Host anti-attack state releasing method and device, storage medium and electronic equipment
By sending a status clearance command to the slave device and obtaining its operational characteristics through the host security chip, the problem of legitimate slave devices being unable to authenticate under anti-attack conditions is solved, achieving secure and efficient status clearance and improving the security and concealment of the device.
Patent Information
- Application Number
- CN202511620860.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-06
- Publication Date
- 2026-02-03
AI Technical Summary
In existing technologies, once the host enters the anti-attack state, even legitimate slave devices cannot complete authentication, affecting the normal use of the device. Furthermore, traditional decryption methods are not secure enough and are easily cracked by attackers.
The host's security chip receives the status release signal and sends a status release command to the slave device. It performs legality verification by acquiring the slave device's operating characteristics, including reusing existing control commands, collecting the slave device's hardware operating characteristics such as instantaneous power and power integral, and software operating characteristics such as iterative calculation values, to ensure the security of the release process.
It improves the security of removing the anti-attack status, making it difficult for attackers to simulate or forge the operating characteristics of the slave device, thus enhancing the security and concealment of the removal process and preventing unauthorized devices from being cracked.
Smart Images

Figure CN121456867A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of device identity authentication, and more specifically, to a method, apparatus, storage medium, and electronic device for removing host anti-attack status. Background Technology
[0002] Device authentication technology between master and slave devices is widely used in various hardware and accessory pairing scenarios, such as between printers and their consumables, smartphones and accessories, medical devices and medical consumables, and game consoles and game controllers / cartridges. In this system, the master device acts as the initiator, sending commands; the slave device responds, executing the corresponding operation based on the received commands. During communication, the master device sends data frames containing command codes, the slave device parses the command codes, executes the corresponding function, and returns a response data frame with the command code identifier. This master-slave architecture enables secure interaction and authentication between devices and accessories, preventing unauthorized accessories from accessing the system and ensuring its secure operation.
[0003] For example, consider a printer and ink cartridges. When the printer receives an authentication trigger signal such as a power-on reset or a physical state change (e.g., the printer lid opening or closing), it sends authentication commands to the connected ink cartridges sequentially according to a preset instruction sequence to verify the cartridge's legitimacy. These authentication commands may include operations such as certificate reading, key verification, algorithm execution, and memory read / write. During communication, the printer sends commands one by one and receives data returned by the slave device. If the feedback data of a command is determined to be abnormal, the authentication process immediately terminates, and the ink cartridge is deemed an illegitimate device. Only when the feedback data of all commands is determined to be normal is the authentication considered successful, confirming the ink cartridge's legitimacy.
[0004] To prevent unauthorized devices from repeatedly attempting to crack the authentication mechanism between the master and slave devices through enumeration, traversal, or other methods, an "anti-attack state" mechanism is introduced. In this state, the master cannot respond normally to the slave's regular commands; for example, it may completely ignore received communication commands. Even if it does respond, it may return incorrect or random data to confuse the external device's normal parsing and operation, thus preventing attackers from gaining control through repeated attempts. For example, after three consecutive authentication failures, the master will enter the anti-attack state and will no longer respond to subsequent authentication requests to protect the master from being exploited by unauthorized consumables, extend the device's lifespan, and ensure operational security.
[0005] Therefore, once the host enters anti-attack mode, even legitimate slave devices will be unable to complete authentication, thus affecting normal user operation. However, anti-attack mode is not a permanent measure; otherwise, even with legitimate slave devices connected, normal authentication and communication processes would be impossible, impacting device usability. Therefore, a solution is needed that can effectively remove anti-attack mode while ensuring security. However, conventional methods for removing anti-attack mode often verify the legitimacy of the communication data content itself, which means the data content itself may be intercepted and cracked. Summary of the Invention
[0006] To overcome at least one deficiency in the prior art, this application provides a method, apparatus, storage medium, and electronic device for removing host anti-attack status, specifically including: In a first aspect, this application provides a method for removing a host's anti-attack status, applied to a security chip in a host, wherein the security chip is communicatively connected to a slave device, and the method includes: Upon receiving and responding to a state release signal, the master sends a state release instruction to the slave, wherein the master is in an attack-resistant state in which it is unable to respond normally to the slave's regular instructions, and the state release instruction is used to instruct the slave to perform a state release task to verify its own legitimacy; During the process of the slave device executing the state release task, the operating characteristics of the slave device are acquired; If the operating characteristics match the preset reference operating characteristics, then the anti-attack state is lifted.
[0007] Secondly, this application provides a method for removing the host's anti-attack status, applied to a slave device that is communicatively connected to the host's security chip, the method comprising: The host receives and responds to the state cancellation signal sent by the state cancellation command, wherein the host is in an attack-resistant state in which it cannot normally respond to the slave's normal commands; In response to the state removal command, a state removal task to verify its own legitimacy is executed. During the execution of the state removal task by the slave device, the security chip acquires the operating characteristics of the slave device and removes the anti-attack state if the operating characteristics meet the preset reference operating characteristics.
[0008] Thirdly, this application provides a host anti-attack status removal device, applied to a host security chip, wherein the security chip is communicatively connected to the slave device, and the device includes: The instruction generation module is used to receive and respond to the state release signal and send a state release instruction to the slave device, wherein the master device is in an anti-attack state in which it cannot normally respond to the slave device's regular instructions, and the state release instruction is used to instruct the slave device to perform a state release task to verify its own legitimacy; The operation feature module is used to acquire the operation features of the slave device during the execution of the state removal task by the slave device; The behavior analysis module is used to deactivate the anti-attack state if the operating characteristics match preset reference operating characteristics.
[0009] Fourthly, this application provides a host anti-attack status removal device, applied to a slave device that is communicatively connected to the host's security chip, the device comprising: The release instruction module is used to receive the state release instruction sent by the host in response to the state release signal, wherein the host is in an anti-attack state that blocks the slave authentication request; The instruction response module is used to respond to the state removal instruction and execute a state removal task to verify its own legitimacy. During the execution of the state removal task by the slave device, the security chip acquires the operating characteristics of the slave device and removes the anti-attack state if the operating characteristics meet the preset reference operating characteristics.
[0010] Fifthly, this application provides a storage medium storing a computer program that, when executed by a processor, implements a method for removing the host anti-attack status applied to a security chip or a slave device.
[0011] Sixthly, this application provides an electronic device, which includes a processor and a memory. The memory stores a computer program, which, when executed by the processor, implements a method for removing the host anti-attack status applied to a security chip or a slave device.
[0012] Compared with the prior art, this application has the following beneficial effects: This application provides a method, apparatus, storage medium, and electronic device for removing a host's anti-attack state. The host's security chip receives and responds to a state removal signal, sending a state removal command to the slave device. The host is in an anti-attack state that blocks slave device authentication requests. The state removal command instructs the slave device to perform a state removal task to verify its own legitimacy. During the slave device's execution of the state removal task, its operational characteristics are acquired. If the operational characteristics match preset reference operational characteristics, the anti-attack state is removed. Thus, since these operational characteristics are determined by the slave device's chip design and manufacturing process, attackers find it difficult to simulate or forge them using conventional attack methods. By verifying legitimacy through the operational characteristics of the slave device during the state removal task, the security deficiencies of traditional solutions are solved, and the security of the process of removing the anti-attack state is improved. Attached Figure Description
[0013] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is one of the flowcharts illustrating a method for removing a host's anti-attack status applied to a host, as provided in an embodiment of this application. Figure 2 A schematic diagram of instantaneous power at multiple first time points provided in the embodiments of this application; Figure 3 This is a schematic diagram illustrating the magnitude relationship between multiple instantaneous powers provided in the embodiments of this application; Figure 4 A schematic diagram of power integration over multiple time periods provided in the embodiments of this application; Figure 5 This is a schematic diagram showing the comparison of calculated values provided in the embodiments of this application; Figure 6 This is a second flowchart illustrating the method for removing the host anti-attack status applied to a slave device, as provided in an embodiment of this application. Figure 7 A flowchart illustrating the method for removing the host anti-attack status applied to a slave device, as provided in an embodiment of this application; Figure 8 A schematic diagram of a host anti-attack status removal device applied to a host provided in an embodiment of this application; Figure 9 A schematic diagram of the structure of the host anti-attack state removal device applied to the slave device provided in the embodiments of this application; Figure 10This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0015] To make the objectives, technical solutions, and advantages of the embodiments of this application (hereinafter referred to as "the embodiments") clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0016] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0017] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0018] In the description of this application, it should be noted that the terms "first," "second," "third," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0019] Based on the above statement, as described in the background section, traditional methods for removing attack-prevention status typically rely on verifying the legitimacy of the communication data content itself, such as comparing preset keys or verifying response values. Therefore, there is a risk that the data content itself may be intercepted and cracked. For example, attackers can intercept communication data through eavesdropping, replay attacks, or man-in-the-middle attacks, and then analyze or forge it to bypass security mechanisms.
[0020] It should be noted that the defects in the solutions in the prior art are the result of practice and careful research. Therefore, the discovery process of the above problems and the solutions proposed by the embodiments of this application in the following text should be regarded as contributions to this application in the process of invention and creation, and should not be understood as technical content known to those skilled in the art.
[0021] Based on the discovery of the aforementioned technical problems, and in order to solve or improve these problems, this embodiment provides a method for removing the host's anti-attack status, applied to the host's security chip, which is communicatively connected to the slave device. For example... Figure 1 As shown, the method includes: S1 receives and responds to the status release signal, and sends a status release command to the slave device.
[0022] In this context, the host is in an attack-prevention state where it cannot respond normally to the slave's regular commands. The state clearance command is used to instruct the slave to perform a state clearance task to verify its own legitimacy.
[0023] S2, during the process of releasing the task from the slave execution state, acquires the operating characteristics of the slave.
[0024] S3. If the operating characteristics match the preset reference operating characteristics, the anti-attack state is lifted.
[0025] Thus, since this operational characteristic is determined by the design scheme of the slave device and the chip manufacturing process, it is difficult for attackers to simulate or forge it through conventional attack methods. By verifying the legitimacy of the operation when the slave device is in execution state and de-tasking, the problem of insufficient security of traditional solutions is solved, and the security of the process of de-attack is improved.
[0026] To make the solution provided in this embodiment clearer, the following uses a printer and ink cartridge scenario as an example to describe in detail each step of the host anti-attack state removal method proposed in this embodiment. However, it should be understood that the operations in the flowchart do not have to be implemented in sequence, and steps without logical context can be reversed or implemented simultaneously. Furthermore, those skilled in the art, guided by the content of this application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart. Based on the relevant statements, please continue to refer to... Figure 1 The method includes: S1 receives and responds to the status release signal, and sends a status release command to the slave device.
[0027] It should be understood that in practical applications, when a printer is in anti-attack mode, it no longer processes the instructions sent by the ink cartridges according to the regular communication protocol. This manifests as blocking the ink cartridge instructions or deliberately returning incorrect response data. In other words, even if a legitimate ink cartridge sends a legally formatted instruction frame, the printer will not execute the corresponding function or provide genuine feedback, thereby preventing the data in the communication flow from being eavesdropped on and preventing unauthorized devices from attempting to crack the communication mechanism through enumeration, traversal, or other methods. To allow legitimate ink cartridges to resume communication while ensuring security, when the user completes a specific physical operation (e.g., opening and closing the printer cover) or the printer undergoes a reset and power-on process, these actions are recognized by the printer's security chip as valid status release signals, thereby triggering the subsequent release process.
[0028] Furthermore, to increase the difficulty for attackers to crack the code, compared to adding a separate state removal instruction, the state deactivation instruction in this embodiment reuses an existing control instruction, thereby achieving the purpose of confusing attackers. Therefore, this embodiment also provides the following optional implementation methods for step S1: S1-1, reuse existing control instructions to generate status release instructions.
[0029] Among them, the reserved fields of existing control instructions are set with a status release flag.
[0030] S1-2, send the status cancellation command to the slave device.
[0031] Specifically, in practical applications, a set of control instructions for the authentication process is usually predefined between the printer and the ink cartridge. These instructions include certificate instructions, key instructions, algorithm instructions, memory read / write instructions, etc., and each instruction has a specific instruction code and data format. In order to improve the security and concealment of the instructions without adding new instruction codes, this embodiment adopts an instruction reuse strategy. That is, an existing authentication instruction (e.g., certificate instruction) is selected as the basis for the status deactivation instruction, and a status deactivation flag is set in the reserved field or data field of the instruction, so that the instruction can retain its original function (e.g., obtaining certificate information) while having the new function of triggering the status deactivation process.
[0032] Therefore, during the execution of the above steps, when the security chip detects an opportunity to send a status deregulation command (e.g., after receiving a status deregulation signal), it selects a command (e.g., a certificate command) from the existing set of authentication commands as the carrier of the status deregulation command. Subsequently, the security chip inserts a status deregulation flag into the data field of this command, for example, by setting a specific flag to indicate that the command is currently used to trigger a status deregulation task. This status deregulation flag serves as the basis for the ink cartridge to parse the command and enter the status deregulation process. Finally, the security chip sends the constructed status deregulation command to the ink cartridge, causing the ink cartridge to execute the corresponding status deregulation task based on the command code and status deregulation flag in the command.
[0033] In this way, by reusing the instruction codes in existing control instructions, it becomes difficult for attackers to determine from the instruction codes themselves whether the instruction is used for the state cancellation task, thereby improving the stealth of the instructions in the communication process and increasing the difficulty of analysis and cracking.
[0034] Based on the status cancellation command sent in the above embodiments, see below. Figure 1 Next, we will explain step S2 in the diagram: S2, during the process of releasing the task from the slave execution state, acquires the operating characteristics of the slave.
[0035] Research has found that while printers in anti-attack mode cannot respond to regular slave device commands to prevent attackers from repeatedly attempting authentication, thus improving system security, data interaction with the slave device is still necessary during the process of deactivating this mode. This communication can be intercepted, replayed, or tampered with by attackers through side-channel eavesdropping, bus sniffing, or man-in-the-middle attacks. Therefore, relying on data interaction has an inherent flaw: it cannot effectively hide the authentication logic itself, allowing attackers to crack and simulate the entire authentication process.
[0036] Therefore, as an optional implementation of step S2, the operating characteristic can be the hardware operating characteristic of the slave device, which is directly measured and acquired by the host side without any data exchange with the slave device. In this way, the printer's security chip can independently collect and acquire the operating status reflecting the true hardware characteristics of the ink cartridge, effectively avoiding the risk of information leakage during communication. Based on the above concept, the hardware operating characteristic can include the instantaneous power of the ink cartridge at multiple first time points. Therefore, this embodiment also provides the following optional implementation of step S2: S2-1A samples the instantaneous power of the slave device at multiple first time points during the process of the slave device releasing the task in the execution state.
[0037] It should be noted that, in this embodiment, the state deregulation task can be a numerical computation task, such as executing a specific iterative algorithm, a combination of multiple algorithms, or parallel computation based on the computational radix. During execution, these computational tasks will cause significant changes in the ink cartridge's power consumption, current, and other electrical parameters due to differences in algorithm complexity. Simultaneously, the state deregulation task can also be a hardware resource access task, such as transferring data back and forth in memory in a specific manner. These operations will also trigger frequent state switching of the ink cartridge's internal logic gates, resulting in power consumption fluctuations. Thus, the execution of the state deregulation task not only reflects the inherent characteristics of the ink cartridge's hardware performance but also makes it difficult for attackers to forge an operating state completely identical to that of a legitimate chip using external simulation methods.
[0038] For example, the printer is designed with a detection circuit connected to the ink cartridge power signal line, assuming the measured power consumption curve is as follows: Figure 2 As shown in the figure, at multiple first time points ( The real-time power consumption of the ink cartridge is sampled to obtain a set of instantaneous power values. .
[0039] This can be understood as the electrical characteristics of the ink cartridge's process of deactivating its anti-attack status being determined by the integrated circuit design and manufacturing process of the chip used, making it difficult to accurately replicate through software simulation or algorithmic simulation. Even if an attacker obtains the ink cartridge's instruction flow and computational logic, it is difficult to accurately recreate the same electrical characteristics without having the same hardware conditions. Furthermore, because unnecessary data transmission is reduced, attackers cannot perceive when the printer's security chip collects the ink cartridge's instantaneous power, thus achieving the goal of covertly deactivating the anti-attack status.
[0040] It should be noted that instantaneous power, as a manifestation of ink cartridge hardware characteristics, is closely related to the computational complexity of the task being performed. However, when performing only a single task, the computational load of the ink cartridge is relatively fixed, resulting in a limited range of power consumption fluctuations, making it difficult to form sufficiently complex power consumption change patterns. This provides attackers with opportunities for attacks. For example, an attacker can repeatedly capture the power consumption curves of the ink cartridge when performing the same task, build a corresponding power consumption model, and then simulate this model to send false power consumption information to the printer's security chip, thereby deceiving the security chip into completing the status deactivation operation.
[0041] Therefore, the status clearing instruction includes a parallel parameter, which instructs the cartridge to determine the number of parallel status clearing tasks and run the corresponding number of status clearing tasks. The number of parallel tasks is positively correlated with the parallel parameter.
[0042] Specifically, the parallel parameter here is defined as a numerical parameter used by the security chip to instruct the cartridge to perform a corresponding number of status deregulation tasks. Its value can be randomly generated by the security chip within a preset data range, or it can be selected from a set of preset candidate numbers. For example, the security chip can randomly select a value from the integer range of 1 to 10 as the parallel parameter for this deregulation operation, or it can select from a preset candidate set according to a polling strategy, such as selecting a value from {3, 5, 7}. This parallel parameter is embedded in the status deregulation instruction and sent to the cartridge along with the instruction.
[0043] After receiving the status deregulation command, the ink cartridge parses the parallel parameters and determines the number of parallel tasks to be executed based on its preset mapping logic. For example, if the parallel parameter is 5, the ink cartridge executes 5 parallel tasks; if it is 8, it executes 8 tasks. Furthermore, since the number of parallel tasks is positively correlated with the parallel parameter, the computational resource consumption and power consumption of the ink cartridge during execution will increase with the increase of the parameter, resulting in different instantaneous power characteristics at multiple first time points. The printer's security chip has locally preset reference power consumption curves corresponding to different numbers of parallel tasks. These curves are constructed based on the instantaneous power data collected by legitimate ink cartridges when executing the same number of parallel tasks. After obtaining the instantaneous power at multiple first time points during the ink cartridge's current execution of the status deregulation task, the printer's security chip compares this operating characteristic with the reference power consumption curves under the corresponding number of parallel tasks.
[0044] Therefore, the printer's security chip achieves dynamic verification of the ink cartridge hardware characteristics through the above implementation method, that is, it not only verifies whether the ink cartridge has performed the task, but also verifies whether its execution method conforms to the physical behavior characteristics of a legitimate device.
[0045] The study also found that instantaneous power only reflects the energy consumption state at a specific point in time, while the power integral over a specific period reflects the overall energy consumption of the ink cartridge during that period. Energy consumption is not only related to the complexity of the executed algorithm, but also closely related to hardware factors such as the integrated circuit design and manufacturing process of the ink cartridge chip. This means that if an attacker wants to accurately simulate the power consumption integral trajectory of a legitimate chip, they not only need to accurately grasp the algorithm execution logic of the ink cartridge, but also need to possess the same hardware implementation characteristics as the target chip, including but not limited to the layout of the internal circuitry, manufacturing process, and clock characteristics. These factors are difficult to achieve through software simulation. Therefore, the power consumption integral can be considered, to some extent, a fingerprint of the ink cartridge's hardware characteristics. Therefore, as another optional implementation of step S2, the hardware operating characteristics can include the power integral of the ink cartridge over multiple time periods. In this case, step S2 can include: S2-1B, acquire the power curve of the slave device during the task release process in the execution state.
[0046] S2-2B, based on the power curve, integrates to obtain the power integral of the slave unit over multiple time periods.
[0047] Specifically, during the execution of tasks such as iterative calculations, parallel computing, and resource calls, the power consumption of the ink cartridge is not constant but fluctuates dynamically as the internal computing units are enabled and disabled. The printer's security chip continuously collects real-time power data from the ink cartridge through external monitoring methods (such as current sensors and power detection circuits) to construct a complete power curve. Subsequently, the security chip performs integral calculations on this power curve over multiple preset time periods, calculating the power integral for each time period.
[0048] Therefore, using power integral as an operational characteristic has higher resistance to cracking compared to relying solely on instantaneous power.
[0049] Furthermore, considering that if an attacker obtains the complete power curve of the cartridge performing a deactivation operation (e.g., iterative calculation of the computational radix), they could reverse-engineer the cartridge's computational logic or operational characteristics, and then attempt to forge legitimate behavior to bypass the attack prevention measures. This embodiment primarily focuses on power integration over multiple time periods; therefore, the cartridge also randomly performs power interference operations outside of these time periods. This power interference operation could involve randomly running multiple interference algorithms and / or randomly activating unnecessary hardware in the slave device.
[0050] Taking multiple random interference algorithms as an example, in practical applications, to prevent attackers from obtaining the complete power curve and performing effective analysis, the ink cartridge, while performing the state deactivation task, also randomly runs multiple interference algorithms during non-critical periods (i.e., periods when the printer's security chip is not used for integral calculation). These interference algorithms can be any form of unnecessary computational task, such as idle loops, pseudo-encryption operations, invalid data processing, etc. Their execution timing and content are dynamically determined by the random generator inside the ink cartridge and do not participate in the verification judgment of the security chip. Because the execution time and computational load of these interference algorithms are highly uncertain, they significantly disrupt the overall power consumption trend of the ink cartridge, making it difficult for attackers to accurately extract the core computational part used for verification from the captured power curve.
[0051] Taking the activation of unnecessary hardware in the slave device as an example, in practical applications, to prevent attackers from obtaining effective power consumption characteristics, the ink cartridge randomly activates unnecessary hardware such as redundant interfaces, coprocessors, and sensors during non-critical periods. The activation and deactivation of this hardware is controlled by an internal random mechanism and does not participate in the verification process, but it introduces unpredictable power consumption fluctuations, disrupts the power curve, and increases the difficulty for attackers to analyze core task characteristics.
[0052] Thus, by introducing power interference operations outside of several key time periods, even if attackers can obtain the complete power curve, they will find it difficult to accurately identify the power consumption integral range used for verification, and therefore will be unable to effectively simulate or replicate the behavior pattern of legitimate ink cartridges.
[0053] The study also found that the ink cartridge's processing speed is affected by factors such as its internal chip architecture design, clock frequency, cache efficiency, and instruction pipeline scheduling. Even chips with the same function and algorithm will exhibit different execution speeds when performing the same iterative calculation due to differences in hardware implementation. Therefore, the time interval for the ink cartridge to return a value essentially reflects the ink cartridge's hardware characteristics. As another optional implementation of step S2, based on this finding, the state release instruction includes an operation radix, and the state release task is an iterative calculation task based on the operation radix. In this case, the running characteristics can be the slave's software running characteristics, which can include the calculation values of the iterative calculation task at multiple second time points. Therefore, this embodiment also provides the following optional implementation of step S2: S2-1C reads the calculated values from the slave device at multiple second time points by sending data read commands to the slave device at multiple second time points.
[0054] This can be understood as follows: in this embodiment, the computational base is used as the initial input, and multiple iterative calculations are performed according to a preset algorithm logic to generate operational features used to verify its legality. The core of this iterative calculation task lies in continuously executing the same computational logic on the previous calculation result to obtain a sequence of values.
[0055] For example, when the printer's security chip generates a status deactivation command, it generates a radix and embeds it as the initial input value in the command, sending it to the ink cartridge. Upon receiving the command, the ink cartridge first parses the radix and uses it as the initial input to execute a preset iterative algorithm. For example, if the algorithm is set as follows:
[0056] Ink cartridges based on arithmetic base Substitute to get Then use this result as new input. Substituting it again, the calculation yields... And so on, a sequence of numerical values can be obtained.
[0057] Furthermore, instead of setting the computational radix to a fixed value, the computational radix can also be a random radix generated randomly by the security chip. This random radix can increase the difficulty for attackers to eavesdrop on and analyze the data when the security chip communicates with the cartridge.
[0058] This can be understood as follows: when the ink cartridge performs an iterative calculation task to clear its state, the result of each step of the iterative algorithm depends on the output of the previous step. Therefore, the ink cartridge must complete a sufficient number of iterations within a specified time to return the correct calculated value when the security chip reads it. If the ink cartridge's calculation speed is too slow (e.g., due to insufficient hardware performance), it may not have completed the expected number of iterations at the specified time, causing the return value to lag behind the security chip's expected result. Conversely, if the ink cartridge's calculation speed is abnormally fast (e.g., due to excessively powerful hardware performance), the return value may be ahead of expectations, also failing to match the security chip's local record.
[0059] The processing speed of an ink cartridge is affected by factors such as its internal chip architecture design, clock frequency, cache efficiency, and instruction pipeline scheduling. Even chips with the same function and algorithm will exhibit different execution speeds when performing the same iterative calculation due to different hardware implementations. Therefore, the time interval between the ink cartridge's return values essentially reflects the ink cartridge's hardware characteristics.
[0060] The study also found that during the dismantling of the anti-attack status, attackers may attempt to obtain the complete operational characteristics of the cartridge's iterative calculations through side-channel eavesdropping, communication monitoring, or waveform capture, thereby simulating the behavior of legitimate devices to bypass the security chip's security mechanisms. Therefore, appropriate methods can be used to confuse attackers, making it difficult for them to determine whether the dismantling process is still in progress or has terminated, thus improving the security of the dismantling process.
[0061] Therefore, the interval between any two adjacent time points in the multiple second time points is greater than 1 minute, and / or a shutdown state is simulated between any two adjacent time points.
[0062] Specifically, the command interactions between the printer's security chip and the ink cartridge are typically measured in seconds or even milliseconds; for example, the interval between two commands is usually controlled within 10 seconds. In this implementation, the security chip sets the interval between two adjacent reading points to be greater than one minute, such as one to five minutes, or even longer. This time interval far exceeds the interaction rhythm expected by attackers during normal eavesdropping, making it difficult for attackers to determine whether the current process is still continuing or has terminated due to an anomaly.
[0063] For example, in practical applications, if the interval between two read operations reaches 4 to 5 minutes, attackers usually will not wait for such a long time, but will mistakenly believe that the chip has crashed or the process has been stopped, thus abandoning the current data capture and trying to reset the process.
[0064] Furthermore, the printer's security chip can simulate a shutdown state by controlling the ink cartridge's operation between every two reading points. This simulated shutdown is not a true power outage or hibernation; rather, it misleads external observers into believing the printer has entered a shutdown state by shutting down some communication channels, indicator lights, cooling fans, reducing power consumption, or sending simulated hibernation signals. However, the printer is actually still running in the background. This further increases the difficulty for attackers to determine whether the process is still in progress, effectively interfering with their eavesdropping and analysis activities.
[0065] Based on the above embodiments' description of the instantaneous power at multiple first time points, the power integral over multiple time periods, and the calculated values at multiple second time points, please refer to [link to previous document]. Figure 1 Next, we will continue to introduce... Figure 1 Step S3: S3. If the operating characteristics match the preset reference operating characteristics, the anti-attack state is lifted.
[0066] When the operating characteristics include hardware operating characteristics encompassing the instantaneous power at multiple first time points, for regular ink cartridges, manufacturers have already tested the power curves during the task release phase of the execution state and have selectively chosen the instantaneous power at multiple first time points. Therefore, the relative magnitudes of these values can be built into the printer's security chip. For example, continuing with... Figure 2 Multiple first time points in the power curve shown ( instantaneous power For example, the reference magnitude relationship of the instantaneous power at three preset first time points in the printer's security chip is as follows: ,and Figure 2 The relationship between the instantaneous power at the three first time points is shown as follows: Figure 3 As shown, this relationship is exactly satisfied. Therefore, the ink cartridge is determined to be a legitimate ink cartridge, thereby removing the anti-attack status and responding to the ink cartridge's subsequent authentication request.
[0067] However, the actual power curve of illegitimate ink cartridges is completely different from that of genuine ones. Figure 2 The power curve shown means The relationship between the instantaneous power may not satisfy This identifies the ink cartridge as invalid. At this point, the printer is kept in anti-attack mode.
[0068] Of course, the relative importance of the three first time points may differ depending on their chosen locations. For example, when the three selected first time points are located at... Figure 2 At other positions on the time axis shown, the reference size relationship may change. ,or Therefore, the three "first time points" need to be preset when the printer's security chip leaves the factory.
[0069] When the operating characteristics include hardware operating characteristics involving power integrals over multiple time periods, the printer's security chip, after sending a state deactivation command, triggers the ink cartridge to enter a state deactivation task, such as an iterative calculation task or other computational task that may generate power consumption changes. During this process, the security chip continuously monitors the real-time power consumption curve of the ink cartridge via its power signal line with the cartridge. Here, we continue to assume that this power consumption curve is... Figure 2 The power consumption curve of the security chip is based on... Figure 4 The method shown divides the data into 3 time periods, and the power integral for each time period is obtained by integration. These integral values reflect the overall energy consumption level of the ink cartridge when executing algorithms at different stages. Since this energy consumption level is closely related to the physical performance of the integrated circuit design and manufacturing process inside the ink cartridge, it means that the power consumption of a legitimate ink cartridge exhibits a certain inherent pattern when executing a specific algorithm. Illegal ink cartridges cannot accurately replicate this pattern, thus preventing attackers from deceiving the system by simulating instantaneous power consumption.
[0070] The security chip will calculate the The system compares the scores with a pre-stored range of reference scores to determine if they all fall within that range. If all scores meet the preset conditions, it indicates that the hardware operating characteristics exhibited by the cartridge during the execution of the state deactivation task are consistent with the behavior model of a legitimate cartridge, thus confirming its legitimacy. The security chip then deactivates the anti-attack state, allowing the subsequent normal authentication process to continue. Conversely, if any score exceeds the preset range, the cartridge is considered potentially an illegitimate device, and the printer will continue to maintain the anti-attack state.
[0071] When the software operation characteristics include calculation values at multiple second time points, the printer's security chip can pre-record reference calculation values at multiple second time points, or the security chip can use the same chip as the ink cartridge and execute the iterative algorithm simultaneously. That is, the iterative calculation algorithm is preset at the factory and is initiated upon task termination; the security chip and ink cartridge independently execute the same algorithm process. Based on timing, the security chip sends a data read command to the ink cartridge at at least one time point to obtain the calculation value iteratively calculated by the ink cartridge at that time point.
[0072] For example, taking three time points as an example, the printer's security chip obtains the ink cartridge calculation results at each time point. It then compares the calculated value with its own reference value at the same time point. Only when the calculated values of all cartridges are consistent with the reference calculated value of the security chip, or satisfy the preset relationship, will the security chip determine that the operating characteristics conform to the reference operating characteristics, thereby deactivating the anti-attack state; if any calculation result does not match, it will determine that the operating characteristics do not conform to the reference operating characteristics, thereby maintaining the anti-attack state and restarting the state deactivation process.
[0073] like Figure 5 As shown, several time points are set in the state resolution process. It also sends a read command to the ink cartridge at each time point to obtain the calculated value of the ink cartridge at that time point. The printer's security chip simultaneously executes the same algorithm locally to obtain the corresponding reference calculation value. .like If the calculation process of the printer's security chip is consistent with that of the ink cartridge, it is determined that the hardware characteristics meet expectations, thus deactivating the anti-attack status. Conversely, if any value does not satisfy the relation, it is determined that the operating characteristics do not meet the reference operating characteristics, the status deactivation fails, and the printer's security chip restarts the status deactivation process.
[0074] Of course, as an optional implementation, the printer's security chip can also determine whether to deactivate the anti-attack state by combining the instantaneous power at multiple first time points, the calculated values at multiple second time points, and the power integral over multiple time periods.
[0075] For example, at multiple preset time points during task execution, the printer's security chip samples the instantaneous power of the ink cartridge to obtain its power consumption performance at different stages. Simultaneously, the security chip also sends read commands to the ink cartridge at set time points to obtain intermediate results generated during iterative computation tasks. Furthermore, the security chip collects the complete power curve of the ink cartridge throughout the entire task execution process and calculates the power integral over multiple preset time periods. Finally, the security chip comprehensively compares these different dimensions of operational characteristics to more fully assess whether the ink cartridge possesses legitimate hardware characteristics. Only when all characteristics highly match preset reference characteristics will the ink cartridge be determined as a legitimate device, and the anti-attack status will be lifted accordingly.
[0076] The study also found that attackers typically use chips found in legitimate ink cartridges to attempt to bypass authentication measures, repeatedly testing to intercept critical information in the authentication process and ultimately crack the code. Therefore, current cracking methods often involve repeatedly testing the original manufacturer's chip on different printers. Attackers can use the same chip to perform multiple disarming attempts on multiple printers, accumulating a large amount of communication data, analyzing and simulating the behavior of legitimate chips, and ultimately bypassing the authentication mechanism. In light of this, if... Figure 6As shown, the host anti-attack status removal method provided in this embodiment also includes: S4. If the running characteristics do not conform to the preset reference running characteristics, then update the cumulative number of failures.
[0077] S5. If the cumulative number of failures after the update exceeds the safety threshold, then an erase command is sent to the slave device to erase the program related to the state release task in the slave device.
[0078] During the above steps, if the printer's security chip determines that the ink cartridge's operating characteristics do not conform to the preset reference operating characteristics, the status clearance process is deemed a failure. The security chip will update the cumulative failure count, which can be indexed based on the chip's unique identifier (such as a certificate) or based on the printer's own identifier. Specifically, after each status clearance failure, the security chip increments the failure count counter and checks whether the updated cumulative failure count exceeds a preset security threshold. If it does not exceed the threshold, the status clearance process can be re-executed; if it exceeds the threshold, the security chip sends an erase command to the ink cartridge to erase the programs related to the status clearance task, including but not limited to the parsing logic of the status clearance command and the iterative algorithm implementation code. After the erase operation is completed, the ink cartridge's status clearance function is permanently disabled, but this does not affect its normal communication and authentication functions on other printers.
[0079] This can be understood as the erasure operation not targeting the entire ink cartridge program, but rather limited to specific program modules related to the status removal task. This prevents attackers from repeatedly attempting the removal operation using the same chip while preserving the ink cartridge's normal usability on other legitimate printers. In this way, the possibility of attackers repeatedly experimenting with the same chip on different printers is effectively limited, thus improving security.
[0080] In addition, the cartridge also records the historical number of times the state deactivation task has been performed. Therefore, before sending an erase command to the slave device to erase the program related to the state deactivation task in the slave device, the security chip can further obtain the historical number of times the state deactivation task has been performed, and send an erase command to the slave device if the historical number is greater than the erase threshold.
[0081] For example, if an attacker attempts to disable the anti-attack status using the same ink cartridge chip on three different printers, or attempts to disable the anti-attack status multiple times on the same printer and fails each time, the printer will send an erase command when the cumulative number of failures exceeds a security threshold. This erases the program related to the status disabling task from the ink cartridge chip. Afterward, the ink cartridge chip can no longer perform the status disabling task on the current printer, but it can still participate in the authentication process normally on other printers that have not undergone the erase operation, and its basic function as a legitimate chip will not be affected.
[0082] In the above embodiments, the method for resolving the host anti-attack state was explained from the perspective of the printer's security chip. Next, using the ink cartridge as the slave device, the method for resolving the host anti-attack state will be explained. Figure 7 As shown, the method includes: P1 receives and responds to the status cancellation command sent by the security chip in response to the status cancellation signal.
[0083] The printer is currently in an anti-attack state, blocking cartridge authentication requests. It should be understood that if the printer's security chip fails to authenticate with the cartridge multiple times consecutively, it enters this anti-attack state. In this state, the printer blocks cartridge authentication commands to prevent attackers from illegally accessing the system through repeated attempts. However, under certain conditions, such as when a user completes a physical operation or the printer undergoes a reset and power-on, the printer recognizes a state deactivation signal and generates a state deactivation command. This command indicates that the printer's security chip requests the cartridge to assist in completing an additional security verification process to confirm whether the current cartridge possesses a legitimate hardware identity.
[0084] After receiving the instruction, the ink cartridge needs to parse out the key parameters used to trigger subsequent verification operations based on its content, and then execute specific calculations or behavioral patterns accordingly, so that the printer can determine whether to disable the anti-attack status by monitoring the operating characteristics of the ink cartridge during the execution process.
[0085] Based on the above explanation of the status cancellation instruction, please refer to [link / reference]. Figure 7 Next, for Figure 7 Step P2 will be explained below: P2, in response to the state removal instruction, performs a state removal task to verify its own legitimacy.
[0086] During the process of removing the ink cartridge from its execution state, the printer's security chip acquires the operating characteristics that reflect the ink cartridge's operating features, and removes the anti-attack state if the operating characteristics meet the preset reference operating characteristics.
[0087] As an optional implementation, the complexity and unpredictability of the cartridge's operational characteristics can be enhanced by dynamically adjusting the number of parallel tasks, thereby improving the accuracy and security of the security chip's judgment on the cartridge's legitimacy. This solves the problem that the operational characteristics of a single task are too regular and easily modeled and simulated by attackers. Therefore, an optional implementation of step P2 includes: P2-1A, based on the parallel parameters, determines the number of parallel tasks for state resolution.
[0088] P2-2A, based on the number of parallel processes, runs the corresponding number of state release tasks.
[0089] In practical applications, after receiving an instruction, the ink cartridge first parses the parallel parameters and determines the number of tasks to be executed based on its internally preset mapping logic (e.g., a functional relationship or lookup table between the cardinality and the number of parallel operations). Subsequently, the ink cartridge schedules and executes a corresponding number of state-clearing tasks. These tasks are typically computationally intensive or resource-intensive operations, such as multi-threaded iterative calculations, parallel algorithm execution, and memory data movement. Their execution process significantly affects the ink cartridge's hardware behavior characteristics, such as instantaneous power consumption, current variations, and execution time.
[0090] Thus, by introducing dynamic changes in the number of parallel tasks, the hardware operating characteristics exhibited by the ink cartridge during each state-clearing process become highly unpredictable and complex. Compared to the relatively fixed power consumption when executing a single task, the parallel execution of multiple tasks results in a richer fluctuation pattern in the ink cartridge's power consumption curve, with the overall power consumption increasing exponentially compared to a single task. This means that the relative magnitudes of instantaneous power at multiple time points remain constant. Therefore, it is difficult for attackers to obtain a consistent characteristic model through repeated listening for simulation. For example, when the parallel parameters are large, the ink cartridge executes more parallel tasks, resulting in an overall increase in power consumption; conversely, when the base number is small, the number of tasks decreases, and the overall power consumption decreases. This increases the difficulty for attackers to forge operational characteristics.
[0091] When the operating characteristics are those of the slave device's hardware, and these hardware operating characteristics include the slave device's power integration over multiple time periods, the cartridge also randomly performs power interference operations outside of these multiple time periods. This power interference operation may involve randomly running multiple interference algorithms and / or randomly activating unnecessary hardware in the slave device.
[0092] Thus, by introducing power interference operations outside of several key time periods, even if attackers can obtain the complete power curve, they will find it difficult to accurately identify the power consumption integral range used for verification, and therefore will be unable to effectively simulate or replicate the behavior pattern of legitimate ink cartridges.
[0093] As another optional implementation, when the ink cartridge performs the status deregulation task, it can perform iterative calculations based on the computational radix carried in the status deregulation instruction issued by the security chip, and save the calculated value generated in each iteration. It should be understood that the calculated value and its generation time interval reflect the hardware performance characteristics of the ink cartridge when performing this task, and therefore can serve as an important reference for the security chip to determine whether the ink cartridge is a legitimate device. In view of this, another optional implementation of step P2 includes: P2-1B performs iterative calculations based on the operational radix and saves the calculated value of each iteration.
[0094] Therefore, in practice, when the security chip generates a status deactivation command, it embeds a computational radix and sends this command to the ink cartridge. Upon receiving the command, the ink cartridge first parses the computational radix and uses it as the initial input to perform continuous calculations according to a preset iterative algorithm. For example, the ink cartridge might use a fixed mathematical formula, using the current calculation result as the input for the next calculation, repeatedly executing it to generate a series of calculated values. These calculated values not only record the result of each iteration but also implicitly reflect the real-time performance of the ink cartridge during the calculation.
[0095] During this task, the ink cartridge receives data read commands from the security chip. These commands are typically triggered at set times to retrieve the calculation results of the current iteration. At this point, the ink cartridge returns the calculated value from the most recent iteration to the printer's security chip. The security chip then compares the calculated value returned by the ink cartridge with its expected value based on its local calculation records. If they match, it means the ink cartridge's calculation logic is consistent with the preset values in the security chip, and its calculation speed is within a reasonable range, conforming to the hardware characteristics of a legitimate ink cartridge. If they do not match, it may indicate that the ink cartridge lacks the corresponding hardware capabilities or is attempting to deceive the printer's security chip by falsifying calculated values, thus being identified as an unauthorized device.
[0096] Therefore, the ink cartridge also receives and responds to the data read command sent by the printer's security chip, sending the calculated value from the most recent iteration to the security chip.
[0097] As described above, when the printer's security chip determines that the ink cartridge's operational characteristics do not match legitimate characteristics, it sends an erase command to cause the ink cartridge to remove a type of program code or logic module related to its execution state deactivation task. This prevents attackers from repeatedly attempting to deactivate the anti-attack status on multiple printer devices using the same ink cartridge chip, thereby accumulating sufficient communication data to crack the authentication process.
[0098] Therefore, the ink cartridge also receives and responds to the erase command sent by the printer's security chip to erase the program associated with the status deactivation task.
[0099] In practical applications, this erase command is typically triggered by the printer's security chip under a specific security policy, and it targets only the program modules related to the status deregulation task, rather than the overall firmware within the ink cartridge. Upon receiving the command, the ink cartridge verifies its legitimacy through its internal security mechanism, and, if confirmed to be valid, executes the erase operation on the target program module.
[0100] Based on the host anti-attack state removal method provided in this embodiment, and under the same inventive concept, this embodiment also provides a host anti-attack state removal device, applied to a host communicating with a slave device. This device includes at least one software functional module that can be stored in memory or embedded in the host. The processor in the host executes the executable module stored in memory. For example, the software functional modules and computer programs included in the device. Please refer to... Figure 8 Functionally, the device may include: The instruction generation module is used to receive and respond to the state release signal and send a state release instruction to the slave device. The master device is in an attack-proof state that cannot respond normally to the slave device's regular instructions. The state release instruction is used to instruct the slave device to perform a state release task to verify its own legitimacy. The runtime characteristics module is used to acquire the runtime characteristics of the slave device during the process of releasing the task from the slave device execution state. The behavior analysis module is used to remove the anti-attack status if the running characteristics match the preset reference running characteristics.
[0101] In this implementation, the instruction generation module is used to implement Figure 1 In step S1A, the feature module is used to implement... Figure 1 In step S2A, the behavior analysis module is used to implement... Figure 1 For details regarding step S3A, please refer to the specific implementation of the corresponding step for a detailed description of each of the above modules.
[0102] It should be understood that the host anti-attack status removal device applied to the host can also implement other steps or sub-steps of the method through the above-mentioned modules.
[0103] Optionally, the operating characteristics are the hardware operating characteristics of the slave device, including the instantaneous power of the slave device at multiple first time points. The operating characteristic module is also specifically used for: During the process of the slave device releasing the task in the execution state, the instantaneous power of the slave device at multiple first time points is sampled.
[0104] Optionally, the state clearing instruction includes an operation radix, which is used to indicate the number of parallel state clearing tasks to be determined by the slave device and to run the corresponding number of state clearing tasks. The number of parallel tasks is positively correlated with the operation radix.
[0105] Optionally, the operating characteristics are the hardware operating characteristics of the slave device, which include the power integral of the slave device over multiple time periods. The operating characteristic module is also specifically used for: Obtain the power curve of the slave device during the task release process in the execution state; Based on the power curve, the power integral of the slave device over multiple time periods is obtained by integration.
[0106] Optionally, the slave device also performs power interference operations outside of multiple time periods.
[0107] Optionally, the power interference operation may involve randomly running multiple interference algorithms and / or randomly enabling unnecessary hardware in the slave device.
[0108] Optionally, the running characteristics are the software running characteristics of the slave device, the state release instruction includes the operation radix, the state release task is an iterative operation task based on the operation radix, and the software running characteristics include the operation values of the iterative operation task at multiple second time points. The running feature module is also specifically used for: The calculated values at multiple second time points are read from the slave device by sending data read commands to the slave device at multiple second time points.
[0109] Optionally, the interval between any two adjacent time points in the plurality of second time points is greater than 1 minute, and / or a shutdown state is simulated between any two adjacent time points.
[0110] Optionally, the behavior analysis module is also used for: If the running characteristics do not meet the preset reference running characteristics, the cumulative number of update failures will be updated. If the cumulative number of failures after the update exceeds the safety threshold, an erase command is sent to the slave device to erase the program related to the state removal task in the slave device.
[0111] Optionally, the instruction generation module is also specifically used for: Reuse existing control instructions to generate status release instructions, wherein the reserved fields of the existing control instructions are set with status release flags; Send the status cancellation command to the slave device.
[0112] Based on the host anti-attack state removal method for slave devices provided in this embodiment, and under the same inventive concept, this embodiment also provides a host anti-attack state removal device for slave devices communicatively connected to a host. This device includes at least one software functional module that can be stored in memory or embedded in the host. The processor in the slave device executes the executable module stored in memory. For example, the software functional modules and computer programs included in the device. Please refer to... Figure 9 Functionally, the device may include: The release instruction module is used to receive and respond to the state release instruction sent by the host in response to the state release signal, wherein the host is in an anti-attack state in which it cannot normally respond to the slave's normal instructions; The instruction response module is used to respond to the status removal instruction and perform a status removal task to verify its own legitimacy. During the process of the slave device performing the status removal task, the security chip obtains the slave device's operating characteristics and removes the anti-attack status if the operating characteristics meet the preset reference operating characteristics.
[0113] In this embodiment, the release instruction module is used to implement Figure 9 Step P1 in the instruction response module is used to implement... Figure 9 Therefore, for a detailed description of each of the above modules, please refer to the specific implementation method of the corresponding step.
[0114] It should be understood that the host anti-attack status removal device applied to the slave device can also implement other steps or sub-steps of the method through the above-mentioned modules.
[0115] Optionally, the state release instruction includes parallel parameters, and the instruction response module is also specifically used for: The number of parallel tasks for state de-listing is determined based on the parallel parameters. Run a corresponding number of state decommissioning tasks based on the number of parallel processes.
[0116] Optionally, the instruction response module is also specifically used for: The task is terminated in multiple time periods, and multiple interference algorithms are randomly run outside of these time periods.
[0117] Optionally, the state release instruction includes an operation radix, and the instruction response module is also specifically used for: Iterative calculations are performed based on the operational radix, and the calculated value from each iteration is saved.
[0118] Optionally, the instruction response module is also specifically used for: It receives and responds to the data read command sent by the security chip, and sends the calculated value from the most recent iteration to the security chip.
[0119] Optionally, the instruction response module is also specifically used for: Receive and respond to the erase command sent by the security chip to erase the program associated with the status removal task.
[0120] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0121] It should also be understood that if the above embodiments are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.
[0122] Therefore, this embodiment also provides a storage medium, which is a computer-readable storage medium. This storage medium stores a computer program, which, when executed by a processor, implements the host anti-attack state removal method provided in this embodiment for a security chip applied to a host or a slave device. The storage medium can be any medium capable of storing program code, such as a USB flash drive, external hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0123] This embodiment provides an electronic device for implementing a method to remove host anti-attack status. This electronic device can be a host security chip or a slave device. For example... Figure 10 As shown, the device may include a processor 22 and a memory 21. The memory 21 stores a computer program, and the processor reads and executes the computer program in the memory 21 corresponding to the above-described embodiments to implement the host anti-attack state removal method provided in this embodiment, applicable to a security chip or a slave device.
[0124] See also Figure 10 The electronic device also includes a communication unit 23. The memory 21, processor 22 and communication unit 23 are electrically connected to each other directly or indirectly through system bus 24 to realize data transmission or interaction.
[0125] The memory 21 can be an information recording device based on any electronic, magnetic, optical, or other physical principles, used to record execution instructions, data, etc. In some embodiments, the memory 21 can be, but is not limited to, volatile memory, non-volatile memory, memory drive, etc.
[0126] In some embodiments, the volatile memory may be random access memory (RAM); in some embodiments, the non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, etc.; in some embodiments, the storage drive may be a disk drive, solid-state drive, any type of storage disk (such as optical disc, DVD, etc.), or similar storage media, or a combination thereof.
[0127] The communication unit 23 is used to send and receive data over a network. In some embodiments, the network may include a wired network, a wireless network, a fiber optic network, a telecommunications network, an intranet, the Internet, a local area network (LAN), a wide area network (WAN), a wireless local area network (WLAN), a metropolitan area network (MAN), a public switched telephone network (PSTN), a Bluetooth network, a ZigBee network, or a near field communication (NFC) network, or any combination thereof. In some embodiments, the network may include one or more network access points. For example, the network may include wired or wireless network access points, such as base stations and / or network switching nodes, through which one or more components of the service request processing system can connect to the network to exchange data and / or information.
[0128] The processor 22 may be an integrated circuit chip with signal processing capabilities, and may include one or more processing cores (e.g., a single-core processor or a multi-core processor). By way of example only, the processor described above may include a Central Processing Unit (CPU), an Application Specific Integrated Circuit (ASIC), an Application Specific Instruction-set Processor (ASIP), a Graphics Processing Unit (GPU), a Physics Processing Unit (PPU), a Digital Signal Processor (DSP), a Field Programmable Gate Array (FPGA), a Programmable Logic Device (PLD), a controller, a microcontroller unit, a Reduced Instruction Set Computing (RISC) computer, or a microprocessor, or any combination thereof.
[0129] Understandable. Figure 10 The structure shown is for illustrative purposes only. Electronic devices may also have more advanced features. Figure 10 Showing more or fewer components, or having with Figure 10 The different configurations shown. Figure 10 The components shown can be implemented using hardware, software, or a combination thereof.
[0130] It should be understood that the apparatus and methods disclosed in the above embodiments can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0131] The above descriptions are merely various embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for deactivating a host's anti-attack status, characterized in that, A security chip applied to a host device, the security chip being communicatively connected to a slave device, the method comprising: Upon receiving and responding to a state release signal, the master sends a state release instruction to the slave, wherein the master is in an attack-resistant state in which it cannot normally respond to the slave's regular instructions, and the state release instruction is used to instruct the slave to perform a state release task to verify its own legitimacy; During the process of the slave device executing the state release task, the operating characteristics of the slave device are acquired; If the operating characteristics match the preset reference operating characteristics, then the anti-attack state is lifted.
2. The method for removing the host anti-attack status according to claim 1, characterized in that, The operating characteristics refer to the hardware operating characteristics of the slave device, which include the instantaneous power of the slave device at multiple first time points. Obtaining the operating characteristics of the slave device includes: During the process of the slave device performing the state release task, the instantaneous power of the slave device at multiple first time points is sampled.
3. The method for removing the host anti-attack status according to claim 2, characterized in that, The state release instruction includes a parallel parameter, which instructs the slave device to determine the number of parallel state release tasks and run the corresponding number of state release tasks. The number of parallel tasks is positively correlated with the parallel parameter.
4. The method for removing the host anti-attack status according to claim 1, characterized in that, The operating characteristics refer to the hardware operating characteristics of the slave device. These hardware operating characteristics include the power integral of the slave device over multiple time periods. Obtaining the operating characteristics of the slave device includes: Obtain the power curve of the slave device during the execution of the state release task; Based on the power curve, the power integral of the slave device over multiple time periods is obtained by integration.
5. The method for deactivating host anti-attack status according to claim 4, characterized in that, The slave device also performs power interference operations outside of the multiple time periods.
6. The method for deactivating the host anti-attack status according to claim 5, characterized in that, The power interference operation involves randomly running multiple interference algorithms and / or randomly enabling unnecessary hardware in the slave device.
7. The method for deactivating host anti-attack status according to claim 1, characterized in that, The running characteristics are the software running characteristics of the slave device, the state release instruction includes an operation base, the state release task is an iterative operation task based on the operation base, and the software running characteristics include the operation values of the iterative operation task at multiple second time points. Acquiring the operating characteristics of the slave device further includes: The calculated values at the plurality of second time points are read from the slave device by sending data read instructions to the slave device at the plurality of second time points.
8. The method for deactivating host anti-attack status according to claim 7, characterized in that, The interval between any two adjacent time points in the plurality of second time points is greater than 1 minute, and / or a shutdown state is simulated between any two adjacent time points.
9. The method for removing the host anti-attack status according to any one of claims 1-8, characterized in that, The method further includes: If the operating characteristics do not conform to the preset reference operating characteristics, then update the cumulative number of failures; If the cumulative number of failures after the update exceeds the safety threshold, an erase command is sent to the slave device to erase the program in the slave device related to the state release task.
10. The method for removing the host anti-attack status according to any one of claims 1-8, characterized in that, Send a status clear command to the slave device, including: Reuse existing control instructions to generate a status release instruction, wherein the reserved field of the existing control instructions is set with a status release flag; The status cancellation command is sent to the slave device.
11. A method for deactivating a host's anti-attack status, characterized in that, The method, applied to a slave device communicating with a host's security chip, includes: The security chip receives and responds to the state release signal sent by the state release command, wherein the host is in an attack-resistant state in which it cannot normally respond to the slave's normal commands; In response to the state removal command, a state removal task to verify its own legitimacy is executed. During the execution of the state removal task by the slave device, the security chip acquires the operating characteristics of the slave device and removes the anti-attack state if the operating characteristics meet the preset reference operating characteristics.
12. The method for deactivating host anti-attack status according to claim 11, characterized in that, The state removal instruction includes parallel parameters and executes a state removal task to verify its own legitimacy, including: The number of parallel tasks for state de-listing is determined based on the parallel parameters. Run a corresponding number of state decommissioning tasks based on the stated number of parallel processes.
13. The method for deactivating host anti-attack status according to claim 11, characterized in that, Perform the status removal task to verify its own legitimacy, including: The task is terminated in multiple time periods, and multiple interference algorithms are randomly run outside of these multiple time periods.
14. The method for deactivating host anti-attack status according to claim 11, characterized in that, The state release instruction includes an operational radix and executes a state release task to verify its own legitimacy, including: Iterative calculations are performed based on the aforementioned operational base, and the calculated values from each iteration are saved.
15. The method for deactivating host anti-attack status according to claim 14, characterized in that, The method further includes: The system receives and responds to the data read command sent by the security chip, and sends the calculated value obtained from the most recent iteration to the security chip.
16. The method for removing the host anti-attack status according to any one of claims 11-15, characterized in that, The method further includes: Receive and respond to the erase command sent by the security chip to erase the program associated with the state deactivation task.
17. A host anti-attack status deactivation device, characterized in that, A security chip for use in a host device, the security chip being communicatively connected to a slave device, the device comprising: The instruction generation module is used to receive and respond to the state release signal and send a state release instruction to the slave device, wherein the master device is in an anti-attack state in which it cannot normally respond to the slave device's regular instructions, and the state release instruction is used to instruct the slave device to perform a state release task to verify its own legitimacy; The operation feature module is used to acquire the operation features of the slave device during the execution of the state release task by the slave device; The behavior analysis module is used to deactivate the anti-attack state if the operating characteristics match preset reference operating characteristics.
18. A host anti-attack status deactivation device, characterized in that, A slave device used in communication with a host's secure chip, the device comprising: The release instruction module is used to receive the state release instruction sent by the security chip in response to the state release signal, wherein the host is in an anti-attack state in which it cannot normally respond to the slave's normal instructions; The instruction response module is used to respond to the state removal instruction and execute a state removal task to verify its own legitimacy. During the execution of the state removal task by the slave device, the security chip acquires the operating characteristics of the slave device and removes the anti-attack state if the operating characteristics meet the preset reference operating characteristics.
19. A storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the host anti-attack status removal method according to any one of claims 1-10 or 11-6.
20. An electronic device, characterized in that, The electronic device includes a processor and a memory, the memory storing a computer program, which, when executed by the processor, implements the host anti-attack status removal method according to any one of claims 1-10 or 11-6.