A method for identifying a computer mainboard and an interface board

CN122839366APending Publication Date: 2026-09-29XIAMEN LIANDAXING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610841171.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-11
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

这导致市场上出现大量仿制接口小板,这些仿制品可能存在信号质量差、协议不兼容、甚至安全隐患等问题,严重影响用户体验和原厂产品的市场秩序

Benefits of technology

本发明通过边带通信通道在PCIe通道启用之前完成身份认证,实现了“先认证、后使能”的安全机制,有效杜绝仿制小板的使用,且采用挑战-响应机制,每次认证使用随机挑战值,防止重放攻击,实现了电脑主板对接口小板的有效身份识别,确保正版产品的生产利益。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122839366A_ABST
    Figure CN122839366A_ABST
Patent Text Reader

Abstract

The application provides a computer mainboard and interface board identification method, comprising the following steps: S1: when the computer mainboard detects the connection of the interface board, an authentication request is sent to the interface board through a preset sideband communication channel in the M.2 interface; wherein the authentication request comprises a random challenge value, and the interface board is provided with a storage module to store an encryption key and / or a device identifier; S2: the computer mainboard receives the authentication response information returned by the interface board, which is generated by the interface board based on the encryption operation of the random challenge value stored in the storage module and / or based on the device identifier; S3: the computer mainboard verifies the validity of the received authentication response information; S4: if the verification is passed, the computer mainboard performs an enabling operation; if the verification is not passed, the computer mainboard performs a limiting operation. The application can realize the effective identity recognition of the interface board by the computer mainboard, prevent the use of counterfeit boards, and ensure the production benefits of genuine products.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer hardware interface technology, and in particular to a method for identifying computer motherboards and interface boards. Background Technology

[0002] With the trend towards thinner and lighter laptops and mini PCs, more and more external function interfaces (such as HDMI, Type-C, USB-A, etc.) are implemented through M.2 interface expansion boards (hereinafter referred to as interface boards). The interface board is pluggably connected to the motherboard through the M.2 interface and integrates functional chips such as signal conversion chips and protocol controller chips, thereby expanding external interfaces not directly provided on the motherboard itself.

[0003] However, existing M.2 interface expansion solutions lack an effective identification mechanism for the inserted interface board. Upon detecting an M.2 device, the motherboard typically activates the PCIe lane and provides power directly, without verifying the interface board's identity. This has led to a proliferation of counterfeit interface boards on the market. These counterfeits may suffer from poor signal quality, protocol incompatibility, or even security vulnerabilities, severely impacting user experience and the market order of genuine products. Summary of the Invention

[0004] The purpose of this invention is to provide a method for identifying computer motherboards and interface boards. In the M.2 interface scenario, this method enables computer motherboards to effectively identify the interface boards, prevents the use of counterfeit boards, and ensures the production interests of genuine products.

[0005] To achieve the above objectives, the solution of the present invention is as follows: A method for identifying a computer motherboard and an interface board, wherein the interface board is pluggably connected to the computer motherboard via an M.2 interface and is used to expand at least one external functional interface, the identification method comprising the following steps: S1: When the computer motherboard detects that the interface board is connected through the M.2 interface, it sends an authentication request to the interface board through the preset sideband communication channel in the M.2 interface; The authentication request includes a random challenge value. The interface board is equipped with a storage module that stores encryption keys and / or device identifiers. S2: The computer motherboard receives the authentication response information returned by the interface board. The authentication response information is generated by the interface board after encrypting the random challenge value based on the encryption key stored in the storage module, and / or, based on the device identifier. S3: The computer motherboard verifies the validity of the received authentication response information; S4: If the verification is successful, the computer motherboard will perform an enable operation to provide the system resources required for normal operation to the interface board. The enable operation includes: powering the interface board through the power pins of the M.2 interface and enabling data transmission between the interface board and the PCIe channel of the M.2 interface. If the verification fails, the computer motherboard will perform restriction operations, including: prohibiting power supply to the interface board through the power pins of the M.2 interface, and / or disabling the PCIe lanes through the M.2 interface.

[0006] In a preferred embodiment, in step S1, the preset sideband communication channel is a communication link established by multiplexing the I2C bus, SMBus bus, or GPIO pins defined in the M.2 interface specification.

[0007] In a preferred embodiment, step S3, verifying the validity of the received authentication response information, includes any of the following methods: The authentication response information is compared with the valid response information pre-stored in the computer motherboard; Alternatively, a public or shared key matching the encryption key pre-installed in the interface board can be used to decrypt and verify the authentication response information.

[0008] In a preferred embodiment, step S4 further includes the following enabling operation: Send an enable signal to the functional chip on the interface board to release it from reset or sleep state; The functional chips include a signal conversion chip for converting PCIe signals to HDMI signals, and / or a protocol controller chip for managing the Type-C interface protocol and power supply.

[0009] In a preferred embodiment, step S4 further includes the following limiting operation: Keep the functional chips on the interface board in a reset or disabled state.

[0010] In a preferred embodiment, the storage module is an encryption chip, an electrically erasable read-only memory, or a one-time programmable memory soldered onto the printed circuit board of the interface board.

[0011] In a preferred embodiment, the sideband communication channel further includes a private communication link established by multiplexing pins defined as reserved or undefined in the M.2 interface specification; In step S1, the authentication request also includes a preset level sequence or clock signal sent through the private communication link; In step S2, the authentication response information also includes the response level sequence or clock signal returned by the interface board through the private communication link.

[0012] In a preferred embodiment, an initialization step is included before step S1: The session key or token for subsequent rapid verification is negotiated and stored between the computer motherboard and the interface board that has been connected and authenticated for the first time. In the subsequent identification process, steps S1 to S3 are replaced by a fast verification process based on session keys or tokens.

[0013] After adopting the above solution, the beneficial effects of the present invention are as follows: This invention completes identity authentication before enabling the PCIe channel through the sideband communication channel, realizing a "first authentication, then enable" security mechanism, effectively preventing the use of counterfeit boards. It also adopts a challenge-response mechanism, using a random challenge value for each authentication to prevent replay attacks, thus enabling the computer motherboard to effectively identify the interface board and ensuring the production interests of genuine products. Attached Figure Description

[0014] Figure 1 This is a schematic diagram of the overall process of the identification method in an embodiment of the present invention; Figure 2 This is a schematic diagram of the challenge-response authentication process based on the SMBus sideband channel in an embodiment of the present invention; Figure 3 This is a schematic diagram of the authentication process based on a reserved pin private protocol in an embodiment of the present invention; Figure 4 This is a schematic diagram of the fast session key verification process in an embodiment of the present invention. Detailed Implementation

[0015] The present invention will now be further described in conjunction with the accompanying drawings and specific embodiments.

[0016] This embodiment provides a method for identifying a computer motherboard and an interface board. The interface board is pluggably connected to the computer motherboard via an M.2 interface and is used to expand at least one external functional interface, such as... Figure 1 and Figure 2 As shown, the identification method includes the following steps: S1: Send authentication request.

[0017] When the computer motherboard detects that the interface board is connected through the M.2 interface, it sends an authentication request to the interface board through the preset sideband communication channel in the M.2 interface; The authentication request includes a random challenge value. The interface board is equipped with a storage module that stores encryption keys and / or device identifiers.

[0018] When the motherboard's M.2 interface detects the insertion of an interface board (which can be determined by the M.2 interface presence detection pin or the PCIe link training signal), the motherboard does not immediately enable the PCIe channel and power supply. Instead, the motherboard sends an authentication request to the storage module on the interface board via the SMBus bus (clock pin SMBCLK and data pin SMBDATA) defined in the M.2 interface specification.

[0019] The authentication request includes a randomly generated challenge value, such as a 128-bit random number. It also contains command codewords instructing the interface board to return an authentication response.

[0020] An encryption chip (such as Microchip ATECC608A) is soldered onto the interface board. This chip stores the encryption key (or device identifier). The encryption chip receives authentication requests from the computer motherboard via the SMBus bus.

[0021] S2: Returns the authentication response.

[0022] The computer motherboard receives the authentication response information returned by the interface board. The authentication response information is generated by the interface board after encrypting the random challenge value based on the encryption key stored in the storage module, and / or, based on the device identifier.

[0023] The encryption chip uses the internally stored encryption key to perform encryption operations (such as AES-128 encryption or HMAC-SHA256 operation) on the random challenge value, generate authentication response information, and return it to the computer motherboard via the SMBus bus.

[0024] Alternatively, if the storage module only stores the device identifier, the interface board will directly return the device identifier as the authentication response information.

[0025] S3: Verify the validity of the response.

[0026] The computer motherboard verifies the validity of the received authentication response information using any of the following methods: Method 1: The computer motherboard has pre-stored the valid response information (or the rules for generating valid responses) of the interface board. The received response is compared with the pre-stored information. If they match, the verification is successful.

[0027] Method 2: The computer motherboard stores a public key or shared key that matches the encryption key of the interface board. This key is used to decrypt and verify the received authentication response information. If the verification passes, the authentication is successful.

[0028] S4: Perform an enable or limit operation.

[0029] If the verification is successful, the computer motherboard will perform an enable operation, providing the system resources required for normal operation to the interface board. The enable operation includes: powering the interface board through the power pins of the M.2 interface and enabling data transmission between the interface board and the PCIe channel of the M.2 interface. If the verification fails, the computer motherboard will perform restriction operations, including: prohibiting power supply to the interface board through the power pins of the M.2 interface, and / or disabling the PCIe lanes through the M.2 interface.

[0030] Once the verification is successful, the computer motherboard will perform the enable operation: (a) Power the interface board via the 3.3V power pin of the M.2 interface; (b) Enable the PCIe channel of the M.2 interface and establish a data transmission link with the interface board; (c) Send an enable signal to the functional chip on the interface board to release it from its reset or sleep state. For example, send a reset signal to the HDMI signal conversion chip (such as PI3HDX1204B) and a wake-up signal to the Type-C protocol controller chip (such as RTS5453H-GR) to enable it to start PD power supply negotiation.

[0031] Verification failed; the computer motherboard is performing a restriction operation. (a) Powering the interface board through the power pins of the M.2 interface is prohibited; the interface board will not be powered on. And / or, (b) disable the PCIe lanes of the M.2 interface so that data communication cannot be performed even if the interface board is powered on; (c) Keep the functional chips on the interface board in a reset or disabled state to prevent abnormal behavior caused by partial power-up.

[0032] like Figure 3 As shown, this embodiment can also add a private communication protocol based on reserved pins of the M.2 interface. The M.2 interface specification defines some "reserved" or "undefined" pins (such as certain key pins or reserved GPIOs), which are not used in standard applications. This embodiment reuses these pins to establish a private communication link.

[0033] In step S1, in addition to sending an authentication request via SMBus, the computer motherboard also sends a preset level sequence or clock signal via a private communication link. For example, the computer motherboard outputs a specific high-low level combination (such as "high-low-high-high-low") on reserved pins as a physical layer identity challenge.

[0034] In step S2, the detection circuit on the interface board (which can be implemented by a CPLD or a dedicated logic chip) identifies the level sequence and returns a response level sequence (such as "low-high-low-low-high") through the same private communication link. This response sequence is returned to the computer motherboard as part of the authentication response information.

[0035] The computer motherboard verifies whether the response level sequence conforms to preset rules. Because this protocol is based on reserved pin definitions, the cloned board, unaware of the protocol content, cannot respond correctly. Based on this, the computer motherboard determines it as an illegal device and performs restrictive operations.

[0036] In this embodiment, the authentication response information includes two parts: an encryption response based on the encryption chip (returned via SMBus) and a level response based on the proprietary protocol (returned via a reserved pin). The computer motherboard needs to verify both parts to determine that the authentication is successful.

[0037] like Figure 4 As shown, this embodiment can also add a session key mechanism to improve the identification speed of subsequent connections.

[0038] Initialization steps: After the computer motherboard and a certain interface board are connected for the first time and the complete authentication process (steps S1 to S3) is completed, the computer motherboard and the interface board negotiate and generate a session key or token through the sideband communication channel, and store them in the storage modules of the computer motherboard and the interface board respectively.

[0039] Quick verification process: When the interface board is subsequently inserted into the same computer motherboard again, the identification process is simplified to: The computer motherboard directly sends a session key or token as an authentication request through the sideband communication channel; the interface board verifies whether the session key / token is consistent with the locally stored one, and if they are consistent, it directly returns a confirmation response; after the computer motherboard verifies the confirmation response, it can perform the enable operation.

[0040] This process omits the generation of random challenge values, encryption calculations, and complex verification processes, reducing the recognition time from milliseconds to microseconds, making it virtually imperceptible to the user.

[0041] Session keys can be set to have an expiration period (e.g., 30 days), and will automatically revert to the full authentication process after expiration, balancing security and convenience.

[0042] The specific implementation of the storage module is as follows: The storage module on the interface board can be implemented in any of the following ways: (1) Encryption chip: such as ATECC608A, SE050, etc., which integrates encryption engine and key storage area and supports I2C / SMBus interface.

[0043] (2) Electrically erasable read-only memory (EEPROM): such as the 24C series, which is low in cost and suitable for storing device identifiers or shared keys.

[0044] (3) One-time programmable memory (OTP): such as eFuse, which cannot be modified after being written, is suitable for storing unique identifiers of storage devices to prevent the key from being read and then counterfeited.

[0045] The storage module is soldered onto the printed circuit board (PCB) of the interface board and is bound to the interface board. It cannot be disassembled and reused independently, which effectively prevents the storage module from being transplanted onto the imitation board.

[0046] The enable control of the functional chip is as follows: In this embodiment, the enabling operation includes not only power supply and PCIe channel activation, but also enabling control of functional chips on the interface board.

[0047] Take the small interface board that expands HDMI + Type-C functionality as an example: The computer motherboard sends a high-level enable signal to the PI3HDX1204B (HDMI Re-timer chip) through the GPIO pin to release its reset state and enable the HDMI output function. The computer motherboard sends a wake-up command to the RTS5453H-GR (Type-C PD controller) via SMBus, and the chip begins Type-C power supply negotiation and data channel management.

[0048] If authentication fails, the above enable signal will not be issued, and the functional chip will remain in a reset or disabled state. Even if the physical connection of the interface board is normal, the HDMI and Type-C interfaces will not work at all.

[0049] This invention implements challenge-response authentication on the sideband communication channel of the M.2 interface, completing the identification of the interface board before enabling the PCIe channel and power supply, effectively preventing the use of counterfeit boards. The solution is compatible with the M.2 interface specification, does not affect standard PCIe data transmission, and supports session key acceleration, balancing security and user experience.

[0050] The above description is only a preferred embodiment of the present invention and is not intended to limit the design of this case. All equivalent changes made based on the key design features of this case shall fall within the protection scope of this case.

Claims

1. A method for identifying a computer motherboard and an interface board, characterized in that: The interface board is pluggably connected to the computer motherboard via an M.2 interface for expanding at least one external functional interface. This identification method includes the following steps: S1: When the computer motherboard detects that the interface board is connected through the M.2 interface, it sends an authentication request to the interface board through the preset sideband communication channel in the M.2 interface; The authentication request includes a random challenge value. The interface board is equipped with a storage module that stores encryption keys and / or device identifiers. S2: The computer motherboard receives the authentication response information returned by the interface board. The authentication response information is generated by the interface board after encrypting the random challenge value based on the encryption key stored in the storage module, and / or, based on the device identifier. S3: The computer motherboard verifies the validity of the received authentication response information; S4: If the verification is successful, the computer motherboard will perform an enable operation to provide the interface board with the system resources required for normal operation. The enable operation includes: powering the interface board through the power pins of the M.2 interface and enabling data transmission between the interface board and the PCIe channel of the M.2 interface. If the verification fails, the computer motherboard will perform restriction operations, including: prohibiting power supply to the interface board through the power pins of the M.2 interface, and / or disabling the PCIe lanes through the M.2 interface.

2. The method for identifying a computer motherboard and interface board as described in claim 1, characterized in that: In step S1, the preset sideband communication channel is a communication link established by multiplexing the I2C bus, SMBus bus or GPIO pins defined in the M.2 interface specification.

3. The method for identifying a computer motherboard and an interface board as described in claim 1, characterized in that: In step S3, verifying the validity of the received authentication response information includes any of the following methods: The authentication response information is compared with the valid response information pre-stored in the computer motherboard; Alternatively, a public or shared key matching the encryption key pre-installed in the interface board can be used to decrypt and verify the authentication response information.

4. The method for identifying a computer motherboard and interface board as described in claim 1, characterized in that: In step S4, the enabling operation further includes: Send an enable signal to the functional chip on the interface board to release it from reset or sleep state; The functional chips include a signal conversion chip for converting PCIe signals to HDMI signals, and / or a protocol controller chip for managing the Type-C interface protocol and power supply.

5. The method for identifying a computer motherboard and interface board as described in claim 1, characterized in that: In step S4, the limiting operation further includes: Keep the functional chips on the interface board in a reset or disabled state.

6. The method for identifying a computer motherboard and an interface board as described in claim 1, characterized in that: The storage module is an encryption chip, an electrically erasable read-only memory, or a one-time programmable memory soldered onto the printed circuit board of the interface board.

7. The method for identifying a computer motherboard and an interface board as described in claim 1, characterized in that: The sideband communication channel also includes a private communication link established by multiplexing pins defined as reserved or undefined in the M.2 interface specification; In step S1, the authentication request also includes a preset level sequence or clock signal sent through the private communication link; In step S2, the authentication response information also includes the response level sequence or clock signal returned by the interface board through the private communication link.

8. A method for identifying a computer motherboard and an interface board as described in any one of claims 1-7, characterized in that: Before step S1, an initialization step is also included: The session key or token for subsequent rapid verification is negotiated and stored between the computer motherboard and the interface board that has been connected and authenticated for the first time. In the subsequent identification process, steps S1 to S3 are replaced by a fast verification process based on session keys or tokens.