A kind of intelligent cipher key equipment and with the mutual method of host information
Technical field
The present invention relates to information security field, particularly a kind of intelligent cipher key equipment and with the mutual method of host information.
Background technology
Intelligent cipher key equipment is as terminal encryption and decryption and authenticating device, and it directly provides safeguard protection for system and hardware view, guarantees that key message such as key, certificate and Authorization Attributes etc. are safely stored in the hardware device.Along with smart card and USB broad application, intelligent cipher key equipment has spread in users' hand.
Several big international IT enterprises have been formulated CCID (USB Chip/Smart CardInterface Devices-USB chip intelligent card equipment) interface standard jointly at the problem of application of IC cards aspect.The CCID kind equipment is chip/intelligence card interface device, and this kind equipment meets the data of CCID interface standard by the USB interface transmitting-receiving, thereby makes equipment be connected communication with main frame or other embedded host.Microsoft provides on its WINDOWS2000 and above operating system and supports CCID to drive, and device fabrication manufacturer can be developed easily use the equipment that meets the CCID interface standard.Simultaneously, the CCID interface standard is supported PC (Personal Computer-personal computer)/SC (Smart Card-smart card) interface interchange, makes numerous developers develop operation to intelligent cipher key equipment easily.On numerous versions of other increase income operating system such as LINUX, also having many CCID that increase income to drive can use for developer and user.
Descriptor is the format piece of data result or information, and it can make main frame know this equipment, and each descriptor has comprised the information about the Global Information of this equipment or an element.According to the CCID consensus standard, the feature that meets its descriptor of equipment of CCID interface standard is: in interface descriptor, byte 0 is the byte length of descriptor, value is 09h, and byte 1 is a fixed terminal, is worth to be 04h, byte 4 is except terminal 0, and the terminal number of support is worth and is 02h or 03h, byte 5 is category codes, value is 0Bh, and byte 6 is the subclass code, is worth to be 00h, byte 7 is protocol code, is worth to be 00h; In the type specification symbol, byte 0 is the byte length of descriptor, is worth to be that 36h, byte 2 are version numbers of CCID standard, and it is the decimal of representing with binary code, is worth to be 0100h, and byte 52 is PIN code supports, is worth to be 00H-03h.Meet the byte in other descriptor of equipment of CCID interface standard, as other byte in the byte in device descriptor, the configuration descriptor and above-mentioned interface descriptor and the type specification symbol still according to the regulation setting in the usb protocol.
Generally speaking, the privately owned driver that information interaction must rely on intelligent cipher key equipment manufacturer and provide is provided for main frame and intelligent cipher key equipment can finish, and such intelligent cipher key equipment is exactly the intelligent cipher key equipment of often saying that the type of driving is arranged.But the privately owned driver that intelligent cipher key equipment production firm provides is all very inconvenient in operating aspects such as installation, upgrading, unloadings, but also easily operating system is caused damage.The information interaction that how to realize main frame and intelligent cipher key equipment simply and easily is the problem that IT worker and user are concerned about very much.
Summary of the invention
Carry out information interaction in order to solve main frame and intelligent cipher key equipment, the driver that needs to rely on intelligent cipher key equipment just can be finished, and the problem of inconvenient operation such as installation of driver, upgrading, unloading, the present invention proposes a kind of intelligent cipher key equipment of the CCID of meeting interface standard, described intelligent cipher key equipment comprises usb interface module and intelligent processing module, and described usb interface module comprises that descriptor is provided with the unit and end points is provided with the unit;
Described descriptor is provided with the unit and is used for being provided with and meets descriptor and the corresponding value thereof that the CCID standard stipulates;
Described end points is provided with the unit and is used at least one OUT end points and is set to the BULK-OUT end points, and at least one IN end points is set to the BULK-IN end points, and at least one IN end points is set to interrupt endpoint.
Described intelligent processing module is made up of master control module and data memory module;
Described master control module is used for the control program operation, carries out the corresponding program order;
Described data memory module is used to store relevant key information.
Described intelligent processing module is made up of master control module, program storage block and intelligent key data storage module;
Described master control module is used for the control program operation, carries out the corresponding program order;
Described program storage block is used to store corresponding program;
Described intelligent key data storage module is used to store relevant key information.
Described intelligent processing module is an intelligent card chip.
Described intelligent processing module and described usb interface module are integrated on the chip or are positioned on two chips.
The present invention also provides a kind of and has utilized described intelligent cipher key equipment to realize and the mutual method of host information, said method comprising the steps of:
Steps A: set up the physical connection of intelligent cipher key equipment and main frame, described intelligent cipher key equipment powers on;
Step B: described intelligent cipher key equipment statement oneself is the equipment that meets the CCID interface standard;
Step C: described main frame sends query State information to described intelligent cipher key equipment, and described intelligent cipher key equipment returns the response message that smart card has inserted to described main frame;
Step D: described main frame sends the smart card electrification reset order that meets the CCID standard to described intelligent cipher key equipment, and described intelligent cipher key equipment is packaged into the packet that meets the CCID standard with reset answer, and sends described packet to described main frame;
Step e: described main frame is set up communication with described intelligent cipher key equipment and is connected, and carries out information interaction according to application program in the described main frame and described intelligent cipher key equipment.
Described reset answer is stored in the described intelligent cipher key equipment or is solidificated in the interior firmware program of described intelligent cipher key equipment.
The intelligent cipher key equipment of the CCID of meeting interface standard provided by the invention has been realized combining of CCID interface standard and intelligent cipher key equipment, when utilizing this intelligent cipher key equipment and main frame to carry out information interaction, main frame no longer needs install driver, improved the applicability of intelligent cipher key equipment widely, simultaneously also help the developer and develop better, more easily intelligent cipher key equipment.
Description of drawings
Fig. 1 is the theory diagram of the embodiment of the invention 1 intelligent cipher key equipment;
Fig. 2 is the theory diagram of the embodiment of the invention 2 intelligent cipher key equipments;
Fig. 3 is that intelligent cipher key equipment and main frame carry out mutual flow chart.
Embodiment
The invention will be further described below in conjunction with the drawings and specific embodiments, but not as a limitation of the invention.
Embodiment 1
A kind of system of imitative smart card that adopted present embodiment realizes that intelligent cipher key equipment and main frame carry out information interaction, in fact just is to use microcontroller to simulate the function that realizes smart card, carries out information interaction by CCID agreement and main frame simultaneously.As shown in Figure 1, intelligent cipher key equipment 102 is made up of usb interface module 103, master control module 104 and data memory module 105.Usb interface module 103 is the interface modules that meet the CCID interface standard, be used to realize that intelligent cipher key equipment and main frame carry out communication according to the CCID interface standard, and the physical connection of setting up main frame and intelligent cipher key equipment, usb interface module comprises that descriptor is provided with the unit and end points is provided with the unit, descriptor is provided with the unit and is used for being provided with and meets descriptor and the corresponding value thereof that the CCID agreement stipulates, end points is provided with the unit and is used to be provided with at least one pair of IN/OUT end points and is claimed as BULK-IN, the BULK-OUT end points, be used for realizing replying and ordering pipeline, at least one IN end points is set is claimed as interrupt endpoint, be used for realization event notice pipeline; Master control module 104 is used for the control program operation, carries out the corresponding program order; Data memory module 105 is used to store the memory of information such as association key.Master control module 104 and data memory module 105 have constituted intelligent processing module 106 (in the frame of broken lines) jointly.Main frame 101 passes through usb interface module 103 physical connections with intelligent cipher key equipment 102, and master control module 104 is carried out communication by usb interface module 103 and main frame 101.
Embodiment 2
Present embodiment has adopted a kind of single-chip to realize that intelligent cipher key equipment and main frame carry out information interaction.Single-chip is meant the integrated chip that can realize USB function and intelligent card function in a slice integrated circuit (IC) chip, the existing usb interface module that meets the CCID standard in this chip, the interface module that meets the ISO7816 standard is also arranged, can be used as smart card and use.As shown in Figure 2, intelligent cipher key equipment 202 is made up of usb interface module 203, program storage block 204, intelligent key data storage module 205, master control module 206 and 7816 interface modules 207.Usb interface module 203 is the interface modules that meet the CCID interface standard, be used to realize that intelligent cipher key equipment 202 and main frame 201 carry out communication according to the CCID interface standard, and the physical connection of setting up main frame 201 and intelligent cipher key equipment 202, usb interface module 203 comprises that descriptor is provided with the unit and end points is provided with the unit, descriptor is provided with the unit and is used for being provided with and meets descriptor and the corresponding value thereof that the CCID agreement stipulates, end points is provided with the unit and is used to be provided with at least one pair of IN/OUT end points and is claimed as BULK-IN, the BULK-OUT end points, be used for realizing replying and ordering pipeline, at least one IN end points is set is claimed as interrupt endpoint, be used for realization event notice pipeline; Program storage block 204 is used to store corresponding program; Intelligent key data storage module 205 is used to store information such as association key; Master control module 206 is used for the control program operation, carries out the corresponding program order.Program storage block 204, intelligent key data storage module 205, master control module 206 and 7816 interface modules 207 have constituted intelligent processing module 208 (in the frame of broken lines) jointly.Main frame 201 passes through usb interface module 203 physical connections with intelligent cipher key equipment 202, and master control module 206 is carried out communication by usb interface module 203 and main frame 201.
Intelligent cipher key equipment and main frame carry out mutual embodiment referring to Fig. 3, may further comprise the steps:
Step 301: set up the physical connection of intelligent cipher key equipment and main frame, intelligent cipher key equipment powers on;
Step 302: the intelligent cipher key equipment statement oneself is the equipment that meets the CCID interface standard;
Step 303: main frame sends query State information to intelligent cipher key equipment;
Step 304: intelligent cipher key equipment returns the response message that smart card has inserted to main frame after receiving the query State information of main frame transmission;
Step 305: after main frame receives the response message of intelligent cipher key equipment transmission, send the smart card electrification reset order that meets the CCID interface standard to intelligent cipher key equipment;
Step 306: intelligent cipher key equipment is packaged into the packet that meets the CCID standard with reset answer after receiving the electrification reset order of main frame transmission, and sends packet to main frame;
Step 307: main frame is set up communication with intelligent cipher key equipment and is connected after receiving the packet of intelligent cipher key equipment transmission;
Step 308: according to the application program of host side, main frame and intelligent cipher key equipment carry out information interaction, finish up to information interaction.
Reset answer in the step 306 can be stored in the intelligent cipher key equipment or be solidificated in the interior firmware program of intelligent cipher key equipment.
Intelligent cipher key equipment of the present invention can be used for carrying out authentication, also can simulate such as reading and writing data, file management, algorithm download, data encryption etc.
Above-described embodiment is a more preferably embodiment of the present invention, and common variation that those skilled in the art carries out in the technical solution of the present invention scope and replacement all should be included in protection scope of the present invention.