Device authentication method and apparatus, storage medium, and electronic device
By receiving and decrypting the identification code of the external device, obtaining its hardware information set and comparing it with the pre-stored information set, the problem of low data security in the PCIe device anti-counterfeiting authentication method is solved, accurate identification and secure access of the external device are achieved, and the overall security of the server is improved.
Patent Information
- Application Number
- CN202510982932.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-16
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-07-16
AI Technical Summary
In the existing technology, the anti-counterfeiting authentication method for PCIe devices has the problem of low data security. Malicious tampering of device information can easily bypass software detection, causing the counterfeit device to appear to be the same as the genuine one in the software, reducing the data security of the server system.
By receiving the first identification code and the second identification code sent by the external device, determining the first key based on the second identification code, and using the first key to decrypt the first identification code, obtaining the hardware information set of the target device, comparing the first hardware information set with the second hardware information set, and determining that the external device has passed the authentication if they are consistent.
The server's anti-counterfeiting recognition accuracy for external devices has been improved, ensuring that only legitimate PCIe devices can be connected, thereby enhancing the security and stability of the server system.
Smart Images

Figure CN120509025B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of device verification, and in particular to a device authentication method and device, a storage medium and an electronic device. BACKGROUND
[0002] Servers connect various peripheral Peripheral Component Interconnect Express (PCIe) devices, such as GPU acceleration cards, network adapters, storage expansion cards, etc., through PCIe interfaces to enhance data processing and communication capabilities. However, with the globalization and complexity of the PCIe device supply chain, counterfeit products have flooded the market, posing a serious threat to server security and business continuity. Therefore, a PCIe device anti-counterfeiting technology is needed to ensure the overall security of the server system.
[0003] In related technologies, the server reads the serial number, firmware version, etc. of the PCIe device through the driver program or operating system to determine the authenticity of the device. However, this software detection method has significant vulnerabilities. Malicious tampering with device information, such as flashing counterfeit firmware, can easily bypass the software detection mechanism, causing counterfeit devices to appear identical to genuine products in the eyes of software. This reduces the reliability and accuracy of anti-counterfeiting, and threatens the data security of the server system. In other words, the device anti-counterfeiting authentication method in the related art has the problem of low data security. SUMMARY
[0004] The present application provides a device authentication method and device, a storage medium and an electronic device to at least solve the problem of low data security of the device anti-counterfeiting authentication method in the related art.
[0005] The present application provides a device authentication method for a server, comprising: receiving a first identification code and a second identification code sent by an external device, wherein the first identification code is used to indicate the hardware information of the target device, and the second identification code is used to indicate the target device;
[0006] Based on the second identification code, a first key is determined, and the first identification code is decrypted using the first key to obtain a first hardware information set of the target device, wherein the first hardware information set contains at least one hardware information of the target device;
[0007] The first hardware information set and the second hardware information set are compared, and in the case where the first hardware information set and the second hardware information set are consistent, the external device is determined to be authenticated, wherein the second hardware information set contains at least one hardware information of the external device.
[0008] The application further provides another device authentication method for an external device, comprising: sending a first identification code and a second identification code to a server, wherein the first identification code is used to indicate hardware information of a target device, and the second identification code is used to indicate the target device and to determine a first key, the first key is used to decrypt the first identification code to obtain a first hardware information set of the target device, the first hardware information set is used to contain at least one hardware information of the target device and is used to be compared with a second hardware information set to determine whether the external device passes authentication, and the second hardware information set contains at least one hardware information of the external device.
[0009] The application further provides a device authentication apparatus for a server, comprising: an identification code receiving module, configured to receive a first identification code and a second identification code sent by an external device, wherein the first identification code is used to indicate hardware information of a target device, and the second identification code is used to indicate the target device;
[0010] a decryption module, configured to determine a first key based on the second identification code, and decrypt the first identification code by using the first key to obtain a first hardware information set of the target device, wherein the first hardware information set contains at least one hardware information of the target device;
[0011] a first authentication module, configured to compare the first hardware information set and a second hardware information set, and determine that the external device passes authentication in a case where the first hardware information set and the second hardware information set are consistent, wherein the second hardware information set contains at least one hardware information of the external device.
[0012] The application further provides another device authentication apparatus for an external device, comprising: an identification code sending module, configured to send a first identification code and a second identification code to a server, wherein the first identification code is used to indicate hardware information of a target device, and the second identification code is used to indicate the target device and to determine a first key, the first key is used to decrypt the first identification code to obtain a first hardware information set of the target device, the first hardware information set is used to contain at least one hardware information of the target device and is used to be compared with a second hardware information set to determine whether the external device passes authentication, and the second hardware information set contains at least one hardware information of the external device.
[0013] The application further provides an electronic device, comprising: a memory, configured to store a computer program; and a processor, configured to execute the computer program to implement steps of any of the above device authentication methods.
[0014] The application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement steps of any of the above device authentication methods.
[0015] The application further provides a computer program product comprising a computer program which, when executed by a processor, implements the steps of any of the above device authentication methods.
[0016] According to the application, the first identification code and the second identification code sent by the external device are received in the server; the first key is determined based on the second identification code, and the first hardware information set of the target device is obtained by decrypting the first identification code using the first key, the first hardware information set containing at least one hardware information of the target device; the first hardware information set and the second hardware information set are compared, and in the case where the first hardware information set and the second hardware information set are consistent, it is determined that the external device passes the authentication, the second hardware information set containing at least one hardware information of the external device. In this way, in the case where the server starts or connects the external device, the first identification code and the second identification code sent by the external device can be obtained, and the first identification code and the second identification code both indicate the information of the target device. The first key corresponding to the target device can be determined through the second identification code, and then the first hardware information set of the target device is obtained by decrypting the first identification code using the first key. The first hardware information set is compared with the second hardware information set of the external device itself, and in the case where they are consistent, it is determined that the external device currently connected by the server is the target device expected to be connected, and it is determined that it passes the authentication. Therefore, the technical problem of low data security in the device anti-counterfeiting authentication method in the related art can be solved, and the technical effect of improving the anti-counterfeiting identification accuracy of the server for the external device is achieved. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the embodiments of the application, the drawings needed in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0018] Figure 1 is a schematic diagram of a hardware environment of an optional device authentication method according to an embodiment of the application;
[0019] Figure 2 is a flowchart of an optional device authentication method according to an embodiment of the application;
[0020] Figure 3 is a schematic diagram of an optional device authentication method according to an embodiment of the application;
[0021] Figure 4 is a schematic diagram of another optional device authentication method according to an embodiment of the application;
[0022] Figure 5is a schematic diagram of another optional device authentication method according to an embodiment of the present application;
[0023] Figure 6 is a structural block diagram of an optional device authentication apparatus according to an embodiment of the present application. DETAILED DESCRIPTION
[0024] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, any other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0025] It should be noted that, in the description of the present application, the terms “comprise”, “contain” or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, a method, an article or an apparatus comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or apparatus. The terms “first”, “second” and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence.
[0026] In order for those skilled in the art to better understand the technical solutions of the present application, the present application will be further described in detail below with reference to the drawings and specific embodiments.
[0027] According to an aspect of an embodiment of the present application, a device authentication method is provided. As an optional implementation, the above-mentioned device authentication method can be applied to, but is not limited to, a device authentication system in a hardware environment as shown in Figure 1 . The server in the device authentication system can include, but is not limited to, one or more (only one is shown in Figure 1 ) central processing units (CPU) 11, a root complex 12, a memory 13 for storing data, and a switch 14. Those skilled in the art can understand that the structure shown in Figure 1 is only a schematic, which does not limit the structure of the above-mentioned server side. For example, the server side can include more or fewer components than those shown in Figure 1 , or have a structure different from that shown in Figure 1The host can be connected to one or more PCIe devices (PCI Express Endpoint) 21 through a Peripheral Component Interconnect Express (PCIe) interface, or to a PCIe bridge (PCI Express-PCI Bridge) 22. Those skilled in the art can understand that, Figure 1 The structure and connection shown are only schematic, and do not limit the structure between the host and the PCIe device described above.
[0028] The central processing unit (CPU) 11 can be responsible for executing program instructions and processing data. In the PCIe architecture, the CPU is usually connected to a root complex. The CPU is connected to the root complex through a high-speed interconnection (such as a cache-coherent interconnection or a dedicated PCIe channel) to achieve fast transmission of data and instructions.
[0029] The root complex (ROOT Complex) 12 is the top layer of the PCIe bus hierarchy, which serves as an interface between the CPU and the PCIe bus. The root complex can include multiple components, such as a processor interface, a DRAM interface, an input / output (I / O) controller, etc. In some systems, the root complex can be integrated into the CPU chip, or placed adjacent to the CPU chip as a separate chip. The root complex is responsible for managing PCIe bus transactions initiated from the CPU, including memory access, device communication, etc. In a PCIe system, data flows through the root complex, through a PCIe switch or other bridge device, to the target PCIe device.
[0030] The memory (Memory) 13 is a hardware component for storing data and programs, which can be a random access memory (RAM), a read-only memory (ROM), a static random access memory (SRAM), etc.
[0031] Switch 14 can be used to connect multiple devices and forward data packets. In the PCIe architecture, Switch is a PCIe switch, which allows multiple PCIe devices to be connected to a PCIe port, expanding the connection capabilities of the system. The PCIe switch can connect multiple PCIe endpoint devices or Root Complex, support more complex system topology, and manage the routing and forwarding of data packets between devices.
[0032] PCIe device (PCI Express Endpoint) 21 refers to a device connected to the PCIe bus. PCIe Endpoint often exists in the form of a board card, such as a graphics card, a solid state drive (SSD), a network card, etc. They communicate with other parts of the system through the PCIe interface. The PCIe device can receive and send data, and it can be the initiator or terminator of bus operations.
[0033] PCIe bridge (PCI Express-PCI Bridge) 22 can allow communication between the PCIe interface and the old PCI (Peripheral Component Interconnect) or PCI-X (PCI eXtended) interface. It can enable the use of old PCIe devices in new PCIe systems, while also allowing old PCI systems to connect to PCIe devices. Support for compatibility between PCI Express and PCI / PCI-X allows the use of PCI devices in PCIe systems.
[0034] In an optional implementation, in the case of server startup or new connection of a PCIe device, the server can obtain a first identification code and a second identification code sent by the external device (PCIe device), both of which indicate information of the target device. The first key corresponding to the target device can be determined through the second identification code, and then the first identification code is decrypted through the first key to obtain the first hardware information set of the target device. The first hardware information set is compared with the second hardware information set of the external device itself, and in the case of consistency, it can be determined that the external device currently connected to the server is the target device expected to be connected, and it is determined to be authenticated.
[0035] Embodiments of the present application provide a device authentication method for a server, Figure 2 is a flowchart of an optional device authentication method according to an embodiment of the present application; as Figure 2 shown, the device authentication method comprises:
[0036] Step S202, receiving a first identification code and a second identification code sent by the external device, wherein the first identification code is used to indicate the hardware information of the target device, and the second identification code is used to indicate the target device;
[0037] It should be noted that the server as a one-side execution subject is responsible for managing and monitoring the connected PCIe device, and performs the anti-fake authentication process through the baseboard management controller (BMC). The external device refers to the PCIe device, which is the external hardware communicated by the server through the PCIe bus. The target device can be a genuine PCIe device expected to be connected by the server.
[0038] The first identification code refers to the device anti-fake key (DAK), which contains detailed hardware information of the device, such as device model, production batch, chip set information, etc., and is bound with the device hardware in the device production stage.
[0039] The second identification code is encrypted information generated based on hardware features, which is used to represent hardware information unique to the target device, such as the encrypted result of the combination of the MAC address and the chip serial number. It is the hardware feature code of the device, which is formed after encryption, and is used to indicate the physical properties of the device, ensuring that each device has a unique hardware identifier.
[0040] In an optional embodiment, when the server starts or performs dynamic authentication in a preset detection period, the baseboard management controller (BMC) of the server receives the second identification code sent by the external PCIe device. This identification code is generated by the device based on its hardware features, and is formed by processing through an encryption algorithm (such as SHA-256), and is used to indicate the hardware information of the device, such as the tamper-proof combination of the MAC address and the chip serial number. It reflects the physical hardware properties of the device and can be regarded as the "fingerprint" of the device. In addition to the second identification code, the BMC also receives the device anti-fake key (DAK), which is generated by the device during production and is bound with the detailed hardware information of the device (such as device model, production batch, chip set information, etc.). This key is stored in the OTP memory of the device and cannot be tampered with. It not only reflects the device hardware configuration parameters, but also establishes a unique and secure association with the device through encryption means. The generation process of the specific identification code will be described later, and will not be described here.
[0041] Step S204, determining a first key based on the second identification code, and decrypting the first identification code using the first key to obtain a first hardware information set of the target device, wherein the first hardware information set contains at least one hardware information of the target device;
[0042] It should be noted that the first key refers to the decryption public key stored in the server BMC, which corresponds to the private key of the encrypted information in the second identification code, and is used to decrypt the first identification code (i.e., the device anti-counterfeit key DAK) to extract the original hardware information set of the device.
[0043] The first hardware information set can be the decrypted information set, which contains multiple hardware features and configuration information of the target PCIe device, such as device model, production batch, chipset information, and hardware configuration parameters, for comparison and verification of the legality of the device.
[0044] In an optional embodiment, the specific operation process of the BMC for authentication after receiving the response of the target PCIe device. The BMC first needs to extract the first identification code (i.e., the encrypted device anti-counterfeit key DAK) from the response, and then use the pre-stored first key (i.e., the decryption public key of the device) to decrypt the first identification code, thereby recovering the original hardware information set of the target PCIe device contained in the first identification code. This hardware information set covers multiple hardware features and configuration data of the device, and is an important basis for verifying the authenticity of the device.
[0045] It should be noted that the first key can be a public key using the RSA asymmetric encryption algorithm, which can have a corresponding private key. Its encryption and decryption use different keys. The sender can use the public key of the receiver for encryption, while the receiver can use its own private key for decryption. This mechanism ensures that the information remains confidential even when transmitted over an insecure channel, because without the private key, no one can decrypt the message, and the private key is stored secretly in the receiver and does not spread over the network.
[0046] Step S206, comparing the first hardware information set and the second hardware information set, and in the case that the first hardware information set and the second hardware information set are consistent, determining that the external device passes the authentication, wherein the second hardware information set contains at least one hardware information of the external device.
[0047] It should be noted that the second hardware information set is a set of information obtained by the server in advance, which contains hardware information corresponding to the first hardware information set, and is used to compare with the first hardware information set in the authentication process to verify the identity of the device. Consistency means that the first hardware information set and the second hardware information set completely match in all corresponding fields without any difference, which means that the information of the device completely matches the information expected by the server, proving the legality and authenticity of the device.
[0048] In optional embodiments, the server can obtain the second set of hardware information of the peripheral device at any time period after the server is started, which is the process of reading the hardware information of the peripheral device, and there is no specific requirement for the timing thereof. Specifically, during the server startup process, the BMC establishes a communication connection with each PCIe device (peripheral device) through the PCIe bus. The PCIe bus is a high-speed serial computer expansion bus standard used for data transmission and communication between devices. The BMC sends a command packet to the PCIe device to read the hardware information. These commands are based on the management commands in the PCIe specification and are designed to obtain specific hardware attributes of the device.
[0049] Each PCIe device has a Configuration Space, which contains information about the working status, capabilities, and configuration of the device. This includes device model, production batch, chipset information, and hardware configuration parameters. The BMC accesses the Configuration Space of the device through the PCIe interface, reads the specified register region or configuration space entry, and thus obtains the hardware information of the device. This information is usually written by the device manufacturer during production and remains unchanged during the device's life cycle. After the BMC receives the hardware information returned by the PCIe device, it parses and extracts it. This may involve understanding the data format of different registers or configuration space entries, and how to extract useful information such as device model, production batch, chipset information, and hardware configuration parameters from these data.
[0050] In optional embodiments, after receiving and decrypting the first and second identification codes of the peripheral PCIe device, the server BMC performs a key authentication step. The BMC compares the decrypted first set of hardware information with the second set of hardware information stored in its own database in detail. If all hardware attributes remain consistent, it indicates that the PCIe device is indeed consistent with the expected legitimate device, and the server BMC determines that the PCIe device has passed the authentication and can be used without worrying about the authenticity and security of the device.
[0051] The BMC extracts various hardware attribute information such as device model, production batch, chipset information, and hardware configuration parameters from the first set of hardware information obtained from the PCIe device. Subsequently, the BMC compares these information one by one with the second set of hardware information stored in its own database to check for complete consistency. The comparison here includes but is not limited to string matching of device model, numerical comparison of production batch, and binary data comparison of chipset information and other hardware parameters. If no discrepancies are found between the first set of hardware information and the second set of hardware information in all corresponding fields, the BMC will recognize that the external PCIe device has passed the authentication and is a legitimate and valid device. This step ensures that only PCIe devices that truly meet the expectations can access the server, greatly improving the security and stability of the server.
[0052] It should be noted that after the PCIe device (external device) passes the anti-counterfeiting authentication of the BMC, the BMC records the information confirming that the device is genuine. This information includes the status flag of the device passing the authentication, and may also include detailed information of the device for subsequent management and monitoring. The log file can be a file on the server for recording system activities, events and states, which can track the authentication history of the device, including the timestamp of successful authentication and the device identification code, which is helpful for subsequent audit and troubleshooting. The security log can be a special log file type, which is specifically used to record system security-related events and abnormal situations such as device authentication failure, suspected device tampering, etc., to facilitate administrators to quickly locate security problems.
[0053] It should be noted that when the BMC completes the interactive authentication with the PCIe device and determines that the device information is correct, it will temporarily store the status of the device passing the authentication and other related information in the high-speed memory of the server, to facilitate the system to call and manage immediately. In addition to recording in the memory, the BMC also permanently stores the timestamp of the device passing the authentication and the device identification code in the log file, providing a basis for long-term audit and troubleshooting.
[0054] If any hardware field (such as device model, production batch, etc.) is found to be inconsistent with the expected value during the comparison of device information, the BMC will immediately consider that the PCIe device may be a counterfeit product or has been tampered with, and enter an abnormal handling mode. Once the BMC detects an abnormal situation, it will activate the alarm and recording system, write the key information such as the abnormal state of the device, the device identification code and the detection time into the security log to form a chain of evidence, facilitating subsequent investigation and evidence collection. In order to ensure that the system administrator can know the security alarm in time, the BMC will actively send alarm information to the administrator through the preset communication means (such as SMS, email, etc.), including the specific situation of the device exception and the suggested countermeasures, to promote the rapid response and handling of the problem.
[0055] Embodiment 1
[0056] Consider a scenario where a server is starting up, and it is equipped with a BMC module for managing the authentication of external PCIe devices. Suppose the server attempts to authenticate a network adapter PCIe card with a device identification code PCIeCard_12345.
[0057] Successful authentication case: The status of the network adapter passing the authentication is stored in the server's memory. The time of successful authentication (e.g., 2023-04-01 10:30:00) and the device identification code PCIeCard_12345 are recorded in the log file for subsequent auditing and management.
[0058] Failed authentication case: The BMC decrypts and compares the hardware information, but finds that the production batch field 202212 does not match the expected 202304, which means that the device may be tampered with or a counterfeit product. The BMC triggers an exception handling, records the exception information in the security log, including the device identification code PCIeCard_67890, the time of authentication failure (e.g., 2023-04-01 10:35:00), and the specific exception type (production batch mismatch). Through the preset alarm mechanism, such as sending an urgent SMS and email to the system administrator, the administrator is notified of the authentication failure of PCIeCard_67890, which may pose a security risk.
[0059] According to the application, the first identification code and the second identification code sent by the external device are received in the server; the first key is determined based on the second identification code, and the first identification code is decrypted by using the first key to obtain a first hardware information set of the target device, the first hardware information set containing at least one hardware information of the target device; the first hardware information set and the second hardware information set are compared, and in the case that the first hardware information set and the second hardware information set are consistent, it is determined that the external device passes the authentication, and the second hardware information set contains at least one hardware information of the external device. Through the above-mentioned manner, in the case that the server starts or connects the external device, the first identification code and the second identification code sent by the external device can be obtained, and the first identification code and the second identification code both indicate the information of the target device. The first key corresponding to the target device can be determined through the second identification code, and then the first identification code is decrypted by using the first key to obtain the first hardware information set of the target device. And the first hardware information set is compared with the second hardware information set of the external device itself, and in the case that they are consistent, it can be determined that the external device currently connected by the server is the target device expected to be connected, and it is determined that it passes the authentication. Therefore, the technical problem that the device anti-counterfeiting authentication method in the related art has low data security can be solved, and the technical effect of improving the anti-counterfeiting identification accuracy of the server for the external device is achieved.
[0060] Embodiments of the present application also provide a device authentication method for an external device, the device authentication method comprising: sending a first identification code and a second identification code to a server, wherein the first identification code is used to indicate hardware information of a target device, and the second identification code is used to indicate the target device and to determine a first key, the first key being used to decrypt the first identification code to obtain a first hardware information set of the target device, the first hardware information set being used to contain at least one hardware information of the target device and to be compared with a second hardware information set to determine whether the external device is authenticated, and the second hardware information set containing at least one hardware information of the external device.
[0061] It should be noted that the external device refers to a hardware device connected to the server through a PCIe interface, such as a graphics card, a storage card, a network adapter, etc.
[0062] In an optional implementation, when the server starts or the BMC performs dynamic authentication, the external PCIe device sends its first identification code and second identification code to the server through the PCIe bus. The external device can read the first identification code and the second identification code from the memory in the device to send to the server. The first identification code and the second identification code can be stored in the encrypted storage ROM.
[0063] It should be noted that ensuring the secure storage of the device anti-counterfeit key (first identification code) is the key to the entire anti-counterfeit system. This involves the use of a special type of memory, a read-only memory (ROM) with encryption storage function, to prevent the key from being illegally read and tampered with during the device life cycle.
[0064] Read-Only Memory (ROM) is a type of non-volatile memory, i.e., the data stored in the ROM remains unchanged after the power is turned off. Typically, ROM is used to store firmware, boot code, and other critical, non-changeable data. In the PCIe device of the server, ROM is used to store the device anti-counterfeit key and other non-tamperable hardware information.
[0065] Encryption storage refers to the application of encryption algorithms when storing data, encrypting the data, and then storing the encrypted data in the ROM. In this way, even if the ROM is physically accessed, the data stored therein is difficult to be directly interpreted. When the anti-counterfeit key stored in the ROM needs to be read, the correct decryption key must be used to restore the original content of the data. This mechanism provides an additional layer of security, ensuring that the anti-counterfeit key stored in the ROM is not easily read and used even if it is accessed at the physical level.
[0066] During the production phase of a PCIe device, the device anti-counterfeit key is burned into an on-board encrypted storage ROM. "Burn" here refers to the process of writing data into a ROM, which is different from ordinary data writing in that it is usually one-time, meaning that once the data is written, it cannot be changed or deleted through conventional means, further enhancing the security of the key. The encrypted storage ROM not only employs encryption storage technology, but also may integrate hardware-level tamper-proofing features. For example, the ROM may have a write protection mechanism that, once data is burned, the ROM will be locked to prevent any subsequent write or modification attempts, thereby avoiding tampering with the key. In addition, the ROM may also include tamper detection functions, if the physical package of the ROM is broken or the data is attempted to be illegally modified, the ROM will automatically clear the stored data or enter a locked state, further protecting the security of the key.
[0067] By using encrypted storage technology in the on-board ROM of the PCIe device, combined with hardware-level tamper-proofing features, the security of the device anti-counterfeit key can be effectively protected. Even if the ROM is physically acquired, it is very difficult for attackers to directly read or tamper with the key, as it requires the correct decryption key and overcoming the ROM's hardware protection mechanism. Therefore, this storage mechanism provides a strong security barrier for server PCIe devices, ensuring the integrity and security of the anti-counterfeit key throughout the entire life cycle of the device from production to deployment.
[0068] In an optional implementation, before receiving the first identification code and the second identification code sent by the external device, the method further includes: sending a first authentication request instruction to the external device, wherein the first authentication request instruction contains the identity information of the server, and the identity information is used to indicate the server and to confirm whether the server is included in a server list in which the external device can be connected; and receiving the first identification code and the second identification code sent by the external device.
[0069] It should be noted that the first authentication request instruction can be an instruction sent by the server BMC to the external PCIe device to start the authentication process, which contains the identity information of the server, such as the BMC public key of the server, the identity, etc., for the device to verify the identity of the server.
[0070] When the server needs to verify the connected PCIe device, the BMC will send a specific instruction to the device, which contains the identity information of the server BMC, the purpose is to let the PCIe device confirm whether the identity of the current server is found in the trusted server list, so as to decide whether to respond to the authentication request. After verifying that the identity of the server is correct, the PCIe device will respond to the authentication request instruction of the BMC and send back the first identification code and the second identification code.
[0071] In an optional embodiment, the server's BMC starts the authentication process of the PCIe device when the server starts or in a preset detection period, or when a specific event trigger is detected. First, the BMC sends a first authentication request instruction to all connected PCIe devices, which contains not only the command to request authentication, but also the identity information of the server BMC. After receiving the instruction, the PCIe device first verifies the identity of the BMC. If the verification is passed, it indicates that the server is in the trusted server list of the device, and the PCIe device will respond to the authentication request and send the first identification code and the second identification code.
[0072] In an optional embodiment, before sending the first identification code and the second identification code to the server, it includes: receiving the first authentication request instruction sent by the server, wherein the first authentication request instruction contains the identity information of the server, and the identity information is used to indicate the server; querying a preset information set, and if the preset information set contains the identity information, sending the first identification code and the second identification code to the server, wherein the preset information set is used to indicate a server list to which the external device can be connected.
[0073] The identity information refers to the digital certificate information of the server BMC, including the public key and identifier of the server, which is used to indicate the identity of the server and ensure that the PCIe device can verify the legality of the server before responding to the authentication request. The preset information set can be a list containing the server identity information stored in the PCIe device in advance, which is used to limit the range of servers that the device can connect to. Only the servers in the list can be authenticated and allowed to connect by the device.
[0074] The PCIe device needs to verify the identity of the server before sending the anti-fake information. The PCIe device first receives the first authentication request instruction containing the identity information sent by the server through the BMC. Then, the device needs to query the preset information set stored in its internal storage to confirm whether the identity information of the server is in the preset trusted server list. Only after confirming the legality of the server identity, the PCIe device will send the first identification code and the second identification code to the server.
[0075] Embodiment 2:
[0076] Suppose a network adapter PCIe device stores a preset information set containing the digital certificate information of the server BMC of A company in its OTP memory. When the server starts, the BMC sends a first authentication request instruction to all connected PCIe devices through the PCIe bus, which contains the digital certificate of the BMC (including the public key and the BMC identifier).
[0077] The network adapter PCIe device receives the first authentication request instruction, first uses its built-in certificate verification module to check whether the digital certificate of the BMC is valid, and whether the BMC identifier in the certificate appears in its preset information set. If the network adapter PCIe device confirms that the identity information of the server BMC matches the record in the preset information set, it will generate a second identification code by encrypting the combination of the MAC address and the chip serial number of the device, and send the first identification code containing the detailed hardware information and configuration parameters of the device to the server BMC.
[0078] After the BMC receives the response of the network adapter PCIe device, it uses the decryption public key stored locally on the server to decrypt the first identification code, obtains the original hardware information set of the device, and then compares this information set with the actual hardware information of the network adapter. If the two hardware information sets are completely consistent, the BMC determines that the device has passed the authentication, and the device can safely access the server and continue subsequent data transmission and communication operations.
[0079] In an optional embodiment, when the server is powered on, the BMC starts the initialization operation to ensure that it can normally perform device management and monitoring functions, which includes loading necessary drivers to support PCIe device identification and control, and initializing the communication interface to prepare for subsequent device authentication and data exchange.
[0080] After initialization, the BMC starts the device detection program and sends an anti-counterfeit authentication request instruction (first authentication request instruction) to all connected PCIe devices through the PCIe bus. This instruction carries an authentication identifier (such as a hexadecimal string) and a digital certificate of the BMC, which contains the identity information of the BMC, used by the device to verify the identity of the BMC and the legality of its communication when receiving the instruction.
[0081] After receiving the authentication request instruction, the PCIe device first checks the digital certificate of the BMC using the built-in certificate verification module. The verification process involves the validity of the certificate signature and whether the certificate is within the valid period, ensuring that only legal BMCs are communicated.
[0082] If the digital certificate of the BMC is verified, the PCIe device reads the device anti-counterfeit key (containing encrypted device identity information and hardware configuration parameters) from its on-board encrypted ROM, and obtains the device identification code. The PCIe device sends the device identification code and the device anti-counterfeit key back to the BMC through the PCIe bus.
[0083] Figure 3 is a schematic diagram of an optional device authentication method according to an embodiment of the present application; as Figure 3As shown, after the server is started, the server can execute step S302 to send a first authentication request instruction to the external device. The first authentication request instruction can carry the server's identity information. After receiving the first authentication request instruction, the external device can query the preset information set based on the identity information carried by it to determine whether the server is a trusted server. If it is determined to be a trusted server, step S306 is executed to send the first identification code and the second identification code to the server. The server can execute step S308 to decrypt the first identification code and compare the first hardware information set and the second hardware information set. If they are consistent, the external device is considered to be normal. That is, the above process is a double verification process of the server and the external device, which verify each other.
[0084] Through the above-described implementation of this application, when the server starts up, the BMC communicates with the PCIe device to perform identity verification and anti-counterfeiting authentication. This process ensures that only authenticated and legitimate PCIe devices can access the server, effectively improving the security and anti-attack capabilities of the server system. This enhances the overall security and anti-counterfeiting capabilities of the server and PCIe devices.
[0085] In an optional embodiment, before sending the first identification code and the second identification code to the server, it includes: generating the second identification code based on the target parameters of the target device, wherein the target parameters are parameters uniquely corresponding to the target device; and encrypting the first hardware information set and the second identification code using the second key to obtain the first identification code.
[0086] It should be noted that the target parameters refer to the parameters that uniquely correspond to each PCIe device, such as its chip serial number, MAC address and other hardware features. These parameters are unique and cannot be tampered with, and are the basis for generating a unique device identifier.
[0087] The second key refers to the private key generated by the device during the production phase. It is used to encrypt the first hardware information set and the second identification code generated based on the target parameters to form the first identification code. The second key is bound to the device and used in the encryption process to ensure the secure transmission of information. The first hardware information set contains the hardware information of the PCIe device, such as model and production batch. This information is collected during the device production phase and used together with the target parameters to generate the second identification code.
[0088] In an optional embodiment, the second identification code is generated based on the unique corresponding parameters of the target device, such as the chip serial number, MAC address, etc., during the device production stage. This identification code contains detailed hardware information about the device, ensuring that it accurately reflects the hardware properties of the device. The first hardware information set (hardware information of the device, such as model, production batch, etc.) and the second identification code are encrypted using the second key (private key) generated during device production to generate the first identification code. This encryption step increases the security during information transmission, ensuring that even if the first identification code is intercepted during transmission, it cannot be easily decrypted and cracked, protecting the hardware information of the device from being illegally obtained.
[0089] Embodiment 3:
[0090] Suppose a PCIe network adapter under production is being processed, with target parameters of MAC address "00:A1:B2:C3:D4:E5" and chip serial number "123456789ABCDEF". During the device production stage, the production device extracts these target parameters and generates a second identification code in combination with detailed hardware information (such as device model "NetAdapter Pro" and production batch "202301").
[0091] After generating the second identification code, the production device uses the second key (private key) bound to the device for encryption operations, and also encrypts the hardware information set such as device model and production batch, finally generating the first identification code. This first identification code contains encrypted hardware information and target parameters, ensuring the security and tamper resistance of the information.
[0092] In an optional embodiment, the second identification code is generated based on the target parameters of the target device, including: sending the target parameters of the target device to the identification code generation module, wherein the identification code generation module is used to encrypt data to generate an identification code; receiving the second identification code sent by the identification code generation module; encrypting the first hardware information set and the second identification code using the second key to obtain the first identification code, including: sending the first hardware information set of the target device to the identification code generation module; receiving the first identification code, wherein the first identification code is generated by the identification code generation module using the second key.
[0093] It should be noted that the identification code generation module can be a module inside the device, or a production module of a production factory that produces PCIe devices.
[0094] The production factory refers to the manufacturing location of the PCIe device, where advanced production equipment and professional production processes are used to manufacture high-quality server PCIe devices. The MAC address (Media Access Control Address) is the physical address of a network device, used to uniquely identify each device in the network. The chip serial number is a unique identifier assigned by the manufacturer to each chip, used to distinguish different chip units and ensure the traceability and uniqueness of each chip.
[0095] In an optional embodiment, during the production phase, the production equipment reads the first set of hardware information (such as MAC address and chip serial number) of each PCIe device using a hardware reading tool. These information are considered as the physical fingerprint of the device, which are tamper-proof and highly stable, to ensure the uniqueness and authenticity of the device. The production equipment combines the read hardware information (MAC address, chip serial number) according to specific encoding rules, and encrypts it through the SHA-256 encryption hash function to generate a 256-bit device identification code (second identification code), which is the basis of the device identity.
[0096] In addition to generating the identification code, the production equipment also needs to collect and record the detailed hardware information of the device, including device model, production batch, chip set information and hardware configuration parameters, etc., and bind these information with the device identification code to form the basis data of the device anti-counterfeiting key. RSA asymmetric encryption algorithm can be used to encrypt the above bound hardware information using the private key (second key) of the production manufacturer, to generate the device anti-counterfeiting key (first identification code). This key plays a key role in the subsequent server authentication process, used to verify the true identity of the device and the integrity of the hardware information.
[0097] The device anti-counterfeiting key is securely burned into the on-board ROM of the device. Due to the read-only nature and encrypted storage function of the ROM, it ensures that the device anti-counterfeiting key cannot be illegally read or tampered with, increasing the security of the device. The device identification code and the decryption public key corresponding to the private key are stored in the server database, and these information will be called when the BMC performs authentication, used to decrypt the device anti-counterfeiting key and compare the hardware information, to confirm the authenticity and legality of the device.
[0098] Through the above embodiments of the present application, the unique identification information of the device is obtained from the hardware bottom layer, and combined with the detailed hardware configuration, a firm anti-counterfeiting and information security framework is established for the PCIe device through encryption and secure storage, providing a solid hardware foundation for subsequent server authentication. Through this series of rigorous production control and information security measures, the security and credibility of the PCIe device in the server system are greatly improved.
[0099] In optional embodiments, in the case that the first set of hardware information and the second set of hardware information are consistent, the external device is determined to pass the authentication, including at least one of the following:
[0100] 1) In the case that the first string and the second string are matched, the external device is determined to pass the authentication, wherein the first string is used to indicate the target device, and the second string is used to indicate the external device.
[0101] 2) In the case that the first parameter and the second parameter are consistent, the external device is determined to pass the authentication, wherein the first parameter is used to indicate the hardware parameter of the target device, and the second parameter is used to indicate the hardware parameter of the external device.
[0102] 3) In the case that the first information and the second information are matched, the external device is determined to pass the authentication, wherein the first information is binary data and is used to indicate the hardware parameter of the target device, and the second information is binary data and is used to indicate the hardware parameter of the external device.
[0103] The first string and the second string correspond to the device model of the target device and the external device, respectively, and are used to verify whether the device model is consistent with the expected one through string matching.
[0104] The first parameter and the second parameter represent the hardware parameter of the target device and the external device, respectively, such as the number of production batch, and the consistency of the production batch is verified through number comparison.
[0105] The first information and the second information represent the chipset information or other hardware parameters of the target device and the external device, and are stored and transmitted in the form of binary data, and the accuracy of the hardware parameters is ensured through binary data comparison.
[0106] In optional embodiments, after the BMC decrypts the first set of hardware information using the first key, the information set is compared with the pre-stored second set of hardware information. The comparison operation covers multiple levels, including string matching of device model, number comparison of production batch, and binary data comparison of chipset information. If the hardware information of the external device matches the expected genuine device information in all these comparisons, the BMC can confirm the authenticity of the external device and determine that it passes the authentication, ensuring that the server can safely communicate with the genuine device. This series of comparison operations ensure the accuracy of the hardware information and is an indispensable step in the BMC authentication process.
[0107] It should be noted that in the anti-counterfeiting authentication process between the BMC and the PCIe device, the compared information specifically includes but is not limited to the following types:
[0108] Device Model: This is the identifier of the device, used to confirm the type and specifications of the device. The accuracy of the device model is verified through string matching (i.e., text comparison).
[0109] Production Batch: Used to track the production history of the device, including the production date, production line number, etc. The matching of production batch information is confirmed through comparison of numbers or strings.
[0110] Chipset Information: Includes the manufacturer, model, serial number, and version number of the chip, etc. This information is usually stored in binary or specific encoding format, and the consistency of chipset information is confirmed through binary data comparison or string comparison after decoding.
[0111] Hardware Configuration Parameters: This may include the firmware version, BIOS version, hardware function configuration (such as supported transmission speed, power consumption settings, etc.) of the device. These parameters may be stored in different data types such as strings, integers or floating-point numbers, and the BMC will perform corresponding comparisons according to the data type.
[0112] MAC Address: The identity of the device is confirmed by comparing the MAC address. The MAC address is a fixed-length binary number, and the BMC will perform a bit-by-bit comparison of the decrypted MAC address with the current MAC address reported by the device.
[0113] Security Status Information: For example, whether the encryption function of the device is normal, whether the security log is complete, etc. This information can be obtained through specific security check commands and then compared with the expected security status.
[0114] Running Status Information: Such as the temperature, voltage, working frequency of the device, etc. These information can reflect the current running status of the device, and the BMC will compare it with the preset normal value range to confirm that the device is running normally.
[0115] In optional embodiments, for different types of hardware information mentioned above, the BMC adopts the following comparison methods:
[0116] String Matching: For device model, firmware version number, etc., the BMC will perform string comparison to ensure that the decrypted string matches the current reported string exactly.
[0117] Numerical Comparison: Production batch, hardware parameters (such as transmission speed, power consumption) and other information stored in numerical form, the BMC will perform numerical comparison to confirm that the numbers are exactly the same or within the allowed tolerance range.
[0118] Binary Data Comparison: Chipset information, MAC address, and some configuration parameters may be stored in binary form. The BMC will perform a bit-by-bit comparison to ensure that each bit of the binary data matches the expected data.
[0119] State check: For security state and running state information, the BMC checks whether the data is within the preset normal range, or whether there is an abnormal flag or log record. For example, ensure that the running state flag of the encryption function is "enabled".
[0120] Integrity check: The BMC can also perform integrity check on the firmware or driver of the device, such as comparing the pre-stored hash value with the current device hash value to confirm that the firmware or driver has not been tampered with.
[0121] Through the above embodiments of the present application, through these accurate comparison and verification processes, the BMC can determine whether the identity, state and configuration of the PCIe device are consistent with the expected, thereby effectively preventing the access of counterfeit devices and ensuring the safe operation of the server, guaranteeing the stable operation of the server system and the security of the data.
[0122] In optional embodiments, after determining that the external device passes the authentication, the method comprises: in the case that the preset authentication condition is met, sending a second authentication request instruction to the external device, wherein the second authentication request instruction contains a challenge code, and the challenge code is a random data sequence of a preset number of bits; receiving a response code sent by the external device, wherein the response code is obtained by the external device encrypting the challenge code and the second identification code; decrypting the response code to obtain first information and second information, and in the case that the first information is consistent with the challenge code and the second information is consistent with the second identification code, determining that the external device passes the current authentication.
[0123] It should be noted that the second authentication request instruction can be an instruction sent by the BMC to the PCIe device after the first stage authentication succeeds, which is used to start the second stage dynamic authentication process and ensure the continuous authenticity of the device.
[0124] The challenge code is a random data sequence generated by the BMC, which is used to test the response of the PCIe device in the second stage authentication. The preset number of bits of the challenge code ensures its randomness and increases the difficulty of cracking. The response code is data generated by the PCIe device using the second identification code in combination with the challenge code after receiving the second authentication request instruction, which is used to respond to the dynamic authentication request of the BMC.
[0125] The first information is the plaintext form of the challenge code obtained by the BMC after decrypting the response code, which is used to verify whether the PCIe device correctly responds to the dynamic authentication request of the BMC. The second information is the encrypted part obtained by the BMC after decrypting the response code, which should theoretically be consistent with the second identification code, and is used to verify the authenticity and consistency of the anti-fake key of the PCIe device.
[0126] In an optional embodiment, after the preliminary authentication, the server BMC performs a second stage of dynamic authentication to ensure the authenticity and integrity of the PCIe device throughout its life cycle. The authentication process in this stage focuses more on the real-time response and dynamic state monitoring of the device. The second authentication request instruction sent by the BMC carries a challenge code, which is a randomly generated data sequence, used to test the real-time response capability of the PCIe device and verify the validity of the device anti-counterfeit key. The PCIe device encrypts the challenge code using its internal encryption mechanism (using the first identification code as the key) and generates a response code to send back to the BMC. After receiving the response code, the BMC decrypts it using a specific key to obtain the first information (which should be the same as the challenge code) and the second information (which should be the same as the second identification code of the device). This process can effectively identify whether the device has been replaced or tampered with, because only the legitimate device that possesses the device anti-counterfeit key (first identification code) can generate the correct response code. Once the BMC confirms that the decrypted information of the response code is consistent with the expected value, it completes the second stage of dynamic authentication, and the current authentication status of the device is also confirmed to be passed.
[0127] In an optional embodiment, after sending the first identification code and the second identification code to the server, the method further includes: receiving a second authentication request instruction sent by the server, and encrypting a challenge code contained in the second authentication request instruction and the second identification code to obtain a response code, wherein the challenge code is a random data sequence of a preset number of bits; and sending the response code to the server, wherein the response code is used to identify whether the external device passes the current authentication.
[0128] After the initial authentication of the PCIe device (external device) is successful, the device further participates in the steps of the dynamic authentication process. After receiving the second authentication request instruction from the server, the challenge code (a random data sequence of a preset number of bits) contained therein is used together with the second identification code stored internally by the device to generate a new encrypted response code, which is then sent back to the server for subsequent dynamic identity verification.
[0129] The authentication of the device does not stop at the one-time check at startup. To enhance the dynamic verification of the device identity and prevent the device from being tampered with or replaced during operation, the server BMC sends a second authentication request instruction periodically after the device passes the preliminary authentication. The challenge code contained in the instruction is a randomly generated data sequence, used to ensure the uniqueness of each authentication request and prevent replay attacks.
[0130] In an optional embodiment, the process of encrypting the response code can use the AES-256 algorithm. When receiving the second authentication request instruction of the BMC (containing the challenge code and the digital certificate of the BMC), the PCIe device starts its internal AES-256 encryption engine, which can use the previously stored device anti-counterfeit key to encrypt the challenge code and the device identification code. The encryption engine uses the AES-256 algorithm to perform complex processing on these information, generating a 128-bit length response code, which is the encrypted response of the device to the BMC request.
[0131] After generating the response code, the PCIe device sends the response code back to the BMC for verification through the PCIe bus using a secure transmission protocol. The transmission process here is usually encrypted to ensure the security of the response code during transmission and prevent interception and tampering.
[0132] After receiving the response code sent by the PCIe device, the BMC first verifies the legitimacy of the response code to avoid receiving responses from unauthorized devices and ensure that the subsequent authentication process is based on interaction with a legitimate device. The BMC uses the server's locally stored decryption key (the public key corresponding to the PCIe device's anti-counterfeit key) and the AES-256 algorithm to decrypt the received response code to obtain the device's response to the challenge code and the device identification code. The decrypted information will be compared with the challenge code and the expected device identification code originally sent by the BMC. If the comparison result is consistent, it proves that the PCIe device's response is correct and the device identification code has not been tampered with, and the device has passed the preliminary anti-counterfeit detection.
[0133] After the preliminary anti-counterfeit detection passes, the BMC will not stop monitoring immediately, but will further analyze the real-time running state information of the device, including data transmission rate, power consumption, etc., to verify whether the PCIe device is running in a normal state and whether these running state information matches the expected genuine device.
[0134] If any abnormalities are found in the preliminary detection or subsequent running state analysis, the BMC will not make a judgment immediately, but will start a multi-round interactive authentication process to further verify the identity and state of the device through incremental encryption information exchange to determine whether the anomaly is a real security threat.
[0135] If the BMC still detects abnormalities in the device after multiple rounds of interactive authentication, it may mean that the device is counterfeit or has been tampered with. At this time, the BMC will immediately start the alarm mechanism, send an alarm notice to the system administrator, and record the details of the abnormality in the security log for subsequent troubleshooting and security audit. After receiving the alarm, the administrator can take appropriate action based on the recorded information, such as isolating or replacing the abnormal device, to ensure the security and stability of the server system.
[0136] Through the above embodiments of the present application, the dynamic anti-counterfeiting authentication process between the BMC and the PCIe device not only detects abnormal changes in the device state in a timely manner, but also further ensures the security and trustworthiness of the device through multiple rounds of interactive verification, providing continuous security monitoring and anti-counterfeiting protection for the server system. In addition, after the initial authentication during the startup process, dynamic authentication is also performed on the device, thereby avoiding replacement of the device during operation.
[0137] In optional embodiments, the second authentication request instruction is sent to the external device under the condition that a preset authentication condition is met, including one of the following:
[0138] 1) The second authentication request instruction is sent to the external device under the condition that the current time point is a preset time point;
[0139] 2) The second authentication request instruction is sent to the external device under the condition that the change rate of at least one performance parameter of the server is greater than a preset change rate;
[0140] 3) The second authentication request instruction is sent to the external device under the condition that the server has a first prompt, wherein the first prompt is used to indicate that an error occurs in the system of the server;
[0141] 4) The second authentication request instruction is sent to the external device under the condition that the server receives a detection instruction.
[0142] It should be noted that the preset authentication condition can be a condition set by the BMC according to the system security policy, which is used to determine when to send the second authentication request instruction to the PCIe device, to ensure dynamic monitoring of the device state.
[0143] The preset time point can be a timing authentication moment set by the BMC according to the security policy, which is used to periodically re-verify the device state to ensure the continuous security of the device. The performance parameter of the server refers to the key indicators of the server during operation, such as CPU utilization, memory usage, network traffic, etc., which are used to monitor the health status of the server. The change rate is the change speed of the performance parameter over time, which is used to detect abnormal changes in the server state, which may indicate an attack or performance bottleneck.
[0144] The first prompt can be a system error indication signal of the server, such as an error entry in the system log, used to trigger the BMC to further authenticate the device in case of device failure or security issues.
[0145] The detection instruction can be a command from a system administrator or other monitoring system, instructing the BMC to execute the second authentication request instruction for on-demand device state checking.
[0146] In optional embodiments, in the anti-counterfeit authentication system of the server PCIe device, the BMC not only performs authentication once at server startup, but also sends a second authentication request instruction to the PCIe device as needed to perform dynamic verification of the device state according to pre-set multiple authentication conditions. These conditions include:
[0147] Timing authentication: At a pre-set time point, such as 2 a.m. every day, the BMC automatically starts the dynamic verification process to confirm that the device state has not changed.
[0148] Performance parameter monitoring: When the performance parameters of the server, such as the change rate of CPU utilization or network throughput, exceed the pre-set threshold, the BMC considers that there may be device abnormalities or security threats, and immediately performs dynamic authentication to check whether the PCIe device is genuine or tampered.
[0149] System error response: If the server system has an error, such as abnormal log entries monitored by the BMC, which may indicate hardware failure or malicious activity, the BMC will send a second authentication request instruction to all PCIe devices to ensure that the devices are not affected.
[0150] On-demand detection: System administrators or external monitoring software can manually trigger the BMC to perform the second authentication request by sending a detection instruction for device state checking at a specific time, such as when a security event is suspected to have occurred.
[0151] Through the above embodiments of the present application, the BMC can flexibly adapt to various operating states and potential threats of the server, ensuring that the PCIe device always remains authentic and secure throughout its entire usage cycle, improving the overall anti-counterfeit capability and operational stability of the server.
[0152] In optional embodiments, receiving the response code sent by the external device includes: receiving the response code sent by the external device, wherein the response code is obtained by the external device using the first identification code to encrypt the challenge code and the second identification code; and decrypting the response code to obtain the first information and the second information, including: decrypting the response code using the first identification code to obtain the first information and the second information.
[0153] As described above, the server can dynamically verify the external device. In the dynamic anti-fake authentication process of the server PCIe device, the PCIe device responds to the second authentication request instruction of the BMC, generates and sends a response code to the server. The response code is generated by encrypting the challenge code received by the external device and the second identification code of the device itself using the first identification code through the encryption engine of the external device. After receiving the response code, the BMC decrypts the response code using the decryption key stored locally in the server to obtain the decrypted challenge code (first information) and the device anti-fake key (second information). Then, the BMC compares the first information obtained by decryption with the challenge code originally sent by itself to verify whether the response of the PCIe device is correct and timely. At the same time, the BMC checks the second information, i.e., the second identification code of the device, to confirm whether the device identity and hardware information are tampered with. Only when both the first information and the second information meet the expectation, the current authentication status of the PCIe device will be confirmed as passed, otherwise, the BMC will mark the device as abnormal, start further verification or directly trigger the alarm mechanism to inform the system administrator to handle possible security problems.
[0154] In an optional embodiment, the challenge code and the second identification code contained in the second authentication request instruction are encrypted to obtain the response code, including: encrypting the challenge code and the second identification code using the first identification code to obtain the response code.
[0155] After receiving the second authentication request instruction, the PCIe device encrypts the challenge code and the second identification code of the device using the device anti-fake key (first identification code) to generate the response code. The encryption process ensures the security of the data during transmission and prevents third parties from eavesdropping or tampering with the information.
[0156] In the dynamic anti-fake authentication mechanism of the server PCIe device, when the BMC sends the second authentication request instruction to the PCIe device during the server operation, the PCIe device will immediately start processing. In the first step, the device will read the stored device anti-fake key from the internal encryption ROM. Then, the PCIe device uses this key to encrypt the challenge code contained in the second authentication request instruction, and also encrypts its own device identification code to generate a complete response code. This response code contains the encrypted challenge code and device identification code, which is used to prove the identity of the device and respond to the anti-fake verification initiated by the BMC. The PCIe device then sends the response code back to the BMC of the server through the PCIe bus for the next step of verification.
[0157] Figure 4 is a schematic diagram of another optional device authentication method according to an embodiment of the present application; as Figure 4As shown, in the case of meeting the preset authentication condition, the server can perform a dynamic authentication process. Step S402 can be performed to send a second authentication request instruction to the external device, the external device performs step S404 to encrypt the challenge code and the second identification code to obtain a response code, and performs step S406 to send the response code to the server. After the server receives the response code, step S408 can be performed to decrypt the response code to obtain the first information and the second information, and compare whether the first information and the challenge code, and the second information and the second identification code are consistent, and in the case of consistency, it is determined that the external device passes the dynamic authentication. In this way, the external device can be authenticated in the running stage of the server, avoiding replacement of the external device in the running process of the server.
[0158] Through the above embodiments of the present application, the server BMC sends a second authentication request instruction containing a challenge code and a timestamp to the PCIe device, and the PCIe device uses a device anti-fake key (first identification code) to encrypt the challenge code to generate a response code. This process ensures that the server can monitor the authenticity and integrity of the PCIe device in real time, prevents the access or replacement of malicious devices, and maintains the safe and stable operation of the server system.
[0159] In an optional embodiment, before receiving the first identification code and the second identification code sent by the external device, it includes: sending a third key to the external device, wherein the third key is used to encrypt data; receiving the response code sent by the external device includes: receiving the response code sent by the external device, wherein the response code is obtained by the external device using the third key to encrypt the challenge code and the second identification code; decrypting the response code to obtain the first information and the second information includes: using the third key to decrypt the response code to obtain the first information and the second information.
[0160] It should be noted that the third key can be a use key generated by the server BMC in the dynamic authentication process, which is used to encrypt and decrypt specific authentication data such as the combination of the challenge code and the second identification code. The use of the third key enhances the security of the authentication, because it is used in the authentication interaction and is dynamically generated by the server, increasing the difficulty of cracking.
[0161] Before the BMC starts to receive the identification code information of the external device, the BMC will first send a unique third key to the device. This key will be used in the encryption process of the response code sent by the device subsequently, ensuring the security of the data in the transmission process, preventing eavesdropping or tampering.
[0162] In an optional embodiment, the BMC can send the third key to the peripheral device through the first authentication request instruction in the case of server startup, that is, the first authentication request instruction can carry the third key in addition to the aforementioned server identity information. In this way, the PCIe device that passes the initial authentication receives the third key, while the PCIe device that is replaced in the middle cannot know the third key.
[0163] The BMC generates a third key before receiving the first identification code and the second identification code of the peripheral device, and sends the third key to the device. Then, the device uses the third key to encrypt the challenge code of the BMC and the second identification code of the device itself to generate a response code, and sends the response code back to the BMC. After receiving the response code, the BMC uses the same third key to decrypt the first information (i.e., the decrypted challenge code) and the second information (i.e., the decrypted second identification code). By comparing the first information and the challenge code, and the second information and the second identification code, the BMC can ensure that the response of the peripheral device is correct, and verify the authenticity and unaltered state of the device. This encryption communication step enhances the security of the authentication, ensures that the authentication information of the device cannot be obtained or tampered with by the attacker even in a network environment with eavesdropping or man-in-the-middle attack, and improves the reliability and security of the entire authentication process.
[0164] In an optional embodiment, before sending the first identification code and the second identification code to the server, the method further includes: receiving a third key sent by the server, wherein the third key is used to encrypt data; and encrypting the challenge code and the second identification code contained in the second authentication request instruction to obtain the response code, including: encrypting the challenge code and the second identification code by using the third key to obtain the response code.
[0165] Before the PCIe device formally sends its identification information (the first identification code and the second identification code) to the server, there is a preprocessing step. The PCIe device first receives a third key sent by the BMC of the server. The main purpose of the third key is to encrypt data, which here specifically refers to the response code that is about to be generated and sent back to the server, that is, the response of the device to the second authentication request instruction sent by the BMC, which contains the encrypted challenge code and the second identification code.
[0166] The PCIe device combines the challenge code (a random data sequence used to verify the response ability of the device) in the instruction and the second identification code (which usually contains detailed hardware information of the device) stored by the device itself, and encrypts them using the third key. The third key is sent by the BMC to the PCIe device at the beginning of this round of authentication, and is used to ensure the security and independence of each communication. The encrypted result is the response code, which is the key data of the PCIe device responding to the authentication request of the BMC, and is used to prove the identity and integrity of the device.
[0167] Embodiment 4:
[0168] The server BMC generates a 128-bit random challenge code, for example, 0x9a8b7c6d5e4f3g2h1i0j, and attaches a preset third key (for example, 0x09a8b7c6d5e4f3g2h1i0j9), encapsulates these data in a second authentication request instruction, and sends the instruction to the PCIe device through the PCIe bus.
[0169] After receiving the second authentication request instruction, the PCIe device first verifies whether the instruction is legal (which usually involves verifying the digital certificate of the BMC, as discussed above). Once it is confirmed that the instruction is legal, the PCIe device will use the received third key to encrypt the challenge code and the second identification code of the device (for example, "Device_ID_12345"). Assuming that the symmetric encryption algorithm AES-128 is used, the PCIe device will generate a new encrypted response code.
[0170] The encrypted response code, for example, 0x1234567890abcdef, is sent back to the server BMC by the PCIe device through the PCIe bus. This response code is the result of encrypting the challenge code and the second identification code based on the third key, and is used to prove the real-time response of the device identity and status.
[0171] After receiving the response code from the PCIe device, the server BMC uses the same third key (0x09a8b7c6d5e4f3g2h1i0j9) to decrypt the received response code to verify the legality of the encryption process. The decrypted data will be compared with the original challenge code and the second identification code expected by the BMC.
[0172] If the decrypted data completely matches the original challenge code and the second identification code of the device, the BMC determines that the response code verification is passed, which means that the PCIe device is legal in the current state, the identity is not tampered with, and it can correctly respond to the authentication request of the BMC. The BMC will continue to monitor the running state of the device to ensure the safety and stability of the entire server system.
[0173] Figure 5 is a schematic diagram of another optional device authentication method according to an embodiment of the present application; as Figure 5As shown, the server identifies the external device during the startup process, and the server can execute step S502 to send a first authentication request instruction to the external device, the first authentication request instruction carrying a third key. The external device can execute steps S504-S506 to query a preset information set, determine whether the server is trustworthy, and in the case of trustworthiness, send a first identification code and a second identification code to the server. Then the server executes step S508 to decrypt the first identification code and compare the first hardware information set and the second hardware information set, and in the case of consistency, pass the initial authentication. During the server running process, to prevent the external device from being replaced, in the case of meeting a preset condition, the server executes step S510 to send a second authentication request instruction to the external device. The external device executes steps S512-S514 to encrypt the challenge code and the second identification code using the third key sent by the server during the startup phase to obtain a response code, and sends the response code to the server. The server executes step S516 to decrypt the response code to obtain first information and second information, and compares whether the first information and the challenge code, and the second information and the second identification code are consistent, and in the case of consistency, determines that the external device passes the dynamic authentication. The above process is a continuous device identification process throughout the server startup to running phase.
[0174] Through the above embodiments of the present application, the third key is introduced for data encryption, which increases the security and dynamics of the authentication process between the server and the PCIe device, effectively preventing replay attacks and other security threats. This mechanism ensures the authenticity and integrity of the PCIe device, and provides continuous anti-fake detection and security protection for the server.
[0175] In an optional embodiment, sending the second authentication request instruction to the external device comprises: sending the second authentication request instruction to the external device, wherein the second authentication request instruction further contains a first timestamp, the first timestamp being used to indicate a time point of sending the second authentication request instruction, and being used to compare with a second timestamp to determine whether the server passes the authentication, and the second timestamp being used to indicate a time point of receiving the second authentication request instruction by the external device.
[0176] The first timestamp can be current time information automatically added by the server BMC when generating and sending the second authentication request instruction, accurate to the millisecond level. Its role is to compare with the second timestamp of the external device in the subsequent authentication process to check whether there is a delay or a replay attack.
[0177] The second timestamp can be local time information recorded by the PCIe device after receiving the second authentication request instruction, also accurate to the millisecond level. It is used to prove that the device receives and responds to the dynamic authentication request of the BMC within a specified time, and is a key data for confirming the response time of the device and preventing replay attacks.
[0178] When performing dynamic authentication, the server BMC will additionally add a first timestamp to the regular authentication request instruction (containing a challenge code, etc.) to record the specific time point when the BMC sends the instruction. This timestamp is dynamically generated and changes with each authentication request, ensuring the uniqueness and timeliness of each communication.
[0179] In an optional implementation, the second authentication request instruction sent by the server is received, and the challenge code and the second identification code contained in the second authentication request instruction are encrypted to obtain a response code, including: receiving the second authentication request instruction sent by the server, wherein the second authentication request instruction further contains a first timestamp, and the first timestamp is used to indicate the time point when the server sends the second authentication request instruction; calculating the time difference between the first timestamp and the second timestamp, and in the case that the time difference is less than a preset time threshold, encrypting the challenge code and the second identification code contained in the second authentication request instruction to obtain a response code, wherein the second timestamp is used to indicate the time point when the external device receives the second authentication request instruction.
[0180] The time difference can be the time interval between the first timestamp of the server BMC and the second timestamp of the PCIe device, which is used to verify whether the instruction received by the PCIe device is the most recently sent one, preventing old instructions from being attacked by replay.
[0181] In an optional implementation, the PCIe device receives the second authentication request instruction containing the challenge code and the second identification code (device anti-fake key), and uses an internal encryption engine in combination with a preset key to encrypt the challenge code and the second identification code to generate a response code, which is used to verify the identity and current state of the device.
[0182] After receiving the instruction, the device first calculates the time difference between the first timestamp (the sending time of the server BMC) contained in the instruction and the second timestamp (the time when the device receives the instruction) generated by the device. If the time difference is less than a preset time threshold (for example, ±5 minutes), the PCIe device considers the instruction to be recent and valid, and can continue the generation and sending process of the response code; otherwise, the device will ignore this instruction and wait for the next valid authentication request, thereby avoiding potential replay attacks and enhancing the security of the authentication process.
[0183] Embodiment 5:
[0184] In an enterprise data center, servers are running 24 hours a day without interruption, processing a large amount of critical business data. In order to ensure that the PCIe device of the server is not replaced or tampered with during operation, the baseboard management controller (BMC) of the server is configured to perform a dynamic anti-fake authentication mechanism.
[0185] The BMC is programmed to perform dynamic authentication every 30 minutes, and is also configured to immediately initiate the dynamic authentication process when it detects any sudden change in device load (such as a load fluctuation of more than 30%) or system abnormal error (such as hard disk read / write error, memory access error, etc.). This is because hot plug support makes it possible for devices to be replaced while running, and timely dynamic authentication can quickly detect and respond to such security threats.
[0186] Under the set detection period or event trigger condition, the BMC generates a random 128-bit challenge code (such as 0x3b1f6c2d9b68523f) and combines the current timestamp (accurate to milliseconds, such as 1630497789123 milliseconds) to encapsulate these information in a dynamic authentication instruction, which is sent to all external PCIe devices through the PCIe bus.
[0187] After receiving the dynamic authentication instruction, the PCIe device first checks the timestamp in the instruction. If the difference between the current time and the timestamp is within the preset range (e.g. ±5 minutes), the timestamp is considered valid and the authentication process can continue; otherwise, the device will ignore this instruction and wait for the next valid authentication request. After confirming the validity of the timestamp, the PCIe device uses the built-in AES-256 encryption engine to encrypt the challenge code and device identification code in combination with the stored device anti-fake key (i.e. the second identification code). The encrypted response code (e.g. 0x8a7b3c4d2e1f7g6h) is a 128-bit ciphertext that contains the encrypted response to the BMC challenge and the encrypted proof of device identity.
[0188] The PCIe device then sends the encrypted response code back to the BMC through the PCIe bus. Since the PCIe bus supports high-speed data transmission, the sending of the response code will hardly affect the normal operation of the server, and at the same time the BMC can quickly receive the response code for the next verification.
[0189] After receiving the response code from the PCIe device, the BMC first decrypts the response code using the decryption key stored locally on the server, also using the AES-256 algorithm. After decryption, the BMC will obtain two pieces of information: the first is the decrypted challenge code, and the second is the decrypted device identification code. Then, the BMC compares these two pieces of information with the original challenge code and device identification code sent. If the decrypted challenge code matches the original challenge code, and the decrypted device identification code matches the device identification code stored in the database, the BMC confirms that the response of the PCIe device is legal, and the device passes the current dynamic authentication. In this case, the BMC updates the status information of the device and records the success of the authentication in the system log, and continues to monitor the operation of the server.
[0190] But if the decrypted challenge code or device identification code does not match the original data, the BMC will immediately start an exception handling process. The BMC records the information of the abnormal device, including the device identification code, the exception timestamp, the possible exception type, etc., and sends an alarm notification to the system administrator, prompting the possible security risks of device replacement or tampering. After receiving the alarm, the administrator can immediately check the server and replace the abnormal device if necessary to ensure the continuous security and stable operation of the server.
[0191] Through the above-mentioned embodiments of the present application, the BMC performs dynamic PCIe device anti-fake authentication and responds quickly when detecting potential security threats, ensuring the security of the server system and the integrity of the data. This dynamic authentication mechanism can effectively prevent devices from being replaced by hot swapping, and strengthens the monitoring and protection of PCIe devices during server operation.
[0192] As mentioned earlier, after identifying an abnormal device, the abnormal device can be recorded. That is, in the anti-fake scheme of the server PCIe device, exception handling and recording are important links to ensure the safe operation of the system.
[0193] In an optional embodiment, a real-time abnormal behavior analysis system is introduced to monitor and analyze the interaction data between the BMC and the PCIe device in real time. This system can establish a baseline model according to the normal operating parameters and historical behavior of the device, and automatically detect any abnormal behavior that deviates from the normal range, such as sudden drop in data transfer rate, abnormal increase in power consumption, or sudden increase in error rate, etc.
[0194] The real-time abnormal behavior analysis system can use machine learning algorithms such as support vector machine (SVM) or recurrent neural network (RNN) to analyze the operating state of the device. The system collects various parameters of the device during normal operation, such as data throughput, power consumption, and error detection rate, to establish a normal operation model. When the device parameters deviate from the normal model, the system immediately marks it as abnormal and triggers further BMC interaction authentication to confirm the true state of the device.
[0195] In an optional embodiment, when a device exception is detected, the device state can be automatically restored, such as restarting the device; if the device cannot be restored to normal, the system will automatically isolate the abnormal device to prevent it from affecting the operation of the entire server. The automatic recovery and isolation system needs to have the ability to monitor and control the device state. After detecting a device exception, the BMC first attempts to automatically restore the device state through software reset or hardware reset commands. If the device state is still abnormal after multiple attempts, the BMC marks the device as isolated, disconnects it from the rest of the server, and updates the server's hardware configuration to notify other system components to bypass the abnormal device, ensuring that the normal operation of the server is not affected.
[0196] Embodiment 6:
[0197] During the running of the data center server, the BMC detects that the performance of a certain PCIe device is abnormal, and the data transmission rate is 50% lower than the normal value.
[0198] The system automatically detects that the performance of the device is abnormal, triggering a multi-level alarm mechanism. According to the preset rules, the system determines that this abnormality is of medium severity, automatically sends an internal message to the administrator, and records the abnormal information to the intelligent log system. The BMC sends a restart command to the abnormal device to attempt to automatically restore the device state. After two restarts, the performance of the device has not improved significantly.
[0199] The intelligent log system automatically analyzes the abnormal record to generate an abnormal report, indicating the device model, abnormal time, performance decline ratio, and attempted recovery measures, and suggesting that the administrator physically check the device and prepare a replacement plan.
[0200] After multiple recovery attempts are ineffective, the automatic recovery and isolation system marks the device as an isolated state, disconnects it from the server, updates the hardware configuration of the server, and notifies other system components to bypass the abnormal device to ensure that the remaining PCIe devices and the server run normally without being affected.
[0201] Through the above embodiments of the present application, when the server BMC detects that the PCIe device has an abnormality, the abnormal information is quickly recorded, multi-level alarm notifications are sent, and diversified notification means are combined to timely warn and solve the problem, effectively preventing potential security risks caused by PCIe device abnormalities.
[0202] Through the above description of the embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and the necessary general hardware platform, of course, it can also be realized by hardware, but in many cases the former is a better embodiment.
[0203] The embodiments of the present application also provide a device authentication apparatus for a server, Figure 6 is a structural block diagram of an optional device authentication apparatus according to an embodiment of the present application, as shown in the figure, the apparatus comprises: Figure 6
[0204] The identification code receiving module 602 is configured to receive the first identification code and the second identification code sent by the external device, wherein the first identification code is used to indicate the hardware information of the target device, and the second identification code is used to indicate the target device.
[0205] The decryption module 604 is configured to determine the first key based on the second identification code, and decrypt the first identification code by using the first key to obtain the first hardware information set of the target device, wherein the first hardware information set contains at least one hardware information of the target device.
[0206] The first authentication module 606 is configured to compare the first hardware information set and the second hardware information set, and determine that the external device passes the authentication in a case where the first hardware information set and the second hardware information set are consistent, wherein the second hardware information set contains at least one hardware information of the external device.
[0207] Optionally, the identification code receiving module 602 is further configured to send a first authentication request instruction to the external device, wherein the first authentication request instruction contains identity information of the server, and the identity information is used to indicate the server and to confirm whether the server is contained in a server list to which the external device can be connected; and receive the first identification code and the second identification code sent by the external device.
[0208] Optionally, the device authentication apparatus further includes a second authentication module configured to send a second authentication request instruction to the external device in a case where a preset authentication condition is met, wherein the second authentication request instruction contains a challenge code, and the challenge code is a random data sequence with a preset number of bits; receive a response code sent by the external device, wherein the response code is obtained by the external device by encrypting the challenge code and the second identification code; and decrypt the response code to obtain first information and second information, and determine that the external device passes the current authentication in a case where the first information is consistent with the challenge code and the second information is consistent with the second identification code.
[0209] Optionally, the second authentication module is further configured to receive a response code sent by the external device, wherein the response code is obtained by the external device by encrypting the challenge code and the second identification code by using the first identification code; and decrypt the response code by using the first identification code to obtain the first information and the second information.
[0210] Optionally, the identification code receiving module is further configured to send a third key to the external device, wherein the third key is used to encrypt data; and receive a response code sent by the external device, including receiving the response code sent by the external device, wherein the response code is obtained by the external device by encrypting the challenge code and the second identification code by using the third key; and decrypt the response code by using the third key to obtain the first information and the second information.
[0211] Optionally, the second authentication module is further configured to send a second authentication request instruction to the external device, wherein the second authentication request instruction further contains a first time stamp, and the first time stamp is used to indicate a time point at which the second authentication request instruction is sent, and is used to compare a second time stamp to determine whether the server passes the authentication, and the second time stamp is used to indicate a time point at which the external device receives the second authentication request instruction.
[0212] Optionally, the second authentication module is further configured to send the second authentication request instruction to the external device in a case where a current time point is a preset time point, in a case where a change rate of at least one performance parameter of the server is greater than a preset change rate, in a case where a first prompt appears on the server, or in a case where the server receives a detection instruction, wherein the first prompt is used to indicate that an error occurs on the system of the server.
[0213] Optionally, the first authentication module is further configured to determine that the external device passes the authentication in a case where a first string and a second string are matched, wherein the first string is used to indicate the target device and the second string is used to indicate the external device, in a case where a first parameter and a second parameter are consistent, wherein the first parameter is used to indicate a hardware parameter of the target device and the second parameter is used to indicate a hardware parameter of the external device, or in a case where a first information and a second information are compared and passed, wherein the first information is binary data and is used to indicate the hardware parameter of the target device and the second information is binary data and is used to indicate the hardware parameter of the external device.
[0214] Embodiments of the present application also provide another device authentication apparatus for an external device, which comprises:
[0215] The identification code sending module is configured to send a first identification code and a second identification code to a server, wherein the first identification code is used to indicate hardware information of the target device and the second identification code is used to indicate the target device and is used to determine a first key, the first key is used to decrypt the first identification code to obtain a first hardware information set of the target device, the first hardware information set is used to contain at least one hardware information of the target device and is used to be compared with a second hardware information set to determine whether the external device passes the authentication, and the second hardware information set contains at least one hardware information of the external device.
[0216] Optionally, the identification code sending module is further configured to receive a first authentication request instruction sent by the server, wherein the first authentication request instruction contains identity information of the server, and the identity information is used to indicate the server; and query a preset information set, and send the first identification code and the second identification code to the server in a case where the identity information is contained in the preset information set, wherein the preset information set is used to indicate a server list to which the external device can be connected.
[0217] Optionally, the device authentication apparatus further comprises a response code generation module configured to receive the second authentication request instruction sent by the server, and encrypt the challenge code and the second identification code contained in the second authentication request instruction to obtain a response code, wherein the challenge code is a random data sequence with a preset number of bits; and send the response code to the server, wherein the response code is used to identify whether the external device passes the current authentication.
[0218] Optionally, the response code generation module is further configured to encrypt the challenge code and the second identification code by using the first identification code to obtain the response code.
[0219] Optionally, the response code generation module is further configured to receive a third key sent by the server, wherein the third key is used to encrypt data; and encrypt the challenge code and the second identification code by using the third key to obtain the response code.
[0220] Optionally, the response code generation module is further configured to receive the second authentication request instruction sent by the server, wherein the second authentication request instruction further contains a first time stamp, and the first time stamp is used to indicate a time point at which the server sends the second authentication request instruction; calculate a time difference value between the first time stamp and a second time stamp, wherein the second time stamp is used to indicate a time point at which the external device receives the second authentication request instruction; and in a case where the time difference value is less than a preset time threshold, encrypt the challenge code and the second identification code contained in the second authentication request instruction to obtain the response code.
[0221] Optionally, the identification code sending module is further configured to generate the second identification code based on a target parameter of the target device, wherein the target parameter is a parameter uniquely corresponding to the target device; and encrypt the first hardware information set and the second identification code by using the second key to obtain the first identification code.
[0222] Optionally, the identification code sending module is further configured to send the target parameter of the target device to an identification code generation module, wherein the identification code generation module is configured to encrypt data to generate an identification code; receive the second identification code sent by the identification code generation module; send the first hardware information set of the target device to the identification code generation module; and receive the first identification code, wherein the first identification code is generated by the identification code generation module by using the second key.
[0223] The features of the embodiments of the device authentication apparatus can be referred to the related descriptions of the embodiments of the device authentication method, which will not be repeated here.
[0224] The embodiments of the present application further provide an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any of the above-mentioned device authentication method embodiments.
[0225] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program, wherein the computer program is arranged to execute the steps in any of the above-mentioned device authentication method embodiments when running.
[0226] In an example embodiment, the above-mentioned computer readable storage medium can include, but is not limited to, a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.
[0227] The embodiment of the present application further provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the steps in any of the above-mentioned device authentication method embodiments.
[0228] The embodiment of the present application further provides another computer program product, which comprises a non-volatile computer readable storage medium, and the non-volatile computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps in any of the above-mentioned device authentication method embodiments.
[0229] The skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in general terms in the above description. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0230] The above provides a detailed introduction to the device authentication method and device, storage medium and electronic device provided by the present application. The principles and implementation modes of the present application are described by applying specific examples in this paper, and the above example description is only used to help understand the method and core idea of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, some improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A device authentication method, characterized in that: For servers, including: Receiving a first identification code and a second identification code sent by an external device, wherein the first identification code is used to indicate hardware information of a target device, and the second identification code is used to indicate the target device; Determining a first key based on the second identification code, and decrypting the first identification code using the first key to obtain a first hardware information set of the target device, wherein the first hardware information set includes at least one hardware information of the target device; comparing the first hardware information set and the second hardware information set, and determining that the external device has passed authentication if the first hardware information set and the second hardware information set are consistent, wherein the second hardware information set includes at least one hardware information of the external device; After determining that the external device passes the authentication, the method further includes: If a preset authentication condition is met, sending a second authentication request instruction to the external device, wherein the second authentication request instruction includes a challenge code, and the challenge code is a random data sequence of a preset number of bits; receiving a response code sent by the external device, wherein the response code is obtained by encrypting the challenge code and the second identification code by the external device; The response code is decrypted to obtain first information and second information. If the first information is consistent with the challenge code and the second information is consistent with the second identification code, it is determined that the external device has passed the current authentication.
2. The method according to claim 1, characterized in that Before receiving the first identification code and the second identification code sent by the external device, the method includes: Sending a first authentication request instruction to the external device, wherein the first authentication request instruction includes identity information of the server, the identity information is used to indicate the server and to confirm whether the server is included in a list of servers to which the external device can connect; Receive the first identification code and the second identification code sent by the external device.
3. The method according to claim 1, characterized in that The receiving a response code sent by the external device includes: receiving a response code sent by the external device, wherein the response code is obtained by the external device encrypting the challenge code and the second identification code using the first identification code; Decrypting the response code to obtain the first information and the second information includes: The response code is decrypted using the first identification code to obtain the first information and the second information.
4. The method according to claim 1, wherein Before receiving the first identification code and the second identification code sent by the external device, the method includes: sending a third key to the external device, wherein the third key is used to encrypt data; The receiving a response code sent by the external device includes: receiving a response code sent by the external device, wherein the response code is obtained by the external device encrypting the challenge code and the second identification code using the third key; Decrypting the response code to obtain the first information and the second information includes: The response code is decrypted using the third key to obtain the first information and the second information.
5. The method according to any one of claims 1 to 4, characterized in that The sending a second authentication request instruction to the external device includes: A second authentication request instruction is sent to the external device, wherein the second authentication request instruction further includes a first timestamp, the first timestamp is used to indicate the time point when the second authentication request instruction is sent, and is used to compare with the second timestamp to determine whether the server passes the authentication, and the second timestamp is used to indicate the time point when the external device receives the second authentication request instruction.
6. The method according to any one of claims 1 to 4, characterized in that The sending of a second authentication request instruction to the external device when a preset authentication condition is met includes one of the following: When the current time point is the preset time point, sending the second authentication request instruction to the external device; When a change rate of at least one performance parameter of the server is greater than a preset change rate, sending the second authentication request instruction to the external device; When a first prompt appears on the server, sending the second authentication request instruction to the external device, wherein the first prompt is used to indicate that an error occurs in the system of the server; When the server receives the detection instruction, it sends the second authentication request instruction to the external device.
7. The method according to any one of claims 1 to 4, characterized in that When the first hardware information set and the second hardware information set are consistent, determining that the external device has passed the authentication includes at least one of the following: If the first character string matches the second character string, determining that the external device has passed the authentication, wherein the first character string is used to indicate the target device and the second character string is used to indicate the external device; If the first parameter and the second parameter are consistent, determining that the external device has passed the authentication, wherein the first parameter is used to indicate the hardware parameters of the target device, and the second parameter is used to indicate the hardware parameters of the external device; If the first information and the second information are compared and passed, it is determined that the external device has passed the authentication, wherein the first information is binary data and is used to indicate the hardware parameters of the target device, and the second information is binary data and is used to indicate the hardware parameters of the external device.
8. A device authentication method, characterized in that: For external devices, including: Sending a first identification code and a second identification code to a server, wherein the first identification code is used to indicate hardware information of a target device, the second identification code is used to indicate the target device and to determine a first key, the first key is used to decrypt the first identification code to obtain a first hardware information set of the target device, the first hardware information set is used to include at least one piece of hardware information of the target device and is used to compare with the second hardware information set to determine whether the external device is authenticated, and the second hardware information set includes at least one piece of hardware information of the external device; After sending the first identification code and the second identification code to the server, the method further includes: receiving a second authentication request instruction sent by the server, and encrypting the challenge code and the second identification code contained in the second authentication request instruction to obtain a response code, wherein the challenge code is a random data sequence of a preset number of bits; The response code is sent to the server, wherein the response code is used to identify whether the external device passes the current authentication.
9. The method according to claim 8, characterized in that Before sending the first identification code and the second identification code to the server, the method includes: receiving a first authentication request instruction sent by the server, wherein the first authentication request instruction includes identity information of the server, and the identity information is used to indicate the server; A preset information set is queried, and when the preset information set includes the identity information, the first identification code and the second identification code are sent to the server, wherein the preset information set is used to indicate a list of servers to which the external device can connect.
10. The method according to claim 8, characterized in that The step of encrypting the challenge code and the second identification code included in the second authentication request instruction to obtain a response code includes: The challenge code and the second identification code are encrypted using the first identification code to obtain the response code.
11. The method according to claim 8, characterized in that Before sending the first identification code and the second identification code to the server, the method includes: receiving a third key sent by the server, wherein the third key is used to encrypt data; The step of encrypting the challenge code and the second identification code included in the second authentication request instruction to obtain a response code includes: The challenge code and the second identification code are encrypted using the third key to obtain the response code.
12. The method according to any one of claims 8 to 11, characterized in that The receiving the second authentication request instruction sent by the server, and encrypting the challenge code and the second identification code included in the second authentication request instruction to obtain a response code, includes: Receiving a second authentication request instruction sent by the server, wherein the second authentication request instruction further includes a first timestamp, and the first timestamp is used to indicate the time point when the server sends the second authentication request instruction; Calculate the time difference between the first timestamp and the second timestamp. If the time difference is less than a preset time threshold, encrypt the challenge code and the second identification code included in the second authentication request instruction to obtain a response code, wherein the second timestamp is used to indicate the time point when the external device receives the second authentication request instruction.
13. The method according to any one of claims 8 to 11, characterized in that Before sending the first identification code and the second identification code to the server, the method includes: generating the second identification code based on a target parameter of the target device, wherein the target parameter is a parameter uniquely corresponding to the target device; The first hardware information set and the second identification code are encrypted using a second key to obtain the first identification code.
14. The method according to claim 13, characterized in that The generating the second identification code based on the target parameter of the target device includes: Sending the target parameters of the target device to an identification code generation module, wherein the identification code generation module is used to encrypt the data to generate an identification code; receiving a second identification code sent by the identification code generation module; The step of encrypting the first hardware information set and the second identification code using the second key to obtain the first identification code includes: Sending the first hardware information set of the target device to the identification code generation module; The first identification code is received, wherein the first identification code is generated by the identification code generation module using the second key.
15. A device authentication apparatus, characterized in that: For servers, including: an identification code receiving module, configured to receive a first identification code and a second identification code sent by an external device, wherein the first identification code is used to indicate hardware information of a target device, and the second identification code is used to indicate the target device; a decryption module, configured to determine a first key based on the second identification code, and decrypt the first identification code using the first key to obtain a first hardware information set of the target device, wherein the first hardware information set includes at least one piece of hardware information of the target device; a first authentication module, configured to compare the first hardware information set and a second hardware information set, and determine that the external device has passed authentication if the first hardware information set and the second hardware information set are consistent, wherein the second hardware information set includes at least one piece of hardware information of the external device; A second authentication module is configured to send a second authentication request instruction to the external device when a preset authentication condition is met, wherein the second authentication request instruction includes a challenge code, and the challenge code is a random data sequence of a preset number of bits; receiving a response code sent by the external device, wherein the response code is obtained by encrypting the challenge code and the second identification code by the external device; The response code is decrypted to obtain first information and second information. If the first information is consistent with the challenge code and the second information is consistent with the second identification code, it is determined that the external device has passed the current authentication.
16. A device authentication apparatus, characterized in that: For external devices, including: an identification code sending module, configured to send a first identification code and a second identification code to a server, wherein the first identification code is used to indicate hardware information of a target device, the second identification code is used to indicate the target device and is used to determine a first key, the first key is used to decrypt the first identification code to obtain a first hardware information set of the target device, the first hardware information set is used to include at least one piece of hardware information of the target device and is used to compare with the second hardware information set to determine whether the external device has passed authentication, and the second hardware information set includes at least one piece of hardware information of the external device; a response code generation module, configured to receive a second authentication request instruction sent by the server, and encrypt the challenge code and the second identification code included in the second authentication request instruction to obtain a response code, wherein the challenge code is a random data sequence of a preset number of bits; The response code is sent to the server, wherein the response code is used to identify whether the external device passes the current authentication.
17. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the device authentication method according to any one of claims 1 to 14 when executing the computer program.
18. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the steps of the device authentication method according to any one of claims 1 to 14 are implemented.
Citation Information
Patent Citations
USB Device Verification System and Method
CN102289607A
Authentication method and system for vehicle ODB diagnosis
CN116893660A