Server hardware anti-counterfeiting methods and electronic devices

By employing a hierarchical polling architecture and encryption algorithms in a distributed cluster to generate hardware environment fingerprints and signatures, the problem of server hardware forgery or replacement is solved, achieving real-time verification and security of server hardware.

CN120915452BActive Publication Date: 2025-12-02INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511446106.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-10
Publication Date
2025-12-02
Estimated Expiration
2045-10-10

Smart Images

  • Figure CN120915452B_ABST
    Figure CN120915452B_ABST
Patent Text Reader

Abstract

This application discloses a server hardware anti-counterfeiting method and electronic device, relating to the field of server security technology. The method includes a first server generating a challenge code using the node characteristics and random numbers of a second server, initiating a verification process to the second server at specified intervals. After the second server successfully decrypts the challenge code, it generates a current environment fingerprint and signature, sending them back to the first server. The first server verifies the signature and uses Hamming distance to verify the consistency of the current hardware environment fingerprint distance threshold, dynamically updating the environment fingerprint. This establishes a dynamic mutual verification mechanism between nodes, verifying the legality of each server hardware component in the cluster in real time, improving the signature verification pass rate under minor environmental fluctuations, ensuring that each server component passes trusted authentication, effectively preventing counterfeit hardware implantation and illegal component replacement. This solves the problems of effective identification of server hardware counterfeiting or replacement, limited verification scope, and poor verification security and effectiveness in related technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of server security technology, and in particular to server hardware anti-counterfeiting methods and electronic devices. Background Technology

[0002] As core hardware in critical areas such as data centers, the authenticity and integrity of server components directly determine system stability and data security.

[0003] In related technologies, if passive protection methods such as static serial numbers or physical seals are used, the serial numbers can be copied and tampered with by software tools, and the physical seals can be easily removed and re-attached, making it difficult to effectively prevent professional counterfeiting. If a solution based on TPM (Trusted Platform Module) chips is used, it is impossible to effectively authenticate external cards such as RAID (Redundant Array of Independent Disks) cards, creating a significant security blind spot. Summary of the Invention

[0004] This application provides a server hardware anti-counterfeiting method and electronic device to at least solve the problems in related technologies such as the effective identification of server hardware counterfeiting or replacement, small verification scope, and poor verification security and effectiveness.

[0005] This application provides a server hardware anti-counterfeiting method, applied to a first server in a distributed cluster. The method includes: obtaining node characteristics and a random number of a second server, wherein the second server is a server in the distributed cluster, and the first server and the second server are different servers; encrypting and generating a challenge code based on the node characteristics and the random number of the second server, sending the challenge code to the second server, and after the second server successfully decrypts the challenge code, generating a current hardware environment fingerprint of the second server based on at least one hardware characteristic of the second server, generating a signature based on the current hardware environment fingerprint and the random number, wherein the current hardware environment fingerprint is the hardware environment fingerprint of the second server at the current moment; and verifying the hardware environment of the second server based on the current hardware environment fingerprint and the signature.

[0006] This application also provides another server hardware anti-counterfeiting method, which is applied to a second server in a distributed cluster. The method includes: obtaining a challenge code sent by a first server in the distributed cluster, wherein the challenge code is generated by the first server based on the node characteristics of the second server and a random number; after successfully decrypting the challenge code to obtain a random number, generating a current hardware environment fingerprint of the second server based on at least one hardware feature in the second server, generating a signature based on the current hardware environment fingerprint and the random number; and sending the current hardware environment fingerprint and the signature to the first server, wherein the first server verifies the hardware environment of the second server based on the current hardware environment fingerprint and the signature.

[0007] This application also provides an electronic device, including: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of the above-described server hardware anti-counterfeiting method.

[0008] Therefore, this application has at least the following beneficial effects:

[0009] This application embodiment can generate challenge codes using node characteristics and random numbers from a second server. Verification processes are initiated to the second server at specified intervals. The second server encrypts the challenge codes and, upon successful decryption, generates a fingerprint and signature for the current environment, sending them back to the first server. The first server verifies the signature, thereby verifying the legitimacy of hardware components on each server in the cluster in real time. This improves the signature verification pass rate under minor environmental fluctuations, ensuring that each server component passes trusted authentication and effectively preventing counterfeit hardware implantation and illegal component replacement. Therefore, it solves the problems of effective identification of server hardware forgery or replacement, limited verification scope, and poor verification security and effectiveness in related technologies.

[0010] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0011] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 A flowchart of a server hardware anti-counterfeiting method provided in the first embodiment of this application;

[0013] Figure 2 This is a schematic flowchart of a server hardware anti-counterfeiting method provided in the second embodiment of this application;

[0014] Figure 3 Flowchart of another server hardware anti-counterfeiting method provided in the third embodiment of this application;

[0015] Figure 4 This is a schematic diagram of the structure of a server hardware anti-counterfeiting device provided in the fourth embodiment of this application;

[0016] Figure 5 This is a schematic diagram of another server hardware anti-counterfeiting device provided in the fifth embodiment of this application. Detailed Implementation

[0017] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0018] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0019] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0020] The specific application environment architecture or specific hardware architecture on which the execution of the server hardware anti-counterfeiting method depends is described here.

[0021] This application provides a server hardware anti-counterfeiting method, and the method is described in detail below with reference to its execution flow. The server hardware anti-counterfeiting method is applied to the first server in a distributed cluster.

[0022] The distributed cluster consists of multiple independent servers, including the first server and the second server, which are connected through the cluster's intranet to form a system architecture. This architecture can break down complex tasks into subtasks and assign them to different servers for parallel execution. The first server is the main server that actively initiates the operation.

[0023] Furthermore, in the embodiments of this application, the distributed cluster includes a hierarchical round-robin architecture, which is used to implement a server hardware anti-counterfeiting method. The hierarchical round-robin architecture includes a physical layer round-robin module, a logical layer arbitration module, and an application layer circuit breaker module. The physical layer round-robin module consists of a ring topology network composed of underlying servers. It triggers periodic verification requests through clock synchronization and prioritizes verifying the hash values ​​of the hardware environment fingerprints of adjacent nodes. The logical layer arbitration module votes on the verification results submitted by the physical layer and determines abnormal hardware environment fingerprints in the server based on the voting results. When the application layer circuit breaker module determines an abnormal node in at least one round of arbitration, it isolates the abnormal node.

[0024] The hierarchical polling architecture breaks down device / module status queries and request processing into multiple independent levels, with responsibilities divided according to each level. The physical layer polling module is a module located between the hardware and logic layers, directly interacting with physical hardware devices. It is a functional unit that periodically queries hardware status and collects hardware data through a preset protocol. The logic layer arbitration module is a resource scheduling module located between the physical layer and the application layer, used to resolve competition conflicts between multiple modules for the same resource. The application layer circuit breaker module is a fault protection unit module located at the top layer of the system. When the failure frequency of a service / interface exceeds a preset threshold, it automatically cuts off the call link of that service / interface to prevent the fault from spreading to the entire system. The ring topology network is a physical / logical network structure in which nodes are connected in a ring. The hardware environment fingerprint is a string generated after irreversibly encrypting the hardware characteristics collected by the server. The hash value is a fixed-length, unique, and irreversible binary string output by calculating input data of arbitrary length using a hash algorithm.

[0025] Understandably, in a distributed cluster with a three-layered polling architecture consisting of a physical layer polling module, a logical layer arbitration module, and an application layer circuit breaker module, a distributed consensus mechanism is adopted to ensure that data tampering on a single node will trigger cluster verification failure, thus fundamentally blocking the risk of forgery.

[0026] Specifically, the layered polling architecture is a phased, multi-layered dynamic verification mechanism. The dynamic verification protocol adopts a layered polling architecture, initiating a round of cross-node verification every 30 minutes. It achieves forward-secure bidirectional authentication through an improved ElGamal (ElGamal Cryptosystem) algorithm, and each session uses a temporary key pair and supports zero-knowledge proofs.

[0027] The layered polling architecture's core design comprises three layers: a physical layer polling module, a logical layer arbitration module, and an application layer circuit breaker module. In the physical layer polling, a ring topology network composed of underlying hardware nodes triggers periodic verification requests through clock synchronization, prioritizing the verification of hardware fingerprint hash values ​​of adjacent nodes. In the logical layer arbitration, the middle layer employs a modified PBFT (Practical Byzantine Fault Tolerance) consensus algorithm, performing a three-stage voting process—request, preparation, and submission—on the verification results submitted by the physical layer to ensure that a majority of nodes reach a consensus on abnormal fingerprints. In the application layer circuit breaker, a dynamic policy engine is deployed at the top layer. When more than 33% of nodes are found to be abnormal in two consecutive rounds of arbitration, the problematic node is automatically isolated and the verification topology is reorganized, while simultaneously triggering a key rotation protocol.

[0028] Based on the distributed cluster architecture described above, the server hardware anti-counterfeiting method will be explained below with reference to the attached diagram, such as... Figure 1 As shown, the server hardware anti-counterfeiting method includes the following steps:

[0029] In step S101, the node characteristics and random numbers of the second server in the distributed cluster are obtained.

[0030] In this context, the second server is a specific server node of the interaction object specified by the first server that initiates the request / operation in the distributed cluster system; the node characteristics of the second server are a set of information that characterizes the inherent attributes, operating status, and internal relationships of the target server node in the distributed cluster; and the random number is a value generated by the first server in the distributed cluster that satisfies statistical randomness and can assist the interaction decision between the first server and the second server.

[0031] It is understandable that in the first server, by obtaining the node characteristics and random number of the second server in the distributed cluster, and binding the node characteristics of the second server with the random number, the unpredictability of each verification can be ensured, the authenticity of the node identity can be verified, and the integrity and freshness of the transmitted data can be ensured.

[0032] Specifically, the node characteristics of the second server are the characteristic identification parameters of the second server. The node characteristics of the second server include multiple dimensions such as hardware, software, network and operating status. Nodes will periodically initiate challenge requests in the form of encrypted sessions. The encrypted session content can contain multi-bit random numbers, such as 128-bit random numbers. The random numbers contain timestamp information when the random numbers were generated.

[0033] Furthermore, in the embodiments of this application, before obtaining the node characteristics and random number of the second server, the method further includes: initializing the distributed cluster, collecting at least one local hardware characteristic, generating a hardware environment fingerprint of the first server based on the at least one hardware characteristic, sending the hardware environment fingerprint to other nodes in the distributed cluster, and deleting the hardware environment fingerprint of the first server; after the initialization of the distributed cluster is completed, performing server hardware anti-counterfeiting verification on the second server at preset intervals.

[0034] The initialization of the distributed cluster involves adding steps such as hardware feature collection, fingerprint generation, and interaction for each node, building upon the standard distributed cluster setup. Hardware environment fingerprinting involves collecting information such as the physical attributes, configuration parameters, and operating status of the device hardware, processing this information through an algorithm to generate unique and stable identifier data. Anti-counterfeiting verification is an operation performed after cluster initialization, for a preset time period, to verify whether the hardware of the second server is the same as the legitimate hardware used during initialization. The preset time period can be set according to actual needs, such as 20 minutes or 30 minutes, without specific limitations.

[0035] Understandably, by collecting local hardware characteristics from the first server in the distributed cluster, generating and sending the hardware environment fingerprint of the first server to other servers in the distributed cluster, deleting the hardware environment fingerprint of the first server, and completing the initialization of the distributed cluster, the server hardware anti-counterfeiting verification is performed on the second server after a pre-set preset time, thereby strengthening real-time monitoring and enhancing anti-counterfeiting capabilities.

[0036] Specifically, during cluster initialization, each server starts collecting local hardware information, generates a server hardware environment fingerprint, sends the hardware environment fingerprint information to and saves it in other nodes of the server cluster. The first local server does not retain this environment fingerprint information and initiates verification to the second server every preset time interval.

[0037] In a distributed cluster, the first server and the second server are different servers. By obtaining the node characteristics and random numbers of the second server in the distributed cluster, and binding the node characteristics of the second server with the random numbers, the unpredictability of each verification can be ensured, the authenticity of the node identity can be verified, and the integrity and freshness of the transmitted data can be ensured.

[0038] This application embodiment can obtain node characteristics and random numbers, generate a hardware environment fingerprint of the first server based on the server hardware characteristics of the first server, send the hardware environment fingerprint to other nodes in the distributed cluster, delete the hardware environment fingerprint of the first server, complete the initialization of the distributed cluster, establish an initial trust database among cluster nodes, ensure the uniqueness and unforgeability of node identities, and avoid the risk of identity forgery caused by the leakage of sensitive information.

[0039] In step S102, a challenge code is generated by encrypting the node characteristics of the second server and a random number. The challenge code is sent to the second server. After the second server successfully decrypts the challenge code, it generates a fingerprint of the current hardware environment based on at least one hardware characteristic of the second server. The second server then generates a signature based on the fingerprint of the current hardware environment and the random number.

[0040] Among them, the challenge code is a dynamic random instruction or string generated by the node initiating the verification in the distributed cluster to confirm the legitimacy of the second server's identity; the hardware feature is the inherent, stable and tamper-proof attribute of the server hardware itself, which can be used as an identifier for identification; the signature is an encrypted string generated by the node in the distributed cluster after encrypting the key data with its own private key, which is used to prove that the sender of the data is legitimate and that the data has not been tampered with during transmission.

[0041] Understandably, the challenge code generated by the node characteristics and random number of the second server is sent to the second server. The second server decrypts the challenge code and generates the fingerprint of the current hardware environment of the second server and a signature. A secure and reliable verification mechanism is established through the challenge code and signature, realizing a strong correlation between the signature and the physical environment of the device, thereby improving the integrity and security of device verification.

[0042] Specifically, when the first server initiates verification against the second server, the second server collects dynamic feature parameters of the current operating environment, such as the CPU (Central Processing Unit) identity credentials, memory physical feature matrix, and hard disk digital fingerprint. The first server first encrypts and generates a challenge code. The second server then initiates the verification process to verify the challenge code generated by the first server. After successful decryption, the second server obtains the original parameters required for verification. The second server collects hardware information data of its own server node to generate a fingerprint of the current environment and uses an improved ElGamal algorithm to generate a signature. The expression for the generated signature is:

[0043]

[0044] in, Indicates signature, Indicates the specific hash function, This indicates the original data that needs to be hash-protected. This indicates data concatenation; E indicates that the SHA3 output is a 256-bit hardware environment fingerprint. This represents the private key. represents a temporary parameter, and p represents the prime field.

[0045] Furthermore, in an embodiment of this application, generating a challenge code based on the node characteristics and random number of the second server includes: inputting the node characteristics and random number of the second server into a pre-set target encryption algorithm, so as to obtain a challenge code by binding the node characteristics and random number of the second server using the target encryption algorithm.

[0046] Among them, the target encryption algorithm is an encryption algorithm designed to achieve specific security goals such as data confidentiality, integrity verification, and identity confirmation, based on specific application scenarios.

[0047] Understandably, by inputting the node characteristics and random number of the second server into the target encryption algorithm and binding them to generate a challenge code, it is impossible to deduce the original information from the result, ensuring the unpredictability of each verification and preventing replay attacks.

[0048] Specifically, the corresponding encryption algorithm, such as AES-GCM (Advanced Encryption Standard - Galois / Counter Mode), is called to process the ciphertext. The node characteristics of the second server are bound to random numbers. All the node characteristics and random number information of the second server are completely scrambled and mixed together, and a complex target encryption algorithm is calculated to obtain the challenge code.

[0049] This application embodiment can generate a challenge code by inputting the node characteristics and random number of the second server into the target encryption algorithm and binding them. The challenge code generated by the node characteristics and random number of the second server is sent to the second server. The second server decrypts the challenge code and generates the current hardware environment fingerprint and signature of the second server. A secure and reliable verification mechanism is established through the challenge code and signature, which ensures the unpredictability of each verification and improves the integrity and security of device verification.

[0050] In step S103, the hardware environment of the second server is verified based on the current hardware environment fingerprint and signature.

[0051] Understandably, by combining fingerprint and signature verification with the current hardware environment to confirm the hardware environment of the second server, the uniqueness of the device is identified by the hardware fingerprint, and the identity is ensured to be unforged or tampered with by the signature verification. This method achieves secure access to the server cluster, ensures that the hardware parameters cannot be tampered with, and provides seamless security for the hardware environment.

[0052] Specifically, each time a user launches the software, the software triggers a signature verification process. This process involves comparing the current hardware environment fingerprint and verifying the validity of the signature to determine the hardware environment of the second server. The second server first generates a current hardware environment fingerprint based on its own hardware environment information, and then encrypts the fingerprint using a unique private key to generate a hardware signature. After obtaining the hardware fingerprint and hardware signature from the second server, the verifier decrypts the signature using the corresponding public key and compares the real-time original fingerprint that has passed the signature verification with the baseline original fingerprint stored in the backend database bit by bit to verify whether the hardware environment of the second server is authentic.

[0053] Furthermore, in the embodiments of this application, verifying the hardware environment of the second server based on the current hardware environment fingerprint and signature includes: verifying the validity of the signature; calling the database of the first server to obtain the reference hardware environment fingerprint of the second server stored in the database, and verifying the consistency of the current hardware environment fingerprint based on the reference hardware environment fingerprint; if the validity of the signature and the consistency verification of the current hardware environment fingerprint pass, then the hardware environment of the second server is determined to be legitimate, and the second server is isolated.

[0054] Among them, the reference hardware environment fingerprint is a device feature pre-constructed by collecting information such as the physical attributes, configuration parameters and operating status of the device hardware; the hardware environment is the sum of all physical hardware components that the server depends on when it runs as a physical entity, the connection relationships between components, and the basic configuration and operating status of the hardware.

[0055] Understandably, by verifying signature validity and hardware fingerprint consistency, a dual-verification hardware environment trust guarantee mechanism is constructed, which improves decision-making accuracy, ensures the authenticity and legitimacy of access hardware, and effectively prevents counterfeit hardware implantation and illegal component replacement.

[0056] Specifically, the second server sends the message and signature to the first server, which then verifies the signature validity according to the signature verification equation, the expression of which is as follows:

[0057]

[0058] Where g represents a generator. Indicates the specific hash function, This indicates the original data that needs to be hash-protected. This indicates data concatenation; E represents the SHA3 output of a 256-bit hardware environment fingerprint; and y represents the public key. Indicates a temporary parameter. Let p represent the signature, and p represent the prime field.

[0059] The consistency of the current hardware environment fingerprint is verified based on the reference hardware environment fingerprint. The expression for verifying environment consistency is as follows:

[0060]

[0061] in, This represents zero-knowledge proof. Describe the proof function. Indicates Hamming distance, Indicates the current hardware fingerprint, This indicates a comparison with hardware fingerprints. The threshold value for Hamming distance.

[0062] If both the signature validity and the consistency of the current hardware environment fingerprint are satisfied, it means that the verification is successful, the hardware environment of the second server is legitimate, and the target server components have not been replaced or altered. If the signature validity verification fails, it means that the verification data has been tampered with, indicating that the message is untrustworthy and the hardware environment of the second server is illegal, triggering the abnormal arbitration mechanism. If the signature validity verification passes, but the consistency verification of the current hardware environment fingerprint fails (i.e., the difference in the environment fingerprint is greater than the environment difference threshold), it means that the server components may have been replaced and the hardware environment of the second server is illegal, triggering the abnormal arbitration mechanism.

[0063] Furthermore, in the embodiments of this application, before obtaining the reference hardware fingerprint of the second server storing the database, the method further includes: obtaining the last update time of the database; calculating the first interval duration between the current time and the last update time; if the first interval duration reaches the update threshold, obtaining the current hardware environment fingerprint of the second server, and updating the database according to the current hardware environment fingerprint.

[0064] Among them, the update time is the specific point in time when the key information update operation is performed in the hardware anti-counterfeiting process of the distributed cluster; the first interval duration is the update interval duration between the current time and the last update time in the hardware anti-counterfeiting process of the distributed cluster; and the update threshold is the critical condition standard for determining whether the key information update needs to be performed in the hardware anti-counterfeiting process of the distributed cluster.

[0065] Understandably, by obtaining the current time and the last update time, calculating the first interval between them, and when the first interval reaches the update threshold, obtaining the current hardware environment fingerprint of the second server and updating the database, dynamic and accurate management of hardware fingerprints can be achieved, ensuring the synchronization between the baseline information in the database and the actual state of the nodes.

[0066] Specifically, the environmental fingerprint information undergoes subtle changes over time. These minor changes can cause old signatures to fail. Therefore, the hardware environmental fingerprint needs to be dynamically updated during use. It is stipulated that the hardware environmental fingerprint should be updated every time interval t. The dynamic update expression for the hardware environmental baseline fingerprint is:

[0067]

[0068] in, This represents the hardware environment baseline fingerprint for the next moment. This indicates Secure Hash Algorithm 3. This represents the baseline fingerprint of the hardware environment at the current moment. Indicates the current baseline fingerprint Data concatenation operators that are sequentially connected to Δ hardware changes. This represents the information on legitimate changes to the hardware environment that occur from time t to t+1.

[0069] Obtain the current time and the last update time, calculate the time interval between the current time and the last update time as the first interval duration, compare the first interval duration with the update threshold, and if the first interval duration reaches the update threshold, obtain the current hardware environment fingerprint of the second server and update the database.

[0070] Furthermore, in the embodiments of this application, verifying the consistency of the current hardware environment fingerprint based on the reference hardware environment fingerprint includes: calculating the Hamming distance between the reference hardware environment fingerprint and the current hardware environment fingerprint; if the Hamming distance is less than a distance threshold, the consistency of the current hardware environment fingerprint is determined to be passed; otherwise, the consistency verification of the current hardware environment fingerprint fails.

[0071] Hamming distance is a quantitative indicator that measures the degree of difference between two strings or data sequences of equal length; the distance threshold is the maximum allowed value of the Hamming distance set in advance.

[0072] Understandably, by calculating the Hamming distance between the reference hardware environment fingerprint and the current hardware environment fingerprint, and comparing the Hamming distance with a distance threshold, it is determined whether the consistency of the current hardware environment fingerprint passes. The introduction of a Hamming distance fault tolerance mechanism, combined with a dynamic threshold, greatly improves the signature verification pass rate under minor environmental fluctuations, ensuring the accuracy of security verification and the controllability of relaxing the threshold, making the authorization conform to the specifications, strengthening device identity authentication, and ensuring data security.

[0073] Specifically, the reference hardware environment fingerprint is taken as the correct hardware state of the device, and the Hamming distance is calculated using the current hardware environment fingerprint and the reference hardware environment fingerprint. The formula for calculating the Hamming distance is as follows:

[0074]

[0075] in, Indicates Hamming distance, Indicates the current hardware fingerprint, This represents the baseline hardware fingerprint.

[0076] The Hamming distance is compared with a distance threshold. If the Hamming distance is less than the distance threshold, it means that there has been no fundamental or unauthorized change to the current hardware environment, and the consistency of the fingerprint in the current hardware environment is confirmed to be successful. If the Hamming distance is greater than the distance threshold, it means that the difference is too large and exceeds the acceptable range, and the consistency verification of the fingerprint in the current hardware environment is confirmed to be unsuccessful.

[0077] Furthermore, in the embodiments of this application, before verifying the consistency of the current hardware environment fingerprint based on the reference hardware environment fingerprint, the method further includes: obtaining a pre-set basic threshold and the setting time of the basic threshold; calculating a second interval duration between the current time and the setting time; and calculating a distance threshold based on the basic threshold and the second interval duration.

[0078] The basic threshold is the initial value of the hardware difference limit set by the system during the initial configuration phase; the second interval is the time difference between the initial threshold taking effect and the current verification requirement.

[0079] Understandably, by calculating the second interval duration using the current time and the set time, and by calculating the distance threshold using the base threshold and the second interval duration, the distance threshold can be reasonably relaxed over time to accommodate legitimate minor changes in hardware, ensuring the accuracy of security verification and the controllability of relaxing the threshold.

[0080] Specifically, by obtaining the set base threshold, the initial allowable difference value can be determined. The setting time of the base threshold, combined with the current time, is used to calculate the second interval duration from factory to the present. The longer the hardware usage time, i.e., the second interval duration, the more relaxed the upper limit of the allowable normal difference for the distance threshold can be. The distance threshold is calculated by setting an update threshold calculation formula, where the update threshold calculation formula is:

[0081]

[0082] in, This indicates that a dynamic threshold for setting and updating is being implemented. Indicates the Hamming distance threshold. Indicates the aging coefficient. This indicates the device's current runtime (in years).

[0083] This application embodiment can construct a dual verification and trust guarantee mechanism for the validity of the signature and the consistency of the hardware environment fingerprint. When the first interval reaches the update threshold, the current hardware environment fingerprint of the second server is obtained and the database is updated. By introducing a Hamming distance fault tolerance mechanism and combining it with a dynamic threshold, the distance threshold can be reasonably relaxed according to the usage time. This enables dynamic and accurate management of hardware fingerprints, adapts to legitimate minor changes in hardware, ensures the accuracy of security verification and the controllability of relaxing the threshold, and ensures the synchronization of baseline information in the database with the actual state of the node.

[0084] To better understand the solution of this application, the server hardware anti-counterfeiting method or execution flow of this application is described below through a specific embodiment, as follows:

[0085] In step S201, a server cluster is constructed.

[0086] Each server collects local hardware information and generates a server hardware environment fingerprint upon startup.

[0087] In step S202, hardware information is obtained to generate a hardware environment fingerprint.

[0088] Each server sends the collected environmental fingerprint information to other nodes, and does not retain the environmental fingerprint information locally.

[0089] In step S203, fingerprints are distributed to cluster nodes.

[0090] Every 30 minutes, each server initiates a verification process.

[0091] In step S204, timing begins.

[0092] Check if 30 minutes have been elapsed. If 30 minutes have been elapsed, initiate server verification. If 30 minutes have not been elapsed, wait one minute and restart the timer.

[0093] In step S205, the server initiates verification.

[0094] Initiate verification to the second server.

[0095] In step S206, a challenge code is generated and sent to the second server.

[0096] Verify the challenge code generated by the first server using encryption.

[0097] In step S207, the second server decrypts the data.

[0098] The second server decrypts the challenge code.

[0099] In step S208, the second server collects hardware information to generate a hardware environment fingerprint.

[0100] After successful decryption, the second server collects hardware information data of the local server node to generate the current environment fingerprint.

[0101] In step S209, the second server performs fingerprint signing based on the hardware environment.

[0102] The second server uses an improved ElGamal algorithm to generate signatures.

[0103] In step S210, the second server sends the hardware environment fingerprint and signature to the first server.

[0104] The second server will send the message The signature is sent to the first server.

[0105] In step S211, the first server receives data.

[0106] The first server receives data sent by the second server.

[0107] In step S212, the signature validity is verified: the first server verifies the signature validity. If the signature validity verification fails, an exception arbitration mechanism is triggered. If the signature validity verification succeeds, the environmental consistency is further verified.

[0108] In step S213, verify the environment consistency: if the environment consistency verification is successful, it means that the second server component has not been replaced or changed, the second server is secure, and this verification ends. If the environment consistency verification fails, the abnormal arbitration mechanism is triggered.

[0109] In step S214, it is determined whether the predetermined time for updating hardware environment variables has been reached: if the predetermined time for updating hardware environment variables has been reached, the hardware environment variables in the cluster are updated; if the predetermined time for updating hardware environment variables has not been reached, the determination is repeated after 30 minutes.

[0110] In step S215, update the hardware environment variables in the cluster: dynamically update the environment fingerprint when the predetermined time node is reached.

[0111] In summary, the server hardware anti-counterfeiting method proposed in this application generates a challenge code using the node characteristics and random numbers of a second server. A verification process is initiated to the second server at specified intervals. The second server successfully decrypts the challenge code, generates a current environment fingerprint and signature, and sends them back to the first server. After verifying the validity of the signature, the first server uses Hamming distance to verify the consistency of the current hardware environment fingerprint distance threshold. When both the signature and hardware environment fingerprint verifications are successful and the update threshold is reached, the environment fingerprint is dynamically updated. This establishes a dynamic mutual verification mechanism between nodes, verifying the legality of each server hardware component in the cluster in real time. Combined with the dynamic threshold, it improves the signature verification pass rate under minor environmental fluctuations, ensuring that each server component passes trusted authentication. This constructs a three-dimensional hardware security system from single-machine to cluster level, effectively preventing counterfeit hardware implantation and illegal component replacement.

[0112] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0113] The embodiments of this application also provide another method for server hardware anti-counterfeiting, such as... Figure 3 As shown, the server hardware anti-counterfeiting method includes the following steps:

[0114] In step S301, the challenge code sent by the first server in the distributed cluster is obtained, wherein the challenge code is generated by the first server based on the node characteristics of the second server and a random number.

[0115] Understandably, by acquiring and decrypting the challenge code generated by the first server based on the node characteristics and random number encryption of the acquired second server, the second server can verify the authenticity and legitimacy of the second server's identity, thus establishing a trusted prerequisite for subsequent secure interactions and ensuring the uniqueness of the verification and the legitimacy of the authorization.

[0116] Specifically, a distributed cluster deploys a node identity information database, recording unique and immutable characteristics of all legitimate nodes, such as the MAC (Media Access Control) address of the second server and the NodeID (Node Identifier) ​​assigned by the cluster. The first server queries the node identity information database through cluster communication protocols such as gRPC (gRPC Remote Procedure Call) and HTTPS (Hypertext Transfer Protocol Secure), passing in identifiers such as the NodeID of the second server to obtain the node characteristics of the second server. The obtained characteristics must be completely consistent with the characteristics actually possessed by the second server; otherwise, subsequent verification will fail. The first server uses a cryptographically secure random number generator such as CSPRNG (Cryptographically Secure Pseudorandom Number Generator) to generate unpredictable, non-repeating random numbers of at least 16 bytes, and immediately stores them in the first server's verification session cache after generation.

[0117] The first server generates a challenge code based on the node characteristics and random number of the second server. By obtaining and decrypting the challenge code, the second server can verify the authenticity and legitimacy of its identity, establishing a trusted prerequisite for subsequent secure interactions and ensuring the uniqueness of the verification and the legitimacy of the authorization.

[0118] In step S302, after successfully decrypting the challenge code, a current hardware environment fingerprint of the second server is generated based on at least one hardware feature within the second server, and a signature is generated based on the current hardware environment fingerprint and a random number.

[0119] Understandably, the second server decrypts the challenge code and generates a hardware environment fingerprint of the second server at the current moment based on at least one hardware feature within the second server. Then, it generates a signature to verify the legitimacy of the hardware components of each server in the cluster, effectively preventing the implantation of counterfeit hardware and the replacement of illegal components, thus ensuring the security of the hardware at the cluster level.

[0120] Specifically, after receiving the challenge code, the server where the second server is located uses the public key in the first server to decrypt the encrypted content and obtain the original information. The server where the second server is located then drives the BIOS (Basic Input / Output System) interface, hardware management tools and other underlying technologies to read its own current hardware core information in real time and generate the current hardware fingerprint. Then, the server where the second server is located uses the stored private key to encrypt the current hardware fingerprint and random number to generate a digital signature.

[0121] Furthermore, in the embodiments of this application, generating a signature based on the current hardware environment fingerprint and a random number includes: calculating a hash value based on the current hardware environment fingerprint and a random number; selecting a prime number from a preset prime number field, and determining the generator of the cyclic group based on the prime number; generating a private key, a public key, and a temporary parameter based on the generator; generating a session key based on the private key, the current hardware environment fingerprint, and the random number, wherein the public key is used to verify the validity of the signature; and calculating the signature based on the private key, the temporary parameter, the session key, and the hash value.

[0122] Among them, the preset prime field is a special form of finite field containing p elements from 0 to p-1. The result of addition and multiplication operations on all elements is divided by p and the remainder is taken to ensure that the result is within the range of elements in the finite field. A prime number is a natural number greater than 1 that cannot be divided by any other natural number except 1 and itself. A generator is a core characteristic element in a finite group that generates all elements in the group through repeated operations. A private key is a secret parameter held exclusively by the user in an asymmetric encryption system and kept absolutely confidential. A public key is a parameter that can be publicly propagated and derived from the private key using a fixed algorithm. A temporary parameter is a parameter that is temporarily generated during a single cryptographic interaction and can be destroyed after use. A session key is a short-term key that is temporarily negotiated and generated by both parties during a communication session for use in symmetric encryption.

[0123] Understandably, the second server generates a signature based on the fingerprint and random number of the current hardware environment. This requires calculating the hash value of the fingerprint and random number, selecting a prime number to determine the generator, and generating a private key, public key, and temporary parameters. The signature is generated by calculating the private key, temporary parameters, session key, and hash value. This constructs a security mechanism that ensures the hardware is unforgeable, the key is difficult to crack, the session cannot be replayed, and the data cannot be tampered with. This ensures that authorized nodes with intact hardware participate in cluster communication, thus preventing hardware-level and network-level security threats from the bottom layer.

[0124] Specifically, the hash value is calculated using the fingerprint and random number of the current hardware environment. By combining multiple hash functions, multiple rounds of hash calculation, or multi-dimensional data input, the final hash result is generated. The expression for the composite hash is:

[0125] ,

[0126] in, This represents a 512-bit hash value for the message and environment output. Indicates the specific hash function, This indicates the original data that needs to be hash-protected. This indicates data concatenation; E indicates that the SHA3 output is a 256-bit hardware environment fingerprint. Represents a random number.

[0127] Choose prime numbers from the prime field of the discrete logarithm problem, such that the prime field satisfies:

[0128] p = 2q + 1

[0129] Where p represents the prime field and q represents a large prime number.

[0130] Prime numbers determine the generators in a cyclic group, and the generators satisfy:

[0131]

[0132]

[0133]

[0134] in, Represents generator, Represents a cyclic group. Indicates that the generator g is in the group In the order p, p represents the prime field.

[0135] The generator generates the signer's private key, the publicly verified public key, and temporary parameters for a single signing session. The private key is a random 256-bit integer that satisfies:

[0136]

[0137] in, Let p represent the private key and p represent the prime number field.

[0138] The public key satisfies:

[0139]

[0140] in, Represents the public key. Represents generator, Let p represent the private key and p represent the prime number field.

[0141] Temporary parameters satisfy:

[0142]

[0143] in, This represents a temporary parameter obtained by taking the k-th power of the generator g modulo p. represents a temporary parameter, and p represents the prime field.

[0144] To eliminate the risk of temporary parameters, the session key can be generated using the HKDF (HMAC-based Extract-and-Expand Key Derivation Function) extraction-expand key derivation function, expressed as:

[0145]

[0146]

[0147]

[0148] in, Indicates a temporary parameter. This represents the extract-expand key derivation function. This represents the private key. This indicates data concatenation; E indicates that the SHA3 output is a 256-bit hardware environment fingerprint. Let p represent random numbers, and p represent the prime number field. This represents the greatest common divisor.

[0149] This application embodiment calculates the hash value of the current hardware environment fingerprint and random number by a second server, decrypts the challenge code, and generates the hardware environment fingerprint of the second server at the current moment based on at least one hardware feature within the second server. Prime numbers are selected to determine the generator and generate a private key, a public key, and temporary parameters. The signature is generated by calculating the private key, temporary parameters, session key, and hash value. This ensures that authorized nodes with intact hardware participate in cluster communication, effectively prevents forged hardware implantation and illegal component replacement, and protects the security of the hardware at the cluster level.

[0150] In step S303, the current hardware environment fingerprint and signature are sent to the first server, and the first server verifies the hardware environment of the second server based on the current hardware environment fingerprint and signature.

[0151] Understandably, the first server receives the current hardware environment fingerprint and signature sent by the second server, and verifies the hardware environment of the second server. This verifies the legitimacy of the physical hardware in the second server, ensuring that it has not been tampered with or replaced, thus guaranteeing the authenticity of the second server's identity and the integrity of the hardware information transmission.

[0152] Specifically, after receiving the hardware environment fingerprint and signature, the first server queries the legitimate hardware feature database to check if the received fingerprint matches the second server's pre-stored legitimate fingerprint. If they match, the signature's identity verification is further confirmed. The management node decrypts the signature using the second server's public key. If the decrypted content is completely identical to what the first server sent, the second server's legitimacy is confirmed. The pre-stored legitimate fingerprint is the aforementioned reference hardware environment fingerprint.

[0153] The first server receives the current hardware environment fingerprint and signature sent by the second server, verifies the hardware environment of the second server, verifies the legitimacy of the physical hardware in the second server, ensures that it has not been tampered with or replaced, and guarantees the authenticity of the second server's identity and the integrity of hardware information transmission.

[0154] In summary, the server hardware anti-counterfeiting method proposed in this application involves generating a challenge code in the first server using the node characteristics of the second server and a random number. A verification process is initiated to the second server at specified intervals. The second server successfully decrypts the challenge code, generates a current environment fingerprint and a signature, and sends them back to the first server. After verifying the validity of the signature, the first server uses Hamming distance to verify the consistency of the current hardware environment fingerprint distance threshold. When both the signature and hardware environment fingerprint verifications are successful and the update threshold is reached, the environment fingerprint is dynamically updated. This establishes a dynamic mutual verification mechanism between nodes, verifying the legality of each server hardware component in the cluster in real time. Combined with the dynamic threshold, it improves the signature verification pass rate under minor environmental fluctuations, ensuring that each server component passes trusted authentication. This constructs a three-dimensional hardware security system from single-machine to cluster level, effectively preventing counterfeit hardware implantation and illegal component replacement.

[0155] Figure 4 This is a schematic diagram of the structure of a server hardware anti-counterfeiting device provided in an embodiment of this application.

[0156] like Figure 4 As shown, the server hardware anti-counterfeiting device 400 includes: an acquisition module 401, a generation module 402, and a verification module 403.

[0157] The acquisition module 401 is used to acquire the node characteristics and random number of the second server in the distributed cluster; the generation module 402 is used to encrypt and generate a challenge code based on the node characteristics and random number of the second server, and send the challenge code to the second server; after the second server successfully decrypts the challenge code and obtains the random number, the second server generates the current hardware environment fingerprint of the second server based on at least one hardware characteristic of the second server, and generates a signature based on the current hardware environment fingerprint and random number; the verification module 403 is used to verify the hardware environment of the second server based on the current hardware environment fingerprint and signature.

[0158] Furthermore, in this embodiment of the application, the generation module 402 is further configured to: input the node characteristics and random number of the second server into a pre-set target encryption algorithm, so as to obtain a challenge code by binding the node characteristics and random number of the second server using the target encryption algorithm.

[0159] Furthermore, in this embodiment of the application, the verification module 403 is further used to: verify the validity of the signature; call the database of the first server to obtain the reference hardware environment fingerprint of the second server stored in the database, and verify the consistency of the current hardware environment fingerprint based on the reference hardware environment fingerprint; if the validity of the signature and the consistency verification of the current hardware environment fingerprint pass, then the hardware environment of the second server is determined to be legal; otherwise, the hardware environment of the second server is determined to be illegal, and the second server is isolated.

[0160] Furthermore, in this embodiment of the application, the server hardware anti-counterfeiting device 400 further includes: a first computing module.

[0161] The first calculation module is used to obtain the last update time of the database before obtaining the reference hardware fingerprint of the second server stored in the database; calculate the first interval between the current time and the last update time; if the first interval reaches the update threshold, obtain the current hardware environment fingerprint of the second server and update the database according to the current hardware environment fingerprint.

[0162] Furthermore, in this embodiment, the verification module 403 is further configured to: calculate the Hamming distance between the reference hardware environment fingerprint and the current hardware environment fingerprint; if the Hamming distance is less than the distance threshold, then the consistency verification of the current hardware environment fingerprint is determined to be successful; otherwise, the consistency verification of the current hardware environment fingerprint fails.

[0163] Furthermore, in this embodiment of the application, the server hardware anti-counterfeiting device 400 further includes: a second computing module.

[0164] The second calculation module is used to obtain a pre-set basic threshold and the setting time of the basic threshold before verifying the consistency of the current hardware environment fingerprint based on the reference hardware environment fingerprint; calculate the second interval duration between the current time and the setting time; and calculate the distance threshold based on the basic threshold and the second interval duration.

[0165] Furthermore, in this embodiment of the application, the server hardware anti-counterfeiting device 400 also includes an initialization module.

[0166] The initialization module is used to initialize the distributed cluster before obtaining the node characteristics and random number of the second server, collect at least one local hardware characteristic, generate the hardware environment fingerprint of the first server based on the at least one hardware characteristic, send the hardware environment fingerprint to other nodes in the distributed cluster, and then delete the hardware environment fingerprint of the first server. After the initialization of the distributed cluster is completed, the second server is subjected to server hardware anti-counterfeiting verification at preset intervals.

[0167] In summary, the server hardware anti-counterfeiting device proposed in this application generates a challenge code in the first server using the node characteristics of the second server and a random number. A verification process is initiated to the second server at specified intervals. The second server successfully decrypts the challenge code, generates a current environment fingerprint and signature, and sends them back to the first server. After verifying the validity of the signature, the first server uses Hamming distance to verify the consistency of the current hardware environment fingerprint distance threshold. When both the signature and hardware environment fingerprint verifications are successful and the update threshold is reached, the environment fingerprint is dynamically updated. This establishes a dynamic mutual verification mechanism between nodes, verifying the legality of each server hardware component in the cluster in real time. Combined with the dynamic threshold, it improves the signature verification pass rate under minor environmental fluctuations, ensuring that each server component passes trusted authentication. This constructs a three-dimensional hardware security system from single-machine to cluster level, effectively preventing counterfeit hardware implantation and illegal component replacement.

[0168] Figure 5 This is a schematic diagram of another server hardware anti-counterfeiting device provided in this application embodiment.

[0169] like Figure 5 As shown, the server hardware anti-counterfeiting device 500 includes: an acquisition module 501, a generation module 502, and a verification module 503.

[0170] The acquisition module 501 is used to acquire the challenge code sent by the first server in the distributed cluster. The challenge code is generated by the first server based on the node characteristics of the second server and a random number. The generation module 502 is used to generate the current hardware environment fingerprint of the second server based on at least one hardware feature of the second server after successfully decrypting the challenge code and obtaining the random number. The generation module 502 is used to generate a signature based on the current hardware environment fingerprint and the random number. The verification module 503 is used to send the current hardware environment fingerprint and the signature to the first server. The first server verifies the hardware environment of the second server based on the current hardware environment fingerprint and the signature.

[0171] Furthermore, in this embodiment, the generation module 502 is further configured to: calculate a hash value based on the current hardware environment fingerprint and a random number; select a prime number from a preset prime number field and determine the generator of the cyclic group based on the prime number; generate a private key, a public key, and temporary parameters based on the generator; generate a session key based on the private key, the current hardware environment fingerprint, and the random number; the public key is used to verify the validity of the signature; and calculate the signature based on the private key, the temporary parameters, the session key, and the hash value.

[0172] In summary, the server hardware anti-counterfeiting device proposed in this application generates a challenge code in the first server using the node characteristics of the second server and a random number. A verification process is initiated to the second server at specified intervals. The second server successfully decrypts the challenge code, generates a current environment fingerprint and signature, and sends them back to the first server. After verifying the validity of the signature, the first server uses Hamming distance to verify the consistency of the current hardware environment fingerprint distance threshold. When both the signature and hardware environment fingerprint verifications are successful and the update threshold is reached, the environment fingerprint is dynamically updated. This establishes a dynamic mutual verification mechanism between nodes, verifying the legality of each server hardware component in the cluster in real time. Combined with the dynamic threshold, it improves the signature verification pass rate under minor environmental fluctuations, ensuring that each server component passes trusted authentication. This constructs a three-dimensional hardware security system from single-machine to cluster level, effectively preventing counterfeit hardware implantation and illegal component replacement.

[0173] Embodiments of this application also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in the above-described embodiments of the server hardware anti-counterfeiting method.

[0174] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0175] The above provides a detailed description of a server hardware anti-counterfeiting method provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only intended to help understand the method and core ideas of this application. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this application.

Claims

1. A method for preventing counterfeiting of server hardware, characterized in that, The method is applied to the first server in a distributed cluster, and the method includes: Obtain the node characteristics and random numbers of the second server in the distributed cluster; A challenge code is generated by encrypting the node characteristics of the second server and the random number, and the challenge code is sent to the second server. After the second server successfully decrypts the challenge code to obtain the random number, the second server generates a current hardware environment fingerprint of the second server based on at least one hardware characteristic of the second server. The second server generates a signature based on the current hardware environment fingerprint and the random number. The hardware environment of the second server is verified based on the current hardware environment fingerprint and the signature.

2. The server hardware anti-counterfeiting method according to claim 1, characterized in that, The step of generating a challenge code by encrypting the node characteristics of the second server and the random number includes: The node characteristics of the second server and the random number are input into a pre-set target encryption algorithm to obtain the challenge code by binding the node characteristics of the second server and the random number using the target encryption algorithm.

3. The server hardware anti-counterfeiting method according to claim 1, characterized in that, The step of verifying the hardware environment of the second server based on the current hardware environment fingerprint and signature includes: Verify the validity of the signature; The database of the first server is invoked to obtain the reference hardware environment fingerprint of the second server stored in the database, and the consistency of the current hardware environment fingerprint is verified based on the reference hardware environment fingerprint. If the validity of the signature and the consistency verification of the current hardware environment fingerprint pass, the hardware environment of the second server is determined to be legitimate; otherwise, the hardware environment of the second server is determined to be illegitimate, and the second server is isolated.

4. The server hardware anti-counterfeiting method according to claim 3, characterized in that, Before obtaining the reference hardware fingerprint of the second server stored in the database, the process also includes: Get the last update time of the database; Calculate the duration of the first interval between the current time and the last update time; If the first interval duration reaches the update threshold, the current hardware environment fingerprint of the second server is obtained, and the database is updated according to the current hardware environment fingerprint.

5. The server hardware anti-counterfeiting method according to claim 3, characterized in that, The step of verifying the consistency of the current hardware environment fingerprint based on the reference hardware environment fingerprint includes: Calculate the Hamming distance between the reference hardware environment fingerprint and the current hardware environment fingerprint; If the Hamming distance is less than the distance threshold, the consistency verification of the current hardware environment fingerprint is determined to be successful; otherwise, the consistency verification of the current hardware environment fingerprint fails.

6. The server hardware anti-counterfeiting method according to claim 5, characterized in that, Before verifying the consistency of the current hardware environment fingerprint based on the reference hardware environment fingerprint, the method further includes: Obtain the preset base threshold and the setting time of the base threshold; Calculate the second interval duration between the current time and the set time; The distance threshold is calculated based on the base threshold and the second interval duration.

7. The server hardware anti-counterfeiting method according to claim 1, characterized in that, Before obtaining the node characteristics and random number of the second server, the process also includes: The distributed cluster is initialized, at least one local hardware feature is collected, a hardware environment fingerprint of the first server is generated based on the at least one hardware feature, the hardware environment fingerprint is sent to other nodes in the distributed cluster, and then the hardware environment fingerprint of the first server is deleted. After the distributed cluster is initialized, the second server is subjected to server hardware anti-counterfeiting verification at preset intervals.

8. A method for preventing counterfeiting of server hardware, characterized in that, The method is applied to a second server in a distributed cluster, and the method includes: Obtain the challenge code sent by the first server in the distributed cluster, wherein the challenge code is generated by the first server based on the obtained node characteristics of the second server and a random number; After successfully decrypting the challenge code to obtain the random number, a current hardware environment fingerprint of the second server is generated based on at least one hardware feature within the second server, and a signature is generated based on the current hardware environment fingerprint and the random number. The current hardware environment fingerprint and the signature are sent to the first server, and the first server verifies the hardware environment of the second server based on the current hardware environment fingerprint and the signature.

9. The server hardware anti-counterfeiting method according to claim 8, characterized in that, The step of generating a signature based on the current hardware environment fingerprint and the random number includes: Calculate the hash value based on the current hardware environment fingerprint and the random number; Select a prime number from a preset prime number field, and determine the generator of the cyclic group based on the prime number; A private key, a public key, and temporary parameters are generated based on the generator. A session key is generated based on the private key, the current hardware environment fingerprint, and the random number. The public key is used to verify the validity of the signature. The signature is calculated based on the private key, the temporary parameter, the session key, and the hash value.

10. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the server hardware anti-counterfeiting method as described in any one of claims 1 to 9 when executing the computer program.

Citation Information

Patent Citations

  • Authentication method based on service identity identification key

    CN116170238A

  • Privacy authentication method and device based on zero-knowledge proof, equipment and medium

    CN120415745A