A device authentication method
Patent Information
- Application Number
- CN202510378080.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2026-09-29
AI Technical Summary
[0027]本申请实施例的有益效果之一在于:通过使I/O单元根据PLC发送的验证请求消息向PLC发送验证响应消息,PLC根据第一验证响应消息确定I/O单元是否通过认证,由此,能够对I/O单元进行认证,提高PLC和I/O单元之间的通信协议的安全性。
Smart Images

Figure CN122837337A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this application relate to the field of industrial control. Background Technology
[0002] In the field of industrial automation, programmable logic controllers (PLCs) play a crucial role as core control devices. PLCs typically work in conjunction with numerous extended I / O units to achieve precise control and monitoring of industrial production processes. The I / O units are responsible for acquiring input signals from the field, such as sensor data, and outputting control commands to actuators, such as motors and valves.
[0003] In the existing communication between PLCs and I / O units, there are various communication protocols, such as Modbus, PROFIBUS, and DeviceNet. When an I / O unit is connected to a PLC system, if it conforms to a pre-set communication protocol, the I / O unit can be connected to the PLC.
[0004] It should be noted that the above introduction to the technical background is only for the purpose of providing a clear and complete explanation of the technical solutions of this application and for the convenience of those skilled in the art to understand them. It should not be assumed that the above technical solutions are known to those skilled in the art simply because these solutions have been described in the background section of this application. Summary of the Invention
[0005] The inventors of this application have discovered that in existing PLC-I / O unit communication, if the communication protocol between the I / O unit and the PLC has been cracked, due to the lack of an authentication mechanism, an unauthorized I / O unit may impersonate a legitimate device to access the PLC and send false input signals to the PLC. This not only interferes with the normal production process but may also threaten the safety of production equipment and personnel. Furthermore, even if an I / O unit is legitimately connected to the PLC, it may malfunction or be maliciously attacked during long-term operation, making it impossible to guarantee the identity of the I / O unit and the authenticity of its data.
[0006] To address at least one or more of the aforementioned technical problems, embodiments of this application provide a device authentication method. This method involves an I / O unit sending a verification response message to a PLC based on a verification request message. The PLC then determines whether the I / O unit has passed authentication based on the first verification response message. This enables the authentication of the I / O unit and improves the security of the communication protocol between the PLC and the I / O unit.
[0007] According to an embodiment of the first aspect of this application, a device authentication method is provided, applied to a programmable logic controller (PLC), the method including a first authentication process, the first authentication process including:
[0008] The PLC sends a first verification request message to the I / O unit;
[0009] The PLC receives a first verification response message sent by the I / O unit. The first verification response message is generated based on the key pre-stored by the I / O unit and the first verification request message.
[0010] The PLC determines whether the I / O unit has passed the first authentication based on the first verification response message.
[0011] In at least one embodiment, the method further includes a second authentication process, the second authentication process comprising:
[0012] The PLC sends a second verification request to the I / O unit;
[0013] The PLC receives a second verification response message sent by the I / O unit, the second verification response message including plaintext copyright statement information;
[0014] The PLC determines whether the I / O unit has passed the second authentication based on the second verification response message.
[0015] In at least one embodiment, the PLC executes the first authentication process; when the I / O unit passes the first authentication, the PLC executes the second authentication process, or
[0016] The PLC executes the second authentication process, and when the I / O unit passes the second authentication, the PLC executes the first authentication process.
[0017] In at least one embodiment, the PLC and the I / O unit are connected via a connector and communicate via a bus;
[0018] Once the I / O unit passes the first authentication, the PLC connects to the I / O unit via the bus.
[0019] In at least one embodiment, after the PLC completes the first authentication of the I / O unit, it sends a first verification request message to the I / O unit at preset time intervals to repeat the first authentication process.
[0020] In at least one embodiment, the first authentication process is implemented based on an asymmetric encryption algorithm.
[0021] In at least one embodiment, the first verification request message includes random information and the ID information of the I / O unit.
[0022] In at least one embodiment, the second verification request information includes a copyright information sending request and the ID information of the I / O unit.
[0023] In at least one embodiment, the random information is a random number generated by the PLC, and the I / O unit uses a key to calculate the random number to obtain a first verification response message.
[0024] According to an embodiment of the second aspect of this application, a device authentication method is provided, applied to an I / O unit, the method comprising:
[0025] The I / O unit receives the first verification request message sent by the PLC;
[0026] The I / O unit generates a first verification response message based on the first verification request message and the pre-stored key, and sends the first verification response message to the PLC.
[0027] One of the beneficial effects of this application embodiment is that: by enabling the I / O unit to send a verification response message to the PLC according to the verification request message sent by the PLC, the PLC determines whether the I / O unit has passed authentication based on the first verification response message. Thus, the I / O unit can be authenticated, improving the security of the communication protocol between the PLC and the I / O unit.
[0028] Referring to the following description and accompanying drawings, specific implementation methods of the embodiments of this application are disclosed in detail, indicating how the principles of the embodiments of this application can be adopted. It should be understood that the implementation methods of this application are not limited in scope. Within the spirit and scope of the appended claims, the implementation methods of this application include many changes, modifications, and equivalents. Attached Figure Description
[0029] The accompanying drawings, which form part of the specification, are used to provide a further understanding of the embodiments of this application and illustrate the implementation methods of this application, together with the textual description, to explain the principles of this application. Obviously, the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other implementation methods based on these drawings without creative effort. In the drawings:
[0030] Figure 1 This is a schematic diagram of a device authentication method according to an embodiment of this application;
[0031] Figure 2This is a schematic diagram of the PLC and I / O unit according to an embodiment of this application;
[0032] Figure 3 This is a schematic diagram of the first authentication process flow according to an embodiment of this application;
[0033] Figure 4 This is a schematic diagram of the second authentication process flow according to an embodiment of this application;
[0034] Figure 5 This is a flowchart illustrating a device authentication method according to an embodiment of this application;
[0035] Figure 6 This is a schematic diagram of a device authentication method according to an embodiment of this application;
[0036] Figure 7 This is a schematic diagram of a device authentication apparatus according to an embodiment of this application;
[0037] Figure 8 This is a schematic diagram of a device authentication apparatus according to an embodiment of this application;
[0038] Figure 9 This is a schematic diagram of an electronic device according to an embodiment of this application. Detailed Implementation
[0039] Referring to the accompanying drawings, the foregoing and other features of the embodiments of this application will become apparent from the following description. Specific embodiments of this application are specifically disclosed in the description and drawings, illustrating partial implementations in which the principles of the embodiments of this application can be adopted. It should be understood that this application is not limited to the described embodiments; rather, the embodiments of this application include all modifications, variations, and equivalents falling within the scope of the appended claims.
[0040] In the embodiments of this application, the terms "first," "second," etc., are used to distinguish different elements by name, but do not indicate the spatial arrangement or chronological order of these elements, and these elements should not be limited by these terms. The term "and / or" includes any one or more of the terms listed in association and all combinations thereof. The terms "comprising," "including," "having," etc., refer to the presence of the stated features, elements, components, or assemblies, but do not exclude the presence or addition of one or more other features, elements, components, or assemblies.
[0041] In the embodiments of this application, the singular forms "a," "the," etc., including the plural forms, should be broadly understood as "a kind" or "a class" rather than limited to the meaning of "an." Furthermore, the term "the" should be understood to include both the singular and plural forms, unless the context explicitly indicates otherwise. Additionally, the term "according to" should be understood as "at least partially based on…," and the term "based on" should be understood as "at least partially based on…," unless the context explicitly indicates otherwise.
[0042] Features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, combined with features in other embodiments, or substituted for features in other embodiments. The term "comprising / including" as used herein means the presence of a feature, integral, step, or component, but does not exclude the presence or addition of one or more other features, integrals, steps, or components.
[0043] First aspect of the embodiments
[0044] This application provides a device authentication method.
[0045] Figure 1 This is a schematic diagram of a device authentication method according to an embodiment of this application, applied to a programmable logic controller (PLC). The method includes a first authentication process, such as... Figure 1 As shown, the first authentication process includes:
[0046] 101. The PLC sends a first verification request message to the I / O unit;
[0047] 102. The PLC receives a first verification response message sent by the I / O unit, the first verification response message being generated based on the key pre-stored by the I / O unit and the first verification request message;
[0048] 103. The PLC determines whether the I / O unit has passed the first authentication based on the first verification response message.
[0049] It is worth noting that the above appendix Figure 1 The embodiments of this application have only been illustrated schematically, and the application is not limited thereto. For example, other operations may be added or some operations may be removed. Those skilled in the art can make appropriate modifications based on the above description, and are not limited to the above-described embodiments. Figure 1 The records.
[0050] According to the embodiments of this application, by having the I / O unit send a verification response message to the PLC based on the verification request message sent by the PLC, the PLC determines whether the I / O unit has passed authentication based on the first verification response message. Thus, the I / O unit can be authenticated, improving the security of the communication protocol between the PLC and the I / O unit.
[0051] In some embodiments, a PLC is an automated control device that can perform logical operations on various input signals and control output signals based on the operation results. Alternatively, a PLC can communicate with other devices to achieve data exchange and remote monitoring. Or, a PLC can process, analyze, and perform operations on collected data and make corresponding control decisions based on the results. An I / O unit, as the interface between the PLC and external devices, is responsible for signal transmission and conversion between the PLC and external devices. An I / O unit can receive various signals from external devices, such as status signals from buttons, switches, and sensors, and convert and transmit them to the PLC for processing. An I / O unit can also output the processed results from the PLC and convert them into signals to drive external devices. For example, an I / O unit can output the processed results from the PLC and convert them into signals to control relays, indicator lights, or motors. Alternatively, the PLC and I / O unit can also perform other functions, as detailed in relevant technologies. This application does not limit these functions.
[0052] Figure 2 This is a schematic diagram of the PLC and I / O unit according to an embodiment of this application.
[0053] In the embodiments of this application, using Figure 2 For example, a PLC can connect to and communicate with multiple I / O units. For instance, a card slot is provided on one side of PLC 201, and I / O unit 202 can be inserted into the slot and connected to PLC 201 via a connector. After multiple I / O units 202(a), 202(b), and 202(c) are connected to the PLC, they can communicate via a bus connection. That is, multiple I / O units and the PLC communicate through a shared bus. Common bus protocols include Modbus, Profibus, CANopen, or proprietary communication protocols. After the PLC and I / O units are connected to the bus unit, the PLC and I / O units authenticate the communication protocol. If the communication protocol is compatible, the PLC registers the I / O unit in its device management table, thus enabling the I / O unit to interact with the PLC. For bus communication between multiple I / O units and the PLC, it can be serial communication or parallel communication. In the following description, serial bus communication is used as an example to illustrate the embodiments of this application, but this application is not limited to this. The connection and communication between the PLC and the I / O units can also be in other ways, such as parallel bus communication and serial communication.
[0054] In some embodiments, the first authentication process can be implemented based on an asymmetric encryption algorithm. The PLC and I / O unit each pre-store agreed-upon keys, which can be public and / or private keys, depending on their intended use; this application does not limit this. Therefore, authentication of the I / O unit can be performed without deploying an additional server, saving system costs. Using an asymmetric encryption algorithm for the first authentication process significantly increases the difficulty of replicating the communication protocol between the PLC and I / O unit, improving communication security. This asymmetric encryption algorithm can be implemented based on a hash algorithm; this application does not limit this either.
[0055] The first authentication process of this application embodiment is illustrated below.
[0056] In step 101, the PLC sends a first verification request message to the I / O unit. This first verification request message may include random information and the I / O unit's ID information. The PLC can send the random information to the corresponding I / O unit based on the I / O unit's ID information and receive the response message sent by the corresponding I / O unit. The PLC can send the first verification request message to the I / O unit at some point before establishing bus communication with it. For example, it can automatically trigger the sending of the first verification request message to the I / O unit some time after the PLC system starts up.
[0057] In some embodiments, the PLC may generate the random information first. For example, the PLC may generate the random information based on software or hardware. The random information may be a random number generated by software, or a random number generated based on the PLC's analog signal, such as a white noise signal collected from the data. The embodiments of this application are not intended to limit the scope of the invention.
[0058] In step 102, the PLC receives a first verification response message (also called a digest) sent by the I / O unit. This first verification response message is generated by the I / O unit based on a pre-stored key and a first verification request message. That is, in some embodiments, the I / O unit can use a pre-stored public key and / or private key to calculate the random information to obtain the first verification response message. The calculation of the first verification response message can be performed using the public key and / or private key and random information based on a hash algorithm. For example, the random information and key can be combined into a new data block according to a specific order or other combination rules, and the new data block can be processed using a selected hash algorithm to obtain a digest with a fixed length. The selected hash algorithm can be M5, SHA-1, SHA-256, etc., and specific details can be found in related technologies. Alternatively, other asymmetric encryption algorithms can be used to calculate the digest, but this application does not limit this to any particular algorithm.
[0059] In step 103, the PLC determines whether the I / O unit has passed the first authentication based on the first verification response message sent by the I / O unit, and verifies the legality of the digest. That is, the PLC can also use the random information contained in the first verification request message, calculate the random information using the same key pre-stored in the PLC, and compare the calculated result with the first verification response message. If the result is the same as the first verification response message, the I / O unit passes the first authentication; otherwise, the I / O unit fails the first authentication.
[0060] Figure 3 This is a schematic diagram of the first authentication process flow according to an embodiment of this application. Figure 3 As shown, taking the example where the PLC and I / O unit each pre-store an agreed-upon private key, the first authentication process includes the following steps:
[0061] 301, PLC generates random numbers;
[0062] 302, The PLC sends a random number to the I / O unit;
[0063] 303, The I / O unit receives the random number and uses its internal private key to calculate the second digest of the random number;
[0064] 304, The I / O unit sends a second summary to the PLC;
[0065] 305. The PLC uses its internal private key to calculate the first digest of the random number, confirms the validity of the second digest, and determines whether the I / O unit has passed the first authentication.
[0066] The implementation methods of 301 to 305 above can refer to the foregoing embodiments, and the repeated parts will not be described again.
[0067] In step 305, the PLC determines the legality of the received second digest by comparing the data. That is, the PLC compares the second digest calculated by the I / O unit using its private key with the first digest calculated by the PLC using its private key. If the first digest and the second digest are the same, the digest is legal and the I / O unit passes the first authentication.
[0068] The above first authentication process is merely an example and is not intended to limit the scope of this application.
[0069] In some embodiments, after the I / O unit passes the first authentication, the PLC connects to the I / O unit via the bus. That is, the first authentication process is performed before the I / O unit connects to the PLC. This ensures the communication security between the PLC and the I / O unit during the initialization process and prevents unauthorized I / O units from joining the system during the initialization of the PLC and I / O units, which could lead to unstable communication between the PLC and the I / O units.
[0070] In some embodiments, after the PLC completes the first authentication of the I / O unit, it can send a first verification request message to the I / O unit at preset time intervals to repeat the first authentication process. That is, after the I / O unit completes the first authentication process before access, the first authentication process can also be performed after the I / O unit is accessed. For example, during data interaction, the PLC can send random information to the I / O unit at regular intervals to authenticate the I / O unit. This can improve the communication security between the PLC and the I / O unit during data interaction and prevent unauthorized I / O units from joining the system and disrupting the data interaction between the PLC and the I / O unit.
[0071] In this embodiment of the application, based on the first authentication process, when performing device authentication, the method may further include a second authentication process to verify copyright information. The second authentication process will be described below.
[0072] Figure 4 This is a schematic diagram of the second authentication process flow according to an embodiment of this application. Figure 4 As shown, the second certification process includes the following steps:
[0073] 401, The PLC sends a second verification request message to the I / O unit;
[0074] 402, The PLC receives a second verification response message sent by the I / O unit. The second verification response information includes a plaintext copyright statement message.
[0075] 403. The PLC determines whether the I / O unit has passed the second authentication based on the second verification response message.
[0076] In some embodiments, the second verification request information includes a copyright information sending request and the ID information of the I / O unit. The PLC can send the copyright sending request to the corresponding I / O unit according to the ID information of the I / O unit, and receive the second verification response information sent by the corresponding I / O unit.
[0077] In the above embodiment, after receiving the second verification request information requesting the sending of a plaintext copyright statement, the I / O unit generates a second verification response information including the plaintext copyright statement information. This plaintext copyright statement information is pre-agreed upon, and may include, for example, the copyright owner, version information, or development date. After receiving the plaintext copyright statement information, the PLC verifies it. If the verification is successful, the I / O unit is determined to have passed the second authentication. If the plaintext copyright statement information is incorrect, or if the I / O unit does not send the plaintext copyright statement information, the I / O unit fails the second authentication, and the I / O unit is determined to be an illegal device.
[0078] In the above embodiments, by authenticating the plaintext copyright statement of the I / O unit, the security of the communication protocol between the I / O unit and the PLC can be further improved, and evidence of rights protection can be obtained by sending the plaintext copyright owner's statement, which facilitates rights protection operations when the communication protocol is violated.
[0079] In the embodiments of this application, the device authentication method for PLC and I / O unit can be used to authenticate the I / O unit through the first authentication as described above, or the first authentication and the second authentication can be combined to authenticate the I / O unit.
[0080] The following describes the device certification method of this application when the first and second certifications are combined to certify the I / O unit.
[0081] In some embodiments, the I / O unit performs a first authentication process, and when the I / O unit passes the first authentication, the PLC performs a second authentication process; or, the I / O unit performs a second authentication process, and when the I / O unit passes the second authentication, the PLC performs the first authentication process.
[0082] In other words, the order of the first and second authentication processes can be interchanged when authenticating I / O units. However, the PLC cannot perform both authentications simultaneously on an I / O unit. When the PLC performs the first authentication and then the second authentication on an I / O unit, if the I / O unit passes the first authentication, the second authentication process is then performed. If the second authentication passes, the I / O unit is authenticated and connected to the PLC. However, if the first authentication fails, the PLC directly determines that the I / O unit has failed authentication, and the second authentication process is unnecessary. Alternatively, the second authentication process can be performed to obtain the copyright information of the I / O unit for subsequent rights protection. Similarly, when the PLC performs the second authentication and then the first authentication on an I / O unit, if the I / O unit passes the second authentication, the first authentication process is then performed. If the first authentication passes, the I / O unit is authenticated. However, if the second authentication fails, the PLC directly determines that the I / O unit has failed authentication, and the first authentication process is unnecessary.
[0083] In some examples, when the first or second authentication fails, the PLC can also store the error data, such as the copyright notice information of the I / O unit, in a database to facilitate the provision of subsequent rights protection information.
[0084] The following describes the device certification method of this application, taking the example of performing the second certification process first and then the first certification process.
[0085] Figure 5 This is a flowchart illustrating a device authentication method according to an embodiment of this application. Figure 5 As shown, the device certification process includes:
[0086] 501, The PLC sends a second verification request message to the I / O unit, which includes a device copyright request;
[0087] 502, The I / O unit sends a second verification response message to the PLC, including copyright notice information;
[0088] 503. The PLC determines whether the I / O unit has passed plaintext verification based on the copyright notice information.
[0089] 504, the PLC sends a first verification request message, including a random number, to the I / O unit;
[0090] 505, The I / O unit uses the key to calculate a digest of the random number;
[0091] 506, The I / O unit sends a first verification response message, including a summary, to the PLC;
[0092] 507. The PLC determines whether the I / O unit has passed key verification based on the digest.
[0093] like Figure 5 As shown, steps 501-503 constitute the second authentication process (plaintext verification), and steps 504-507 constitute the first authentication process (key verification). When the I / O unit passes both plaintext verification and key verification, the I / O unit is authenticated by the device. Specifically, in step 503, it is determined whether the I / O unit has passed plaintext verification. If the I / O unit passes plaintext verification, key verification is performed, i.e., steps 504-507 are executed. If the I / O unit fails plaintext verification, the process ends, and the I / O unit has not been authenticated by the device. In step 507, it is determined whether the I / O unit has passed key verification. If the I / O unit passes key verification, the I / O unit is authenticated by the device. If the I / O unit fails key verification, the process ends, and the I / O unit has not been authenticated by the device.
[0094] also, Figure 5 The device authentication method shown is the device authentication performed by the PLC during the initialization phase, that is, Figure 5 The first certification shown is the first certification performed by the PLC on the I / O unit.
[0095] The implementation methods of 501 to 507 described above can refer to the foregoing embodiments, and the repeated parts will not be described again. In the above embodiments, combining the first authentication and the second authentication can further improve the security of the communication protocol between the PLC and the I / O unit.
[0096] In the above embodiments, the illustration of this application takes only one PLC authenticating one I / O unit as an example. This application is not limited to this. Figure 2 As shown, a PLC can also perform the authentication process described above on multiple I / O units in sequence. That is, a PLC will only authenticate the next I / O unit after authenticating the previous one. This can ensure the security of the communication protocol between the PLC and multiple I / O units.
[0097] According to the above embodiments, the I / O unit sends a verification response message to the PLC based on the verification request message sent by the PLC. The PLC determines whether the I / O unit has passed authentication based on the first verification response message. Thus, the I / O unit can be authenticated, improving the security of the communication protocol between the PLC and the I / O unit.
[0098] The above description only covers the steps or processes relevant to this application, but this application is not limited thereto. The method may also include other steps or processes; for details of these steps or processes, please refer to the prior art.
[0099] The above embodiments are merely illustrative examples of embodiments of this application, but this application is not limited thereto, and appropriate modifications can be made based on the above embodiments. For example, the above embodiments can be used alone, or one or more of the above embodiments can be combined.
[0100] Second aspect of the embodiments
[0101] The second aspect of the embodiment relates to a device authentication method, which corresponds to the device authentication method of the first aspect.
[0102] Figure 6 This is a schematic diagram of a device authentication method according to an embodiment of this application. Figure 6 As shown, the method includes:
[0103] 601, the I / O unit receives the first verification request message sent by the PLC;
[0104] 602, the I / O unit generates a first verification response message based on the first verification request message and the pre-stored key, and sends the first verification response message to the PLC.
[0105] For a description of the first verification request message, the first verification response message, etc., please refer to the embodiments of the first aspect.
[0106] For a description of steps 601 to 602 above, please refer to the embodiment of the first aspect, which will not be repeated here.
[0107] The above description only covers the steps or processes relevant to this application, but this application is not limited thereto. The method may also include other steps or processes; for details of these steps or processes, please refer to the prior art.
[0108] The above embodiments are merely illustrative examples of embodiments of this application, but this application is not limited thereto, and appropriate modifications can be made based on the above embodiments. For example, the above embodiments can be used alone, or one or more of the above embodiments can be combined.
[0109] Third aspect of the embodiments
[0110] This application provides a device authentication apparatus configured in a PLC. Since the principle of this apparatus in solving the problem is similar to that of the method in the first aspect embodiment, its specific implementation can refer to the implementation of the method in the first aspect embodiment, and the contents that are the same will not be repeated.
[0111] Figure 7 This is a schematic diagram of a device authentication apparatus according to an embodiment of this application. Figure 7As shown, the device authentication apparatus 700 of this application embodiment is used to perform a first authentication process, including:
[0112] The sending unit 701 sends a first verification request message to the I / O unit;
[0113] The receiving unit 702 receives a first verification response message sent by the I / O unit, the first verification response message being generated based on the key pre-stored by the I / O unit and the first verification request message;
[0114] The determining unit 703 determines whether the I / O unit has passed the first authentication based on the first verification response message.
[0115] In some embodiments, the device authentication apparatus 700 is further configured to perform a second authentication process, the second authentication process including:
[0116] Sending unit 701 sends a second verification request to the I / O unit;
[0117] The receiving unit 702 receives a second verification response message sent by the I / O unit, the second verification response message including plaintext copyright statement information;
[0118] The determining unit 703 determines whether the I / O unit has passed the second authentication based on the second verification response message.
[0119] In some embodiments, the I / O unit executes the first authentication process; when the I / O unit passes the first authentication, the PLC executes the second authentication process, or
[0120] The I / O unit executes the second authentication process, and when the I / O unit passes the second authentication, the PLC executes the first authentication process.
[0121] In some embodiments, the PLC and the I / O unit are connected via a connector and communicate via a bus.
[0122] Once the I / O unit passes the first authentication, the PLC connects to the I / O unit via the bus.
[0123] In some embodiments, after the PLC completes the first authentication of the I / O unit, the sending unit 601 sends a first verification request message to the I / O unit at preset time intervals to repeat the first authentication process.
[0124] In some embodiments, the first authentication process is implemented based on an asymmetric encryption algorithm.
[0125] In some embodiments, the first verification request message includes random information and the ID information of the I / O unit.
[0126] In some embodiments, the second verification request information includes a copyright information sending request and the ID information of the I / O unit.
[0127] In some embodiments, the apparatus further includes a processing unit 704 that generates a random number as the random information, and the I / O unit uses a key to calculate the random number to obtain a first verification response message.
[0128] This application also provides a device authentication apparatus. Since the principle by which this apparatus solves the problem is similar to the method in the second aspect embodiment, its specific implementation can be referred to the implementation of the methods in the first and second aspects embodiments, and the similarities will not be repeated.
[0129] Figure 8 This is a schematic diagram of a device authentication apparatus according to an embodiment of this application. Figure 8 As shown, the device authentication apparatus 800 of this application embodiment includes:
[0130] The receiving unit 801 receives the first verification request message sent by the PLC.
[0131] The processing unit 802 generates a first verification response message based on the first verification request message and the pre-stored key, and sends the first verification response message to the PLC.
[0132] It is worth noting that the above description only covers the components or modules relevant to this application, but this application is not limited thereto. The aforementioned device may also include other components or modules, and for details regarding these components or modules, please refer to related technologies.
[0133] For the sake of simplicity, Figure 7 and Figure 8 The diagram only exemplifies the connection relationships or signal flow between various components or modules; however, those skilled in the art should understand that various related technologies, such as bus connections, can be employed. The aforementioned components or modules can be implemented using hardware facilities such as processors and memory; this application does not limit the scope of the embodiments.
[0134] The above embodiments are merely illustrative examples of embodiments of this application, but this application is not limited thereto, and appropriate modifications can be made based on the above embodiments. For example, the above embodiments can be used alone, or one or more of the above embodiments can be combined.
[0135] Fourth aspect of the embodiment
[0136] This application provides an electronic device including device authentication devices 700 and 800 as described in the embodiments of the third aspect, the contents of which are incorporated herein by reference. The electronic device may be, for example, a computer, server, workstation, laptop computer, smartphone, etc.; however, this application is not limited thereto.
[0137] Figure 9 This is a schematic diagram of an electronic device according to an embodiment of this application. For example... Figure 9 As shown, the electronic device 900 may include a processor (e.g., a central processing unit, CPU) 910 and a memory 920; the memory 920 is coupled to the central processing unit 910. The memory 920 can store various types of data; it also stores an information processing program 921, and executes the program 921 under the control of the processor 910.
[0138] In some embodiments, the functions of device authentication devices 700 and 800 are integrated into processor 910. Processor 910 is configured to implement the device authentication method as described in the embodiments of the first and second aspects.
[0139] In some embodiments, the device authentication devices 700 and 800 are configured separately from the processor 910. For example, the device authentication devices 700 and 800 can be configured as chips connected to the processor 910, and the functions of the device authentication devices 700 and 800 can be implemented through the control of the processor 910.
[0140] In addition, such as Figure 9 As shown, the electronic device 900 may also include: an input / output (I / O) device 930 and a display 940, etc.; the functions of the above components are similar to those in the prior art, and will not be described in detail here. It is worth noting that the electronic device 900 is not necessarily required to include... Figure 9 All components shown; in addition, the electronic device 900 may also include Figure 9 For components not shown, please refer to relevant technologies.
[0141] This application also provides a computer-readable program, wherein when executed in an electronic device, the program causes the computer in the electronic device to perform the device authentication method as described in the embodiments of the first and second aspects.
[0142] This application also provides a storage medium storing a computer-readable program, wherein the computer-readable program causes a computer in an electronic device to perform the device authentication method as described in the embodiments of the first and second aspects.
[0143] This application also provides a computer program product that enables a computer to perform the device authentication method as described in the embodiments of the first and second aspects in an electronic device.
[0144] The apparatus and methods described above in this application can be implemented in hardware or in combination with software. This application relates to a computer-readable program that, when executed by a logic component, enables the logic component to implement the apparatus or components described above, or to implement the various methods or steps described above. This application also relates to storage media for storing the above programs, such as hard disks, magnetic disks, optical disks, DVDs, flash memory, etc.
[0145] The methods / apparatus described in conjunction with the embodiments of this application can be directly embodied in hardware, software modules executed by a processor, or a combination of both. For example, one or more and / or combinations of one or more functional block diagrams shown in the figures can correspond to various software modules in a computer program flow, or to various hardware modules. These software modules can correspond to the various steps shown in the figures, respectively. These hardware modules can be implemented, for example, using a field-programmable gate array (FPGA) to embed these software modules.
[0146] The software module can reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art. A storage medium can be coupled to the processor, enabling the processor to read information from and write information to the storage medium; or the storage medium can be an integral part of the processor. The processor and storage medium can reside in an ASIC. The software module can be stored in the memory of a mobile terminal or in a memory card that can be inserted into the mobile terminal. For example, if the device (such as a mobile terminal) uses a high-capacity MEGA-SIM card or a high-capacity flash memory device, the software module can be stored in the MEGA-SIM card or the high-capacity flash memory device.
[0147] One or more and / or one or more combinations of functional blocks described in the accompanying drawings can be implemented as a general-purpose processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, or any suitable combination thereof for performing the functions described herein. One or more and / or one or more combinations of functional blocks described in the accompanying drawings can also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in communication with a DSP, or any other such configuration.
[0148] The present application has been described above with reference to specific embodiments. However, those skilled in the art should understand that these descriptions are exemplary and not intended to limit the scope of protection of the present application. Those skilled in the art can make various modifications and variations to the present application based on the principles thereof, and these modifications and variations are also within the scope of the present application.
Claims
1. A device authentication method applied to a programmable logic controller (PLC), the method comprising a first authentication process, the first authentication process comprising: The PLC sends a first verification request message to the I / O unit; The PLC receives a first verification response message sent by the I / O unit. The first verification response message is generated based on the key pre-stored by the I / O unit and the first verification request message. The PLC determines whether the I / O unit has passed the first authentication based on the first verification response message.
2. The method according to claim 1, wherein, The method further includes a second authentication process, which includes: The PLC sends a second verification request to the I / O unit; The PLC receives a second verification response message sent by the I / O unit, the second verification response message including plaintext copyright statement information; The PLC determines whether the I / O unit has passed the second authentication based on the second verification response message.
3. The method according to claim 2, wherein, The PLC executes the first authentication process. When the I / O unit passes the first authentication, the PLC executes the second authentication process, or The PLC executes the second authentication process, and when the I / O unit passes the second authentication, the PLC executes the first authentication process.
4. The method according to claim 1, wherein, The PLC and the I / O unit are connected via connectors and communicate via a bus. Once the I / O unit passes the first authentication, the PLC connects to the I / O unit via the bus.
5. The method according to claim 1, wherein, After completing the first authentication of the I / O unit, the PLC sends a first verification request message to the I / O unit at preset time intervals to repeat the first authentication process.
6. The method according to claim 1, wherein, The first authentication process is implemented based on an asymmetric encryption algorithm.
7. The method according to claim 1, wherein, The first verification request message contains random information and the ID information of the I / O unit.
8. The method according to claim 2, wherein, The second verification request information includes a copyright information sending request and the ID information of the I / O unit.
9. The method according to claim 7, wherein, The random information is a random number generated by the PLC, and the I / O unit uses a key to calculate the random number to obtain the first verification response message.
10. A device authentication method applied to an I / O unit, the method comprising: The I / O unit receives the first verification request message sent by the PLC; The I / O unit generates a first verification response message based on the first verification request message and the pre-stored key, and sends the first verification response message to the PLC.