Consumable authentication chip and encryption authentication method
By constructing a three-party authentication architecture between the consumable authentication chip and the cloud server, and combining physically isolated key storage and dynamic authentication mechanisms, the problems of easy copying of consumable authentication and insufficient lifespan management are solved, achieving high security and full lifespan management, which is suitable for high-end industrial and automotive fields.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN SHIBO TECH CO LTD
- Filing Date
- 2026-01-30
- Publication Date
- 2026-05-08
AI Technical Summary
Existing consumable certification technologies are easily copied or replay attacks, lack effective lifespan management, leading to a proliferation of counterfeit consumables, and are not secure enough to meet the stringent requirements of high-end industrial and automotive fields.
A three-party authentication architecture consisting of consumable authentication chips, user devices, and cloud servers is constructed. By combining physically isolated key storage with dynamically changing authentication mechanisms, highly secure identity authentication and full lifecycle management are achieved through consumable authentication chips.
It achieves highly secure consumable authentication, dynamically resists replay attacks, ensures forward security of keys, provides intelligent management throughout the entire lifecycle, eliminates the refurbishment of old parts, and improves the security of equipment operation.
Smart Images

Figure CN122001645A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of encryption authentication technology, and in particular to a consumable authentication chip and encryption authentication method. Background Technology
[0002] With the popularization of IoT technology and the development of intelligent devices, the anti-counterfeiting and security management of high-value consumables is crucial. Existing authentication technologies mostly use static encoding or fixed keys, resulting in unchanging authentication information that is easily copied or replay attacks, leading to a proliferation of counterfeit consumables. Furthermore, these solutions generally lack effective lifespan management mechanisms, failing to prevent the recycling and refurbishment of obsolete consumables, posing risks to device security and user rights.
[0003] While existing improvements have introduced two-way authentication or cloud verification, they have failed to fundamentally address security issues. For example, the authentication process relies excessively on terminal devices; once a device is compromised, the entire system's security collapses. Furthermore, most solutions suffer from rigid authentication logic, fixed keys, and a lack of close integration with the real-time status of consumables, resulting in insufficient security and an inability to meet the stringent authentication requirements of high-end industrial and automotive applications. Summary of the Invention
[0004] To address the aforementioned challenges, this invention provides a consumable authentication chip and an encrypted authentication method. By constructing a three-party authentication architecture consisting of the consumable authentication chip, the user device, and a cloud server, and combining physically isolated key storage with a dynamically changing authentication mechanism, highly secure consumable identity authentication and full lifecycle management are achieved.
[0005] To achieve the above objectives, the present invention provides a consumable authentication chip, disposed on the consumable, for authentication and data management with devices using the consumable, comprising: The information traceability unit is used to store static and dynamic information of consumables, as well as keys and authentication protocols, in encrypted form; the static information includes factory information, initial life cycle value, unique identifier, material number, manufacturer information, production date, backup identifier, and serial number; the dynamic information includes charging count and health status. The anti-counterfeiting authentication unit is used to generate authentication information based on the stored information using a hash function for the device to verify authenticity. The lifespan management unit has a built-in counter for managing the lifespan of consumables based on the number of charging cycles, and can trigger a status change when a preset threshold is reached.
[0006] Preferably, the information traceability unit includes a FLASH memory, which is divided into three physically isolated areas: The first area is used to store the encrypted static information; The second area is used to store the dynamic information; The third area is used to store keys and authentication protocols.
[0007] Preferably, the anti-counterfeiting authentication unit uses the static and dynamic information of the consumables as input and generates the authentication information by calculating a hash function.
[0008] Preferably, the lifespan management unit specifically includes: When the number of charging cycles recorded by the counter reaches a first threshold, a replacement reminder signal is sent to the device. When the number of charging cycles recorded by the counter reaches the second threshold, an irreversible disable command is triggered, preventing the consumable from being used again.
[0009] An encrypted authentication method based on a consumable authentication chip, wherein the chip, the user device, and the cloud server constitute a three-party authentication architecture, comprising the following steps: S1: Use the device to generate a random number challenge value and send an authentication request to the consumable authentication chip; S2: The anti-counterfeiting authentication unit receives the random number challenge value and reads the static information, dynamic information and the key of the physically isolated key storage area in the information traceability unit. Based on the above information and the random number challenge value, it generates a first authentication code through a cryptographic hash function and sends the first authentication code and the chip's unique identifier to the device in use. S3: The device forwards the first authentication code, the unique identifier, and the random number challenge value to the cloud server; the cloud server obtains the corresponding verification information based on the unique identifier, generates a second authentication code using the same algorithm as the chip, and compares the consistency between the first authentication code and the second authentication code; S4: If the comparison matches, the authentication is successful, the cloud server authorizes the device and triggers the consumable authentication chip to update the counter and key; if the comparison does not match, the authentication fails, the cloud server returns a failure alarm, and the device immediately cuts off the power supply to the consumable authentication chip.
[0010] Preferably, step S2 specifically includes: The anti-counterfeiting authentication unit constructs the input string. It is composed of the static information, the current value of the counter and the health status in the dynamic information, and the random number challenge value; Based on keys read from physically isolated key stores Calculate the first authentication code : ; in, Given a predefined cryptographic hash function, the number of iterations is... It is an integer derived from the current value of the counter according to a preset rule; The first authentication code The chip's unique identifier is sent to the device in use.
[0011] Preferably, the number of iterations Represented as: ; in, This is the current value of the counter.
[0012] Preferably, S3 specifically includes: The cloud server queries the corresponding static information copy, dynamic information copy, and key copy based on the unique identifier, and generates a second authentication code using the same algorithm as S2.
[0013] Preferably, when the consumable is first used, the consumable authentication chip is initialized with a key, the process of which includes: The key is output by iteratively processing a single state sequence. Define the internal state of the data as initial state , from initial parameters constitute; conduct The nth state iteration operation, where the nth Second-rate( From 1 to The iterative process is as follows: Current state With fixed input values As input, through the mapping function The new internal state is calculated. , is represented as: ; Through the above After the iteration, the final internal state of the data is obtained. ; Key generation function In this final state and parameters As input, generate the initial key. The calculation formula is as follows: ; Therefore, the present invention, by employing the above-mentioned consumable authentication chip and encryption authentication method, has the following beneficial effects: (1) The present invention constructs a highly secure third-party authentication trust system: through the collaborative authentication of consumable chips, devices and cloud servers, the core verification logic is placed in a trusted cloud, eliminating the risk of single point of failure from the system architecture level.
[0014] (2) The present invention realizes a dynamic and attack-resistant authentication mechanism: the authentication process introduces random number challenge value and real-time dynamic information of consumables (such as charging times and health status), so that the authentication code generated each time changes dynamically, effectively resisting replay attacks and data eavesdropping, and greatly improving the technical threshold for cloning and forgery.
[0015] (3) The present invention provides chip-level security key protection: by storing the key in a physically isolated hardware area and entrusting it to a dedicated encryption unit for processing, the core secret is ensured to be "available but not visible". Even if some functions of the chip are compromised, the key seed can still be effectively protected, laying the physical foundation for system security.
[0016] (4) This invention realizes intelligent management of the entire life cycle of consumables: it deeply integrates identity authentication and life management, and through irreversible counters and threshold control, it accurately realizes the automated process from usage reminders to forced disabling, effectively preventing overdue use and refurbishment of old parts, and ensuring the safety of equipment operation and user experience.
[0017] (5) The present invention ensures forward security of the key: after each authentication, the system triggers the key update mechanism to ensure that even if the current key is cracked, it is impossible to trace the decryption history communication or impersonate the future identity, thus minimizing the impact of potential security leakage and realizing dynamic evolution of security.
[0018] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0019] Figure 1 This is a flowchart illustrating an encryption authentication method according to the present invention. Detailed Implementation
[0020] The following detailed description of embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0021] Unless otherwise defined, the technical or scientific terms used in this invention shall have the ordinary meaning as understood by one of ordinary skill in the art to which this invention pertains.
[0022] The terms "comprising" or "including" as used in this invention mean that the element preceding the term encompasses the element listed after the term, and do not exclude the possibility of encompassing other elements. Terms such as "inner," "outer," "upper," and "lower" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. When the absolute position of the described object changes, the relative positional relationship may also change accordingly. In this invention, unless otherwise explicitly specified and limited, the term "attached" and similar terms should be interpreted broadly. For example, it can refer to a fixed connection, a detachable connection, or an integral part; it can refer to a direct connection or an indirect connection through an intermediate medium; it can refer to the internal communication of two elements or the interaction relationship between two elements. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0023] Example A consumable authentication chip and encryption authentication method are disposed on the consumable for authentication and data management with devices using the consumable, including: The information traceability unit is used to store static and dynamic information of consumables, as well as keys and authentication protocols, in encrypted form; the static information includes factory information, initial life cycle value, unique identifier, material number, manufacturer information, production date, backup identifier, and serial number; the dynamic information includes charging count and health status. The health status is calculated by a dedicated algorithm built into the consumable certification chip based on real-time monitored sensor data. Specifically: Monitoring parameters: Sensors connected to the chip (such as a battery) continuously monitor voltage, current, temperature, and internal resistance. An experience-based weighted scoring model is used. For example: ; in, , , As a weight, the cycle count decay coefficient decreases linearly or exponentially with the number of charging cycles. At the end of each charging or discharging cycle, the chip automatically performs a health calculation and updates the stored dynamic information.
[0024] Specifically, the voltage score can be obtained by looking up a table: if the measured voltage is 3.1V, consult the preset table. For example, a score of 60 is obtained in the range [3.0V, 3.2V), and a score of 80 is obtained in the range [3.2V, 3.4V). Therefore, the voltage score is 60. The internal resistance change rate score = 100 - (current internal resistance / initial internal resistance - 1) × 1000. The weights W1, W2, and W3 can be preset during production according to the type of consumables, for example, 0.5, 0.3, and 0.2 respectively.
[0025] The unique identifier is pre-programmed by the chip manufacturer during the production of the security chip, ensuring global uniqueness. The identifier encoding rules follow international standards and include the manufacturer code, chip model code, and serial number. The manufacturer pre-enters the identifier and corresponding initial key information into the cloud server's security database via a secure channel. Identifier recycling and reuse are not supported. At the end of the consumable's lifecycle, its record status in the cloud is marked as "discarded."
[0026] The information traceability unit contains a FLASH memory, which is divided into three physically isolated areas: The first area is used to store the encrypted static information; The second area is used to store the dynamic information; The third area is used to store keys and authentication protocols.
[0027] Specifically, a secure element (SE) chip compliant with national cryptographic level 2 or higher certification is used as the hardware carrier for the information traceability unit. The three areas of the FLASH memory are physically isolated within the secure chip via hardware fuses and a memory protection unit (MPU). Unauthorized access (such as directly reading memory addresses) will trigger a chip self-locking mechanism. The key storage area (the third area) can only be accessed by the chip's internal cryptographic coprocessor; no external interface (such as I2C or SPI) can directly read its contents, achieving usability without visibility. The chip package has anti-tamper detection capabilities; once physical intrusion is detected, all data in the key storage area is immediately erased.
[0028] The anti-counterfeiting authentication unit is used to generate authentication information based on the stored information using a hash function for the device to verify authenticity. The anti-counterfeiting authentication unit uses the static and dynamic information of the consumables as input and generates the authentication information by calculating a hash function.
[0029] The lifespan management unit has a built-in counter for managing the lifespan of consumables based on the number of charging cycles, and can trigger a status change when a preset threshold is reached.
[0030] The lifespan management unit specifically includes: When the number of charging cycles recorded by the counter reaches a first threshold, a replacement reminder signal is sent to the device. When the number of charging cycles recorded by the counter reaches the second threshold, an irreversible disable command is triggered, preventing the consumable from being used again.
[0031] Specifically, the counter can be designed as a monotonically increasing, rollback-resistant hardware counter. The counter is stored in the protected OTP memory of the security chip and is locked after each write, preventing it from decrementing. After each successful authentication, the counter update operation and the key update operation are completed in an atomic transaction, ensuring consistency. Once the counter reaches its maximum value (e.g., 32 bits), the chip will automatically trigger an irreversible disable instruction to prevent overflow. Counter reset is not supported. Any attempt to tamper with or perform an abnormal rollback will trigger the chip's self-locking mechanism. The atomic transaction can be achieved by first writing the new key and the new counter value to the buffer in software logic, and then simultaneously writing them to the corresponding location in the OTP memory via an uninterruptible hardware instruction.
[0032] Example 1 An encryption authentication method where the chip, the user device, and the cloud server form a three-party authentication architecture, such as... Figure 1 As shown, it includes the following steps: S1: Use the device to generate a random number challenge value and send an authentication request to the consumable authentication chip; The device and the cloud server communicate using a bidirectional protocol (based on the SM2 / SM4 / SM9 suite). The device comes pre-installed with the cloud server's SM2 root certificate, and the cloud server verifies the device's client certificate (based on SM2). All transmitted data, including random number challenge values, authentication codes, and unique identifiers, is transmitted within a TLS encrypted channel.
[0033] S2: The anti-counterfeiting authentication unit receives the random number challenge value and reads the static information, dynamic information and the key of the physically isolated key storage area in the information traceability unit. Based on the above information and the random number challenge value, it generates a first authentication code through a cryptographic hash function and sends the first authentication code and the chip's unique identifier to the device in use. Step S2 specifically includes: The anti-counterfeiting authentication unit constructs the input string. It is composed of the static information, the current value of the counter and the health status in the dynamic information, and the random number challenge value; Based on keys read from physically isolated key stores Calculate the first authentication code : ; in, For the preset cryptographic hash function, the HMAC algorithm based on SM3 (i.e., HMAC-SM3) is used, with the number of iterations... It is an integer derived from the current value of the counter according to a preset rule; Number of iterations Represented as: ; in, This is the current value of the counter.
[0034] The first authentication code The chip's unique identifier is sent to the device in use.
[0035] S3: The device forwards the first authentication code, the unique identifier, and the random number challenge value to the cloud server; the cloud server obtains the corresponding verification information based on the unique identifier, generates a second authentication code using the same algorithm as the chip, and compares the consistency between the first authentication code and the second authentication code; The cloud server queries the corresponding static information copy, dynamic information copy, and key copy based on the unique identifier, and generates a second authentication code using the same algorithm as S2.
[0036] S4: If the comparison matches, the authentication is successful, the cloud server authorizes the device and triggers the consumable authentication chip to update the counter and key; if the comparison does not match, the authentication fails, the cloud server returns a failure alarm, and the device immediately cuts off the power supply to the consumable authentication chip.
[0037] The key update process specifically includes: After successful authentication, the cloud server generates a temporary elliptic curve key pair (e.g., based on an SM2 curve). The cloud server sends the public key to the consumable chip. The consumable chip uses its own fixed private key and the received server public key to calculate a shared secret using the SM2 key negotiation protocol. Both parties use this shared secret as input to generate a new session key using the SM3 Key Derivation Function (KDF). The consumable chip writes the new key to a physically isolated key storage area, overwriting the old key. The cloud server synchronously updates the key copy corresponding to the chip identifier. Even if the key for a session is cracked, because the attacker does not have the chip's fixed private key, they cannot calculate historical or future session keys, thus achieving forward security.
[0038] When the consumable is first activated, the authentication chip of the consumable is initialized with a key, the process of which includes: The key is output by iteratively processing a single state sequence. Define the internal state of the data as initial state , from initial parameters constitute; conduct The nth state iteration operation, where the nth Second-rate( From 1 to The iterative process is as follows: Current state With fixed input values As input, through the mapping function The new internal state is calculated. , is represented as: ; In a specific iteration, output can be generated based on the current state. For example, it can be defined as follows: Through the above After the iteration, the final internal state of the data is obtained. ; Key generation function In this final state and parameters As input, generate the initial key. The calculation formula is as follows: ; As a preferred implementation method: initial parameters This is the root entropy extracted from the chip's physically unclonable function (PUF).
[0039] Fixed input value This is a byte array containing the chip's unique identifier.
[0040] Mapping function Defined as using A as the encryption key for the SM4 algorithm, encrypting a 128-bit data block formed by padding B with PKCS#7 in ECB mode, and outputting the ciphertext.
[0041] It is defined as taking 16 consecutive bytes (128 bits) from the (count mod 16)th byte of the state data as the output key K.
[0042] When the consumable is first activated, the authentication chip of the consumable is initialized with a key, the process of which includes: The key is output by iteratively processing the single state sequence. The state sequence before and after the output is calculated as follows: ; ; in, The output value of a single sequence state after iteration. For byte data at a certain moment, The initial sequence input values contain information such as unique identifiers. The parameters are in the initial state; the mapping function. Defined as using A as the encryption key for the SM4 algorithm, encrypting a 128-bit data block formed by padding B with PKCS#7 in ECB mode, and outputting the ciphertext.
[0043] The internal state of the iterated data is obtained through the above calculations. and combined with mapping functions Complete Key Generation: .
[0044] It is defined as taking 16 consecutive bytes (128 bits) from the (count mod 16)th byte of the state data as the output key K.
[0045] Therefore, the present invention adopts the above-mentioned consumable authentication chip and encryption authentication method, and constructs a three-party authentication architecture consisting of a consumable authentication chip, a user device and a cloud server, and combines physically isolated key storage and a dynamically changing authentication mechanism to achieve highly secure consumable identity authentication and full life cycle management.
[0046] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A consumable authentication chip, disposed on a consumable, for authentication and data management with a device using the consumable, characterized in that, include: The information traceability unit is used to store static and dynamic information of consumables, as well as keys and authentication protocols, in encrypted form; the static information includes factory information, initial life cycle value, unique identifier, material number, manufacturer information, production date, backup identifier, and serial number; the dynamic information includes charging count and health status. The anti-counterfeiting authentication unit is used to generate authentication information based on the stored information using a hash function for the device to verify authenticity. The lifespan management unit has a built-in counter for managing the lifespan of consumables based on the number of charging cycles, and can trigger a status change when a preset threshold is reached.
2. The consumable authentication chip according to claim 1, characterized in that: The information traceability unit includes a FLASH memory, which is divided into three physically isolated areas: The first area is used to store the encrypted static information; The second area is used to store the dynamic information; The third area is used to store keys and authentication protocols.
3. The consumable authentication chip according to claim 1, characterized in that: The anti-counterfeiting authentication unit uses the static and dynamic information of the consumables as input and generates the authentication information by calculating a hash function.
4. The consumable authentication chip according to claim 1, characterized in that, The lifespan management unit specifically includes: When the number of charging cycles recorded by the counter reaches a first threshold, a replacement reminder signal is sent to the device. When the number of charging cycles recorded by the counter reaches the second threshold, an irreversible disable command is triggered, preventing the consumable from being used again.
5. An encryption authentication method based on a consumable authentication chip according to any one of claims 1-4, wherein the chip, the user device, and the cloud server constitute a three-party authentication architecture, characterized in that... Includes the following steps: S1: Use the device to generate a random number challenge value and send an authentication request to the consumable authentication chip; S2: The anti-counterfeiting authentication unit receives the random number challenge value and reads the static information, dynamic information and the key of the physically isolated key storage area in the information traceability unit. Based on the above information and the random number challenge value, it generates a first authentication code through a cryptographic hash function and sends the first authentication code and the chip's unique identifier to the device in use. S3: The device forwards the first authentication code, the unique identifier, and the random number challenge value to the cloud server; the cloud server obtains the corresponding verification information based on the unique identifier, generates a second authentication code using the same algorithm as the chip, and compares the consistency between the first authentication code and the second authentication code; S4: If the comparison matches, the authentication is successful, the cloud server authorizes the device and triggers the consumable authentication chip to update the counter and key; if the comparison does not match, the authentication fails, the cloud server returns a failure alarm, and the device immediately cuts off the power supply to the consumable authentication chip.
6. The encryption authentication method according to claim 5, characterized in that, Step S2 specifically includes: The anti-counterfeiting authentication unit constructs the input string. It is composed of the static information, the current value of the counter and the health status in the dynamic information, and the random number challenge value; Based on keys read from physically isolated key stores Calculate the first authentication code : ; in, For a cryptographic hash function, the number of iterations is... It is an integer derived from the current value of the counter according to a preset rule; The first authentication code The chip's unique identifier is sent to the device in use.
7. The encryption authentication method according to claim 6, characterized in that: The number of iterations Represented as: ; in, This is the current value of the counter.
8. The encryption authentication method according to claim 7, characterized in that, S3 specifically includes: The cloud server queries the corresponding static information copy, dynamic information copy, and key copy based on the unique identifier, and generates a second authentication code using the same algorithm as S2.
9. The encryption authentication method according to claim 8, characterized in that: When the consumable is first activated, the authentication chip of the consumable is initialized with a key, the process of which includes: The key is output by iteratively processing a single state sequence. Define the internal state of the data as initial state , from initial parameters constitute; conduct The nth state iteration operation, where the nth Second-rate( From 1 to The iterative process is as follows: Current state With fixed input values As input, through the mapping function The new internal state is calculated. , is represented as: ; Through the above After the iteration, the final internal state of the data is obtained. ; Key generation function In this final state and parameters As input, generate the initial key. The calculation formula is as follows: 。