintext includes multiple authentication procedures;
[0025] The step of obtaining an expected result based on the third information of the slave device to be authenticated includes:
[0026] Determining an authentication identifier and a random parameter according to a current update node of the slave device to be authenticated;
[0027] According to the authentication identifier, obtaining a target authentication program corresponding to the current update node from all authentication programs of the slave device to be authenticated;
[0028] The target authentication procedure is performed based on the random parameters to obtain the expected result.
[0029] In an optional embodiment, all authentication passwords and all encrypted authentication procedures of any one of the slave devices are obtained in the following manner:
[0030] Obtain multiple preset program generation rules;
[0031] For each program generation rule, generating a corresponding authentication program based on the device identification of the slave device according to the program generation rule, thereby obtaining multiple authentication programs for the slave device;
[0032] generating a plurality of authentication passwords for the slave device based on the device identification of the slave device; wherein the plurality of authentication passwords for the slave device are matched one-to-one with the plurality of authentication programs thereof;
[0033] By utilizing each authentication password of the slave device, the authentication program matched thereto is encrypted to obtain an encrypted authentication program, thereby obtaining a plurality of encrypted authentication programs of the slave device.
[0034] In an optional embodiment, the step of generating a corresponding authentication program according to the program generation rule and the device identification of the slave device includes:
[0035] Dividing the device identification of the slave device into a plurality of data groups according to the parsing parameters in the program generation rule; wherein the length of each data group is equal to the parsing parameters;
[0036] According to the parsing rules in the program generation rules, a corresponding function is generated based on each data group, and an authentication program containing the functions corresponding to all data groups is obtained; wherein the parsing rules represent the correspondence between the values on each bit in the data group and the function elements, and the function elements include function type, operation type, operation strategy and number of loops.
[0037] In an optional embodiment, when the device identifier of the slave device is a binary number, the function type includes a first type and a second type, the first type indicating that the function operates based on multiple data, and the second type indicating that the function operates based on a single data.
[0038] In a second aspect, the present invention provides a device authentication method, which is applied to a slave device, wherein the slave device is communicatively connected to a master device, the slave device stores first information, and the master device stores second information and third information of the slave device, the method comprising:
[0039] obtaining an actual result based on the second information in the authentication instruction received from the master device and the first information stored in the master device, and feeding the result back to the master device, so that the master device obtains an expected result based on the third information of the slave device, and compares the expected result with the actual result, and determines that the authentication of the slave device is successful if the actual result is consistent with the expected result, or determines that the authentication of the slave device is unsuccessful if the actual result is inconsistent with the expected result;
[0040] Among them, the authentication instruction is generated by the master device based on the second information of the slave device; when the first information is ciphertext, the second information is a key; when the first information is a key, the second information is ciphertext; and the third information is plaintext.
[0041] In a third aspect, the present invention provides a system comprising a master device and a slave device in communication connection, wherein the master device is used to implement the device authentication method described in any one of the aforementioned embodiments, and the slave device is used to implement the device authentication method described in the aforementioned embodiments.
[0042] In a fourth aspect, the present invention provides an electronic device, comprising a processor and a memory, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the device authentication method described in any one of the aforementioned embodiments, and / or the device authentication method described in the aforementioned embodiments.
[0043] In a fifth aspect, the present invention provides a storage medium having a computer program stored thereon. When the computer program is executed by a processor, the device authentication method described in any one of the aforementioned embodiments and / or the device authentication method described in the aforementioned embodiments is implemented.
[0044] Embodiments of the present invention provide a device authentication method, system, electronic device, and storage medium. The method includes: a master device generates an authentication instruction based on second information of a slave device to be authenticated and sends it to the slave device to be authenticated, so that the slave device to be authenticated obtains an actual result based on the second information in the authentication instruction and its own stored first information and feeds it back to the master device; the master device then obtains an expected result based on third information of the slave device to be authenticated and compares the expected result with the actual result; and when the two are consistent, determines that the authentication of the slave device to be authenticated is successful, or when the two are inconsistent, determines that the authentication of the slave device to be authenticated fails. By setting different authentication information for different slave devices, the embodiments of the present invention ensure that the authentication mechanisms of different slave devices are unique. Even if a slave device is compromised, the security of other slave devices will not be affected, thereby improving the security of the entire system. Furthermore, only a portion of the authentication information is stored in the slave device, and the remaining authentication information is sent to the slave device only when the master device authenticates the slave device. This increases the difficulty of device compromise and further ensures the security of the device.
[0045] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0047] Figure 1 A schematic diagram of a system provided by an embodiment of the present invention is shown;
[0048] Figure 2 A schematic diagram showing a flow chart of a device authentication method provided by an embodiment of the present invention is shown;
[0049] Figure 3 An example diagram of a device authentication method provided by an embodiment of the present invention when the first information is ciphertext and the second information is a key is shown;
[0050] Figure 4An example diagram of a device authentication method provided by an embodiment of the present invention when the first information is a key and the second information is ciphertext is shown;
[0051] Figure 5 A schematic diagram of a flow chart of generating an authentication password and an encryption authentication procedure for a slave device provided in an embodiment of the present invention is shown;
[0052] Figure 6 A block diagram of an electronic device provided by an embodiment of the present invention is shown.
[0053] Icon: 110 - processor; 120 - memory; 130 - communication module. DETAILED DESCRIPTION
[0054] The following will be combined with the accompanying drawings to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.
[0055] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but is merely intended to represent selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0056] It should be noted that relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
[0057] See also Figure 1 , is a schematic diagram of a system provided by an embodiment of the present invention. The system includes a master device and multiple slave devices, with the master device being in communication with each slave device. The master device is the device that plays the leading role in the communication process; the slave device is the device that responds to instructions from the master device.
[0058] In related technologies, before transmitting important data to a slave, a master device typically authenticates the slave to determine its trustworthiness. However, the current approach of using only different keys to authenticate different slave devices poses a security threat to the entire system. For example, if all slave devices use the same authentication mechanism, an attacker can simply crack the authentication mechanism of one slave to deduce the authentication process of the other devices, thereby launching an attack on the entire system.
[0059] Therefore, embodiments of the present invention provide a device authentication method that, by setting different authentication information for different slave devices, ensures that each slave device's authentication mechanism is unique, thereby improving device authentication security and reducing the impact of a single device compromise on the entire system. The following describes the various steps of the methods provided by embodiments of the present invention, using the aforementioned master device as the execution subject, and the corresponding technical effects.
[0060] See also Figure 2 , is a flow chart of a device authentication method provided by an embodiment of the present invention.
[0061] Step S202: Generate an authentication instruction based on the second information of the slave device to be authenticated; wherein, when the first information is ciphertext, the second information is a key; when the first information is a key, the second information is ciphertext.
[0062] Step S204: Send the authentication instruction to the slave device to be authenticated, so that the slave device to be authenticated obtains an actual result based on the second information in the authentication instruction and the first information stored in itself, and feeds it back to the master device.
[0063] Step S206: obtaining an expected result based on third information of the slave device to be authenticated, and comparing the expected result with the actual result; wherein the third information is plain text.
[0064] Step S208: If the actual result is consistent with the expected result, it is determined that the authentication of the slave device to be authenticated is successful.
[0065] Step S210: If the actual result is inconsistent with the expected result, it is determined that the authentication of the slave device to be authenticated has failed.
[0066] In this embodiment, each slave device stores first information before leaving the factory. The first information stored in each slave device is unique, and each slave device also has unique second and third information. When the first information is ciphertext, the second information is the key required for decryption; when the first information is the key, the second information is the ciphertext that needs to be decrypted; and the third information is the plaintext that does not need to be decrypted. This means that each slave device uses a different key, ciphertext, and plaintext for authentication. By setting different authentication information for different slave devices, each slave device can have a unique authentication mechanism.
[0067] It is understood that the process of the master device authenticating each slave device is similar. For the sake of simplicity, the following description uses the slave device to be authenticated as an example. For example, the master device can generate the second information and the third information of each slave device by using the device identifier of each slave device, such as the UID (User Identification).
[0068] If the first information stored in the slave device to be authenticated is ciphertext, and its second information is a key, the master device first obtains the second information (key) based on the UID of the slave device to be authenticated and generates an authentication instruction to send to the slave device to be authenticated. The slave device to be authenticated then obtains the second information (key) based on the authentication instruction and decrypts it in conjunction with its own stored first information (ciphertext). The decryption process generates the actual result and sends it back to the master device.
[0069] If the first information stored in the slave device to be authenticated is a key, and its second information is ciphertext, the master device first obtains the second information (the ciphertext) based on the UID of the slave device to be authenticated and generates an authentication instruction to send to the slave device to be authenticated. The slave device to be authenticated then obtains the second information (the ciphertext) based on the authentication instruction and decrypts it with its own stored first information (the key), obtaining the actual result and feeding it back to the master device.
[0070] Next, the master device retrieves the third information (the plaintext) from the slave device to be authenticated based on its UID to obtain the expected result. Finally, the master device compares the expected result with the actual result to obtain the authentication result for the slave device to be authenticated. If the two match, it indicates that the slave device to be authenticated followed the correct authentication mechanism and its identity is trustworthy. The authentication of the slave device to be authenticated is considered successful. If the two do not match, it indicates that the slave device to be authenticated may have been tampered with and its identity is untrustworthy. The authentication of the slave device to be authenticated is considered a failure.
[0071] It can be understood that by setting different authentication information for different slave devices, the embodiments of the present invention ensure that the authentication mechanisms of different slave devices are unique. This ensures that even if a slave device is compromised, the security of other slave devices will not be affected, thereby improving the security of the entire system. Furthermore, only partial authentication information is stored in the slave device. The remaining authentication information is only sent to the slave device when the master device authenticates the slave device. This makes it more difficult to compromise the device and further ensures its security.
[0072] Optionally, the plaintext and ciphertext described above can be in the form of data, i.e., the plaintext is the original data, and the ciphertext is the encrypted data obtained by encrypting the original data. Then, for the above-mentioned process of obtaining the actual result and the expected result and comparing the two, the following method can be adopted: the slave device to be authenticated decrypts the ciphertext, i.e., the encrypted data, based on the key, obtains the decrypted data, and feeds it back to the master device as the actual result. The master device obtains the plaintext of the slave device to be authenticated, i.e., the original data, and uses it as the expected result. The master device then determines the authentication result of the slave device to be authenticated by comparing the decrypted data with the original data. That is, if the decrypted data is consistent with the original data, the authentication of the slave device to be authenticated is determined to be successful; if the decrypted data is inconsistent with the original data, the authentication of the slave device to be authenticated is determined to be unsuccessful.
[0073] However, in practical applications, ciphertext in the form of data is easily tampered with and intercepted, which can affect device security. Therefore, embodiments of the present invention provide an implementation method in which ciphertext is implemented in the form of a program. Furthermore, considering that a device's authentication program remains unchanged over its long lifecycle, attackers have ample time to crack the authentication mechanism. To further enhance device security, embodiments of the present invention also provide an implementation method for dynamically adjusting the authentication program based on the device's update node, thereby dynamically changing the device's authentication mechanism. Specifically, for step S202, embodiments of the present invention provide two possible implementation methods.
[0074] Step S202-1: Determine the authentication identifier and random parameters according to the current update node of the slave device to be authenticated.
[0075] In step S202-2A, when the first information is ciphertext and the second information is a key, according to the authentication identifier, obtain the target authentication password corresponding to the current update node from all authentication passwords of the slave device to be authenticated, and generate an authentication instruction based on the authentication identifier, random parameters and target authentication password.
[0076] Step S202-2B, when the first information is a key and the second information is a ciphertext, according to the authentication identifier, obtain the target encryption authentication program corresponding to the current update node from all encryption authentication programs of the slave device to be authenticated, and generate an authentication instruction based on the authentication identifier, random parameters and target encryption authentication program.
[0077] In this embodiment, the ciphertext of each slave device includes multiple encryption authentication programs, and the key of each slave device includes multiple authentication passwords. The multiple encryption authentication programs and multiple authentication passwords of a slave device correspond one-to-one. Furthermore, each slave device has multiple update nodes. These update nodes can be time nodes reached after the device leaves the factory, such as six months or one year, or they can be maintenance nodes reached after the device leaves the factory, such as firmware upgrades or configuration updates. In other words, the update nodes can be set according to actual circumstances, and this embodiment of the present invention does not limit this.
[0078] For ease of understanding, the following explanation uses the example of an update node being a time node. For example, when the master device detects that the slave device to be authenticated has been out of the factory for six months, it will obtain the corresponding authentication identifier such as 3A and random parameters such as H based on the current update node of six months.
[0079] See also Figure 3 If the first information stored in the slave device to be authenticated is ciphertext, i.e., multiple encrypted authentication programs, and the second information is keys, i.e., multiple authentication passwords, the master device retrieves all of its authentication passwords based on the UID of the slave device to be authenticated. Using the authentication identifier, i.e., 3A, as an index, the master device retrieves the authentication password corresponding to the current update time (six months) from the authentication passwords of the device to be authenticated, thereby obtaining the target authentication password, i.e., key1. The master device then uses the authentication identifier, i.e., 3A, as a command header, and generates an authentication command based on the random parameter, i.e., H, and the target authentication password, i.e., key1, and sends it to the slave device to be authenticated.
[0080] See also Figure 4 If the first information stored in the slave device to be authenticated is a key, i.e., multiple authentication passwords, and the second information is ciphertext, i.e., multiple encrypted authentication programs, the master device retrieves all of its encrypted authentication programs based on the UID of the slave device to be authenticated. Using the authentication identifier, i.e., 3A, as an index, the master device retrieves the encryption authentication program corresponding to the current update time, i.e., the half-year update time, from among all the encryption authentication programs of the device to be authenticated. This results in the target encryption authentication program, such as Encryption Program 1. The master device then uses the authentication identifier, i.e., 3A, as a command header, and generates an authentication command based on the random parameter, i.e., H, and the target encryption authentication program, i.e., Encryption Program 1, and sends it to the slave device to be authenticated.
[0081] It can be understood that the embodiments of the present invention not only set different authentication information for different slave devices, but also use different authentication parameters, namely, authentication passwords and authentication procedures, for the same slave device at different stages of its life cycle. This ensures that the authentication mechanism of the slave device can dynamically change over its life cycle, thereby improving the slave device's anti-cracking capabilities. Furthermore, the complexity of the authentication instructions is increased, ensuring the security of the authentication process.
[0082] Optionally, with respect to the two aforementioned methods for generating authentication instructions by the master device, embodiments of the present invention correspondingly provide two implementation methods for the slave device to be authenticated to obtain actual results based on the authentication instructions and feed the results back to the master device.
[0083] In step S210A, when the first information is ciphertext and the second information is a key, the slave device to be authenticated obtains the authentication identifier, random parameters and target authentication password according to the received authentication instruction, and obtains the target encryption authentication program from all encryption authentication programs stored in itself according to the authentication identifier.
[0084] In step S210B, when the first information is a key and the second information is a ciphertext, the slave device to be authenticated obtains an authentication identifier, random parameters, and a target encryption authentication program according to the received authentication instruction, and obtains the target authentication password from all authentication passwords stored in itself according to the authentication identifier.
[0085] In step S212, the slave device to be authenticated uses the target authentication password to decrypt the target encrypted authentication program to obtain the target authentication program, and executes the target authentication program based on the random parameters to obtain the actual result and feed it back to the master device.
[0086] In the first implementation, the first information stored in the slave device to be authenticated is ciphertext, i.e., multiple encrypted authentication programs, and the second information is a key, i.e., multiple authentication passwords. For ease of understanding, the example above, where the authentication identifier is 3A, the random parameter is H, and the target authentication password is key1, is used for further explanation.
[0087] See also Figure 3 First, the slave device to be authenticated receives the authentication instruction sent by the master device and obtains the authentication identifier (3A), the random parameter (H), and the target authentication password (key1). The slave device to be authenticated then uses the authentication identifier (3A) as an index to retrieve the corresponding encrypted authentication program from all its stored encrypted authentication programs, obtaining the target encrypted authentication program, such as encrypted program 1. The slave device to be authenticated then decrypts the target encrypted authentication program (encrypted program 1) using the target authentication password (key1), obtaining the target authentication program (program 1), and executes program 1 based on the random parameter (H) to obtain the actual result.
[0088] In a second implementation, the first information stored in the slave device to be authenticated is a key, i.e., multiple authentication passwords, and the second information is a ciphertext, i.e., multiple encryption authentication programs. For ease of understanding, the example above, where the authentication identifier is 3A, the random parameter is H, and the target encryption authentication program is encryption program 1, will be used for further explanation.
[0089] See also Figure 4 First, the slave device to be authenticated receives the authentication command sent by the master device and obtains the authentication identifier (3A), the random parameter (H), and the target encrypted authentication program (Encryption Program 1). The slave device to be authenticated then uses the authentication identifier (3A) as an index to retrieve the corresponding authentication password from all stored authentication passwords, thereby obtaining the target authentication password (e.g., key1). The slave device to be authenticated then uses the target authentication password (key1) to decrypt the target encrypted authentication program (Encryption Program 1), obtaining the target authentication program (Program 1). It then executes Program 1 based on the random parameter (H) to obtain the actual result.
[0090] Optionally, the process of obtaining the actual result by executing program 1 based on the random parameter H on the authenticated slave device can be implemented as follows: For example, program 1 includes multiple functions, such as N. Then, the random parameter H is used as the input data of the first function and the first function is executed. Then, the output data of the nth function is used as the input data of the n+1th function. Each function is executed in sequence until the output data of the last function is obtained, thereby obtaining the actual result. Where n is a positive integer not greater than N.
[0091] This embodiment of the present invention, by including an authentication identifier in the authentication instruction to instruct the slave device to obtain the corresponding authentication password or encrypted authentication program, ensures that the slave device can only obtain specific authentication information under specific conditions, effectively preventing attackers from illegally obtaining sensitive authentication information. Furthermore, by using random parameters, the results of each authentication operation are unpredictable, making it more difficult for attackers to crack the authentication mechanism through repeated attacks.
[0092] Optionally, based on the above implementation of the slave device to be authenticated obtaining the actual result according to the authentication instruction, the embodiment of the present invention provides a possible implementation for step S206, i.e., the process of the master device obtaining the expected result, which can be seen in FIG. Figure 3 and Figure 4 .
[0093] Step S206 - 1 : Determine the authentication identifier and random parameters according to the current update node of the slave device to be authenticated.
[0094] Step S206-2: According to the authentication identifier, a target authentication program corresponding to the current update node is obtained from all authentication programs of the slave device to be authenticated.
[0095] Step S206-3: Execute the target authentication procedure based on the random parameters to obtain the expected result.
[0096] In this embodiment, each slave device has different third information, i.e., plain text, which includes multiple authentication programs. It is understandable that the master device can generate the third information, i.e., multiple authentication programs, of the slave device based on the UID of the slave device.
[0097] For ease of understanding, let's continue with the example of the current update node being the six-month time point when the slave device to be authenticated was shipped. For example, upon detecting that the slave device to be authenticated has been shipped for six months, the master device will retrieve the corresponding authentication identifier, such as 3A, and the random parameter, such as H, based on the six-month current update node. The master device then retrieves all authentication programs for the slave device to be authenticated based on its UID. Using the authentication identifier, 3A, as an index, the master device retrieves the authentication program corresponding to the six-month current update node from the entire list of authentication programs for the slave device to be authenticated, resulting in the target authentication program, such as Program 1.
[0098] Next, the master device executes program 1 based on the random parameter H to obtain the desired result. For example, program 1 includes multiple functions, such as N. The first function is executed using the random parameter H as input. The output of the nth function is then used as input for the n+1th function. Each function is executed sequentially until the output of the last function is obtained, thereby obtaining the desired result. Here, n is a positive integer not greater than N.
[0099] It can be understood that the embodiment of the present invention directly obtains the original authentication program to calculate the expected result through the main device based on the device to be authenticated and its current update node, thereby improving the efficiency of device authentication, and by using random parameters to simplify the verification logic, avoiding unnecessary redundant calculations and saving the computing resources of the device.
[0100] It is understandable that the method of obtaining all authentication passwords and all encryption authentication programs of each slave device is similar. For the sake of brief description, the following uses a slave device as an example to introduce the implementation method of obtaining all authentication passwords and all encryption authentication programs of a slave device. Figure 5 .
[0101] Step S214: obtaining a plurality of preset program generation rules.
[0102] Step S216 : For each program generation rule, a corresponding authentication program is generated based on the device identification of the slave device according to the program generation rule, thereby obtaining multiple authentication programs for the slave device.
[0103] Step S218: Generate multiple authentication passwords for the slave device based on the device identification of the slave device; wherein the multiple authentication passwords for the slave device are matched one-to-one with the multiple authentication programs thereof.
[0104] Step S220 , using each authentication password of the slave device, encrypting the authentication program matched thereto to obtain an encrypted authentication program, thereby obtaining multiple encrypted authentication programs of the slave device.
[0105] In this embodiment, multiple program generation rules can be pre-set based on the total number of update nodes in the slave device. That is, the total number of update nodes in the slave device is the same as the total number of program generation rules. For ease of understanding, the following explanation uses the total number of update nodes as an example. For example, based on the total number of update nodes being M, M program generation rules can be pre-set. Then, according to each program generation rule, a corresponding authentication program is generated based on the slave device's device identifier, i.e., the UID, resulting in M authentication programs for the slave device.
[0106] Next, based on the total number of update nodes, i.e., M, and the UID of the slave device, M authentication passwords for the slave device can be generated. Furthermore, the M authentication passwords of the slave device are matched one-to-one with its M authentication programs. Then, using a preset cryptographic algorithm, each authentication password of the slave device can be used to encrypt the matching authentication program to obtain an encrypted authentication program, thereby obtaining M encrypted authentication programs for the slave device. The cryptographic algorithm can be a symmetric algorithm, such as the DES (Data Encryption Standard) algorithm, the AES (Advanced Encryption Standard) algorithm, etc. The cryptographic algorithm can also be set according to actual conditions, and this is not limited in the embodiments of the present invention.
[0107] It is understood that, because each slave device has a different UID, even if the same M program generation rules are used to generate the authentication program for each slave device, it is ensured that the authentication program for each slave device is different, and therefore the encryption authentication program for each slave device is also different. Furthermore, because each program generation rule is different, even if the UID used for the same slave device is the same, it is ensured that the authentication programs for the same slave device are different, and therefore the encryption authentication programs for the same slave device are also different.
[0108] Furthermore, the burning device can be used to generate all encrypted authentication programs and all authentication passwords for each slave device in accordance with the above implementation method. The master device can also be used to generate all authentication programs, all encrypted authentication programs, and all authentication passwords for each slave device in accordance with the above implementation method.
[0109] In one possible implementation, the burning device uses the entire encrypted authentication program of each slave device as its first information and burns it into the memory of the slave device. In another possible implementation, the burning device uses the entire authentication password of each slave device as its first information and burns it into the memory of the slave device.
[0110] It can be understood that the embodiments of the present invention utilize multiple program generation rules and combine them with the slave device's UID to generate the authentication program, thereby ensuring the diversity and uniqueness of the authentication program. Furthermore, the authentication program is encrypted using an authentication password to protect the security of its content. This improves the slave device's anti-cracking capabilities when the encrypted authentication program is pre-stored on the slave device. Furthermore, when the encrypted authentication program is transmitted from the master device to the slave device, the security of the authentication information during transmission is also improved, thereby enhancing system security.
[0111] Optionally, for the process of generating a corresponding authentication program based on the device identification of the slave device according to the program generation rule in step S216, an embodiment of the present invention provides a possible implementation method.
[0112] Step S216 - 1 : Divide the device identification of the slave device into a plurality of data groups according to the parsing parameters in the program-generated rule; wherein the length of each data group is equal to the parsing parameters.
[0113] Step S216-2, according to the parsing rules in the program generation rules, a corresponding function is generated based on each data group to obtain an authentication program containing the functions corresponding to all data groups; wherein the parsing rules represent the correspondence between the values on each bit in the data group and the function elements, and the function elements include function type, operation type, operation strategy and number of loops.
[0114] In this embodiment, each program generation rule includes parsing parameters and parsing rules, and the parsing parameters and parsing rules of each program generation rule are different. It is understandable that the method of generating the authentication program using each program generation rule is similar. For the sake of simplicity, the following program generation rule is used as an example to illustrate.
[0115] For example, according to the parsing parameter L in the program generation rules, the UID of the slave device is divided into multiple data groups, and the length of each data group is equal to the parsing parameter L. Then, according to the parsing rules in the program generation rules, a corresponding function is generated based on each data group to obtain multiple functions; these multiple functions are then superimposed to obtain the authentication program. Optionally, the UID of the device can be data expanded and then divided into multiple data groups according to the parsing parameter L. This can increase the number of data groups and the number of functions that make up the authentication program, thereby increasing the complexity of the authentication program and ensuring the diversity and uniqueness of the authentication program.
[0116] The above parsing rules represent the correspondence between the values of each bit in a data set and function elements. Function elements include the function type, operation type, operation strategy, and number of loops. The process of generating a function for each data set is similar. For simplicity, the following uses a data set as an example.
[0117] First, according to the parsing rules, the first digit representing the function type, the second digit representing the operation type, the third digit representing the operation strategy, and the fourth digit representing the number of loops in the data set are determined. Then, based on the value of the first digit, a matching target function type is obtained from a plurality of preset function types; and based on the value of the second digit, a matching target operation type is obtained from a plurality of operation types corresponding to the target function type; then, based on the value of the third digit, a matching target operation strategy is obtained from a plurality of operation strategies corresponding to the target operation type; and then, based on the value of the fourth digit, a matching target number of loops is obtained from a plurality of preset numbers of loops. Finally, based on the target function type, target operation type, target operation strategy, and target number of loops, a function corresponding to the data set is generated.
[0118] It can be understood that the embodiments of the present invention divide the device identifier of a device into multiple data groups by parsing parameters. Based on the data groups, functions are generated and superimposed using multiple dimensions, including function type, calculation type, calculation strategy, and number of loops, to ensure that the resulting authentication program has specific computing capabilities and structure. This ensures that the authentication programs of different slave devices and the same slave device are different, thereby supporting the uniqueness of the authentication mechanism of each slave device and the dynamic change of the authentication mechanism of the same slave device.
[0119] Optionally, when the UID of the slave device is binary data, an embodiment of the present invention provides a possible implementation. For example, there are two types of functions, namely a first type and a second type, where the first type indicates that the function operates based on multiple data, and the second type indicates that the function operates based on a single data.
[0120] For example, a first type of function operates on two data, namely, first data and second data, with the first data being a random parameter. Furthermore, the operation types corresponding to the first type of function may include addition, subtraction, modular operation, XOR operation, AND operation, OR operation, etc. Furthermore, the multiple operation strategies corresponding to these operation types are all strategies for selecting the second data. It should be understood that for the first type of function, its operation type can be set according to actual circumstances, as long as the number of bits in the operation result of the multiple data is consistent with the number of bits in the input data.
[0121] The second type of function is to perform operations based on a single data, and its corresponding operation type may include: circular left shift, circular right shift, positive position permutation, reverse position permutation, etc. And the multiple operation strategies corresponding to circular left shift and circular right shift are all strategies for selecting the number of moving bits. And the multiple operation strategies corresponding to positive position permutation and reverse position permutation are all strategies for selecting substitution rules. It should be understood that, for the second type of function, its operation type can be set according to actual conditions, as long as the number of digits of the operation result of the single data is guaranteed to be consistent with the number of digits of the input data.
[0122] For ease of understanding, the embodiment of the present invention takes the parsing parameter L as 8, that is, a data group is an 8-bit binary number as an example, and provides an example of a parsing rule, as shown in Table 1 and Table 2.
[0123] Table 1
[0124]
[0125]
[0126] Table 2
[0127]
[0128]
[0129]
[0130] In Table 2, the eight S-boxes of the DES algorithm can be used as the eight preset permutation rules. It should be understood that the parsing rules shown in Tables 1 and 2 are merely examples, and the function type, operation type, operation strategy, and number of loops can be set according to actual conditions.
[0131] It is understandable that, based on the above-mentioned parsing parameter of 8 and the parsing rule, multiple other program generation rules can be derived. For ease of understanding, the embodiments of the present invention are described with respect to decreasing and increasing parsing parameters.
[0132] For example, when the parsing parameter is reduced to 7, its parsing rules can reduce the number of operation types and the number of bits required to represent the operation types, such as using one bit to represent the operation type; or it can reduce the number of operation strategies and the number of bits required to represent the operation strategies, such as using two bits to represent the operation strategies; it can also reduce the number of loop times and the number of bits required to represent the loop times, such as using one bit to represent the loop times.
[0133] For example, when the parsing parameter increases to 9, the parsing rule can increase the number of operation types and increase the number of bits required to represent the operation type, such as using three bits to represent the operation type; or it can increase the number of operation strategies and increase the number of bits required to represent the operation strategy, such as using four bits to represent the operation strategy; it can also increase the number of loop times and increase the number of bits required to represent the loop times, such as using three bits to represent the loop times.
[0134] It can be understood that based on the above-mentioned program generation rule whose parsing parameter is 8 and its parsing rule, multiple other program generation rules can be obtained by reducing or increasing the parsing parameter to reduce or increase the number of at least one function elements in the operation type, operation strategy and number of loops, as well as the number of bits required to represent the function element.
[0135] Optionally, an embodiment of the present invention further provides a device authentication method for a slave device, wherein the authentication method is implemented by obtaining an actual result based on the second information in the authentication instruction received from the master device and the first information stored in the master device, and feeding it back to the master device, so that the master device obtains an expected result based on the third information of the slave device, compares the expected result with the actual result, and determines that the slave device authentication is successful if the actual result is consistent with the expected result, or determines that the slave device authentication fails if the actual result is inconsistent with the expected result. The authentication instruction is generated by the master device based on the second information of the slave device; when the first information is ciphertext, the second information is a key; when the first information is a key, the second information is ciphertext; and the third information is plaintext.
[0136] It can be understood that in the above-mentioned embodiment of the authentication method applied to the master device, the process of the slave device obtaining the actual result based on the second information in the authentication instruction and the first information stored in itself and feeding it back to the master device has been explained. Its basic principles and the technical effects produced are the same as those in the above-mentioned embodiment. For the sake of brief description, reference may be made to the corresponding content in the above-mentioned embodiment.
[0137] An embodiment of the present invention further provides a system including a master device and a slave device in communication connection, wherein the master device is used to implement the device authentication method disclosed in the embodiment of the present invention, and the slave device is used to implement the device authentication method disclosed in the embodiment of the present invention.
[0138] The present invention also provides an electronic device. Figure 6 , is a block diagram of an electronic device provided by an embodiment of the present invention. The structure of the electronic device can be used to implement the above Figure 6 The electronic device includes a processor 110, a memory 120, and a communication module 130. Each component is electrically connected to each other directly or indirectly to achieve data transmission or interaction. For example, these components can be electrically connected to each other via one or more communication buses or signal lines.
[0139] The processor 110 is used to read / write data or programs stored in the memory 120 and execute corresponding functions. It can be a general-purpose processor, including a CPU (Central Processing Unit), an NP (Network Processor), etc.; it can also be a DSP digital signal processor, an ASIC application-specific integrated circuit, an FPGA off-the-shelf programmable gate array or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0140] The memory 120 is used to store programs or data. The memory 120 can be RAM (Random Access Memory), ROM (Read Only Memory), PROM (Programmable Read-Only Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electric Erasable Programmable Read-Only Memory), etc.
[0141] The communication module 130 is used to communicate signaling or data with other devices.
[0142] It is understandable that Figure 6 The structure shown is only a schematic diagram of the structure of the electronic device. The electronic device may also include Figure 6 More or fewer components than shown, or with Figure 6 Different configurations shown. Figure 6 Each component shown in the figure can be implemented by hardware, software or a combination thereof.
[0143] The memory in the electronic device provided by the embodiment of the present invention stores a computer program, and when the processor executes the computer program, the device authentication method disclosed in the embodiment of the present invention is implemented.
[0144] An embodiment of the present invention further provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the device authentication method disclosed in the embodiment of the present invention is implemented.
[0145] In the several embodiments provided in this application, it should be understood that the disclosed methods can also be implemented in other ways. The embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible implementation architectures, functions and operations of the methods and computer program products according to multiple embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a portion of code, and the module, program segment or a portion of code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0146] In addition, the functional modules in the various embodiments of the present invention may be integrated together to form an independent part, or each module may exist independently, or two or more modules may be integrated to form an independent part.
[0147] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0148] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
Claims
1. A device authentication method, characterized in that: Applied to a master device, the master device is communicatively connected to at least one slave device, each slave device stores different first information, and each slave device has different second information and third information, the method comprising: Generate an authentication instruction based on second information of the slave device to be authenticated; wherein, when the first information is ciphertext, the second information is a key; when the first information is a key, the second information is ciphertext; Sending the authentication instruction to the slave device to be authenticated, so that the slave device to be authenticated obtains an actual result based on the second information in the authentication instruction and the first information stored in the slave device, and feeds the result back to the master device; Obtaining an expected result based on third information of the slave device to be authenticated, and comparing the expected result with the actual result; wherein the third information is plain text; If the actual result is consistent with the expected result, it is determined that the authentication of the slave device to be authenticated is successful; otherwise, if the actual result is inconsistent with the expected result, it is determined that the authentication of the slave device to be authenticated is failed.
2. The device authentication method according to claim 1, wherein: The ciphertext includes a plurality of encryption authentication programs, and the key includes a plurality of authentication passwords; In a case where the first information is ciphertext and the second information is a key, the step of generating an authentication instruction based on the second information of the slave device to be authenticated includes: Determining an authentication identifier and a random parameter according to a current update node of the slave device to be authenticated; According to the authentication identifier, a target authentication password corresponding to the current update node is obtained from all authentication passwords of the slave device to be authenticated, and an authentication instruction is generated based on the authentication identifier, the random parameter and the target authentication password.
3. The device authentication method according to claim 1, wherein: The ciphertext includes a plurality of encryption authentication programs, and the key includes a plurality of authentication passwords; In a case where the first information is a key and the second information is ciphertext, the step of generating an authentication instruction based on the second information of the slave device to be authenticated includes: Determining an authentication identifier and a random parameter according to a current update node of the slave device to be authenticated; According to the authentication identifier, a target encryption authentication program corresponding to the current update node is obtained from all encryption authentication programs of the slave device to be authenticated, and an authentication instruction is generated based on the authentication identifier, the random parameter and the target encryption authentication program.
4. The device authentication method according to claim 2, wherein: In the case where the first information is ciphertext and the second information is a key, the slave device to be authenticated obtains an actual result based on the second information in the authentication instruction and the first information stored in the slave device and feeds the result back to the master device in the following manner: The slave device to be authenticated obtains an authentication identifier, a random parameter, and a target authentication password according to the received authentication instruction, and obtains a target encryption authentication program from all encryption authentication programs stored in the slave device according to the authentication identifier; The slave device to be authenticated uses the target authentication password to decrypt the target encrypted authentication program to obtain a target authentication program, and executes the target authentication program based on the random parameters to obtain the actual result and feed it back to the master device.
5. The device authentication method according to claim 3, wherein: In the case where the first information is a key and the second information is ciphertext, the slave device to be authenticated obtains an actual result based on the second information in the authentication instruction and the first information stored in the slave device and feeds the result back to the master device in the following manner: The slave device to be authenticated obtains an authentication identifier, a random parameter, and a target encryption authentication program according to the received authentication instruction, and obtains a target authentication password from all authentication passwords stored in the slave device according to the authentication identifier; The slave device to be authenticated uses the target authentication password to decrypt the target encrypted authentication program to obtain a target authentication program, and executes the target authentication program based on the random parameters to obtain the actual result and feed it back to the master device.
6. The device authentication method according to claim 1, wherein: The plaintext includes multiple authentication procedures; The step of obtaining an expected result based on the third information of the slave device to be authenticated includes: Determining an authentication identifier and a random parameter according to a current update node of the slave device to be authenticated; According to the authentication identifier, obtaining a target authentication program corresponding to the current update node from all authentication programs of the slave device to be authenticated; The target authentication procedure is performed based on the random parameters to obtain the expected result.
7. The device authentication method according to claim 2 or 3, characterized in that: All authentication passwords and all encrypted authentication procedures of any of the slave devices are obtained in the following manner: Obtain multiple preset program generation rules; For each program generation rule, generating a corresponding authentication program based on the device identification of the slave device according to the program generation rule, thereby obtaining multiple authentication programs for the slave device; generating a plurality of authentication passwords for the slave device based on the device identification of the slave device; wherein the plurality of authentication passwords for the slave device are matched one-to-one with the plurality of authentication programs thereof; By utilizing each authentication password of the slave device, the authentication program matched thereto is encrypted to obtain an encrypted authentication program, thereby obtaining a plurality of encrypted authentication programs of the slave device.
8. The device authentication method according to claim 7, characterized in that: The step of generating a corresponding authentication program according to the program generation rule and the device identification of the slave device includes: Dividing the device identification of the slave device into a plurality of data groups according to the parsing parameters in the program generation rule; wherein the length of each data group is equal to the parsing parameters; According to the parsing rules in the program generation rules, a corresponding function is generated based on each data group, and an authentication program containing the functions corresponding to all data groups is obtained; wherein the parsing rules represent the correspondence between the values on each bit in the data group and the function elements, and the function elements include function type, operation type, operation strategy and number of loops.
9. The device authentication method according to claim 8, characterized in that: In the case where the device identifier of the slave device is a binary number, the function type includes a first type and a second type, the first type indicating that the function operates based on multiple data, and the second type indicating that the function operates based on a single data.
10. A device authentication method, characterized in that: Applied to a slave device, the slave device being communicatively connected to a master device, the slave device storing first information, and the master device storing second information and third information of the slave device, the method comprising: obtaining an actual result based on the second information in the authentication instruction received from the master device and the first information stored in the master device, and feeding the result back to the master device, so that the master device obtains an expected result based on the third information of the slave device, and compares the expected result with the actual result, and determines that the authentication of the slave device is successful if the actual result is consistent with the expected result, or determines that the authentication of the slave device is unsuccessful if the actual result is inconsistent with the expected result; Among them, the authentication instruction is generated by the master device based on the second information of the slave device; when the first information is ciphertext, the second information is a key; when the first information is a key, the second information is ciphertext; and the third information is plaintext.
11. A system, characterized in that: The invention comprises a master device and a slave device in communication connection, wherein the master device is used to implement the device authentication method according to any one of claims 1 to 9, and the slave device is used to implement the device authentication method according to claim 10.
12. An electronic device, characterized in that: The device comprises a processor and a memory, wherein the memory stores a computer program, and when the processor executes the computer program, the device authentication method according to any one of claims 1 to 9 and / or the device authentication method according to claim 10 is implemented.
13. A storage medium, characterized in that: The storage medium stores a computer program, which, when executed by a processor, implements the device authentication method according to any one of claims 1 to 9 and / or the device authentication method according to claim 10.
Citation Information
Patent Citations
Electronic no-parking charging system, device, authentication method and trading method
CN104077814A
Equipment authentication method and device, computer equipment and storage medium
CN112115461A
Security authentication method and device, electronic equipment and storage medium
CN118199888A
Multi-factor authentication method and device, equipment and storage medium
CN119520127A
Group message encryption method and apparatus, device and storage medium
WO2023160420A1