Work implementation method and apparatus for online OTP device

By setting the default storage area and ordinary storage area in the online OTP device and requiring users to verify and operate, the problem of lack of access rights control on the online OTP device is solved, and data security and management convenience are achieved.

WO2025138481A1PCT designated stage expired Publication Date: 2025-07-03FEITIAN TECHNOLOGIES CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/085300
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-28
Filing Date
2024-04-01
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

The lack of access rights control of existing online OTP devices, resulting in illegal users being able to configure and change at will, posing serious security risks.

Method used

The default storage area and ordinary storage area are built in the online OTP device. Each storage area has an independent protection code. Users need to pass the identity authentication before they can operate to ensure data security.

Benefits of technology

Effectively prevent online OTP devices from being maliciously modified, ensure the security of user information and property, and improve the security of device management and use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024085300_03072025_PF_FP_ABST
    Figure CN2024085300_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to the field of information security, and disclosed are a work implementation method and apparatus for an online OTP device. When an application selection instruction is received, an OTP application is selected on the basis of an application identifier, and a storage area configuration and computing participation device data are returned to a superordinate computer; when a protection code setting instruction is received, if the selected OTP application has been set with an access permission, a protection code is stored in a storage area; when a personalized data writing instruction is received, if the selected OTP application has been set with an access permission, the personalized data writing instruction is verified on the basis of the protection code in the storage area, and if the verification succeeds, personalized data is stored in a default storage area or personalized data stored in an ordinary storage area is replaced; and when a personalized data processing instruction is received, if the selected OTP application has been set with an access permission, the personalized data processing instruction is verified on the basis of the protection code in the storage area, and if the verification succeeds, the personalized data in the storage area is correspondingly processed.
Need to check novelty before this filing date? Find Prior Art

Description

A method and device for implementing the operation of an online OTP device

[0001] Cross-references

[0002] This application claims priority to the Chinese patent application with application number 202311825247.2, filed on December 28, 2023, entitled “A method and device for implementing the operation of an online OTP device”, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present disclosure relates to the field of information security, and in particular to a method and apparatus for implementing the operation of an online OTP device. Background Art

[0004] An online OTP device is an electronic device with buttons that needs to be connected to a host computer to work. In the existing technology, online OTP devices do not require any access rights, and anyone can configure, change, and perform other operations on them. If the online OTP device is obtained by an illegal user, the illegal user can configure, change, and perform other operations on the online OTP device, thereby using the online OTP device to perform some illegal operations, which poses a great security risk. Therefore, there is an urgent need to provide a safe and reliable method for implementing the operation of an online OTP device.

[0005] Summary of the Invention

[0006] The purpose of the present invention is to overcome the deficiencies of the prior art and to provide a method and apparatus for implementing the operation of an online OTP device.

[0007] In a first aspect, an embodiment of the present disclosure provides a method for implementing the operation of an online OTP device, wherein the online OTP device has a built-in default storage area and a common storage area, wherein the default storage area can store multiple pieces of personalized data, and the common storage area stores one piece of personalized data, the method comprising:

[0008] Step S1: When the online OTP device receives a command from the host computer, it determines the type of the command. If it is an application selection command, it executes step S2; if it is a protection code setting command, it executes step S3; if it is a personalized data writing command, it executes step S5; if it is a personalized data processing command, it executes step S9;

[0009] Step S2: The online OTP device selects the corresponding OTP application according to the application identifier in the application selection instruction, obtains the set storage area configuration, generates an application selection response according to the storage area configuration and preset participating computing device data, and returns it to the host computer. The storage area configuration includes a storage area identifier and a storage area status code, and then returns to step S1;

[0010] Step S3: The online OTP device determines whether the OTP application has been selected. If yes, it executes step S4; otherwise, it reports an error and returns to step S1;

[0011] Step S4: the online OTP device determines whether the OTP application has set access rights. If so, an error is reported and the process returns to step S1. Otherwise, the protection code in the set protection code instruction is saved in a storage area corresponding to the storage area identifier in the set protection code instruction, a setting success response is returned to the host computer, and the process returns to step S1.

[0012] Step S5: The online OTP device determines whether the OTP application has been selected. If yes, it executes step S6; otherwise, it reports an error and returns to step S1;

[0013] Step S6: The online OTP device determines whether the OTP application has access rights set. If yes, execute step S7; otherwise, report an error and return to step S1;

[0014] Step S7: The online OTP device obtains the protection code in the corresponding storage area based on the storage area identifier in the instruction to write personalized data, calculates fourth comparison data based on the fourth random number in the instruction to write personalized data and the protection code, and determines whether the fourth comparison data is consistent with the fourth intermediate data in the instruction to write personalized data. If so, step S8 is executed; otherwise, an error is reported and the process returns to step S1.

[0015] Step S8: The online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier. If so, the personalized data in the write personalized data instruction is stored in the default storage area, a write success response is returned to the host computer, and the process returns to step S1. Otherwise, the personalized data in the write personalized data instruction is used to update the personalized data stored in the storage area corresponding to the storage area identifier, a write success response is returned to the host computer, and the process returns to step S1.

[0016] Step S9: The online OTP device determines whether the OTP application has been selected. If yes, step S10 is executed. Otherwise, an error message is reported and the process returns to step S1.

[0017] Step S10: The online OTP device determines whether the OTP application has access rights set. If yes, step S11 is executed. Otherwise, an error is reported and the process returns to step S1.

[0018] Step S11: The online OTP device obtains a protection code from a corresponding storage area based on the storage area identifier in the personalized data processing instruction, calculates first comparison data based on the first random number in the personalized data processing instruction and the protection code, and determines whether the first intermediate data in the personalized data processing instruction is consistent with the first comparison data. If so, step S12 is executed; otherwise, an error is reported and the process returns to step S1.

[0019] Step S12: the online OTP device processes the personalized data stored in the storage area corresponding to the storage area identifier according to the personalized data processing instruction, and returns the processing result to the host computer, and returns to step S1.

[0020] In a second aspect, an embodiment of the present disclosure provides a device for implementing the operation of an online OTP device, wherein the online OTP device has a built-in default storage area and a common storage area, wherein the default storage area can store multiple pieces of personalized data, and the common storage area stores one piece of personalized data, and the device includes:

[0021] a receiving and judging module, configured to receive instructions issued by the host computer, and upon receiving an instruction, to judge the type of the instruction. If the instruction is an application selection instruction, the calculation and return selection module is triggered; if the instruction is a protection code setting instruction, the first judging module is triggered; if the instruction is a personalized data writing instruction, the second judging module is triggered; and if the instruction is a personalized data processing instruction, the fourth judging module is triggered;

[0022] The selection calculation return module is used to select the corresponding OTP application according to the application identifier in the selection application instruction, obtain the set storage area configuration, generate the selected application response according to the storage area configuration and the preset participating computing device data, and return it to the host computer. The storage area configuration includes a storage area identifier and a storage area status code, and trigger the reception judgment module;

[0023] The first judgment module is used to judge whether the OTP application has been selected, and if so, trigger the judgment setting return module; otherwise, an error is reported and the receiving judgment module is triggered;

[0024] The determination setting return module is used to determine whether the OTP application has set access rights, and if so, report an error and trigger the receiving and judging module; otherwise, save the protection code in the setting protection code instruction in a storage area corresponding to the storage area identifier in the setting protection code instruction, return a setting success response to the host computer, and trigger the receiving and judging module;

[0025] The second judgment module is used to judge whether the OTP application has been selected, and if so, trigger the third judgment module; otherwise, an error is reported and the receiving judgment module is triggered;

[0026] The third judgment module is used to judge whether the OTP application has set access rights, and if so, trigger the first acquisition and calculation judgment module; otherwise, an error is reported and the reception judgment module is triggered;

[0027] The first acquisition, calculation and judgment module is configured to obtain a protection code in a corresponding storage area based on a storage area identifier in the personalized data writing instruction, calculate fourth comparison data based on a fourth random number in the personalized data writing instruction and the protection code, and determine whether the fourth comparison data is consistent with the fourth intermediate data in the personalized data writing instruction. If so, triggering the judgment and writing module; otherwise, reporting an error and triggering the receiving and judgment module;

[0028] The judgment writing module is configured to judge whether the corresponding storage area is a default storage area based on the storage area identifier; if so, store the personalized data in the write personalized data instruction in the default storage area, return a write success response to the host computer, and return to step S1; otherwise, update the personalized data stored in the storage area corresponding to the storage area identifier with the personalized data in the write personalized data instruction, return a write success response to the host computer, and trigger the receiving judgment module;

[0029] The fourth judgment module is used to determine whether the OTP application has been selected, and if so, trigger the fifth judgment module; otherwise, an error is reported and the receiving judgment module is triggered;

[0030] The fifth judgment module is used to judge whether the OTP application has set access rights, and if so, trigger the second acquisition and calculation judgment module; otherwise, an error is reported and the reception judgment module is triggered;

[0031] the second acquisition, calculation and judgment module is configured to obtain a protection code in a corresponding storage area according to the storage area identifier in the personalized data processing instruction, calculate first comparison data according to a first random number in the personalized data processing instruction and the protection code, and determine whether the first intermediate data in the personalized data processing instruction is consistent with the first comparison data. If so, triggering the processing return module; otherwise, reporting an error and triggering the receiving and judgment module;

[0032] The processing and returning module is configured to process the personalized data stored in the storage area corresponding to the storage area identifier according to the personalized data processing instruction, and return the processing result to the host computer to trigger the receiving and judging module.

[0033] In a third aspect, an embodiment of the present disclosure further provides an electronic device, which includes at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, and the at least one processor executes the instructions to implement the above-mentioned working implementation method of the online OTP device.

[0034] In a fourth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which includes a computer program. When the computer program runs on an electronic device, the electronic device executes the above-mentioned working implementation method of the online OTP device.

[0035] In a fifth aspect, an embodiment of the present disclosure further provides a chip system, comprising a chip, wherein the chip is coupled to a memory and is used to execute a computer program stored in the memory to execute the above-mentioned working implementation method of the online OTP device.

[0036] Compared with the prior art, the present invention has the following advantages: the online OTP device in the technical solution of the present invention has a built-in default storage area and a general storage area, each storage area is set with its own protection code, the default storage area can store multiple personalized data, and the general storage area stores one personalized data. Each storage area is independent of each other and does not affect each other, which is convenient for management and use; when using the online OTP device, the user must first use the protection code for identity authentication, which can effectively ensure that the data in the storage area (including personalized data and protection code) is not maliciously modified, and ensure the security of user information and property in situations such as the loss of the online OTP device. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] FIG1 is a flow chart of a method for implementing an online OTP device according to a first embodiment of the present disclosure;

[0038] FIG2 and FIG3 are flow charts of a method for implementing an online OTP device according to a second embodiment of the present disclosure;

[0039] FIG4 and FIG5 are flow charts of a method for implementing the operation of an online OTP device provided in the third embodiment of the present disclosure. DETAILED DESCRIPTION

[0040] This application proposes a method and apparatus for implementing an online OTP device. The following describes specific implementations of this application in detail with reference to the accompanying drawings. Examples of the embodiments are shown in the accompanying drawings. The embodiments described below with reference to the accompanying drawings are illustrative and intended only to explain this application, and are not to be construed as limiting this application.

[0041] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. It should also be understood that terms such as those defined in common dictionaries should be understood to have meanings consistent with their meanings in the context of the prior art and will not be interpreted in an idealized or overly formal sense unless specifically defined as herein.

[0042] In order to make the objectives, technical solutions and advantages of the present disclosure more clear, the embodiments of the present disclosure are further described in detail below with reference to the accompanying drawings.

[0043] The online OTP device in this embodiment has a built-in default storage area and a common storage area. One or more common storage areas can be set. In this embodiment, two are taken as an example. The default storage area can store multiple personalized data, and the common storage area can store one personalized data.

[0044] Example 1

[0045] The first embodiment of the present disclosure provides a method for implementing the operation of an online OTP device, as shown in FIG1 , including:

[0046] Step S1: When the online OTP device receives a command from the host computer, it determines the type of command. If it is an application selection command, it executes step S2; if it is a protection code setting command, it executes step S3; if it is a personalized data writing command, it executes step S5; if it is a personalized data processing command, it executes step S9;

[0047] Step S2: The online OTP device selects the corresponding OTP application according to the application identifier in the application selection instruction, obtains the set storage area configuration, generates an application selection response based on the storage area configuration and the preset participating computing device data, and returns it to the host computer. The storage area configuration includes the storage area identifier and the storage area status code, and then returns to step S1;

[0048] Optionally, the participating computing device data in this embodiment may be a challenge code or a device serial number;

[0049] Step S3: The online OTP device determines whether the OTP application has been selected. If yes, it executes step S4; otherwise, it reports an error and returns to step S1.

[0050] Step S4: The online OTP device determines whether the OTP application has set access rights. If so, an error is reported and the process returns to step S1. Otherwise, the protection code in the set protection code instruction is saved in the storage area corresponding to the storage area identifier in the set protection code instruction, and a setting success response is returned to the host computer, and the process returns to step S1.

[0051] Specifically, in this embodiment, the online OTP device determines whether the OTP application has set the access right, including: the online OTP device determines whether the storage area corresponding to the storage area identifier in the setting protection code instruction stores the protection code, if yes, the OTP application has set the access right, otherwise the OTP application has not set the access right;

[0052] Step S5: The online OTP device determines whether the OTP application has been selected. If yes, it executes step S6; otherwise, it reports an error and returns to step S1.

[0053] Step S6: The online OTP device determines whether the OTP application has set access rights. If so, it executes step S7. Otherwise, it reports an error and returns to step S1.

[0054] Specifically, in this embodiment, the online OTP device determines whether the OTP application has set the access right, including: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage area identifier in the instruction to write personalized data, if so, the OTP application has set the access right, otherwise, the OTP application has not set the access right;

[0055] Step S7: The online OTP device obtains the protection code in the corresponding storage area based on the storage area identifier in the instruction to write personalized data, calculates fourth comparison data based on the fourth random number in the instruction to write personalized data and the protection code, and determines whether the fourth comparison data is consistent with the fourth intermediate data in the instruction to write personalized data. If so, step S8 is executed; otherwise, an error is reported and the process returns to step S1.

[0056] Specifically, in this embodiment, calculating the fourth comparison data based on the fourth random number in the instruction to write personalized data and the protection code includes: using the protection code to calculate the fourth random number in the instruction to write personalized data to obtain the fourth comparison data;

[0057] Step S8: The online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier. If so, the personalized data in the "write personalized data" instruction is stored in the default storage area, a write success response is returned to the host computer, and the process returns to step S1. Otherwise, the personalized data in the "write personalized data" instruction is used to update the personalized data stored in the storage area corresponding to the storage area identifier, a write success response is returned to the host computer, and the process returns to step S1.

[0058] Step S9: The online OTP device determines whether the OTP application has been selected. If yes, it executes step S10. Otherwise, it reports an error and returns to step S1.

[0059] Step S10: The online OTP device determines whether the OTP application has set access rights. If so, step S11 is executed. Otherwise, an error is reported and the process returns to step S1.

[0060] Specifically, in this embodiment, the online OTP device determines whether the OTP application has set the access right, including: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage area identifier in the instruction to process personalized data, if so, the OTP application has set the access right, otherwise, the OTP application has not set the access right;

[0061] Step S11: The online OTP device obtains the protection code in the corresponding storage area based on the storage area identifier in the personalized data processing instruction, calculates the first comparison data based on the first random number in the personalized data processing instruction and the protection code, and determines whether the first intermediate data in the personalized data processing instruction is consistent with the first comparison data. If so, step S12 is executed; otherwise, an error is reported and the process returns to step S1.

[0062] Step S12: The online OTP device processes the personalized data stored in the storage area corresponding to the storage area identifier according to the personalized data processing instruction, and returns the processing result to the host computer, and returns to step S1.

[0063] Optionally, the personalized data processing instruction in this embodiment includes: a dynamic password generation instruction, a personalized data deletion instruction, and a personalized data reset instruction;

[0064] If the instruction for processing personalized data is specifically an instruction for generating a dynamic password, and the personalized data includes a seed, step S12 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier, and if so, prompts the user to perform a key confirmation, and when receiving the user's key confirmation information, obtains the corresponding seed stored in the default storage area according to the name of the personalized data in the instruction for generating the dynamic password, generates the dynamic password according to the seed, generates a processing success response according to the processing success status code, the storage area status code, and the dynamic password, and returns it to the host computer, and returns to step S1; otherwise, the user is prompted to perform a key confirmation, and when receiving the user's key confirmation information, generates a dynamic password according to the seed stored in the storage area corresponding to the storage area identifier, and generates a processing success response according to the processing success status code, the storage area status code, and the dynamic password, and returns it to the host computer, and returns to step S1.

[0065] If the personalized data processing instruction is specifically a personalized data deletion instruction, step S12 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier, and if so, prompts the user to press a key to confirm, and upon receiving the user's key confirmation information, deletes the personalized data corresponding to the name of the personalized data in the personalized data deletion instruction stored in the default storage area, generates a processing success response based on the deletion success status code and the storage area status code, and returns it to the host computer, and returns to step S1; otherwise, the user is prompted to press a key to confirm, and upon receiving the user's key confirmation information, deletes the personalized data stored in the storage area corresponding to the storage area identifier, and generates a processing success response based on the deletion success status code and the storage area status code, and returns it to the host computer, and returns to step S1.

[0066] If the instruction for processing personalized data is specifically an instruction for resetting personalized data, step S12 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier; if so, prompts the user to perform a key confirmation; upon receiving the user's key confirmation information, uses the personalized data in the reset personalized data instruction to update the personalized data corresponding to the name of the personalized data in the reset personalized data instruction stored in the default storage area; generates a processing success response based on the reset success status code and the storage area status code and returns it to the host computer; and returns to step S1; otherwise, prompts the user to perform a key confirmation; upon receiving the user's key confirmation information, uses the personalized data in the reset personalized data instruction to update the personalized data stored in the storage area corresponding to the storage area identifier; generates a processing success response based on the reset success status code and the storage area status code and returns it to the host computer; and returns to step S1.

[0067] Optionally, in this embodiment, if it is determined in step S1 that the type of instruction is a modification protection code instruction, step H1 is executed;

[0068] Step H1: The online OTP device determines whether the OTP application has been selected. If yes, it executes step H2; otherwise, it reports an error and returns to step S1;

[0069] Step H2: The online OTP device determines whether the OTP application has set access rights. If so, it executes step H3; otherwise, it reports an error and returns to step S1.

[0070] Specifically, in this embodiment, the online OTP device determines whether the OTP application has set the access right, including: the online OTP device determines whether the storage area corresponding to the storage area identifier in the instruction to modify the protection code stores the protection code, if so, the OTP application has set the access right, otherwise, the OTP application has not set the access right;

[0071] Step H3: The online OTP device obtains the protection code in the corresponding storage area based on the storage area identifier in the instruction to modify the protection code, generates second comparison data based on the second random number in the instruction to modify the protection code and the obtained protection code, and determines whether the second comparison data is identical to the second intermediate data in the instruction to modify the protection code. If so, the process proceeds to Step H4; otherwise, an error is reported and the process returns to Step S1.

[0072] Step H4: The online OTP device replaces the protection code stored in the storage area corresponding to the storage area identifier with the new protection code in the protection code modification instruction, returns a modification success response to the host computer, and returns to step S1.

[0073] Optionally, in this embodiment, if it is determined in step S1 that the type of instruction is a protection code deletion instruction, step L1 is executed;

[0074] Step L1: The online OTP device determines whether the OTP application has been selected. If yes, it executes step L2; otherwise, it reports an error and returns to step S1;

[0075] Step L2: The online OTP device determines whether the OTP application has set access rights. If so, it executes step L3; otherwise, it reports an error and returns to step S1;

[0076] Specifically, in this embodiment, the online OTP device determines whether the OTP application has set the access right, including: the online OTP device determines whether the storage area corresponding to the storage area identifier in the instruction to delete the protection code stores the protection code, if so, the OTP application has set the access right, otherwise, the OTP application has not set the access right;

[0077] Step L3: The online OTP device obtains the protection code in the corresponding storage area according to the storage area identifier in the protection code deletion instruction, calculates the third comparison data according to the protection code and the third random number in the protection code deletion instruction, and determines whether the third comparison data is consistent with the third intermediate data in the protection code deletion instruction. If so, step L4 is executed; otherwise, an error is reported and the process returns to step S1;

[0078] Step L4: The online OTP device deletes the protection code stored in the storage area corresponding to the storage area identifier, returns a deletion success response to the host computer, and returns to step S1.

[0079] Optionally, in this embodiment, if it is determined in step S1 that the type of instruction is a personalized data initialization instruction, step K1 is executed;

[0080] Step K1: The online OTP device determines whether the OTP application has been selected. If yes, it executes step K2; otherwise, it reports an error and returns to step S1;

[0081] Step K2: The online OTP device determines whether the OTP application has set access rights. If so, it executes step K3; otherwise, it reports an error and returns to step S1.

[0082] Specifically, in this embodiment, the online OTP device determines whether the OTP application has set the access right, including: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage area identifier in the personalized data initialization instruction, if so, the OTP application has set the access right, otherwise, the OTP application has not set the access right;

[0083] Step K3: The online OTP device obtains the protection code in the corresponding storage area based on the storage area identifier in the personalized data initialization instruction, calculates fifth comparison data based on the fifth random number in the personalized data initialization instruction and the obtained protection code, and determines whether the fifth comparison data is consistent with the fifth intermediate data in the personalized data initialization instruction. If so, step K4 is executed; otherwise, an error is reported and the process returns to step S1.

[0084] Step K4: The online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier. If yes, execute step K5; otherwise, report an error and return to step S1;

[0085] Step K5: The online OTP device deletes the protection code and personalized data stored in the default storage area, returns an initialization success response to the host computer, and returns to step S1.

[0086] Optionally, in this embodiment, if it is determined in step S1 that the type of instruction is an enumeration personalized data instruction, step P1 is executed;

[0087] Step P1: The online OTP device determines whether the OTP application has been selected. If yes, it executes step P2; otherwise, it reports an error and returns to step S1;

[0088] Step P2: The online OTP device determines whether the OTP application has set access rights. If so, it executes step P3; otherwise, it reports an error and returns to step S1.

[0089] Step P3: The online OTP device obtains the protection code and all personalized data in the corresponding storage area based on the storage area identifier in the personalized data enumeration instruction, calculates sixth comparison data based on the sixth random number in the personalized data enumeration instruction and the obtained protection code, and determines whether the sixth comparison data is consistent with the sixth intermediate data in the personalized data enumeration instruction. If so, step P4 is executed; otherwise, an error is reported and the process returns to step S1.

[0090] Step P4: The online OTP generates an enumeration success response based on the acquired personalized data and returns it to the host computer, and then returns to step S1.

[0091] The method in this embodiment also includes: after the upper computer receives the storage area configuration and the participating computing device data, it displays the corresponding storage area for the user to select according to the storage area configuration, and when receiving the user's selection information, prompts the user to enter the access code of the selected storage area, and generates a protection code based on the received access code and the participating computing device data.

[0092] Specifically, if the participating computing device data is a challenge code, generating the protection code according to the received access code and the participating computing device data includes: performing a hash calculation on the access code and the challenge code by the host computer to obtain a first hash value, and extracting data at a predetermined position in the first hash value as the protection code;

[0093] Alternatively, if the participating computing device data is a device serial number, generating a protection code based on the received access code and participating computing device data includes: the host computer uses the access code and the device serial number as parameters, calls a preset algorithm to construct a symmetric key of a preset byte length and uses it as a protection code.

[0094] In this embodiment, after the host computer generates the protection code, it can generate various operation instructions based on the protection code, storage area identifier and other data, for example:

[0095] After receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select based on the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area. The host computer performs a hash calculation on the received access code and challenge code to obtain a first hash value. The host computer extracts the data at a predetermined position in the first hash value as a protection code. The host computer generates a set protection code instruction based on the storage area identifier and the protection code and sends the instruction to the online OTP device, and then returns to step S1.

[0096] Alternatively, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select based on the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area, performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a fourth random number, calculates the fourth random number using the protection code to obtain fourth intermediate data, generates a write personalized data instruction based on the storage area identifier, the fourth random number, the fourth intermediate data, and the personalized data, and sends the instruction to the online OTP device, and then returns to step S1;

[0097] Alternatively, the host computer performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a sixth random number, calculates the sixth random number using the protection code to obtain sixth intermediate data, generates an enumeration personalized data instruction based on the storage area identifier, the sixth random number, and the sixth intermediate data, and sends the instruction to the online OTP device, executing step S1;

[0098] The host computer parses the received enumeration success response to obtain the personalized data and displays it. When receiving the user's selection information, it can generate a personalized data processing instruction and a personalized data initialization instruction according to the name of the personalized data in the selection information;

[0099] Alternatively, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area, performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a first random number, calculates the first random number using the protection code to obtain first intermediate data, generates a personalized data processing instruction based on the storage area identifier, the first random number, the first intermediate data, and the name of the personalized data, and sends the instruction to the online OTP device, and then returns to step S1; the personalized data processing instruction includes a personalized data reset instruction, a personalized data deletion instruction, and a dynamic password generation instruction;

[0100] Alternatively, after the host computer receives the storage area configuration and the challenge code, it displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, it prompts the user to enter the old access code and the new access code of the selected storage area, performs a hash calculation on the received old access code and the challenge code to obtain a first hash value, extracts the data at a predetermined position in the first hash value as the old protection code, performs a hash calculation on the received new access code and the challenge code to obtain a second hash value, extracts the data at a predetermined position in the second hash value as the new protection code, generates a second random number, uses the old protection code to calculate the second random number to obtain second intermediate data, generates a modification protection code instruction according to the storage area identifier, the second random number, the second intermediate data and the new protection code, and sends the instruction to the online OTP device, and then returns to step S1;

[0101] Alternatively, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area, performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a third random number, calculates the third random number using the protection code to obtain third intermediate data, generates a protection code deletion instruction based on the storage area identifier, the third random number, and the third intermediate data, and sends the instruction to the online OTP device, and then returns to step S1;

[0102] Alternatively, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select based on the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area, performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a fifth random number, calculates the fifth random number using the protection code to obtain fifth intermediate data, generates a personalized data initialization instruction based on the storage area identifier, the fifth random number, the fifth intermediate data, and the name of the personalized data, and sends the instruction to the online OTP device, and then returns to step S1;

[0103] Optionally, the method of this embodiment further includes: after the online OTP device is inserted into the host computer, if the user presses the confirmation key information, the online OTP device generates a dynamic password based on the seed in the general storage area, and sends the dynamic password to the host computer for display.

[0104] Specifically, sending the dynamic password to the host computer for display includes: sending the dynamic password to the host computer for display according to the keyboard protocol format.

[0105] The online OTP device in this embodiment has a built-in default storage area and a general storage area. Each storage area is set with its own protection code. Multiple personalized data can be stored in the default storage area, and one personalized data can be stored in the general storage area. Each storage area is independent of each other and does not affect each other, which is convenient for management and use. When using the online OTP device, the user must first use the protection code for identity authentication, which can effectively ensure that the data in the storage area (including personalized data and protection code) is not maliciously modified, and ensure the security of user information and property in situations such as the loss of the online OTP device.

[0106] Example 2

[0107] A second embodiment of the present disclosure provides a method for implementing the operation of an online OTP device. In this method, the device participation data is a challenge code, as shown in Figures 2 and 3. The method of this embodiment includes:

[0108] Step 201: When the online OTP device receives a command from the host computer, it determines the type of command. If it is an application selection command, it executes step 202; if it is a protection code setting command, it executes step 204; if it is a personalized data writing command, it executes step 207; if it is a personalized data processing command, it executes step 214; if it is a protection code modification command, it executes step 219; if it is a protection code deletion command, it executes step 224; if it is a personalized data initialization command, it executes step 229; if it is a personalized data enumeration command, it executes step 235; if it is other commands, it executes the corresponding operation;

[0109] In this embodiment, the command sent by the host computer to the online OTP device is in APDU format, specifically: CLA INS P1P2 Lc Data Le, where CLA is the command type, INS is the command code, P1 and P2 are parameters, Lc is the length of Data, and Le is the length of the response data;

[0110] Specifically, in this embodiment, when the online OTP device receives a command issued by the host computer, it parses the command and determines the type of the command based on the command header obtained by parsing;

[0111] Step 202: The online OTP device parses the application selection instruction and selects the corresponding OTP application according to the application identifier in the parsing result;

[0112] For example, the command received by the online OTP device is 00A4040009 D15600013283260101, where the data D15600013283260101 in the data field is the application identifier;

[0113] Step 203: The online OTP device obtains the set storage area configuration, generates a selected application response based on the storage area configuration and the preset challenge code, and returns it to the host computer, and then returns to step 201;

[0114] In this embodiment, there are three storage areas in the online OTP device, namely the first storage area, the second storage area, and the default storage area;

[0115] Optional, the challenge code is 8 bytes of data;

[0116] For example, the selected application response in this embodiment is 5903010002 5108AB61365B4024B533 7B0100 9000, where 5108AB61365B4024B533 is the challenge code, the last byte of data in 7B0100 represents the storage area configuration, and 9000 indicates successful instruction execution.

[0117] The storage area configuration includes: a storage area status code, where the storage area status code 00 indicates that no access code is set for the three storage areas; 01 indicates that an access code is set for the first storage area; 02 indicates that an access code is set for the second storage area; 04 indicates that an access code is set for the default storage area; 03 indicates that an access code is set for the first storage area and the second storage area; 05 indicates that an access code is set for both the first storage area and the default storage area; 06 indicates that an access code is set for both the second storage area and the default storage area; and 07 indicates that access codes are set for the first storage area, the second storage area, and the default storage area.

[0118] In this embodiment, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select based on the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area. The host computer can generate different instructions based on the challenge code, access code and storage area identifier of the selected storage area and send them to the online OTP device for corresponding processing;

[0119] For example, if the storage area is configured as 06, the host computer will display the second storage area and the default storage area for the user to choose;

[0120] Specifically, the host computer can generate different instructions based on the challenge code, access code and storage area identifier of the selected storage area and send them to the online OTP device for corresponding processing, including:

[0121] The host computer performs a SHA256 hash calculation on the received access code and challenge code to obtain a first hash value, extracts the first 16 bytes of data from the first hash value as a protection code, generates a set protection code instruction based on the storage area identifier and the protection code, and sends the instruction to the online OTP device, executing step 201;

[0122] Alternatively, the host computer performs a SHA256 hash calculation on the received access code and challenge code to obtain a first hash value, extracts the first 16 bytes of data from the first hash value as a protection code, generates a fourth random number, performs an HMAC-SHA256 calculation on the fourth random number using the protection code to obtain fourth intermediate data, generates a write personalized data instruction based on the storage area identifier, the fourth random number, the fourth intermediate data, and the personalized data, and sends the instruction to the online OTP device, executing step 201;

[0123] Alternatively, the host computer performs a SHA256 hash calculation on the received access code and challenge code to obtain a first hash value, extracts the first 16 bytes of data from the first hash value as a protection code, generates a sixth random number, performs an HMAC-SHA256 calculation on the sixth random number using the protection code to obtain sixth intermediate data, generates an enumeration personalized data instruction based on the storage area identifier, the sixth random number, and the sixth intermediate data, and sends the instruction to the online OTP device, executing step 201;

[0124] The host computer parses the received enumeration success response to obtain the personalized data and displays it. When receiving the user's selection information, it can generate a personalized data processing instruction and a personalized data initialization instruction according to the name of the personalized data in the selection information;

[0125] Alternatively, the host computer performs a SHA256 hash calculation on the received access code and challenge code to obtain a first hash value, extracts the first 16 bytes of data from the first hash value as a protection code, generates a first random number, uses the protection code to perform an HMAC-SHA256 calculation on the first random number to obtain first intermediate data, generates a personalized data processing instruction based on the storage area identifier, the first random number, the first intermediate data, and the name of the personalized data, and sends the instruction to the online OTP device, executing step 201; the personalized data processing instruction includes a personalized data reset instruction, a personalized data delete instruction, and a dynamic password generation instruction;

[0126] Alternatively, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the old access code and the new access code of the selected storage area, performs a SHA256 hash calculation on the received old access code and the challenge code to obtain a first hash value, extracts the first 16 bytes of data in the first hash value as the old protection code, performs a SHA256 hash calculation on the received new access code and the challenge code to obtain a second hash value, extracts the first 16 bytes of data in the second hash value as the new protection code, generates a second random number, performs an HMAC-SHA256 calculation on the second random number using the old protection code to obtain second intermediate data, generates a modification protection code instruction according to the storage area identifier, the second random number, the second intermediate data, and the new protection code, and sends the instruction to the online OTP device, and executes step 201;

[0127] Alternatively, the host computer performs a SHA256 hash calculation on the received access code and challenge code to obtain a first hash value, extracts the first 16 bytes of data from the first hash value as a protection code, generates a third random number, performs an HMAC-SHA256 calculation on the third random number using the protection code to obtain third intermediate data, generates a delete protection code instruction based on the storage area identifier, the third random number, and the third intermediate data, and sends the instruction to the online OTP device, executing step 201;

[0128] Alternatively, the host computer performs a SHA256 hash calculation on the received access code and challenge code to obtain a first hash value, extracts the first 16 bytes of data from the first hash value as a protection code, generates a fifth random number, performs an HMAC-SHA256 calculation on the fifth random number using the protection code to obtain fifth intermediate data, generates a personalized data initialization instruction based on the storage area identifier, the fifth random number, the fifth intermediate data, and the name of the personalized data, and sends the instruction to the online OTP device, executing step 201;

[0129] In this embodiment, the access code corresponding to the first storage area is 6 bytes long, the access code corresponding to the second storage area is 6 bytes long, and the length of the access code corresponding to the default storage area is not fixed; the protection code is 16 bytes of data, the first random number, the second random number, the third random number, the fourth random number, and the fifth random number are 16 bytes of data, and the first intermediate data, the second intermediate data, the third intermediate data, the fourth intermediate data, and the fifth intermediate data are 32 bytes of data;

[0130] Step 204: The online OTP device determines whether the OTP application has been selected. If so, step 205 is executed. Otherwise, an error message is reported and the process returns to step 201.

[0131] Specifically, in this embodiment, the hardware in the online OTP device determines whether an application has been selected and the selected application is an OTP application. If so, step 205 is executed; otherwise, an error is reported and the process returns to step 201.

[0132] Step 205: The online OTP device determines whether the OTP application has set access rights. If yes, an error is reported and the process returns to step 201. Otherwise, the process goes to step 206.

[0133] Specifically, in this embodiment, step 205 includes: the online OTP device determines whether a protection code is stored in the storage area corresponding to the storage area identifier in the setting protection code instruction; if so, the access right is set, an error is reported, and the process returns to step 201; otherwise, the access right is not set, and step 206 is executed;

[0134] Optionally, in this embodiment, the error reporting in step 204 and step 205 specifically includes: returning a setting failure response to the host computer;

[0135] Step 206: The online OTP device parses the protection code setting instruction to obtain the protection code and the storage area identifier, stores the protection code in the storage area corresponding to the storage area identifier, returns a setting success response to the host computer, and returns to step 201;

[0136] For example, the setting instruction in this embodiment is 00A3020112 5310E707BECF8E25D958803FC45A0A1B4740, wherein the fourth byte data 01 in the setting instruction is the storage area identifier, and E707BECF8E25D958803FC45A0A1B4740 is the protection code;

[0137] In this embodiment, after the online OTP device saves the protection code in the storage area of ​​the OTP application, the online OTP device must verify the protection code successfully when receiving other instructions before it can operate the OTP application;

[0138] Step 207: The online OTP device determines whether the OTP application has been selected. If so, step 208 is executed. Otherwise, an error message is reported and the process returns to step 201.

[0139] Step 208: The online OTP device determines whether the OTP application has set access rights. If so, execute step 209; otherwise, report an error and return to step 201;

[0140] Step 209: The online OTP device parses the instruction to write personalized data to obtain a storage area identifier, a fourth random number, fourth intermediate data, and personalized data. The device obtains a protection code from the corresponding storage area based on the storage area identifier, and calculates fourth comparison data based on the fourth random number and the obtained protection code.

[0141] Step 210: The online OTP device determines whether the fourth comparison data is consistent with the fourth intermediate data. If so, step 211 is executed; otherwise, an error is reported and the process returns to step 201.

[0142] Optionally, the error reporting in step 207, step 208 and step 210 may be: the online OTP device returns a write failure response to the host computer;

[0143] Step 211: The online OTP device determines whether the corresponding storage area is the default storage area according to the storage area identifier. If yes, execute step 212; otherwise, execute step 213;

[0144] Step 212: The online OTP device saves the personalized data in the storage area corresponding to the storage area identifier, returns a write success response to the host computer, and returns to step 201;

[0145] In this embodiment, the personalized data includes information such as name, slot, seed, OTP type, hash algorithm, and length. The online OTP device calculates a 6- or 8-digit dynamic password based on the seed;

[0146] Step 213: The online OTP device updates the personalized data stored in the storage area corresponding to the storage area identifier with the personalized data, returns a write success response to the host computer, and returns to step 201;

[0147] Step 214: The online OTP device determines whether the OTP application has been selected. If so, step 215 is executed. Otherwise, an error message is reported and the process returns to step 201.

[0148] Step 215: The online OTP device determines whether the OTP application has set access rights. If so, execute step 216; otherwise, report an error and return to step 201;

[0149] Step 216: The online OTP device parses the personalized data processing instruction to obtain the storage area identifier, the first random number, the first intermediate data, and the name of the personalized data. The device obtains the protection code in the corresponding storage area based on the storage area identifier, and calculates the first comparison data based on the first random number and the obtained protection code.

[0150] Step 217: The online OTP device determines whether the first intermediate data is consistent with the first comparison data. If so, step 218 is executed. Otherwise, an error message is issued and the process returns to step 201.

[0151] Optionally, the error reporting in step 214, step 215, and step 217 is specifically as follows: the online OTP device generates an operation failure response according to the verification failure status code and the storage area status code and returns it to the host computer;

[0152] Specifically, the online OTP device generates an operation failure response according to the verification failure status code and the storage area status code, including: the online OTP device sequentially concatenates the storage area status code and the verification failure status code to generate the operation failure response;

[0153] Step 218: The online OTP device processes the personalized data corresponding to the name of the personalized data stored in the storage area corresponding to the storage area identifier according to the personalized data processing instruction, and returns the processing result to the host computer, and returns to step 201;

[0154] Optionally, in this embodiment, if the instruction for processing personalized data is specifically an instruction for generating a dynamic password, and the personalized data includes a seed, step 218 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier, and if so, prompts the user to perform key confirmation, obtains the corresponding seed stored in the default storage area based on the name of the personalized data in the instruction for generating the dynamic password upon receiving the user's key confirmation information, generates the dynamic password based on the seed, generates a processing success response based on the processing success status code, the storage area status code, and the dynamic password, and returns it to the host computer, and returns to step 201; otherwise, the user is prompted to perform key confirmation, generates the dynamic password based on the seed stored in the storage area corresponding to the storage area identifier upon receiving the user's key confirmation information, generates the dynamic password based on the processing success status code, the storage area status code, and the dynamic password, and returns it to the host computer, and returns to step 201;

[0155] Specifically, in this embodiment, generating a successful processing response according to the verification success status code, the storage area status code, and the dynamic password includes: sequentially concatenating the dynamic password, the storage area status code, and the verification success status code to generate a successful processing response;

[0156] In this embodiment, the first storage area and the second storage area store one piece of personalized data, and the default storage area can store multiple pieces of personalized data. The personalized data includes: the name, seed, OTP type, hash algorithm, length, etc. of the personalized data;

[0157] The storage area status codes include: 00 indicates that the storage area has no access code configured, 01 indicates that the first storage area has an access code configured, 02 indicates that the second storage area has an access code configured, 03 indicates that the first storage area and the second storage area have access codes configured, 04 indicates that the default storage area has an access code configured, 05 indicates that the first storage area and the default storage area have access codes configured, 06 indicates that the second storage area and the default storage area have access codes configured, and 07 indicates that the first storage area, the second storage area, and the default storage area all have access codes configured;

[0158] The verification success status code is 9000, and the verification failure status code is 0000;

[0159] For example, the generated successful processing response is: 5903010002510802241BBC2DFA1E2A7B0101 9000, where 5903010002510802241BBC2DFA1E2A is the dynamic password, the last byte data 01 in 7B0101 is the storage area status code, and 9000 is the verification success status code;

[0160] If the personalized data processing instruction is specifically a personalized data deletion instruction, step 218 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier; if so, prompts the user to press a key to confirm; upon receiving the user's key confirmation information, deletes the personalized data corresponding to the name of the personalized data in the personalized data deletion instruction stored in the default storage area; generates a processing success response based on the deletion success status code and the storage area status code and returns it to the host computer; and returns to step 201; otherwise, prompts the user to press a key to confirm; upon receiving the user's key confirmation information, deletes the personalized data stored in the storage area corresponding to the storage area identifier; generates a processing success response based on the deletion success status code and the storage area status code and returns it to the host computer; and returns to step 201;

[0161] If the instruction for processing personalized data is specifically an instruction for resetting personalized data, step 218 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier; if so, prompts the user to perform a key confirmation; upon receiving the user's key confirmation information, updates the personalized data corresponding to the name of the personalized data in the reset personalized data instruction and stored in the default storage area with the personalized data in the reset personalized data instruction; generates a processing success response based on the reset success status code and the storage area status code and returns it to the host computer; and returns to step 201; otherwise, prompts the user to perform a key confirmation; upon receiving the user's key confirmation information, updates the personalized data stored in the storage area corresponding to the storage area identifier with the personalized data in the reset personalized data instruction; generates a processing success response based on the deletion success status code and the storage area status code and returns it to the host computer; and returns to step 201;

[0162] Step 219: The online OTP device determines whether the OTP application has been selected. If so, step 220 is executed. Otherwise, an error message is reported and the process returns to step 201.

[0163] Step 220: The online OTP device determines whether the OTP application has set access rights. If so, execute step 221; otherwise, report an error and return to step 201;

[0164] Step 221: The online OTP device parses the instruction to modify the protection code to obtain the storage area identifier, the second intermediate data, the second random number, and the new protection code, obtains the protection code in the corresponding storage area according to the storage area identifier, and generates second comparison data according to the second random number and the obtained protection code;

[0165] Step 222: The online OTP device determines whether the second comparison data is identical to the second intermediate data. If yes, execute step 223; otherwise, report an error and return to step 201.

[0166] Optionally, the error reporting in step 219, step 220, and step 222 is: the online OTP device returns a modification failure response to the host computer;

[0167] Step 223: The online OTP device replaces the protection code stored in the storage area corresponding to the storage area identifier with the new protection code, returns a modification success response to the host computer, and returns to step 201;

[0168] Step 224: The online OTP device determines whether the OTP application has been selected. If so, step 225 is executed. Otherwise, an error message is reported and the process returns to step 201.

[0169] Step 225: The online OTP device determines whether the OTP application has set access rights. If so, execute step 226; otherwise, report an error and return to step 201;

[0170] Step 226: The online OTP device parses the instruction to delete the protection code to obtain a storage area identifier, the third intermediate data, and a third random number, obtains the protection code in the corresponding storage area based on the storage area identifier, and calculates the third comparison data based on the obtained protection code and the third random number.

[0171] Step 227: The online OTP device determines whether the third comparison data is consistent with the third intermediate data. If yes, execute step 228; otherwise, report an error and return to step 201;

[0172] Optionally, the error reporting in step 224, step 225, and step 227 is specifically: the online OTP device returns a deletion failure response to the host computer;

[0173] Step 228: The online OTP device deletes the protection code stored in the storage area corresponding to the storage area identifier, returns a deletion success response to the host computer, and returns to step 201;

[0174] Step 229: The online OTP device determines whether the OTP application has been selected. If so, step 230 is executed. Otherwise, an error message is reported and the process returns to step 201.

[0175] Step 230: The online OTP device determines whether the OTP application has set access rights. If so, execute step 231; otherwise, report an error and return to step 201;

[0176] Step 231: The online OTP device parses the personalized data initialization instruction to obtain a storage area identifier, a fifth random number, and fifth intermediate data, obtains a protection code from the corresponding storage area based on the storage area identifier, and calculates fifth comparison data based on the fifth random number and the obtained protection code.

[0177] Step 232: The online OTP device determines whether the fifth comparison data is consistent with the fifth intermediate data. If yes, execute step 233; otherwise, return to step 201;

[0178] Step 233: The online OTP device determines whether the corresponding storage area is the default storage area according to the storage area identifier. If yes, execute step 234; otherwise, report an error and return to step 201;

[0179] Optionally, the error reporting in step 229, step 230, step 232, and step 233 is specifically: the online OTP returns a reset failure response to the host computer;

[0180] Step 234: The online OTP device deletes the personalized data and protection code stored in the default storage area, returns an initialization success response to the host computer, and returns to step 201;

[0181] Step 235: The online OTP device determines whether the OTP application has been selected. If so, step 236 is executed. Otherwise, an error message is reported and the process returns to step 201.

[0182] Step 236: The online OTP device determines whether the OTP application has set access rights. If so, execute step 237; otherwise, report an error and return to step 201;

[0183] Step 237: The online OTP device parses the personalized data enumeration instruction to obtain a storage area identifier, a sixth random number, and sixth intermediate data. Based on the storage area identifier, the device obtains the protection code and all personalized data in the corresponding storage area. Based on the sixth random number and the obtained protection code, the device calculates sixth comparison data.

[0184] Step 238: The online OTP device determines whether the sixth comparison data is consistent with the sixth intermediate data. If so, step 239 is executed. Otherwise, an error is reported and the process returns to step 201.

[0185] Optionally, the error reporting in step 235, step 236, and step 238 is specifically: the online OTP returns an enumeration failure response to the host computer;

[0186] Step 239: The online OTP device generates an enumeration success response based on the acquired personalized data and returns it to the host computer, and then returns to step 201;

[0187] In this embodiment, the host computer parses the received enumeration success response to obtain and display personalized data. When receiving user selection information, it can generate personalized data processing instructions and personalized data initialization instructions according to the name of the personalized data in the selection information.

[0188] In this embodiment, the online OTP device has a built-in first storage area, a second storage area and a default storage area, wherein the first storage area and the second storage area are only allowed to store one personalized data, and support setting a protection code. The host computer generates a protection code according to the access code entered by the user and sends it to the online OTP device for verification. Only after the verification is passed is it allowed to modify, delete, etc. the personalized data and protection code in the first storage area and / or the second storage area; multiple personalized data can be stored in the default storage area, with no limit on the number of pieces. The default storage area supports setting a protection code. The host computer generates a protection code according to the access code entered by the user and sends it to the online OTP device for verification. Only after the verification is passed is it allowed to modify, use, initialize, etc. the personalized data and access code in the default storage area, which facilitates the management of the online OTP device and improves the security of the online OTP device.

[0189] Example 3

[0190] A third embodiment of the present disclosure provides a method for implementing the operation of an online OTP device. The participating computing device data in the method is the device serial number, as shown in FIG4 and FIG5 . The method of this embodiment includes:

[0191] Step 301: When the online OTP device receives a command from the host computer, it determines the type of command. If it is an application selection command, it executes step 302; if it is a protection code setting command, it executes step 304; if it is a personalized data writing command, it executes step 307; if it is a personalized data processing command, it executes step 314; if it is a protection code modification command, it executes step 319; if it is a protection code deletion command, it executes step 324; if it is a personalized data initialization command, it executes step 329; if it is a personalized data enumeration command, it executes step 335; if it is other commands, it executes the corresponding operation;

[0192] In this embodiment, the command sent by the host computer to the online OTP device is in APDU format, specifically: CLA INS P1 P2 Lc Data Le, where CLA is the command type, INS is the command code, P1 and P2 are parameters, Lc is the length of Data, and Le is the length of the response data;

[0193] Specifically, in this embodiment, when the online OTP device receives a command issued by the host computer, it parses the command and determines the type of the command based on the command header obtained by parsing;

[0194] Step 302: The online OTP device parses the application selection instruction and selects the corresponding OTP application according to the application identifier in the parsing result;

[0195] For example, the command received by the online OTP device is 00A4040007A0000005272101, where the data A0000005272101 in the data field is the application identifier;

[0196] Step 303: The online OTP device obtains the configured storage area configuration, generates an application selection response based on its own device serial number and storage area configuration, and returns it to the host computer, and then returns to step 301;

[0197] In this embodiment, there are three storage areas in the online OTP device, namely the first storage area, the second storage area, and the default storage area;

[0198] For example, the select application response in this embodiment is 7903010004 7108E6029A6D1E7F85557B0102 9000, where 7108E6029A6D1E7F8555 represents the device serial number, the last byte of data in 7B0102 represents the storage area configuration, and 9000 indicates that the command was executed successfully;

[0199] The storage area configuration includes: storage area status code, storage area status code 00 indicates that no configuration code is set for the three storage areas, 01 indicates that the first storage area is configured with an access code, 02 indicates that the second storage area is configured with an access code, 04 indicates that the default storage area is configured with an access code, 03 indicates that the first storage area and the second storage area are configured with an access code, 05 indicates that the first storage area and the default storage area are configured with an access code, 06 indicates that the second storage area and the default storage area are configured with an access code, and 07 indicates that the first storage area, the second storage area, and the default storage area are all configured with access codes;

[0200] In this embodiment, after receiving the storage area configuration and the device serial number, the host computer displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area. The host computer can generate different instructions based on the device serial number, access code and storage area identifier of the selected storage area and send them to the online OTP device for corresponding processing;

[0201] Specifically, the host computer can generate different instructions based on the device serial number, access code and storage area identifier of the corresponding storage area and send them to the online OTP device for corresponding processing, including:

[0202] The host computer uses the received access code and device serial number as parameters to call the Android system method SecretKeyFactory's PBKDF2WithHmacSHA1 to construct a 16-byte symmetric key and use it as a protection code. The host computer generates a set protection code instruction based on the storage area identifier and the protection code and sends it to the online OTP device, executing step 301. Furthermore, the host computer system is not limited to Android and will not be described in detail here.

[0203] Alternatively, the host computer uses the received access code and device serial number as parameters to call the PBKDF2WithHmacSHA1 method of the Android system SecretKeyFactory to construct a 16-byte symmetric key and use it as a protection code to generate a fourth random number. The protection code is used to perform an HMAC sha1 calculation on the fourth random number to obtain fourth intermediate data. A write personalized data instruction is generated based on the storage area identifier, the fourth random number, the fourth intermediate data, and the personalized data, and the instruction is sent to the online OTP device, and step 301 is executed.

[0204] Alternatively, the host computer uses the received access code and device serial number as parameters to call the Android system method SecretKeyFactory's PBKDF2WithHmacSHA1 to construct a 16-byte symmetric key and use it as a protection code to generate a sixth random number. The host computer uses the protection code to perform an HMAC sha1 calculation on the sixth random number to obtain sixth intermediate data. Based on the storage area identifier, the sixth random number, and the sixth intermediate data, the host computer generates an enumeration personalized data instruction and sends it to the online OTP device, executing step 201.

[0205] The host computer parses the received enumeration success response to obtain the personalized data and displays it. When receiving the user's selection information, it can generate a personalized data processing instruction and a personalized data initialization instruction according to the name of the personalized data in the selection information;

[0206] Alternatively, the host computer uses the received access code and device serial number as parameters to call the PBKDF2WithHmacSHA1 method of the Android system SecretKeyFactory to construct a 16-byte symmetric key and use it as a protection code to generate a first random number. The protection code is used to perform an HMAC sha1 calculation on the first random number to obtain first intermediate data. A personalized data processing instruction is generated based on the storage area identifier, the first random number, the first intermediate data, and the name of the personalized data, and the instruction is sent to the online OTP device to execute step 301. The personalized data processing instruction includes a personalized data reset instruction, a personalized data delete instruction, and a dynamic password generation instruction.

[0207] Alternatively, after receiving the storage area configuration and the device serial number, the host computer displays the corresponding storage area for the user to select based on the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the old access code and new access code of the selected storage area. The received old access code and the device serial number are used as parameters to call the Android system method SecretKeyFactory's PBKDF2WithHmacSHA1 to construct a 16-byte symmetric key and use it as the old protection code. The received new access code and the device serial number are used as parameters to call the Android system method SecretKeyFactory's PBKDF2WithHmacSHA1 to construct a 16-byte symmetric key and use it as the new protection code. A second random number is generated. The old protection code is used to perform an HMAC sha1 calculation on the second random number to obtain second intermediate data. A modification protection code instruction is generated based on the storage area identifier, the second random number, the second intermediate data, and the new protection code, and the instruction is sent to the online OTP device to execute step 301.

[0208] Alternatively, the host computer uses the received access code and device serial number as parameters to call the Android system method SecretKeyFactory's PBKDF2WithHmacSHA1 to construct a 16-byte symmetric key and use it as a protection code, generates a third random number, uses the protection code to perform an HMAC sha1 calculation on the third random number to obtain third intermediate data, generates a delete protection code instruction based on the storage area identifier, the third random number, and the third intermediate data, and sends the instruction to the online OTP device, executing step 301;

[0209] Alternatively, the host computer uses the received access code and device serial number as parameters to call the Android system method SecretKeyFactory's PBKDF2WithHmacSHA1 to construct a 16-byte symmetric key and use it as a protection code to generate a fifth random number. The host computer uses the protection code to perform an HMAC sha1 calculation on the fifth random number to obtain fifth intermediate data. A personalized data initialization instruction is generated based on the storage area identifier, the fifth random number, the fifth intermediate data, and the name of the personalized data, and the instruction is sent to the online OTP device, and step 301 is executed.

[0210] In this embodiment, the access code corresponding to the first storage area is 6 bytes long, the access code corresponding to the second storage area is 6 bytes long, and the length of the access code corresponding to the default storage area is not fixed; the protection code is 16 bytes of data, the first random number, the second random number, the third random number, the fourth random number, and the fifth random number are 16 bytes of data, and the first intermediate data, the second intermediate data, the third intermediate data, the fourth intermediate data, and the fifth intermediate data are 32 bytes of data;

[0211] Step 304: The online OTP device determines whether the OTP application has been selected. If so, step 305 is executed. Otherwise, an error message is reported and the process returns to step 301.

[0212] Specifically, in this embodiment, the hardware in the online OTP device determines whether an application has been selected and the selected application is an OTP application. If so, step 305 is executed; otherwise, an error is reported and the process returns to step 301.

[0213] Step 305: The online OTP device determines whether the OTP application has set access rights. If yes, an error is reported and the process returns to step 301. Otherwise, the process goes to step 306.

[0214] Specifically, in this embodiment, step 305 includes: the online OTP device determines whether the protection code is stored in the storage area corresponding to the storage area identifier in the setting protection code instruction; if so, the access right is set, an error is reported, and the process returns to step 301; otherwise, the access right is not set, and step 306 is executed;

[0215] Optionally, in this embodiment, the error reporting in step 304 and step 305 specifically includes: returning a setting failure response to the host computer;

[0216] Step 306: The online OTP device parses the protection code setting instruction to obtain the protection code and storage area identifier, stores the protection code in the storage area corresponding to the storage area identifier, returns a setting success response to the host computer, and returns to step 301;

[0217] In this embodiment, after the online OTP device saves the protection code in the storage area of ​​the OTP application, the online OTP device must verify the protection code successfully when receiving other instructions before it can operate the OTP application;

[0218] Step 307: The online OTP device determines whether the OTP application has been selected. If so, step 308 is executed. Otherwise, an error message is reported and the process returns to step 301.

[0219] Step 308: The online OTP device determines whether the OTP application has set access rights. If so, it executes step 309. Otherwise, it reports an error and returns to step 301.

[0220] Step 309: The online OTP device parses the instruction to write personalized data to obtain a storage area identifier, a fourth random number, fourth intermediate data, and personalized data. The device obtains a protection code from the corresponding storage area based on the storage area identifier, and calculates fourth comparison data based on the fourth random number and the obtained protection code.

[0221] Step 310: The online OTP device determines whether the fourth comparison data is consistent with the fourth intermediate data. If so, step 311 is executed; otherwise, an error is reported and the process returns to step 301.

[0222] Optionally, the error reporting in step 307, step 308 and step 310 may be: the online OTP device returns a write failure response to the host computer;

[0223] Step 311: The online OTP device determines whether the corresponding storage area is the default storage area according to the storage area identifier. If yes, execute step 312; otherwise, execute step 313;

[0224] Step 312: The online OTP device saves the personalized data in the storage area corresponding to the storage area identifier, returns a write success response to the host computer, and returns to step 301;

[0225] In this embodiment, the personalized data includes information such as name, slot, seed, OTP type, hash algorithm, and length. The online OTP device calculates a 6- or 8-digit dynamic password based on the seed.

[0226] Step 313: The online OTP device updates the personalized data stored in the storage area corresponding to the storage area identifier with the personalized data, returns a write success response to the host computer, and returns to step 301;

[0227] Step 314: The online OTP device determines whether the OTP application has been selected. If so, step 315 is executed. Otherwise, an error message is reported and the process returns to step 301.

[0228] Step 315: The online OTP device determines whether the OTP application has set access rights. If so, execute step 316; otherwise, report an error and return to step 301.

[0229] Step 316: The online OTP device parses the personalized data processing instruction to obtain the storage area identifier, the first random number, the first intermediate data, and the name of the personalized data. The device obtains the protection code in the corresponding storage area based on the storage area identifier, and calculates the first comparison data based on the first random number and the obtained protection code.

[0230] Step 317: The online OTP device determines whether the first intermediate data is consistent with the first comparison data. If so, step 318 is executed. Otherwise, an error message is issued and the process returns to step 301.

[0231] Optionally, the error reporting in step 314, step 315, and step 317 is: the online OTP device generates an operation failure response according to the verification failure status code and the storage area status code and returns it to the host computer;

[0232] Specifically, the online OTP device generates an operation failure response according to the verification failure status code and the storage area status code, including: the online OTP device sequentially concatenates the storage area status code and the verification failure status code to generate the operation failure response;

[0233] Step 318: The online OTP device processes the personalized data corresponding to the name of the personalized data stored in the storage area corresponding to the storage area identifier according to the personalized data processing instruction, and returns the processing result to the host computer, and returns to step 301;

[0234] Optionally, in this embodiment, if the instruction for processing personalized data is specifically an instruction for generating a dynamic password, and the personalized data includes a seed, step 318 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier, and if so, prompts the user to perform key confirmation, obtains the corresponding seed stored in the default storage area based on the name of the personalized data in the instruction for generating the dynamic password upon receiving the user's key confirmation information, generates the dynamic password based on the seed, generates a processing success response based on the processing success status code, the storage area status code, and the dynamic password, and returns it to the host computer, and returns to step 301; otherwise, the user is prompted to perform key confirmation, generates the dynamic password based on the seed stored in the storage area corresponding to the storage area identifier upon receiving the user's key confirmation information, generates the processing success response based on the processing success status code, the storage area status code, and the dynamic password, and returns it to the host computer, and returns to step 301;

[0235] Specifically, in this embodiment, generating a successful processing response according to the verification success status code, the storage area status code, and the dynamic password includes: sequentially concatenating the dynamic password, the storage area status code, and the verification success status code to generate a successful processing response;

[0236] In this embodiment, the first storage area and the second storage area store one piece of personalized data, and the default storage area can store multiple pieces of personalized data. The personalized data includes: the name, seed, OTP type, hash algorithm, length, etc. of the personalized data;

[0237] The storage area status codes include: 00 indicates that the storage area has no access code configured, 01 indicates that the first storage area has an access code configured, 02 indicates that the second storage area has an access code configured, 03 indicates that the first storage area and the second storage area have access codes configured, 04 indicates that the default storage area has an access code configured, 05 indicates that the first storage area and the default storage area have access codes configured, 06 indicates that the second storage area and the default storage area have access codes configured, and 07 indicates that the first storage area, the second storage area, and the default storage area all have access codes configured;

[0238] The verification success status code is 9000, and the verification failure status code is 0000;

[0239] For example, the generated successful processing response is: 5903010002510802241BBC2DFA1E2A7B0101 9000, where 5903010002510802241BBC2DFA1E2A is the dynamic password, the last byte data 01 in 7B0101 is the storage area status code, and 9000 is the verification success status code;

[0240] If the personalized data processing instruction is specifically a personalized data deletion instruction, step 318 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier; if so, prompts the user to press a key to confirm; upon receiving the user's key confirmation information, deletes the personalized data corresponding to the name of the personalized data in the personalized data deletion instruction stored in the default storage area; generates a processing success response based on the deletion success status code and the storage area status code and returns it to the host computer; and returns to step 301; otherwise, prompts the user to press a key to confirm; upon receiving the user's key confirmation information, deletes the personalized data stored in the storage area corresponding to the storage area identifier; generates a processing success response based on the deletion success status code and the storage area status code and returns it to the host computer; and returns to step 301;

[0241] If the instruction to process personalized data is specifically an instruction to reset personalized data, step 318 includes: the online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier; if so, prompts the user to press a key to confirm; upon receiving the user's key confirmation information, uses the personalized data in the reset personalized data instruction to update the personalized data corresponding to the name of the personalized data in the reset personalized data instruction stored in the default storage area; generates a processing success response based on the reset success status code and the storage area status code and returns it to the host computer; and returns to step 301; otherwise, prompts the user to press a key to confirm; upon receiving the user's key confirmation information, uses the personalized data in the reset personalized data instruction to update the personalized data stored in the storage area corresponding to the storage area identifier; generates a processing success response based on the deletion success status code and the storage area status code and returns it to the host computer; and returns to step 301;

[0242] Step 319: The online OTP device determines whether the OTP application has been selected. If so, execute step 320; otherwise, report an error and return to step 301;

[0243] Step 320: The online OTP device determines whether the OTP application has set access rights. If so, execute step 321; otherwise, report an error and return to step 301;

[0244] Step 321: The online OTP device parses the instruction to modify the protection code to obtain the storage area identifier, the second intermediate data, the second random number, and the new protection code. The device obtains the protection code in the corresponding storage area based on the storage area identifier, and generates second comparison data based on the second random number and the obtained protection code.

[0245] Specifically, the instruction to modify the protection code received by the online OTP device includes three TLV structures;

[0246] For example, the instruction to modify the protection code in this step is: 0003000033 7311 21 09FA07217854138DAF43B7FD2FEADC97 7408 19E052E744BA5AE4 7514 7C4D9A8947E14E9B92198883E92197371E2A7F94, where 7311 21 09FA07217854138DAF43B7FD2FEADC97 is the first TLV, T=73, L=11, V=21 09FA07217854138DAF43B7FD2FEADC97 (the first byte 21 is the OTP type, and the data starting from the second byte is the new protection code); 19E052E744BA5AE4 is the second TLV, T=74, L=08, V=19E052E744BA5AE4 (second random number); 7514 7C4D9A8947E14E9B92198883E92197371E2A7F94 is the third TLV, T=75, L=14, V=7C4D9A8947E14E9B92198883E92197371E2A7F94 (second intermediate data);

[0247] Step 322: The online OTP device determines whether the second comparison data and the second intermediate data are identical. If yes, step 323 is executed. Otherwise, an error message is issued and the process returns to step 301.

[0248] Optionally, the error reporting in step 319, step 320, and step 322 is: the online OTP device returns a modification failure response to the host computer;

[0249] Step 323: The online OTP device replaces the protection code stored in the storage area corresponding to the storage area identifier with the new protection code, returns a modification success response to the host computer, and returns to step 301;

[0250] Step 324: The online OTP device determines whether the OTP application has been selected. If so, execute step 325; otherwise, report an error and return to step 301;

[0251] Step 325: The online OTP device determines whether the OTP application has set access rights. If so, execute step 326; otherwise, report an error and return to step 301.

[0252] Step 326: The online OTP device parses the instruction to delete the protection code to obtain a storage area identifier, the third intermediate data, and a third random number. The device obtains the protection code in the corresponding storage area based on the storage area identifier, and calculates the third comparison data based on the obtained protection code and the third random number.

[0253] Step 327: The online OTP device determines whether the third comparison data is consistent with the third intermediate data. If so, step 328 is executed. Otherwise, an error is reported and the process returns to step 301.

[0254] Optionally, the error reporting in step 324, step 325, and step 327 is specifically: the online OTP device returns a deletion failure response to the host computer;

[0255] Step 328: The online OTP device deletes the protection code stored in the storage area corresponding to the storage area identifier, returns a deletion success response to the host computer, and returns to step 301;

[0256] Step 329: The online OTP device determines whether the OTP application has been selected. If yes, execute step 330; otherwise, report an error and return to step 301;

[0257] Step 330: The online OTP device determines whether the OTP application has set access rights. If so, execute step 331; otherwise, report an error and return to step 301;

[0258] Step 331: The online OTP device parses the personalized data initialization instruction to obtain a storage area identifier, a fifth random number, and fifth intermediate data, obtains a protection code from the corresponding storage area based on the storage area identifier, and calculates fifth comparison data based on the fifth random number and the obtained protection code.

[0259] Step 332: The online OTP device determines whether the fifth comparison data is consistent with the fifth intermediate data. If yes, execute step 333; otherwise, report an error and return to step 301;

[0260] Step 333: The online OTP device determines whether the corresponding storage area is the default storage area based on the storage area identifier. If yes, execute step 334; otherwise, report an error and return to step 301;

[0261] Optionally, the error reporting in step 329, step 330, step 332, and step 233 is specifically: the online OTP returns a reset failure response to the host computer;

[0262] Step 334: The online OTP device deletes the personalized data and protection code stored in the default storage area, returns an initialization success response to the host computer, and returns to step 301;

[0263] Step 335: The online OTP device determines whether the OTP application has been selected. If so, execute step 336; otherwise, report an error and return to step 301;

[0264] Step 336: The online OTP device determines whether the OTP application has set access rights. If so, execute step 337; otherwise, report an error and return to step 301.

[0265] Step 337: The online OTP device parses the personalized data enumeration instruction to obtain the storage area identifier, the sixth random number, and the sixth intermediate data. Based on the storage area identifier, the protection code and all personalized data in the corresponding storage area are obtained. Based on the sixth random number and the obtained protection code, the sixth comparison data is calculated.

[0266] Step 338: The online OTP device determines whether the sixth comparison data is consistent with the sixth intermediate data. If so, execute step 339; otherwise, report an error and return to step 301;

[0267] Optionally, the error reporting in step 335, step 336, and step 338 is specifically: the online OTP returns an enumeration failure response to the host computer;

[0268] Step 339: The online OTP device generates an enumeration success response based on the acquired personalized data and returns it to the host computer, and then returns to step 301;

[0269] In this embodiment, the host computer parses the received enumeration success response to obtain and display personalized data. When receiving user selection information, it can generate personalized data processing instructions and personalized data initialization instructions according to the name of the personalized data in the selection information.

[0270] After the online OTP device in this embodiment is inserted into the host computer, if the user's short press confirmation key information (or long press confirmation key information) is received, the device generates a dynamic password based on the seed in the first storage area (or the second storage area) and sends it to the host computer for display;

[0271] Optionally, after the device generates the dynamic password, it sends the dynamic password to the host computer for display according to the keyboard protocol format.

[0272] Example 4

[0273] A fourth embodiment of the present disclosure provides an apparatus for implementing the operation of an online OTP device, wherein the online OTP device has a built-in default storage area and a common storage area. The default storage area can store multiple pieces of personalized data, and the common storage area stores one piece of personalized data. The apparatus of this embodiment includes:

[0274] a receiving and judging module, configured to receive instructions issued by the host computer and, upon receiving an instruction, to judge the type of the instruction. If the instruction is an application selection instruction, the calculation and return selection module is triggered; if the instruction is a protection code setting instruction, the first judging module is triggered; if the instruction is a personalized data writing instruction, the second judging module is triggered; and if the instruction is a personalized data processing instruction, the fourth judging module is triggered;

[0275] The calculation and return module is used to select the corresponding OTP application according to the application identifier in the application selection instruction, obtain the set storage area configuration, generate the application selection response based on the storage area configuration and the preset participating calculation device data, and return it to the host computer. The storage area configuration includes the storage area identifier and storage area status code, which triggers the receiving judgment module;

[0276] Optionally, the participating computing device data in this embodiment may be a challenge code or a device serial number;

[0277] The first judgment module is used to judge whether the OTP application has been selected. If yes, it triggers the judgment setting return module; otherwise, it reports an error and triggers the receiving judgment module;

[0278] The judgment setting return module is used to judge whether the OTP application has set access rights. If so, an error is reported to trigger the receiving judgment module. Otherwise, the protection code in the setting protection code instruction is saved in the storage area corresponding to the storage area identifier in the setting protection code instruction, and a setting success response is returned to the host computer to trigger the receiving judgment module.

[0279] The second judgment module is used to judge whether the OTP application has been selected. If yes, the third judgment module is triggered. Otherwise, an error is reported and the receiving judgment module is triggered.

[0280] The third judgment module is used to judge whether the OTP application has set access rights. If so, it triggers the first acquisition and calculation judgment module; otherwise, it reports an error and triggers the reception judgment module;

[0281] a first acquisition, calculation and judgment module, configured to obtain a protection code in a corresponding storage area based on a storage area identifier in the personalized data write instruction, calculate fourth comparison data based on a fourth random number and the protection code in the personalized data write instruction, and determine whether the fourth comparison data is consistent with the fourth intermediate data in the personalized data write instruction. If so, trigger the judgment and writing module; otherwise, report an error and trigger the reception and judgment module;

[0282] In this embodiment, the first acquisition, calculation and judgment module is configured to calculate and obtain fourth comparison data based on the fourth random number and the protection code in the instruction for writing personalized data, including: the first acquisition, calculation and judgment module is specifically configured to calculate and obtain fourth comparison data based on the fourth random number in the instruction for writing personalized data using the protection code;

[0283] a determination writing module, configured to determine whether the corresponding storage area is the default storage area based on the storage area identifier; if so, to store the personalized data in the write personalized data instruction in the default storage area, return a write success response to the host computer, and return to step S1; otherwise, to update the personalized data stored in the storage area corresponding to the storage area identifier with the personalized data in the write personalized data instruction, return a write success response to the host computer, and trigger the receiving determination module;

[0284] The fourth judgment module is used to judge whether the OTP application has been selected, and if so, trigger the fifth judgment module; otherwise, an error is reported and the receiving judgment module is triggered;

[0285] The fifth judgment module is used to judge whether the OTP application has set access rights. If so, it triggers the second acquisition and calculation judgment module. Otherwise, it reports an error and triggers the reception judgment module.

[0286] a second acquisition, calculation and judgment module, configured to obtain a protection code in a corresponding storage area based on a storage area identifier in the personalized data processing instruction, calculate first comparison data based on a first random number in the personalized data processing instruction and the protection code, and determine whether the first intermediate data in the personalized data processing instruction is consistent with the first comparison data. If so, triggering the processing and returning module; otherwise, reporting an error and triggering the receiving and judging module;

[0287] The processing and returning module is used to process the personalized data stored in the storage area corresponding to the storage area identifier according to the personalized data processing instruction, and return the processing result to the host computer to trigger the receiving and judging module.

[0288] Optionally, the personalized data processing instruction in this embodiment includes: a dynamic password generation instruction, a personalized data deletion instruction, and a personalized data reset instruction;

[0289] If the instruction for processing personalized data is specifically an instruction for generating a dynamic password, the personalized data includes a seed, and the processing return module is specifically used to determine whether the corresponding storage area is the default storage area based on the storage area identifier. If so, the user is prompted to press a key to confirm. When the user's key confirmation information is received, the corresponding seed stored in the default storage area is obtained according to the name of the personalized data in the instruction for generating a dynamic password, a dynamic password is generated according to the seed, a processing success response is generated according to the processing success status code, the storage area status code and the dynamic password, and the response is returned to the host computer, triggering the receiving and judging module. Otherwise, the user is prompted to press a key to confirm. When the user's key confirmation information is received, a dynamic password is generated according to the seed stored in the storage area corresponding to the storage area identifier, a processing success response is generated according to the processing success status code, the storage area status code and the dynamic password, and the response is returned to the host computer, triggering the receiving and judging module.

[0290] If the personalized data processing instruction is specifically a personalized data deletion instruction, the processing return module is specifically used to determine whether the corresponding storage area is the default storage area based on the storage area identifier. If so, the user is prompted to press a key to confirm. When the user's key confirmation information is received, the personalized data corresponding to the name of the personalized data in the personalized data deletion instruction stored in the default storage area is deleted. A processing success response is generated based on the deletion success status code and the storage area status code and returned to the host computer, triggering the receiving judgment module. Otherwise, the user is prompted to press a key to confirm. When the user's key confirmation information is received, the personalized data stored in the storage area corresponding to the storage area identifier is deleted. A processing success response is generated based on the deletion success status code and the storage area status code and returned to the host computer, triggering the receiving judgment module.

[0291] If the personalized data processing instruction is specifically a reset personalized data instruction, the processing return module is specifically used to determine whether the corresponding storage area is the default storage area based on the storage area identifier. If so, the user is prompted to press a key to confirm. When the user's key confirmation information is received, the personalized data corresponding to the name of the personalized data in the reset personalized data instruction and stored in the default storage area is updated with the personalized data in the reset personalized data instruction. A processing success response is generated based on the reset success status code and the storage area status code and returned to the host computer, triggering the receiving judgment module. Otherwise, the user is prompted to press a key to confirm. When the user's key confirmation information is received, the personalized data in the reset personalized data instruction is used to update the personalized data stored in the storage area corresponding to the storage area identifier. A processing success response is generated based on the reset success status code and the storage area status code and returned to the host computer, triggering the receiving judgment module.

[0292] Optionally, the device of this embodiment further includes:

[0293] A sixth judgment module, configured to determine whether the OTP application has been selected when the receiving judgment module determines that the type of instruction is a modification protection code instruction, and trigger the seventh judgment module if so; otherwise, an error is reported and the receiving judgment module is triggered;

[0294] The seventh judgment module is used to judge whether the OTP application has set access rights. If so, the third acquisition and calculation judgment module is triggered. Otherwise, an error is reported and the reception judgment module is triggered.

[0295] a third acquisition calculation judgment module, configured to obtain the protection code in the corresponding storage area according to the storage area identifier in the protection code modification instruction, generate second comparison data according to the second random number in the protection code modification instruction and the obtained protection code, and determine whether the second comparison data is identical to the second intermediate data in the protection code modification instruction. If so, trigger the replacement return module; otherwise, report an error and trigger the reception judgment module;

[0296] The replacement return module is used to replace the protection code stored in the storage area corresponding to the storage area identifier with the new protection code in the protection code modification instruction, return a modification success response to the host computer, and trigger the receiving judgment module.

[0297] Optionally, the device of this embodiment further includes:

[0298] An eighth judgment module is configured to, when the receiving judgment module determines that the type of instruction is a protection code deletion instruction, determine whether the OTP application has been selected, and trigger the ninth judgment module if so; otherwise, report an error and trigger the receiving judgment module;

[0299] A ninth judgment module is used to judge whether the OTP application has set access rights, and if so, trigger the fourth acquisition and calculation judgment module; otherwise, an error is reported and the reception judgment module is triggered;

[0300] a fourth acquisition, calculation and judgment module, configured to obtain the protection code in the corresponding storage area according to the storage area identifier in the protection code deletion instruction, calculate third comparison data according to the protection code and the third random number in the protection code deletion instruction, and determine whether the third comparison data is consistent with the third intermediate data in the protection code deletion instruction. If so, triggering the first deletion and return module; otherwise, reporting an error and triggering the reception and judgment module;

[0301] The first deletion return module is used to delete the protection code stored in the storage area corresponding to the storage area identifier, return a deletion success response to the host computer, and trigger the receiving judgment module.

[0302] Optionally, the device of this embodiment further includes:

[0303] a tenth judgment module, configured to, when the receiving judgment module determines that the type of the instruction is a personalized data initialization instruction, determine whether the OTP application has been selected, and trigger the eleventh judgment module if so, otherwise report an error and trigger the receiving judgment module;

[0304] The eleventh judgment module is used to judge whether the OTP application has set access rights, and if so, trigger the fifth acquisition and calculation judgment module; otherwise, an error is reported and the reception judgment module is triggered;

[0305] a fifth acquisition, calculation and judgment module, configured to obtain a protection code from a corresponding storage area based on the storage area identifier in the personalized data initialization instruction, calculate fifth comparison data based on a fifth random number in the personalized data initialization instruction and the obtained protection code, and determine whether the fifth comparison data is consistent with the fifth intermediate data in the personalized data initialization instruction. If so, triggering the twelfth judgment module; otherwise, reporting an error and triggering the receiving and judgment module;

[0306] a twelfth judgment module, configured to judge whether the corresponding storage area is a default storage area according to the storage area identifier, and trigger the second deletion and return module if it is, otherwise, report an error and trigger the receiving judgment module;

[0307] The second deletion return module is used to delete the protection code and personalized data stored in the default storage area, return an initialization success response to the host computer, and trigger the receiving judgment module.

[0308] Optionally, the device of this embodiment further includes:

[0309] a thirteenth judgment module, configured to, when the receiving judgment module determines that the type of instruction is an enumeration personalized data instruction, determine whether the OTP application has been selected, and trigger the fourteenth judgment module if so, otherwise report an error and trigger the receiving judgment module;

[0310] The fourteenth judgment module is used to judge whether the OTP application has set access rights. If so, the sixth acquisition and calculation judgment module is triggered. Otherwise, an error is reported and the reception judgment module is triggered.

[0311] a sixth acquisition, calculation, and judgment module, configured to obtain, based on the storage area identifier in the instruction for enumerating personalized data, the protection code and all personalized data in the corresponding storage area, calculate sixth comparison data based on the sixth random number in the instruction for enumerating personalized data and the obtained protection code, and determine whether the sixth comparison data is consistent with the sixth intermediate data in the instruction for enumerating personalized data. If so, triggering the thirteenth judgment module; otherwise, reporting an error and triggering the receiving and judgment module;

[0312] a thirteenth judgment module, configured to judge whether the corresponding storage area is a default storage area according to the storage area identifier, and trigger the generation return module if it is, otherwise, report an error and trigger the reception judgment module;

[0313] The generation return module is used to generate an enumeration success response based on the acquired personalized data and return it to the host computer, triggering the receiving judgment module.

[0314] Optionally, the device of this embodiment further includes:

[0315] The receiving, generating and sending module is used to generate a dynamic password based on the seed in the general storage area after the online OTP device is inserted into the host computer, such as after receiving the user's confirmation key information, and send the dynamic password to the host computer for display.

[0316] The receiving, generating and sending module is used to send the dynamic password to the host computer for display, including: the receiving, generating and sending module is specifically used to send the dynamic password to the host computer for display according to the keyboard protocol format.

[0317] In this embodiment, after the upper computer receives the storage area configuration and the participating computing device data, it displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, it prompts the user to enter the access code of the selected storage area, and generates a protection code based on the received access code and the participating computing device data.

[0318] Specifically, if the participating computing device data is a challenge code, generating the protection code according to the received access code and the participating computing device data includes: performing a hash calculation on the access code and the challenge code by the host computer to obtain a first hash value, and extracting data at a predetermined position in the first hash value as the protection code;

[0319] Alternatively, if the participating computing device data is a device serial number, generating a protection code based on the received access code and participating computing device data includes: the host computer uses the access code and the device serial number as parameters, calls a preset algorithm to construct a symmetric key of a preset byte length and uses it as a protection code.

[0320] Preferably, the preset byte length is 16 bytes;

[0321] In this embodiment, after the host computer generates the protection code, it can generate various operation instructions based on the protection code, storage area identifier and other data, for example:

[0322] After receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select based on the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area. The host computer performs a hash calculation on the received access code and challenge code to obtain a first hash value. The host computer extracts the data at a predetermined position in the first hash value as a protection code. The host computer generates a set protection code instruction based on the storage area identifier and the protection code and sends the instruction to the online OTP device, and then returns to step S1.

[0323] Alternatively, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select based on the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area, performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a fourth random number, calculates the fourth random number using the protection code to obtain fourth intermediate data, generates a write personalized data instruction based on the storage area identifier, the fourth random number, the fourth intermediate data, and the personalized data, and sends the instruction to the online OTP device, and then returns to step S1;

[0324] Alternatively, the host computer performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a sixth random number, calculates the sixth random number using the protection code to obtain sixth intermediate data, generates an enumeration personalized data instruction based on the storage area identifier, the sixth random number, and the sixth intermediate data, and sends the instruction to the online OTP device, executing step S1;

[0325] The host computer parses the received enumeration success response to obtain the personalized data and displays it. When receiving the user's selection information, it can generate a personalized data processing instruction and a personalized data initialization instruction according to the name of the personalized data in the selection information;

[0326] Alternatively, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area, performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a first random number, calculates the first random number using the protection code to obtain first intermediate data, generates a personalized data processing instruction based on the storage area identifier, the first random number, the first intermediate data, and the name of the personalized data, and sends the instruction to the online OTP device, and then returns to step S1; the personalized data processing instruction includes a personalized data reset instruction, a personalized data deletion instruction, and a dynamic password generation instruction;

[0327] Alternatively, after the host computer receives the storage area configuration and the challenge code, it displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, it prompts the user to enter the old access code and the new access code of the selected storage area, performs a hash calculation on the received old access code and the challenge code to obtain a first hash value, extracts the data at a predetermined position in the first hash value as the old protection code, performs a hash calculation on the received new access code and the challenge code to obtain a second hash value, extracts the data at a predetermined position in the second hash value as the new protection code, generates a second random number, uses the old protection code to calculate the second random number to obtain second intermediate data, generates a modification protection code instruction according to the storage area identifier, the second random number, the second intermediate data and the new protection code, and sends the instruction to the online OTP device, and then returns to step S1;

[0328] Alternatively, after receiving the storage area configuration and the challenge code, the host computer displays the corresponding storage area for the user to select according to the storage area configuration. When receiving the user's selection information, the host computer prompts the user to enter the access code of the selected storage area, performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts data at a predetermined position in the first hash value as a protection code, generates a third random number, calculates the third random number using the protection code to obtain third intermediate data, generates a protection code deletion instruction based on the storage area identifier, the third random number, and the third intermediate data, and sends the instruction to the online OTP device, and then returns to step S1;

[0329] Alternatively, after the upper computer receives the storage area configuration and the challenge code, it displays the corresponding storage area for the user to select according to the storage area configuration, and when receiving the user's selection information, prompts the user to enter the access code of the selected storage area, performs a hash calculation on the received access code and challenge code to obtain a first hash value, extracts the data at a predetermined position in the first hash value as a protection code, generates a fifth random number, uses the protection code to calculate the fifth random number to obtain fifth intermediate data, generates a personalized data initialization instruction according to the storage area identifier, the fifth random number, the fifth intermediate data and the name of the personalized data, and sends it to the online OTP device, and returns to step S1.

[0330] Optionally, an embodiment of the present application further provides an electronic device, comprising at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, wherein the at least one processor executes the instructions to implement the method for implementing the online OTP device in the above embodiment. When the electronic device is a chip system, it can be composed of a chip or include a chip and other discrete devices, which is not specifically limited in the embodiment of the present application; the chip is coupled to the memory and is used to execute a computer program stored in the memory to execute the method for implementing the online OTP device in the above embodiment.

[0331] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on an electronic device, all or part of the processes or functions described in the embodiments of the present application are generated. The computer program can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one base station, electronic device, server, or data center to another base station, electronic device, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by the electronic device or a data storage device such as a server or data center that includes one or more media integrated therein. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state drive (SSD)). In the embodiments of the present application, the electronic device can include the device described above.

[0332] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other changes to the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0333] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, the present application is intended to include such modifications and variations as fall within the scope of the claims of the present application and their equivalents.

Claims

1. A working implementation method for an online OTP device, where the online OTP device is an electronic device with buttons that needs to be connected to a host computer for operation. The online OTP device has a default storage area and a general storage area built-in. The default storage area stores multiple pieces of personalized data, and the general storage area stores one piece of personalized data. The method includes: Step S1: When the online OTP device receives an instruction sent by the host computer, determine the type of the instruction. If it is a select application instruction, execute Step S2; if it is a set protection code instruction, execute Step S3; if it is a write personalized data instruction, execute Step S5; if it is a process personalized data instruction, execute Step S9; Step S2: The online OTP device selects the corresponding OTP application according to the application identifier in the select application instruction, obtains the set storage area configuration, generates a select application response based on the storage area configuration and the preset participating computing device data, and returns it to the host computer. The storage area configuration includes a storage area identifier and a storage area status code. Return to Step S1; Step S3: The online OTP device determines whether an OTP application has been selected. If so, execute Step S4; otherwise, report an error and return to Step S1; Step S4: The online OTP device determines whether the OTP application has set access rights. If so, report an error and return to Step S1; otherwise, save the protection code in the set protection code instruction in the storage area corresponding to the storage area identifier in the set protection code instruction, return a set success response to the host computer, and return to Step S1; Step S5: The online OTP device determines whether an OTP application has been selected. If so, execute Step S6; otherwise, report an error and return to Step S1; Step S6: The online OTP device determines whether the OTP application has set access rights. If so, execute Step S7; otherwise, report an error and return to Step S1; Step S7: The online OTP device obtains the protection code in the corresponding storage area according to the storage area identifier in the write personalized data instruction, calculates the fourth comparison data based on the fourth random number in the write personalized data instruction and the protection code, and determines whether the fourth comparison data is consistent with the fourth intermediate data in the write personalized data instruction. If so, execute Step S8; otherwise, report an error and return to Step S1; Step S8: The online OTP device determines whether the corresponding storage area is the default storage area according to the storage area identifier. If so, save the personalized data in the write personalized data instruction in the default storage area, return a write success response to the host computer, and return to Step S1; otherwise, update the personalized data saved in the storage area corresponding to the storage area identifier with the personalized data in the write personalized data instruction, return a write success response to the host computer, and return to Step S1; Step S9: The online OTP device determines whether an OTP application has been selected. If so, execute Step S10; otherwise, report an error and return to Step S1; Step S10: The online OTP device determines whether the OTP application has set access rights. If so, it proceeds to step S11; otherwise, it reports an error and returns to step S1. Step S11: The online OTP device obtains the protection code in the corresponding storage area according to the storage area identifier in the personalization data processing instruction, calculates the first comparison data based on the first random number in the personalization data processing instruction and the protection code, and determines whether the first intermediate data in the personalization data processing instruction is consistent with the first comparison data. If so, it proceeds to step S12; otherwise, it reports an error and returns to step S1. Step S12: The online OTP device performs corresponding processing on the personalization data saved in the storage area corresponding to the storage area identifier according to the personalization data processing instruction, and returns the processing result to the host computer, then returns to step S1.

2. The method according to claim 1, wherein the personalization data processing instruction is specifically a dynamic password generation instruction, and the personalization data includes seeds. The said step S12 includes: The online OTP device determines whether the corresponding storage area is the default storage area according to the storage area identifier. If so, it prompts the user to press a key for confirmation. When receiving the user's key confirmation information, it obtains the corresponding seed saved in the default storage area according to the name of the personalization data in the dynamic password generation instruction, generates a dynamic password according to the seed, generates a processing success response according to the processing success status code, the storage area status code, and the dynamic password, and returns it to the host computer, then returns to step S1. Otherwise, it prompts the user to press a key for confirmation. When receiving the user's key confirmation information generates a dynamic password according to the seed saved in the storage area corresponding to the storage area identifier, generates a processing success response according to the processing success status code, the storage area status code, and the dynamic password, and returns it to the host computer, then returns to step S1.

3. The method according to claim 1, wherein the instruction for processing personalized data is specifically an instruction for deleting personalized data, and the step S12 includes: The online OTP device determines whether the corresponding storage area is the default storage area according to the storage area identifier. If so, it prompts the user to press a key for confirmation. When receiving the user's key confirmation information, it deletes the personalization data corresponding to the name of the personalization data in the delete personalization data instruction saved in the default storage area, generates a processing success response according to the delete success status code and the storage area status code, and returns it to the host computer, then returns to step S1. Otherwise, it prompts the user to press a key for confirmation. When receiving the user's key confirmation information, it deletes the personalization data saved in the storage area corresponding to the storage area identifier, generates a processing success response according to the delete success status code and the storage area status code, and returns it to the host computer, then returns to step S1.

4. The method according to claim 1, wherein the instruction for processing personalized data is specifically a reset personalized data instruction, and the step S12 includes: The online OTP device determines whether the corresponding storage area is the default storage area according to the storage area identifier. If so, it prompts the user to press a key for confirmation. When receiving the user's key confirmation information, it updates the personalized data corresponding to the name of the personalized data in the reset personalized data instruction in the default storage area with the personalized data in the reset personalized data instruction, generates a successful processing response according to the reset success status code and the storage area status code, and returns it to the host computer, then returns to step S1. Otherwise, it prompts the user to press a key for confirmation. When receiving the user's key confirmation information, it updates the personalized data saved in the storage area corresponding to the storage area identifier with the personalized data in the reset personalized data instruction, generates a successful processing response according to the reset success status code and the storage area status code, and returns it to the host computer, then returns to step S1.

5. The method according to claim 1, wherein, If it is determined in step S1 that the type of the instruction is a modify protection code instruction, then execute step H1; Step H1: The online OTP device determines whether an OTP application has been selected. If so, execute step H2; otherwise, report an error and return to step S1; Step H2: The online OTP device determines whether the OTP application has set access rights. If so, execute step H3; otherwise, report an error and return to step S1; Step H3: The online OTP device obtains the protection code in the corresponding storage area according to the storage area identifier in the modify protection code instruction, generates second comparison data according to the second random number in the modify protection code instruction and the obtained protection code, and determines whether the second comparison data is the same as the second intermediate data in the modify protection code instruction. If so, execute step H4; otherwise, report an error and return to step S1; Step H4: The online OTP device replaces the protection code saved in the storage area corresponding to the storage area identifier with the new protection code in the modify protection code instruction, returns a modify success response to the host computer, and returns to step S1.

6. The method according to claim 1, wherein If it is determined in step S1 that the type of the instruction is a delete protection code instruction, then execute step L1; Step L1: The online OTP device determines whether an OTP application has been selected. If so, execute step L2; otherwise, report an error and return to step S1; Step L2: The online OTP device determines whether the OTP application has set access rights. If so, execute step L3; otherwise, report an error and return to step S1; Step L3: The online OTP device obtains the protection code in the corresponding storage area according to the storage area identifier in the delete protection code instruction, calculates third comparison data according to the protection code and the third random number in the delete protection code instruction, and determines whether the third comparison data is consistent with the third intermediate data in the delete protection code instruction. If so, execute step L4; otherwise, report an error and return to step S1; Step L4: The online OTP device deletes the protection code saved in the storage area corresponding to the storage area identifier, returns a delete success response to the host computer, and returns to step S1.

7. The method according to claim 1, wherein, If it is determined in step S1 that the type of the instruction is a personalized data initialization instruction, then execute step K1; Step K1: The online OTP device determines whether an OTP application has been selected. If so, it proceeds to Step K2; otherwise, it reports an error and returns to Step S1. Step K2: The online OTP device determines whether the OTP application has set access rights. If so, it proceeds to Step K3; otherwise, it reports an error and returns to Step S1. Step K3: The online OTP device obtains the protection code in the corresponding storage area according to the storage area identifier in the personalization data initialization instruction, calculates the fifth comparison data based on the fifth random number in the personalization data initialization instruction and the obtained protection code, and determines whether the fifth comparison data is consistent with the fifth intermediate data in the personalization data initialization instruction. If so, it proceeds to Step K4; otherwise, it reports an error and returns to Step S1. Step K4: The online OTP device determines whether the corresponding storage area is the default storage area according to the storage area identifier. If so, it proceeds to Step K5; otherwise, it reports an error and returns to Step S1. Step K5: The online OTP device deletes the protection code and personalization data saved in the default storage area, returns an initialization success response to the host computer, and returns to Step S1.

8. The method according to claim 1, wherein If it is determined in Step S1 that the type of the instruction is an enumerated personalization data instruction, then Step P1 is executed. Step P1: The online OTP device determines whether an OTP application has been selected. If so, it proceeds to Step P2; otherwise, it reports an error and returns to Step S1. Step P2: The online OTP device determines whether the OTP application has set access rights. If so, it proceeds to Step P3; otherwise, it reports an error and returns to Step S1. Step P3: The online OTP device obtains the protection code and all personalization data in the corresponding storage area according to the storage area identifier in the enumerated personalization data instruction, calculates the sixth comparison data based on the sixth random number in the enumerated personalization data instruction and the obtained protection code, and determines whether the sixth comparison data is consistent with the sixth intermediate data in the enumerated personalization data instruction. If so, it proceeds to Step P4; otherwise, it reports an error and returns to Step S1. Step P4: The online OTP generates an enumeration success response based on the obtained personalization data and returns it to the host computer, and returns to Step S1.

9. The method according to claim 1, further comprising: After receiving the storage area configuration and the data of the participating computing device, the host computer displays the storage area configuration for the user to select. When receiving the user's selection information, it prompts the user to input the access code corresponding to the selected storage area identifier, and generates a protection code based on the received access code and the data of the participating computing device.

10. The method according to claim 9, wherein the participating computing device data is a challenge code, and the generating of the protection code according to the received access code and the participating computing device data specifically comprises: The host computer performs a hash calculation on the access code and the challenge code to obtain a first hash value, and extracts the data at a predetermined position in the first hash value as the protection code. Or, the data of the participating computing device is the device serial number. The specific process of generating the protection code based on the received access code and the data of the participating computing device includes: The host computer uses the access code and the device serial number as parameters, calls a preset algorithm to construct a symmetric key with a preset byte length and uses it as the protection code.

11. The method according to claim 1, wherein the online OTP device determines whether the access right is set for the OTP application, including: The online OTP device determines whether a protection code is stored in the storage area corresponding to the storage area identifier in the received instruction. If so, the OTP application sets the access right; otherwise, the OTP application does not set the access right.

12. The method according to claim 1, further comprising: After the online OTP device is connected to the host computer, if it receives the user's confirmation key information, the online OTP device generates a dynamic password based on the seed in the common storage area and sends the dynamic password to the host computer for display.

13. The method according to claim 12, wherein the sending the dynamic password to the host computer for display includes: The dynamic password is sent to the host computer for display according to the keyboard protocol format.

14. An operating implementation device of an online OTP device. The online OTP device is an electronic device with keys that needs to be connected to a host computer for operation. The online OTP device has a default storage area and a common storage area built-in. The default storage area stores multiple pieces of personalized data, and the common storage area stores one piece of personalized data. The device includes: A receiving and judging module, which is used to receive the instruction sent by the host computer. When an instruction is received, it judges the type of the instruction. If it is a select application instruction, it triggers the select calculation and return module; if it is a set protection code instruction, it triggers the first judgment module; if it is a write personalized data instruction, it triggers the second judgment module; if it is a process personalized data instruction, it triggers the fourth judgment module; The select calculation and return module is used to select the corresponding OTP application according to the application identifier in the select application instruction, obtain the set storage area configuration, generate a select application response based on the storage area configuration and the preset participating calculation device data, and return it to the host computer. The storage area configuration includes a storage area identifier and a storage area status code, and triggers the receiving and judging module; The first judgment module is used to judge whether an OTP application has been selected. If so, it triggers the judgment setting and return module; otherwise, it reports an error and triggers the receiving and judging module; The judgment setting and return module is used to judge whether the OTP application has set the access right. If so, it reports an error and triggers the receiving and judging module; otherwise, it saves the protection code in the setting protection code instruction in the storage area corresponding to the storage area identifier in the setting protection code instruction, returns a setting success response to the host computer, and triggers the receiving and judging module; The second judgment module is used to judge whether an OTP application has been selected. If so, it triggers the third judgment module; otherwise, it reports an error and triggers the receiving and judging module; The third judgment module is used to judge whether the OTP application has set the access right. If so, it triggers the first acquisition calculation and judgment module; otherwise, it reports an error and triggers the receiving and judging module; The first acquisition calculation and judgment module is used to obtain the protection code in the corresponding storage area according to the storage area identifier in the write personalized data instruction, calculate the fourth comparison data based on the fourth random number in the write personalized data instruction and the protection code, and judge whether the fourth comparison data is consistent with the fourth intermediate data in the write personalized data instruction. If so, it triggers the judgment write module; otherwise, it reports an error and triggers the receiving and judging module; The fourth judgment module is used to judge whether an OTP application has been selected. If so, it triggers the fifth judgment module; otherwise, it reports an error and triggers the receiving and judging module; The described write judgment module is used to judge whether the corresponding storage area is the default storage area according to the storage area identifier. If so, it saves the personalization data in the write personalization data instruction in the default storage area, returns a write success response to the host computer, and returns to step S1. Otherwise, it updates the personalization data saved in the storage area corresponding to the storage area identifier with the personalization data in the write personalization data instruction, returns a write success response to the host computer, and triggers the receive judgment module; The described fourth judgment module is used to judge whether the OTP application has been selected. If so, it triggers the fifth judgment module. Otherwise, it reports an error and triggers the receive judgment module; The described fifth judgment module is used to judge whether the OTP application has set access rights. If so, it triggers the second acquisition calculation judgment module. Otherwise, it reports an error and triggers the receive judgment module; The described second acquisition calculation judgment module is used to obtain the protection code in the corresponding storage area according to the storage area identifier in the process personalization data instruction, calculate the first comparison data according to the first random number in the process personalization data instruction and the protection code, and judge whether the first intermediate data in the process personalization data instruction is consistent with the first comparison data. If so, it triggers the process return module. Otherwise, it reports an error and triggers the receive judgment module; The described process return module is used to perform corresponding processing on the personalization data saved in the storage area corresponding to the storage area identifier according to the process personalization data instruction, and return the processing result to the host computer, triggering the receive judgment module.

15. An electronic device, wherein the electronic device includes at least one processor, a memory, and instructions stored on the memory and executed by the at least one processor. The at least one processor executes the instructions to implement the working implementation method of the online OTP device according to any one of claims 1 to 13.

16. A computer-readable storage medium, wherein the computer-readable storage medium includes a computer program. When the computer program runs on an electronic device, it causes the electronic device to execute the working implementation method of the online OTP device according to any one of claims 1 to 13.

17. A chip system includes a chip coupled to a memory for executing a computer program stored in the memory to execute the working implementation method of the online OTP device according to any one of claims 1 - 13.

Citation Information

Patent Citations

  • Data protecting method based on portable storage device

    CN103678959A

  • Encryption method, decryption method, electronic equipment and storage medium

    CN112257121A

  • Identity authentication implementation method and device

    CN114338052A

  • Work implementation method and device of online OTP (One Time Programmable) equipment

    CN117473560A

  • Automatic replacement of passwords with secure claims

    US10484372B1