Peripheral bidirectional authentication configuration method and system based on key domain isolation

CN122268653BActive Publication Date: 2026-09-22GUANGZHOU ZONERICH COMP EQUIP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610497951.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-04-15
Publication Date
2026-09-22
Estimated Expiration
2046-04-15

AI Technical Summary

Technical Problem

[0004]其二,上述基于内网部署的AI智能体会自动记录交互缓存,可能会在软件测试更新时被侵入者利用

Benefits of technology

(1)相较于现有技术,本发明方法能够在瞬间完成键盘和配置终端的双向认证,实现跨域密钥隔离、配置锁定。在配置锁定状态下,一台配置终端仅对配置锁定的键盘作出响应,由于基于交互动态随机数生成的令牌不具有复刻性,AI键盘操作、插件操作和远程键盘无权对键盘进行输入读取或操作,使得对信息安全要求极高的单位能够放心部署本地AI智能体。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122268653B_ABST
    Figure CN122268653B_ABST
Patent Text Reader

Abstract

The application relates to the field of interactive information security technology, in particular to a peripheral bidirectional authentication configuration method and system based on key domain isolation, wherein the method responds to keyboard access to a configuration terminal, calls a system root key and a unique device serial number of the keyboard preset in a secure isolation environment, and then derives a corresponding device key based on the system root key and the unique device serial number; then, in response to the establishment of the keyboard and the configuration terminal, an interactive dynamic random number generation instruction is sent to the keyboard, and the device key and the interactive dynamic random number returned by the keyboard are input into a preset bidirectional identity authentication mechanism to generate and verify a dynamic identity authentication token; finally, in response to the verification of the dynamic identity authentication token, a key configuration rule in a ciphertext format is issued to the keyboard to trigger the keyboard bottom-layer firmware to analyze the key configuration rule and set a hardware state lock. The method can guarantee that internal interactive data is not leaked and external malicious instructions are prevented from being input.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of interactive information security technology. More specifically, this invention relates to a method and system for configuring two-way authentication for peripheral devices based on key domain isolation. Background Technology

[0002] AI agents are intelligent systems capable of autonomously perceiving their environment, making inferences and decisions, and automatically assigning strategies to decision-making modules for execution. They have been criticized for their security shortcomings. Unlike traditional AI agents, AI agents deployed on intranets offer higher security due to network isolation. To improve daily office efficiency, some organizations with extremely high information security requirements (such as government, finance, military, and public security) have already deployed intranet-based AI agents.

[0003] However, the aforementioned AI agents deployed on intranets still face the following security risks: Firstly, the aforementioned AI agents deployed on the intranet are often granted extremely high interactive operation permissions, enabling them to automatically operate the intranet-specific keyboard and automatically tamper with or delete internal data.

[0004] Secondly, the AI ​​agents deployed on the intranet mentioned above automatically record interaction caches, which may be exploited by intruders during software testing and updates.

[0005] Therefore, ensuring that internal interactive data is not leaked and preventing the input of malicious external commands in the above scenarios are the key points of current AI agent security deployment. Summary of the Invention

[0006] To address the aforementioned technical issues of ensuring the non-disclosure of internal interactive data and preventing the input of malicious external commands, this invention discloses a peripheral two-way authentication configuration method and system based on key domain isolation.

[0007] In a first aspect, the present invention discloses a peripheral two-way authentication configuration method based on key domain isolation, comprising: In response to the keyboard access configuration terminal, retrieve the pre-set system root key and the keyboard's unique device serial number in the secure isolation environment; The corresponding device key is derived based on the system root key and the unique device serial number; In response to the establishment of a connection between the keyboard and the configuration terminal, an interactive dynamic random number generation command is sent to the keyboard; Input the device key and the interactive dynamic random number returned by the keyboard into the preset two-way authentication mechanism to generate and verify the dynamic authentication token; In response to the successful verification of the dynamic identity authentication token, the key configuration rules in encrypted format are sent to the keyboard to trigger the underlying firmware of the keyboard to parse the key configuration rules and set the hardware state lock. Based on the hardware state lock, the keyboard closes the bidirectional configuration interface at the physical layer and only performs unidirectional restricted key signal upload.

[0008] Beneficial effects: At the moment the keyboard is connected to the configuration terminal, the method of this invention first retrieves the system root key and the keyboard's unique device serial number as the basis for generating the device key and interactive dynamic random number. Then, the device key and interactive dynamic random number are input into the two-way authentication mechanism to achieve real-time, unreplicable random responses, thereby improving authentication security. When the dynamic authentication token is verified, encrypted key configuration rules are sent to the keyboard to trigger the keyboard's underlying firmware to parse the key configuration rules and set the hardware state lock to close the two-way configuration interface and reject all key inputs except for the current keyboard, such as AI keyboard operations, plug-in operations, or remote keyboard inputs, thereby ensuring the security of internal interactive data and preventing external malicious command input.

[0009] Preferably, it is used to configure the terminal; inputting the device key and the interactive dynamic random number returned by the keyboard into a preset two-way authentication mechanism to generate and verify a dynamic authentication token, including: Generate a temporary session key; The device key is encrypted and encapsulated using a temporary session key to obtain encrypted verification data, which is then sent to the keyboard. Receive the interactive dynamic random number and keyboard authentication token returned by the keyboard; Based on the temporary session key and the device key, the interactive dynamic random number is subjected to compound encryption and hash digest operation to generate a terminal authentication token; Perform a consistency comparison between the terminal authentication token and the keyboard authentication token; If the consistency comparison passes, a mutual trust status with the keyboard is established.

[0010] Preferably, the device key and the interactive dynamic random number are input into a preset two-way authentication mechanism to generate and verify a dynamic authentication token, and the mechanism also includes synchronization actions on the keyboard side. Decrypt the encrypted verification data to obtain the temporary session key; It sends interactive dynamic random number generation commands to the keyboard based on the built-in hardware random number generator; Based on the temporary session key, synchronous calculations are performed on the interactive dynamic random numbers to obtain the keyboard authentication token; Return the interactive dynamic random number and keyboard authentication token to the configuration terminal.

[0011] Preferably, it is used for keyboards; based on hardware state locks, the keyboard disables the bidirectional configuration interface at the physical level, including: Real-time monitoring of hardware status lock flags; If the flag is locked, data packets with read / write commands sent through the configured endpoint will be silently discarded.

[0012] Preferably, if the flag is in a locked state, the method also includes configuring synchronization actions on the terminal side: Disable the configuration writing interface for other keyboards or remote keyboard plugins.

[0013] Preferably, the execution of unidirectional restricted key signal uploading includes: The row and column matrix circuit of the keyboard is periodically scanned to obtain the position code of the currently triggered physical key. Convert the position code to the corresponding standard key code; Query the valid key mapping table generated by parsing the key configuration rules; Determine if the standard keycode exists in the valid key mapping table; If so, encapsulate the standard key code into a protocol message and trigger an interrupt endpoint to upload it to the configuration terminal; If not, intercept and erase the standard keycode.

[0014] Preferably, before responding to the keyboard interface access, the method further includes: Enter the administrator's unique identity credentials; Check if the unique identity credential matches the pre-configured list of personnel permissions; If so, execute the steps after keyboard interface access and write the administrator's operation information to the preset audit log.

[0015] Preferably, if not, the steps after keyboard interface access are terminated, and the violation information is written to the preset audit log.

[0016] Preferably, the keyboard is a wired keyboard.

[0017] Secondly, the present invention also discloses a peripheral two-way authentication configuration system based on key domain isolation, including a processor and a memory, wherein the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the peripheral two-way authentication configuration method based on key domain isolation described in the first aspect is implemented.

[0018] The beneficial effects of this invention are as follows: (1) Compared with the prior art, the method of the present invention can complete the two-way authentication between the keyboard and the configuration terminal in an instant, and realize cross-domain key isolation and configuration locking. In the configuration locking state, a configuration terminal only responds to the configuration-locked keyboard. Since the token generated based on the interactive dynamic random number is not replicable, the AI ​​keyboard operation, plug-in operation and remote keyboard have no right to input, read or operate the keyboard, so that units with extremely high information security requirements can confidently deploy local AI agents.

[0019] (2) Compared with the prior art, the method of the present invention is safer, more reliable and can be connected to the audit system for real-time compliance operation monitoring. Attached Figure Description

[0020] The above and other objects, features, and advantages of exemplary embodiments of the present invention will become readily apparent upon reading the following detailed description with reference to the accompanying drawings. In the drawings, several embodiments of the invention are illustrated by way of example and not limitation, and like or corresponding reference numerals denote like or corresponding parts, wherein: Figure 1 This is a flowchart of the peripheral two-way authentication configuration method based on key domain isolation in Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of the peripheral two-way authentication configuration system based on key domain isolation in Embodiment 2 of the present invention. Detailed Implementation

[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0022] The specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings.

[0023] Example 1 like Figure 1 As shown, this embodiment discloses a peripheral two-way authentication configuration method based on key domain isolation, including: S10: In response to the keyboard access configuration terminal, retrieve the system root key and the keyboard's unique device serial number preset in the secure isolation environment.

[0024] In this embodiment, in an organization with extremely high information security requirements, the hardware of the aforementioned keyboard must at least meet the following basic configuration requirements: The main controller must have a 32-bit high-security MCU to support encrypted operations and code read protection; the interface must use the USB 2.0 standard HID keyboard protocol, driverless; storage must use on-chip Flash memory, external flash memory is not readable and offline copying is not supported; it must not have Bluetooth communication, Wi-Fi communication, TF card access, or USB flash drive access, and preferably be a wired keyboard with shielded cable layers. Each keyboard must be factory-programmed with a unique device serial number (SN), which cannot be modified or copied.

[0025] It should be further clarified that the aforementioned configuration terminals can be bank ATMs, government office mainframes, or secure workshop mainframes. These devices often require the input of account passwords, internal information transmission, pricing / controlling data, or evidentiary information, and therefore have extremely high security requirements. Information leakage can cause losses to individuals, businesses, and even higher levels of management. The aforementioned secure isolation environment mainly refers to intranets, local area networks, or other network application scenarios requiring confidentiality. As for the system root key, it is not written to the keyboard but exists only in the intranet configuration software encryption machine or encryption module. Root keys differ between different organizations and are independent of each other, not circulated, and incompatible.

[0026] Preferably, before step S10, the method of this embodiment also needs to perform the following: S100: Enter the administrator's unique identity credentials.

[0027] It should be noted that the aforementioned unique identification credential can be a fingerprint, voiceprint, or live facial image. Before configuring a keyboard on the terminal, a fingerprint reader, microphone, or camera must be used to obtain the aforementioned unique identification credential for record-keeping and evidence preservation to ensure compliance and information security.

[0028] S200: Query whether the unique identity credential matches the pre-configured list of personnel permissions.

[0029] It should be explained that, generally, each enterprise / unit enters personnel information into the personnel management system and configures their positions and authority. The above personnel permission list can be adaptively configured based on personnel information and authority.

[0030] S300: If so, execute the steps after keyboard interface access and write the administrator's operation information to the preset audit log.

[0031] S400: If not, stop the execution of the steps after keyboard interface access and write the violation information to the preset audit log.

[0032] Even the most secure national cryptographic algorithms are difficult to prevent leaks by internal personnel. Therefore, through the above steps S100-S400, the method of this embodiment can support the access of the audit system and realize real-time monitoring of operational compliance, thereby improving the security of the method of this embodiment.

[0033] S20: Derive the corresponding device key based on the system root key and the unique device serial number.

[0034] It should be explained that the aforementioned device key (DevKey) is mainly derived from the root key and the unique device serial number using a national cryptographic algorithm. Its specific instruction operation is as follows: DevKey=SM4_KeyDerive(RootKey,SN) The SM4_KeyDerive mentioned above refers to the Chinese national cryptographic algorithm SM4, officially released in 2012 with standard number GM / T0002-2012. It has a block size and key length of 128 bits and employs a 32-round non-linear iterative structure, providing extremely high security. SM4 exhibits a strong avalanche effect; even a single bit change in the plaintext or key will drastically alter the ciphertext. This prevents AI from deducing the key by analyzing the outputs of similar inputs, effectively cutting off the cracking path based on training and learning. Therefore, relying on this national cryptographic algorithm, a highly secure device key can be obtained. However, even a highly secure device key is difficult to prevent leakage by internal personnel. Therefore, further encryption verification is required.

[0035] S30: In response to the establishment of the keyboard and configuration terminal, send an interactive dynamic random number generation command to the keyboard.

[0036] Specifically, after receiving an interaction request from the configuration terminal, the keyboard returns a unique device serial number and, based on the instruction scheduling built-in hardware random number generator, generates a dynamic random number. This dynamic random number is a randomly generated, time-limited 16-byte encoding that is not replicable and has an extremely short validity period, effectively preventing internal personnel from leaking it through data scraping.

[0037] S40: Input the device key and the interactive dynamic random number returned by the keyboard into the preset two-way authentication mechanism to generate and verify the dynamic authentication token.

[0038] In this embodiment, the aforementioned dynamic identity authentication token includes a terminal authentication token and a keyboard authentication token. Both of these tokens are unique and are "used up and then discarded".

[0039] Specifically, for configuring the terminal itself, the above step S40 includes: S411: Generate a temporary session key.

[0040] It should be explained that the aforementioned temporary session key is a symmetric key used to encrypt communication data. It is only valid for one session and is destroyed after the session ends.

[0041] S412: Use the temporary session key to encrypt and encapsulate the device key, obtain encrypted verification data, and send it to the keyboard.

[0042] Specifically, by extracting the identifier of the temporary session key and concatenating it with the aforementioned device key, encrypted verification data is obtained. This encrypted verification data is unique and real-time. Even if internal personnel know the specific unique device key, they cannot immediately access the aforementioned encrypted verification data.

[0043] S413: Receives the interactive dynamic random number and keyboard authentication token returned by the keyboard.

[0044] S414: Based on the temporary session key and the device key, perform compound encryption and hash digest operations on the interactive dynamic random number to generate a terminal authentication token.

[0045] Specifically, the configuration software uses the root key of the corresponding system, combined with the device key derived from the keyboard serial number, and simultaneously uses the temporary session key to calculate the SM3 hash value: Hash_PC =SM3_Hash(Random_Kbd) Here, SM3_Hash represents the SM3 hash algorithm, and Random_Kbd represents interactive dynamic random numbers.

[0046] Then, the hash value is encrypted using SM4 to generate a terminal authentication token (Token_PC): Token_PC = SM4_Encrypt(DevKey, SM3_Hash(Random_Kbd)) In the formula, SM4_Encrypt represents the SM4 hash algorithm; after the calculation is completed, the encrypted terminal authentication token will also be sent to the keyboard authentication.

[0047] S415: Perform a consistency comparison between the terminal authentication token and the keyboard authentication token.

[0048] The corresponding consistency calculation procedure logic is as follows: Token_PC == Token_Kbd In the formula, Token_Kbd is the keyboard authentication token.

[0049] S416: If the consistency check passes, establish a mutual trust status with the keyboard.

[0050] After step S412 is completed, the MCU on the keyboard side executes synchronously: S421: Decrypt the encrypted verification data to obtain the temporary session key.

[0051] S422: Generates interactive dynamic random numbers based on a built-in hardware random number generator.

[0052] S423: Based on the temporary session key, perform synchronous calculations on the interactive dynamic random number to obtain the keyboard authentication token.

[0053] Specifically, the generation of keyboard authentication tokens is similar to the generation of terminal authentication tokens, and the specific algorithm is as follows: Token_Kbd= SM4_Encrypt(DevKey, SM3_Hash(Random_Kbd)) S424: Return the interactive dynamic random number and keyboard authentication token to the configuration terminal.

[0054] Through the steps S411-S416 and S421-S424 described above, two-way authentication can be completed quickly, securely, and accurately, enabling the configuration terminal to uniquely lock keyboard input. Furthermore, the data transmission process described above makes it virtually impossible to obtain useful data through external intrusion; even if such data is obtained, it will time out, resulting in a failed attempt to crack the authentication.

[0055] S50: In response to the successful verification of the dynamic identity authentication token, it sends the key configuration rules in encrypted format to the keyboard to trigger the underlying firmware of the keyboard to parse the key configuration rules and set the hardware state lock.

[0056] Based on the hardware state lock, the keyboard disables the bidirectional configuration interface at the physical level, and only performs unidirectional restricted key signal upload.

[0057] In this embodiment, the key configuration rules described above are used to limit the keys or shortcuts that are allowed to be input on the keyboard. For example, in some important systems that need to run continuously, inputting the "Alt+F4" shortcut is strictly prohibited, as this may cause the system to shut down directly, resulting in serious consequences. The key configuration rules described above can directly disable this function.

[0058] Furthermore, regarding the keyboard, based on the hardware state lock, the keyboard disables the bidirectional configuration interface at the physical level, including: Real-time monitoring of hardware status lock flags.

[0059] If the flag is locked, data packets with read / write commands sent through the configured endpoint will be silently discarded.

[0060] It should be explained that the above solution is mainly aimed at keyboard key inputs that do not conform to the key configuration rules. By locking the flag bit to silently discard certain key / shortcut key input functions, the security and reliability of the method in this embodiment are further improved.

[0061] Furthermore, if the flag is in a locked state, it also includes configuring synchronization actions on the terminal side: Disable the configuration writing interface for other keyboards or remote keyboard plugins.

[0062] The above solution primarily targets unauthorized operations by AI agents / remote operators. When AI agents or remote operators execute key input, they need to invoke smart keyboard plugins, wireless keyboards, or remote control plugins to perform the key input. By directly disabling the configuration writing interface, key input is limited to keyboard input that has passed the aforementioned two-way authentication, thus preventing malicious external command input, such as from AI agents or remote operators, from the physical layer.

[0063] Furthermore, the aforementioned one-way restricted key signal upload is specifically as follows: First, the keyboard's row and column matrix circuits are periodically scanned to obtain the position code of the currently triggered physical key. Then, the position code is converted into the corresponding standard key code. Next, the valid key mapping table generated by parsing the key configuration rules is queried. Finally, it is determined whether the standard key code exists in the valid key mapping table: if so, the standard key code is encapsulated into a protocol message and an interrupt endpoint is triggered to upload it to the configuration terminal. If not, the standard key code is intercepted and erased.

[0064] The above solution achieves a dual-layer constraint on key input based on hardware locking and software limitation. Even if the flag is reset by special means, malicious commands cannot be input, thereby further improving the security of the method in this embodiment.

[0065] Unlike existing technologies, the method in this embodiment has at least the following advantages: (1) In scenarios where AI agents are deployed locally, it is possible to ensure that internal interactive data is not leaked and to prevent the input of malicious external commands.

[0066] (2) The software or system developed based on the method of the present invention has stronger security and reliability and can be connected to the intranet security audit system.

[0067] (3) It is particularly suitable for environments with high requirements for information confidentiality, such as when an office host carrying evidentiary data is taken to court to testify, there is almost no need to worry about external malicious intrusion and tampering.

[0068] (4) Before the formal entry into the quantum computing era, the two-way authentication mechanism of the method in this embodiment cannot be cracked and is extremely secure.

[0069] Example 2 like Figure 2 As shown, this embodiment discloses a peripheral two-way authentication configuration system based on key domain isolation, including a processor and a memory. The memory stores computer program instructions, and when the computer program instructions are executed by the processor, the peripheral two-way authentication configuration method based on key domain isolation described in Embodiment 1 is implemented.

[0070] The system in this embodiment also includes other components well known to those skilled in the art, such as communication interfaces. Their settings and functions are known in the art, and therefore will not be described in detail here.

[0071] In this invention, the aforementioned memory can be any tangible medium containing or storing a program that can be used or combined with an instruction execution system, apparatus, or device. For example, a computer-readable storage medium can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc., or any other medium that can be used to store desired information and can be accessed by an application, module, or both. Any such computer storage medium can be part of a device or accessible to or connected to a device. Any application or module described in this invention can be implemented using computer-readable / executable instructions that can be stored or otherwise maintained by such a computer-readable medium.

[0072] In the description of this specification, "multiple" means at least two, such as two, three or more, etc., unless otherwise expressly and specifically defined.

[0073] While this specification has shown and described numerous embodiments of the invention, it will be apparent to those skilled in the art that such embodiments are provided by way of example only. Many modifications, alterations, and alternatives will occur to those skilled in the art without departing from the spirit and essence of the invention. It should be understood that various alternatives to the embodiments of the invention described herein may be employed in the practice of this invention.

Claims

1. A peripheral two-way authentication configuration method based on key domain isolation, characterized in that, include: In response to the keyboard access configuration terminal, the system root key and the unique device serial number of the keyboard, which are preset in the secure isolation environment, are retrieved. The corresponding device key is derived based on the system root key and the unique device serial number; In response to the establishment of the connection between the keyboard and the configuration terminal, an interactive dynamic random number generation command is sent to the keyboard; The device key and the interactive dynamic random number returned by the keyboard are input into a preset two-way authentication mechanism to generate and verify a dynamic authentication token. In response to the successful verification of the dynamic identity authentication token, a key configuration rule in encrypted format is sent to the keyboard to trigger the keyboard's underlying firmware to parse the key configuration rule and set a hardware state lock; wherein, based on the hardware state lock, the keyboard closes the bidirectional configuration interface at the physical layer and only performs unidirectional restricted key signal upload.

2. The peripheral two-way authentication configuration method based on key domain isolation according to claim 1, characterized in that, For use in the configuration terminal; The device key and the interactive dynamic random number returned by the keyboard are input into a preset two-way authentication mechanism to generate and verify a dynamic authentication token, including: Generate a temporary session key; The device key is encrypted and encapsulated using the temporary session key to obtain encrypted verification data, which is then sent to the keyboard. Receive the interactive dynamic random number and keyboard authentication token returned by the keyboard; Based on the temporary session key and the device key, the interactive dynamic random number is subjected to compound encryption and hash digest operation to generate a terminal authentication token; Perform a consistency comparison between the terminal authentication token and the keyboard authentication token; If the consistency comparison passes, a mutual trust state with the keyboard is established.

3. The peripheral two-way authentication configuration method based on key domain isolation according to claim 2, characterized in that, The device key and the interactive dynamic random number returned by the keyboard are input into a preset two-way authentication mechanism to generate and verify a dynamic authentication token. The mechanism also includes synchronization actions on the keyboard side. The encrypted verification data is decrypted to obtain the temporary session key; The interactive dynamic random number is generated based on the built-in hardware random number generator; Based on the temporary session key, the interactive dynamic random number is synchronously calculated to obtain the keyboard authentication token; The interactive dynamic random number and the keyboard authentication token are returned to the configuration terminal.

4. The peripheral two-way authentication configuration method based on key domain isolation according to claim 1, characterized in that, For the keyboard; Based on the aforementioned hardware state lock, the keyboard disables the bidirectional configuration interface at the physical layer, including: Real-time detection of the flag bits of the hardware state lock; If the flag is in a locked state, data packets with read / write commands issued through the configured endpoint will be silently discarded.

5. The peripheral two-way authentication configuration method based on key domain isolation according to claim 4, characterized in that, If the flag is in a locked state, the system also includes configuring synchronization actions on the terminal side: Disable the configuration writing interface for other keyboards or remote keyboard plugins.

6. The peripheral two-way authentication configuration method based on key domain isolation according to claim 1, characterized in that, Perform one-way restricted key signal upload, including: The row and column matrix circuit of the keyboard is periodically scanned to obtain the position code of the currently triggered physical key; Convert the position code into the corresponding standard key code; Query the valid key mapping table generated by parsing the key configuration rules; Determine whether the standard key code exists in the valid key mapping table; If so, the standard key code is encapsulated into a protocol message and an interrupt endpoint is triggered to upload it to the configuration terminal; If not, intercept and erase the standard keycode.

7. The peripheral two-way authentication configuration method based on key domain isolation according to claim 1, characterized in that, Prior to the interface access in response to the keyboard, the method further includes: Enter the administrator's unique identity credentials; Query whether the unique identity credential matches a pre-configured list of personnel permissions; If so, execute the steps after keyboard interface access and write the administrator's operation information to the preset audit log.

8. The peripheral two-way authentication configuration method based on key domain isolation according to claim 7, characterized in that, If not, stop the steps after keyboard interface access and write the violation information to the preset audit log.

9. The peripheral two-way authentication configuration method based on key domain isolation according to claim 1, characterized in that, The keyboard is a wired keyboard.

10. A peripheral two-way authentication configuration system based on key domain isolation, characterized in that, It includes a processor and a memory, wherein the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the peripheral two-way authentication configuration method based on key domain isolation as described in any one of claims 1-9 is implemented.

Citation Information

Patent Citations

  • Method for realizing mutual authentication of self-service terminal and pin pad

    CN102521546A

  • Safe switch and isolation system and method of keyboard, mouse and screen suitable for dual-computer environment

    CN106445182A