Security authentication method, device, storage medium and program product
Patent Information
- Application Number
- CN202510387995.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]本申请的多个方面提供一种安全认证方法、设备、存储介质及程序产品,用以解决可信控制单元访问主机中数据的安全性低的问题
[0186]本申请实施例提供一种安全认证方法、设备、存储介质及程序产品。主机可以向可信控制单元发送认证请求。可信控制单元可以响应于认证请求,生成自签名证书,并向证书服务器发送自签名证书和背书证书。证书服务器可以基于自签名证书和背书证书对可信控制单元进行安全认证。在证书服务器对可信控制单元认证通过之后,可信控制单元可以响应于认证请求向主机发送认证信息。主机可以基于认证信息,对可信控制单元进行安全认证,以使可信控制单元在安全认证通过之后访问主机中的数据。由于在实际工作中,主机信任证书服务器,因此可信控制单元先向证书服务器发送自签名证书和背书证书,以使证书服务器先对可信控制单元进行安全认证,初步确定了可信控制单元的安全性;证书服务器对可信控制单元认证通过之后,可信控制单元再向主机发送认证信息,以使主机对可信控制单元进行安全认证,防止了可信控制单元在安全性低的情况下向主机发送信息,且通过主机进一步确定了可信控制单元的安全性。对可信控制单元进行双重安全认证通过之后,可信控制单元再访问主机中的数据,提高了可信控制单元访问主机中数据的安全性。
Smart Images

Figure CN122845153A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing, and more particularly to a security authentication method, device, storage medium, and program product. Background Technology
[0002] Electronic devices may include a trusted control unit and a host. The host can run application services and store large amounts of data; the trusted control unit typically has higher privileges and can access the data in the host.
[0003] In practice, on the one hand, the software in the Trusted Control Unit (TCU) has security vulnerabilities and requires periodic updates, resulting in low security for the TCU; on the other hand, the TCU is vulnerable to network attacks, further complicating its security. This low security of the TCU leads to low security for its access to data on the host machine. Summary of the Invention
[0004] This application provides a security authentication method, device, storage medium, and program product to address the problem of low security when a trusted control unit accesses data in a host.
[0005] In a first aspect, embodiments of this application provide a security authentication method applied to a trusted control unit, the method comprising:
[0006] In response to an authentication request sent by the host, a self-signed certificate is generated;
[0007] The self-signed certificate and the endorsement certificate are sent to the certificate server, and the self-signed certificate and the endorsement certificate are used by the certificate server to perform security authentication on the trusted control unit;
[0008] After the certificate server authenticates the trusted control unit, it sends authentication information to the host in response to the authentication request, so that the host can perform security authentication on the trusted control unit and access the data in the host after the security authentication is successful.
[0009] In one possible implementation, the endorsement certificate includes an endorsement public key and an endorsement private key; after sending the self-signed certificate and the endorsement certificate to the certificate server, the method further includes:
[0010] The system receives a key encryption result sent by the certificate server. The key encryption result is obtained by the certificate server encrypting a first session key and an authentication public key based on the endorsement public key after verifying the self-signed certificate. The first session key is generated by the certificate server after verifying the self-signed certificate.
[0011] Based on the endorsed private key, the key encryption result is decrypted to obtain the second session key;
[0012] The second session key is sent to the certificate server so that the certificate server, after verifying that the first session key and the second session key are consistent, generates a self-signed certificate encryption result, which is used to indicate that the certificate server has successfully authenticated the trusted control unit.
[0013] Receive the encryption result of the self-signed certificate sent by the certificate server.
[0014] In one possible implementation, the trusted control unit includes a security component and a service component; in response to an authentication request sent by the host, it generates a self-signed certificate, including:
[0015] The service component responds to the authentication request by sending a trusted authentication command to the security component;
[0016] The security component responds to the trusted authentication command sent by the service component and generates an authentication key pair, which includes an authentication private key and an authentication public key.
[0017] In response to the security verification command sent by the service component, the security component generates the self-signed certificate based on the authentication key pair. The self-signed certificate includes the authentication public key and the digital signature corresponding to the authentication private key.
[0018] In one possible implementation, the authentication information includes trusted measurement information, a trusted measurement hash value, and a self-signed certificate encryption result, wherein the self-signed certificate encryption result is sent by the certificate server to the trusted control unit after successful authentication; sending authentication information to the host in response to the authentication request includes:
[0019] In response to the authentication request, the security component determines the trust measurement information and generates the trust measurement hash value;
[0020] The service component sends the trusted measurement information, the trusted measurement hash value, and the self-signed certificate encryption result to the host, so that the host can decrypt the self-signed certificate encryption result based on the certificate public key to obtain the self-signed certificate, and perform security authentication on the trusted control unit based on the authentication public key in the self-signed certificate, the trusted measurement information, and the trusted measurement hash value.
[0021] In one possible implementation, the authentication request includes an identifier for a random number and a hash algorithm; in response to the authentication request, a trusted metric hash value is generated by the security component, including:
[0022] In response to the authentication request, the security component performs a hash operation on the random number and the trust measurement information based on the hash algorithm to obtain a first hash value;
[0023] The first hash value is encrypted using the authentication private key to obtain the trust metric hash value.
[0024] In one possible implementation, the method further includes:
[0025] Verify the user certificate sent by the target server to obtain the certificate verification result. The user certificate is determined by the target server in response to the login request, which is used to request login to the trusted control unit.
[0026] When the certificate verification result indicates that the user certificate is valid, a first challenge data is sent to the target server;
[0027] The system receives a first challenge response corresponding to the first challenge data sent by the target server. The first challenge response is obtained by the target server signing the first challenge data based on a user key pair, where the user key pair is generated based on the user's biometric information.
[0028] The first challenge verification result corresponding to the first challenge response is determined, and the first challenge verification result is sent to the target server. The first challenge verification result is used to indicate whether the trusted control unit allows the login request to pass.
[0029] In one possible implementation, the method further includes:
[0030] In response to an initial registration request sent by the target server, a challenge request is generated and sent to the target server. The initial registration request includes user information.
[0031] Receive a second challenge response corresponding to the challenge request, wherein the second challenge response is generated by the target server based on the user key pair;
[0032] The second challenge verification result corresponding to the second challenge response is determined, and the second challenge verification result is sent to the target server. The second challenge verification result is used to indicate whether the user has successfully registered the trusted control unit.
[0033] In one possible implementation, the trusted control unit includes a security component and a service component; in response to an initial registration request sent by the target server, a challenge request is generated, including:
[0034] In response to the initial registration request, a target registration request is generated through the service component, the target registration request including a user identifier generated based on the user information;
[0035] The security component generates the challenge request in response to the target registration request.
[0036] In one possible implementation, the user key pair includes a user public key; the method further includes:
[0037] After successfully verifying the second challenge response, a public key mapping relationship between the user identifier and the user public key is established through the security component.
[0038] In one possible implementation, the trusted control unit is any one of the following: a baseboard management controller, a discrete trusted platform module, or a firmware trusted platform module.
[0039] Secondly, embodiments of this application provide a security authentication method applied to a certificate server, the method comprising:
[0040] Receive a self-signed certificate and an endorsement certificate sent by a trusted control unit, wherein the self-signed certificate is generated by the trusted control unit in response to an authentication request sent by the host;
[0041] The trusted control unit performs security authentication based on the self-signed certificate and the endorsement certificate, so that after successful authentication, the trusted control unit sends authentication information to the host, requesting the host to perform security authentication.
[0042] In one possible implementation, security authentication of the trusted control unit is performed based on the self-signed certificate and the endorsement certificate, including:
[0043] The self-signed certificate is verified to obtain the self-signed certificate verification result;
[0044] After the self-signed certificate verification result indicates that the verification is successful, a first session key is generated;
[0045] The trusted control unit is securely authenticated based on the first session key, the self-signed certificate, and the endorsement certificate.
[0046] In one possible implementation, the endorsement certificate includes an endorsement public key and an endorsement private key; based on the first session key, the self-signed certificate, and the endorsement certificate, security authentication of the trusted control unit is performed, including:
[0047] Based on the endorsement public key, the first session key and the authentication public key in the self-signed certificate are encrypted to obtain a key encryption result, and the key encryption result is sent to the trusted control unit.
[0048] The system receives a second session key sent by the trusted control unit. The second session key is obtained by the trusted control unit decrypting the key encryption result based on the endorsement private key.
[0049] If the first session key and the second session key are the same, the self-signed certificate is encrypted based on the certificate private key to obtain the self-signed certificate encryption result. The self-signed certificate encryption result is used to indicate that the certificate server has successfully authenticated the trusted control unit.
[0050] The self-signed certificate encryption result is sent to the trusted control unit.
[0051] In one possible implementation, the self-signed certificate includes an authentication public key, a digital signature corresponding to the authentication private key, and certificate information, wherein the digital signature is generated based on the authentication private key; verifying the self-signed certificate to obtain a self-signed certificate verification result includes:
[0052] The digital signature is decrypted using the authentication public key to obtain the second hash value;
[0053] The certificate information is hashed using the hash algorithm in the self-signed certificate to obtain a third hash value;
[0054] If the second hash value matches the third hash value, then the self-signed certificate verification result is determined to be successful.
[0055] If the second hash value is inconsistent with the third hash value, then the self-signed certificate verification result is determined to be verification failure.
[0056] Thirdly, embodiments of this application provide a security authentication method applied to a host, the method comprising:
[0057] Send an authentication request to the trusted control unit;
[0058] The system receives authentication information sent by the trusted control unit in response to the authentication request, wherein the authentication information is determined by the certificate server after the trusted control unit has been successfully authenticated.
[0059] The trusted control unit is securely authenticated based on the authentication information, so that the trusted control unit can access the data in the host after the security authentication is successful.
[0060] In one possible implementation, the authentication information includes trust measurement information, a trust measurement hash value, and a self-signed certificate encryption result; the authentication request includes a random number.
[0061] Based on the authentication information, security authentication is performed on the trusted control unit, including:
[0062] Based on the certificate public key, the encryption result of the self-signed certificate is decrypted to obtain the self-signed certificate;
[0063] Based on the authentication public key in the self-signed certificate, the trust metric hash value is decrypted to obtain the first hash value;
[0064] A hash operation is performed on the random number and the trust measurement information to obtain a fourth hash value;
[0065] If the first hash value and the fourth hash value are consistent, then the authentication of the trusted control unit is confirmed to be successful.
[0066] Fourthly, embodiments of this application provide a security authentication method applied to a target server, the method comprising:
[0067] In response to a login request, the user certificate is determined and sent to the trusted control unit;
[0068] Receive the first challenge data sent by the trusted control unit when the certificate verification result indicates that the user certificate is valid;
[0069] Based on the user key pair, the first challenge data is signed to obtain a first challenge response, and the first challenge response is sent to the trusted control unit. The user key pair is generated based on the user's biometric information.
[0070] The system receives the first challenge response corresponding to the first challenge verification result sent by the trusted control unit, and determines that the user has successfully logged into the trusted control unit when the first challenge verification result indicates that the verification is successful. After logging into the trusted control unit, the user performs security authentication on the trusted control unit through the certificate server and the host, and accesses data in the host through the trusted control unit.
[0071] In one possible implementation, the target server includes a private key mapping relationship, which includes the biometric information and the user's private key corresponding to the biometric information; in response to a login request, determining the user certificate includes:
[0072] In response to the login request, the user's biometric information is obtained;
[0073] Based on the mapping relationship between the biometric information and the private key, the user's private key corresponding to the biometric information is determined;
[0074] Based on the user's private key, determine the user's public key from the user key pair;
[0075] The user certificate is determined based on the user's public key.
[0076] In one possible implementation, the method further includes:
[0077] Send an initial registration request to the trusted control unit, the initial registration request including the user's user information;
[0078] Receive the challenge request sent by the trusted control unit in response to the initial registration request;
[0079] A second challenge response corresponding to the challenge request is generated based on the user key pair, and the second challenge response is sent to the trusted control unit.
[0080] The system receives the second challenge verification result corresponding to the second challenge response sent by the trusted control unit, and determines that the user has successfully registered the trusted control unit when the second challenge verification result indicates that the verification is successful.
[0081] In one possible implementation, the user key pair includes a user public key and a user private key; generating a second challenge response corresponding to the challenge request based on the user key pair includes:
[0082] In response to the query request, the user's biometric information is collected;
[0083] Based on the biometric information, the user's public key and private key are generated;
[0084] Based on the user's public key and the user information, the user applies for a user certificate from the certificate server;
[0085] Based on the user's private key, the second challenge data in the challenge request is encrypted to obtain the challenge signature;
[0086] The second challenge response is generated based on the challenge signature and the user certificate.
[0087] In one possible implementation, after generating the user key pair based on the biometric information, the method further includes:
[0088] Establish a private key mapping relationship between the biometric information and the user's private key.
[0089] Fifthly, embodiments of this application provide a security authentication device applied to a trusted control unit, the device comprising: a first generation module and a first transmission module, wherein...
[0090] The first generation module is used to generate a self-signed certificate in response to an authentication request sent by the host;
[0091] The first sending module is used to send the self-signed certificate and the endorsement certificate to the certificate server, wherein the self-signed certificate and the endorsement certificate are used by the certificate server to perform security authentication on the trusted control unit;
[0092] The first sending module is configured to, after the certificate server has authenticated the trusted control unit, send authentication information to the host in response to the authentication request, so that the host can perform security authentication on the trusted control unit and access the data in the host after the security authentication is successful.
[0093] In one possible implementation, the endorsement certificate includes an endorsement public key and an endorsement private key; after sending the self-signed certificate and endorsement certificate to the certificate server, the apparatus further includes: a first receiving module and a processing module, wherein,
[0094] The first receiving module is configured to receive a key encryption result sent by the certificate server, wherein the key encryption result is obtained by the certificate server encrypting a first session key and an authentication public key based on the endorsement public key after the self-signed certificate has been verified; the first session key is generated by the certificate server after the self-signed certificate has been verified.
[0095] The processing module is used to decrypt the key encryption result based on the endorsement private key to obtain the second session key;
[0096] The first sending module is further configured to send the second session key to the certificate server, so that after the certificate server verifies that the first session key and the second session key are consistent, it generates a self-signed certificate encryption result, the self-signed certificate encryption result being used to indicate that the certificate server has successfully authenticated the trusted control unit;
[0097] The first receiving module is further configured to receive the encryption result of the self-signed certificate sent by the certificate server.
[0098] In one possible implementation, the trusted control unit includes a security component and a service component; the first generation module is specifically used for:
[0099] The service component responds to the authentication request by sending a trusted authentication command to the security component;
[0100] The security component responds to the trusted authentication command sent by the service component and generates an authentication key pair, which includes an authentication private key and an authentication public key.
[0101] In response to the security verification command sent by the service component, the security component generates the self-signed certificate based on the authentication key pair. The self-signed certificate includes the authentication public key and the digital signature corresponding to the authentication private key.
[0102] In one possible implementation, the authentication information includes trust measurement information, a trust measurement hash value, and a self-signed certificate encryption result, wherein the self-signed certificate encryption result is sent by the certificate server to the trusted control unit after successful authentication; the first sending module is specifically used for:
[0103] In response to the authentication request, the security component determines the trust measurement information and generates the trust measurement hash value;
[0104] The service component sends the trusted measurement information, the trusted measurement hash value, and the self-signed certificate encryption result to the host, so that the host can decrypt the self-signed certificate encryption result based on the certificate public key to obtain the self-signed certificate, and perform security authentication on the trusted control unit based on the authentication public key in the self-signed certificate, the trusted measurement information, and the trusted measurement hash value.
[0105] In one possible implementation, the first sending module is specifically used for:
[0106] In response to the authentication request, the security component performs a hash operation on the random number and the trust measurement information based on the hash algorithm to obtain a first hash value;
[0107] The first hash value is encrypted using the authentication private key to obtain the trust metric hash value.
[0108] In one possible implementation, the device further includes: a verification module.
[0109] The verification module is used to verify the user certificate sent by the target server and obtain the certificate verification result. The user certificate is determined by the target server in response to the login request. The login request is used to request login to the trusted control unit.
[0110] The first sending module is further configured to send first challenge data to the target server when the certificate verification result indicates that the user certificate is valid;
[0111] The first receiving module is further configured to receive a first challenge response corresponding to the first challenge data sent by the target server, wherein the first challenge response is obtained by the target server signing the first challenge data based on a user key pair, and the user key pair is generated based on the user's biometric information.
[0112] The verification module is further configured to determine the first challenge verification result corresponding to the first challenge response, and send the first challenge verification result to the target server. The first challenge verification result is used to indicate whether the trusted control unit allows the login request to pass.
[0113] In one possible implementation,
[0114] The first generation module is further configured to, in response to an initial registration request sent by the target server, generate a challenge request and send the challenge request to the target server, wherein the initial registration request includes user information;
[0115] The first receiving module is further configured to receive a second challenge response corresponding to the challenge request, wherein the second challenge response is generated by the target server based on the user key pair;
[0116] The verification module is further configured to determine the second challenge verification result corresponding to the second challenge response, and send the second challenge verification result to the target server. The second challenge verification result is used to indicate whether the user has successfully registered the trusted control unit.
[0117] In one possible implementation, the trusted control unit includes a security component and a service component; the first generation module is specifically used for:
[0118] In response to the initial registration request, a target registration request is generated through the service component, the target registration request including a user identifier generated based on the user information;
[0119] The security component generates the challenge request in response to the target registration request.
[0120] In one possible implementation, the user key pair includes a user public key; the apparatus further includes: a first establishment module, the first establishment module being configured to:
[0121] After successfully verifying the second challenge response, a public key mapping relationship between the user identifier and the user public key is established through the security component.
[0122] In one possible implementation, the trusted control unit is any one of the following: a baseboard management controller, a discrete trusted platform module, or a firmware trusted platform module.
[0123] Sixthly, embodiments of this application provide a security authentication device applied to a certificate server, the device comprising: a second receiving module and a first authentication module, wherein,
[0124] The second receiving module is used to receive a self-signed certificate and an endorsement certificate sent by the trusted control unit, wherein the self-signed certificate is generated by the trusted control unit in response to an authentication request sent by the host;
[0125] The first authentication module is used to perform security authentication on the trusted control unit based on the self-signed certificate and the endorsement certificate, so that after the authentication is successful, the trusted control unit sends authentication information to the host and requests the host to perform security authentication.
[0126] In one possible implementation, the first authentication module is specifically used for:
[0127] The self-signed certificate is verified to obtain the self-signed certificate verification result;
[0128] After the self-signed certificate verification result indicates that the verification is successful, a first session key is generated;
[0129] The trusted control unit is securely authenticated based on the first session key, the self-signed certificate, and the endorsement certificate.
[0130] In one possible implementation, the endorsement certificate includes an endorsement public key and an endorsement private key; the first authentication module is specifically used for:
[0131] Based on the endorsement public key, the first session key and the authentication public key in the self-signed certificate are encrypted to obtain a key encryption result, and the key encryption result is sent to the trusted control unit.
[0132] The system receives a second session key sent by the trusted control unit. The second session key is obtained by the trusted control unit decrypting the key encryption result based on the endorsement private key.
[0133] If the first session key and the second session key are the same, the self-signed certificate is encrypted based on the certificate private key to obtain the self-signed certificate encryption result. The self-signed certificate encryption result is used to indicate that the certificate server has successfully authenticated the trusted control unit.
[0134] The self-signed certificate encryption result is sent to the trusted control unit.
[0135] In one possible implementation, the self-signed certificate includes an authentication public key, a digital signature corresponding to the authentication private key, and certificate information, wherein the digital signature is generated based on the authentication private key; the first authentication module is specifically used for:
[0136] The digital signature is decrypted using the authentication public key to obtain the second hash value;
[0137] The certificate information is hashed using the hash algorithm in the self-signed certificate to obtain a third hash value;
[0138] If the second hash value matches the third hash value, then the self-signed certificate verification result is determined to be successful.
[0139] If the second hash value is inconsistent with the third hash value, then the self-signed certificate verification result is determined to be verification failure.
[0140] In a seventh aspect, embodiments of this application provide a security authentication device applied to a host computer. The device includes: a second transmitting module, a third receiving module, and a second authentication module, wherein...
[0141] The second sending module is used to send an authentication request to the trusted control unit;
[0142] The third receiving module is used to receive authentication information sent by the trusted control unit in response to the authentication request, wherein the authentication information is determined by the certificate server after the trusted control unit has been authenticated.
[0143] The second authentication module is used to perform security authentication on the trusted control unit based on the authentication information, so that the trusted control unit can access the data in the host after the security authentication is passed.
[0144] In one possible implementation, the authentication information includes trust measurement information, a trust measurement hash value, and a self-signed certificate encryption result; the authentication request includes a random number; the second authentication module is specifically used for:
[0145] Based on the certificate public key, the encryption result of the self-signed certificate is decrypted to obtain the self-signed certificate;
[0146] Based on the authentication public key in the self-signed certificate, the trust metric hash value is decrypted to obtain the first hash value;
[0147] A hash operation is performed on the random number and the trust measurement information to obtain a fourth hash value;
[0148] If the first hash value and the fourth hash value are consistent, then the authentication of the trusted control unit is confirmed to be successful.
[0149] Eighthly, embodiments of this application provide a security authentication device applied to a target server. The device includes: a determining module, a third sending module, a fourth receiving module, and a signature module, wherein...
[0150] The determining module is used to determine the user certificate in response to a login request;
[0151] The third sending module is used to send the user certificate to the trusted control unit;
[0152] The fourth receiving module is used to receive the first challenge data sent by the trusted control unit when the certificate verification result indicates that the user certificate is valid.
[0153] The signature module is used to sign the first challenge data based on the user key pair to obtain the first challenge response;
[0154] The third sending module is used to send the first challenge response to the trusted control unit, wherein the user key pair is generated based on the user's biometric information;
[0155] The fourth receiving module is used to receive the first challenge verification result corresponding to the first challenge response sent by the trusted control unit;
[0156] The determining module is further configured to, when the first challenge verification result indicates that the verification is passed, determine that the user has successfully logged into the trusted control unit, so that after logging into the trusted control unit, the user can perform security authentication of the trusted control unit through the certificate server and the host, and access data in the host through the trusted control unit.
[0157] In one possible implementation, the target server includes a private key mapping relationship, which includes the biometric information and the user's private key corresponding to the biometric information; the determining module is specifically used for:
[0158] In response to the login request, the user's biometric information is obtained;
[0159] Based on the mapping relationship between the biometric information and the private key, the user's private key corresponding to the biometric information is determined;
[0160] Based on the user's private key, determine the user's public key from the user key pair;
[0161] The user certificate is determined based on the user's public key.
[0162] In one possible implementation, the apparatus further includes: a second generation module, wherein,
[0163] The third sending module is further configured to send an initial registration request to the trusted control unit, wherein the initial registration request includes the user's user information.
[0164] The fourth receiving module is further configured to receive a challenge request sent by the trusted control unit in response to the initial registration request;
[0165] The second generation module is used to generate a second challenge response corresponding to the challenge request based on the user key pair;
[0166] The third sending module is further configured to send the second challenge response to the trusted control unit;
[0167] The fourth receiving module is further configured to receive the second challenge verification result corresponding to the second challenge response sent by the trusted control unit;
[0168] The determining module is further configured to determine that the user has successfully registered the trusted control unit when the second challenge verification result indicates that the verification has passed.
[0169] In one possible implementation, the user key pair includes a user public key and a user private key; the second generation module is specifically used for:
[0170] In response to the query request, the user's biometric information is collected;
[0171] Based on the biometric information, the user's public key and private key are generated;
[0172] Based on the user's public key and the user information, the user applies for a user certificate from the certificate server;
[0173] Based on the user's private key, the second challenge data in the challenge request is encrypted to obtain the challenge signature;
[0174] The second challenge response is generated based on the challenge signature and the user certificate.
[0175] In one possible implementation, after generating the user key pair based on the biometric information, the device further includes: a second establishment module, the second establishment module being used for:
[0176] Establish a private key mapping relationship between the biometric information and the user's private key.
[0177] Ninthly, embodiments of this application provide a trusted control unit, which is used to perform the method described in any of the first aspects.
[0178] In a tenth aspect, embodiments of this application provide a host computer for performing the method described in any of the third aspects.
[0179] Eleventhly, embodiments of this application provide an electronic device, including a trusted control unit as described in the ninth aspect and a host as described in the tenth aspect.
[0180] In a twelfth aspect, embodiments of this application provide a server, including:
[0181] At least one processor; and
[0182] A memory that is communicatively connected to the at least one processor;
[0183] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, cause the server to perform the method described in either the second or fourth aspect.
[0184] In a thirteenth aspect, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, are used to implement the method described in any one of the first to fourth aspects.
[0185] In a fourteenth aspect, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the method shown in any one of the first to fourth aspects.
[0186] This application provides a security authentication method, device, storage medium, and program product. A host can send an authentication request to a trusted control unit (TCU). In response to the authentication request, the TCU generates a self-signed certificate and sends the self-signed certificate and endorsement certificate to a certificate server. The certificate server can perform security authentication on the TCU based on the self-signed certificate and endorsement certificate. After the certificate server successfully authenticates the TCU, the TCU can send authentication information to the host in response to the authentication request. The host can then perform security authentication on the TCU based on the authentication information, allowing the TCU to access data on the host after successful authentication. Since the host trusts the certificate server in practice, the TCU first sends the self-signed certificate and endorsement certificate to the certificate server, enabling the certificate server to perform initial security authentication and establish the TCU's security. After the certificate server successfully authenticates the TCU, the TCU then sends authentication information to the host, allowing the host to perform security authentication on the TCU. This prevents the TCU from sending information to the host under low-security conditions and further confirms the TCU's security through the host. By performing dual security authentication on the TCU, the TCU can then access data on the host, improving the security of the TCU's access to data on the host. Attached Figure Description
[0187] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0188] Figure 1 A schematic diagram illustrating an application scenario provided for an exemplary embodiment of this application;
[0189] Figure 2 A flowchart illustrating a security authentication method provided for an exemplary embodiment of this application;
[0190] Figure 3 A flowchart illustrating another security authentication method provided for an exemplary embodiment of this application;
[0191] Figure 4 A flowchart illustrating yet another security authentication method provided for an exemplary embodiment of this application;
[0192] Figure 5 A flowchart illustrating a registration method for a trusted control unit provided as an exemplary embodiment of this application;
[0193] Figure 6 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 1 ;
[0194] Figure 7 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 2 ;
[0195] Figure 8 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 3 ;
[0196] Figure 9 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 4 ;
[0197] Figure 10 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 5 ;
[0198] Figure 11 A schematic diagram of the structure of an electronic device provided as an exemplary embodiment of this application;
[0199] Figure 12 This is a schematic diagram of the structure of a server provided for an exemplary embodiment of this application. Detailed Implementation
[0200] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0201] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0202] Below, in conjunction with Figure 1 The application scenarios of this application will be explained.
[0203] Figure 1 This is a schematic diagram illustrating an application scenario provided for an exemplary embodiment of this application. Please refer to [link / reference]. Figure 1An electronic device may include a trusted control unit and a host. The host may run application services and store the corresponding data. The trusted control unit can access the data in the host.
[0204] In practice, on the one hand, the software in the Trusted Control Unit (TCU) has security vulnerabilities and requires periodic updates, resulting in low security for the TCU; on the other hand, the TCU is vulnerable to network attacks, further complicating its security. This low security of the TCU leads to low security for its access to data on the host machine.
[0205] To address the aforementioned technical problems, this application provides a secure authentication method. A trusted control unit (TCU) can respond to an authentication request sent by a host, generate a self-signed certificate, and send the self-signed certificate and endorsement certificate to a certificate server. This allows the certificate server to perform security authentication on the TCU based on the self-signed certificate and endorsement certificate. After the certificate server successfully authenticates the TCU, the TCU can respond to the authentication request by sending authentication information to the host. This allows the host to perform security authentication on the TCU, enabling access to data on the host after successful authentication. Since the host trusts the certificate server in practice, the TCU first sends the self-signed certificate and endorsement certificate to the certificate server, allowing the certificate server to perform initial security authentication and establishing the TCU's security. After the certificate server successfully authenticates the TCU, the TCU then sends authentication information to the host, enabling the host to perform security authentication on the TCU. This prevents the TCU from sending information to the host under low-security conditions and further confirms the TCU's security through the host's verification. By performing dual security authentication on the TCU, the TCU can then access data on the host, improving the security of the TCU's access to data on the host.
[0206] The technical solutions shown in this application will now be described in detail through specific embodiments. It should be noted that the following embodiments may exist independently or in combination with each other; for identical or similar content, the description will not be repeated in different embodiments.
[0207] Figure 2 This is a flowchart illustrating a security authentication method provided for an exemplary embodiment of this application. Please refer to [link / reference]. Figure 2 The method may include:
[0208] S201. The host sends an authentication request to the trusted control unit.
[0209] The electronic device may include a host and a trusted control unit. Optionally, the trusted control unit may be any of the following: a Baseboard Management Controller (BMC), a Discrete Trusted Platform Module (dTPM), or a Firmware Trusted Platform Module (fTPM).
[0210] The authentication request may include an identifier for the key algorithm and an identifier for the hash algorithm.
[0211] Key algorithms use keys to implement encryption and decryption, primarily for protecting data confidentiality. For example, a key algorithm can be a symmetric key algorithm or an asymmetric key algorithm.
[0212] For example, symmetric key algorithms can be Advanced Encryption Standard (AES) or Data Encryption Standard (DES); asymmetric key algorithms can be Elliptic Curve Cryptography (ECC) or Digital Signature Algorithm (DSA).
[0213] A hash algorithm is a function used to map data to hash values, primarily for data integrity verification. Examples of hash algorithms include Message Digest Algorithm 5 (MD5) and Secure Hash Algorithm 256-bit (SHA-256).
[0214] For example, a host can send an authentication request to a trusted control unit, which may include an identifier for the key algorithm as DSA and an identifier for the hash algorithm as SHA-256.
[0215] S202. The trusted control unit responds to the authentication request and generates a self-signed certificate.
[0216] The trusted control unit can respond to authentication requests and generate authentication key pairs based on the key algorithm in the authentication request. An authentication key pair can include an authentication private key and an authentication public key. For example, an authentication key pair can be represented as AK, the authentication private key as AK-s, and the authentication public key as AK-p.
[0217] For example, if the key algorithm identifier in the authentication request is DSA, the trusted control unit can generate an authentication key pair based on the DSA algorithm.
[0218] A self-signed certificate is a certificate issued by the trusted control unit itself. A self-signed certificate can include an authentication public key and a digital signature corresponding to the authentication private key. For example, a self-signed certificate can be represented as AKCert.
[0219] A self-signed certificate may also include certificate information. Optionally, the certificate information may include any of the following: certificate holder information, certificate validity period, certificate serial number, hash algorithm identifier, certificate scope of application, and certificate purpose.
[0220] A digital signature can be obtained by hashing the certificate information to obtain a second hash value, and then encrypting the second hash value using the authentication private key. Digital signatures can be used for identity authentication.
[0221] After the trusted control unit generates an authentication key pair, it can generate a self-signed certificate based on the authentication key pair. For example, the self-signed certificate AKCert can include the authentication public key AK-p, the digital signature corresponding to the authentication private key AK-s, and certificate information.
[0222] S203. The trusted control unit sends a self-signed certificate and an endorsement certificate to the certificate server.
[0223] A certificate server is a server used to issue certificates. For example, a certificate server can be a server with a Private Certification Authority (PCA).
[0224] Optionally, the trusted control unit may have a pre-set endorsement key certificate (EKCert), which serves as a unique identifier for the trusted control unit. The endorsement certificate may include an endorsement public key and an endorsement private key. The endorsement public key can be represented as EK-p, and the endorsement private key can be represented as EK-s.
[0225] The trusted control unit can send a self-signed certificate AKCert and an endorsement certificate EKCert to the certificate server.
[0226] S204. The certificate server performs security authentication of the trusted control unit based on self-signed certificates and endorsement certificates.
[0227] Since the self-signed certificate is a certificate issued by the trusted control unit itself, and the endorsement certificate is the unique identifier of the trusted control unit, the certificate server can perform security authentication on the trusted control unit based on the self-signed certificate and the endorsement certificate after receiving them.
[0228] Optionally, the certificate server can verify the self-signed certificate to obtain a verification result. The verification result can be either "verification passed" or "verification failed".
[0229] After the self-signed certificate verification result indicates successful verification, the certificate server can generate a first session key and perform security authentication on the trusted control unit based on the first session key, the self-signed certificate, and the endorsement certificate. The first session key can be represented as K.
[0230] The certificate server can authenticate the trusted control unit by either passing or failing the authentication.
[0231] A certificate server may include certificate key pairs, which may include a public key and a private key. Optionally, the certificate key pair may be represented as a CA, the public key may be represented as CA-p, and the private key may be represented as CA-s.
[0232] If the authentication result is successful, the certificate server can use the certificate private key CA-s to encrypt the self-signed certificate, obtaining the encrypted self-signed certificate result. The encrypted self-signed certificate result can be used to indicate that the certificate server has successfully authenticated the trusted control unit. Optionally, the encrypted self-signed certificate result can be represented as (AKCert)CA-s.
[0233] The certificate server can send the encrypted result of the self-signed certificate to the trusted control unit.
[0234] S205. After the certificate server authenticates the trusted control unit, the trusted control unit responds to the authentication request by sending authentication information to the host.
[0235] Optionally, the authentication request may also include a random number. Optionally, the random number may be represented as n.
[0236] The authentication information may include trusted measurement information, trusted measurement hash value, and self-signed certificate encryption result.
[0237] The trusted measurements include hash values calculated using a hash algorithm for the configuration of at least one component during system startup. At least one component may include at least one of the following: Basic Input Output System (BIOS), bootloader, operating system, etc.
[0238] The trusted measurement hash value refers to the first hash value obtained by hashing trusted measurement information and a random number together, and then encrypting the first hash value with the authentication private key. Optionally, the trusted measurement hash value can be represented as (n, Measurements)AK-s.
[0239] For example, in response to an authentication request, the trusted control unit can send authentication information to the host. This authentication information may include trusted measurement information, trusted measurement hash values (n, Measurements) AK-s, and the self-signed certificate encryption result (AKCert) CA-s. The trusted measurement information may include hash value one corresponding to the BIOS, hash value two corresponding to the bootloader, and hash value three corresponding to the operating system.
[0240] S206. The host performs security authentication on the trusted control unit based on the authentication information, so that the trusted control unit can access the data in the host after the security authentication is successful.
[0241] Optionally, the certificate server can send certificate key pairs to the host.
[0242] Since the authentication information includes trusted measurement information, trusted measurement hash value (n, Measurements) AK-s, and self-signed certificate encryption result (AKCert) CA-s, after the host receives the authentication information, it can decrypt the self-signed certificate encryption result (AKCert) CA-s based on the certificate public key CA-p in the certificate key pair to obtain the self-signed certificate AKCert.
[0243] Since the self-signed certificate includes the authentication public key AK-p, the host can decrypt the trusted measurement hash (n, Measurements) AK-s based on the authentication public key AK-p to obtain the first hash value.
[0244] The host can use the hash algorithm in the self-signed certificate to hash the random number and trust measurement information together to obtain a fourth hash value.
[0245] The host can verify whether the first hash value and the fourth hash value are consistent. If the first hash value and the fourth hash value are consistent, the authentication of the trusted control unit is successful; if the first hash value and the fourth hash value are inconsistent, it means that the trusted measurement information has been tampered with, and the authentication of the trusted control unit fails.
[0246] After the host authenticates the trusted control unit, the trusted control unit can access the data in the host.
[0247] In this embodiment, the host can send an authentication request to the trusted control unit. In response to the authentication request, the trusted control unit generates a self-signed certificate and sends the self-signed certificate and endorsement certificate to the certificate server. The certificate server can perform security authentication on the trusted control unit based on the self-signed certificate and endorsement certificate. After the certificate server successfully authenticates the trusted control unit, the trusted control unit can send authentication information to the host in response to the authentication request. The host can then perform security authentication on the trusted control unit based on the authentication information, allowing the trusted control unit to access data on the host after successful security authentication. Since the host trusts the certificate server in practice, the trusted control unit first sends the self-signed certificate and endorsement certificate to the certificate server, enabling the certificate server to perform security authentication on the trusted control unit and initially determine its security. After the certificate server successfully authenticates the trusted control unit, the trusted control unit then sends authentication information to the host, allowing the host to perform security authentication on the trusted control unit. This prevents the trusted control unit from sending information to the host under low-security conditions and further confirms the security of the trusted control unit through the host. By performing dual security authentication on the trusted control unit, the trusted control unit can access data on the host, improving the security of the trusted control unit's access to data on the host.
[0248] Below, in Figure 2 Based on the implementation examples, combined with Figure 3 The above security authentication methods will be explained in detail.
[0249] Figure 3 A schematic flowchart illustrating another security authentication method provided for an exemplary embodiment of this application. Please refer to... Figure 3 The methods may include:
[0250] S301, The host sends an authentication request to the trusted control unit.
[0251] It should be noted that the execution process of step S301 can be referred to the execution process of step S201, and will not be repeated here.
[0252] S302. In response to the authentication request, the Trusted Control Unit sends a Trusted Authentication Command to the Security Component through the Service Component.
[0253] Optionally, the trusted control unit may include a security component and a service component. The security component can be used to store confidential data. The service component can act as a network server for the trusted control unit, handling tasks such as forwarding relevant network messages.
[0254] The trusted control unit can receive authentication requests sent by the host through the service component. The authentication request may include an identifier for the key algorithm, an identifier for the hash algorithm, and a random number. For example, the authentication request may include an identifier for the key algorithm as DSA, an identifier for the hash algorithm as SHA-256, and a random number as 123.
[0255] After receiving an authentication request, the service component can determine the identifier of the key algorithm from the authentication request and then generate a trusted authentication command. The trusted authentication command can include the identifier of the key algorithm. For example, if the authentication request is as shown in the example above, the trusted authentication command can include the identifier of the key algorithm as DSA.
[0256] The trusted authentication command can be used to request a security component to generate an authentication key pair. Optionally, the trusted authentication command can be represented as sec_make credential.
[0257] S303. The Trusted Control Unit responds to the Trusted Authentication Command sent by the Service Component and generates an authentication key pair through the Security Component.
[0258] After receiving the trusted authentication command from the service component, the security component can generate an authentication key pair based on the key algorithm indicated in the trusted authentication command. The authentication key pair AK can include an authentication private key AK-s and an authentication public key AK-p.
[0259] For example, if the trusted authentication command includes a key algorithm identifier of DSA, the security component can generate an authentication key pair AK based on the DSA algorithm.
[0260] S304. The service component sends a security verification command to the security component.
[0261] Optionally, the service component can determine the identifier of the hash algorithm in the authentication request, and then generate a security verification command. The security verification command may include the identifier of the hash algorithm. For example, if the authentication request is as illustrated above, the security verification command may include the hash algorithm identifier as SHA-256.
[0262] The security verification command can be used to request a security component to generate a self-signed certificate. Optionally, the security verification command can be represented as sec_certify.
[0263] S305. The trusted control unit responds to the security verification command sent by the service component and generates a self-signed certificate based on the authentication key pair through the security component.
[0264] Optionally, the trusted control unit may have pre-set certificate information. After receiving the security verification command, the security component can determine the certificate information in the trusted control unit and perform a hash operation on the certificate information based on the hash algorithm indicated in the security verification command to obtain a hash value. Since the authentication key pair AK generated by the security component includes an authentication private key AK-s and an authentication public key AK-p, the security component can use the authentication private key AK-s to encrypt the hash value to obtain a digital signature.
[0265] For example, if the security verification command includes a hash algorithm identifier of SHA-256, the security component can perform a hash operation on the certificate information based on the SHA-256 algorithm to obtain a second hash value, and then use the authentication private key AK-s to encrypt the second hash value to obtain a digital signature.
[0266] The security component can generate self-signed certificates, which may include the authentication public key AK-p, a digital signature, and certificate information. The hash algorithm identifier in the certificate information is SHA-256.
[0267] S306. The trusted control unit sends a self-signed certificate and an endorsement certificate to the certificate server.
[0268] The trusted control unit can be pre-loaded with an endorsement certificate.
[0269] After the trusted control unit generates a self-signed certificate through the security component, the security component can send the self-signed certificate to the service component. Upon receiving the self-signed certificate, the service component can send the self-signed certificate and endorsement certificate to the certificate server.
[0270] S307. The certificate server verifies the self-signed certificate and obtains the self-signed certificate verification result.
[0271] Optionally, the self-signed certificate can be verified in the following way to obtain the self-signed certificate verification result: based on the authentication public key, the digital signature is decrypted to obtain a second hash value; the certificate information is hashed using the hash algorithm in the self-signed certificate to obtain a third hash value; if the second hash value and the third hash value are consistent, the self-signed certificate verification result is determined to be successful; if the second hash value and the third hash value are inconsistent, the self-signed certificate verification result is determined to be unsuccessful.
[0272] Since a self-signed certificate includes an authentication public key AK-p, a digital signature, and certificate information (which includes an identifier for the hash algorithm), the certificate server can decrypt the digital signature using the AK-p to obtain a second hash value. Then, it can perform a hash operation on the certificate information using the hash algorithm specified in the certificate information to obtain a third hash value. The certificate server can determine the verification result of the self-signed certificate based on whether the second and third hash values match.
[0273] For example, a certificate server can decrypt a digital signature based on the authentication public key to obtain a second hash value of 65a8e…29. If the hash algorithm identifier in the certificate information is SHA-256, the certificate server can perform a hash operation on the certificate information using the SHA-256 algorithm to obtain a third hash value.
[0274] If the third hash value is 65a8e……29, since the second and third hash values are the same, it means that the self-signed certificate has not been tampered with, and the self-signed certificate verification result can be determined as verification passed; if the third hash value is 71c6f……65, since the second and third hash values are different, it means that the self-signed certificate may have been tampered with, and the self-signed certificate verification result can be determined as verification failed.
[0275] S308. After the self-signed certificate verification result indicates that the verification has passed, the certificate server generates the first session key.
[0276] Optionally, after the self-signed certificate verification result indicates successful verification, the certificate server may randomly generate a first session key. Optionally, the first session key may be represented as K.
[0277] S309. The certificate server encrypts the first session key and the authentication public key in the self-signed certificate based on the endorsement public key to obtain the key encryption result.
[0278] Since the endorsement certificate includes the endorsement public key EK-p and the self-signed certificate includes the authentication public key AK-p, the certificate server can encrypt the first session key K and the authentication public key AK-p to obtain the key encryption result. Optionally, the key encryption result can be represented as (K, AK-p)EK-p.
[0279] S310, the certificate server sends the key encryption result to the trusted control unit.
[0280] The certificate server can send the key encryption result (K, AK-p)EK-p to the service components in the trusted control unit.
[0281] S311, The trusted control unit decrypts the key encryption result based on the endorsed private key through the security component to obtain the second session key.
[0282] Optionally, the trusted control unit can receive the key encryption result (K, AK-p)EK-p through the service component and send an activation command to the security component through the service component. The activation command may include the key encryption result (K, AK-p)EK-p.
[0283] The activation command can be used to request the security component to decrypt the key encryption result. Optionally, the activation command can be represented as sec_activatecredential.
[0284] Since the trusted control unit includes an endorsement certificate, which contains an endorsement public key EK-p and an endorsement private key EK-s, the security component can, in response to an activation command, determine the endorsement private key EK-s from the endorsement certificate, and use the endorsement private key EK-s to decrypt the key encryption result (K, AK-p)EK-p to obtain the second session key and the authentication public key AK-p. Optionally, the second session key can be represented as K′.
[0285] S312, The trusted control unit sends the second session key to the certificate server.
[0286] The trusted control unit sends the second session key K′ to the service component through the security component, and then sends the second session key K′ to the certificate server through the service component.
[0287] S313. If the first session key and the second session key are the same, the certificate server encrypts the self-signed certificate based on the certificate private key to obtain the self-signed certificate encryption result.
[0288] After receiving the second session key K′, the certificate server can verify whether the first session key and the second session key are consistent. If the first session key K and the second session key K′ are consistent, it means that the authentication public key AK-p has been bound to the endorsement public key EK-p; if the first session key and the second session key are inconsistent, it means that the authentication public key AK-p is not bound to the endorsement public key EK-p.
[0289] Since a certificate server contains a certificate key pair, which includes a private key CA-s and a public key CA-p, if the first session key K and the second session key K′ are consistent, the certificate server can encrypt the self-signed certificate AKCert based on the private key CA-s, obtaining the self-signed certificate encryption result (AKCert)CA-s. The self-signed certificate encryption result (AKCert)CA-s can be used to indicate that the certificate server has successfully authenticated the trusted control unit.
[0290] S314. The certificate server sends the self-signed certificate encryption result to the trusted control unit.
[0291] Optionally, the certificate server may send the self-signed certificate encryption result (AKCert) CA-s to the service component in the trusted control unit.
[0292] S315. After the certificate server authenticates the trusted control unit, in response to the authentication request, the trusted measurement information is determined by the security component and a trusted measurement hash value is generated.
[0293] After receiving the encryption result of the self-signed certificate, the service component in the Trusted Control Unit can determine that the certificate server has successfully authenticated the Trusted Control Unit.
[0294] After the certificate server authenticates the trusted control unit, the service component can send an authentication request to the security component.
[0295] Since the authentication request includes an identifier of the hash algorithm, the trusted control unit can, in response to the authentication request, perform a hash operation on the configuration of at least one component during system startup based on the hash algorithm to obtain at least one hash value, and then determine that the trusted measurement information includes the at least one hash value.
[0296] For example, if the hash algorithm identifier in the authentication request is SHA-256, the security component can perform hash operations on the BIOS configuration, bootloader configuration, and operating system configuration based on SHA-256. The hash value corresponding to the BIOS is 1, the hash value corresponding to the bootloader is 2, and the hash value corresponding to the operating system is 3. The trust measurement information can include the hash value corresponding to the BIOS is 1, the hash value corresponding to the bootloader is 2, and the hash value corresponding to the operating system is 3.
[0297] Optionally, in response to an authentication request, a trusted measurement hash value can be generated by a security component as follows: the security component performs a hash operation on a random number and trusted measurement information based on a hash algorithm to obtain a first hash value; the first hash value is then encrypted based on the authentication private key to obtain the trusted measurement hash value.
[0298] For example, if the authentication request includes the hash algorithm identifier SHA-256 and the random number 123, and the trusted measurement information is as shown in the example above, the security component can perform a hash operation on the trusted measurement information and the random number 123 based on the SHA-256 algorithm to obtain the first hash value, and then encrypt the first hash value with the authentication private key AK-s to obtain the trusted measurement hash value.
[0299] S316. The Trusted Control Unit sends trusted measurement information, trusted measurement hash value, and self-signed certificate encryption result to the host through the service component.
[0300] The security component can send trusted measurement information and trusted measurement hash values to the service component.
[0301] After receiving the trusted measurement information and trusted measurement hash value, the service component can send the trusted measurement information, trusted measurement hash value, and self-signed certificate encryption result to the host.
[0302] S317. The host decrypts the encryption result of the self-signed certificate based on the certificate's public key to obtain the self-signed certificate.
[0303] Optionally, the certificate server may send a certificate key pair (CA) to the host, which includes a public key (CA-p) and a private key (CA-s).
[0304] The host can decrypt the self-signed certificate encryption result (AKCert) CA-s based on the certificate public key CA-p to obtain the self-signed certificate AKCert.
[0305] S318. The host decrypts the trusted measurement hash value based on the authentication public key in the self-signed certificate to obtain the first hash value.
[0306] Since the self-signed certificate includes the authentication public key AK-p, the host can determine the authentication public key AK-p in the self-signed certificate and decrypt the trusted measurement hash value (n, Measurements) AK-s based on the authentication public key AK-p to obtain the first hash value.
[0307] S319. The host performs a hash operation on the random number and the trust measurement information to obtain the fourth hash value.
[0308] Because the self-signed certificate includes an identifier for the hash algorithm, the host can determine the indicated hash algorithm in the self-signed certificate and perform a hash operation on the random number and trust metric information based on that hash algorithm to obtain a fourth hash value.
[0309] For example, if the self-signed certificate includes the hash algorithm identifier SHA-256, the random number 123, and the trust measurement information as shown in the example above, then the host can perform a hash operation on the random number 123 and the trust measurement information based on the SHA-256 algorithm to obtain the fourth hash value.
[0310] S320. If the first hash value and the fourth hash value are the same, the host determines that the trusted control unit has been successfully authenticated.
[0311] The host can verify whether the first hash value and the fourth hash value are consistent. If they are consistent, it means that the authentication information sent by the trusted control unit (i.e., the trusted measurement information, the trusted measurement hash value, and the encryption result of the self-signed certificate) has not been tampered with, and the host can determine that the authentication of the trusted control unit is successful; if they are inconsistent, it means that the authentication information sent by the trusted control unit may have been tampered with, and the host fails to authenticate the trusted control unit.
[0312] Optionally, after the host confirms that the trusted control unit has been successfully authenticated, it can also store trusted measurement information for later use or comparison. For example, the host can periodically read the stored trusted measurement information and compare it with the system's current trusted measurement information to determine whether the system has been tampered with or compromised by malware.
[0313] In this embodiment, the host can send an authentication request to the trusted control unit. In response to the authentication request, the trusted control unit can send a trusted authentication command to the security component via a service component, and in response to the trusted authentication command sent by the service component, generate an authentication key pair via the security component. The service component can send a security verification command to the security component, and in response to the security verification command sent by the service component, generate a self-signed certificate based on the authentication key pair via the security component. The trusted control unit can send the self-signed certificate and an endorsement certificate to the certificate server. The certificate server can verify the self-signed certificate, obtain a self-signed certificate verification result, and after the self-signed certificate verification result indicates successful verification, generate a first session key. Then, based on the endorsement public key, it can encrypt the first session key and the authentication public key in the self-signed certificate to obtain a key encryption result. The certificate server can send the key encryption result to the trusted control unit. The trusted control unit can decrypt the key encryption result based on the endorsement private key via the security component to obtain a second session key, and send the second session key to the certificate server. If the first session key and the second session key match, the certificate server can encrypt the self-signed certificate based on the certificate's private key, obtain the encrypted self-signed certificate result, and send the encrypted self-signed certificate result to the trusted control unit. After the certificate server authenticates the trusted control unit, the trusted control unit can respond to the authentication request, determine the trusted measurement information through the security component, generate a trusted measurement hash value, and then send the trusted measurement information, the trusted measurement hash value, and the encrypted self-signed certificate result to the host through the service component. The host can decrypt the encrypted self-signed certificate result based on the certificate's public key to obtain the self-signed certificate. The host can decrypt the trusted measurement hash value based on the authentication public key in the self-signed certificate to obtain the first hash value, and perform a hash operation on the random number and the trusted measurement information to obtain the fourth hash value. If the first hash value and the fourth hash value match, the host determines that the trusted control unit has been successfully authenticated. In practice, since the host trusts the certificate server, the trusted control unit (TCU) generates a self-signed certificate and first sends it along with an endorsement certificate to the certificate server. This allows the certificate server to perform initial security authentication on the TCU, thus establishing its security. After the certificate server successfully authenticates the TCU, it then sends authentication information to the host for further authentication. This prevents the TCU from sending information to the host under insecure conditions and further validates its security through the host's verification. This dual authentication process enhances the security of the TCU's access to data on the host.
[0314] In real-world work scenarios, users can log in to the Trusted Control Unit. To improve the security of the Trusted Control Unit, it's also necessary to enhance the security of the user authentication process during login. Below, we will discuss this in conjunction with... Figure 4 This provides another secure authentication method.
[0315] Figure 4 This is a flowchart illustrating yet another security authentication method provided for an exemplary embodiment of this application. Please refer to... Figure 4 The method may include:
[0316] S401. The target server responds to the login request to determine the user's certificate.
[0317] The target server can provide a login interface. Users can log in through this interface, which will then prompt the target server to generate a login request.
[0318] Optionally, the user certificate can be determined in response to a login request in the following manner: in response to the login request, obtain the user's biometric information; determine the user's private key corresponding to the biometric information based on the mapping relationship between the biometric information and the private key; determine the user's public key in the user key pair based on the user's private key; and determine the user certificate based on the user's public key.
[0319] The target server may include authentication tools. These tools can respond to login requests by displaying a prompt for biometric information collection. Users can then enter their biometric information according to the prompts, allowing the target server to obtain this information.
[0320] Alternatively, the biometric information can be any of the following: fingerprints, palm prints, facial features, irises, etc.
[0321] The target server may include private key mapping relationships, user key pairs, and user certificates.
[0322] The private key mapping relationship can include biometric information and the user's private key corresponding to the biometric information.
[0323] User key pairs are generated based on the user's biometric information. A user key pair may include a user's public key and a user's private key.
[0324] The private key mapping relationship and user key pair can be generated by the target server during the user registration process and stored on the target server.
[0325] A user certificate may include the user's public key and user certificate information. The user certificate may be requested by the target server from a certificate server during the user registration process and stored on the target server. User certificate information may include any of the following: user information, certificate validity period, certificate serial number, certificate scope of application, and purpose of certificate use.
[0326] For example, if the biometric information is a fingerprint, and user A enters their fingerprint according to the biometric information collection prompt, the target server can use an authentication tool to determine the user's private key As corresponding to user A's fingerprint in the private key mapping relationship. Then, based on the user's private key As, the target server can determine the user's key pair, including the user's private key As. The target server can then determine the user's public key Ap from the user key pair, and further determine the user certificate A-Cert based on the user's public key Ap.
[0327] S402, The target server sends the user certificate to the trusted control unit.
[0328] The trusted control unit may include a security component and a service component. The target server can send a user certificate to the service component, and the service component can forward the user certificate to the security component.
[0329] S403. The trusted control unit verifies the user certificate and obtains the certificate verification result.
[0330] The trusted control unit can verify the validity of user certificates through security components and obtain the certificate verification result.
[0331] Optionally, at least one verification item for verifying the validity of a user certificate may include at least one of the following: certificate validity period, digital signature in the user certificate, certificate chain, certificate revocation status, certificate subject information, etc.
[0332] If at least one verification item passes the verification, the user certificate is considered valid. If any verification item fails the verification, the user certificate is considered invalid.
[0333] S404. When the certificate verification result indicates that the user certificate is valid, the trusted control unit sends the first challenge data to the target server.
[0334] When the certificate verification result shows that the user certificate is valid, the trusted control unit can randomly generate the first challenge data through the security component.
[0335] The trusted control unit can send the first challenge data to the service component through the security component. After receiving the first challenge data, the service component can send the first challenge data to the target server.
[0336] Optionally, the trusted control unit can send the certificate verification result to the service component through the security component, so that the service component can determine the certificate verification result.
[0337] Optionally, the trusted control unit can also send service information to the target server. The service information may include at least one of the following: the key algorithms supported by the trusted control unit, the supported hash algorithms, the supported network protocols, the network connection status, the network address of the trusted control unit, and its operating status.
[0338] S405. The target server signs the first challenge data based on the user key pair to obtain the first challenge response.
[0339] After receiving the first challenge data, the target server can use an authentication tool to encrypt the first challenge data based on the user's private key in the user key pair to obtain the target challenge signature, and then package the target challenge signature and the user certificate as the first challenge response. The first challenge response may include the target challenge signature and the user certificate.
[0340] S406. The target server sends the first challenge response to the trusted control unit.
[0341] The target server can send a first challenge response to the service component in the trusted control unit, and the service component can forward the first challenge response to the security component.
[0342] S407. The trusted control unit determines the first challenge verification result corresponding to the first challenge response.
[0343] Since the first challenge response includes the target challenge signature and the user certificate, and the user certificate includes the user's public key and user certificate information, the trusted control unit can determine the user's public key from the user certificate through the security component, and decrypt the target challenge signature based on the user's public key to obtain the third challenge data.
[0344] Since the first challenge data is initially randomly generated by the security component, after receiving the third challenge data, the security component can verify whether the first challenge data and the third challenge data are consistent. If they are consistent, the first challenge verification result is determined to be successful; if they are inconsistent, the first challenge verification result is determined to be unsuccessful.
[0345] S408, the trusted control unit sends the first challenge verification result to the target server.
[0346] After the security component in the trusted control unit determines the first challenge verification result, it can send the first challenge verification result to the service component, and then the service component can send the first challenge verification result to the target server.
[0347] S409. When the first challenge verification result indicates that the verification is successful, determine that the trusted control unit allows the login request to pass.
[0348] The result of the first challenge verification can be used to indicate whether the trusted control unit allows the login request to pass.
[0349] If the first challenge verification result is successful, the target server can determine that the trusted control unit allows the login request to pass, meaning the user successfully logs into the trusted control unit through the target server; if the first challenge verification result is unsuccessful, the target server can determine that the trusted control unit does not allow the login request to pass, meaning the user fails to log into the trusted control unit through the target server.
[0350] Optionally, after a user successfully logs into the trusted control unit through the target server, the host can perform security authentication on the trusted control unit so that the trusted control unit can access the data in the host.
[0351] It should be noted that the method for the host to perform security authentication of the trusted control unit can be found in [reference needed]. Figure 2 or Figure 3 Examples are not described in detail here.
[0352] In this embodiment, the target server can determine the user certificate in response to a login request and send the user certificate to the trusted control unit. The trusted control unit can verify the user certificate, obtain a certificate verification result, and send first challenge data to the target server when the certificate verification result indicates that the user certificate is valid. The target server can sign the first challenge data based on the user key pair to obtain a first challenge response and send the first challenge response to the trusted control unit. The trusted control unit can determine the first challenge verification result corresponding to the first challenge response and send the first challenge verification result to the target server. When the first challenge verification result indicates that the verification is successful, the target server can determine that the trusted control unit allows the login request to proceed. Because biometric information is used for login to the trusted control unit via the target server, the security of user authentication during the login process is improved compared to using a static digital password. Furthermore, the trusted control unit and the target server can verify each other based on user certificates and user key pairs, further enhancing the security of user authentication during the login process. This comprehensive improvement in the security of the trusted control unit, and consequently, the security of its access to data on the host, is also enhanced. In addition, in the technical solution of this application embodiment, users can log in using biometric information, eliminating the need for them to remember digital passwords, thus improving user experience, reducing the risk of password cracking, increasing password security, and improving the efficiency of user login to the trusted control unit.
[0353] In real-world scenarios, users need to register within the Trusted Control Unit before logging into the target server. Below, we will discuss this further. Figure 5 The process of user registration of trusted control units is explained.
[0354] Figure 5 This is a flowchart illustrating a registration method for a trusted control unit provided as an exemplary embodiment of this application. Please refer to... Figure 5 The method may include:
[0355] S501, The target server sends an initial registration request to the trusted control unit.
[0356] An initial registration request can be used by a user to request the registration of a trusted control unit through a target server.
[0357] The initial registration request may include user information. User information may include at least one of the following: user role, user account, etc.
[0358] For example, the user information in the initial registration request may include the user role as an operations and maintenance personnel and the user account as A001.
[0359] S502. In response to the initial registration request, the Trusted Control Unit generates a challenge request.
[0360] Since the trusted control unit may include security components and service components, a challenge request may optionally be generated in response to an initial registration request in the following ways: a target registration request is generated by the service component in response to the initial registration request; a challenge request is generated by the security component in response to the target registration request.
[0361] The trusted control unit can determine user information in the initial registration request through service components, generate a user identifier based on the user information, and then generate a target registration request based on the user identifier.
[0362] The target registration request may include a user identifier. A target registration request can be used to request a security component to register a user identifier.
[0363] For example, if the user information includes the user role as an operations and maintenance personnel and the user account as A001, the service component can generate a user identifier OpA001 based on this user information, and then generate a target registration request based on this user identifier OpA001. The target registration request may include the user identifier OpA001.
[0364] After the service component generates a target registration request, it can send the target registration request to the security component. The security component can then respond to the target registration request by generating a challenge request.
[0365] The challenge request may include second challenge data. This second challenge data may be randomly generated by the security component.
[0366] Optionally, the challenge request may also include service information. Service information may include at least one of the following: the key algorithms supported by the trusted control unit, the supported hash algorithms, the supported network protocols, the network connection status, the network address of the trusted control unit, and its operational status.
[0367] For example, a challenge request may include second challenge data 35 and service information.
[0368] S503, the trusted control unit sends a challenge request to the target server.
[0369] The security component in the trusted control unit can send challenge requests to the service component, which in turn can send challenge requests to the target server.
[0370] S504. The target server generates a second challenge response corresponding to the challenge request based on the user key pair.
[0371] Optionally, the second challenge response corresponding to the challenge request can be generated using the following method: in response to the challenge request, collect the user's biometric information; generate a user public key and a user private key based on the biometric information; apply for a user certificate from the certificate server based on the user public key and user information; encrypt the second challenge data in the challenge request based on the user private key to obtain a challenge signature; and generate a second challenge response based on the challenge signature and the user certificate.
[0372] The target server may include authentication tools. These tools can respond to challenge requests by displaying prompts for biometric information collection. Users can then enter their biometric information according to these prompts, allowing the target server to obtain that information.
[0373] The target server can use authentication tools to generate user key pairs based on biometric information. The user key pair can include the user's public key Ap and private key As.
[0374] The target server can use an authentication tool to request a user certificate from a certificate server based on the user's public key (AP) and user information. The user certificate can include the user's public key and user certificate information.
[0375] Since the challenge request includes second challenge data, the second target server can use an authentication tool to encrypt the second challenge data based on the user's private key to obtain a challenge signature, and then package the challenge signature and the user certificate as the second challenge response. The second challenge response can include the challenge signature and the user certificate.
[0376] Optionally, after generating a user key pair based on biometric information, the target server can also establish a private key mapping relationship between the biometric information and the user's private key through an authentication tool. The private key mapping relationship can include both biometric information and the user's private key.
[0377] S505, The target server sends a second challenge response to the trusted control unit.
[0378] The target server can send a second challenge response to the service component in the trusted control unit, and the service component can forward the second challenge response to the security component.
[0379] S506, The trusted control unit determines the second challenge verification result corresponding to the second challenge response.
[0380] Since the second challenge response includes a challenge signature and a user certificate, and the user certificate includes the user's public key and user certificate information, the trusted control unit can determine the user's public key from the user certificate through the security component, and decrypt the challenge signature based on the user's public key to obtain the fourth challenge data.
[0381] Since the second challenge data is initially randomly generated by the security component, after receiving the fourth challenge data, the security component can verify whether the second and fourth challenge data are consistent. If they are consistent, the second challenge verification result is determined to be successful; if they are inconsistent, the second challenge verification result is determined to be unsuccessful.
[0382] Optionally, after successfully verifying the second challenge response, the trusted control unit can also establish a public key mapping relationship between the user identifier and the user's public key. The public key mapping relationship may include the user identifier and the user's public key.
[0383] S507, The Trusted Control Unit sends the second challenge verification result to the target server.
[0384] After the security component in the trusted control unit determines the second challenge verification result, it can send the second challenge verification result to the service component, which in turn can send the second challenge verification result to the target server.
[0385] S508. When the second challenge verification result indicates that the verification is successful, the target server determines that the user has successfully registered the trusted control unit.
[0386] The second challenge verification result can be used to indicate whether the user has successfully registered the trusted control unit.
[0387] If the second challenge verification result is successful, the target server can determine that the user has successfully registered the trusted control unit; if the second challenge verification result is unsuccessful, the target server can determine that the user's registration of the trusted control unit has failed.
[0388] In this embodiment, the target server can send an initial registration request to the trusted control unit. The trusted control unit can generate a challenge request in response to the initial registration request and send the challenge request to the target server. The target server can generate a second challenge response corresponding to the challenge request based on the user key pair and send the second challenge response to the trusted control unit. The trusted control unit can determine the second challenge verification result and send the second challenge verification result to the target server. When the second challenge verification result indicates that the verification is successful, the target server can determine that the user has successfully registered with the trusted control unit. Because biometric information is used for registration during the user's registration of the trusted control unit through the target server, the security of the trusted control unit's authentication of the user is improved compared to registration using a static digital password. Furthermore, the target server can generate a user key pair based on the user's biometric information and then apply for a user certificate. The trusted control unit and the target server can then perform secure authentication based on the user key pair and the user certificate, further enhancing the security of the trusted control unit's authentication of the user during registration. This comprehensive improvement in the security of the trusted control unit, and consequently, the security of the trusted control unit's access to data in the host, is also enhanced. In addition, in the technical solution of this application embodiment, users can register using biometric information, eliminating the need for users to remember digital passwords, reducing the risk of password cracking, improving password security, and facilitating user login to the trusted control unit, thus improving the efficiency of user login to the trusted control unit.
[0389] It should be noted that, in any of the above embodiments, the various processing steps shown in the embodiments do not constitute a specific limitation on the process of the embodiments. In other embodiments of this application, the process of the embodiments may include more or fewer steps than in the corresponding embodiments. For example, with Figure 3 For example, in the implementation of this embodiment, the security authentication process may include Figure 3 Some steps in the embodiments, or, Figure 3 Some steps in the embodiments can be replaced by steps with the same function, or Figure 3 Some steps in the embodiments can be broken down into multiple steps, etc.
[0390] Figure 6 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 1 Please see. Figure 6The security authentication device is applied to a trusted control unit. The security authentication device 60 includes: a first generation module 61 and a first sending module 62, wherein...
[0391] The first generation module 61 is used to generate a self-signed certificate in response to an authentication request sent by the host;
[0392] The first sending module 62 is used to send the self-signed certificate and the endorsement certificate to the certificate server, wherein the self-signed certificate and the endorsement certificate are used by the certificate server to perform security authentication on the trusted control unit;
[0393] The first sending module 62 is configured to, after the certificate server has authenticated the trusted control unit, send authentication information to the host in response to the authentication request, so that the host can perform security authentication on the trusted control unit and access the data in the host after the security authentication is successful.
[0394] The security authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0395] Figure 7 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 2 Please see. Figure 7 ,exist Figure 6 Based on the illustrated embodiment, the security authentication device 60 further includes: a first receiving module 63 and a processing module 64, wherein,
[0396] The first receiving module 63 is configured to receive a key encryption result sent by the certificate server, wherein the key encryption result is obtained by the certificate server encrypting a first session key and an authentication public key based on the endorsement public key after the self-signed certificate has been verified; the first session key is generated by the certificate server after the self-signed certificate has been verified.
[0397] The processing module 64 is used to decrypt the key encryption result based on the endorsement private key to obtain the second session key;
[0398] The first sending module 62 is further configured to send the second session key to the certificate server, so that after the certificate server verifies that the first session key and the second session key are consistent, it generates a self-signed certificate encryption result, the self-signed certificate encryption result being used to indicate that the certificate server has successfully authenticated the trusted control unit;
[0399] The first receiving module 63 is further configured to receive the encryption result of the self-signed certificate sent by the certificate server.
[0400] In one possible implementation, the trusted control unit includes a security component and a service component; the first generation module 61 is specifically used for:
[0401] The service component responds to the authentication request by sending a trusted authentication command to the security component;
[0402] The security component responds to the trusted authentication command sent by the service component and generates an authentication key pair, which includes an authentication private key and an authentication public key.
[0403] In response to the security verification command sent by the service component, the security component generates the self-signed certificate based on the authentication key pair. The self-signed certificate includes the authentication public key and the digital signature corresponding to the authentication private key.
[0404] In one possible implementation, the authentication information includes trusted measurement information, a trusted measurement hash value, and a self-signed certificate encryption result, wherein the self-signed certificate encryption result is sent by the certificate server to the trusted control unit after successful authentication; the first sending module 62 is specifically used for:
[0405] In response to the authentication request, the security component determines the trust measurement information and generates the trust measurement hash value;
[0406] The service component sends the trusted measurement information, the trusted measurement hash value, and the self-signed certificate encryption result to the host, so that the host can decrypt the self-signed certificate encryption result based on the certificate public key to obtain the self-signed certificate, and perform security authentication on the trusted control unit based on the authentication public key in the self-signed certificate, the trusted measurement information, and the trusted measurement hash value.
[0407] In one possible implementation, the first sending module 62 is specifically used for:
[0408] In response to the authentication request, the security component performs a hash operation on the random number and the trust measurement information based on the hash algorithm to obtain a first hash value;
[0409] The first hash value is encrypted using the authentication private key to obtain the trust metric hash value.
[0410] In one possible implementation, the security authentication device 60 further includes a verification module 65.
[0411] The verification module 65 is used to verify the user certificate sent by the target server and obtain the certificate verification result. The user certificate is determined by the target server in response to the login request. The login request is used to request login to the trusted control unit.
[0412] The first sending module 62 is further configured to send first challenge data to the target server when the certificate verification result indicates that the user certificate is valid;
[0413] The first receiving module 63 is further configured to receive a first challenge response corresponding to the first challenge data sent by the target server, wherein the first challenge response is obtained by the target server signing the first challenge data based on a user key pair, and the user key pair is generated based on the user's biometric information.
[0414] The verification module 65 is further configured to determine the first challenge verification result corresponding to the first challenge response, and send the first challenge verification result to the target server. The first challenge verification result is used to indicate whether the trusted control unit allows the login request to pass.
[0415] In one possible implementation,
[0416] The first generation module 61 is further configured to, in response to an initial registration request sent by the target server, generate a challenge request and send the challenge request to the target server, wherein the initial registration request includes user information;
[0417] The first receiving module 63 is further configured to receive a second challenge response corresponding to the challenge request, wherein the second challenge response is generated by the target server based on the user key pair;
[0418] The verification module 65 is further configured to determine the second challenge verification result corresponding to the second challenge response, and send the second challenge verification result to the target server. The second challenge verification result is used to indicate whether the user has successfully registered the trusted control unit.
[0419] In one possible implementation, the trusted control unit includes a security component and a service component; the first generation module 61 is specifically used for:
[0420] In response to the initial registration request, a target registration request is generated through the service component, the target registration request including a user identifier generated based on the user information;
[0421] The security component generates the challenge request in response to the target registration request.
[0422] In one possible implementation, the user key pair includes a user public key; the security authentication device 60 further includes: a first establishment module 66, the first establishment module 66 being used for:
[0423] After successfully verifying the second challenge response, a public key mapping relationship between the user identifier and the user public key is established through the security component.
[0424] In one possible implementation, the trusted control unit is any one of the following: a baseboard management controller, a discrete trusted platform module, or a firmware trusted platform module.
[0425] The security authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0426] Figure 8 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 3 Please see. Figure 8 The security authentication device 80 is applied to a certificate server. The security authentication device 80 includes a second receiving module 81 and a first authentication module 82, wherein...
[0427] The second receiving module 81 is used to receive a self-signed certificate and an endorsement certificate sent by the trusted control unit, wherein the self-signed certificate is generated by the trusted control unit in response to an authentication request sent by the host;
[0428] The first authentication module 82 is used to perform security authentication on the trusted control unit based on the self-signed certificate and the endorsement certificate, so that after the authentication is successful, the trusted control unit sends authentication information to the host and requests the host to perform security authentication.
[0429] The security authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0430] In one possible implementation, the first authentication module 82 is specifically used for:
[0431] The self-signed certificate is verified to obtain the self-signed certificate verification result;
[0432] After the self-signed certificate verification result indicates that the verification is successful, a first session key is generated;
[0433] The trusted control unit is securely authenticated based on the first session key, the self-signed certificate, and the endorsement certificate.
[0434] In one possible implementation, the endorsement certificate includes an endorsement public key and an endorsement private key; the first authentication module 82 is specifically used for:
[0435] Based on the endorsement public key, the first session key and the authentication public key in the self-signed certificate are encrypted to obtain a key encryption result, and the key encryption result is sent to the trusted control unit.
[0436] The system receives a second session key sent by the trusted control unit. The second session key is obtained by the trusted control unit decrypting the key encryption result based on the endorsement private key.
[0437] If the first session key and the second session key are the same, the self-signed certificate is encrypted based on the certificate private key to obtain the self-signed certificate encryption result. The self-signed certificate encryption result is used to indicate that the certificate server has successfully authenticated the trusted control unit.
[0438] The self-signed certificate encryption result is sent to the trusted control unit.
[0439] In one possible implementation, the self-signed certificate includes an authentication public key, a digital signature corresponding to the authentication private key, and certificate information, wherein the digital signature is generated based on the authentication private key; the first authentication module 82 is specifically used for:
[0440] The digital signature is decrypted using the authentication public key to obtain the second hash value;
[0441] The certificate information is hashed using the hash algorithm in the self-signed certificate to obtain a third hash value;
[0442] If the second hash value matches the third hash value, then the self-signed certificate verification result is determined to be successful.
[0443] If the second hash value is inconsistent with the third hash value, then the self-signed certificate verification result is determined to be verification failure.
[0444] The security authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0445] Figure 9 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 4 Please see. Figure 9 The security authentication device 90 is applied to the host computer and includes: a second sending module 91, a third receiving module 92, and a second authentication module 93.
[0446] The second sending module 91 is used to send an authentication request to the trusted control unit;
[0447] The third receiving module 92 is used to receive authentication information sent by the trusted control unit in response to the authentication request, wherein the authentication information is determined by the certificate server after the trusted control unit has been authenticated.
[0448] The second authentication module 93 is used to perform security authentication on the trusted control unit based on the authentication information, so that the trusted control unit can access the data in the host after the security authentication is passed.
[0449] The security authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0450] In one possible implementation, the authentication information includes trust measurement information, a trust measurement hash value, and a self-signed certificate encryption result; the authentication request includes a random number; the second authentication module 93 is specifically used for:
[0451] Based on the certificate public key, the encryption result of the self-signed certificate is decrypted to obtain the self-signed certificate;
[0452] Based on the authentication public key in the self-signed certificate, the trust metric hash value is decrypted to obtain the first hash value;
[0453] A hash operation is performed on the random number and the trust measurement information to obtain a fourth hash value;
[0454] If the first hash value and the fourth hash value are consistent, then the authentication of the trusted control unit is confirmed to be successful.
[0455] The security authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0456] Figure 10 A schematic diagram of the structure of a security authentication device provided for an exemplary embodiment of this application. Figure 5 Please see. Figure 10 The security authentication device 1000 is applied to the target server. The security authentication device 1000 includes: a determining module 1001, a third sending module 1002, a fourth receiving module 1003, and a signature module 1004.
[0457] The determining module 1001 is used to determine the user certificate in response to a login request;
[0458] The third sending module 1002 is used to send the user certificate to the trusted control unit;
[0459] The fourth receiving module 1003 is used to receive the first challenge data sent by the trusted control unit when the certificate verification result indicates that the user certificate is valid.
[0460] The signature module 1004 is used to sign the first challenge data based on the user key pair to obtain a first challenge response;
[0461] The third sending module 1002 is used to send the first challenge response to the trusted control unit, wherein the user key pair is generated based on the user's biometric information;
[0462] The fourth receiving module 1003 is used to receive the first challenge verification result corresponding to the first challenge response sent by the trusted control unit;
[0463] The determining module 1001 is further configured to, when the first challenge verification result indicates that the verification is passed, determine that the user has successfully logged into the trusted control unit, so that after logging into the trusted control unit, the user can perform security authentication of the trusted control unit through the certificate server and the host, and access data in the host through the trusted control unit.
[0464] The security authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0465] In one possible implementation, the target server includes a private key mapping relationship, which includes the biometric information and the user's private key corresponding to the biometric information; the determining module 1001 is specifically used for:
[0466] In response to the login request, the user's biometric information is obtained;
[0467] Based on the mapping relationship between the biometric information and the private key, the user's private key corresponding to the biometric information is determined;
[0468] Based on the user's private key, determine the user's public key from the user key pair;
[0469] The user certificate is determined based on the user's public key.
[0470] In one possible implementation, the security authentication device 1000 further includes: a second generation module 1005, wherein,
[0471] The third sending module 1002 is further configured to send an initial registration request to the trusted control unit, wherein the initial registration request includes the user's user information.
[0472] The fourth receiving module 1003 is further configured to receive a challenge request sent by the trusted control unit in response to the initial registration request;
[0473] The second generation module 1005 is used to generate a second challenge response corresponding to the challenge request based on the user key pair;
[0474] The third sending module 1002 is further configured to send the second challenge response to the trusted control unit;
[0475] The fourth receiving module 1003 is further configured to receive the second challenge verification result corresponding to the second challenge response sent by the trusted control unit;
[0476] The determining module 1001 is further configured to determine that the user has successfully registered the trusted control unit when the second challenge verification result indicates that the verification has passed.
[0477] In one possible implementation, the user key pair includes a user public key and a user private key; the second generation module 1005 is specifically used for:
[0478] In response to the query request, the user's biometric information is collected;
[0479] Based on the biometric information, the user's public key and private key are generated;
[0480] Based on the user's public key and the user information, the user applies for a user certificate from the certificate server;
[0481] Based on the user's private key, the second challenge data in the challenge request is encrypted to obtain the challenge signature;
[0482] The second challenge response is generated based on the challenge signature and the user certificate.
[0483] In one possible implementation, after generating the user key pair based on the biometric information, the device further includes: a second establishment module 1006, the second establishment module 1006 being used for:
[0484] Establish a private key mapping relationship between the biometric information and the user's private key.
[0485] The security authentication device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0486] This application provides a trusted control unit, which is used to execute the method described in the above-described method embodiments.
[0487] This application provides a host computer for executing the methods described in the above-described method embodiments.
[0488] Figure 11 This is a schematic diagram of the structure of an electronic device provided for an exemplary embodiment of this application. Please refer to... Figure 11 The electronic device 1100 may include a trusted control unit 1101 and a host 1102.
[0489] In electronic device 1100, trusted control unit 1101 and host 1102 can communicate with each other.
[0490] The trusted control unit 1101 and the host 1102 can execute the methods described in the above-described method embodiments.
[0491] Figure 12 This is a schematic diagram of a server structure provided for an exemplary embodiment of this application. Please refer to... Figure 12 The server 1200 may include a processor 1201 and a memory 1202. Exemplarily, the processor 1201 and the memory 1202 are interconnected via a bus 1203.
[0492] The memory 1202 stores computer-executed instructions;
[0493] The processor 1201 executes the computer execution instructions stored in the memory 1202, causing the processor 1201 to perform the method as shown in the above method embodiment.
[0494] Figure 12 The server shown can be the certificate server or the target server described in any of the above embodiments.
[0495] Accordingly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the above-described method embodiments.
[0496] Accordingly, embodiments of this application may also provide a computer program product, including a computer program, which, when executed by a processor, can implement the methods shown in the above-described method embodiments.
[0497] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0498] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0499] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0500] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0501] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0502] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0503] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0504] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0505] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A security authentication method, characterized in that, Applied to a trusted control unit, the method includes: In response to an authentication request sent by the host, a self-signed certificate is generated; The self-signed certificate and the endorsement certificate are sent to the certificate server, and the self-signed certificate and the endorsement certificate are used by the certificate server to perform security authentication on the trusted control unit; After the certificate server authenticates the trusted control unit, it sends authentication information to the host in response to the authentication request, so that the host can perform security authentication on the trusted control unit and access the data in the host after the security authentication is successful.
2. The method according to claim 1, characterized in that, The endorsement certificate includes an endorsement public key and an endorsement private key; After sending the self-signed certificate and endorsement certificate to the certificate server, the method further includes: The system receives a key encryption result sent by the certificate server. The key encryption result is obtained by the certificate server encrypting a first session key and an authentication public key based on the endorsement public key after verifying the self-signed certificate. The first session key is generated by the certificate server after verifying the self-signed certificate. Based on the endorsed private key, the key encryption result is decrypted to obtain the second session key; The second session key is sent to the certificate server so that the certificate server, after verifying that the first session key and the second session key are consistent, generates a self-signed certificate encryption result, which is used to indicate that the certificate server has successfully authenticated the trusted control unit. Receive the encryption result of the self-signed certificate sent by the certificate server.
3. The method according to claim 1, characterized in that, The trusted control unit includes security components and service components; in response to an authentication request sent by the host, it generates a self-signed certificate, including: The service component responds to the authentication request by sending a trusted authentication command to the security component; The security component responds to the trusted authentication command sent by the service component and generates an authentication key pair, which includes an authentication private key and an authentication public key. In response to the security verification command sent by the service component, the security component generates the self-signed certificate based on the authentication key pair. The self-signed certificate includes the authentication public key and the digital signature corresponding to the authentication private key.
4. The method according to claim 3, characterized in that, The authentication information includes trusted measurement information, trusted measurement hash value, and self-signed certificate encryption result, which is sent by the certificate server to the trusted control unit after successful authentication. In response to the authentication request, authentication information is sent to the host, including: In response to the authentication request, the security component determines the trust measurement information and generates the trust measurement hash value; The service component sends the trusted measurement information, the trusted measurement hash value, and the self-signed certificate encryption result to the host, so that the host can decrypt the self-signed certificate encryption result based on the certificate public key to obtain the self-signed certificate, and perform security authentication on the trusted control unit based on the authentication public key in the self-signed certificate, the trusted measurement information, and the trusted measurement hash value.
5. The method according to claim 4, characterized in that, The authentication request includes identifiers for a random number and a hash algorithm; In response to the authentication request, the trusted metric hash value is generated by the security component, including: In response to the authentication request, the security component performs a hash operation on the random number and the trust measurement information based on the hash algorithm to obtain a first hash value; The first hash value is encrypted using the authentication private key to obtain the trust metric hash value.
6. The method according to claim 1, characterized in that, The method further includes: Verify the user certificate sent by the target server to obtain the certificate verification result. The user certificate is determined by the target server in response to the login request, which is used to request login to the trusted control unit. When the certificate verification result indicates that the user certificate is valid, a first challenge data is sent to the target server; The system receives a first challenge response corresponding to the first challenge data sent by the target server. The first challenge response is obtained by the target server signing the first challenge data based on a user key pair, where the user key pair is generated based on the user's biometric information. The first challenge verification result corresponding to the first challenge response is determined, and the first challenge verification result is sent to the target server. The first challenge verification result is used to indicate whether the trusted control unit allows the login request to pass.
7. The method according to claim 6, characterized in that, The method further includes: In response to an initial registration request sent by the target server, a challenge request is generated and sent to the target server. The initial registration request includes user information. Receive a second challenge response corresponding to the challenge request, wherein the second challenge response is generated by the target server based on the user key pair; The second challenge verification result corresponding to the second challenge response is determined, and the second challenge verification result is sent to the target server. The second challenge verification result is used to indicate whether the user has successfully registered the trusted control unit.
8. The method according to claim 7, characterized in that, The trusted control unit includes security components and service components; In response to the initial registration request sent by the target server, a challenge request is generated, including: In response to the initial registration request, a target registration request is generated through the service component, the target registration request including a user identifier generated based on the user information; The security component generates the challenge request in response to the target registration request.
9. The method according to claim 8, characterized in that, The user key pair includes a user public key; the method further includes: After successfully verifying the second challenge response, a public key mapping relationship between the user identifier and the user public key is established through the security component.
10. The method according to any one of claims 1-9, characterized in that, The trusted control unit is any one of the following: baseboard management controller, discrete trusted platform module, or firmware trusted platform module.
11. A security authentication method, characterized in that, Applied to a certificate server, the method includes: Receive a self-signed certificate and an endorsement certificate sent by a trusted control unit, wherein the self-signed certificate is generated by the trusted control unit in response to an authentication request sent by the host; The trusted control unit performs security authentication based on the self-signed certificate and the endorsement certificate, so that after successful authentication, the trusted control unit sends authentication information to the host, requesting the host to perform security authentication.
12. The method according to claim 11, characterized in that, Security authentication of the trusted control unit based on the self-signed certificate and the endorsement certificate includes: The self-signed certificate is verified to obtain the self-signed certificate verification result; After the self-signed certificate verification result indicates that the verification is successful, a first session key is generated; The trusted control unit is securely authenticated based on the first session key, the self-signed certificate, and the endorsement certificate.
13. The method according to claim 12, characterized in that, The endorsement certificate includes an endorsement public key and an endorsement private key; Based on the first session key, the self-signed certificate, and the endorsement certificate, security authentication is performed on the trusted control unit, including: Based on the endorsement public key, the first session key and the authentication public key in the self-signed certificate are encrypted to obtain a key encryption result, and the key encryption result is sent to the trusted control unit. The system receives a second session key sent by the trusted control unit. The second session key is obtained by the trusted control unit decrypting the key encryption result based on the endorsement private key. If the first session key and the second session key are the same, the self-signed certificate is encrypted based on the certificate private key to obtain the self-signed certificate encryption result. The self-signed certificate encryption result is used to indicate that the certificate server has successfully authenticated the trusted control unit. The self-signed certificate encryption result is sent to the trusted control unit.
14. The method according to claim 12 or 13, characterized in that, The self-signed certificate includes an authentication public key, a digital signature corresponding to the authentication private key, and certificate information, wherein the digital signature is generated based on the authentication private key; The self-signed certificate is verified to obtain a self-signed certificate verification result, including: The digital signature is decrypted using the authentication public key to obtain the second hash value; The certificate information is hashed using the hash algorithm in the self-signed certificate to obtain a third hash value; If the second hash value matches the third hash value, then the self-signed certificate verification result is determined to be successful. If the second hash value is inconsistent with the third hash value, then the self-signed certificate verification result is determined to be verification failure.
15. A security authentication method, characterized in that, Applied to a host, the method includes: Send an authentication request to the trusted control unit; The system receives authentication information sent by the trusted control unit in response to the authentication request, wherein the authentication information is determined by the certificate server after the trusted control unit has been successfully authenticated. The trusted control unit is securely authenticated based on the authentication information, so that the trusted control unit can access the data in the host after the security authentication is successful.
16. The method according to claim 15, characterized in that, The authentication information includes trust measurement information, trust measurement hash value, and self-signed certificate encryption result; The authentication request includes a random number; Based on the authentication information, security authentication is performed on the trusted control unit, including: Based on the certificate public key, the encryption result of the self-signed certificate is decrypted to obtain the self-signed certificate; Based on the authentication public key in the self-signed certificate, the trust metric hash value is decrypted to obtain the first hash value; A hash operation is performed on the random number and the trust measurement information to obtain a fourth hash value; If the first hash value and the fourth hash value are consistent, then the authentication of the trusted control unit is confirmed to be successful.
17. A security authentication method, characterized in that, Applied to a target server, the method includes: In response to a login request, the user certificate is determined and sent to the trusted control unit; Receive the first challenge data sent by the trusted control unit when the certificate verification result indicates that the user certificate is valid; Based on the user key pair, the first challenge data is signed to obtain a first challenge response, and the first challenge response is sent to the trusted control unit. The user key pair is generated based on the user's biometric information. The system receives the first challenge response corresponding to the first challenge verification result sent by the trusted control unit, and determines that the user has successfully logged into the trusted control unit when the first challenge verification result indicates that the verification is successful. After logging into the trusted control unit, the user performs security authentication on the trusted control unit through the certificate server and the host, and accesses data in the host through the trusted control unit.
18. The method according to claim 17, characterized in that, The target server includes a private key mapping relationship, which includes the biometric information and the user's private key corresponding to the biometric information. In response to a login request, the user's certificate is determined, including: In response to the login request, the user's biometric information is obtained; Based on the mapping relationship between the biometric information and the private key, the user's private key corresponding to the biometric information is determined; Based on the user's private key, determine the user's public key from the user key pair; The user certificate is determined based on the user's public key.
19. The method according to claim 17, characterized in that, The method further includes: Send an initial registration request to the trusted control unit, the initial registration request including the user's user information; Receive the challenge request sent by the trusted control unit in response to the initial registration request; A second challenge response corresponding to the challenge request is generated based on the user key pair, and the second challenge response is sent to the trusted control unit. The system receives the second challenge verification result corresponding to the second challenge response sent by the trusted control unit, and determines that the user has successfully registered the trusted control unit when the second challenge verification result indicates that the verification is successful.
20. The method according to claim 19, characterized in that, The user key pair includes a user public key and a user private key; Generate a second challenge response corresponding to the challenge request based on the user key pair, including: In response to the query request, the user's biometric information is collected; Based on the biometric information, the user's public key and private key are generated; Based on the user's public key and the user information, the user applies for a user certificate from the certificate server; Based on the user's private key, the second challenge data in the challenge request is encrypted to obtain the challenge signature; The second challenge response is generated based on the challenge signature and the user certificate.
21. A trusted control unit, characterized in that, The trusted control unit is used to perform the method as described in any one of claims 1-10.
22. A host computer, characterized in that, The host is used to perform the method as described in claim 15 or 16.
23. An electronic device, characterized in that, This includes the trusted control unit as described in claim 21 and the host as described in claim 22.
24. A server, characterized in that, include: At least one processor; as well as A memory that is communicatively connected to the at least one processor; The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, cause the server to perform the method according to any one of claims 11-14 or 17-20.
25. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, implement the method as described in any one of claims 1-20.
26. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-20.