Interface expansion circuit, and USB-key and control method therefor

By introducing interface expansion circuits for master and slave chips into the USB-KEY, local devices and cloud servers can access the USB-KEY simultaneously, solving the problems of high hardware cost and management complexity in existing technologies, and achieving cost reduction and management simplification.

WO2026011522A1PCT designated stage Publication Date: 2026-01-15SHANGHAI HUASHEN INTELLIGENT IC CARD APPL SYST
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/111391
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-10
Filing Date
2024-08-12
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

Existing technologies have drawbacks such as high hardware costs and increased management complexity when accessing a USB-KEY simultaneously from local devices and cloud servers. In particular, they have limitations when using multi-session access, USB redirection software in conjunction with virtualization technology and customized services from cloud service providers.

Method used

By introducing interface expansion circuits for master and slave chips into the USB-KEY, the master chip performs identity authentication and extends the slave chip through interface analog signals, enabling simultaneous access by local devices and cloud servers. The SPI interface and USB HUB chip management interface are used to ensure independent authentication for each chip.

Benefits of technology

It enables simultaneous access to the USB-KEY by local devices and cloud servers, reducing hardware costs and management complexity, and minimizing the need to manage multiple USB-KEY devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024111391_15012026_PF_FP_ABST
    Figure CN2024111391_15012026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present invention are an interface expansion circuit, and a USB-key and a control method therefor. The interface expansion circuit comprises: a master chip, wherein after receiving a first authentication instruction, the master chip loads a security authentication algorithm in a first memory space to perform first identity authentication, the master chip serves as a first USB-key and outputs first identity authentication information, and the master chip sends an interface simulation signal; and a slave chip, which is connected to the master chip, and simulates a second USB-key in response to the interface simulation signal sent by the master chip, wherein when the master chip receives a second authentication instruction of the slave chip, the master chip loads the security authentication algorithm in a second memory space to perform second identity authentication, and maps second identity authentication information to the slave chip, and the slave chip serves as the second USB-key to output the second identity authentication information. The present invention realizes the expansion of a USB-key interface, so that a local device and a cloud server simultaneously access the same USB-key, thereby reducing enterprise costs and the complexity of hardware device management.
Need to check novelty before this filing date? Find Prior Art

Description

Interface expansion circuit, USB-KEY and its control method Technical Field

[0001] This invention relates to the field of security authentication for USB-KEYs, and more particularly to interface expansion circuits, USB-KEYs, and USB-KEY control methods. Background Technology

[0002] USB keys, often referred to as USB security tokens or U-shields, are used to enhance computer system security, providing users with a secure means of authentication and data protection. Currently, methods enabling simultaneous access to a USB key by local devices and cloud servers include: USB server devices, USB redirection software combined with virtualization technology, specific interface services from cloud service providers, and dual USB keys. However, using USB server devices that support multi-session access requires additional hardware purchases, leading to higher costs; USB redirection software combined with virtualization technology shares USB key usage rights by switching between local devices and cloud servers, making data synchronization impossible; specific services from cloud service providers require customized solutions, and service availability is limited by the support and maintenance provided by the cloud service provider; using dual USB keys requires managing two devices, increasing enterprise costs and the complexity of hardware management.

[0003] Summary of the Invention

[0004] The purpose of this invention is to provide an interface expansion circuit, a USB-KEY, and a control method thereof to expand the USB-KEY interface. When a local device and a cloud server access the USB-KEY simultaneously, the USB-KEY's security chip expands the USB-KEY through an interface analog signal, enabling the local device and cloud server to synchronize the status and operation data of their respective USB-KEYs in real time, reducing hardware costs and simplifying hardware device management.

[0005] The technical solution provided by this invention is as follows:

[0006] This invention provides an interface expansion circuit for use in a USB-KEY, comprising:

[0007] Upon receiving the first authentication command, the main chip loads a security authentication algorithm into the first memory space to perform the first identity authentication. The main chip acts as the first USB-KEY and outputs the first identity authentication information. The main chip also sends an interface analog signal.

[0008] From the chip, it connects to the main chip; in response to the interface simulation signal sent by the main chip, it simulates a second USB-KEY.

[0009] When the master chip receives the second authentication command from the slave chip, the master chip loads the security authentication algorithm in the second memory space to perform the second identity authentication and maps the second identity authentication information to the slave chip; the slave chip acts as the second USB-KEY and outputs the second identity authentication information.

[0010] Furthermore, it also includes: a USB HUB chip, which is connected to the master chip and the slave chip respectively, for managing the USB interface; allowing the slave chip to emulate a second USB-KEY as an independent USB-KEY.

[0011] Furthermore, it also includes a USB power supply module connected to the main chip to provide stable power during the main chip's authentication process.

[0012] Furthermore, it also includes: the master chip is connected to the slave chip via an SPI interface.

[0013] Furthermore, it also includes a main chip and a slave chip that are USB-KEY chips.

[0014] The present invention also provides a USB-KEY, comprising: an interface expansion circuit including any of the steps described above.

[0015] The present invention also provides a method for controlling a USB-KEY, comprising:

[0016] The master chip acts as the first USB-KEY, sending an interface simulation signal to the slave chip; the slave chip responds to the interface simulation signal sent by the master chip and simulates a second USB-KEY.

[0017] When the first USB-KEY receives the first authentication command, it loads the security authentication algorithm into the first memory space on the main chip to perform the first identity authentication, and the first USB-KEY outputs the first identity authentication information.

[0018] When the master chip receives the second authentication command sent by the slave chip, the master chip loads a security authentication algorithm in the second memory space to perform the second identity authentication and maps the second identity authentication information to the slave chip; the second USB-KEY outputs the second identity authentication information.

[0019] Furthermore, after the chip simulates the second USB-KEY in response to the interface simulation signal sent by the main chip, the process also includes: mapping one of the first USB-KEY and the second USB-KEY to the cloud server, and connecting the remaining USB-KEY to the local device; the cloud server and the local device synchronize the status and operation data of their respective USB-KEYs in real time.

[0020] Furthermore, the slave chip sends the second authentication command to the master chip via the SPI interface.

[0021] Furthermore, the first and second authentication instructions include security authentication and digital signatures.

[0022] This invention provides an interface expansion circuit, a USB-KEY, and a control method thereof, enabling the expansion of the USB-KEY interface. When the cloud server accesses the USB-KEY, the local device's USB-KEY is not ejected. The cloud server and the local device independently complete authentication using their respective USB-KEYs, reducing the complexity of managing multiple USB-KEY devices and decreasing the cost of purchasing other hardware. Attached Figure Description

[0023] The preferred embodiments will now be described in a clear and easy-to-understand manner, with reference to the accompanying drawings, to further explain the above-mentioned characteristics, technical features, advantages, and implementation methods of an interface expansion circuit, a USB-KEY, and a USB-KEY control method.

[0024] Figure 1 is a circuit structure diagram of an embodiment of an interface expansion circuit of the present invention;

[0025] Figure 2 is a circuit diagram of the USB port power supply module of an interface expansion circuit according to the present invention;

[0026] Figure 3 is a circuit structure diagram of the crystal oscillator and reset circuit of an interface expansion circuit according to the present invention;

[0027] Figure 4 is a schematic diagram illustrating the working principle of an embodiment of a USB-KEY control method according to the present invention. Detailed Implementation

[0028] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application can also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0029] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or sets.

[0030] It should also be further understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0031] Furthermore, in the description of this application, the terms "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0032] A USB-KEY, also known as a U-shield, is a high-security tool used for electronic banking transactions. It typically contains a built-in micro smart card processor that uses digital certificates to ensure the security of transaction data. The U-shield connects to a computer or other device via a USB interface and is used for identity authentication, data encryption and decryption, digital signatures, and secure storage to guarantee the security of electronic banking transactions.

[0033] For a standard USB key, when it's plugged into a local device's USB port, the local device's operating system recognizes the key through a driver. The driver then establishes a communication connection with the key to send and receive data after authentication. In some special business scenarios, such as two-factor authentication, remote access and local operation, or cross-platform operation, both the cloud server and the local device need to access the key simultaneously. However, for security reasons, when the cloud server accesses a standard USB key, the key will not be used in two places simultaneously, causing the local device's key to log out. Alternatively, if USB redirection technology is used, once the key is redirected to the cloud server, the local device's access permissions may be revoked, causing the local device to log out.

[0034] Under current technology, when a USB-KEY communicates with a cloud server, the local device cannot simultaneously recognize the security certificate. This is because the USB-KEY is mapped from the local device to the cloud server, and its functions and interfaces are transferred to the remote environment via a network connection. Therefore, the local device cannot directly access the USB-KEY as it would normally. To enable simultaneous access to the USB-KEY by both the local device and the cloud server, the following methods are currently used: employing a USB Server device that supports multi-session access, providing a network interface for different systems to connect and use the USB-KEY; using USB redirection software in conjunction with virtualization technology to share the USB-KEY connected to the physical host with the cloud server; using a specific service from a cloud service provider to share the USB-KEY to the cloud server via a dedicated secure channel; and employing a dual USB-KEY approach, with two independent USB-KEYs used for authentication and encryption operations on the local device and cloud server environments respectively.

[0035] However, using USB Server devices that support multi-session access requires additional hardware purchases, resulting in higher costs; USB redirection software, combined with virtualization technology, shares the right to use the USB-KEY by switching between local devices and cloud servers, making it impossible to synchronize operational data; specific services from cloud service providers require collaboration with cloud service providers to develop customized solutions, and service availability is also limited by the support and maintenance of cloud service providers; adopting a dual USB-KEY approach requires managing two devices, increasing enterprise costs and the complexity of hardware management.

[0036] Therefore, this invention provides a USB-KEY that allows both local devices and cloud servers to access it simultaneously. Furthermore, through interface expansion, cloud servers and local devices can independently complete authentication using their respective USB-KEYs. Based on this invention, the USB-KEY enables simultaneous login from both cloud servers and local devices without requiring customized solutions, dual USB-KEYs, or USB Servers, thus reducing hardware procurement costs and the complexity of hardware management.

[0037] The USB-KEY of this invention achieves identity authentication by loading a digital certificate stored in the main chip, which embeds identity information and the digital certificate. The interface extended from the slave chip in the USB-KEY is a communication channel. The slave chip performs identity authentication by loading the identity information from the main chip, and its operation instructions are distributed to the main chip to simulate the main chip's function. The USB-KEY of this invention is generated based on an interface extension circuit, which includes a main chip and a slave chip, expanding the USB-KEY interface. This allows local devices and cloud servers to access the USB-KEY simultaneously, while the cloud server and local device can independently complete authentication using their respective USB-KEYs.

[0038] The following description is in conjunction with the accompanying drawings:

[0039] In one embodiment of the present invention, as shown in FIG1, an interface expansion circuit includes:

[0040] When the main chip 10 receives the first authentication command, the main chip 10 loads the security authentication algorithm in the first memory space to perform the first identity authentication. The main chip 10 acts as the first USB-KEY, outputs the first identity authentication information, and sends the interface analog signal.

[0041] Chip 20 is connected to main chip 10; in response to the interface simulation signal sent by main chip 10, it simulates a second USB-KEY.

[0042] When the main chip 10 receives the second authentication instruction from the slave chip 20, the main chip 10 loads the security authentication algorithm in the second memory space to perform the second identity authentication, and maps the second identity authentication information to the slave chip 20. The slave chip 20 acts as the second USB-KEY and outputs the second identity authentication information.

[0043] Specifically, both the main chip 10 and the slave chip 20 are secure cryptographic chips used to ensure that the communication channel for USB-KEY authentication is not exposed. The main chip 10, as the first USB-KEY, possesses complete USB-KEY functionality, including security authentication and digital signatures. The main chip contains multiple memory spaces: one for authentication of the first USB-KEY, and the others for authentication of other extended USB-KEYs.

[0044] In this embodiment, both the master chip 10 and the slave chip 20 have SPI interfaces. The SPI interface of the master chip 10 and the SPI interface of the slave chip 20 are connected via the SPI full-duplex protocol, so the master chip 10 and the slave chip 20 can simultaneously perform bidirectional communication and data transmission.

[0045] In this embodiment, the master chip 10 has three SPI interfaces: MISO, MOSI, and SCK. The MISO and MOSI interfaces are input / output interfaces, and the SCK interface is a clock interface. The slave chip 20 also has three SPI interfaces: MISO, MOSI, and SCK. The MISO and MOSI interfaces are input / output interfaces, and the SCK interface is a clock interface. In this embodiment, the MISO, MOSI, and SCK interfaces are connected accordingly. By connecting the corresponding SPI interfaces of the master chip 10 and the slave chip 20, data transmission and control command exchange between the master and slave chips are achieved through the SPI communication protocol as a communication bridge. This enables fast and stable data transmission and real-time synchronization of the status and operation data of both parties, ensuring consistency between the device and the virtual cloud server in accessing and operating the USB-KEY.

[0046] The SDA and SCL pins of the master chip 10 are connected to the SDA and SCL pins of the slave chip 20. The master chip 10 sends interface simulation signals to the slave chip 20 through these two pins, enabling one USB-KEY hardware device to simulate the behavior of multiple devices. The slave chip 20 responds to the simulation signals to simulate a second USB-KEY. When the second USB-KEY of the slave chip 20 needs to be authenticated, it needs to send an authentication command to the master chip 10. After the master chip authenticates the identity of the second USB-KEY in the second memory space, it sends the result back to the slave chip 20.

[0047] Please refer to Figure 1. When implementing interface expansion, after the second USB-KEY is added, it needs to be independently identifiable. The interface expansion circuit also includes:

[0048] USB HUB chip 30 is connected to master chip 10 and slave chip 20 respectively. It is mainly responsible for coordinating data transmission between the host and multiple USB devices. It can be used for data transmission management, bandwidth management, port expansion, etc. It is used to manage USB interfaces and allows slave chip 20 to simulate a second USB-KEY as an independent USB-KEY.

[0049] Specifically, in this embodiment, the USB HUB chip 30 has multiple USB expansion interfaces, which are connected to the DP and DM pins of the master chip 10 and the slave chip 20 respectively. The master chip 10 and the slave chip 20 can simultaneously perform independent data transmission with external devices through these two USB ports.

[0050] The USB HUB chip 30 has two upload interfaces (DM1, DP1), and the main chip 10 has two downlink interfaces (DM1, DP1). The two downlink interfaces (DM1, DP1) of the main chip 10 are connected to the two upload interfaces (DM1, DP1) of the USB HUB expansion chip 30. The signal transmitted between the main chip 10 and the USB HUB expansion chip 30 is a differential signal.

[0051] The USB HUB chip 30 has two upload interfaces (DM2, DP2), and the slave chip 20 has two downlink interfaces (DM2, DP2). The two downlink interfaces (DM2, DP2) of the slave chip 20 are connected to the two upload interfaces (DM2, DP2) of the USB HUB expansion chip 30. The signal transmitted between the slave chip 20 and the USB HUB expansion chip 30 is a differential signal.

[0052] The differential signal between the master and slave chips allows the USB-KEY to be independently recognized in both the physical host and the virtual machine.

[0053] Please refer to Figure 2. When the main chip 10 performs identity authentication, it needs to be provided with a stable voltage suitable for the operation of the main chip 10. The interface expansion circuit also includes:

[0054] The USB power supply module 40 is connected to the main chip 10 and is used to provide a stable power supply when the main chip 10 performs identity authentication.

[0055] Specifically, in this embodiment, the USB port power supply module 40 is connected to the positive power electrode (VDD33) of the main chip 10 to provide a stable power supply during the main chip 10's authentication process, ensuring its normal operation and computation. The USB-KEY connects to a local device, such as a computer or laptop, via its USB interface. When the USB-KEY's power supply module detects the USB connection and identifies the power supplied by the local device, it converts the voltage provided by the local device (such as the 5V USB standard voltage) into different voltage levels suitable for the operation of the USB-KEY main chip 10, ensuring a stable power supply to the main chip.

[0056] The USB port power supply module 40 contains a circuit board of model AS2932M5-3.3, where the VOUT pin outputs the regulated and stable voltage to the main chip 10. Capacitors and resistors in the USB port power supply module 40 are used to filter out noise and ripple on the input power supply, providing a smoother DC power supply.

[0057] Please refer to Figure 3. To ensure stable and reliable operation of the main chip 10 during identity authentication, the interface expansion circuit also includes:

[0058] The crystal oscillator circuit 50 is connected to the EXTAL pin of the main chip 10 and the EXTAL pin of the slave chip 20 respectively. It mainly provides a stable clock signal to the main chip 10 and the slave chip 20 to ensure that the digital logic circuits inside the main chip 10 and the slave chip 20 operate synchronously and avoid data misalignment.

[0059] The crystal oscillator circuit 50 also includes an oscillator module. The VCC pin of the oscillator provides the power supply voltage to the oscillator; the CLK pin outputs the clock signal generated by the oscillator; the OE pin is a control pin. When OE is set to a low level, the CLK output may be disabled, while when it is set to a high level, the CLK output is enabled.

[0060] The reset circuit 60 has its RSTOUT pin connected to the FCEN pin of the main chip 10 and its VDD33 pin connected to the VDD33 pin of the slave chip 20. It is used for system startup initialization and fault recovery, ensuring the secure authentication of the main chip. The reset circuit 60 includes resistors and capacitors to form a delay circuit, achieving delayed release of the reset signal. It also uses a PNP transistor to generate and control the reset signal, ensuring that the circuit can be correctly initialized during reset.

[0061] The crystal oscillator circuit 50 and the reset circuit 60 together ensure the stable operation and reliability of the master chip 10 and the slave chip 20. The crystal oscillator circuit 50 provides the necessary clock signal, while the reset circuit 60 provides a reset mechanism when the system starts up or encounters a problem.

[0062] Please refer to Figure 4, which shows a flowchart of a USB-KEY control method provided in some embodiments of this disclosure. This method is executed based on the interface expansion circuit described above and includes at least the following steps:

[0063] The S100 master chip acts as the first USB-KEY, sending an interface simulation signal to the slave chip. The slave chip responds to the interface simulation signal sent by the master chip and simulates a second USB-KEY.

[0064] When the first USB-KEY receives the first authentication command, the S200 loads the security authentication algorithm in the first memory space on the main chip to perform the first identity authentication, and the first USB-KEY outputs the first identity authentication information.

[0065] When the S300 receives the second authentication command from the slave chip, the main chip loads the security authentication algorithm in the second memory space to perform the second identity authentication, and maps the second identity authentication information to the slave chip. The second USB-KEY then outputs the second identity authentication information.

[0066] Specifically, a USB-KEY, also known as a U-shield, is used to enhance the security of computer systems, providing users with a secure means of authentication and data protection.

[0067] When the USB-KEY is inserted into the USB port of the physical host, the internal firmware is started. The USB controller of the physical host will detect the access of a new device, and the operating system will search for and load the corresponding driver. If there is already a suitable driver in the system, the driver will establish a communication connection with the USB-KEY, and the main chip will be initialized.

[0068] The master chip sends an interface activation simulation signal to the slave chip through the communication interface. After receiving the activation command, the slave chip responds to the simulation signal and activates the USB-KEY simulation function of the slave chip, thereby simulating a second USB-KEY.

[0069] After the main chip is initialized, the authentication algorithm needs to be loaded in preparation for secure authentication. The USB key typically has a secure storage area for storing sensitive information such as the authentication algorithm and keys. The main chip reads the necessary authentication algorithm from this secure storage area. After the algorithm is read, it is loaded into the main chip's memory for execution. These algorithms may include symmetric encryption algorithms, asymmetric encryption algorithms, hash algorithms, etc. After the authentication algorithm is loaded, the USB key establishes a secure session with the computer or other host device to ensure the security of data transmission.

[0070] In one embodiment of this application, the main chip contains two memory spaces. The first memory space is used for authentication of the first USB-KEY, and the second memory space is used for authentication of the second USB-KEY of the slave chip. After authentication, the main chip maps the authentication result of the second USB-KEY to the slave chip.

[0071] After the chip simulates the second USB-KEY in response to the interface simulation signal sent by the main chip, the above step S100 may include: mapping one of the first USB-KEY and the second USB-KEY to the cloud server, and connecting the remaining USB-KEY to the local device; the cloud server and the local device independently complete authentication through their respective USB-KEYs.

[0072] Specifically, before the two USB keys can be mapped, they need to be identified. A USB hub chip is an integrated circuit used to manage the connection of multiple USB devices. When managing USB interfaces, it can control the local host to recognize the simulated devices connected to the hub. If a USB key is connected to the local device via the USB hub and the chip simulates the key's signals, the USB hub chip can correctly transmit these simulated signals to the host, allowing the host to recognize the simulated key as an independent device.

[0073] A USB hub allows the chip-emulated USB key to be recognized as an independent device by the physical host. Either of the two USB keys recognized by the local device can be mapped to a virtual cloud server. On the local device, after the operating system recognizes the connected USB key, it configures the virtualization environment, selects the appropriate cloud server, chooses one of the USB keys on the cloud server for connection, and loads the corresponding driver. The other USB key is then connected to the local device.

[0074] Based on the ability to independently recognize and manage USB keys in both the local device and virtual cloud server environments, applications in the local device and virtual machine can be configured to use the connected or mapped USB key for operations. The local device and virtual cloud server can operate on their respective USB keys simultaneously.

[0075] When the slave chip sends the second authentication command to the master chip, the above step S300 may include: the slave chip sending the second authentication command to the master chip through the SPI interface.

[0076] Specifically, during the process of simulating a second USB-KEY using the slave chip, the master chip and the slave chip establish a communication connection through the SPI interface to achieve high-speed data transmission and control signal exchange, ensuring the smooth progress of the task. The slave chip sends data to the master chip through the MISO pin, the master chip sends data to the slave chip through the MOSI pin, and then synchronizes the data transmission through the SCK pin.

[0077] When both the master chip and the slave chip receive operation commands simultaneously, the master chip sends control commands or data to the slave chip via the SPI interface. These operation commands include security authentication, digital signatures, etc. The master chip and the slave chip take turns responding to the commands from the upper-layer application, and the master chip and the slave chip synchronize data transmission via the SCK line.

[0078] When the master chip and slave chip do not receive operation instructions at the same time, and only the master chip receives the operation instructions, a security authentication algorithm is loaded into the first memory space of the master chip to authenticate the master chip's identity. The processor on the master chip executes the task to be completed, stores the calculation result in the internal memory of the master chip, and transmits the calculated result to the upper layer application through the corresponding communication interface.

[0079] When the master chip and slave chip do not receive operation instructions simultaneously, and only the slave chip receives the operation instructions, the slave chip sends the received instructions to the master chip through the MISO line. After receiving the instructions from the slave chip, the master chip loads a security authentication algorithm in its second memory space to authenticate the slave chip's identity, and maps the second authentication information to the slave chip through the MOSI line. The slave chip then transmits the calculation results to the upper-layer application through the corresponding communication interface.

[0080] Based on the interface expansion circuit of this application, the USB-KEY interface can be expanded through the above-mentioned USB-KEY control method. When the cloud server accesses the USB-KEY, the local device's USB-KEY will not be ejected. The cloud server and the local device can independently complete authentication through their respective USB-KEYs, which reduces the complexity of managing multiple USB-KEY devices and reduces the cost of purchasing other hardware devices.

[0081] It should be noted that the above embodiments can be freely combined as needed. The above description is only a preferred embodiment of the present invention. It should be pointed out that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. An interface expansion circuit, used in a USB-KEY, characterized in that, include: Upon receiving the first authentication command, the main chip loads a security authentication algorithm into the first memory space to perform the first identity authentication. The main chip acts as the first USB-KEY and outputs the first identity authentication information. The main chip also sends an interface analog signal. The chip connects to the main chip; In response to the interface simulation signal sent by the main chip, a second USB-KEY is simulated; When the master chip receives the second authentication instruction from the slave chip, the master chip loads the security authentication algorithm in the second memory space to perform the second identity authentication and maps the second identity authentication information to the slave chip; the slave chip acts as the second USB-KEY and outputs the second identity authentication information.

2. The interface expansion circuit according to claim 1, characterized in that, Also includes: The USB HUB chip is connected to the main chip and the slave chip respectively, and is used to manage the USB interface; This allows the chip to emulate a second USB-KEY as a standalone USB-KEY.

3. The interface expansion circuit according to claim 1, characterized in that, Also includes: The USB power supply module is connected to the main chip and is used to provide a stable power supply when the main chip performs identity authentication.

4. The interface expansion circuit according to claim 1, characterized in that: The master chip is connected to the slave chip via an SPI interface.

5. The interface expansion circuit according to claim 1, characterized in that: The master chip and slave chip are secure cryptographic chips.

6. A USB-KEY, characterized in that, Includes the interface expansion circuit described in any one of claims 1-5.

7. A method for controlling a USB-KEY, characterized in that, include: The master chip acts as the first USB-KEY, sending interface analog signals to the slave chip; The slave chip responds to the interface simulation signal sent by the master chip to simulate a second USB-KEY; When the first USB-KEY receives the first authentication command, a security authentication algorithm is loaded into the first memory space on the main chip to perform the first identity authentication, and the first USB-KEY outputs the first identity authentication information. When the master chip receives the second authentication command sent by the slave chip, the master chip loads the security authentication algorithm in the second memory space to perform the second identity authentication and maps the second identity authentication information to the slave chip; The second USB-KEY outputs the second identity authentication information.

8. The control method for a USB-KEY according to claim 7, characterized in that, After the slave chip simulates a second USB-KEY in response to the interface simulation signal sent by the master chip, the method further includes: Map one of the first USB-KEY and the second USB-KEY to the cloud server, and connect the remaining USB-KEY to the local device; the cloud server and the local device independently complete authentication through their respective USB-KEYs.

9. The control method for a USB-KEY according to claim 7, characterized in that: The slave chip sends the second authentication command to the master chip via the SPI interface.

10. The control method for a USB-KEY according to claim 7, characterized in that: The first and second authentication instructions include security authentication and digital signature.

Citation Information

Patent Citations

  • Electronic signature verification extension equipment and information processing method

    CN104102871A

  • Extending single-sign-on to relying parties of federated logon providers

    CN111052706A

  • Main control for USB key

    CN202093520U

  • Data exchange system

    WO2016045573A1