A locking authentication device and a locking authentication method

By locking the authentication device's multi-level permission verification mechanism, the security problem of sensitive resource carriers of network security devices is solved, and strict verification of device identity and strengthening of binding relationships are achieved to prevent replay attacks and unauthorized access, ensuring high security and availability of the network system.

CN121367620BActive Publication Date: 2026-04-03WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing network security devices lack deep interaction mechanisms for sensitive resource carriers, which cannot guarantee the security of network systems. Furthermore, traditional transmission media are insufficient in terms of encryption protection, identity authentication, and proactive defense, making them a weak link in the network security chain.

Method used

The system employs a locking authentication device, including mobile authentication devices and network security devices, and establishes a communication connection through a custom interface. It is configured with a multi-level permission verification mechanism, including first permission for device information, second permission for binding information, and third permission for dynamic updates, to ensure the authentication and binding relationship of legitimate devices. Dynamic permission codes prevent replay attacks and unauthorized access.

Benefits of technology

It implements strict verification of device identity and strengthens binding relationships to prevent replay attacks and brute-force attacks, ensuring full-process security control of network security devices and maintaining system availability and high security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121367620B_ABST
    Figure CN121367620B_ABST
Patent Text Reader

Abstract

This application belongs to the field of information security technology and relates to the transmission of digital information. Specifically, it discloses a locking authentication device and a locking authentication method. This application adopts a deep interaction architecture between a mobile authentication device and a network security device, and achieves security enhancement through a three-level permission verification mechanism. The system first verifies the identity information of the mobile authentication device, then verifies the device binding relationship, and finally achieves continuous authentication through dynamically updated permission codes. When any permission verification fails or exceeds the limit, the mobile authentication device is automatically locked. This design ensures that only legitimate devices that have completed the full authentication process can access sensitive resources, continuously preventing unauthorized access and replay attacks during the provision of network security services. Compared with existing technologies, this solution achieves full-process security control at the device authentication, resource protection, and service provision levels through hierarchical permission management and a dynamic update mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information security technology, specifically relating to the transmission of digital information, and more specifically, to a locking authentication device and a locking authentication method. Background Technology

[0002] Network security devices are deployed between an enterprise's trusted internal network and the internet, operating at the network layer to provide network security protection. Due to the inherent sensitivity of network security devices, sensitive resources are typically stored using resource segmentation and encryption to prevent the leakage of sensitive information within them.

[0003] Sensitive resource carriers, as key components of network security equipment, store sensitive resource data and provide resource data injection for network security devices. In the early days, the sensitive resource data to be injected into network security devices was small, and IC cards were often chosen as the carrier for delivery. As network security equipment has been upgraded, the demand for the capacity of transmitted sensitive resource data has increased, and the security requirements for transmitted sensitive resource data have also become more stringent.

[0004] Currently available transmission media are all general-purpose media, lacking data encryption and protection, making data security impossible to guarantee in the event of media loss. Furthermore, traditional resource transmission media have simple and limited functions, failing to play a crucial role in the secure operation and access control of network security equipment. Whether it's unauthorized users gaining access to network security equipment, malicious users stealing sensitive information, or data loss itself, these issues are difficult to prevent.

[0005] Therefore, the lack of encryption protection, identity authentication, and proactive defense capabilities in general-purpose transmission media makes it a weak and passive link in the cybersecurity chain. It not only fails to protect critical infrastructure but may also become a hidden danger that invites intruders. Summary of the Invention

[0006] In view of the shortcomings of the existing technology, the purpose of this application is to provide a locking authentication device and locking authentication method, which aims to solve the problem that the lack of deep interaction mechanism between existing sensitive resource carriers and network security devices makes it impossible to guarantee the security of the entire network system.

[0007] The first aspect of this application relates to a locking authentication device, comprising: a mobile authentication device and a network security device; the mobile authentication device includes: a first storage module, a first control module, and a custom interface; the first storage module and the first control module are communicatively connected; the network security device is communicatively connected to the mobile authentication device through the custom interface; the first control module is configured with a first permission for device authentication and a second permission for device binding; the first storage module is configured with a third permission for continuous authentication and stores sensitive resources; wherein, the first permission is device information of the mobile authentication device, the second permission is binding information written by the network security device, and the third permission is a license code written by the network security device and dynamically updated after each operation; the network security device is used to sequentially verify the first permission and the second permission when any mobile authentication device accesses the network, and after the first permission and the second permission verification is passed, access the first storage module and verify the third permission; when the third permission verification is passed, the first control module of the mobile authentication device is invoked to read sensitive resources to provide network security services; the mobile authentication device is used to enter a locked state when the number of failed verifications of any permission exceeds a preset value.

[0008] In one embodiment, the network security device includes: a second control module and a second storage module; the second control module is communicatively connected to the second storage module; the first control module is used to receive first verification information from the second control module and verify it with the first permission; the second control module is used to generate a second permission and store it in the second storage module and output it to the first control module when the second permission does not exist in the second storage module after the first permission verification is passed, and then drive the first control module to establish a storage area in the first storage module, and the second permission is associated with the storage area.

[0009] In one embodiment, the network security device further includes: a license code generation module and a data segmentation module; the license code generation module is communicatively connected to a second control module; the data segmentation module is communicatively connected to the second control module; the second control module is used to, after the first permission verification passes, call the second permission stored in the first control module to perform a second permission verification when a second permission exists in the second storage module; after the second permission verification passes, call the third permission of the second storage module and the license code of the storage area to perform a third permission verification; the second control module is used to, after the third permission verification passes, call the license code generation module to generate and update the license code and store it in the second storage module; if during the writing process, output the license code and the sensitive resource segmentation component segmented by the data segmentation module to the storage area; if during the reading process, output the license code to the storage area and read the sensitive resource component of the storage area.

[0010] In one embodiment, the mobile authentication device further includes: an encryption / decryption module; the encryption / decryption module is communicatively connected to the first control module and the first storage module; the first control module is configured to call the encryption / decryption module to encrypt the sensitive resources and store them in the first storage module when the sensitive resources are written to the first storage module; the first control module is also configured to call the encryption / decryption module to decrypt the sensitive resources transmitted from the first storage module and then transmit them to the network security device when the sensitive resources are read from the network security device.

[0011] In one embodiment, the network security device further includes: an in-situ detection module; the in-situ detection module is communicatively connected to a second control module; the second control module is used to enter a working state after reading sensitive resources and to call the in-situ detection module to detect the connection status of the mobile authentication device; the second control module is used to destroy sensitive resources when the connection status of the mobile authentication device is not connected, and the network security device switches from the working state to the locked state to stop providing network security services to the outside world.

[0012] In one embodiment, the presence check is to re-verify all permissions and update the third permission after all permissions have been verified.

[0013] In one embodiment, the network security device is a VPN device; the first control module is a SOC chip; and the first storage module is an SpiFlash chip.

[0014] The second aspect of this application relates to a locking authentication method, which applies the locking authentication device of the first aspect, comprising: performing a preset first permission check after any mobile authentication device is connected, and determining that the mobile authentication device is a legitimate device after the first permission check passes; performing a second permission check after determining that the mobile authentication device is a legitimate device, and determining that the mobile authentication device and the network security device have a binding relationship after the second permission check passes; performing a third permission check after determining that the mobile authentication device and the network security device have a binding relationship, and determining that the mobile authentication device is successfully authenticated after the third permission check passes; controlling the network security device to read sensitive resources of the mobile authentication device or write sensitive resources to the mobile authentication device to provide network security services; randomly generating and updating the third permission to achieve continuous authentication; and controlling the mobile authentication device to enter a locked state when the number of failed permissions check exceeds a preset value.

[0015] In one embodiment, after the mobile authentication device is identified as a legitimate device, a second permission verification is performed. After the second permission verification is passed, it is determined that the mobile authentication device and the network security device have a binding relationship. Before this, the method further includes: after the mobile authentication device is identified as a legitimate device, controlling the network security device to establish a storage area in the mobile authentication device, generating a second permission associated with the storage area, and then storing the second permission in the network security device and the mobile authentication device respectively; storing the sensitive resources obtained by the network security device in the storage area, and randomly generating a third permission and storing it in the storage area and the network security device.

[0016] In one embodiment, after determining that the mobile authentication device and the network security device have a binding relationship, a third permission verification is performed. After the third permission verification is passed, the mobile authentication device is deemed to have successfully authenticated. The network security device is then controlled to read the sensitive resources of the mobile authentication device to provide network security services. The third permission is randomly generated and updated to achieve continuous authentication. The method further includes: when the network security device provides network security services, detecting the connection status of the mobile authentication device; when the connection status of the mobile authentication device is disconnected, controlling the network security device to clear the sensitive resources and stop providing network services.

[0017] Overall, the technical solutions conceived in this application have the following beneficial effects compared with the prior art:

[0018] The technical solution proposed in this application adopts a structure in which the mobile authentication device includes a first storage module, a first control module, and a custom interface. It establishes a communication connection with the network security device through the custom interface, enabling bidirectional authentication and data exchange between the two. Furthermore, by configuring the first control module with a first permission based on device information and a second permission based on binding information, and configuring the first storage module with a dynamically updated third permission, the network security device must sequentially verify these three types of permissions when the mobile authentication device accesses the network. This multi-level permission verification mechanism ensures that only legitimate devices that have been authenticated and bound can access sensitive resources, thereby achieving strict verification of device identity and strengthening of the binding relationship.

[0019] Furthermore, since the third permission is dynamically updated after each operation, continuous authentication is achieved, effectively preventing replay attacks and unauthorized access; at the same time, since the mobile authentication device automatically enters a locked state when any permission verification fails and exceeds the limit, it provides security protection against brute-force attacks.

[0020] Compared with existing technologies, this solution maintains system availability while ensuring high security through the synergistic effect of the above-mentioned technical means, and realizes full-process security control from device authentication, resource access to service provision. Attached Figure Description

[0021] Figure 1 This is one of the structural block diagrams of the locking authentication device provided in the embodiments of this application;

[0022] Figure 2 This is a schematic diagram of the locking authentication device provided in the embodiments of this application;

[0023] Figure 3 This is a second structural block diagram of the locking authentication device provided in the embodiments of this application;

[0024] Figure 4 This is a flowchart illustrating the locking authentication method provided in an embodiment of this application;

[0025] Figure 5 This is a flowchart illustrating the write permission process of the locking authentication method provided in this application embodiment;

[0026] Figure 6 This is a schematic diagram of the in-situ detection process of the locking authentication method provided in the embodiments of this application.

[0027] In all the accompanying drawings, the same reference numerals are used to denote the same elements or structures, wherein:

[0028] 10 is a mobile authentication device; 11 is a first control module; 12 is a first storage module; 13 is an encryption / decryption module; 20 is a network security device; 21 is a second control module; 22 is a second storage module; 23 is a license code generation module; 24 is a data segmentation module; and 25 is an in-situ detection module. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0030] It should be understood that expressions such as “comprising” and “may include” used in this application indicate the existence of the disclosed functions, operations, or constituent elements, and do not limit one or more additional functions, operations, and constituent elements. In this application, terms such as “comprising” and / or “having” are to be interpreted as indicating a particular characteristic, number, operation, constituent element, component, or combination thereof, but not to exclude the existence or possibility of adding one or more other characteristics, numbers, operations, constituent elements, components, or combinations thereof.

[0031] Furthermore, in this application, the expression "and / or" includes any and all combinations of the associated listed words. For example, the expression "A and / or B" may include A, may include B, or may include both A and B.

[0032] In the description of the embodiments of this application, it should be noted that, unless otherwise explicitly specified and limited, the term "communication connection" should be interpreted broadly. It can refer to a wired communication connection established through physical cables, such as USB, Ethernet cables, or custom interface cables, or a wireless communication connection established through wireless communication technologies, such as Wi-Fi, Bluetooth, ZigBee, Near Field Communication (NFC), or cellular mobile networks. Furthermore, the connection can be a direct connection between two components or modules, or an indirect connection established through intermediate devices, relay modules, or communication networks, such as routers, switches, or gateways. The communication method can be based on any existing or future-developed wired or wireless communication protocol, with the aim of enabling the transmission and interaction of data or signals between the two endpoints of the connection.

[0033] Currently, the transfer of data and resources largely relies on physical media such as portable hard drives. However, these commercially available transfer media generally suffer from significant security flaws. While designed for convenient data storage and movement, they typically lack mechanisms for data encryption. This means that if the media is lost or stolen, all stored data, including sensitive information, system configuration files, and operation logs, will be exposed to malicious third parties. Data security depends entirely on the moral integrity of the finder, which is extremely vulnerable in reality.

[0034] Looking further, the function of traditional resource transfer media is too simple and singular, limiting their role to data transport and failing to integrate into the overall network security protection system. In the operation and maintenance scenarios of critical network security equipment such as firewalls and intrusion detection systems, these media could play a crucial role in the secure operation and access control of the equipment, but the current situation is quite the opposite. For example, during equipment configuration updates or system recovery, an unverified ordinary external hard drive can become a springboard for attacks. It may be maliciously implanted with Trojans or have its configuration files tampered with. When maintenance personnel use it, it may cause equipment configuration errors and service interruptions, or even open a hidden backdoor channel for attackers, allowing them to illegally access or even control the secure equipment.

[0035] Based on this, this application proposes a locking authentication device. Please refer to... Figure 1 , Figure 1 This is one of the structural block diagrams of the locking authentication device provided in the embodiments of this application.

[0036] In this embodiment, the authentication device includes a mobile authentication device 10 and a network security device 20. Specifically, the mobile authentication device 10 includes a first storage module 12, a first control module 11, and a custom interface. The first storage module 12 and the first control module 11 are communicatively connected; the network security device 20 is communicatively connected to the mobile authentication device 10 through the custom interface.

[0037] It should be noted that the mobile authentication device 10, in its physical form, can be understood as a dedicated portable device with a built-in security chip. It is not merely an ordinary mobile device, but more akin to a smart token or hardware security key integrated with security elements. The network security device 20, in its physical form, refers to hardware devices deployed at critical network nodes that require extremely high security. It is typically a core component of an enterprise or organization's network infrastructure, and its specific implementation can include firewalls, VPN gateway devices, or servers.

[0038] Further, please refer to Figure 2 , Figure 2 This is a schematic diagram of the locking authentication device provided in this application embodiment. As shown, the mobile authentication device 10 on the left is a compact, flat, red structure, easy to carry and manage; the network security device 20 on the right is a standard black rack-mount device, reflecting its core position in the network infrastructure. The two establish a physical connection through a clearly defined custom interface. In the figure, the front panel of the network security device 20 has a dedicated insertion slot, whose physical specifications and electrical definitions match the interface at the end of the mobile authentication device 10. When the mobile authentication device 10 is directly inserted into this slot, the communication interfaces of the two automatically align and connect stably, forming an integrated unit. This connection method has the advantages of reliable contact and compact structure.

[0039] In addition, the mobile authentication device 10 and the network security device 20 can also be connected to a custom interface via an external cable. In this case, the interfaces of the mobile authentication device 10 and the network security device 20 are bridged through a dedicated cable, providing deployment flexibility.

[0040] It should be noted that the core of the custom interface in this application lies in the proprietary nature of its communication protocol and security authentication logic, rather than necessarily referring to a specific non-standard physical form. Therefore, the interface can physically use industry-standard interfaces such as USB, Type-C, or RJ45 Ethernet ports, but its underlying driver and data exchange protocol are custom-defined, thus achieving a logical distinction from general-purpose storage devices while utilizing mature hardware.

[0041] It should be noted that the first control module 11 is configured with a first permission for device authentication and a second permission for device binding; the first storage module 12 is configured with a third permission for continuous authentication and stores sensitive resources; wherein, the first permission is the device information of the mobile authentication device 10, the second permission is the binding information written by the network security device 20, and the third permission is the license code written by the network security device 20 and dynamically updated after each operation.

[0042] Understandably, the core security of this device lies in its finely defined access control and dynamic authentication mechanism. Inside the mobile authentication device 10, the first control module 11 is configured with two key permissions: first permission and second permission.

[0043] Understandably, the first permission is the mobile authentication device 10's own digital identity card, which is essentially the device's unique and unalterable device information, such as a unique identifier or digital certificate within the hardware security module. When the device connects, this permission is used to prove its identity to the network security device 20, that is, to complete the initial identity authentication of the device and confirm whether it is a legitimate device. A legitimate device refers to a terminal device with a genuine and trustworthy identity, and which has been explicitly authorized by the system or network to communicate or access.

[0044] Specifically, the first permission can be set to administrator permission. This administrator permission is set at the factory when the mobile authentication device 10 is manufactured. The administrator permission is responsible for setting the attributes of the mobile authentication device 10 and setting and unlocking user permissions. In other words, the administrator permission restricts which network security devices 20 the mobile authentication device 10 can work on.

[0045] Understandably, the second permission is the foundation of trust for device binding. This permission is not pre-set, but rather binding information written by the authorized network security device 20 in a trusted initialization environment, such as the unique identifier of the target device. This establishes a unique and mandatory binding relationship between the mobile authentication device 10 and the specific network security device 20, ensuring that the mobile authentication device cannot be used on other unbound devices, fundamentally preventing cross-device abuse.

[0046] Meanwhile, the first storage module 12 is not only used to securely store sensitive resources such as configurations, keys, and logs, but is also configured with third-party permissions. This permission is a dynamic permission code written by the network security device 20 and maintained on the mobile authentication device 10. Its core function is to achieve continuous authentication. Specifically, after each successful interaction, such as reading a configuration or writing a log, the network security device 20 generates a new permission code and updates it in the mobile authentication device 10. This is like a dynamically changing one-time password, ensuring that even if the mobile authentication device is lost, attackers cannot reuse the state from the previous interaction to perform illegal operations, because all previous permission codes have expired. This design achieves continuous authentication of communication, greatly improving the system's proactive defense capabilities.

[0047] Therefore, in practical implementation, the first control module 11 can be implemented using a SOC chip. The SOC chip can efficiently perform device authentication, permission verification, communication protocol processing, and manage the entire device's operational logic. Its powerful processing capabilities provide the hardware foundation for implementing complex triple-authorization authentication processes. The first storage module 12 can be implemented using an SpiFlash chip. As a common non-volatile memory, the SpiFlash chip communicates with the SOC chip through a standard SPI interface, making it ideal for securely storing sensitive resources such as system configurations, encryption keys, and dynamically updated license codes. Its advantages include low cost, high reliability, and communication entirely controlled by the SOC chip as the master controller. This creates ideal conditions for the first control module 11 to implement access control over the stored content.

[0048] It should be noted that the network security device 20 is used to sequentially verify the first permission and the second permission when any mobile authentication device 10 accesses the network, and after the first permission and the second permission are verified, it accesses the first storage module 12 and verifies the third permission.

[0049] Understandably, when mobile authentication device 10 connects to network security device 20 via a custom interface, a tightly linked authentication chain is immediately triggered. Network security device 20, as the process leader, first performs dual identity verification on mobile authentication device 10: verifying its first permission—the administrator permission preset at the factory as the device's root identity—and its second permission—the binding information written during the device binding phase to establish a unique association with the specific network security device 20. Only after both layers of permissions have been verified successfully does network security device 20 gain preliminary qualification to access the first storage module 12, and then proceed to the third permission verification phase—the dynamic license code verification phase.

[0050] It should be noted that when the third permission verification passes, the network security device 20 calls the first control module 11 of the mobile authentication device 10 to read sensitive resources in order to provide network security services; the mobile authentication device 10 is used to enter a locked state when the number of failed permission verifications exceeds a preset value.

[0051] Understandably, the third permission verification phase aims to confirm the continuity of the current session and effectively prevent replay attacks. Only when all three permissions are verified successfully can the network security device 20 invoke the first control module 11 to securely read sensitive resources stored in the first storage module 12, thereby obtaining and providing critical network security services.

[0052] Understandably, to strengthen proactive defense, the mobile authentication device 10 incorporates a security locking mechanism: at any stage of the authentication process, if the number of consecutive failed verifications for a single permission exceeds a preset threshold, the device will immediately enter a locked state, cutting off all functions and refusing subsequent attempts until manual intervention by an authorized administrator. This progressive verification system, from identity authentication and device binding to operational continuity verification, constitutes a defense-in-depth architecture, ensuring that only legitimate, bound devices in a trusted session can enable critical services, thus achieving a balance between ease of operation and maintenance and system security.

[0053] In this embodiment, the mobile authentication device is designed with a structure including a first storage module, a first control module, and a custom interface. A communication connection is established with the network security device through the custom interface, enabling bidirectional authentication and data interaction between the two. Furthermore, the first control module is configured with a first permission based on device information and a second permission based on binding information, and the first storage module is configured with a dynamically updated third permission. This requires the network security device to sequentially verify these three types of permissions when the mobile authentication device accesses the network. This multi-level permission verification mechanism ensures that only legitimate devices that have been authenticated and bound can access sensitive resources, thereby achieving strict verification of device identity and strengthening of the binding relationship.

[0054] Furthermore, since the third permission is dynamically updated after each operation, continuous authentication is achieved, effectively preventing replay attacks and unauthorized access; at the same time, since the mobile authentication device automatically enters a locked state when any permission verification fails and exceeds the limit, it provides security protection against brute-force attacks.

[0055] Compared with existing technologies, this solution maintains system availability while ensuring high security through the synergistic effect of the above-mentioned technical means, and realizes full-process security control from device authentication, resource access to service provision.

[0056] Based on the embodiments described above, this application improves upon them by integrating more components into the mobile authentication device 10 and the network security device 20 to achieve a more secure implementation. Please refer to... Figure 3 , Figure 3 This is the second structural block diagram of the locking authentication device provided in the embodiments of this application.

[0057] In this embodiment, the network security device 20 will be described in detail using a VPN device as an example.

[0058] In this embodiment, the network security device 20 includes: a second control module 21 and a second storage module 22; the second control module 21 and the second storage module 22 are communicatively connected.

[0059] It should be noted that the first control module 11 is used to receive the first verification information from the second control module 21 and verify the first permission.

[0060] Understandably, when a network security device 20, such as a VPN device, accesses a mobile authentication device 10, it first verifies administrator privileges, i.e., first-level privileges. The second control module 21 then sends a pre-set administrator password along with the command code CHECK_ADMINPIN to the first control module 11 of the mobile authentication device 10. The first control module 11 of the mobile authentication device 10 verifies the administrator privileges issued by the VPN device. Only after successful verification is the VPN device allowed to set its own attribute information for the mobile authentication device 10, mainly including device type, device user, device attribute setting time, and other related attributes. This design ensures that the root identity of the mobile authentication device must be verified before any high-level operations such as device binding and resource access are executed, thus establishing an initial trust foundation for the entire authentication system.

[0061] It should be noted that the second control module 21 is used to generate a second permission in the second storage module 22 and output it to the first control module 11 after the first permission verification is passed, when there is no second permission bound to the network security device 20 in the second storage module 22. Then, it drives the first control module 11 to establish a storage area in the first storage module 12, and the second permission is associated with the storage area.

[0062] It is understandable that in the binding initialization process of this application, the second control module 21 of the network security device 20 plays a core driving and coordinating role. Specifically, after successfully completing the first permission verification (i.e., administrator permission verification) of the mobile authentication device 10, if the second control module 21 detects that there is no second permission in the second storage module 22 that is currently bound to the network security device 20, it means that the two devices have not been bound before, and the device binding process will be automatically triggered.

[0063] Understandably, the second control module 21 dynamically generates a unique second permission and stores it in the second storage module 22. This permission typically contains encrypted data consisting of elements such as the unique identifier of the network security device 20, a random sequence, and a digital signature. This complete binding information packet is then output to the first control module 11 of the mobile authentication device 10. Upon receiving the second permission, the first control module 11 immediately creates an independent storage area dedicated to the network security device 20 within the first storage module 12. This storage area logically establishes a strict association with the incoming second permission, ensuring that all subsequent operations based on this binding relationship are performed within this isolated secure space.

[0064] Understandably, in order to build a two-way authentication mechanism, the second control module 21 will simultaneously write this newly generated second permission to the second storage module 22 on the local network security device 20 for persistent storage.

[0065] For example, after the VPN device completes administrator privilege verification for the mobile authentication device, it can create a directory in the first storage module 12 and set user permissions in the first control module, namely access permissions to file directories and files, allowing operations on directories and files. In other words, user permissions restrict VPN device access. Subsequently, when the VPN device accesses a file directory, it must do so through user access permissions, i.e., the binding relationship between the VPN device and the directory, also known as second permissions. The directory and files will occupy the storage area corresponding to the second permissions.

[0066] In this embodiment, the network security device 20 further includes: a license code generation module 23 and a data segmentation module 24; the license code generation module 23 is communicatively connected to the second control module 21; and the data segmentation module 24 is communicatively connected to the second control module 21.

[0067] It should be noted that the second control module 21 is used to perform a second permission verification by calling the second permission stored in the first control module 11 when the second permission exists in the second storage module 22 after the first permission verification has passed. After the second permission verification has passed, it calls the third permission of the second storage module 22 and the license code of the storage area to perform a third permission verification.

[0068] Understandably, the second permission verification compares the binding relationship between the second storage module 22 and the first control module 11. If they match perfectly, the second permission authentication is successful. Afterward, any access operation to the dedicated storage area, including writing or reading data, must undergo additional authentication with a third permission.

[0069] It should be noted that the second control module 21 is used to call the license code generation module 23 to generate and update the license code and store it in the second storage module 22 after the third permission verification is passed; and output the license code and the sensitive resource segmentation component divided by the data segmentation module 24 to the storage area during the writing process; or output the license code to the storage area and read the sensitive resource component of the storage area during the reading process.

[0070] Understandably, the data segmentation module 24 is used to segment sensitive resources. Through segmentation algorithms, such as secret sharing schemes, the original sensitive resources are processed and divided into multiple components, ensuring that no single component exposes complete data information. The permission code generation mechanism can be implemented based on various cryptographic principles, such as using a timestamp-based dynamic token algorithm, a cryptographically secure random number generator, or a hash chain-based one-way sequence generation method, ensuring the uniqueness and unpredictability of each permission code. This design, combining a dynamic permission code mechanism and resource segmentation technology, not only achieves continuous authentication but also significantly reduces the risk of data leakage through a distributed data storage strategy, providing deep defense for the entire authentication system.

[0071] In addition, the license code that changes with the operation also ensures that the mobile authentication device 10 and the network security device 20 must be in a continuous matching working state. Once the network security device 20 connects to another mobile authentication device 10, or the mobile authentication device 10 connects to another network security device 20, the license code will change, making it impossible to access sensitive resources and maintaining system security.

[0072] In this embodiment, the network security device 20 further includes: an in-situ detection module 25; the in-situ detection module 25 is communicatively connected to the second control module 21.

[0073] It should be noted that the second control module 21 is used to enter the working state after reading the sensitive resources and call the in-situ detection module 25 to detect the connection status of the mobile authentication device 10.

[0074] Understandably, once the second control module 21 completes the reading operation of sensitive resources and puts the network security device 20 into working state, it will immediately activate the presence detection module 25 to continuously monitor the physical connection status of the mobile authentication device 10 at fixed time intervals. This presence detection is essentially a periodic verification of the integrity of all permissions, and its detection process includes re-verifying the device identity of the first permission, the binding relationship of the second permission, and the dynamic license code of the third permission.

[0075] It should be noted that the second control module 21 is used to destroy sensitive resources when the connection state of the mobile authentication device 10 is not connected, and the network security device 20 switches from the working state to the locked state to stop providing network security services to the outside world.

[0076] Understandably, once the connection status of the mobile authentication device 10 is detected to change to disconnected, the second control module 21 will immediately initiate a security protection process. First, it will clear all copies of sensitive resources in the device's memory, then switch the network security device 20 from the active state to the locked state, immediately ceasing to provide all network security services to the outside world.

[0077] It should be noted that after each successful in-situ detection, the system executes a complete permission verification process and updates the third permission (dynamic license code) after all permission verifications are successful. This ensures that even if the device remains continuously connected, its access permissions are refreshed periodically. This design achieves continuous security monitoring throughout the entire process from device connection and permission verification to service provision, effectively preventing security risks that may arise from unauthorized removal or replacement of the device during operation.

[0078] Besides these, there are many options for presence detection. For example, a periodic query-response mechanism can be used to confirm the device's logical presence through cryptographic challenges and digital signatures; heartbeat monitoring can be implemented to continuously verify connection validity based on fixed-interval data packet transmission and reception; or operation-triggered verification can be established, confirming the device's status only before performing sensitive operations. These solutions each have their own emphasis on security, real-time performance, and system overhead, and can be selected or combined according to the security level and performance requirements of the actual application scenario. The core goal is to ensure that the device can immediately terminate the session and protect sensitive resources when needed. However, presence detection based on three permissions can save resources without introducing additional procedures.

[0079] In this embodiment, the mobile authentication device 10 further includes: an encryption / decryption module 13; the encryption / decryption module 13 is communicatively connected to the first control module 11 and the first storage module 12; the first control module 11 is used to call the encryption / decryption module 13 to encrypt the sensitive resources and store them in the first storage module 12 when the sensitive resources are written to the first storage module 12; the first control module 11 is also used to call the encryption / decryption module 13 to decrypt the sensitive resources transmitted from the first storage module 12 when reading sensitive resources from the network security device 20, and then transmit them to the network security device 20.

[0080] Understandably, this design ensures that sensitive resources are always stored in encrypted form on the storage medium of the mobile authentication device 10. Even if the device is lost or the storage medium is read directly, the sensitive information in plaintext cannot be obtained, thus providing a deeper level of data protection at the physical level.

[0081] It should be noted that encryption and decryption modules can also be integrated into the SOC chip. However, in network security devices, such as VPN devices, the second control module, second storage module, license code generation module, data segmentation module, and presence detection module can be integrated into the same hardware security platform, such as a dedicated security chip or hardware security module.

[0082] In this embodiment, the mobile authentication device is divided into a first control module, a first storage module, and an encryption / decryption module, achieving a clear division of functions and secure isolation. The first control module, as the core processing unit, is responsible for overall control and decision-making; the first storage module provides secure data storage space; and the encryption / decryption module is specifically responsible for data encryption and decryption operations. This modular design effectively improves the device's security and operating efficiency.

[0083] In this embodiment, a complete security protection system is constructed by dividing the network security device into a second control module, a second storage module, a license code generation module, a data segmentation module, and an in-situ detection module. The second control module acts as the main control unit to coordinate the work of each module; the second storage module provides local secure storage; the license code generation module is responsible for generating dynamic security credentials; the data segmentation module realizes the distributed processing of sensitive data; and the in-situ detection module provides continuous monitoring of device status. This modular architecture allows each security function to be relatively independent yet cooperate with each other, jointly constructing a defense-in-depth system and significantly enhancing the overall security of the system.

[0084] Furthermore, based on the above-described device embodiments, this application proposes an embodiment of a lock authentication method. Please refer to... Figure 4 , Figure 4 This is a flowchart illustrating the locking authentication method provided in the embodiments of this application.

[0085] In this embodiment, the locking authentication method uses the locking authentication device described above, including steps S10 to S40.

[0086] Step S10: After any mobile authentication device is connected, a preset first permission verification is performed. After the first permission verification is passed, the mobile authentication device is identified as a legitimate device.

[0087] Understandably, when a mobile authentication device connects to a network security device, the system first performs a primary access control (PAC) verification. This step verifies the mobile authentication device's factory credentials to confirm its legitimacy. The verification process includes checking the device's digital certificate and verifying the hardware signature. Only after passing this step can the system recognize the mobile authentication device as legitimate and proceed to the next verification stage.

[0088] Step S20: After the mobile authentication device is identified as a legitimate device, a second permission verification is performed. After the second permission verification is passed, the mobile authentication device and the network security device are identified as having a binding relationship.

[0089] Understandably, after device identity verification, the system performs a second permission check. This step verifies whether a legitimate binding relationship has been established between the mobile authentication device and the specific network security device. The system compares the binding information stored in the mobile authentication device with the binding record stored locally on the network security device to ensure a match. Successful verification confirms a correct binding relationship between the devices, laying the foundation for subsequent operations.

[0090] In one feasible implementation, write permissions are restricted in the mobile authentication device. Please refer to... Figure 5 , Figure 5 This is a flowchart illustrating the write permission process of the locking authentication method provided in this application embodiment. Steps S11 and S12 are included before step S20.

[0091] Step S11: After verifying that the mobile authentication device is a legitimate device, the network security device is controlled to establish a storage area in the mobile authentication device and generate a second permission associated with the storage area. The second permission is then stored in both the network security device and the mobile authentication device.

[0092] Understandably, after verifying the legitimacy of the mobile authentication device through the first permission check, the network security device will create a dedicated storage area within this mobile authentication device and generate a second permission (device binding information) uniquely associated with that storage area. This second permission will be stored in both the local storage unit of the network security device and the designated storage area of ​​the mobile authentication device, establishing a two-way storage binding relationship.

[0093] Step S12: Store the sensitive resources obtained by the network security device in the storage area, and randomly generate third-party permissions and store them in the storage area and the network security device.

[0094] Understandably, after the storage area is created and permissions are bound, the network security device writes the sensitive resources that need protection into the storage area and randomly generates a third permission (dynamic license code). This dynamic license code will be stored synchronously in the storage area of ​​the mobile authentication device and the local storage of the network security device, completing the initialization settings.

[0095] In this implementation, the binding initialization process ensures that each mobile authentication device establishes a unique correspondence with a specific network security device, laying a secure foundation for subsequent normal use. Through a step-by-step permission writing mechanism, the reliability of the binding relationship between devices is guaranteed, and the necessary initialization environment is provided for the subsequent dynamic authentication mechanism, forming a complete security closed loop.

[0096] Step S30: After confirming that the mobile authentication device and the network security device have a binding relationship, a third permission verification is performed. After the third permission verification is passed, the mobile authentication device is deemed to have successfully authenticated. The network security device is then controlled to read or write sensitive resources of the mobile authentication device to provide network security services. The third permission is randomly generated and updated to achieve continuous authentication.

[0097] Understandably, after confirming the binding relationship, the system performs a third-party permission verification. This step verifies the validity of the dynamic license code to ensure operational continuity. Upon successful verification, the system determines that the mobile authentication device has been successfully authenticated, authorizing the network security device to read or write sensitive resources on the mobile authentication device to provide network security services. Simultaneously, the system immediately generates a new dynamic license code randomly and updates its storage, achieving continuous authentication.

[0098] In one embodiment, the in-situ detection is limited. Please refer to [reference needed]. Figure 6 , Figure 6 This is a schematic flowchart of the in-situ detection process of the locking authentication method provided in this application embodiment. Step S30 is followed by steps S31 and S32.

[0099] Step S31: When the network security device provides network security services, detect the connection status of the mobile authentication device.

[0100] Understandably, while network security devices are providing network security services normally, the system continuously monitors the physical connection status of mobile authentication devices through an in-place detection module. This monitoring can involve periodically performing full-authority re-verification at fixed time intervals to ensure timely detection of changes in the device's connection status.

[0101] Step S31: When the connection status of the mobile authentication device is disconnected, control the network security device to clear sensitive resources and stop providing network services.

[0102] Understandably, when the in-situ detection module detects that the connection status of the mobile authentication device has become disconnected, the system immediately activates the security protection mechanism. The network security device will automatically clear all temporarily stored sensitive resources and immediately stop providing network services to the outside world, ensuring that sensitive information is not leaked or services are not interrupted when the device is abnormally disconnected.

[0103] Step S40: When the number of failed authentication attempts for any permission exceeds a preset value, control the mobile authentication device to enter a locked state.

[0104] Understandably, at any stage of the authentication process, if the number of consecutive failed verifications for a single permission exceeds a preset threshold, the system will immediately lock the mobile authentication device. This protection mechanism effectively prevents brute-force attacks, ensuring timely blocking of abnormal access and protecting system security.

[0105] In this embodiment, the method establishes a complete security chain from device authentication and binding verification to continuous authentication through a three-level permission verification and dynamic security mechanism, coupled with comprehensive security protection measures to ensure the reliability and security of the system in various scenarios. Compared with the prior art, the beneficial effects of the method provided in this application are the same as those of the locking authentication device provided in the above embodiments, and will not be repeated here.

[0106] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A locking authentication device, characterized in that, include: Mobile authentication devices and network security devices; The mobile authentication device includes: a first storage module, a first control module, and a custom interface; The first storage module and the first control module are communicatively connected; the network security device is communicatively connected to the mobile authentication device through the custom interface. The first control module is configured with a first permission for device authentication and a second permission for device binding; the first storage module is configured with a third permission for continuous authentication and stores sensitive resources; wherein, the first permission is the device information of the mobile authentication device, the second permission is the binding information written by the network security device, and the third permission is the license code written by the network security device and dynamically updated after each operation; The network security device is used to sequentially verify the first permission and the second permission when any mobile authentication device accesses the network, and after the first permission and the second permission are verified, access the first storage module and verify the third permission; when the third permission is verified, the first control module of the mobile authentication device is invoked to read the sensitive resources to provide network security services. The mobile authentication device is used to enter a locked state when the number of failed authentication attempts for any permission exceeds a preset value.

2. The locking authentication device as described in claim 1, characterized in that, The network security device includes: a second control module and a second storage module; The second control module is communicatively connected to the second storage module; The first control module is used to receive the first verification information from the second control module and verify it with the first permission; After the first permission verification is passed, if there is no second permission bound to the network security device in the second storage module, the second control module generates a second permission, stores it in the second storage module, and outputs it to the first control module. Then, it drives the first control module to establish a storage area in the first storage module, and the second permission is associated with the storage area.

3. The locking authentication device as described in claim 2, characterized in that, The network security device also includes: a license code generation module and a data segmentation module; The license code generation module is communicatively connected to the second control module; the data segmentation module is communicatively connected to the second control module. The second control module is used to perform a second permission verification by calling the second permission stored in the first control module when the second permission exists in the second storage module after the first permission verification passes; and to perform a third permission verification by calling the third permission of the second storage module and the license code of the storage area after the second permission verification passes. The second control module is used to call the license code generation module to generate and update the license code and store it in the second storage module after the third permission verification is passed; if it is writing, it outputs the license code and the sensitive resource component segmented by the data segmentation module to the storage area; if it is reading, it outputs the license code to the storage area and reads the sensitive resource component of the storage area.

4. The locking authentication device as described in any one of claims 1 to 3, characterized in that, The mobile authentication device also includes: an encryption / decryption module; The encryption / decryption module is communicatively connected to the first control module and the first storage module; The first control module is used to call the encryption / decryption module to encrypt the sensitive resources and store them in the first storage module when the sensitive resources are written to the first storage module; The first control module is also used to call the encryption / decryption module to decrypt the sensitive resources transmitted from the first storage module when reading sensitive resources from the network security device, and then transmit them to the network security device.

5. The locking authentication device as described in claim 3, characterized in that, The network security device also includes: an in-situ detection module; The in-situ detection module is communicatively connected to the second control module; The second control module is used to enter the working state after reading sensitive resources and call the in-situ detection module to detect the connection status of the mobile authentication device; The second control module is used to destroy sensitive resources and switch the network security device from the working state to the locked state to stop providing network security services when the connection state of the mobile authentication device is not connected.

6. The locking authentication device as described in claim 5, characterized in that, The in-place detection involves re-verifying all permissions and updating the third permission after all permissions have been verified.

7. The locking authentication device as described in claim 1, characterized in that, The network security device is a VPN device; the first control module is a SOC chip; the first storage module is an SpiFlash chip.

8. A locking authentication method, characterized in that, The locking authentication method uses the locking authentication device as described in any one of claims 1 to 7, comprising: After any mobile authentication device is connected, a preset first permission verification is performed. If the first permission verification is passed, the mobile authentication device is identified as a legitimate device. After determining that the mobile authentication device is a legitimate device, a second permission verification is performed. After the second permission verification is passed, it is determined that the mobile authentication device and the network security device have a binding relationship. After confirming that the mobile authentication device and the network security device have a binding relationship, a third permission verification is performed. After the third permission verification is passed, the mobile authentication device is deemed to have successfully authenticated. The network security device is then controlled to read or write sensitive resources of the mobile authentication device to the mobile authentication device to provide network security services. The third permission is randomly generated and updated to achieve continuous authentication. When the number of failed permission verifications exceeds a preset value, the mobile authentication device is controlled to enter a locked state.

9. The locking authentication method as described in claim 8, characterized in that, After verifying that the mobile authentication device is a legitimate device, a second permission verification is performed. Upon successful verification of the second permission, the mobile authentication device and the network security device are deemed to have a binding relationship. Prior to this, the process also includes: After determining that the mobile authentication device is a legitimate device, the network security device is controlled to establish a storage area in the mobile authentication device and generate a second permission associated with the storage area. The second permission is then stored in both the network security device and the mobile authentication device. Sensitive resources obtained by network security devices are stored in the storage area, and third-party permissions are randomly generated and stored in the storage area and the network security device.

10. The locking authentication method as described in claim 8, characterized in that, After confirming the binding relationship between the mobile authentication device and the network security device, a third-party permission verification is performed. Upon successful verification of the third-party permission, the mobile authentication device is deemed to have successfully authenticated. The network security device is then controlled to read the sensitive resources of the mobile authentication device to provide network security services. Third-party permissions are randomly generated and updated to achieve continuous authentication. The process then includes: When a network security device provides network security services, the connection status of the mobile authentication device is detected. When the connection status of the mobile authentication device is disconnected, control the network security device to clear sensitive resources and stop providing network services.

Citation Information

Patent Citations

  • Safety communication method and system based on USB protocol

    CN105099705A

  • Safety certificate method, device and system

    CN106991308A