USB equipment authentication method and device based on USB enumeration time sequence characteristics and storage medium

By extracting the characteristics of the USB device enumeration stage and building a multi-layer authentication mechanism, the problem of identity verification before USB device access is solved, timely and accurate identity authentication is achieved, and the security and stability of the device access process are improved.

CN120688048AActive Publication Date: 2025-09-23XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510770836.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-09-23
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

In the prior art, USB devices cannot be authenticated before being connected to a computer system, which results in illegal devices disguising and tampering with their identities, thereby reducing the security of the computer system or terminal device.

Method used

By extracting the global features, intra-stage features, dynamic timing features and event sequence features of the USB device enumeration stage, the static feature layer, dynamic behavior layer and protocol logic layer are constructed, and identity authentication is performed in sequence to ensure that the USB device complies with the USB protocol requirements.

Benefits of technology

This technology implements identity authentication before a USB device is connected to a host, improves the timeliness and accuracy of authentication, avoids the impersonation or identity tampering of illegal devices, and enhances the security and robustness of the device access process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120688048A_ABST
    Figure CN120688048A_ABST
Patent Text Reader

Abstract

The invention discloses a USB equipment authentication method and device based on USB enumeration time sequence characteristics and a storage medium, and the method comprises the steps: extracting global characteristics, intra-stage characteristics, dynamic time sequence characteristics and event sequence characteristics of USB equipment in an enumeration stage under the condition that the USB equipment and a host enter the enumeration stage; determining a static feature layer, a dynamic behavior layer and a protocol logic layer based on the global feature, the intra-stage feature, the dynamic time sequence feature and the event sequence feature; and performing identity authentication on the USB equipment based on the protocol logic layer, the static feature layer and the dynamic behavior layer in sequence. According to the invention, before the USB equipment is accessed to the host, the identity verification of the USB equipment can be completed, so that the identity disguising or tampering of illegal equipment before the illegal equipment is accessed to the host is effectively avoided, and the timeliness and accuracy of the identity verification of the USB equipment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of device authentication, and in particular relates to a USB device authentication method, device and storage medium based on USB enumeration timing characteristics. Background Art

[0002] Universal Serial Bus (USB) devices, as convenient and efficient external storage tools, are widely used in various fields, including data storage and backup, file transfer and sharing. Mobile storage device authentication is a key method for ensuring the authenticity and legitimacy of USB devices when connected to computer systems or terminal devices. This prevents unauthorized devices from forging identities and accessing the system, thereby ensuring the security of computer systems and terminal devices.

[0003] Mobile storage device authentication involves verifying the legitimacy of a USB device connected to a computer system or terminal device by authenticating the device. Typically, this is done by verifying the USB device's hardware features or physical characteristics to confirm its legitimacy. However, these hardware and physical characteristics are only accessible after the USB device is connected to the computer system or terminal device. This means that if the USB device is not authenticated beforehand, it can be disguised and tampered with by an unauthorized device, potentially allowing it to mistakenly pass authentication and compromise the security of the computer system or terminal device.

[0004] Therefore, how to improve the timeliness and accuracy of USB device authentication is a technical problem that urgently needs to be solved. Summary of the Invention

[0005] To address the issue of low timeliness and accuracy in USB device authentication, the present invention provides a USB device authentication method, apparatus, and readable storage medium based on USB enumeration timing characteristics. The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0006] The present invention provides a USB device authentication method based on USB enumeration timing characteristics, which is applied to a host and includes:

[0007] When the USB device and the host enter the enumeration phase, the global features, intra-phase features, dynamic timing features, and event sequence features of the USB device in the enumeration phase are extracted. The global features are used to reflect the response rate of the USB device in the enumeration phase. The intra-phase features are used to reflect the behavior pattern and resource scheduling characteristics of the USB device in the enumeration phase. The dynamic timing features are used to reflect the time interval and response delay changes of communication events between the USB device and the host in the enumeration phase. The event sequence features are used to reflect the sequential nature of communication events between the USB device and the host in the enumeration phase.

[0008] Based on global features, intra-stage features, dynamic timing features, and event sequence features, a static feature layer, a dynamic behavior layer, and a protocol logic layer are constructed. The static feature layer is used to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements of the USB protocol. The dynamic behavior layer is used to verify whether the feature score of the USB device meets the standard. The protocol logic layer is used to verify whether the USB device complies with the USB protocol.

[0009] The USB device is authenticated based on the protocol logic layer, static feature layer and dynamic behavior layer in sequence.

[0010] In one embodiment of the present invention, when a USB device and a host enter an enumeration phase, global features, intra-phase features, dynamic timing features, and event sequence features of the USB device in the enumeration phase are extracted, including:

[0011] When the USB device and the host enter the enumeration phase, the entire enumeration phase is divided into the first event phase, the second event phase, the third event phase, and the fourth event phase. The first event phase is used to indicate the start of the enumeration phase, the second event phase is used to indicate that the USB device enters the recognizable state, the third event phase is used to indicate that the USB device enters the usable state, and the fourth event phase is used to indicate the end of the enumeration phase.

[0012] Obtaining a total enumeration duration and a time interval between adjacent event phases; determining the total enumeration duration and the time interval between adjacent event phases as global characteristics of the USB device;

[0013] Obtaining a first sending time T1 of the last sending of a SET_FEATURE request in the first event phase, an operation time H of the USB device in the second event phase, a target number F of sending CLEAR_FEATURE requests in the second event phase, a second sending time T2 of the last sending of a CLEAR_FEATURE request in the second event phase, a target number N of sending GET DESCRIPTOR requests in the third event phase, a target response time T3 of the USB device responding to a SET CONFIGURATION request in the third event phase, and a third sending time T4 of sending a GET MAX LUN request in the fourth event phase; and determining the first sending time T1, the operation time H, the target number F, the second sending time T2, the target number N, the target response time T3, and the third sending time T4 as intra-phase features of the USB device;

[0014] Obtaining a command rate and response characteristic S1 and a command processing jitter time S2, and determining the command rate and response characteristic S1 and the command processing jitter time S2 as dynamic timing characteristics of the USB device. The command rate and response characteristic S1 is used to reflect the frequency of the host sending corresponding requests and the time interval between sending each request in each event stage. The command processing jitter time S2 is used to reflect the random fluctuation of the response delay when the USB device responds to the same request;

[0015] An event sequence consistency C is obtained and determined as an event sequence feature of the USB device. The event sequence consistency C is used to reflect the sequence of the first event stage, the second event stage, the third event stage, and the fourth event stage.

[0016] In one embodiment of the present invention, based on global features, intra-stage features, dynamic timing features, and event sequence features, a static feature layer, a dynamic behavior layer, and a protocol logic layer are constructed, including:

[0017] Determine global features and intra-stage features as static feature layers;

[0018] Determine the dynamic temporal characteristics as the dynamic behavior layer;

[0019] Characterize the sequence of events into the protocol's logical layers.

[0020] In one embodiment of the present invention, the USB device is authenticated based on the protocol logic layer, the static feature layer, and the dynamic behavior layer, including:

[0021] When the USB device passes the verification of the protocol logic layer, the static feature layer, and the dynamic behavior layer in sequence, the USB device is determined to be a legitimate device;

[0022] In the case that the USB device fails to pass any one of the verifications at the protocol logic layer, the static feature layer, and the dynamic behavior layer, the USB device is determined to be an illegal device.

[0023] In one embodiment of the present invention, the protocol logic layer includes an L-dimensional vector, and performing identity authentication on the USB device based on the protocol logic layer includes:

[0024] Obtain each request sent by the host during the enumeration phase in turn, and compare each obtained request with the corresponding reference request in turn;

[0025] If the type of each request is consistent with the type of the corresponding reference request and the character length of each request is consistent with the character length of the corresponding reference request, determining that the USB device passes the verification;

[0026] If a request type is inconsistent with a corresponding reference request type, or a request character length is inconsistent with a corresponding reference request character length, it is determined that the USB device fails the authentication.

[0027] In one embodiment of the present invention, the static feature layer includes an M-dimensional feature vector, and the identity authentication of the USB device based on the static feature layer includes:

[0028] The M-dimensional feature vector of the static feature layer is input into the trained multi-layer perceptron to obtain the verification result of the USB device output by the multi-layer perceptron.

[0029] In one embodiment of the present invention, the dynamic behavior layer includes a K-dimensional feature vector, and the identity authentication of the USB device based on the dynamic behavior layer includes:

[0030] The weight of each eigenvector in the dynamic behavior layer is calculated by principal component analysis method;

[0031] Normalizing each eigenvector in the dynamic behavior layer to obtain a normalized eigenvector corresponding to each eigenvector in the dynamic behavior layer;

[0032] Based on the weight of each feature vector in the dynamic behavior layer and the normalized feature vector corresponding to each feature vector, a feature score of the USB device is calculated;

[0033] If the feature score of the USB device is within the score threshold, it is determined that the USB device passes the verification; otherwise, it fails the verification.

[0034] In one embodiment of the present invention, the calculation formula for calculating the feature score of a USB device is:

[0035]

[0036] Among them, Score is the feature score of USB device, w s is the weight of the Sth eigenvector in the K-dimensional eigenvector, f s is the normalized eigenvector corresponding to the Sth eigenvector.

[0037] Another aspect of the present invention provides a USB device authentication device based on USB enumeration timing characteristics, which is applied to a host, and includes:

[0038] an extraction module for extracting, when the USB device and the host enter the enumeration phase, global features, intra-phase features, dynamic timing features, and event sequence features of the USB device during the enumeration phase, wherein the global features are used to reflect the response rate of the USB device during the enumeration phase, the intra-phase features are used to reflect the behavior pattern and resource scheduling characteristics of the USB device during the enumeration phase, the dynamic timing features are used to reflect the time interval and response delay changes of communication events between the USB device and the host during the enumeration phase, and the event sequence features are used to reflect the sequential nature of communication events between the USB device and the host during the enumeration phase;

[0039] a determination module, configured to determine a static feature layer, a dynamic behavior layer, and a protocol logic layer based on global features, intra-stage features, dynamic timing features, and event sequence features, wherein the static feature layer is configured to verify whether the hardware features of the USB device meet the hardware feature requirements of the USB protocol, the dynamic behavior layer is configured to verify whether the feature score of the USB device meets the standard, and the protocol logic layer is configured to verify whether the USB device complies with the USB protocol;

[0040] The authentication module is used to authenticate the USB device based on the protocol logic layer, static feature layer and dynamic behavior layer in sequence.

[0041] Another aspect of the present invention provides a storage medium storing a computer program for executing the steps of the USB device authentication method based on USB enumeration timing characteristics described in any one of the above embodiments.

[0042] Another aspect of the present invention provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the USB device authentication method based on USB enumeration timing characteristics as described in any of the above embodiments are implemented.

[0043] Compared with the prior art, the present invention has the following beneficial effects:

[0044] 1. The USB device authentication method based on USB enumeration timing features provided by the present invention extracts global features, intra-stage features, dynamic timing features, and event sequence features of the USB device enumeration stage, and uses the global features, intra-stage features, dynamic timing features, and event sequence features to verify whether the USB device is a legitimate device. This enables the authentication of the USB device to be completed before the USB device is connected to the host, thereby effectively preventing illegal devices from disguising or tampering with their identities before connecting to the host, and improving the timeliness of USB device identity authentication.

[0045] 2. The present invention authenticates the USB device by extracting various features during the USB enumeration phase. Since these features are extracted during the natural interaction between the USB device and the host, they are highly stable and do not rely on dedicated components. Therefore, even under different environmental conditions, the extracted features can maintain consistency and reliability, thereby avoiding the instability caused by aging of dedicated components and environmental changes, and improving the robustness and reliability of USB device authentication.

[0046] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 This is a flowchart of a USB device authentication method based on USB enumeration timing characteristics provided by an embodiment of the present invention;

[0048] Figure 2 This is a schematic diagram of a layered architecture of USB device features provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0049] In order to further illustrate the technical means and effects adopted by the present invention to achieve the predetermined purpose of the invention, the following is a detailed description of a USB device authentication method based on USB enumeration timing characteristics proposed in accordance with the present invention, in conjunction with the accompanying drawings and specific implementation methods.

[0050] The aforementioned and other technical contents, features, and effects of the present invention are clearly presented in the following detailed description of the specific embodiments in conjunction with the accompanying drawings. Through the description of the specific embodiments, a deeper and more specific understanding of the technical means and effects adopted by the present invention to achieve the intended purpose can be obtained. However, the accompanying drawings are provided for reference and illustration purposes only and are not intended to limit the technical solutions of the present invention.

[0051] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations are intended to cover non-exclusive inclusion, such that an article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the article or device comprising the element.

[0052] The present invention aims to solve the problem of low timeliness and accuracy of USB device identity authentication and provides a USB device authentication method based on USB enumeration timing characteristics. Figure 1 , the method comprises the following steps:

[0053] S1: When the USB device and the host enter the enumeration phase, the global features, intra-phase features, dynamic timing features, and event sequence features of the USB device in the enumeration phase are extracted.

[0054] Among them, the global feature is used to reflect the response rate of the USB device during the enumeration phase; the intra-phase feature is used to reflect the behavior pattern and resource scheduling characteristics of the USB device during the enumeration phase; the dynamic timing feature is used to reflect the time interval and response delay changes of communication events between the USB device and the host during the enumeration phase; and the event sequence feature is used to reflect the sequential nature of communication events between the USB device and the host during the enumeration phase.

[0055] The enumeration phase refers to the process by which a host identifies and configures a USB device when it is first connected to a host (such as a computer or terminal device). In other words, the enumeration phase is essentially the process by which the USB device and the host complete status negotiation, resource configuration, and function initialization through standard control transmission. It should be noted that the prior art authenticates the identity of a USB device only after the USB device is connected to the host, meaning that the identity of the USB device can only be authenticated after the USB device and the host have completed the enumeration phase. The present invention, however, authenticates the identity of the USB device after the USB device and the host have entered the enumeration phase, i.e., before the USB device is connected to the host. This effectively prevents unauthorized devices from disguising or tampering with the USB device's identity before it connects to the host, thereby improving the timeliness of USB device identity authentication.

[0056] Specifically, when the USB device and the host enter the enumeration phase, the entire enumeration phase can be divided into a first event phase (also known as a port connection detection phase), a second event phase (also known as a port reset phase), a third event phase (also known as a USB device configuration phase), and a fourth event phase (also known as a logical unit query) in terms of process flow by detecting request operations in the enumeration traffic. The first event phase indicates the start of the enumeration phase, the second event phase indicates the USB device enters a recognizable state, the third event phase indicates the USB device enters a usable state, and the fourth event phase indicates the end of the enumeration phase.

[0057] It should be noted that in the first event phase, the host detects the physical connection status of the USB device by sending requests such as GET_STATUS, URB_INTERRUPT, and CLEAR_FEATURE. This event marks the start of the enumeration phase, which clears the port's connection change flag to ensure that the host can identify newly connected USB devices. In the second event phase, the host forces the USB device to enter its default state by sending requests such as SET_FEATURE. It then sends a CLEAR_FEATURE request to clear the port's status flag after the reset. This verifies the hardware integrity of the USB device and makes it identifiable (addressable). In the third event phase, the host obtains the USB device descriptor (which includes the vendor ID, product ID, and product information) by sending requests such as GET_DESCRIPTOR, and completes interface configuration by sending requests such as SET_CONFIGURATION. This phase determines the function enabled state of the USB device, i.e., puts the USB device into an available state. In the fourth event phase, the host queries the number of GET MAX LUN requests sent, thereby concluding the enumeration phase at the protocol level with the USB device.

[0058] Furthermore, after the entire enumeration phase is divided into the first event phase, the second event phase, the third event phase and the fourth event phase in terms of process, the total enumeration duration and the time interval between adjacent event phases (also known as the inter-phase transition delay) can be obtained, and the total enumeration duration and the time interval between adjacent event phases can be determined as the global characteristics of the USB device.

[0059] The total enumeration duration refers to the time from when a USB device is connected to the host and the enumeration phase starts, to when the USB device completes the enumeration phase and enters a usable state. Specifically, it is the time difference between when the host sends the first (i.e., the first) GET_STATUS request (which marks the start of the enumeration phase) and when the host sends the last (i.e., the last) GET MAX LUN request. It should be noted that the total enumeration duration is not only a key metric for measuring USB device enumeration efficiency, but is also closely related to the USB device's hardware performance (such as the controller chip's clock frequency and bus bandwidth) and firmware optimization strategies (such as interrupt priority and resource scheduling). Furthermore, the total enumeration duration not only reveals the USB device's response speed but also indirectly reflects the complexity of USB device design and optimization.

[0060] The time interval between adjacent event phases is the time interval between the end of the previous phase and the start of the next phase, for example, the time interval between the end of the first event phase and the start of the second event phase. This time interval reflects the state switching responsiveness of the USB device and can effectively reveal the conversion efficiency of the USB device between multiple operation phases.

[0061] In an embodiment of the present invention, the first sending time T1 (also referred to as the last SET_FEATURE request time T1) of the host for the last time sending the SET_FEATURE request in the first event phase, the operation time H of the USB device in the second event phase (also referred to as the reset operation time H), the target number F of CLEAR_FEATURE requests sent by the host in the second event phase (also referred to as the status clearing request frequency F), the second sending time T2 (also referred to as the last CLEAR_FEATURE request time T2) of the host for the last time sending the CLEAR_FEATURE request in the second event phase, the target number N of GET DESCRIPTOR requests sent by the host in the third event phase (also referred to as the total descriptor transfer amount N), the target response time T3 (also referred to as the configuration request time T3) of the USB device responding to the SET CONFIGURATION request in the third event phase, and the target number F of GET DESCRIPTOR requests sent by the host in the fourth event phase. The third sending time T4 of the LUN request (also known as the logical unit query time T4), and the first sending time T1, operation time H, target number F, second sending time T2, target number N, target response time T3 and third sending time T4 are determined as the intra-stage characteristics of the USB device.

[0062] The first transmission time, T1, is the time when the host completes sending the last SET_FEATURE request during the first event phase. This time indicates that the host has completed confirming the USB device's physical connection status and triggering the necessary reset before entering the next phase. It reflects the latency from physical connection to reset preparation, and can reveal the USB device's responsiveness to changes in port connection status.

[0063] Operation duration H refers to the time it takes for the USB device to complete the reset process and become addressable during the second event phase, the port reset phase. Specifically, it is the time interval from the issuance of the first CLEAR_FEATURE request to the completion of the last SET_FEATURE request. This interval reflects the total time it takes for the USB device to complete the initial reset operation.

[0064] The target number F is the number of times the host sends CLEAR_FEATURE requests in the second event phase, that is, the port reset phase. This number reflects the number of operations that the USB device needs to perform due to state clearing in the port reset phase. More reset requests indicate that the USB device has redundant or complex internal processing logic when switching states, while fewer requests indicate that the USB device is more efficient when switching states.

[0065] The second sending time T2 is the completion time of the host sending the CLEAR_FEATURE request for the last time in the second event phase, that is, the port reset phase. This time point marks the end of the port reset phase and reflects the time it takes for the USB device to complete all status clearing during the reset process. Its timing characteristics can be used to evaluate the readiness of the USB device after the reset operation is completed.

[0066] The target number N refers to the total number of GETDESCRIPTOR requests sent by the host during the third event phase, the USB device configuration phase. The total number of these requests reflects the complexity of the USB device's information structure and the level of firmware implementation. A higher number of requests generally indicates a USB device with more functions, interfaces, or descriptors, demonstrating the device's complexity and resource configuration. The number of descriptor requests also correlates with enumeration efficiency and USB device initialization time, making it a crucial metric for evaluating USB device performance and firmware optimization.

[0067] The target response time T3 refers to the response time of the USB device in response to the SETCONFIGURATION request in the third event phase, that is, the USB device configuration phase. This time point marks the formal completion of the USB device configuration phase, that is, the USB device completes the descriptor transmission, driver loading and resource allocation, and enters the available (i.e., operational) state.

[0068] The third sending time T4 refers to the time when the host sends the GET MAX LUN request in the fourth event phase. This time point marks the end of the logical unit query phase, that is, the end of the enumeration phase, and the USB device enters the final usable state. This time point serves as the global enumeration end mark. Its timing characteristics can reveal the response delay of the USB device at the very end of the protocol, and also reflect the comprehensive processing speed of the USB device, such as memory initialization and driver loading.

[0069] In an embodiment of the present invention, the command rate and response characteristics S1 and the command processing jitter time S2 can also be obtained and determined as the dynamic timing characteristics of the USB device. The command rate and response characteristics S1 reflect the frequency of the host sending corresponding requests and the time interval between sending requests at each event stage, and the command processing jitter time S2 reflects the random fluctuations in the response delay when the USB device responds to the same request.

[0070] Among them, the time difference sequence between adjacent key commands (such as consecutive CLEAR_FEATURE requests or GETDESCRIPTOR requests) can be calculated and these intervals can be counted to quantify the command sending rate and stability. Specifically, in an embodiment of the present invention, a three-level quantitative index system can be constructed for the command rate and response feature S1, namely, the average response speed μ v , average command interval μ δ and timing stability σ cv , where the average response speed μ v Used to reflect the overall efficiency of USB device processing protocol commands, average command interval μ δ Used to reflect the benchmark level and timing stability of USB device response timing cv Used to quantify the degree of fluctuation in response time.

[0071] Specifically, calculate the average response speed μ v The calculation formula is:

[0072]

[0073] Among them, N c The total number of requests completed for the USB device, T tol is the total enumeration time, t start The time when the host sends the first GET_STATUS request, t end Time when the host sent the last GET MAX LUN request.

[0074] It should be noted that the standard command interval defined by the USB protocol specification is 1ms to 10ms. The actual USB device will have a slight offset due to differences in clock accuracy. The average command interval μ δ It can capture the clock cumulative error of the control chip, which is defined as the arithmetic mean of the response time difference of adjacent commands, and calculate the average command interval μ δ The calculation formula is:

[0075]

[0076] Where N′ is the collected time series {t1, t2, ..., t N} length, δ i is the time interval between the response of the i-th and i+1-th commands.

[0077] It should be noted that the timing stability σ cv The introduction of is to quantify the inherent regularity of response time fluctuations during protocol interaction, the timing stability σ cv The physical root of the stability lies in the time base accuracy of the USB device hardware circuit and the determinism of the firmware scheduling algorithm, which is defined as the coefficient of variation of the response time series, that is, the dimensionless ratio of the standard deviation to the mean, which is used to calculate the timing stability σ cv The calculation formula is:

[0078]

[0079] Among them, δ i is the time interval between the response of the ith and i+1th commands, μ δ is the average command interval, and n1 is the number of samples.

[0080] It's important to note that command processing jitter (S2) reflects timing fluctuations caused by physical variations in hardware circuitry during protocol interaction. The essence of timing jitter stems from phase noise in the USB device's internal clock signal, the modulation of logic gate delays by power supply ripple, and the randomness of the firmware's interrupt response mechanism. These microscopic fluctuations are non-stationary and nonlinear, requiring specific analytical methods to effectively characterize.

[0081] In the embodiment of the present invention, dynamic capture can be achieved by directly analyzing the timing data and extracting local features in the continuous timing, and timing jitter can be quantified by directly calculating the timing fluctuation through global analysis. mean and jitter intensity J inten Specifically, the timing jitter J mean It is expressed as the change of each command interval, and the jitter intensity J inten It is to quantify the sudden abnormal energy in timing fluctuations. Its core value lies in revealing the nonlinear disturbances hidden in the hardware system.

[0082] Specifically, the timing jitter can be quantified by the fluctuation of δi. The calculation formula for timing jitter is:

[0083]

[0084] Where n2 is the total number of command intervals, δ i is the time interval between the response of the ith and the (i+1)th command, and μ is the global mean, which represents the baseline stability of timing fluctuations.

[0085] Specifically, the sudden fluctuation, i.e., the jitter intensity, can be quantified by calculating the second-order moment statistics of the timing fluctuation. The jitter intensity J is calculated as inten The calculation formula is:

[0086]

[0087] Where n2 is the total number of command intervals, δi is the time interval between the i-th and i+1-th command responses, and μ is the global mean, which represents the baseline stability of timing fluctuations.

[0088] In an embodiment of the present invention, an event sequence consistency C may be obtained and determined as an event sequence feature of the USB device. The event sequence consistency C is used to reflect the sequence of the first event stage, the second event stage, the third event stage, and the fourth event stage.

[0089] It should be noted that Event Sequence Consistency C can analyze the order of events in the enumeration process of the USB standard protocol to determine whether the USB device strictly complies with the USB protocol. For example, the standard enumeration process should appear in the order of the GET_STATUS request, URB_INTERRUPT request, SET_FEATURE request, CLEAR_FEATURE request, GET_DESCRIPTOR request, SET_CONFIGURATION request, and GETMAX LUN request.

[0090] S2: Based on global features, intra-stage features, dynamic timing features, and event sequence features, we build the static feature layer, dynamic behavior layer, and protocol logic layer.

[0091] Among them, the static feature layer is used to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements in the USB protocol, the dynamic behavior layer is used to verify whether the feature score of the USB device meets the standard, and the protocol logic layer is used to verify whether the USB device complies with the USB protocol.

[0092] It should be noted that the USB protocol stack itself has a strict layered architecture, which determines the natural layered properties of USB device features. The embodiment of the present invention can decouple the hardware-related features, firmware scheduling features, and protocol logic features of USB devices into different layers through layered processing. This decoupling is consistent with the working principle of USB devices and improves the physical interpretability of the feature space. Specifically, Figure 2 As shown, the embodiment of the present invention divides the characteristics of the USB device into three layers, namely the static characteristic layer, the dynamic behavior layer and the protocol logic layer.

[0093] Specifically, the global features and intra-stage features are determined as the static feature layer, that is, the total enumeration time, the time interval between adjacent event stages, the first sending time T1, the operation time H, the target number F, the second sending time T2, the target number N, the target response time T3 and the third sending time T4 are determined as the static feature layer; the dynamic timing features are determined as the dynamic behavior layer, that is, the command rate and response features S1 and the command processing jitter time S2 are determined as the dynamic behavior layer; the event sequence features are determined as the protocol logic layer, that is, the sequentiality of the first event stage, the second event stage, the third event stage and the fourth event stage (event sequence consistency C) is determined as the protocol logic layer.

[0094] It is understood that in the embodiment of the present invention, the static feature layer is normalized to obtain the M-dimensional feature vector Z S , where each eigenvector is a rational number, and each eigenvector corresponds to the total enumeration time T tol , the time interval T between adjacent event stages def , first sending time T1, operation time H, target number F, second sending time T2, target number N, target response time T3 and third sending time T4, that is, M-dimensional feature vector Z s =[T tol ,T def , T1, H, F, T2, N, T3, T4]. It can be seen from this that M is equal to 9 at this time. It should be noted that the size of M can be flexibly adjusted based on actual applications, that is, M can be greater than 9 or less than 9. The embodiment of the present invention does not specifically limit the size of M.

[0095] In the embodiment of the present invention, the dynamic behavior layer obtains a K-dimensional feature vector Z by normalization processing. d , where each eigenvector is a rational number, and each eigenvector corresponds to the above average response speed μ v , average command interval μ δ and timing stability σ cv , Timing Jitter mean and jitter intensity J inten , that is, the K-dimensional feature vector Zd =[μ v ,μ δ ,σ cv ,J mean ,J inten ]. It can be seen from this that K is equal to 5 at this time. Similarly, the size of K can be flexibly adjusted based on actual applications, that is, K can be greater than 5 or less than 5. The embodiment of the present invention does not specifically limit the size of K.

[0096] In the embodiment of the present invention, the protocol logic layer obtains an L-dimensional vector Z by normalization processing. f , where each eigenvector is a rational number, and each eigenvector corresponds to the request in each of the above event stages, that is, the L-dimensional vector Z f =[S1, S2, S3, S4, S5, S6, S7], where S1 is a GET_STATUS request, S2 is a URB_INTERRUPT request, S3 is a SET_FEATURE request, S4 is a CLEAR_FEATURE request, S5 is a GET_DESCRIPTOR request, S6 is a SET_CONFIGURATION request, and S7 is a GETMAX LUN request. As can be seen, L is equal to 7. Similarly, the size of L can be flexibly adjusted based on actual applications; that is, L can be greater than or less than 7. This embodiment of the present invention does not specifically limit the size of L.

[0097] Furthermore, after obtaining the M-dimensional feature vector Z S , K-dimensional feature vector Z d and the L-dimensional vector Z f Afterwards, a multi-modal concatenation strategy can be used to concatenate the feature vectors corresponding to each layer according to the physical meaning to obtain a fused feature vector:

[0098] F=[Z s ,Z d ,Z f ] T

[0099] Where F is the fusion feature vector, [·] T is the transpose operation.

[0100] S3: Authenticate the USB device based on the protocol logic layer, static feature layer, and dynamic behavior layer.

[0101] Specifically, when the USB device passes the verification of the protocol logic layer, the static feature layer and the dynamic behavior layer in sequence, the USB device is determined to be a legal device; when the USB device fails to pass any of the verifications of the protocol logic layer, the static feature layer and the dynamic behavior layer, the USB device is determined to be an illegal device.

[0102] In an embodiment of the present invention, the identity authentication of a USB device is performed based on the protocol logic layer, specifically comprising the following steps:

[0103] S3.1: Obtain each request sent by the host during the enumeration phase in sequence, and compare the obtained request with the corresponding reference request in sequence.

[0104] S3.2: When the type of each request is consistent with the type of the corresponding reference request and the character length of each request is consistent with the character length of the corresponding reference request, determine that the USB device passes the verification.

[0105] Specifically, during protocol logic layer verification, the state machine model in the USB protocol specification is utilized, employing a dual-pointer traversal approach to strictly match the command sequence (i.e., request sequence) during the USB device enumeration phase, ensuring that the USB device's command sequence is consistent with the standard process (i.e., the reference request sequence in the reference mode). Only when the state machine model outputs a 1—that is, only when the type of each request matches the type of the corresponding reference request, and the character length of each request matches the character length of the corresponding reference request—is the USB device considered verified and then proceeds to subsequent authentication operations, i.e., continuing to authenticate the USB device based on the static feature layer.

[0106] S3.3: If a request type is inconsistent with a corresponding reference request type, or a request character length is inconsistent with a corresponding reference request character length, determine that the USB device fails verification.

[0107] Specifically, when the state machine model outputs 0, it is determined that the USB device fails the verification, and subsequent authentication operations are stopped.

[0108] In an embodiment of the present invention, the identity authentication of a USB device is performed based on the static feature layer, specifically comprising the following steps:

[0109] S3.4: Input the M-dimensional feature vector of the static feature layer into the trained multi-layer perceptron to obtain the verification result of the USB device output by the multi-layer perceptron.

[0110] Among them, Multilayer Perceptron (MLP), as a deep learning model, can transmit information and extract features through multiple levels of neurons, effectively capturing the potential patterns in USB device behavior.

[0111] In an embodiment of the present invention, the M-dimensional feature vector is normalized and used as the input of a trained MLP model so that the model outputs a legitimacy prediction label of the USB device, and whether the USB device is a legal device is determined by the predicted label.

[0112] It should be noted that in order to improve the accuracy and robustness of USB device authentication, in an embodiment of the present invention, the MLP model adopts a multi-layer structure, each layer contains multiple neurons, and the neurons perform nonlinear transformations on the input features through activation functions. The input layer receives an M-dimensional static feature vector and passes it to multiple hidden layers for feature mapping and complex pattern learning. The output of each layer serves as the input of the next layer, and ultimately the classification decision is made through the output layer. In order to enhance the nonlinear expression ability of the network and avoid the gradient vanishing problem, ReLU is selected as the activation function. The output layer uses the sigmoid activation function for binary classification, and the output value is in the range of [0,1], where the predicted label 1 indicates that the USB device is a legal device, and the predicted label 0 indicates that the USB device is an illegal device. The training of the MLP model uses the cross-entropy loss function, which can effectively measure the difference between the predicted label output by the MLP model and the true label. After training is completed, after evaluation on the validation set and the test set, the MLP model can accurately determine the legitimacy of different USB device identities.

[0113] In an embodiment of the present invention, the identity authentication of a USB device is performed based on the dynamic feature layer, specifically comprising the following steps:

[0114] S3.5: Calculate the weight of each feature vector in the dynamic feature layer by using the principal component analysis (PCA) method.

[0115] Specifically, PCA calculates the covariance matrix between each eigenvector in the dynamic feature layer, extracts the principal components (eigenvectors), and determines the weight of each eigenvector according to the variance contribution of each principal component.

[0116] It should be noted that the "weight" here can be understood as the relative size of the eigenvalue corresponding to each eigenvector. It reflects the ability of the corresponding principal component to explain the variability of the data. A larger eigenvalue means that the corresponding eigenvector is more important.

[0117] S3.6: Perform normalization processing on each feature vector in the dynamic behavior layer to obtain a normalized feature vector corresponding to each feature vector in the dynamic behavior layer.

[0118] Specifically, by using the Z-Score standardization method, the mean and standard deviation of each feature dimension are calculated, and the original feature value is converted into a standard value with a mean of 0 and a standard deviation of 1, thereby obtaining a standardized feature vector corresponding to each feature vector in the dynamic behavior layer.

[0119] S3.7: Calculate a feature score of the USB device based on the weight of each feature vector in the dynamic behavior layer and the normalized feature vector corresponding to each feature vector.

[0120] Specifically, the calculation formula for calculating the feature score of a USB device is:

[0121]

[0122] Among them, Score is the feature score of USB device, w s is the weight of the Sth eigenvector in the K-dimensional eigenvector, f s is the normalized eigenvector corresponding to the Sth eigenvector.

[0123] S3.8: When the characteristic score of the USB device is within the score threshold [θ min ,θ max ], it is determined that the USB device passes the verification; otherwise, it fails the verification.

[0124] Among them, θ min Score the minimum characteristics of a legitimate device, θ max Score the maximum characteristics of legitimate devices.

[0125] It should be noted that the setting of the scoring threshold is based on the statistical analysis of historical data samples. By collecting time series data samples of multiple legal devices under standard working conditions, these samples are subjected to PCA feature extraction and weighted processing, and then the weighted score of each legal device is calculated. Finally, through statistical analysis of these score distributions, the score range of legal devices is determined.

[0126] It should be noted that the USB device authentication method based on USB enumeration timing characteristics provided by the embodiment of the present invention can complete attack detection during the enumeration stage when the attacker is unaware of the USB device model, thereby significantly limiting the amount of information exposed to the attacker. That is, the attacker cannot disguise or tamper with the identity before accessing the host, thereby improving the security of the host.

[0127] In summary, the USB device authentication method based on USB enumeration timing features provided by the embodiment of the present invention extracts the global features, intra-stage features, dynamic timing features, and event sequence features of the USB enumeration stage, and uses the global features, intra-stage features, dynamic timing features, and event sequence features to verify whether the USB device is a legitimate device. This achieves the completion of USB device identity authentication before the USB device is connected to the host, thereby effectively preventing illegal devices from disguising or tampering with their identities before connecting to the host, and improving the timeliness of USB device identity authentication.

[0128] In addition, the embodiment of the present invention authenticates the USB device by extracting various features during the USB enumeration phase. Since these features are extracted during the natural interaction between the USB device and the host, they are highly stable and do not rely on dedicated components. Therefore, even under different environmental conditions, the extracted features can maintain consistency and reliability, thereby avoiding the instability caused by aging of dedicated components and environmental changes, and improving the robustness and reliability of USB device authentication.

[0129] In addition, the embodiment of the present invention implements a multi-layer authentication mechanism through a hierarchical design, effectively ensuring the security of the USB device access process.

[0130] In the several embodiments provided herein, it should be understood that the apparatus and method disclosed herein can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the module division is merely a logical functional division. In actual implementation, other division methods may be used. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not implemented.

[0131] In addition, the functional modules in various embodiments of the present invention may be integrated into a single processing module, each module may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or hardware plus software functional modules.

[0132] Another embodiment of the present invention provides a USB device authentication apparatus based on USB enumeration timing characteristics, the apparatus being applied to a host and comprising:

[0133] an extraction module for extracting, when the USB device and the host enter the enumeration phase, global features, intra-phase features, dynamic timing features, and event sequence features of the USB device during the enumeration phase, wherein the global features are used to reflect the response rate of the USB device during the enumeration phase, the intra-phase features are used to reflect the behavior pattern and resource scheduling characteristics of the USB device during the enumeration phase, the dynamic timing features are used to reflect the time interval and response delay changes of communication events between the USB device and the host during the enumeration phase, and the event sequence features are used to reflect the sequential nature of communication events between the USB device and the host during the enumeration phase;

[0134] A construction module is used to construct a static feature layer, a dynamic behavior layer, and a protocol logic layer based on global features, intra-stage features, dynamic timing features, and event sequence features. The static feature layer is used to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements of the USB protocol. The dynamic behavior layer is used to verify whether the feature score of the USB device meets the standard. The protocol logic layer is used to verify whether the USB device complies with the USB protocol.

[0135] The authentication module is used to authenticate the USB device based on the protocol logic layer, static feature layer and dynamic behavior layer in sequence.

[0136] Yet another embodiment of the present invention provides a storage medium storing a computer program for executing the steps of the USB device authentication method based on USB enumeration timing characteristics described in the above embodiment.

[0137] Another aspect of the present invention provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor calls the computer program in the memory, it implements the steps of the USB device authentication method based on USB enumeration timing characteristics as described in the above embodiment. Specifically, the above-mentioned integrated module implemented in the form of a software function module can be stored in a computer-readable storage medium. The above-mentioned software function module is stored in a storage medium and includes a number of instructions for causing an electronic device (which can be a personal computer, server, or network device, etc.) or a processor to perform some steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc., various media that can store program code.

[0138] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A USB device authentication method based on USB enumeration timing characteristics, characterized in that: Applied to the host, including: When the USB device and the host enter an enumeration phase, extracting global features, intra-phase features, dynamic timing features, and event sequence features of the USB device during the enumeration phase, wherein the global features are used to reflect the response rate of the USB device during the enumeration phase, the intra-phase features are used to reflect the behavior pattern and resource scheduling characteristics of the USB device during the enumeration phase, the dynamic timing features are used to reflect the time interval and response delay changes of communication events between the USB device and the host during the enumeration phase, and the event sequence features are used to reflect the sequential nature of communication events between the USB device and the host during the enumeration phase; Based on the global features, the intra-stage features, the dynamic timing features, and the event sequence features, a static feature layer, a dynamic behavior layer, and a protocol logic layer are constructed, wherein the static feature layer is used to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements of the USB protocol, the dynamic behavior layer is used to verify whether the feature score of the USB device meets the standard, and the protocol logic layer is used to verify whether the USB device complies with the USB protocol; The USB device is authenticated based on the protocol logic layer, the static feature layer, and the dynamic behavior layer in sequence.

2. The USB device authentication method based on USB enumeration timing characteristics according to claim 1, characterized in that: When the USB device and the host enter the enumeration phase, extracting global features, intra-phase features, dynamic timing features, and event sequence features of the USB device in the enumeration phase includes: When the USB device and the host enter the enumeration phase, the entire enumeration phase is divided into a first event phase, a second event phase, a third event phase, and a fourth event phase in terms of process, wherein the first event phase is used to indicate the start of the enumeration phase, the second event phase is used to indicate that the USB device enters a recognizable state, the third event phase is used to indicate that the USB device enters a usable state, and the fourth event phase is used to indicate the end of the enumeration phase; Obtaining a total enumeration duration and a time interval between adjacent event phases; determining the total enumeration duration and the time interval between adjacent event phases as global features of the USB device; Obtaining a first sending time T1 of the last sending of a SET_FEATURE request in the first event phase, an operation time H of the USB device in the second event phase, a target number F of sending CLEAR_FEATURE requests in the second event phase, a second sending time T2 of the last sending of the CLEAR_FEATURE request in the second event phase, a target number N of sending GET DESCRIPTOR requests in the third event phase, a target response time T3 of the USB device responding to a SET CONFIGURATION request in the third event phase, and a third sending time T4 of sending a GET MAX LUN request in the fourth event phase; and determining the first sending time T1, the operation time H, the target number F, the second sending time T2, the target number N, the target response time T3, and the third sending time T4 as intra-phase features of the USB device; Obtaining a command rate and response characteristic S1 and a command processing jitter time S2, and determining the command rate and response characteristic S1 and the command processing jitter time S2 as dynamic timing characteristics of the USB device, wherein the command rate and response characteristic S1 is used to reflect the frequency of the host sending corresponding requests and the time interval between sending each request in each event stage, and the command processing jitter time S2 is used to reflect the random fluctuation of the response delay when the USB device responds to the same request; Acquire event sequence consistency C, and determine the event sequence consistency C as an event sequence feature of the USB device, wherein the event sequence consistency C is used to reflect the sequentiality of the first event stage, the second event stage, the third event stage, and the fourth event stage.

3. The USB device authentication method based on USB enumeration timing characteristics according to claim 1, characterized in that: The step of constructing a static feature layer, a dynamic behavior layer, and a protocol logic layer based on the global features, the intra-stage features, the dynamic timing features, and the event sequence features includes: Determine the global features and the intra-stage features as the static feature layer; Determining the dynamic time series feature as the dynamic behavior layer; The event sequence characteristics are determined as the protocol logic layer.

4. The USB device authentication method based on USB enumeration timing characteristics according to claim 1, characterized in that: The authenticating the USB device based on the protocol logic layer, the static feature layer, and the dynamic behavior layer in sequence includes: When the USB device passes verification of the protocol logic layer, the static feature layer, and the dynamic behavior layer in sequence, determining that the USB device is a legitimate device; If the USB device fails to pass any one of the verifications at the protocol logic layer, the static feature layer, and the dynamic behavior layer, the USB device is determined to be an illegal device.

5. The USB device authentication method based on USB enumeration timing characteristics according to claim 4, characterized in that: Authenticating the USB device based on the protocol logic layer includes: Sequentially obtaining each request sent by the host during the enumeration phase, and sequentially comparing the obtained request with the corresponding reference request; If the type of each request is consistent with the type of the corresponding reference request and the character length of each request is consistent with the character length of the corresponding reference request, determining that the USB device passes the verification; If a request type is inconsistent with a corresponding reference request type, or a request character length is inconsistent with a corresponding reference request character length, it is determined that the USB device fails verification.

6. The USB device authentication method based on USB enumeration timing characteristics according to claim 4, characterized in that: The static feature layer includes an M-dimensional feature vector, and authenticating the USB device based on the static feature layer includes: The M-dimensional feature vector of the static feature layer is input into a trained multi-layer perceptron to obtain a verification result of the USB device output by the multi-layer perceptron.

7. The USB device authentication method based on USB enumeration timing characteristics according to claim 4, characterized in that: The dynamic behavior layer includes a K-dimensional feature vector, and identity authentication of the USB device is performed based on the dynamic behavior layer, including: Calculating the weight of each eigenvector in the dynamic behavior layer by a principal component analysis method; performing normalization processing on each feature vector in the dynamic behavior layer to obtain a normalized feature vector corresponding to each feature vector in the dynamic behavior layer; Calculating a feature score of the USB device based on a weight of each feature vector in the dynamic behavior layer and a normalized feature vector corresponding to each feature vector; If the feature score of the USB device is within the score threshold, it is determined that the USB device passes the verification; otherwise, it fails the verification.

8. The USB device authentication method based on USB enumeration timing characteristics according to claim 7, characterized in that: The calculation formula for calculating the characteristic score of the USB device is: Among them, Score is the feature score of the USB device, w s is the weight of the Sth eigenvector in the K-dimensional eigenvector, f s is the normalized eigenvector corresponding to the Sth eigenvector.

9. A USB device authentication device based on USB enumeration timing characteristics, characterized in that: Applied to a host, the device includes: an extraction module configured to, when the USB device and the host enter an enumeration phase, extract global features, intra-phase features, dynamic timing features, and event sequence features of the USB device during the enumeration phase, wherein the global features are used to reflect the response rate of the USB device during the enumeration phase, the intra-phase features are used to reflect the behavior pattern and resource scheduling characteristics of the USB device during the enumeration phase, the dynamic timing features are used to reflect the time interval and response delay changes of communication events between the USB device and the host during the enumeration phase, and the event sequence features are used to reflect the sequential nature of communication events between the USB device and the host during the enumeration phase; a construction module, configured to construct a static feature layer, a dynamic behavior layer, and a protocol logic layer based on the global features, the intra-stage features, the dynamic timing features, and the event sequence features, wherein the static feature layer is configured to verify whether the hardware features of the USB device meet the hardware feature requirements of the USB protocol, the dynamic behavior layer is configured to verify whether the feature score of the USB device meets the standard, and the protocol logic layer is configured to verify whether the USB device complies with the USB protocol; An authentication module is used to authenticate the USB device based on the protocol logic layer, the static feature layer, and the dynamic behavior layer in sequence.

10. A storage medium storing a computer program, wherein: The computer program is used to execute the steps of the USB device authentication method based on USB enumeration timing characteristics according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • USB (Universal Serial Bus) equipment identification and authentication method based on transmission delay characteristic

    CN118246001A

  • Behavioral authentication of universal serial bus (USB) devices

    US10169567B1