USB device authentication method and device based on USB enumeration timing characteristics, and storage medium
By extracting features from the USB device enumeration phase and constructing a multi-layer authentication mechanism, the problem of USB device authentication before connection is solved, realizing the legitimacy verification of USB devices before connection to the host, and improving the timeliness and robustness of authentication.
Patent Information
- Application Number
- CN202510770836.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2045-06-10
Smart Images

Figure CN120688048B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of device authentication, and particularly relates to a USB device authentication method and device based on USB enumeration timing sequence characteristics and a storage medium. BACKGROUND
[0002] As a convenient and efficient external storage tool, a Universal Serial Bus (USB) device is widely used in many fields such as data storage and backup, file transmission and sharing. Among them, mobile storage device authentication is an important means to ensure the authenticity and legitimacy of the identity of the USB device when it accesses a computer system or a terminal device, which can prevent illegal devices from accessing the system by forging their identities, thereby protecting the security of the computer system and the terminal device.
[0003] The mobile storage device authentication method refers to verifying the identity of the USB device accessing the computer system or the terminal device to ensure the legitimacy of the device. Usually, the hardware features or physical characteristics of the USB device are verified to confirm whether it is a legitimate device. However, the hardware features and physical characteristics of the USB device need to be extracted after the device accesses the computer system or the terminal device, i.e., the identity of the USB device is not verified before it accesses the computer system, which provides an opportunity for illegal devices to disguise and tamper with their identities, thereby making illegal devices pass the identity verification and reducing the security of the computer system or the terminal device.
[0004] Therefore, how to improve the timeliness and accuracy of USB device identity authentication is a technical problem to be solved at present. SUMMARY
[0005] In view of the low timeliness and accuracy of USB device identity authentication, the present application provides a USB device authentication method and device based on USB enumeration timing sequence characteristics and a readable storage medium. The technical problem to be solved by the present application is realized by the following technical solutions:
[0006] The present application provides a USB device authentication method based on USB enumeration timing sequence characteristics, applied to a host, comprising:
[0007] In the case that the USB device and the host enter the enumeration phase, global features, in-phase features, dynamic timing features and event sequence features of the USB device in the enumeration phase are extracted, the global features are used to reflect the response rate of the USB device in the enumeration phase, the in-phase features are used to reflect the behavior mode and resource scheduling characteristics of the USB device in the enumeration phase, the dynamic timing features are used to reflect the time interval and response delay change of the communication events between the USB device and the host in the enumeration phase, and the event sequence features are used to reflect the orderliness of the communication events between the USB device and the host in the enumeration phase.
[0008] Based on the global features, the in-phase features, the dynamic timing features and the event sequence features, a static feature layer, a dynamic behavior layer and a protocol logic layer are constructed, the static feature layer is used to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements in the USB protocol, the dynamic behavior layer is used to verify whether the feature score of the USB device meets the standard, and the protocol logic layer is used to verify whether the USB device complies with the USB protocol.
[0009] The USB device is authenticated based on the protocol logic layer, the static feature layer and the dynamic behavior layer in sequence.
[0010] In an embodiment of the present application, in the case that the USB device and the host enter the enumeration phase, global features, in-phase features, dynamic timing features and event sequence features of the USB device in the enumeration phase are extracted, including:
[0011] In the case that the USB device and the host enter the enumeration phase, the entire enumeration phase is divided into a first event phase, a second event phase, a third event phase and a fourth event phase in the flow, the first event phase is used to represent the start of the enumeration phase, the second event phase is used to represent that the USB device enters the identifiable state, the third event phase is used to represent that the USB device enters the available state, and the fourth event phase is used to represent the end of the enumeration phase.
[0012] The total enumeration time length and the time interval of adjacent event phases are obtained, and the total enumeration time length and the time interval of adjacent event phases are determined as the global features of the USB device.
[0013] acquire a first sending time T1 of a last time of sending a SET_FEATURE request in a first event stage, an operation time H of the USB device in a second event stage, a target number F of times of sending a CLEAR_FEATURE request in the second event stage, a second sending time T2 of a last time of sending the CLEAR_FEATURE request in the second event stage, a target number N of times of sending a GET DESCRIPTOR request in a third event stage, a target response time T3 of the USB device responding to a SET CONFIGURATION request in the third event stage, and a third sending time T4 of sending a GET MAX LUN request in a fourth event stage; and determine the first sending time T1, the operation time H, the target number F, the second sending time T2, the target number N, the target response time T3, and the third sending time T4 as in-stage features of the USB device.
[0014] acquire a command rate and response feature S1 and a command processing jitter time S2, and determine the command rate and response feature S1 and the command processing jitter time S2 as dynamic timing features of the USB device; the command rate and response feature S1 is used to reflect a frequency of sending corresponding requests and a time interval of sending each request of the host in each event stage, and the command processing jitter time S2 is used to reflect a random fluctuation of a response time delay of the USB device responding to the same request.
[0015] acquire event order consistency C, and determine the event order consistency C as an event sequence feature of the USB device; the event order consistency C is used to reflect a sequence of the first event stage, the second event stage, the third event stage, and the fourth event stage.
[0016] In an embodiment of the present application, based on the global features, the in-stage features, the dynamic timing features, and the event sequence features, a static feature layer, a dynamic behavior layer, and a protocol logic layer are constructed, including:
[0017] the global features and the in-stage features are determined as the static feature layer;
[0018] the dynamic timing features are determined as the dynamic behavior layer;
[0019] the event sequence features are determined as the protocol logic layer.
[0020] In an embodiment of the present application, the USB device is authenticated based on the protocol logic layer, the static feature layer, and the dynamic behavior layer in sequence, including:
[0021] in a case where the USB device passes the verification of the protocol logic layer, the static feature layer, and the dynamic behavior layer in sequence, the USB device is determined as a legal device;
[0022] In a case where the USB device fails to pass the verification in any one of the protocol logic layer, the static feature layer, and the dynamic behavior layer, the USB device is determined as an illegal device.
[0023] In an embodiment of the present application, the protocol logic layer includes an L-dimensional vector, and the identity authentication of the USB device based on the protocol logic layer includes:
[0024] The requests sent by the host in the enumeration phase are acquired in sequence, and the acquired requests are compared with the corresponding reference requests in sequence;
[0025] In a case where the type of each request is consistent with the type of the corresponding reference request, and the character length of each request is consistent with the character length of the corresponding reference request, the USB device is determined as passing the verification;
[0026] In a case where the type of one request is inconsistent with the type of the corresponding reference request, or in a case where the character length of one request is inconsistent with the character length of the corresponding reference request, the USB device is determined as failing to pass the verification.
[0027] In an embodiment of the present application, the static feature layer includes an M-dimensional feature vector, and the identity authentication of the USB device based on the static feature layer includes:
[0028] The M-dimensional feature vector of the static feature layer is input into the trained multi-layer perception, and a verification result of the USB device output by the multi-layer perception is obtained.
[0029] In an embodiment of the present application, the dynamic behavior layer includes a K-dimensional feature vector, and the identity authentication of the USB device based on the dynamic behavior layer includes:
[0030] The weight of each feature vector in the dynamic behavior layer is calculated by a principal component analysis method;
[0031] Each feature vector in the dynamic behavior layer is normalized to obtain a standardized feature vector corresponding to each feature vector in the dynamic behavior layer;
[0032] Based on the weight of each feature vector in the dynamic behavior layer and the standardized feature vector corresponding to each feature vector, a feature score of the USB device is calculated;
[0033] In a case where the feature score of the USB device is within a score threshold, the USB device is determined as passing the verification, otherwise, the USB device is determined as failing to pass the verification.
[0034] In an embodiment of the present application, the calculation formula of the feature score of the USB device is:
[0035]
[0036] wherein, Score is a feature score of the USB device, w s is a weight of the Sth feature vector in the K-dimensional feature vector, f s is a normalized feature vector corresponding to the Sth feature vector.
[0037] Another aspect of the present application provides a USB device authentication device based on USB enumeration timing features, applied to a host, the device comprising:
[0038] an extraction module configured to extract global features, intra-phase features, dynamic timing features and event sequence features of the USB device in the enumeration phase when the USB device and the host enter the enumeration phase, the global features being used to reflect response speed of the USB device in the enumeration phase, the intra-phase features being used to reflect behavior mode and resource scheduling characteristics of the USB device in the enumeration phase, the dynamic timing features being used to reflect time interval and response delay variation of communication events between the USB device and the host in the enumeration phase, and the event sequence features being used to reflect orderliness of communication events between the USB device and the host in the enumeration phase;
[0039] a determination module configured to determine a static feature layer, a dynamic behavior layer and a protocol logic layer based on the global features, the intra-phase features, the dynamic timing features and the event sequence features, the static feature layer being used to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements in the USB protocol, the dynamic behavior layer being used to verify whether the feature score of the USB device meets the standard, and the protocol logic layer being used to verify whether the USB device complies with the USB protocol;
[0040] an authentication module configured to perform identity authentication on the USB device based on the protocol logic layer, the static feature layer and the dynamic behavior layer in sequence.
[0041] Still another aspect of the present application provides a storage medium having a computer program stored therein, the computer program being used to perform the steps of the USB device authentication method based on USB enumeration timing features according to any one of the above embodiments.
[0042] Still another aspect of the present application provides an electronic device comprising a memory and a processor, the memory having a computer program stored therein, and the processor being configured to realize the steps of the USB device authentication method based on USB enumeration timing features according to any one of the above embodiments when invoking the computer program in the memory.
[0043] Compared with the prior art, the present application has the following beneficial effects:
[0044] 1. The USB device authentication method based on USB enumeration timing characteristics provided by the application, by extracting the global features, intra-stage features, dynamic timing features and event sequence features of the USB device enumeration stage, and using the global features, intra-stage features, dynamic timing features and event sequence features to verify whether the USB device is a legal device, the identity authentication of the USB device can be completed before the USB device accesses the host, thereby effectively avoiding the illegal device from disguising or tampering with the identity before accessing the host, and improving the timeliness of the USB device identity authentication.
[0045] 2. The application extracts various features of the USB enumeration stage to perform identity authentication on the USB device, and since these features are extracted in the process of natural interaction between the USB device and the host, these features have high stability and do not depend on special devices, so that even in different environmental conditions, the extracted features can maintain consistency and reliability, thereby avoiding the instability problem caused by the aging of special devices and environmental changes, and improving the robustness and reliability of the USB device identity authentication.
[0046] The application will be further described in detail below in combination with the drawings and embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0047] Figure 1 is a flowchart of a USB device authentication method based on USB enumeration timing characteristics provided by an embodiment of the application;
[0048] Figure 2 is a hierarchical architecture diagram of a USB device feature provided by an embodiment of the application. DETAILED DESCRIPTION
[0049] In order to further illustrate the technical means and effects adopted by the application to achieve the predetermined purpose, a USB device authentication method based on USB enumeration timing characteristics according to the application will be described in detail below in combination with the drawings and specific embodiments.
[0050] The foregoing and other technical contents, features and effects of the application can be clearly presented in the specific embodiment description below in combination with the drawings. Through the description of the specific embodiments, the technical means and effects adopted by the application to achieve the predetermined purpose can be more deeply and specifically understood, however, the attached drawings are provided for reference and explanation only, and are not used to limit the technical solutions of the application.
[0051] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one from another entity or action, without necessarily requiring or implying any actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process or method that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process or method. Elements defined by an expression "comprising a" do not exclude the presence of additional identical elements in the process or method comprising the defined element.
[0052] The present application is directed to the problem of low timeliness and accuracy of USB device identity authentication, and provides a USB device authentication method based on USB enumeration timing characteristics, please see Figure 1 The method comprises the following steps:
[0053] S1: In the case that the USB device and the host enter the enumeration phase, extracting the global feature, the intra-phase feature, the dynamic timing feature and the event sequence feature of the USB device in the enumeration phase.
[0054] The global feature is used to reflect the response rate of the USB device in the enumeration phase, the intra-phase feature is used to reflect the behavior mode and resource scheduling characteristics of the USB device in the enumeration phase, the dynamic timing feature is used to reflect the time interval and response delay change of the communication event between the USB device and the host in the enumeration phase, and the event sequence feature is used to reflect the orderliness of the communication event between the USB device and the host in the enumeration phase.
[0055] The enumeration phase refers to the process that when a USB device is connected to a host (such as a computer, a terminal device, etc.) for the first time, the host identifies the USB device and configures the device, in other words, the enumeration phase is essentially the process that the USB device and the host complete the state negotiation, resource configuration and function initialization through standard control transmission. It should be noted that the prior art can authenticate the identity of the USB device only after the USB device is connected to the host, which means that the identity of the USB device can be authenticated only after the USB device and the host end the enumeration phase, and the present application authenticates the identity of the USB device in the case that the USB device and the host enter the enumeration phase, i.e. before the USB device is connected to the host, thereby effectively avoiding the illegal device from disguising or tampering the identity before being connected to the host, and improving the timeliness of the USB device identity authentication.
[0056] Specifically, in the case that the USB device and the host enter the enumeration phase, the entire enumeration phase can be divided into a first event phase (also referred to as a port connection detection phase), a second event phase (also referred to as a port reset phase), a third event phase (also referred to as a USB device configuration phase), and a fourth event phase (also referred to as a logical unit query) by detecting the request operation in the enumeration traffic.
[0057] It should be noted that in the first event phase, the host detects the physical connection state of the USB device by sending a GET STATUS request, a URB_INTERRUPT interrupt signal, and a CLEAR_FEATURE request, etc. This event marks the start of the enumeration phase, and its function is to clear the connection change flag of the port to ensure that the host can identify the newly connected USB device. In the second event phase, the host forces the USB device to enter the default state by sending a SET_FEATURE request, and then sends a CLEAR_FEATURE request to clean up the port state flag after reset. Its function is to verify the hardware integrity of the USB device and make it enter the identifiable (addressable) state. In the third event phase, the host obtains the USB device descriptor (including manufacturer ID, product ID, product information, etc.) by sending a GET_DESCRIPTOR request, and completes the interface configuration by sending a SET_CONFIGURATION request, etc. This phase determines the function enable state of the USB device, i.e., makes the USB device enter the available state. In the fourth event phase, the host queries the number of GET_MAX_LUN requests to end the enumeration phase at the protocol level with the USB device.
[0058] Further, after dividing the entire enumeration phase into the first event phase, the second event phase, the third event phase, and the fourth event phase, the total enumeration time and the time interval between adjacent event phases (also referred to as phase transition delay) can be obtained, and the total enumeration time and the time interval between adjacent event phases are determined as the global features of the USB device.
[0059] The total enumeration duration refers to the time experienced from the USB device accessing the host and starting the enumeration stage to the USB device ending the enumeration stage and entering the available state, specifically the time difference between the host sending the first (i.e., the first) GET_STATUS request (the request indicating the start of the enumeration stage) and the host sending the last (i.e., the last) GET_MAX_LUN request. It should be noted that the total enumeration duration is not only a key indicator for measuring the enumeration efficiency of the USB device, but also closely related to the hardware performance (such as the clock frequency of the control chip, the bus bandwidth, etc.) and the firmware optimization strategy (such as the interrupt priority, resource scheduling, etc.) of the USB device. In addition, the total enumeration duration not only reveals the speed of the USB device response, but also indirectly reflects the complexity of the USB device design and optimization.
[0060] The time interval of adjacent event stages is the time interval between the end of the previous stage and the start of the next stage, for example, the time interval between the end of the first event stage and the start of the second event stage, which reflects the state switching response capability of the USB device and can effectively reveal the conversion efficiency of the USB device between multiple operation stages.
[0061] In the embodiments of the present application, the first sending time T1 of the host sending the last SET_FEATURE request in the first event stage (which can also be referred to as the last SET_FEATURE request time T1), the operation time H of the USB device in the second event stage (which can also be referred to as the reset operation time H), the target number F of the host sending the CLEAR_FEATURE request in the second event stage (which can also be referred to as the state clearing request frequency F), the second sending time T2 of the host sending the last CLEAR_FEATURE request in the second event stage (which can also be referred to as the last CLEAR_FEATURE request time T2), the target number N of the host sending the GET_DESCRIPTOR request in the third event stage (which can also be referred to as the total amount of descriptor transmission N), the target response time T3 of the USB device responding to the SET_CONFIGURATION request in the third event stage (which can also be referred to as the request configuration time T3), and the third sending time T4 of the host sending the GET_MAX_LUN request in the fourth event stage (which can also be referred to as the logical unit query time T4) can also be obtained, and the first sending time T1, the operation time H, the target number F, the second sending time T2, the target number N, the target response time T3, and the third sending time T4 are determined as the in-stage characteristics of the USB device.
[0062] The first sending time T1 is the completion time of the last SET_FEATURE request sent by the host in the first event stage, which marks that the host has completed the confirmation of the physical connection state of the USB device and the necessary reset triggering action before entering the next stage. It reflects the delay from the physical access to the start of the reset preparation of the USB device, and can reveal the response speed of the USB device to the change of the port connection state.
[0063] The operation time H is the time experienced by the USB device from the receipt of the reset command to the completion of the reset process and entering the addressable state in the second event stage, i.e. in the port reset stage. Specifically, it is the time interval from the issuance of the first CLEAR_FEATURE request to the completion of the last SET_FEATURE request, which reflects the total time consumed by the USB device to complete the preliminary reset operation.
[0064] The target number F is the number of times of sending the CLEAR_FEATURE request by the host in the second event stage, i.e. in the port reset stage. This number reflects the number of operations that need to be performed by the USB device due to state cleaning in the port reset stage. More reset requests indicate that the USB device has redundant or complex internal processing logic when the state is switched, while fewer requests indicate that the USB device is more efficient when the state is switched.
[0065] The second sending time T2 is the completion time of the last CLEAR_FEATURE request sent by the host in the second event stage, i.e. in the port reset stage, which marks the end of the port reset stage and reflects the time taken by the USB device to complete all state cleanings in the reset process. The timing characteristics can be used to evaluate the preparation of the USB device after the reset operation is completed.
[0066] The target number N is the number of all GETDESCRIPTOR requests sent by the host in the third event stage, i.e. in the USB device configuration stage. The total number of requests reflects the complexity of the information structure of the USB device and the implementation degree of the firmware. The more the number of requests, the more functions, interfaces or descriptors the USB device usually has, which shows the complexity and resource configuration of the USB device. At the same time, the number of descriptor requests is also related to the enumeration efficiency and the initialization time of the USB device, and is an important indicator for evaluating the performance of the USB device and the optimization level of the firmware.
[0067] The target response time T3 is the response time of the USB device responding to the SETCONFIGURATION request in the third event stage, i.e. in the USB device configuration stage, which marks the formal completion of the USB device configuration stage, i.e. the USB device has completed the descriptor transmission, driver loading and resource allocation, and enters the available (i.e. operable) state.
[0068] The third sending time T4 refers to a sending time of the host sending the GET MAX LUN request in the fourth event stage, and the time point marks the end of the logical unit query stage, i.e., the end of the enumeration stage, the USB device enters the final available state, and the time point is taken as an end flag of the global enumeration, and the timing feature can reveal the response delay of the USB device at the end of the protocol, and also reflects the comprehensive processing speed of the USB device memory initialization, driver loading, etc.
[0069] In the embodiment of the application, the command rate and response feature S1 and the command processing jitter time S2 can also be acquired, and the command rate and response feature S1 and the command processing jitter time S2 are determined as the dynamic timing features of the USB device. The command rate and response feature S1 is used to reflect the frequency of the host sending the corresponding request in each event stage and the time interval of sending each request, and the command processing jitter time S2 is used to reflect the random fluctuation of the response delay of the USB device responding to the same request.
[0070] The command rate and response feature S1 can be quantified by calculating the time difference sequence between adjacent key commands (such as consecutive CLEAR_FEATURE requests or GETDESCRIPTOR requests) and performing statistics on the intervals. Specifically, in the embodiment of the application, a three-level quantification index system of the command rate and response feature S1 can be constructed, i.e., the average response speed μ v , the average command interval μ δ , and the timing stability σ cv , wherein the average response speed μ v is used to reflect the overall efficiency of the USB device processing the protocol command, the average command interval μ δ is used to reflect the baseline level of the response timing of the USB device, and the timing stability σ cv is used to quantify the fluctuation degree of the response time.
[0071] Specifically, the calculation formula of the average response speed μ v is as follows:
[0072]
[0073] , wherein N c is the total number of requests completed by the USB device, T tol is the total enumeration time length, t start is the time of the host sending the first GET_STATUS request, and t end is the time of the host sending the last GET MAX LUN request.
[0074] It should be noted that the standard command interval defined by the USB protocol specification is 1ms to 10ms, and the actual USB device will have a slight deviation due to the clock accuracy difference, and the average command interval μ δ The clock cumulative error of the control chip can be captured, which is defined as the arithmetic mean of the time difference of adjacent command responses, and the average command interval μ δ The calculation formula is:
[0075]
[0076] Where N' is the length of the collected time sequence {t1, t2,..., t N} and δ i is the time interval between the i-th and i+1-th command responses.
[0077] It should be noted that the introduction of timing stability σ cv is to quantify the inherent regularity of the response time fluctuation in the protocol interaction process, and the physical root of timing stability σ cv is the time reference accuracy of the USB device hardware circuit and the determinacy of the firmware scheduling algorithm, which is defined as the coefficient of variation of the response time sequence, that is, the dimensionless ratio of the standard deviation to the mean. The calculation formula of timing stability σ cv is:
[0078]
[0079] Where δ i is the time interval between the i-th and i+1-th command responses, μ δ is the average command interval, and n1 is the sample number.
[0080] It should be noted that the command processing jitter time S2 aims to reflect the timing fluctuation characteristics caused by the physical difference of the hardware circuit in the protocol interaction process. The essence of time jitter is derived from the phase noise of the USB device internal clock signal, the modulation effect of power ripple on logic gate delay, and the randomness of the firmware interrupt response mechanism. These microscopic fluctuations have non-stationary and nonlinear characteristics, and need to be effectively characterized by a specific analysis method.
[0081] In the embodiments of the present application, the dynamic capture can be realized by directly analyzing the timing data and extracting the local features in the continuous timing, and the timing jitter J mean and the jitter intensity J inten can be quantified by directly calculating the timing fluctuation through global analysis. Specifically, the timing jitter J mean represents the change of each command interval, and the jitter intensity J inten is to quantify the burst abnormal energy in the timing fluctuation, and its core value lies in revealing the hidden nonlinear disturbance in the hardware system.
[0082] Specifically, the timing jitter can be quantified by the fluctuation of δi, and a calculation formula for calculating the timing jitter is as follows:
[0083]
[0084] Wherein, n2 is the total number of command intervals, δi is the time interval between the i th and the i+1 th command response, and μ is the global mean value, indicating the reference stability of timing fluctuation. i
[0085] Specifically, the burst fluctuation, i.e., the jitter intensity, can be quantified by calculating the second moment statistic of timing fluctuation, and a calculation formula for calculating the jitter intensity J inten is as follows:
[0086]
[0087] Wherein, n2 is the total number of command intervals, δi is the time interval between the i th and the i+1 th command response, and μ is the global mean value, indicating the reference stability of timing fluctuation.
[0088] In the embodiment of the application, the event sequence consistency C can also be obtained, and the event sequence consistency C is determined as the event sequence feature of the USB device. The event sequence consistency C is used to reflect the sequence of the first event stage, the second event stage, the third event stage and the fourth event stage.
[0089] It should be noted that the event sequence consistency C can analyze the order of occurrence of each event in the enumeration process in the USB standard protocol to determine whether the USB device strictly follows the USB protocol. For example, in the standard enumeration process, events such as GET_STATUS request, URB_INTERRUPT request, SET_FEATURE request, CLEAR_FEATURE request, GET_DESCRIPTOR request, SET_CONFIGURATION request and GETMAX LUN request should appear in turn.
[0090] S2: Based on the global feature, the stage feature, the dynamic timing feature and the event sequence feature, a static feature layer, a dynamic behavior layer and a protocol logic layer are constructed.
[0091] The static feature layer is used to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements in the USB protocol, the dynamic behavior layer is used to verify whether the feature score of the USB device meets the standard, and the protocol logic layer is used to verify whether the USB device follows the USB protocol.
[0092] It should be noted that the USB protocol stack itself has a strict layered architecture, which determines the natural layered nature of USB device features. This embodiment of the invention, through layered processing, decouples the hardware-related features, firmware scheduling features, and protocol logic features of a USB device to different layers. This decoupling aligns with the working principle of USB devices and improves the physical interpretability of the feature space. Specifically, as... Figure 2 As shown, this embodiment of the invention divides the features of a USB device into three layers: a static feature layer, a dynamic behavior layer, and a protocol logic layer.
[0093] Specifically, global features and intra-stage features are defined as the static feature layer, namely, the total enumeration time, the time interval between adjacent event stages, the first transmission time T1, the operation time H, the number of targets F, the second transmission time T2, the number of targets N, the target response time T3, and the third transmission time T4 are defined as the static feature layer; dynamic timing features are defined as the dynamic behavior layer, namely, the command rate and response feature S1 and the command processing jitter time S2 are defined as the dynamic behavior layer; and event sequence features are defined as the protocol logic layer, namely, the sequentiality (event order consistency C) of the first event stage, the second event stage, the third event stage, and the fourth event stage are defined as the protocol logic layer.
[0094] It is understood that, in the embodiments of the present invention, the static feature layer obtains the M-dimensional feature vector Z through normalization processing. S Each feature vector is a rational number, and each feature vector corresponds to the total enumeration time T mentioned above. tol The time interval T between adjacent event phases def The first sending time T1, operation time H, target count F, second sending time T2, target quantity N, target response time T3, and third sending time T4 are represented by the M-dimensional feature vector Z. s =[T tol ,T def [T1,H,F,T2,N,T3,T4]. It can be seen that M equals 9 at this time. It should be noted that the size of M can be flexibly adjusted based on actual applications; that is, M can be greater than 9 or less than 9. This embodiment of the invention does not specifically limit the size of M.
[0095] In an embodiment of the present invention, the dynamic behavior layer obtains a K-dimensional feature vector Z through normalization processing. d Each eigenvector is a rational number, and each eigenvector corresponds to the aforementioned average response speed μ. v Average command interval μ δ and timing stability σ cv Timing jitter J mean and jitter intensity J inten That is, the K-dimensional eigenvector Zd = [μ v , μ δ , σ cv , J mean , J inten ]. It can be seen that K is equal to 5 at this time, and K can be greater than 5 or less than 5 based on actual application, and the size of K is not limited in the embodiment of the application.
[0096] In the embodiment of the application, the protocol logic layer obtains the L-dimensional vector Z f , wherein each feature vector is a rational number, and each feature vector corresponds to a request in each event stage, that is, the L-dimensional vector Z f = [S1, S2, S3, S4, S5, S6, S7], wherein S1 is a GET_STATUS request, S2 is a URB_INTERRUPT request, S3 is a SET_FEATURE request, S4 is a CLEAR_FEATURE request, S5 is a GET_DESCRIPTOR request, S6 is a SET_CONFIGURATION request, and S7 is a GET_MAX LUN request. It can be seen that L is equal to 7 at this time, and L can be greater than 7 or less than 7 based on actual application, and the size of L is not limited in the embodiment of the application.
[0097] Further, after obtaining the M-dimensional feature vector Z S , the K-dimensional feature vector Z d , and the L-dimensional vector Z f , the feature vectors corresponding to each layer can be dimensionally spliced according to physical meaning by using a multimodal series strategy to obtain a fusion feature vector:
[0098] F = [Z s , Z d , Z f ] T
[0099] , wherein F is a fusion feature vector, and [·] T is a transpose operation.
[0100] S3: sequentially performing identity authentication on the USB device based on the protocol logic layer, the static feature layer, and the dynamic behavior layer.
[0101] Specifically, in a case where the USB device sequentially passes the verification of the protocol logic layer, the static feature layer, and the dynamic behavior layer, the USB device is determined to be a legal device; in a case where the USB device does not pass the verification of any one of the protocol logic layer, the static feature layer, and the dynamic behavior layer, the USB device is determined to be an illegal device.
[0102] In the embodiment of the present application, the USB device is authenticated based on the protocol logic layer, specifically including the following steps:
[0103] S3.1: sequentially obtain each request sent by the host in the enumeration stage, and sequentially compare the obtained request with the corresponding reference request.
[0104] S3.2: in the case that the type of each request is consistent with the type of the corresponding reference request, and the character length of each request is consistent with the character length of the corresponding reference request, it is determined that the USB device passes the verification.
[0105] Specifically, in the protocol logic layer verification, the state machine model in the USB protocol specification is used, and the double-pointer traversal method is used to strictly match the command sequence (i.e. the request sequence) of the enumeration stage of the USB device, to ensure that the command sequence of the USB device is consistent with the standard flow (i.e. the reference request sequence in the reference mode). Only when the state machine model outputs 1, i.e. only when the type of each request is consistent with the type of the corresponding reference request, and the character length of each request is consistent with the character length of the corresponding reference request, it is determined that the USB device passes the verification, and then the subsequent authentication operation is continued, i.e. the subsequent operation of authenticating the USB device based on the static feature layer is continued.
[0106] S3.3: in the case that the type of one request is inconsistent with the type of the corresponding reference request, or the character length of one request is inconsistent with the character length of the corresponding reference request, it is determined that the USB device does not pass the verification.
[0107] Specifically, when the state machine model outputs 0, it is determined that the USB device does not pass the verification, i.e. the subsequent authentication operation is stopped.
[0108] In the embodiment of the present application, the USB device is authenticated based on the static feature layer, specifically including the following steps:
[0109] S3.4: input the M-dimensional feature vector of the static feature layer into the trained multilayer perceptron to obtain the verification result of the USB device output by the multilayer perceptron.
[0110] Wherein, the multilayer perceptron (MLP) as a kind of deep learning model, can pass through multiple levels of neurons to carry out information transmission and feature extraction, effectively capture the potential law in the behavior of USB device.
[0111] In the embodiment of the present application, the M-dimensional feature vector after normalization is taken as the input of the trained MLP model, so that the model outputs the legitimacy prediction label of the USB device. Whether the USB device is a legitimate device is determined by the prediction label.
[0112] It should be noted that, in order to improve the accuracy and robustness of USB device authentication, in the embodiment of the present application, the MLP model adopts a multi-layer structure, each layer containing multiple neurons, and the neurons perform nonlinear transformation on the input features through an activation function. The input layer receives the M-dimensional static feature vector and transmits it to multiple hidden layers for feature mapping and complex pattern learning. The output of each layer is taken as the input of the next layer, and finally a classification decision is made through the output layer. In order to enhance the nonlinear expression ability of the network and avoid the problem of gradient disappearance, the activation function is selected as ReLU. The output layer uses a sigmoid activation function for binary classification, and the output value is in the range of [0, 1], wherein, the prediction label 1 indicates that the USB device is a legitimate device, and the prediction label 0 indicates that the USB device is an illegal device. The training of the MLP model adopts a cross-entropy loss function, which can effectively measure the difference between the prediction label output by the MLP model and the true label. After training, the MLP model can accurately determine the legitimacy of different USB device identities through the evaluation of the validation set and the test set.
[0113] In the embodiment of the present application, the identity of the USB device is authenticated based on the dynamic feature layer, which includes the following steps:
[0114] S3.5: Calculate the weight of each feature vector in the dynamic feature layer by the Principal Component Analysis (PCA) method.
[0115] Specifically, PCA calculates the covariance matrix between each feature vector in the dynamic feature layer, extracts principal components (feature vectors), and determines the weight of each feature vector according to the variance contribution of each principal component.
[0116] It should be noted that the "weight" here can be understood as the relative size of the corresponding eigenvalue of each feature vector, which reflects the ability of the corresponding principal component to explain the data variability. A larger eigenvalue means that the corresponding feature vector is more important.
[0117] S3.6: Standardize each feature vector in the dynamic behavior layer to obtain a standardized feature vector corresponding to each feature vector in the dynamic behavior layer.
[0118] Specifically, by adopting a Z-Score standardization method, the mean and standard deviation of each feature dimension are calculated respectively, the original feature value is converted into a standard value with a mean of 0 and a standard deviation of 1, and thus a standardized feature vector corresponding to each feature vector in the dynamic behavior layer is obtained
[0119] S3.7: Based on the weight of each feature vector in the dynamic behavior layer and the standardized feature vector corresponding to each feature vector, the feature score of the USB device is calculated.
[0120] Specifically, the calculation formula of the feature score of the USB device is:
[0121]
[0122] wherein, Score is the feature score of the USB device, w s is the weight of the Sth feature vector in the K-dimensional feature vector, f s is the standardized feature vector corresponding to the Sth feature vector.
[0123] S3.8: In the case that the feature score of the USB device is within the score threshold [θ min , θ max ], it is determined that the USB device passes the verification, otherwise, it does not pass the verification.
[0124] wherein, θ min is the minimum feature score of the legal device, and θ max is the maximum feature score of the legal device.
[0125] It should be noted that the setting of the score threshold is based on statistical analysis of historical data samples, by collecting time sequence data samples of a plurality of legal devices under standard working conditions, performing PCA feature extraction and weighting processing on these samples, then calculating the weighted score of each legal device, and finally determining the score range of the legal device through statistical analysis of the score distribution.
[0126] It should be noted that the USB device authentication method based on USB enumeration time sequence features provided by the embodiment of the present application can complete attack detection in the enumeration stage in the case that the attacker does not know the model of the USB device, so that the information exposure amount of the attacker is significantly limited, that is, the attacker cannot disguise or tamper with the identity before accessing the host, thereby improving the security of the host.
[0127] In summary, the USB device authentication method based on the USB enumeration timing sequence characteristics provided by the embodiment of the present application extracts the global feature, the intra-stage feature, the dynamic timing sequence feature and the event sequence feature in the USB enumeration stage, and verifies whether the USB device is a legal device by using the global feature, the intra-stage feature, the dynamic timing sequence feature and the event sequence feature, so that the identity authentication of the USB device can be completed before the USB device accesses the host, thereby effectively avoiding the illegal device from disguising or tampering the identity before accessing the host, and improving the timeliness of the identity authentication of the USB device.
[0128] In addition, the embodiment of the present application performs the identity authentication of the USB device by extracting various features in the USB enumeration stage, and since the features are extracted in the process of the natural interaction between the USB device and the host, the features have high stability and do not depend on special devices, so that the consistency and reliability of the extracted features can be maintained even in different environmental conditions, thereby avoiding the instability problems caused by the aging of the special devices and the change of the environment, and improving the robustness and reliability of the identity authentication of the USB device.
[0129] In addition, the embodiment of the present application realizes the multi-layer authentication mechanism by the hierarchical design, and effectively guarantees the security of the USB device access process.
[0130] In the several embodiments of the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only schematic, and the division of the modules is only a logical function division, and there can be another division manner in actual implementation, for example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed.
[0131] In addition, each functional module in each embodiment of the present application can be integrated in a processing module, or each module can exist physically, or two or more modules can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of hardware plus software function module.
[0132] Another embodiment of the present application provides a USB device authentication device based on USB enumeration timing sequence characteristics, which is applied to a host, and the device comprises:
[0133] The extraction module is configured to extract global features, in-stage features, dynamic timing features and event sequence features of the USB device in the enumeration phase when the USB device and the host enter the enumeration phase, the global features are used to reflect response speed of the USB device in the enumeration phase, the in-stage features are used to reflect behavior mode and resource scheduling characteristics of the USB device in the enumeration phase, the dynamic timing features are used to reflect time interval and response delay variation of communication events between the USB device and the host in the enumeration phase, and the event sequence features are used to reflect orderliness of communication events between the USB device and the host in the enumeration phase.
[0134] The construction module is configured to construct a static feature layer, a dynamic behavior layer and a protocol logic layer based on the global features, the in-stage features, the dynamic timing features and the event sequence features, the static feature layer is used to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements in the USB protocol, the dynamic behavior layer is used to verify whether the feature score of the USB device meets the standard, and the protocol logic layer is used to verify whether the USB device complies with the USB protocol.
[0135] The authentication module is configured to perform identity authentication on the USB device based on the protocol logic layer, the static feature layer and the dynamic behavior layer in sequence.
[0136] Still another embodiment of the present application provides a storage medium, which stores a computer program for performing the steps of the USB device authentication method based on USB enumeration timing features in the above embodiments.
[0137] Still another aspect of the present application provides an electronic device, which comprises a memory and a processor, the memory stores a computer program, and the processor realizes the steps of the USB device authentication method based on USB enumeration timing features in the above embodiments when invoking the computer program in the memory. Specifically, the integrated modules realized in the form of software function modules can be stored in a computer readable storage medium. The software function modules stored in a storage medium include a plurality of instructions for making an electronic device (which can be a personal computer, a server, or a network device, etc.) or a processor execute part of the steps of the method described in various embodiments of the present application. The aforementioned storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.
[0138] The above is further detailed description of the present application in combination with specific preferred embodiments, and cannot be deemed as limitation of the specific implementation of the present application to these descriptions. For those skilled in the art to which the present application belongs, without departing from the concept of the present application, a number of simple deductions or substitutions can be made, and all should be deemed as falling within the protection scope of the present application.
Claims
1. A USB device authentication method based on USB enumeration timing characteristics, characterized in that, Applied to a host, comprising: In the case that a USB device and the host enter an enumeration phase, extracting global features, intra-phase features, dynamic timing features and event sequence features of the USB device in the enumeration phase, the global features are used to reflect response speed of the USB device in the enumeration phase, the intra-phase features are used to reflect behavior mode and resource scheduling characteristics of the USB device in the enumeration phase, the dynamic timing features are used to reflect time interval and response delay variation of communication events between the USB device and the host in the enumeration phase, and the event sequence features are used to reflect orderliness of communication events between the USB device and the host in the enumeration phase; Based on the global features, the intra-phase features, the dynamic timing features and the event sequence features, constructing a static feature layer, a dynamic behavior layer and a protocol logic layer, the static feature layer is used to verify whether hardware characteristics of the USB device meet hardware characteristic requirements in a USB protocol, the dynamic behavior layer is used to verify whether feature scores of the USB device meet standards, and the protocol logic layer is used to verify whether the USB device complies with the USB protocol; The based on the global features, the intra-phase features, the dynamic timing features and the event sequence features, constructing a static feature layer, a dynamic behavior layer and a protocol logic layer, comprising: Determining the global features and the intra-phase features as the static feature layer; Determining the dynamic timing features as the dynamic behavior layer; Determining the event sequence features as the protocol logic layer; Sequentially performing identity authentication on the USB device based on the protocol logic layer, the static feature layer and the dynamic behavior layer.
2. The USB device authentication method based on USB enumeration timing characteristics according to claim 1, characterized in that, The in the case that a USB device and the host enter an enumeration phase, extracting global features, intra-phase features, dynamic timing features and event sequence features of the USB device in the enumeration phase, comprising: In the case that the USB device and the host enter the enumeration phase, dividing the entire enumeration phase into a first event phase, a second event phase, a third event phase and a fourth event phase in a flow, the first event phase is used to represent starting the enumeration phase, the second event phase is used to represent that the USB device enters an identifiable state, the third event phase is used to represent that the USB device enters an available state, and the fourth event phase is used to represent that the enumeration phase ends; Obtaining total enumeration duration and time interval of adjacent event phases; and determining the total enumeration duration and the time interval of the adjacent event phases as the global features of the USB device; a first transmission time of a last transmission of a SET_FEATURE request in the first event stage , an operation time consumption of the USB device in the second event stage , a target number of transmissions of a CLEAR_FEATURE request in the second event stage , a second transmission time of a last transmission of the CLEAR_FEATURE request in the second event stage , a target number N of transmissions of a GET DESCRIPTOR request in the third event stage, a target response time of the USB device responding to a SET CONFIGURATION request in the third event stage , and a third transmission time of a GET MAX LUN request in the fourth event stage ; and determining the first transmission time , the operation time consumption , the target number , the second transmission time , the target number N , the target response time , and the third transmission time as in-stage features of the USB device. Acquiring a command rate and response characteristic and a command processing jitter time , the command rate and response characteristic and the command processing jitter time , determining a dynamic timing characteristic for the USB device, the command rate and response characteristic for reflecting a frequency at which the host sends a corresponding request at each event stage and a time interval at which each request is sent, the command processing jitter time for reflecting a random fluctuation of a response latency when the USB device responds to the same request; acquire event order consistency C, the event order consistency C determine event sequence characteristics for the USB device, the event order consistency C being configured to reflect the order of the first event phase, the second event phase, the third event phase, and the fourth event phase. 3.The USB device authentication method based on USB enumeration timing characteristics of claim 1, wherein, The sequentially performing identity authentication on the USB device based on the protocol logic layer, the static feature layer and the dynamic behavior layer, comprising: In the case that the USB device passes the verification of the protocol logic layer, the static feature layer and the dynamic behavior layer in sequence, determining that the USB device is a legal device. In a case where the USB device is not verified by any one of the protocol logic layer, the static feature layer and the dynamic behavior layer, the USB device is determined as an illegal device.
4. The USB device authentication method based on USB enumeration timing characteristics according to claim 3, characterized in that, The identity authentication of the USB device based on the protocol logic layer comprises: The requests sent by the host in the enumeration phase are acquired in sequence, and the acquired requests are compared with the corresponding reference requests in sequence; In a case where the type of each request is consistent with the type of the corresponding reference request, and the character length of each request is consistent with the character length of the corresponding reference request, the USB device is determined as passing the verification; In a case where the type of one request is inconsistent with the type of the corresponding reference request, or in a case where the character length of one request is inconsistent with the character length of the corresponding reference request, the USB device is determined as not passing the verification.
5. The USB device authentication method based on USB enumeration timing characteristics according to claim 3, characterized in that, The static feature layer comprises an M-dimensional feature vector, and the identity authentication of the USB device based on the static feature layer comprises: The M-dimensional feature vector of the static feature layer is input into a trained multilayer perceptron to obtain a verification result of the USB device output by the multilayer perceptron.
6. The USB device authentication method based on USB enumeration timing characteristics according to claim 3, characterized in that, The dynamic behavior layer comprises a K-dimensional feature vector, and the identity authentication of the USB device based on the dynamic behavior layer comprises: The weight of each feature vector in the dynamic behavior layer is calculated by a principal component analysis method; Each feature vector in the dynamic behavior layer is normalized to obtain a standardized feature vector corresponding to each feature vector in the dynamic behavior layer; The feature score of the USB device is calculated based on the weight of each feature vector in the dynamic behavior layer and the standardized feature vector corresponding to each feature vector; In a case where the feature score of the USB device is within a score threshold, the USB device is determined as passing the verification, otherwise, the USB device is determined as not passing the verification.
7. The USB device authentication method based on USB enumeration timing characteristics according to claim 6, characterized in that, The calculation formula of the feature score of the USB device is: wherein, score a feature of the USB device, is a weight of an S-th feature vector in the K-dimensional feature vector, is a normalized feature vector corresponding to the S-th feature vector.
8. A USB device authentication apparatus based on USB enumeration timing characteristics, characterized by, The device comprises: In a case where the USB device and the host enter an enumeration phase, the extraction module extracts the global feature, the in-phase feature, the dynamic timing feature and the event sequence feature of the USB device in the enumeration phase, the global feature is used to reflect the response rate of the USB device in the enumeration phase, the in-phase feature is used to reflect the behavior mode and resource scheduling characteristics of the USB device in the enumeration phase, the dynamic timing feature is used to reflect the time interval and response delay change of the communication event between the USB device and the host in the enumeration phase, and the event sequence feature is used to reflect the orderliness of the communication event between the USB device and the host in the enumeration phase. The constructing module is configured to construct a static feature layer, a dynamic behavior layer, and a protocol logic layer based on the global feature, the in-stage feature, the dynamic timing feature, and the event sequence feature, the static feature layer being configured to verify whether the hardware characteristics of the USB device meet the hardware characteristic requirements in the USB protocol, the dynamic behavior layer being configured to verify whether the feature score of the USB device meets the standard, and the protocol logic layer being configured to verify whether the USB device complies with the USB protocol. The constructing, based on the global feature, the in-stage feature, the dynamic timing feature, and the event sequence feature, of the static feature layer, the dynamic behavior layer, and the protocol logic layer comprises: determining the global feature and the in-stage feature as the static feature layer; determining the dynamic timing feature as the dynamic behavior layer; determining the event sequence feature as the protocol logic layer; The authentication module is configured to perform identity authentication on the USB device based on the protocol logic layer, the static feature layer, and the dynamic behavior layer in sequence.
9. A storage medium having stored therein a computer program, characterized in that, The computer program is configured to execute the steps of the USB device authentication method based on the USB enumeration timing feature according to any one of claims 1 to 7.
Citation Information
Patent Citations
USB (Universal Serial Bus) equipment identification and authentication method based on transmission delay characteristic
CN118246001A
Behavioral authentication of universal serial bus (USB) devices
US10169567B1