A method and system for anti-counterfeiting identification of server hardware
By extracting the power supply transient ripple voltage sequence and generating a composite hardware anti-counterfeiting seed through thermal normalization compensation, and combining it with the digital signature mechanism of the trusted platform module, the problem of not being able to identify counterfeit hardware in existing technologies is solved, ensuring the security and stability of server hardware.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHONGNAN INFORMATION TECH (SHENZHEN) CO LTD
- Filing Date
- 2026-05-26
- Publication Date
- 2026-06-23
AI Technical Summary
Existing technologies cannot effectively prevent physical hardware cloning by simply identifying firmware data, which threatens the data security and operational stability of the server's underlying infrastructure.
By capturing the transient ripple voltage sequence of the power supply, extracting the hardware physical characteristics, calculating the transient signal distortion index and performing thermal normalization compensation, a composite hardware anti-counterfeiting seed is generated, which is then combined with the digital signature mechanism of the trusted platform module for anti-counterfeiting verification.
It enables accurate identification of counterfeit hardware, ensuring the data security and operational stability of the server's underlying infrastructure, and improving the reliability and security of anti-counterfeiting verification.
Smart Images

Figure CN122263174A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to an anti-counterfeiting identification method and system for server hardware. Background Technology
[0002] With the development of cloud computing, big data, and artificial intelligence computing power industries, large-scale distributed data centers have become the core carrier of digital infrastructure. The number of server nodes in a single data center can reach tens of thousands to hundreds of thousands. In the full lifecycle operation and maintenance management of multi-node distributed data centers, remote operation and maintenance cloud platforms need to achieve remote batch anti-counterfeiting inspection and physical identity authentication of core hardware such as CPUs, memory, hard drives, and expansion cards inside massive server nodes without physical contact. This is to ensure the security of the underlying hardware supply chain of servers, prevent unauthorized hardware replacement, avoid operational risks and data security risks caused by inferior counterfeit hardware, and at the same time achieve precise full lifecycle management of hardware assets.
[0003] Currently, the industry commonly uses a platform configuration register reference signature verification algorithm based on a trusted platform module to build a secure trust chain. This core technology typically involves hashing the firmware, driver, or configuration data loaded on the server and extending the result into the platform configuration register. Then, the register value is digitally signed using the identity verification key inside the trusted platform module and handed over to a remote cloud platform for signature verification and comparison.
[0004] However, existing anti-counterfeiting verification algorithms based on trusted platform modules have significant limitations in measurement granularity. These algorithms essentially only measure anti-counterfeiting at the software firmware level, lacking the ability to extract underlying physical characteristics. In actual data center maintenance and anti-counterfeiting scenarios, counterfeiters often use inferior hardware and specialized burning tools to perfectly clone the data of genuine electronically erasable rewritable read-only memory (EROM). Since the underlying firmware data of counterfeit hardware is completely identical to that of genuine products, the register hash value calculated by existing algorithms will be the same as that of genuine products. This leads to the deception of remote inspection systems, making it impossible to effectively identify counterfeit physical hardware and thus seriously threatening the data security and operational stability of the server's underlying infrastructure. Summary of the Invention
[0005] To address the problem that existing technologies, which rely solely on firmware data identification, cannot effectively prevent physical hardware cloning, thereby seriously threatening the data security and operational stability of the server's underlying infrastructure, this invention provides a method and system for anti-counterfeiting identification of server hardware.
[0006] In a first aspect, the present invention provides an anti-counterfeiting identification method for server hardware, employing the following technical solution: A method for anti-counterfeiting identification of server hardware includes: sending a read command to the target hardware to be verified via a baseboard management controller on the server motherboard, and activating a built-in analog-to-digital converter to capture the power transient ripple voltage sequence on the power supply pin of the target hardware to be verified during the response to the read command at a preset discrete sampling frequency; extracting the deviation between the power transient ripple voltage sequence and a factory-stored reference voltage sequence, and calculating the transient signal distortion index; obtaining the current real-time operating temperature of the target hardware to be verified via a digital temperature sensor, and performing feature compensation on the transient signal distortion index based on the real-time operating temperature to generate thermally normalized physical characteristics; and further... The raw firmware binary data read from the target hardware to be verified is hashed to obtain a static firmware digest. Based on the noise tolerance bit width of the hardware model to which the target hardware to be verified belongs, the thermally normalized physical characteristics are converted into a fixed-length digital format and hashed and fused with the static firmware digest to construct a composite hardware anti-counterfeiting seed. The composite hardware anti-counterfeiting seed is then sent to the trusted platform module on the server motherboard. The trusted platform module performs a platform configuration register extension operation to generate the current register value, and uses the built-in identity verification key to digitally sign the current register value to generate a signature result. The signature result and the real-time operating temperature are sent to the remote cloud platform for anti-counterfeiting verification.
[0007] This invention extracts the physical characteristics of target hardware by capturing the transient ripple voltage sequence of the power supply, accurately reflecting the physical and electrical characteristics of the hardware circuit and providing a reliable physical characteristic basis for subsequent calculation of transient signal distortion index. By calculating the transient signal distortion index and performing thermal normalization compensation, thermally normalized physical characteristics are generated, realizing a numerical representation of the hardware's physical characteristics. This accurately distinguishes the physical and electrical differences between genuine and counterfeit hardware, effectively solving the limitation of existing algorithms that only measure at the software firmware level. By constructing a composite hardware anti-counterfeiting seed, the physical characteristics and firmware digest are integrated, containing both the hardware's physical characteristics and firmware information, improving the reliability of anti-counterfeiting verification. Based on the digital signature mechanism of the trusted platform module, the security and immutability of the anti-counterfeiting verification process are ensured, effectively identifying counterfeit physical hardware and protecting the data security and operational stability of the server's underlying infrastructure.
[0008] The transient signal distortion index satisfies: In the formula, The transient signal distortion index of the target hardware to be verified. The total number of sampling points. The first in the power supply transient ripple voltage sequence Voltage values obtained from each sampling point For genuine hardware, within the factory-pre-stored reference voltage sequence, the first... Voltage values obtained from each sampling point This is the standard rated operating voltage for the power supply pin.
[0009] This invention achieves a scientific assessment of the transient signal distortion index by constructing a mean model that includes the square of the relative error between the power supply transient ripple voltage and the reference voltage. This more accurately reflects the difference between the target hardware and genuine hardware in power supply transient response. The normalization process eliminates the influence of dimensions, thereby effectively distinguishing the differences in physical and electrical characteristics between genuine hardware and counterfeit hardware.
[0010] The thermally normalized physical characteristic satisfies: In the formula, The thermally normalized physical characteristics of the target hardware to be verified. The transient signal distortion index of the target hardware to be verified. This is the standard test environment reference temperature for genuine hardware during factory calibration. The target is the current real-time operating temperature of the hardware to be verified. The temperature drift compensation coefficient is the hardware model to which the target hardware to be verified belongs.
[0011] This invention achieves a scientific evaluation of thermally normalized physical characteristics by constructing a product model that includes transient signal distortion index and temperature compensation term. It more accurately corrects the influence of temperature changes on physical characteristics, ensures the consistency of physical characteristics under different temperature conditions, and thus accurately reflects the essential physical and electrical characteristics of the hardware, providing reliable temperature-independent characteristics for anti-counterfeiting identification.
[0012] Furthermore, the composite hardware anti-counterfeiting seed satisfies: In the formula, A composite hardware anti-counterfeiting seed for the target hardware to be verified. For the static firmware summary of the target hardware to be verified, The thermally normalized physical characteristics of the target hardware to be verified. For the sampling bit width of the analog-to-digital converter, The noise tolerance bit width of the target hardware model to be verified. This is a standard 256-bit secure hash algorithm operation. For bit width alignment operation, For data concatenation operations, This is a floor operation.
[0013] This invention achieves the generation of composite hardware anti-counterfeiting seeds by constructing a hash fusion model that includes static firmware summaries and thermally normalized physical features. It accurately integrates the firmware information and physical features of the hardware, and introduces a noise tolerance bit width to perform low-bit truncation of the physical features, effectively smoothing out numerical fluctuations caused by minor electrical noise at the underlying level. This avoids false anti-counterfeiting judgments caused by the hash avalanche effect triggered by minor measurement deviations in the same genuine hardware. While maintaining the feature gap between genuine and counterfeit products, it ensures the absolute stability of anti-counterfeiting features. The bit width alignment operation ensures the uniformity of the data format, thereby effectively preventing forgery attacks based solely on firmware data and improving the reliability of hardware anti-counterfeiting verification.
[0014] Furthermore, the step of generating the current register value by the platform configuration register extension operation performed by the trusted platform module includes: the trusted platform module calling the internal hash engine to concatenate the historical register value before extension with the composite hardware anti-counterfeiting seed and perform a hash operation to generate the current register value.
[0015] This invention achieves incremental updates to the current register value by concatenating historical register values with a composite hardware anti-counterfeiting seed and performing a hash operation. This ensures that the register value contains complete hardware anti-counterfeiting information while maintaining the continuity of the trust chain, providing a reliable data foundation for subsequent digital signature verification.
[0016] Furthermore, the step of sending the signature result and real-time operating temperature to the remote cloud platform for anti-counterfeiting verification includes: after receiving the signature result and real-time operating temperature, the remote cloud platform uses the corresponding public key to perform a signature verification operation; after the signature verification is successful, the verified current register value is compared with the factory-level physical anti-counterfeiting database pre-established by the remote cloud platform to confirm the true physical identity of the target hardware to be verified.
[0017] Furthermore, the bit width alignment operation includes: in response to the converted integer bit width being less than or equal to 256 bits, padding the high bits with zeros to 256 bits; in response to the converted integer bit width being greater than 256 bits, truncating the lower 256 bits of data.
[0018] Furthermore, the temperature drift compensation coefficient is a fixed value determined based on batch testing of hardware of the same hardware model at the factory.
[0019] Furthermore, the total number of sampling points is calculated by multiplying the sampling duration of the analog-to-digital converter by the discrete sampling frequency.
[0020] Secondly, the present invention provides an anti-counterfeiting identification system for server hardware, which adopts the following technical solution: An anti-counterfeiting identification system for server hardware includes a processor and a memory, wherein the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the aforementioned anti-counterfeiting identification method for server hardware is implemented.
[0021] By adopting the above technical solution, a computer program for anti-counterfeiting identification method for server hardware is generated and stored in a memory for loading and execution by a processor, thereby creating a terminal device based on the memory and processor for convenient use.
[0022] The present invention has the following technical effects: (1) In view of the fact that traditional algorithms based on trusted platform modules can only achieve anti-counterfeiting measurement at the firmware level and cannot deal with the problem of high-imitation counterfeit hardware with perfectly cloned firmware, this invention captures the power transient ripple voltage sequence of the power supply pin when the hardware responds to the read command, and extracts the inherent physical characteristics of the hardware that cannot be cloned. These characteristics are derived from the inherent discrete attributes of the physical level such as the electrical characteristics of hardware components, PCB trace impedance, and power supply circuit design. Even if the counterfeit hardware completely clones the original firmware data through a special burning tool, its power transient ripple characteristics cannot be completely consistent with the genuine product, thus breaking the cloning deception path of counterfeit hardware from the bottom layer. Combined with the legality verification of firmware static hash digest, dual anti-counterfeiting verification of physical hardware identity and firmware program integrity is realized, which effectively solves the core pain point of traditional algorithms being deceived by cloned firmware and unable to identify high-imitation counterfeit hardware.
[0023] (2) In view of the problem that real-time temperature changes during server operation can affect the power supply ripple characteristics, thereby causing physical feature distortion and anti-counterfeiting misjudgment, this invention obtains the real-time operating temperature of the hardware through a digital temperature sensor, performs temperature feature compensation on the transient signal distortion index, and generates thermally normalized physical features. This effectively eliminates feature deviations caused by ambient temperature fluctuations and hardware load temperature rise, ensuring that the true inherent physical features of the hardware can be extracted stably and accurately under different operating conditions such as low temperature no-load and high temperature full load, avoiding anti-counterfeiting misjudgment and missed judgment caused by temperature changes, and effectively improving the stability and recognition accuracy of anti-counterfeiting identification in the complex operating environment of the computer room.
[0024] (3) This invention converts thermally normalized physical features into a fixed-length digital format, performs hash fusion with static firmware digest to construct a composite hardware anti-counterfeiting seed, and then sends it to the trusted platform module to perform platform configuration register expansion and digital signature operation. This not only fully retains the security features and mature signature verification process of the existing TPM trusted trust chain, but also adds an anti-counterfeiting measurement dimension of the underlying physical hardware without changing the existing server hardware architecture or reconstructing the remote cloud platform signature verification system, thus reducing the transformation cost and implementation threshold of the technology. Attached Figure Description
[0025] Figure 1 This is a flowchart of a method for anti-counterfeiting identification of server hardware according to an embodiment of the present invention.
[0026] Figure 2 This is a partial comparison diagram of a reference voltage sequence and a power supply transient ripple voltage sequence of a genuine hardware under test in an anti-counterfeiting identification method for server hardware according to an embodiment of the present invention.
[0027] Figure 3 This is a partial comparison diagram of a reference voltage sequence and a power supply transient ripple voltage sequence of a counterfeit hardware under test in an anti-counterfeiting identification method for server hardware according to an embodiment of the present invention.
[0028] Figure 4 This is a schematic diagram comparing the byte distribution of register values generated by the platform configuration register extension operation of the trusted platform module for genuine and counterfeit products in an anti-counterfeiting identification method for server hardware according to an embodiment of the present invention.
[0029] Figure 5 This is a schematic diagram comparing the pass rates of genuine and counterfeit products in various anti-counterfeiting verification indicators in an anti-counterfeiting identification method for server hardware according to an embodiment of the present invention. Detailed Implementation
[0030] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0031] This invention discloses an anti-counterfeiting identification method for server hardware, referring to... Figure 1 This includes steps S001-S005: S001: Obtain the power supply transient ripple voltage sequence on the power supply pin of the target hardware to be verified during the response to the read command.
[0032] Specifically, a read command is sent to the target hardware to be verified via the baseboard management controller on the server motherboard, such as sending a specific read command via the system management bus, and the built-in analog-to-digital converter is simultaneously activated at a preset discrete sampling frequency, such as a sampling frequency of... Capture the transient power supply ripple voltage sequence on the power supply pin of the target hardware to be verified during the response to the read command, such as a sampling duration of... .
[0033] S002: Extract the deviation between the power supply transient ripple voltage sequence and the factory-stored reference voltage sequence, and calculate the transient signal distortion index.
[0034] It's important to note that power supply transient ripple is a unique signal determined by the inherent electrical characteristics of internal components, PCB trace impedance, and load transient response characteristics of the hardware's power supply circuit when responding to read commands. It's a physical characteristic that cannot be replicated by the hardware. The physical manufacturing differences between genuine and counterfeit hardware are directly reflected in the deviation of the ripple voltage sequence, and the transient signal distortion index is the core indicator for evaluating this physical difference. Therefore, this step, by normalizing and quantifying the deviation between the measured ripple sequence and the factory reference sequence, accurately characterizes the degree of difference in transient electrical response between the hardware under test and genuine hardware, providing a core evaluation basis for subsequent temperature compensation and anti-counterfeiting feature fusion.
[0035] Specifically, the transient signal distortion index satisfies: ; In the formula, The transient signal distortion index of the target hardware to be verified. The total number of sampling points is calculated by multiplying the sampling duration of the analog-to-digital converter integrated within the baseboard management controller by the sampling frequency. The first in the power supply transient ripple voltage sequence Voltage values obtained from each sampling point For genuine hardware, within the factory-pre-stored reference voltage sequence, the first... Voltage values obtained from each sampling point This is the standard rated operating voltage for the power supply pins. During the server's factory calibration phase, the standard rated operating voltage is determined based on the hardware specifications and motherboard power supply design specifications. In this embodiment, it is taken as [value missing]. , It is a universal standard power rail rating applicable to most replaceable anti-counterfeiting hardware in the server industry. It can accurately capture micro-physical differences in hardware, reduce the false judgment rate of anti-counterfeiting, and also meet the engineering implementation needs of mass production deployment and batch inspection of servers.
[0036] The above formula employs a normalized mean square error (MSE) calculation framework. First, the difference between the measured voltage and the reference voltage at each sampling point is normalized relative to the rated operating voltage to eliminate the dimensional influence of the difference in rated voltage of different power supply rails on the calculation results. Then, the square of the normalized relative error is taken to amplify the subtle differences in electrical characteristics between genuine and counterfeit products, while suppressing the interference of small-amplitude random noise on the distortion judgment during the sampling process. Finally, the arithmetic mean of the square values of all sampling points within the entire sampling period is taken to obtain an evaluation value that can comprehensively reflect the overall transient response distortion of the hardware. This value can stably and accurately reflect the differences in inherent electrical characteristics between the hardware to be verified and genuine hardware.
[0037] like Figure 2 As shown, in Within the sampling period, the power supply transient ripple voltage sequence of the genuine hardware under test closely matches the fluctuation trend of the factory-stored reference voltage sequence. The voltage deviation between the two is within a very small range, resulting in a very low transient signal distortion index. This accurately reflects the consistency of the physical and electrical characteristics between the genuine hardware and the factory reference.
[0038] like Figure 3 As shown, under the same sampling duration and test conditions, the power supply transient ripple voltage sequence of the counterfeit hardware under test has a large amplitude deviation and phase difference from the reference voltage sequence. Its voltage fluctuation amplitude is far greater than that of the genuine hardware. The corresponding calculated transient signal distortion index is significantly higher than the threshold of the genuine product. This intuitively reflects the essential difference between the counterfeit hardware and the genuine hardware in terms of inherent physical and electrical characteristics, and verifies the effectiveness of the present invention in identifying counterfeit hardware based on transient ripple characteristics.
[0039] S003: Obtain the current real-time operating temperature of the target hardware to be verified through a digital temperature sensor, perform feature compensation on the transient signal distortion index based on the real-time operating temperature, and generate thermally normalized physical characteristics.
[0040] It should be noted that the electrical parameters of the electronic components used in the hardware will drift regularly with operating temperature, causing fluctuations in the transient ripple characteristics of the power supply that are unrelated to the inherent physical characteristics of the hardware. If the original transient signal distortion index is directly used for anti-counterfeiting verification, it is prone to characteristic deviations due to changes in the ambient temperature of the computer room and the temperature rise of the hardware load, affecting the accuracy of anti-counterfeiting judgment. Therefore, this step introduces a real-time temperature compensation mechanism based on the inherent temperature drift characteristics of the hardware model to perform thermal normalization correction on the transient signal distortion index, eliminating the interference of temperature fluctuations on physical characteristics, and generating temperature-independent stable physical characteristics that are only related to the inherent electrical characteristics of the hardware, ensuring the accuracy and stability of anti-counterfeiting identification under different operating conditions.
[0041] Specifically, the thermally normalized physical characteristic satisfies: ; In the formula, The thermally normalized physical characteristics of the target hardware to be verified. The transient signal distortion index of the target hardware to be verified. This is the standard test environment reference temperature for genuine hardware during factory calibration. During the server hardware factory calibration phase, this standard test environment temperature is set according to server industry standards and the corresponding hardware specifications. It is typically set to a value of [value missing]. , As the standard room temperature reference temperature used in the electronics industry, the performance parameter calibration and factory calibration of most server hardware are based on this temperature. This ensures that the thermal normalization reference is consistent with the calibration state of the hardware at the time of manufacture, avoids interference of ambient temperature differences on the verification results, and complies with the general calibration specifications of the server industry. The target is the current real-time operating temperature of the hardware to be verified. The temperature drift compensation coefficient is the temperature drift compensation factor for the hardware model to be verified, which is applied to this model of server hardware. , , Performance tests were conducted at multiple temperature points, and the temperature drift compensation coefficient for this hardware model was obtained by least squares fitting. In this embodiment, the value is taken as [value missing]. The temperature drift coefficient of electronic components in server hardware, such as power modules and signal processing components, is typically within a certain range. Within the range, This is a typical value within this range, and it can effectively correct server performance. The signal distortion difference within the normal operating temperature range is balanced between compensation accuracy and engineering implementation cost.
[0042] The above-mentioned relationship adopts a linear temperature compensation model, which uses the standard reference temperature during hardware factory calibration as a reference. Through a pre-calibrated temperature drift compensation coefficient, the influence weight of temperature deviation on the distortion index is quantified. By calculating the difference between the real-time operating temperature and the factory reference temperature, and combining the compensation coefficient, a corresponding temperature compensation term is generated to linearly correct the distortion index of the original transient signal. The distortion index collected at different temperatures is normalized to the characteristic level corresponding to the factory reference temperature, ensuring that the finally generated thermally normalized physical characteristics only reflect the inherent physical properties of the hardware itself and are not affected by temperature changes caused by the operating environment and load conditions.
[0043] S004: Perform a hash operation on the raw firmware binary data read from the target hardware to be verified to obtain a static firmware digest. Based on the noise tolerance bit width of the hardware model to which the target hardware to be verified belongs, convert the thermally normalized physical characteristics into a fixed-length digital format and perform hash fusion with the static firmware digest to construct a composite hardware anti-counterfeiting seed. Then send the composite hardware anti-counterfeiting seed to the trusted platform module on the server motherboard.
[0044] It should be noted that firmware static digests can verify the integrity and legitimacy of hardware programs, while thermally normalized physical features can identify the true physical identity of the hardware. The fusion of these two technologies enables dual-dimensional anti-counterfeiting verification, encompassing both hardware and software. However, electrical signals inevitably exhibit minute random fluctuations. Directly quantizing high-precision floating-point features can easily trigger an avalanche effect in subsequent hash algorithms due to minor jumps at critical points, completely altering the anti-counterfeiting seed generated from genuine features. Therefore, this step introduces a noise tolerance bit width mechanism. Before fixed-length format conversion, low-bit precision truncation is proactively performed to effectively filter out the influence of unstable noise. Subsequently, through data concatenation and secure hashing, the firmware integrity information and stable inherent physical features are irreversibly fused and bound, generating a unique composite hardware anti-counterfeiting seed. This achieves a strong binding between hardware and software anti-counterfeiting dimensions and fully adapts to the trusted platform module's input data format requirements, providing a secure and standard input source for subsequent trust chain expansion.
[0045] Specifically, the composite hardware anti-counterfeiting seed satisfies: ; In the formula, A composite hardware anti-counterfeiting seed for the target hardware to be verified. For the static firmware summary of the target hardware to be verified, The thermally normalized physical characteristics of the target hardware to be verified. For the sampling bit width of the analog-to-digital converter, The noise tolerance bit width is determined by statistically analyzing the maximum fluctuation range of the characteristics of genuine hardware of the same model as the target hardware under all operating conditions. The minimum significant number of bits affected by the quantization of this range is then evaluated to obtain the noise tolerance bit width. This setting can accurately remove unstable low-bit data affected by environmental noise and retain core high-bit features, thereby blocking the path of small analog fluctuations triggering hash avalanche effects at the source and ensuring anti-counterfeiting stability. In this embodiment, the value is set to 4, which can balance the anti-counterfeiting anti-interference stability and physical identity uniqueness while adapting to the sampling accuracy of the constant scale converter. This is a standard 256-bit secure hash algorithm operation. For bit width alignment operations, if the converted integer bit width The high-order bits are padded with zeros to a total of 256 bits, if the converted integer has a bit width. Take the lower 256 bits; The data stitching operation is implemented by memory operation instructions from the baseboard management controller; This is a floor operation.
[0046] Among them, the above relation is first passed through of The exponentiation and rounding down process converts the thermally normalized physical characteristics of floating-point data into integer data that matches the sampling precision of the analog-to-digital converter. During this conversion, the subtraction of the noise tolerance bit width essentially performs a low-bit truncation operation, actively removing the last few unstable bits of data that are affected by environmental thermal noise or electromagnetic interference. Since the slight measurement deviations between genuine hardware components are limited to the discarded low-bit interval, this operation forces floating-point values with slight fluctuations to converge to the same absolutely equal integer, thus avoiding the avalanche effect of hash algorithms. Then, through bit width alignment, the converted physical characteristic data is unified into a 256-bit fixed-length format to ensure consistency with the data concatenation format of the static firmware digest. Subsequently, the fixed-length physical characteristic data is concatenated with the static firmware digest to fully integrate the dual anti-counterfeiting information of software and hardware. Finally, a fixed-length 256-bit composite hardware anti-counterfeiting seed is generated through the SHA256 secure hash algorithm, realizing irreversible compression and strong binding of anti-counterfeiting information, ensuring that the integrated anti-counterfeiting seed cannot be reverse-engineered, tampered with, or counterfeited independently.
[0047] S005: The trusted platform module performs a platform configuration register extension operation to generate the current register value, and uses the built-in identity verification key to digitally sign the current register value to generate a signature result. The signature result and the real-time operating temperature are then sent to the remote cloud platform for anti-counterfeiting verification.
[0048] It should be noted that the Trusted Platform Module, as the core carrier of the server hardware root of trust, performs key storage, hash operations, and digital signature operations within a hardware-level secure isolation environment. This ensures the confidentiality, integrity, and immutability of anti-counterfeiting feature data throughout the entire process. Furthermore, its operation process fully complies with the TPM2.0 industry standard and is compatible with existing server trusted computing architectures. Therefore, this step, based on the standard security mechanism of the Trusted Platform Module, completes the trust chain extension and unforgeable digital signature of the anti-counterfeiting seed, ensuring that the verification data uploaded to the remote cloud platform is of reliable origin, complete, and tamper-proof. It also seamlessly adapts to the existing server's trusted verification system and the remote cloud platform's signature verification process, achieving full-chain security and trustworthiness in anti-counterfeiting verification.
[0049] Specifically, the baseboard management controller sends the generated composite hardware anti-counterfeiting seed to the trusted platform module on the server motherboard. The trusted platform module then performs a platform configuration register extension operation to generate the current register value. This includes: the trusted platform module calling its internal hash engine to concatenate the historical register value before extension with the composite hardware anti-counterfeiting seed and performing a SHA256 hash operation to generate the current register value (following...). specification); When the remote cloud platform initiates a remote hardware anti-counterfeiting inspection command, the trusted platform module uses its built-in non-exportable proof identity key to cite the current register value to generate a digital signature, and sends the signature result and real-time operating temperature to the remote cloud platform for anti-counterfeiting verification. After receiving the signature result and real-time operating temperature, the remote cloud platform uses the corresponding public key to verify the signature. After the signature is verified, the current register value is compared with the factory-grade anti-counterfeiting database pre-entered by the remote cloud platform, thereby completing the high-precision contactless authentication of the distributed node hardware and confirming the true physical identity of the target hardware to be verified.
[0050] like Figure 4 As shown, the 32-byte register values generated by the PCR expansion operation of genuine and counterfeit hardware show significant differences in the numerical distribution of each byte position, with no overlapping stable feature ranges. This is because the composite hardware anti-counterfeiting seed incorporates the physical characteristics of hardware that cannot be cloned. Even if the counterfeit product clones the complete firmware data, it cannot generate the same PCR register value as the genuine product, thus eliminating the risk of anti-counterfeiting deception caused by firmware cloning at the source.
[0051] like Figure 5 As shown, among the three core verification indicators of the remote cloud platform, genuine hardware can pass all signature verification, PCR matching, and feature deviation verification; while counterfeit hardware, even if it can pass signature verification through cloned firmware, cannot pass PCR matching and feature deviation verification, and can be effectively identified and intercepted by the anti-counterfeiting method of this invention, fully verifying the reliability and effectiveness of the dual anti-counterfeiting verification of software and hardware of this invention.
[0052] This invention also discloses an anti-counterfeiting identification system for server hardware, including a processor and a memory. The memory stores computer program instructions, which, when executed by the processor, implement an anti-counterfeiting identification method for server hardware according to the present invention.
[0053] The system also includes other components well known to those skilled in the art, such as communication buses and communication interfaces, the settings and functions of which are known in the art and will not be described in detail here.
[0054] The above are all preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Therefore, all equivalent changes made in accordance with the structure, shape and principle of the present invention should be covered within the scope of protection of the present invention.
Claims
1. A method for anti-counterfeiting identification of server hardware, characterized in that, include: The server motherboard sends a read command to the target hardware to be verified by the baseboard management controller and activates the built-in analog-to-digital converter to capture the power transient ripple voltage sequence on the power supply pin of the target hardware to be verified during the response to the read command at a preset discrete sampling frequency. The deviation between the power supply transient ripple voltage sequence and the factory-stored reference voltage sequence is extracted, and the transient signal distortion index is calculated. The transient signal distortion index satisfies the following: ; In the formula, The transient signal distortion index of the target hardware to be verified. The total number of sampling points. The first in the power supply transient ripple voltage sequence Voltage values obtained from each sampling point For genuine hardware, within the factory-pre-stored reference voltage sequence, the first... Voltage values obtained from each sampling point The standard rated operating voltage for the power supply pin; The real-time operating temperature of the target hardware to be verified is obtained through a digital temperature sensor. Based on the real-time operating temperature, the transient signal distortion index is compensated for to generate a thermally normalized physical characteristic. The thermally normalized physical characteristic satisfies the following: ; In the formula, The thermally normalized physical characteristics of the target hardware to be verified. The transient signal distortion index of the target hardware to be verified. This is the standard test environment reference temperature for genuine hardware during factory calibration. The target is the current real-time operating temperature of the hardware to be verified. The temperature drift compensation coefficient for the hardware model to which the target hardware to be verified belongs; The raw firmware binary data read from the target hardware to be verified is hashed to obtain a static firmware digest. Based on the noise tolerance bit width of the hardware model to which the target hardware to be verified belongs, the thermally normalized physical characteristics are converted into a fixed-length digital format and hashed and fused with the static firmware digest to construct a composite hardware anti-counterfeiting seed. The composite hardware anti-counterfeiting seed is then sent to the trusted platform module on the server motherboard. The trusted platform module performs platform configuration register extension operations to generate the current register value, and uses the built-in identity verification key to digitally sign the current register value to generate a signature result. The signature result and the real-time operating temperature are then sent to the remote cloud platform for anti-counterfeiting verification.
2. The anti-counterfeiting identification method for server hardware according to claim 1, characterized in that, The composite hardware anti-counterfeiting seed satisfies: ; In the formula, A composite hardware anti-counterfeiting seed for the target hardware to be verified. For the static firmware summary of the target hardware to be verified, The thermally normalized physical characteristics of the target hardware to be verified. For the sampling bit width of the analog-to-digital converter, The noise tolerance bit width of the target hardware model to be verified. This is a standard 256-bit secure hash algorithm operation. For bit width alignment operation, For data concatenation operations, This is a floor operation.
3. The anti-counterfeiting identification method for server hardware according to claim 1, characterized in that, The step of generating the current register value by performing platform configuration register extension operations by the trusted platform module includes: The trusted platform module calls the internal hash engine to concatenate the historical register value before expansion with the composite hardware anti-counterfeiting seed and perform hash operation to generate the current register value.
4. The anti-counterfeiting identification method for server hardware according to claim 1, characterized in that, The step of sending the signature result and real-time operating temperature to a remote cloud platform for anti-counterfeiting verification includes: After receiving the signature result and real-time operating temperature, the remote cloud platform uses the corresponding public key to verify the signature. After the signature verification is successful, the current register value is compared with the factory-level physical anti-counterfeiting database pre-established on the remote cloud platform to confirm the true physical identity of the target hardware to be verified.
5. The anti-counterfeiting identification method for server hardware according to claim 2, characterized in that, The bit width alignment operation includes: In response to a converted integer bit width being less than or equal to 256 bits, zeros are padded to the high bits to bring the total bit width to 256. When the converted integer has a bit width greater than 256 bits, the lower 256 bits of data are truncated.
6. The anti-counterfeiting identification method for server hardware according to claim 1, characterized in that, The temperature drift compensation coefficient is a fixed value determined based on batch testing of hardware of the same model at the factory.
7. The anti-counterfeiting identification method for server hardware according to claim 1, characterized in that, The total number of sampling points is calculated by multiplying the sampling duration of the analog-to-digital converter by the discrete sampling frequency.
8. A counterfeit identification system for server hardware, characterized in that, include: A processor and a memory, the memory storing computer program instructions that, when executed by the processor, implement an anti-counterfeiting identification method for server hardware according to any one of claims 1-7.