Slave anti-attack state relieving method and device, storage medium and electronic equipment
By determining the target execution order of multiple algorithms in the slave security chip and deactivating the anti-attack state when the order is consistent, the security problem of fixed communication mode in the prior art is solved, and the ability to resist eavesdropping and replay attacks is achieved, thus improving the anti-cracking capability.
Patent Information
- Application Number
- CN202511620868.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-06
- Publication Date
- 2026-02-03
AI Technical Summary
Existing methods for removing slave-based attack protection rely on key confidentiality and encryption algorithm strength. Their communication patterns are fixed and predictable, making them vulnerable to eavesdropping or replay attacks.
By determining the target execution order of multiple algorithms in the slave's security chip, receiving the host's state deactivation instruction and executing the algorithm in that order, receiving the instruction to be verified and deactivating the anti-attack state when the order is consistent, and using dynamic behavioral characteristics to perform legality judgment, avoiding reliance on static message values.
It effectively resists eavesdropping and replay attacks, enhances anti-cracking capabilities, ensures that legitimacy judgments rely on dynamic behavioral characteristics rather than static message values, and strengthens the system's resistance to analysis.
Smart Images

Figure CN121456868A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of master-slave device communication verification, in particular to a slave anti-attack state release method and device, a storage medium and an electronic device. BACKGROUND
[0002] In a master-slave communication system, the master and the slave perform identity authentication, data interaction and other operations through instruction frames. When the slave detects abnormal behavior or potential security threats, it will actively enter an anti-attack state to prevent being illegally manipulated. Therefore, the anti-attack state is essentially a self-protection mechanism, indicating that the slave has suspected that it may be under external attack, and therefore no longer responds normally to the regular instructions of the master. In this state, the slave may completely ignore the received communication instructions, or even respond, but return error or random data to confuse the normal analysis and operation of the external device.
[0003] It should be understood that the anti-attack state is not a permanent measure, otherwise even in the case of a legal master access, the normal authentication and communication process cannot be completed, affecting the normal use of the device. Therefore, after confirming the safety of the communication environment, a corresponding release method is needed to make the slave exit the anti-attack state. Currently, the conventional anti-attack state release method usually relies on whether the data content transmitted between the master and the slave conforms to the preset rules to perform legality verification, that is, the entire judgment process focuses on the field values in the communication message, such as instruction code, response code, checksum, encryption result, etc. As long as the data matches the expectation, it is considered as passing the verification.
[0004] However, research has found that the security of these conventional anti-attack state release methods is based on key secrecy and encryption algorithm strength, but the communication mode is fixed and the process is predictable, which can still be cracked through listening or playback. SUMMARY
[0005] In order to overcome at least one of the deficiencies in the prior art, one of the purposes of the present application is to provide a slave anti-attack state release method, device, storage medium and electronic device, comprising: In a first aspect, the present application provides a slave anti-attack state release method applied to a security chip of a slave, wherein the security chip is in communication connection with a master, the slave is in an anti-attack state in which it cannot respond to regular instructions of the master, and the method comprises: receiving and responding to a state release instruction sent by the master, determining a target execution order of a plurality of preset algorithms; executing the plurality of algorithms according to the target execution order; receiving a to-be-verified instruction sent by the master, wherein the to-be-verified instruction includes sequence prediction information of the plurality of algorithms by the master; If the sequence prediction information indicates that the execution sequence of the plurality of algorithms is consistent with the target execution sequence, the anti-attack state is released.
[0006] In a second aspect, the application provides a method for releasing an anti-attack state of a slave machine, applied to a host machine in communication connection with a security chip of the slave machine, the slave machine being in an anti-attack state in which it cannot respond to regular instructions of the host machine, and the method comprising: sending a state release instruction to the security chip, wherein the state release instruction is used to instruct the security chip to determine a target execution sequence of a plurality of preset algorithms and execute the plurality of algorithms according to the target execution sequence; obtaining sequence prediction information of the security chip executing the plurality of algorithms; sending a to-be-verified instruction including the sequence prediction information to the security chip, wherein the to-be-verified instruction is used to instruct the security chip to release the anti-attack state when the sequence prediction information indicates that the execution sequence of the plurality of algorithms is consistent with the target execution sequence.
[0007] In a third aspect, the application provides a device for releasing an anti-attack state of a slave machine, applied to a security chip of the slave machine, the security chip being in communication connection with a host machine, the slave machine being in an anti-attack state in which it cannot respond to regular instructions of the host machine, and the device comprising: an instruction response module, configured to receive and respond to a state release instruction sent by the host machine, and determine a target execution sequence of a plurality of preset algorithms; an algorithm execution module, configured to execute the plurality of algorithms according to the target execution sequence; a host machine verification module, configured to receive a to-be-verified instruction sent by the host machine, wherein the to-be-verified instruction includes sequence prediction information of the host machine on the plurality of algorithms; and if the sequence prediction information indicates that the execution sequence of the plurality of algorithms is consistent with the target execution sequence, the anti-attack state is released.
[0008] In a fourth aspect, a device for releasing an anti-attack state of a slave machine, applied to a host machine in communication connection with a security chip of the slave machine, the slave machine being in an anti-attack state in which it cannot respond to regular instructions of the host machine, and the device comprising: an initiation release module, configured to send a state release instruction to the security chip, wherein the state release instruction is used to instruct the security chip to determine a target execution sequence of a plurality of preset algorithms and execute the plurality of algorithms according to the target execution sequence; a sequence prediction module, configured to obtain sequence prediction information of the security chip executing the plurality of algorithms; A state release module sends a to-be-verified instruction including the sequence prediction information to the security chip, where the to-be-verified instruction is used to instruct the security chip to release the anti-attack state when the sequence prediction information indicates that the execution sequence of the multiple algorithms is consistent with the target execution sequence.
[0009] In a fifth aspect, the present application provides a storage medium, which stores a computer program, and the computer program, when executed by a processor, implements the slave anti-attack state release method.
[0010] In a sixth aspect, the present application provides an electronic device, which includes a processor and a memory, and the memory stores a computer program, and the computer program, when executed by the processor, implements the slave anti-attack state release method.
[0011] Compared with the prior art, the present application has the following beneficial effects: The present application provides a slave anti-attack state release method, device, storage medium and electronic device. The slave is in an anti-attack state in which it cannot respond to normal instructions from the master. The security chip of the slave receives and responds to a state release instruction sent by the master, determines a target execution sequence of a plurality of preset algorithms, executes the plurality of algorithms according to the target execution sequence, receives a to-be-verified instruction sent by the master, and releases the anti-attack state if the to-be-verified instruction includes sequence prediction information of the plurality of algorithms from the master and the execution sequence of the plurality of algorithms is the target execution sequence. In this way, the verification object is transferred from the communication data content itself to the internal processing sequence of the security chip executing the algorithms, so that the legality is determined based on the dynamic behavior characteristics rather than the static message value. Therefore, even if an attacker intercepts all the communication data, the attacker cannot obtain the hidden state of the algorithm execution sequence, thereby effectively resisting monitoring and playback attacks and significantly improving the anti-cracking capability. BRIEF DESCRIPTION OF DRAWINGS
[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor.
[0013] Figure 1 The slave anti-attack state release method applied to the slave provided by the embodiments of the present application; Figure 2 The efficient operation principle diagram of all permutations provided by the embodiments of the present application; Figure 3This application provides a method for removing the slave device's anti-attack status from the host. Figure 4 This is a schematic diagram of master-slave interaction based on power consumption measurement provided in an embodiment of this application; Figure 5 This is a schematic diagram of master-slave interaction based on a correspondence table provided in an embodiment of this application; Figure 6 This application provides a slave device for disabling anti-attack status applied to a slave device; Figure 7 This application provides a slave anti-attack state removal device for a host machine; Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0014] To make the objectives, technical solutions, and advantages of the embodiments of this application (hereinafter referred to as "the embodiments") clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0015] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0016] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0017] In the description of this application, it should be noted that the terms "first," "second," "third," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0018] Based on the above statement, as introduced in the background technology, the security of conventional anti-attack deactivation methods is based on key confidentiality and encryption algorithm strength. However, the communication mode is fixed and the process is predictable, so it is still possible to crack them through means such as eavesdropping or replay.
[0019] It should be noted that the defects in the solutions in the prior art are the result of practice and careful research. Therefore, the discovery process of the above problems and the solutions proposed by the embodiments of this application in the following text should be regarded as contributions to this application in the process of invention and creation, and should not be understood as technical content known to those skilled in the art.
[0020] Based on the discovery of the above-mentioned technical problems, this embodiment provides a method for removing the slave device's anti-attack state, applied to the slave device's security chip. The security chip is communicatively connected to the host, and the slave device is in an anti-attack state where it cannot respond to the host's regular commands. For example... Figure 1 As shown, the method includes: S1 receives and responds to the status release command sent by the host, and determines the target execution order of multiple preset algorithms.
[0021] S2 executes multiple algorithms according to the target execution order.
[0022] S3 receives the verification command sent by the host.
[0023] The instructions to be verified include the host's sequential prediction information for various algorithms.
[0024] S4. If the sequence prediction information indicates that the execution order of multiple algorithms is consistent with the target execution order, then the anti-attack state is lifted.
[0025] Thus, by shifting the verification object from the communication data content itself to the internal processing order of the algorithm executed by the security chip, the judgment of legitimacy relies on its dynamic behavioral characteristics rather than static message values. Therefore, even if an attacker intercepts all communication data, they cannot know the hidden state of the algorithm execution order, thereby effectively resisting eavesdropping and replay attacks and significantly improving anti-cracking capabilities.
[0026] It should be noted that in this implementation, the host device typically refers to a master control device with control and data processing capabilities, while the slave device is an auxiliary module that works in conjunction with the host to provide specific functions or authentication support. The slave device integrates a security chip to implement an anti-attack protection mechanism. For example, in the field of office equipment, when the host device is a printer, the slave device can be consumables. When a user replaces consumables, the printer, as the host, needs to authenticate the legitimacy of the newly connected consumable chip. If the chip is in anti-attack mode, the host device must be verified before subsequent printing operations can proceed. Furthermore, in the field of medical equipment, the host device can be a blood analyzer or infusion pump, while the slave device is a security chip embedded in a matching reagent kit or disposable consumable to prevent the unauthorized use of non-original consumables. In the field of home devices, the host device can be a laptop, desktop computer, or tablet, while the slave device can be a manufacturer-supplied peripheral device, such as a stylus, mouse, or keyboard.
[0027] To make the solution provided in this embodiment clearer, the steps of the anti-attack state removal method provided in this embodiment are described in detail below. However, it should be understood that the operations in the flowchart do not have to be implemented in sequence, and steps without logical context can be reversed in order or implemented simultaneously. Furthermore, those skilled in the art, guided by the content of this application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart. See also... Figure 1 The method includes: S1 receives and responds to the status release command sent by the host, and determines the target execution order of multiple preset algorithms.
[0028] It should be understood that the slave device is in an attack-protected state before receiving the state cancellation command. In this state, the slave device cannot respond to the master's regular commands. This attack-protected state refers to a protective operating mode that the slave device actively enters due to the detection of a potential security threat. In this state, the slave device no longer processes commands issued by the master according to the regular communication protocol, which manifests as blocking master commands or deliberately returning incorrect response data. In other words, even if the master sends a legally formatted command frame, the slave device will not execute the corresponding function or provide genuine feedback, thereby preventing the data during the communication flow from being eavesdropped on.
[0029] In this embodiment, the status cancellation instruction received by the slave device has the following instruction structure: Command header + flag information + Parameters +
[0030] Among them, the sign information The function category of the instruction is indicated by values divided into at least two logical intervals (e.g., a two-way handshake authentication interval and a status deactivation interval). Therefore, when When within the two-way handshake authentication range, it indicates that the instruction is used in the two-way handshake authentication process; when When in the state release interval, it indicates that the instruction is used to release the slave device's anti-attack status. During this process, if... If the condition falls within the state-clearing range, it is confirmed that the received command is a state-clearing instruction, and the subsequent processing flow is initiated accordingly. Meanwhile, the parameters... The random numbers are extracted and used as parameters to be calculated, serving as input data for subsequent algorithm calculations.
[0031] Therefore, although the state clearing instruction is the same as the two-handshake authentication instruction in terms of communication format, it is transmitted through... The interval coding achieves functional differentiation, thereby enhancing the system's anti-analysis capability by reusing existing instructions and avoiding the predictability brought by using independent instructions.
[0032] Research has found that if the algorithm execution order is fixed or predictable, it means that the means by which the slave device's security chip can deactivate its anti-attack status are still traceable and could be cracked by attackers. Therefore, this embodiment provides the following optional implementation methods for step S1: S1-1, randomly determine the execution order of multiple algorithms.
[0033] As an optional approach provided in this embodiment, the security chip can determine the target execution order from multiple execution orders among various algorithms based on the generated random number.
[0034] It should be understood that after receiving the status clearing command from the host, the security chip internally generates a random number. This random number serves as an index value to uniquely determine the target execution order from all possible algorithm execution orders. Since there are multiple permutations and combinations among various algorithms, each random number corresponds to one of these permutations.
[0035] In this process, each permutation of the various algorithms is predefined in the slave device's security chip. Assume there are four algorithms in total, namely... There are a total of 24 possible permutations, numbered 1 to 24. Details are shown in Table 1 below: Table 1
[0036] Therefore, each arrangement corresponds to a unique execution order, such as sequence number 1 corresponding to... Serial number 24 corresponds to The slave device's security chip uses the generated random number... Based on the preset mapping rules, the corresponding sequence number is calculated.
[0037] For example, this mapping can be obtained by directly taking a random number and taking the remainder when divided by 24, i.e., the sequence number. The expression is:
[0038] In the formula, This represents the modulo operation. The resulting sequence number is... It points to a specific algorithm sequence, which serves as the target execution order for this task.
[0039] Furthermore, in this embodiment, to increase the diversity of algorithms, the number of algorithms is positively correlated with the length of the parameters to be computed. When the slave device's security chip receives the status release command, it first determines the command header and flag information. If the state is in the state release interval, extract the parameters to be calculated. As input data for subsequent algorithm execution.
[0040] Specifically, the slave device's security chip operates based on the parameters to be processed. The data length is parsed to determine the corresponding number of algorithms. If the parameters to be calculated... If the data is 32 bits (i.e., 4 bytes), such as 0x44332211, then the number of algorithms executed this time is determined to be 4.
[0041] If the parameters to be calculated If the data is 64 bits (i.e. 8 bytes), such as 0x8877665544332211, then the number of algorithms executed this time is determined to be 8.
[0042] Furthermore, this embodiment also utilizes the flag information in the state release instruction to enhance the diversity of algorithm execution order. Specifically, the target execution order includes a first execution order and a second execution order of multiple algorithms. The first execution order is determined by a random number generated by the slave device's security chip; the second execution order is adjusted based on the sequence number determined by the random number, combined with the flag information in the instruction as an offset, to obtain a new sequence number.
[0043] As another optional approach provided in this embodiment, the slave security chip can also assign a random weight value to each algorithm, and then sort the algorithms according to the magnitude of these weight values to form the target execution order. Therefore, the slave security chip uses the generated random weights as the sorting basis, directly affecting the final execution order.
[0044] For example, let's continue to assume there are four algorithms in total. After receiving the status clearing command, the slave device's security chip generates a set of random weight values, for example: Corresponding to 0.82, Corresponding to 0.35, Corresponding to 0.91, This corresponds to 0.67. During this process, the slave device's security chip sorts the aforementioned weight values, either from highest to lowest or lowest to highest, thereby determining the algorithm's execution order. If sorted from highest to lowest weight, the corresponding algorithm execution order is as follows: This order is determined as the target execution order and is used for subsequent parameter adjustments. Iterative operations.
[0045] It should be understood that regardless of whether random number lookup or random weighted sorting is used, the algorithm execution order can be dynamically changed. This can be understood as follows: by introducing random weights and dynamically generating the execution order based on their size relationships, the algorithm call path during each unlocking process becomes unpredictable, effectively enhancing the stealth and anti-analysis capabilities of the anti-attack state removal mechanism.
[0046] Based on the above embodiments' description of the target execution order and status cancellation instructions, the following will continue to discuss... Figure 1 Step S2 will be explained in detail: S2 executes multiple algorithms according to the target execution order.
[0047] In this embodiment, when it is not necessary to feed back the calculation results of multiple algorithms to the host, the slave security chip can perform calculations based on its own generated random numbers as the input parameters for multiple algorithms. When it is necessary to feed back the calculation results to the host, the calculations can be performed based on the parameters from the host; that is, the status release instruction includes the input parameters for multiple algorithms.
[0048] It should be noted that after determining the target execution order of multiple algorithms, various forms of operations can be performed on the parameters to be operated on based on the target execution order, including but not limited to chained iterative operations and grouping operations.
[0049] In chained iterative computation, the slave device's security chip directly uses the output of the previous algorithm as the input of the next algorithm. (The parameters to be computed are...) Taking 0x44332211 as an example, and assuming the target execution order is as follows: At this point, the slave device's security chip will first... Enter to Obtain intermediate results ; then Enter to get Then Enter to get Finally, Enter to Obtain the final calculation result Since the output of each step depends on the calculation result of the previous step, different execution orders will produce different final outputs, thus increasing the unpredictability of the algorithm's behavior.
[0050] In grouped computation, the slave device's security chip decomposes the parameters to be computed, inputs them separately to each algorithm module for independent computation, and then reassembles the independent results according to the original parameter data structure. (Continuing with...) Taking 0x44332211 as an example, the slave device's security chip first splits the data into byte segments: 0x11, 0x22, 0x33, and 0x44, and then assigns them to corresponding bytes. The input. Based on this, the slave device's security chip follows... Input 0x22 in the following order. We get 0x88, 0x11 input Input 0x55, 0x44 We get 0xAA, 0x33 input The result is 0xEE; and these independent calculation results are then processed according to the original... The byte order is rearranged, that is, the high-order bits are concatenated to form 0xAA ( ), 0xEE ( ), 0x88 ( ), 0x55 The final calculation result is formed. It is 0xAAEE8855.
[0051] It should be noted that when the target execution order includes the first execution order and the second execution order of multiple algorithms, the slave security chip performs calculations on the parameters to be calculated according to the first execution order and the second execution order respectively, and obtains the first calculation result and the second calculation result; then it extracts part of the data from the two calculation results, combines them to form the parameters to be matched, and feeds them back to the host.
[0052] For example, When the corresponding sequence number is 3, the corresponding first execution order is: ; logo information For an offset of 5, the new sequence number is 8, and the corresponding second execution order is... The calculation details are as follows: Will Perform iterative calculations in sequence number 3 to obtain the result 1 - 0xAB12; Will Perform iterative calculations in the order of number 8, and obtain the result 2 - 0x2956; Extract the high-order bits of result 1 and the low-order bits of result 2 respectively, and combine them to get out - 0xAB56.
[0053] Finally, 0xAB56 is used as the parameter to be matched and fed back to the host.
[0054] Thus, by setting flexible algorithm execution paths, the same set of inputs can produce variable or seemingly unchanging but internally complex outputs in different orders, thereby enhancing the concealment and anti-eavesdropping capabilities of the security chip's operation process. Whether using iterative or grouping methods, the algorithm execution process is ensured to be closely bound to the target execution order.
[0055] Based on the explanation of the target execution order in the above embodiments, the following will continue to discuss... Figure 1 Step S3 will be explained in detail: S3 receives the verification command sent by the host.
[0056] The instructions to be verified include prediction information for the execution order of various algorithms. For the host side, this embodiment provides multiple methods for predicting the execution order of various algorithms. Specifically, the host can predict the algorithm execution order through two methods: power consumption measurement or constructing a correspondence table. The power consumption measurement method infers the order by analyzing the power consumption information during the operation of various algorithms, while the latter determines the order by comparing the calculation results returned by the security chip with a pre-calculated mapping table. However, it should be understood that the power consumption measurement method is suitable for hosts with side-channel analysis capabilities, capable of collecting the dynamic power consumption characteristics of the security chip or slave device during the operation of various algorithms using hardware interfaces. In other words, the power consumption can originate from the security chip or the slave device itself. The correspondence table method is suitable when the host has sufficient computing resources and can quickly generate a complete mapping table through software simulation. Regardless of the method used, the host can effectively infer the algorithm execution order without decryption or directly reading the internal state of the slave device, thereby completing the legality verification of the anti-attack status removal request.
[0057] To distinguish between the two methods mentioned above, the state release interval in the slave device includes a first release interval and a second release interval. If the flag information in the state release instruction is located in the first release interval, it is determined that the master device obtains the order prediction information of multiple algorithms through power consumption measurement. If the flag information in the state release instruction is located in the second release interval, it is determined that the master device obtains the order prediction information of multiple algorithms by constructing a corresponding relationship table.
[0058] Taking power consumption measurement as an example, since different algorithms generate different power consumption when running, the host obtains sequential prediction information by analyzing the power consumption information during the operation of multiple algorithms.
[0059] It should be understood that after determining the target execution order of multiple preset algorithms, the slave device's security chip must execute these algorithms sequentially according to that order. During this process, each algorithm exhibits distinct power consumption characteristics due to differences in computational complexity or data access patterns. If the master device is a legitimate host, it possesses external physical layer monitoring capabilities, enabling it to detect power consumption changes during the execution of multiple algorithms and thus determine the actual execution order.
[0060] Specifically, different algorithms generate different power consumption levels during operation. For example, some algorithms exhibit high power consumption due to intensive computation, while others are low-power due to their simple operation. When the slave device's security chip executes each algorithm in the target execution sequence, its overall power consumption over time forms a recognizable curve. The legitimate host measures the current value on the slave device's power supply line (VCC line) and converts it into power consumption data, thus constructing a power consumption-time curve. Based on this curve, the host can analyze the power consumption amplitude corresponding to each algorithm's runtime segment and its relative order.
[0061] For example, suppose The power consumption of these four algorithms increases sequentially, with their respective power consumption levels as follows: Low (lowest level), Low-Medium (above Low but below the middle level), Medium-High (close to the highest but not peak), and High (the highest power consumption level among all algorithms). The host computer, by observing the power consumption-time curve, identified four consecutive power consumption levels and their order of increase: Low-medium → Low-positive → High-positive → High-medium Because of the low-to-medium correspondence algorithm Positive low correspondence algorithm Positive height correspondence algorithm Algorithm for medium to high level From this, we can deduce the target execution order as follows: .
[0062] In this way, by monitoring and analyzing the physical layer power consumption behavior of the security chip during operation, the host can indirectly infer the algorithm scheduling logic inside the security chip without relying on direct communication feedback, thereby achieving non-intrusive verification of the target execution order.
[0063] Continuing with the example of constructing a correspondence table, the state release instruction includes input parameters to be processed for multiple algorithms. Before receiving the verification instruction sent by the host, the slave's security chip sends the calculation results of the parameters to be processed as matching parameters to the host. The host performs calculations on the parameters to be processed according to the complete permutation order of multiple algorithms and constructs a correspondence table between the complete permutation order and the calculation results of each algorithm. The matching parameters are used to instruct the host to match the matching parameters with the correspondence table to obtain the order prediction information.
[0064] Therefore, it can be understood that the slave device's security chip processes the parameters to be computed according to the target execution order of multiple algorithms determined internally, and generates corresponding computation results. These computation results are then sent to the host device as parameters to be matched. During this process, the host device pre-executes the combined operations under each order based on the same parameters to be computed and all possible algorithm permutations, constructing a complete correspondence table. This table records the mapping relationship between each algorithm permutation order and its generated computation results.
[0065] After receiving the matching parameters returned by the security chip, the host compares them one by one with the calculation results in the corresponding relationship table. Through the matching operation, it identifies the specific algorithm arrangement order corresponding to the matching parameter, thereby obtaining the order prediction information. In other words, this embodiment uses the single calculation result fed back by the security chip to deduce the actual algorithm execution path used internally, enabling the host to complete the identification of the target execution order without directly obtaining the order information.
[0066] Continuing with the example of four algorithms, to efficiently generate the correspondence table, the host is configured with four independent hardware algorithm circuits, each capable of performing one algorithm operation within a single time period. Since there are 24 possible permutations of the four algorithms, all possible calculation results can be obtained by performing the calculation on the parameters to be computed using these 24 permutations.
[0067] However, considering the 24 possible permutations, each requiring 4 computation cycles, a total of 4 * 24 = 96 cycles are needed. To improve computational efficiency, this embodiment employs an improved approach combining a parallel computing architecture with an intermediate result reuse mechanism. Specifically, within each time cycle, the host executes four different algorithm operations simultaneously through four configured independent hardware algorithm circuits, achieving physical-level parallel processing capabilities and significantly improving the computational throughput per unit time. Furthermore, the intermediate computation results generated in each cycle are systematically stored in a preset address range and reused as input data in subsequent cycles, avoiding the repeated execution of the same sub-operations. This improves computational efficiency.
[0068] The following is combined with Figure 2 To provide a more intuitive explanation of the calculation process for the parameters to be calculated: (1) Period 1 The parameters to be calculated are Enter at the same time , , , Four algorithm circuits were used to obtain intermediate results. , , , And store them respectively in a preset address range. Stored in Addr_1-6, Stored in Addr_7-12 Stored in Addr_13-18 It was stored in Addr_17-24.
[0069] This can be understood as, with The order of the first algorithm will reuse the intermediate results from Addr_1-6, in order to... The order of the first algorithm will reuse the intermediate results from Addr_7-12, in order to... The order of the first algorithm will reuse the intermediate results from Addr_13-18, in order to The order of the first algorithm will reuse the intermediate results from Addr_17-24. Based on these intermediate results, see [link to relevant documentation]. Figure 2 Next, the operation process of cycle 2 will be explained.
[0070] (2) Period 2 Change the value of Addr1-2 Enter to The result was obtained. Store the results in Addr1-2, overwriting any existing intermediate results. Change the value of Addr7-8 Enter to The result was obtained. Store the results in Addr7-8, overwriting any existing intermediate results. Change the value of Addr13-14 Enter to The result was obtained. Store the results in Addr13-14, overwriting any existing intermediate results.
[0071] Change the value of Addr19-20 Enter to The result was obtained. Store the results in Addr19-20, overwriting any existing intermediate results.
[0072] This can be understood as, express , The intermediate results from Addr1-2 will continue to be reused as the order of the first two algorithms; , The order of the first two algorithms will reuse the intermediate results from Addr7-8, so that... , The order of the first two algorithms will reuse the intermediate results from Addr13-14, in order to... , The order in which the first two algorithms are arranged will reuse the intermediate results from Addr19-20. Based on these intermediate results, see [link to relevant documentation]. Figure 2 The following explains the calculation process for cycle 3: (3) Period 3 The value of Addr1 Enter to The result was obtained. Store the results in Addr1, overwriting any existing intermediate results. The value of Addr7 Enter to The result was obtained. Store the results in Addr7, overwriting any existing intermediate results. The value of Addr13 Enter to The result was obtained. Store the results in Addr13, overwriting any existing intermediate results. Enter the value of Addr19 Enter The result was obtained. Store the results in Addr19, overwriting any existing intermediate results.
[0073] Based on these intermediate calculation results, see below. Figure 2 The following explains the calculation process for cycle 4: The value of Addr1 Enter to The result was obtained. Store the results in Addr1, overwriting any existing intermediate results. The value of Addr7 Enter to The result was obtained. Store the results in Addr7, overwriting any existing intermediate results. The value of Addr13 Enter to The result was obtained. Store the results in Addr13, overwriting any existing intermediate results. The value of Addr19 Enter to The result was obtained. Store the results in Addr19, overwriting any existing intermediate results. This process continues in sequence, storing the new result back to the corresponding address. Subsequent cycles repeat this pipelined calculation process, ensuring that each algorithm circuit performs the operation only once per cycle, avoiding redundant calculations. Only 16 cycles are needed to calculate the results for 24 possible permutations. This improves the efficiency of generating the host-side lookup table.
[0074] Based on the explanation of the sequence prediction information in the above embodiments, the following will continue to discuss... Figure 1 Step S4 will be explained in detail: S4. If the sequence prediction information indicates that the execution order of multiple algorithms is consistent with the target execution order, then the anti-attack state is lifted.
[0075] It should be understood that sequence prediction information represents the execution path of the algorithm actually used, inferred from the host's response behavior during the execution of multiple algorithms based on the security chip. This sequence prediction information can be represented in various forms. For example, sequence prediction information can be a pre-defined number uniquely corresponding to the target execution order, i.e., pre-numbering all possible algorithm sequences, for example... Corresponding number 0x03 The corresponding number is 0x17, which the host obtains as the sequence prediction information through comparison. Furthermore, this sequence prediction information can directly represent the sequence data of the algorithm call order. For example, the sequence prediction information could specifically be the string "2143", where each character represents the corresponding algorithm, and the order of the characters corresponds to the order of the algorithms.
[0076] Therefore, during the interaction process of disabling the anti-attack status, sequence prediction information is generated by the host and sent to the slave security chip. This information indicates the host's prediction of the execution order of various algorithms used by the security chip. The slave security chip receives the instruction to be verified and parses the sequence prediction information from it. Subsequently, the security chip compares its locally recorded target execution order with the sequence prediction information to determine if they match. If the comparison shows that the algorithm execution order predicted by the host is the same as the target execution order actually used by the security chip, it indicates that the host has correct decoding capabilities or legitimate identification logic, thereby confirming the authenticity of the host's identity and the security of communication, and thus disabling its own anti-attack status.
[0077] Research has found that the timing of interactions between the host and slave security chips during the disarming process of a slave device's anti-attack status can serve as a crucial indicator of the communication environment's security. This is because the instruction to be verified requires the host to first obtain sequence prediction information, then generate and send it to the security chip. The time required for this process is influenced by a combination of factors, including the host's processing power, physical circuit characteristics, and communication protocol mechanisms. This means that sending the correct sequence prediction information to the security chip too early or too late poses a security risk.
[0078] Therefore, as an optional implementation provided in this embodiment, compared to the security chip immediately deactivating its anti-attack state upon receiving correct sequence prediction information, this embodiment also introduces a reception delay to increase the difficulty for attackers to crack the code. In other words, this reception delay needs to fall within a pre-agreed delay interval between the host and the security chip, and this delay interval needs to be longer than the time required for the host to obtain the sequence prediction information and send the verification command.
[0079] Therefore, before executing the deactivation of the anti-attack status in step S4, the slave device's security chip also obtains the reception delay of the instruction to be verified; if the reception delay is within the preset delay interval, the deactivation of the anti-attack status is executed.
[0080] It should be noted that the reception delay is calculated based on a specific reference time point. This reference time point can be the time when the security chip returns the corresponding response instruction to the host after receiving the status clearance instruction, or it can be the time when the status clearance instruction is received.
[0081] Here, the timing starts from the moment the response command is sent. The slave device's security chip then initiates its internal timing mechanism, continuously monitoring the arrival time of subsequent commands to be verified. Therefore, during the execution of the above steps, after the host device analyzes the power consumption information generated during the execution of various algorithms by the security chip, it generates a command to be verified containing the sequence prediction information based on the obtained sequence prediction information, and sends it with a delay within a preset delay interval. Therefore, the length of the delay interval must at least cover the cycle required for the host device to perform necessary operations such as power signal acquisition, algorithm sequence identification, and data encapsulation, ensuring that the actual host device does not issue the command prematurely.
[0082] After receiving the verification command, the slave device's security chip calculates the time interval between sending the response command and receiving the verification command, i.e., the reception delay, and compares this delay value with a preset delay interval. If the reception delay is within this interval, it indicates that the host has not undergone a complete physical layer analysis process, and may be a fast response simulated by an unauthorized device.
[0083] Thus, by introducing a receive delay detection mechanism based on the moment the response command is sent, the slave device's security chip can identify whether the master device follows the actual indirect measurement and calculation process, thereby eliminating spoofing behavior that lacks actual processing delay. Therefore, the anti-attack state is only allowed to be deactivated when the receive delay meets the condition of being within the delay interval.
[0084] The study also found that in existing technologies, the process of disabling the anti-attack status between the security chips of the host and slave devices typically follows a fixed time rhythm or predictable communication sequence (generally not exceeding 10 seconds). For example, it may immediately proceed to the next stage after completing a certain verification operation, or execute multiple command interactions in a short period of time. This deterministic timing behavior provides attackers with an exploitable analysis window, allowing malicious manufacturers to infer the complete unlocking timing logic by listening to the communication data lines and recording the time intervals between commands. Based on this, they can construct simulated devices to perform replay attacks or timing forgery. If a command is sent but no response is received within a short period of time, it is considered a communication failure or chip malfunction, thereby terminating the current cracking attempt or marking the path as invalid.
[0085] In this context, in the optional method provided in this embodiment, before executing step S3 to deactivate the anti-attack state, the slave device's security chip first determines whether it has received an instruction from the host within a preset silence period; if not, it executes the step of deactivating the anti-attack state. Of course, if so, it means that there are still external hacking devices continuing to spy on the security chip, therefore, the anti-attack state is maintained.
[0086] The preset silence period is a fixed time interval pre-defined at the factory, typically set to 2 to 4 minutes. During this period, the slave device's security chip neither expects nor needs to receive any communication commands from the host. Only when no commands are detected from the host throughout the entire preset silence period is the condition met and subsequent steps to deactivate the anti-attack status allowed; otherwise, if any commands are received during this period, it is determined that the host behavior is abnormal, and the deactivation operation is refused.
[0087] Therefore, this preset silence period can be understood as an artificially set period of no communication, the duration of which far exceeds the conventional range of command intervals in traditional communication protocols. For legitimate hosts, knowing the existence and mechanism of this silence period, they will proactively pause communication after completing the initial verification preparations, waiting for the period to end naturally before proceeding to the next stage. For attackers, if they detect that the host has not sent subsequent commands for an extended period while monitoring communication, they are highly likely to misjudge that the chip has failed, the communication link has been interrupted, or the unlocking process has been terminated, thus abandoning their current cracking attempt.
[0088] The above implementation describes methods such as sequential prediction information, reception delay, and preset silence duration to verify the identity of the host. The security chip of the slave device can combine these methods to increase the difficulty for attackers to crack the code. For example, the security chip of the slave device can only disable the attack prevention if the execution order represented by the sequential prediction information is consistent with the target execution order, the reception delay is within the delay interval, and no instructions are received from the host within the preset silence duration.
[0089] The above implementation explained the anti-attack state removal method provided in this embodiment from the perspective of the security chip. Next, the anti-attack state removal method provided in this embodiment will be explained from the perspective of the host. Therefore, this method is applied to a host that is communicatively connected to the security chip of the slave device, where the slave device is in an anti-attack state that cannot respond to the host's regular commands, such as... Figure 3 As shown, the method includes: P1 sends a status cancellation command to the security chip.
[0090] The status clearing instruction is used to instruct the security chip to determine the target execution order of multiple preset algorithms and execute the multiple algorithms in the target execution order.
[0091] P2 obtains the order prediction information of the security chip executing multiple algorithms.
[0092] In this embodiment, different algorithms will generate different power consumption when running. The host obtains the power consumption information of the security chip during the running of multiple algorithms; based on the power consumption information, the order prediction information of multiple algorithms is determined.
[0093] As described in the above embodiments, the host can construct a power consumption-time relationship curve by measuring the current value on the slave's power supply line (VCC line) and converting it into power consumption data. Based on this curve, the host can analyze the power consumption amplitude and its relative ranking for each algorithm's runtime segment.
[0094] In another optional implementation, the state release instruction includes parameters to be calculated. The host can perform calculations on the parameters to be calculated according to all permutations of various algorithms, obtaining different calculation results for each permutation; and construct a correspondence table between all permutations and their respective calculation results. Then, the host receives the parameters to be matched sent by the security chip, wherein the parameters to be matched are obtained by the slave's security chip iteratively calculating the parameters to be calculated according to the target execution order of various algorithms; the parameters to be matched are matched with the correspondence table to obtain order prediction information.
[0095] P3 sends a verification instruction, including sequence prediction information, to the security chip.
[0096] Among them, the instruction to be verified is used to instruct the security chip to deactivate the anti-attack state when the sequence prediction information indicates that the execution order of multiple algorithms is consistent with the target execution order.
[0097] In the above embodiments, each step of the anti-attack state removal method provided in this embodiment has been explained in detail, specifically including the host obtaining the target execution order of multiple algorithms in the slave's security chip through power consumption measurement or a correspondence table. The following is in conjunction with... Figure 4 as well as Figure 5 Both methods will be explained in detail.
[0098] like Figure 4 As shown, the host first sends a status cancellation command, i.e., the command... It contains identification information. ,parameter and Verification code. The slave device's security chip receives this command and parses it. When it falls into the preset state release range, the unlocking operation is initiated and recorded. As input for subsequent calculations.
[0099] During this process, the slave device's security chip generates random numbers. Based on this value, multiple preset algorithms are determined. The target execution order; execute according to this target execution order. It performs calculations, generating specific power consumption characteristics. The host receives instructions from the slave's security chip. After sending the response command, the power consumption signal during the operation of the slave device's security chip is measured. The actual execution order of the algorithm is analyzed to obtain sequence prediction information.
[0100] Based on this sequential prediction information, the host generates... And construct the instruction to be verified, i.e., the instruction The command is sent to the slave device's security chip. The slave device's security chip receives the command. Then, the receiving delay T1 is obtained. If T1 is within the preset delay interval, the process proceeds to the next step; otherwise, an anomaly is detected, and the anti-attack state is terminated. This time verification mechanism enhances the ability to identify illegal host simulation behavior.
[0101] Subsequently, the slave device's security chip is based on its own... The determined execution order of the target is based on the receiving host. The indicated sequence prediction information is checked for consistency. If they match, a result indicating that the check has passed is generated. And it sends a response to the host; otherwise, it generates an error flag. The host resolves the error by parsing the code. Determine the verification result.
[0102] After successful verification, the slave device's security chip performs an operation to deactivate the anti-attack status, specifically by checking for a master command within a preset silent period T2. If no communication occurs during T2, the environment is deemed secure, and the anti-attack status is deactivated; otherwise, an error is detected, and unlocking fails. This silent period design makes it easy for attackers to mistakenly believe the unlocking was unsuccessful, triggering additional operations and exposing their attack behavior.
[0103] like Figure 5 As shown, the host first sends a status cancellation command, i.e., the command... It contains identification information. ,parameter and Verification code. The slave device's security chip receives this command and parses it. When it falls into the preset state release range, the unlocking operation is initiated and recorded. As input for subsequent calculations.
[0104] During this process, the slave device's security chip generates random numbers. Based on this value, multiple preset algorithms are determined. The target execution order. Simultaneously, the slave device's security chip, according to... Run the corresponding algorithm in the order of execution of the target to obtain the output results. Subsequently, the slave device's security chip will Enter the feedback instruction as a parameter to be matched. And return it to the host.
[0105] The host receives the feedback command Then, the analysis revealed Content, and based on pre-defined Calculate the correspondence table between the generated algorithm sequence and its corresponding operation result, and then... By comparing the results with those in the table, the algorithm order results corresponding to the matching items can be found, which serves as information for predicting the order of multiple algorithms.
[0106] Next, the host generates the results based on the determined algorithm order. And encapsulate it in the instruction to be verified, i.e., the instruction. The command is sent from the central terminal to the slave device's security chip. The slave device's security chip receives the command. Then, analyze it. And based on its own The determined order of execution of objectives is related to Perform a validation to determine if it accurately reflects the current execution order. If they match, generate a result indicating that the validation has passed. The system then sends a response to the host; otherwise, it generates an error flag. The host parses the response command. In Determine whether the unlock verification was successful, and then decide whether to continue the unlock process.
[0107] After successful verification, the slave device's security chip performs an operation to deactivate the anti-attack status, specifically by checking for a master command within a preset silent period T2. If no communication occurs during T2, the environment is deemed secure, and the anti-attack status is deactivated; otherwise, an error is detected, and unlocking fails. This silent period design makes it easy for attackers to mistakenly believe the unlocking was unsuccessful, triggering additional operations and exposing their attack behavior.
[0108] Based on the same inventive concept as the slave device anti-attack state removal method provided in this embodiment, this embodiment also provides a slave device anti-attack state removal device. This device includes at least one software functional module that can be stored in a memory or embedded in an electronic device. The processor in the electronic device executes the executable module stored in the memory. For example, the software functional module and computer program included in this device. Please refer to... Figure 6 When the electronic device is a slave security chip, functionally, the device may include: The instruction response module 11A is used to receive and respond to the status release instruction sent by the host, and determine the target execution order of multiple preset algorithms; Algorithm execution module 12A is used to execute multiple algorithms according to the target execution order; The host verification module 13A is used to receive a verification instruction sent by the host, wherein the verification instruction includes the host's order prediction information for multiple algorithms; if the order prediction information indicates that the execution order of multiple algorithms is consistent with the target execution order, the anti-attack state is deactivated.
[0109] In this embodiment, the instruction response module 11A is used to implement Figure 1 In step S1, the algorithm execution module 12A is used to implement... Figure 1 In step S2, the host verification module 13A is used to implement... Figure 1 Steps S3 and S4 in the above steps. Therefore, for a detailed description of each of the above modules, please refer to the specific implementation method of the corresponding step.
[0110] Optionally, before disabling the anti-attack status, the host verification module 13A is also used for: Get the reception delay of the command to be verified; If the receiving delay is within the preset delay range, then the anti-attack status will be deactivated.
[0111] Optionally, before disabling the anti-attack status, the host verification module 13A is also used for: Determine whether any instructions have been received from the host within the preset silence period; If not, proceed with the steps to remove the anti-attack status.
[0112] Optionally, the instruction response module 11A is also specifically used for: The execution order of multiple algorithms is randomly determined.
[0113] Optionally, different algorithms will generate different power consumption when running. The host obtains sequential prediction information by analyzing the power consumption information of the slave during the operation of multiple algorithms.
[0114] Optionally, the state release instruction includes input parameters for various algorithms to be processed. Before receiving the verification instruction sent by the host, the algorithm execution module 12A is further used for: The result of the operation on the parameter to be operated is sent to the host as the parameter to be matched. The host operates on the parameter to be operated according to all permutations of various algorithms and constructs a correspondence table between all permutations and their respective operation results. The parameter to be matched is used to instruct the host to match the parameter to be matched with the correspondence table to obtain the order prediction information.
[0115] Please refer to Figure 7 When the electronic device is the host, functionally, the device may include: The release module 11B is used to send a state release instruction to the security chip. The state release instruction is used to instruct the security chip to determine the target execution order of multiple preset algorithms and execute the multiple algorithms according to the target execution order. The sequence prediction module 12B is used to obtain the sequence prediction information of the security chip executing multiple algorithms; The state deactivation module 13B sends a verification instruction including sequence prediction information to the security chip. The verification instruction is used to instruct the security chip to deactivate the anti-attack state when the sequence prediction information indicates that the execution order of multiple algorithms is consistent with the target execution order.
[0116] In this embodiment, the release module 11B is used to implement... Figure 3 In step P1, the sequential prediction module 12B is used to implement... Figure 3 In step P2, the state release module 13B is used to implement... Figure 1 Step P3 in the above steps. Therefore, for a detailed description of each of the above modules, please refer to the specific implementation method of the corresponding step.
[0117] Optionally, the state release instruction includes parameters to be computed. Before obtaining the order prediction information for the security chip to execute multiple algorithms, the order prediction module 12B is also used for: The parameters to be operated on are processed according to all possible permutations of the algorithms, and different operation results are obtained for all possible permutations. A table was constructed showing the correspondence between all permutation orders and their respective calculation results; Sequential prediction module 12B is also specifically used for: The system receives the parameters to be matched sent by the security chip. These parameters are obtained by the security chip iteratively performing calculations on the parameters to be operated on according to the target execution order of multiple algorithms. The parameters to be matched are matched with the corresponding relationship table to obtain the order prediction information.
[0118] Optionally, different algorithms will generate different power consumption when running, and the sequential prediction module 12B is also specifically used for: Obtain the power consumption information of the slave device during the execution of multiple algorithms; Based on power consumption information, the order prediction information of various algorithms is determined.
[0119] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0120] It should also be understood that if the above embodiments are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.
[0121] Therefore, this embodiment also provides a storage medium, which is a computer-readable storage medium. This storage medium stores a computer program, which, when executed by a processor, implements the slave-machine anti-attack state removal method provided in this embodiment, applicable to a security chip in a slave device or a host device. The storage medium can be any medium capable of storing program code, such as a USB flash drive, external hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0122] This embodiment provides an electronic device for implementing the method for disabling the slave device's anti-attack state. For example... Figure 8As shown, the electronic device may include a processor 22 and a memory 21. The memory 21 stores a computer program, and the processor reads and executes the computer program in the memory 21 corresponding to the above-described embodiments to implement the slave anti-attack state removal method provided in this embodiment.
[0123] See also Figure 8 The electronic device also includes a communication unit 23. The memory 21, processor 22 and communication unit 23 are electrically connected to each other directly or indirectly through system bus 24 to realize data transmission or interaction.
[0124] The memory 21 can be an information recording device based on any electronic, magnetic, optical, or other physical principles, used to record execution instructions, data, etc. In some embodiments, the memory 21 can be, but is not limited to, volatile memory, non-volatile memory, memory drive, etc.
[0125] In some embodiments, the volatile memory may be random access memory (RAM); in some embodiments, the non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, etc.; in some embodiments, the storage drive may be a disk drive, solid-state drive, any type of storage disk (such as optical disc, DVD, etc.), or similar storage media, or a combination thereof.
[0126] The communication unit 23 is used to send and receive data over a network. In some embodiments, the network may include a wired network, a wireless network, a fiber optic network, a telecommunications network, an intranet, the Internet, a local area network (LAN), a wide area network (WAN), a wireless local area network (WLAN), a metropolitan area network (MAN), a public switched telephone network (PSTN), a Bluetooth network, a ZigBee network, or a near field communication (NFC) network, or any combination thereof. In some embodiments, the network may include one or more network access points. For example, the network may include wired or wireless network access points, such as base stations and / or network switching nodes, through which one or more components of the service request processing system can connect to the network to exchange data and / or information.
[0127] The processor 22 may be an integrated circuit chip with signal processing capabilities, and may include one or more processing cores (e.g., a single-core processor or a multi-core processor). By way of example only, the processor described above may include a Central Processing Unit (CPU), an Application Specific Integrated Circuit (ASIC), an Application Specific Instruction-set Processor (ASIP), a Graphics Processing Unit (GPU), a Physics Processing Unit (PPU), a Digital Signal Processor (DSP), a Field Programmable Gate Array (FPGA), a Programmable Logic Device (PLD), a controller, a microcontroller unit, a Reduced Instruction Set Computing (RISC) computer, or a microprocessor, or any combination thereof.
[0128] Understandable. Figure 8The structure shown is for illustrative purposes only. Electronic devices may also have more advanced features. Figure 8 Showing more or fewer components, or having with Figure 8 The different configurations shown. Figure 8 The components shown can be implemented using hardware, software, or a combination thereof.
[0129] It should be understood that the apparatus and methods disclosed in the above embodiments can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0130] The above descriptions are merely various embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for deactivating a slave device's anti-attack status, characterized in that, A security chip applied to a slave device, the security chip being communicatively connected to a host device, wherein the slave device is in a protected state where it cannot respond to the host's regular commands, the method comprising: Receive and respond to the status release command sent by the host, and determine the target execution order of multiple preset algorithms; The various algorithms are executed in the order of the stated objectives. Receive a verification instruction sent by the host, wherein the verification instruction includes the host's sequential prediction information for the multiple algorithms; If the sequence prediction information indicates that the execution order of the various algorithms is consistent with the target execution order, then the anti-attack state is lifted.
2. The method for deactivating the slave device's anti-attack status according to claim 1, characterized in that, Before deactivating the anti-attack status, the method further includes: Obtain the reception delay of the instruction to be verified; If the receiving delay is within a preset delay interval, and no instruction is received from the host within a preset silence period after receiving the instruction to be verified, then the step of deactivating the anti-attack state is executed.
3. The method for deactivating the slave device's anti-attack status according to claim 1, characterized in that, Determine the target execution order of multiple preset algorithms, including: The target execution order of the various algorithms is randomly determined.
4. The method for deactivating the slave device's anti-attack status according to claim 1, characterized in that, The various algorithms generate different power consumptions when running. The host obtains the sequence prediction information by analyzing the power consumption information of the slave during the operation of the various algorithms.
5. The method for deactivating the slave device's anti-attack status according to claim 1, characterized in that, The state release instruction includes inputting the parameters to be computed for the various algorithms. Before receiving the verification instruction sent by the host, the method further includes: The calculation result of the parameter to be calculated is sent to the host as the matching parameter. The host performs calculations on the parameter to be calculated according to all permutations of the multiple algorithms and constructs a correspondence table between the all permutations and their respective calculation results. The matching parameter is used to instruct the host to match the matching parameter with the correspondence table to obtain the order prediction information.
6. A method for deactivating a slave device's anti-attack status, characterized in that, A method applicable to a host communicating with a slave device's security chip, wherein the slave device is in an attack-resistant state unable to respond to the host's regular commands, the method comprising: A state release instruction is sent to the security chip, wherein the state release instruction is used to instruct the security chip to determine the target execution order of a preset set of multiple algorithms, and to execute the multiple algorithms in the target execution order; Obtain the order prediction information of the execution of the multiple algorithms by the security chip; A verification instruction including the sequence prediction information is sent to the security chip, wherein the verification instruction is used to instruct the security chip to deactivate the anti-attack state when the sequence prediction information indicates that the execution order of the multiple algorithms is consistent with the target execution order.
7. The method for deactivating the slave device's anti-attack status according to claim 6, characterized in that, The state release instruction includes parameters to be calculated. Before obtaining the order prediction information for the security chip to execute the multiple algorithms, the method further includes: The parameters to be computed are calculated according to all possible permutations of the various algorithms to obtain different computation results for all possible permutations. Construct a table showing the correspondence between all the permutation orders and their respective calculation results; Obtaining the order prediction information of the execution of the multiple algorithms by the security chip includes: The system receives a parameter to be matched sent by the security chip, wherein the parameter to be matched is obtained by the security chip performing calculations on the parameter to be calculated according to the target execution order of the multiple algorithms; The parameters to be matched are matched with the corresponding relationship table to obtain the order prediction information.
8. The method for deactivating the slave device's anti-attack status according to claim 6, characterized in that, The various algorithms generate different power consumptions when running. Obtaining the order prediction information of the security chip's execution of these algorithms includes: Obtain the power consumption information of the slave device during the operation of the various algorithms; Based on the power consumption information, the order prediction information of the various algorithms is determined.
9. A device for deactivating a machine's anti-attack status, characterized in that, A security chip applied to a slave device, the security chip being communicatively connected to a host device, the slave device being in a protected state where it cannot respond to the host's regular commands, the device comprising: The instruction response module is used to receive and respond to the status release instruction sent by the host, and determine the target execution order of multiple preset algorithms; The algorithm execution module is used to execute the various algorithms according to the target execution order; The host verification module is used to receive a verification instruction sent by the host, wherein the verification instruction includes the host's order prediction information for the multiple algorithms; if the order prediction information indicates that the execution order of the multiple algorithms is consistent with the target execution order, then the anti-attack state is lifted.
10. A device for deactivating a machine's anti-attack status, characterized in that, An apparatus for use with a host device communicating with a slave device's security chip, wherein the slave device is in an attack-resistant state unable to respond to the host's regular commands, the apparatus comprising: The release module is used to send a state release instruction to the security chip, wherein the state release instruction is used to instruct the security chip to determine the target execution order of a preset set of multiple algorithms, and to execute the multiple algorithms in the target execution order; The sequence prediction module is used to obtain the sequence prediction information of the security chip executing the multiple algorithms; The status deactivation module sends a verification instruction, including the sequence prediction information, to the security chip. The verification instruction is used to instruct the security chip to deactivate the anti-attack status when the sequence prediction information indicates that the execution order of the multiple algorithms is consistent with the target execution order.
11. A storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the slave anti-attack state removal method according to any one of claims 1-6 or 7-8.
12. An electronic device, characterized in that, The electronic device includes a processor and a memory, the memory storing a computer program, which, when executed by the processor, implements the slave anti-attack state removal method according to any one of claims 1-6 or 7-8.