WO2006010332A1 - A method for logically binding and verifying devices in an apparatus - Google Patents

A method for logically binding and verifying devices in an apparatus Download PDF

Info

Publication number
WO2006010332A1
WO2006010332A1 PCT/CN2005/001136 CN2005001136W WO2006010332A1 WO 2006010332 A1 WO2006010332 A1 WO 2006010332A1 CN 2005001136 W CN2005001136 W CN 2005001136W WO 2006010332 A1 WO2006010332 A1 WO 2006010332A1
Authority
WO
WIPO (PCT)
Prior art keywords
module
sub
main module
information
submodule
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2005/001136
Other languages
English (en)
French (fr)
Inventor
Zhengwei Wang
Guzheng Wu
Yang Huang
Zhaohui Wu
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Family has litigation
First worldwide family litigation filed litigation Critical https://patents.darts-ip.com/?family=35785904&utm_source=google_patent&utm_medium=platform_link&utm_campaign=public_patent_search&patent=WO2006010332(A1) "Global patent litigation dataset” by Darts-ip is licensed under a Creative Commons Attribution 4.0 International License.
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to DE602005021341T priority Critical patent/DE602005021341D1/de
Priority to EP05772421A priority patent/EP1744574B2/en
Priority to AT05772421T priority patent/ATE468676T1/de
Publication of WO2006010332A1 publication Critical patent/WO2006010332A1/zh
Priority to US11/609,571 priority patent/US7634658B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information

Definitions

  • the present invention relates to device security techniques, and more particularly to a method of logically binding and verifying devices in a device. Background of the invention
  • an anti-theft method can be set for the mobile terminal, so that even if the illegal user steals the mobile terminal, the anti-theft method is also set.
  • the mobile terminal cannot be used normally, and the mobile terminal can not be profited by reselling, so that the phenomenon of stealing the mobile terminal can be effectively suppressed.
  • some devices inside the mobile terminal such as baseband chips, mobile terminal batteries, etc.
  • illegal users who steal the mobile terminal may not be able to use the entire mobile terminal, nor can they profit directly by reselling the mobile terminal, but they can The mobile terminal is taken apart and profited by using or reselling some of the devices with higher value, thereby affecting the anti-theft effect of the mobile terminal.
  • the mobile terminal encrypts by an encryption component and performs theft prevention by such encryption, the illegal user who steals the mobile terminal can make the mobile terminal reusable by replacing the encryption component, thereby profiting accordingly.
  • the present invention provides a method of logically binding and authenticating a device in a device, comprising at least the following steps:
  • each sub-module separately stores a personalized information, and saves the personalized information of the sub-module in the main module;
  • the main module sends verification information corresponding to the personalized information of the sub-module saved by the main module to the sub-module;
  • the sub-module After receiving the verification information, the sub-module determines whether the received verification information matches the personalized information saved by itself, and if so, works normally, otherwise stops working.
  • an identifier for identifying the submodule is set for each submodule, and the main module further saves the correspondence between the personalized information of the submodule and the identifier of the submodule, and the main module sends the submodule to the submodule in step b.
  • the verification information includes: the main module determines the personalized information of the sub-module according to the corresponding relationship, and then sends the verification information corresponding to the personalized information of the sub-module to the sub-module corresponding to the sub-module identifier.
  • the method further includes setting a personalized information in the main module, and before step b, further comprising: inputting verification information to the main module through an input unit of the device or through a verification device outside the device, the main module determining the received verification information and Whether the personalized information saved by yourself matches, if yes, execute step b, otherwise the main module stops working.
  • the above method further includes setting a maximum number of input verification information errors in the main module and/or the submodule, and when the number of errors of the input verification information received by the main module and/or the submodule reaches the maximum number of input verification information errors, the main module And/or submodules stop working.
  • the above method further includes setting a maintenance password in the main module and/or the submodule, and further Steps include the steps to set, change, or clear personalized information by entering a maintenance password.
  • the method further includes setting a maximum number of maintenance password input errors, and when the number of errors of the maintenance password received by the main module and/or the submodule reaches the maximum number of maintenance password input errors, the main module and/or the submodule stops inputting again.
  • the maintenance password responds.
  • a super maintenance password can also be set in the main module, and further includes the steps of setting, changing, or clearing the maintenance password in the main module by entering the super maintenance password.
  • the initial value of the maintenance password for the main module and/or submodule is null.
  • the method further includes setting the maintenance password of the main module/submodule when setting the personalization information of the main module and/or the submodule.
  • the verification information received by the main module and/or the submodule is a joint calculation result of the personalized information and a random number, and the main module and/or the submodule determines whether the verification information matches the personalized information saved by itself, including: the main module and And the sub-module performs the same or corresponding combination calculation on the personalized information saved by itself and the random number, and compares whether the obtained joint calculation result and the received verification information are the same or satisfy a predetermined correspondence relationship.
  • the above method may further comprise the step of setting a predetermined time in the main module and/or the submodule, and further comprising the main module and/or the submodule determining whether the verification information is received within a predetermined time, and if yes, performing step C, otherwise stop working.
  • the apparatus of the present invention may further comprise a master program module for communicating messages between the master module and the slave modules.
  • the main module is separately provided in the device or integrated with one device in the device.
  • the sub-module when the sub-module stops working, the sub-module further includes: the sub-module returns a notification message indicating that the user is in an illegal use state, and the main module outputs the message to the user through the output device.
  • the method when the main module stops working, the method further includes: the main module passes the output The device outputs a notification message indicating that the user is in an illegal use state to the user.
  • the device in the device needs to be protected by theft protection as a sub-module, and a main module is set in the device, and a personalized information is saved in each sub-module, and The personalization information of all submodules is saved in the main module.
  • the main module sends verification information corresponding to the personalized information of the sub-module saved by the sub-module, and then the sub-module determines whether the received verification information matches the personalized information saved by itself. Yes, make sure that you are in a legal use state, otherwise you are sure that you are in an illegal use state.
  • the present invention extends the anti-theft from the device level to the device level, greatly improving the security of the user using the device.
  • the method of the present invention is not limited to the anti-theft purpose of the device and the device, and can also be used for various purposes, such as verifying that the reinstallation is correct in the case of device disassembly and reinstallation, and whether the device of one device is installed. Another device, etc., therefore, the invention has a very broad application prospect.
  • 1 is a flow chart in accordance with a first embodiment of the present invention.
  • 2 is a flow chart in accordance with a second embodiment of the present invention.
  • Figure 3 is a flow chart in accordance with a third embodiment of the present invention.
  • FIG. 4 is a flow chart in accordance with a fourth embodiment of the present invention. Mode for carrying out the invention
  • a single device is composed of a plurality of internal devices, for example, a mobile terminal includes a baseband chip, a battery, a display screen, etc., in order to ensure that these devices cannot be separately disassembled and used for other devices, the present invention
  • the key components inside the device are bound. In other words, these devices can only be used in this device, and if they are used in other devices, they will not work properly.
  • the anti-theft measures taken on the entire device the anti-theft is extended from the device level to the device level, greatly improving the anti-theft effect.
  • a device to be bound inside a device is separately used as a sub-module, and a main module is set separately in the device or integrated with a certain device.
  • the sub-module identification and personalization information are set separately, and the sub-module saves its own personalized information, and the main module saves the list of the correspondence between the sub-module's identification and the personalized information.
  • the main module sends the personalized information of the submodule to the submodule, and the submodule compares whether the personalized information saved by itself and the information of the receiving autonomous module match, and accordingly determines whether it is working normally.
  • Fig. 1 shows a first embodiment of the invention.
  • a main module is set inside the device, and the main module can be set separately or integrated with a specific device in the device.
  • step 102 a sub-module that needs to be bound is set inside the device, that is, which devices in the device need to be bound.
  • step 103 an identifier and a personalized information are set for each sub-module, the personalized information of the sub-module is saved in the sub-module, and a list of correspondences between the sub-module identification and the personalized information is saved in the main module. .
  • step 104 after the main module and the sub-module are powered on, after a preset time, the main module separately sends a personalized letter corresponding to the sub-module identification to each sub-module.
  • step 105 the sub-module determines the personality of the receiving self-module. Whether the information is consistent with the personalized information saved by itself, if it is consistent, it is considered that it has passed the verification and works normally in step 106; otherwise, it is considered that it has not passed the verification, and stops working in step 107.
  • the preset time of step 104 may be zero, that is, the main module sends personalized information to the sub-module immediately after power-on.
  • the personalized information can be sent at the same time, or it can be sent sequentially.
  • step 106 when the submodule passes the verification and works normally, a notification message indicating that the verification is successful may be returned to the main module.
  • step 107 when the submodule fails to pass the verification and stops working, the main module may The module returns a notification message indicating that its verification failed.
  • the main module can output these messages to the user through the output device, for example, on the display, or by voice to the user.
  • a predetermined time may be set in the submodule, and a step of determining whether to receive the personalized information of the autonomous module within a predetermined time is added before step 105, and if yes, executing step 105; if the predetermined time is reached.
  • the submodule still does not receive the personalized information of the incoming autonomous module, and directly executes step 107, that is, it considers that it has not passed the verification, thereby stopping the work.
  • the second embodiment of the present invention includes the following steps.
  • a main module is set inside the device, and the main module can be set separately or integrated with a specific device in the device.
  • step 202 a sub-module that needs to be bound is set inside the device, that is, which devices in the device need to be bound.
  • a personalized information is set for the main module, an identifier and a personalized information are set for each sub-module, the personalized information of the sub-module is saved in the sub-module, and the sub-module identifier is saved in the main module.
  • a list of correspondences with personalized information is set for the main module, an identifier and a personalized information are set for each sub-module, the personalized information of the sub-module is saved in the sub-module, and the sub-module identifier is saved in the main module.
  • step 204 after the main module and the sub-module are powered on, the main module determines whether the personalized information received from the external input is consistent with the personalized information saved by itself, and if yes, step 205 and subsequent steps are performed, otherwise in step 209 Stop working and end this process.
  • step 205 the main module separately sends personalized information corresponding to the sub-module identification to each sub-module.
  • step 206 the sub-module determines whether the personalized information of the receiving autonomous module is consistent with the personalized information saved by itself, and if it is consistent, it considers that it has passed the verification, and works normally in step 207; otherwise, it considers that it has not passed the verification, and stops at step 208. jobs.
  • the external input may be manually input by the user through the input unit of the device, such as by keyboard input of the mobile terminal.
  • a verification device is additionally set up separately from the device to be verified, and the verification device saves the personalized information of the main module of the device to be verified, and sends the personalized information to the main module of the device to be verified.
  • the program module inside the device saves the personalized information of the main module, and sends the personalized information to the main module. Information.
  • step 204 it is also possible to set a predetermined time in the main module, and after the main module is powered on in step 204, add a step of determining whether to receive personalized information from the outside input within a predetermined time, and if so, perform the steps.
  • the determining step in 204 if the main module still does not receive the personalized information from the outside input after the predetermined time is reached, directly executing step 209, that is, stopping the work, ending the process.
  • the sub-module may return a corresponding notification message
  • the main module may also generate a notification message indicating that the verification fails, and the main module may pass all of the notification messages to the output device. Output to the user.
  • the main module can also use a verification information corresponding to the personalized information instead of sending the personalized information. For example, a joint operation is performed on the personalized information and a random number, and the obtained operation result is sent as verification information to the sub-module, and the sub-module compares whether the verification information matches the personalized information saved by itself.
  • a third embodiment is proposed on the basis of the first embodiment, and the specific flow is shown in FIG. 3. The steps 301 to 303 for which the device logically binds are identical to the steps 101 to 103 of the first embodiment, and a detailed description thereof is omitted here.
  • the verification process begins with step 304.
  • step 304 after the main module and the sub-module are powered on, after a preset time, the main module sends a request message for requesting random numbers to each sub-module.
  • step 305 after receiving the request message, the submodule respectively generates a random number, and then sends the random number to the main module.
  • step 306 the main module performs joint calculation according to the received random number from the sub-module and the saved personalized information of the corresponding sub-module, and obtains a calculation result, that is, verification information corresponding to the personalized information.
  • the main module sends verification information to each of the sub-modules.
  • the sub-module compares whether the verification information sent by the main module matches the personalized information saved by the sub-module, specifically including the following steps:
  • step 308 the sub-module performs the same or corresponding joint calculation according to the self-saved random number and the personalized information generated by itself, and obtains a calculation result, that is, verification information corresponding to the personalized information saved by itself.
  • step 309 the sub-module determines whether the verification information received from the main module is the same as the verification information generated by itself or satisfies the correspondence relationship. If yes, it considers that it has passed the verification, and works normally in step 310; otherwise, it considers that it has not passed the verification. Step 311 stops working.
  • the corresponding joint calculation in step 308 means that the calculation performed by the main module and the calculation performed by the sub-module may be different as long as they satisfy a predetermined correspondence, for example, the calculated results differ by an integer multiple, or differ by a fixed offset. and many more.
  • the sub-module determines whether the verification information obtained by itself and the verification information of the receiving autonomous module satisfy the predetermined correspondence relationship to determine whether or not the verification is passed.
  • the joint calculation may also be a digest calculation or an encryption calculation.
  • the personalized information may be used as a key to encrypt the random number, that is, the main module uses the personality corresponding to the sub-module.
  • the information is used to encrypt the random number, and then the calculation result is sent to the sub-module.
  • the sub-module uses its own personalized information to decrypt, and determines whether the decrypted result is the same as the self-saved random number. Yes, it is considered that it has passed the verification and works normally in step 310; otherwise, it is considered that it has not passed the verification, and stops working in step 311.
  • the outside world can also use a verification information corresponding to the personalized information instead of sending the personalized information.
  • a joint operation is performed on the personalized information and a random number, and the obtained operation result is sent as verification information to the main module, and the main module compares whether the verification information matches the personalized information saved by itself. Therefore, a fourth embodiment is proposed on the basis of the second embodiment.
  • the external input here is an example of a verification device, and the specific The process is shown in Figure 4.
  • the steps 401 to 403 in which the device logically binds are identical to the steps 201 to 203 in the second embodiment, and a detailed description thereof is omitted here.
  • the verification process is described below starting from step 404.
  • step 404 after the main module and the sub-module are powered on, the main module generates a random number, and sends the random number and a request message requesting the verification information to the verification device.
  • step 405 after receiving the request message and the random number, the verification device jointly calculates the personalized information and the random number of the main module of the corresponding device saved by the device, and obtains a calculation result, that is, the verification information.
  • the verification device sends the verification information generated by itself to the main module of the device to be verified.
  • step 407 after receiving the verification information, the main module performs the same or corresponding joint calculation on the personalized information saved by itself and the random number generated by itself, and obtains the verification information corresponding to the personalized information saved by itself.
  • step 408 the main module determines whether the verification information received from the outside world is the same as the verification information generated by itself or satisfies the corresponding relationship. If yes, step 409 and subsequent steps are performed, otherwise the operation is stopped in step 413, and the process ends. .
  • step 409 the main module separately sends personalized information corresponding to the sub-module identification to each sub-module.
  • step 410 the sub-module determines whether the personalized information received from the main module is consistent with the personalized information saved by itself, and if it is consistent, it considers that it has passed the verification, and works normally in step 411; otherwise, it considers that it has not passed the verification, in step 412 stop working.
  • the sub-module can also be similar to the third embodiment, and the verification information calculated by the personalized information and the random number is used for verification.
  • the submodule may first send a request message requesting personalized information or verification information to the main module, and the main module sends the personalized message after receiving the request message. Information or verification information.
  • the main module may first send a request message requesting personalized information or verification information to the verification device, or prompt the user to input a personalized information or verification information through the output unit, or, after the device is powered on, the main module waits for the outside world. Enter the corresponding personalized information of the main module within a set time.
  • the random number required for the verification of the submodule can also be generated by the main module and sent by the main module to the submodule
  • the random number required for the verification of the main module can also be generated by the outside world and sent to the main module by the outside, where
  • the outside world includes verification devices, user inputs, and program modules.
  • the corresponding interaction information can be transmitted in the middle through a main control program module, so that the main module and each sub-module can indirectly exchange information, thereby reducing the complexity of the circuit design.
  • the submodule fails to verify itself, it can directly return the verification failure information to the main control module, and the main control program module directly outputs the information to the user, so that the failure information does not need to be returned to the main module.
  • a maintenance password can be set in the submodule, by which the personalized information in the submodule can be controlled, changed, and cleared, and the maintenance password can be reset by the maintenance password.
  • the sub-module changes the personalized information
  • the changed personalized information is sent to the main module, and the main module updates the corresponding sub-module personalized information saved by itself.
  • the maximum number of maintenance password input errors can be set.
  • a maintenance password can also be set in the main module.
  • the maintenance password can be used to set, change and clear the personalized information in the main module, and reset the maintenance password through the maintenance password.
  • the list information saved by the main module is obtained by the maintenance password. And, you can set the maximum number of maintenance password input errors. When the user enters the maintenance password incorrectly for the first time, he can re-enter, but if the maintenance password cannot be entered correctly after a limited number of inputs, the main module will refuse to respond to the user inputting the maintenance password.
  • the main module you can also set a super maintenance password. With this super maintenance password, you can set, change, and clear the maintenance password of the main module, and reset the super maintenance password with this super maintenance password. In addition, you can set the number of times the super maintenance password is entered. When the user enters the super maintenance password for the first time, you can re-enter it. However, if the super maintenance password cannot be entered correctly after a limited number of inputs, the main module will reject the user input. The super password responds. In the actual situation, the user may forget to maintain the password, and the user is provided with a chance to remedy by providing a super password.
  • the initial value of the maintenance password for the submodule and the main module can be empty and set only when the device is logically bound. Specifically, when the main module performs a binding operation on the submodule, the maintenance password of the submodule is set, and the personalized information of the submodule is set.
  • the maintenance password and the personalized information of each sub-module may also be set by the main control program module, and respectively Saved in each submodule as well as in the main module.
  • the maintenance password of the main module is set by the outside world, and the personalized information of the main module is set.
  • a maximum verification information input error number can be set for the sub-module.
  • the main module inputs the verification information error for the first time, the main module can re-enter, but if the verification information cannot be correctly input after the limit number of times, the sub-module will reject the main The input to the module.
  • a maximum number of verification information input errors can be set.
  • the external input error message is input for the first time, the input can be re-entered. However, if the verification information cannot be correctly input after the limit number, the main module will reject the external input. .
  • the personalized information, the maintenance password and the super maintenance password of the present invention implement access control access through logic circuits.
  • Such access technology has been widely used in the field of IC cards, and will not be described here.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Storage Device Security (AREA)
  • Automatic Disk Changers (AREA)
  • Tests Of Electronic Circuits (AREA)
  • Computer And Data Communications (AREA)

Description

一种在设备中逻辑绑定和验证器件的方法
技术领域
本发明涉及器件安全技术, 特别是指一种在设备中逻辑绑定和验证 器件的方法。 发明背景
目前针对诸如移动电话和便携式电脑等的移动终端设备的盗抢现象 依然时有发生, 为此可以针对移动终端设置一种防盗方法, 这样即使非 法用户盗抢了移动终端, 也由于防盗方法的设置而不能正常使用该移动 终端, 并且不能通过转卖该移动终端获利, 从而能够有效地抑制盗抢移 动终端的现象。
但是移动终端内部的一些器件, 例如基带芯片、 移动终端电池等也 有一定价值 , 因此盗抢了移动终端的非法用户可能不能使用整个移动终 端, 也不能通过直接转卖该移动终端获利, 但是他们可以将移动终端拆 开, 并通过使用或者转卖其中一些具有较高价值的器件而获利, 从而影 响了移动终端的防盗效果。 或者, 如果移动终端是通过一个加密部件来 进行加密, 并通过这种加密来进行防盗的话, 那么盗抢移动终端的非法 用户可以通过更换加密部件使移动终端可以重新使用, 从而据此获利。
另外, 用户将自己的移动终端或计算机等送到维护点进行维修时, 常常有不法分子趁此机会更换用户的移动终端或计算机的器件, 例如将 一个使用寿命长的原装器件更换为使用寿命短的假冒器件, 从而给用户 带来经济上的损失。
因此, 如何有效地杜绝上述盗抢设备的现象是目前迫切需要解决的 一个问题。 发明内容
有鉴于此, 本发明的目的在于提供一种在设备中逻辑绑定和验证器 件的方法, 以有效地杜绝盗抢设备现象的发生。
为了达到上述目的, 本发明提供了一种在设备中逻辑绑定和验证器 件的方法, 至少包括如下步骤:
a. 将设备中的器件设置为子模块, 并在设备中设置一个主模块, 每 一个子模块分别保存一个个性化信息, 并且在主模块中保存该子模块的 个性化信息;
b. 当需要对子模块进行验证时, 主模块向子模块发送对应自己保存 的该子模块的个性化信息的验证信息;
c 子模块接收到所述验证信息后, 判断所接收的验证信息和自己保 存的个性化信息是否匹配, 如果是, 则正常工作, 否则停止工作。
在上述方法中,为每一个子模块设置一个用于标识该子模块的标识, 主模块进一步保存子模块的个性化信息和子模块的标识之间的对应关 系, 步骤 b中主模块向子模块发送验证信息包括: 主模块根据所述对应 关系确定子模块的个性化信息, 然后向子模块标识对应的子模块发送对 应该子模块的个性化信息的验证信息。
上述方法进一步包括在主模块中设置一个个性化信息, 在步骤 b之 前进一步包括: 通过设备的输入单元或者通过该设备外的验证设备向主 模块输入验证信息, 主模块判断所接收的验证信息和自己保存的个性化 信息是否匹配, 如果是, 执行步骤 b, 否则主模块停止工作。
上述方法进一步包括在主模块和 /或子模块中设置一个最大输入验 证信息错误次数,当主模块和 /或子模块接收到的输入验证信息的错误次 数达到所述最大输入验证信息错误次数, 主模块和 /或子模块停止工作。
上述方法进一步包括在主模块和 /或子模块中设置维护密码, 并进一 步包括通过输入维护密码设置、 更改或清除个性化信息的步骤。
上述方法进一步包括设置一个最大维护密码输入错误次数, 当主模 块和 /或子模块接收到的维护密码的错误次数达到所述最大维护密码输 入错误次数, 主模块和 /或子模块停止对再次输入的维护密码进行响应。
主模块中还可以设置一个超级维护密码, 并进一步包括通过输入超 级维护密码设置、 更改或清除主模块中的维护密码的步骤。
主模块和 /或子模块的维护密码的初始值为空, 该方法进一步包括在 设置主模块和 /或子模块的个性化信息时设置主模块 /子模块的维护密 码。
主模块和 /或子模块接收的验证信息是个性化信息和一个随机数的 联合计算结果,所述主模块和 /或子模块判断验证信息和自己保存的个性 化信息是否匹配包括:主模块和 /或子模块对自己保存的个性化信息和所 述随机数进行相同或对应的 合计算, 并比较所得到的联合计算结果和 所接收的验证信息是否相同或者满足预定对应关系。
上述方法可以进一步包括在主模块和 /或子模块中设置一个预定时 间的步骤,并进一步包括主模块和 /或子模块判断是否在预定时间内接收 到验证信息, 如果是, 执行步骤 C , 否则停止工作。
本发明的设备可以进一步包括一个主控程序模块, 所述主控程序模 块用于传递主模块和子模块之间交互的消息。
在本发明中, 主模块在设备中单独设置, 或者和设备中的一个器件 集成在一起。
上述方法中, 子模块停止工作的同时进一步包括: 子模块向主模块 返回表示自己为非法使用状态的通知消息, 主模块将该消息通过输出设 备输出给用户。
上述方法中, 主模块停止工作的同时进一步包括: 主模块通过输出 设备向用户输出表示自己为非法使用状态的通知消息。
从本发明的技术方案可以看出, 本发明将设备中需要进行防盗保护 的器件设置为子模块, 并在设备中设置一个主模块, 在每一个子模块中 分别保存一个个性化信息, 并且在主模块中保存所有子模块的个性化信 息。 这样在主模块中包含了所有子模块的信息, 也就是将所有需要进行 防盗保护的器件绑定在该设备中。 当需要对子模块进行验证时, 主模块 向子模块发送对应自己保存的该子模块的个性化信息的验证信息, 然后 子模块判断所接收的验证信息和自己保存的个性化信息是否匹配, 如果 是, 确定自己为合法使用状态, 否则确定自己为非法使用状态。
通过本发明上述对器件的逻辑绑定和验证技术, 如果设备内的一个 单独器件被拆卸下来并用于另一个设备, 那么新设备内的主模块并未正 确保存被拆卸下来的器件的个性化信息, 因此在执行验证步骤时, 该器 件得到的对应个性化信息的验证信息必定和自己保存的原有个性化信 息不匹配,此时该器件会确定自己为非法使用状态,并且可以停止工作, 从而使该器件无法在整个设备中正常运转。 这样非法用户即使盗抢或更 换了设备内的有价值的器件, 也因为不能再次使用这些器件而不能从中 牟利, 从而从根本上打击非法用户盗抢器件的现象。 并且, 本发明将防 盗从设备级延伸到器件级, 极大地提高了用户使用设备的安全性。
另外, 本发明的方法并不局限于对设备和器件的防盗目的, 还可以 有多种用途, 例如在器件拆卸和重新安装的情况下可以验证重新安装是 否正确, 是否将一个设备的器件安装到了另一个设备等等, 因此本发明 具有十分广阔的应用前景。 附图简要说明
图 1是根据本发明的第一实施例的流程图。 图 2是根据本发明的第二实施例的流程图。
图 3是根据本发明的第三实施例的流程图。
图 4是根据本发明的第四实施例的流程图。 实施本发明的方式
为使本发明的目的、 技术方案和优点更加清楚, 下面结合附图对本 发明作进一步的详细描述。
一般而言, 一个单独的设备是由多个内部器件构成的, 例如一个移 动终端包括基带芯片、 电池、 显示屏等器件, 为了保证这些器件不能被 单独拆卸下来并用于其他设备, 本发明对一个设备内部的关键器件进行 了绑定。 也就是说, 这些器件只能在这一个设备内才能使用, 如果用于 其他设备则不能正常工作。 结合对整个设备采取的防盗措施, 这样就将 防盗从设备级延伸到器件级, 极大地提高了防盗的效果。
在本发明中, 将一个设备内部的需要绑定的器件分别作为一个子模 块, 同时在设备内部单独设置或者通过和某一个器件集成的方式设置一 个主模块。 对于每一个子模块分别设置子模块标识和个性化信息, 子模 块自己保存自己的个性化信息, 同时主模块保存子模块的标识和个性化 信息之间对应关系的列表。 当子模块需要进行验证时, 主模块将子模块 的个性化信息发送给子模块, 子模块比较自己保存的个性化信息和接收 自主模块的信息是否匹配, 并据此来决定自己是否正常工作。
图 1示出了本发明的第一实施例。 如图 1所示, 在步骤 101 , 在设 备内部设置一个主模块, 该主模块可以单独设置, 也可以和设备内的某 一个具体器件集成在一起。
在步骤 102, 在设备内部设置需要绑定的子模块, 也就是确定设备 内哪些器件需要进行绑定。 在步骤 103 , 为每一个子模块设置一个标识和一个个性化信息, 将 子模块的个性化信息保存在子模块中, 并在主模块中保存包含子模块标 识和个性化信息的对应关系的列表。
通过前述步骤 101至 103 , 即完成了器件的逻辑绑定。 下面对经过 逻辑绑定的器件进行验证。
在步骤 104, 当主模块和子模块上电运行后, 经过一个预先设置的 时间, 主模块向每一个子模块分别发送对应该子模块标识的个性化信 在步骤 105, 子模块判断接收自主模块的个性化信息是否和自己保 存的个性化信息一致, 如果一致, 则认为自己通过验证, 在步骤 106正 常工作; 否则认为自己没有通过验证, 在步骤 107停止工作。
步骤 104的预先设置的时间可以是零, 也就是主模块在上电后立即 向子模块发送个性化信息。 这里如果有多个子模块, 发送个性化信息可 以是同时发送, 也可以是顺序发送。
在步驟 106中, 当子模块通过验证并正常工作时, 可以向主模块返 回一个表示自己验证成功的通知消息; 同样, 在步骤 107中, 当子模块 没有通过验证并停止工作时, 可以向主模块返回一个表示自己验证失败 的通知消息。 主模块可以将这些消息通过输出设备输出给用户, 例如在 显示屏上显示出来, 或者通过语音播放给用户等等。
另外, 可以在子模块中设置一个预定时间, 并且在步骤 105之前增 加一个判断是否在预定时间内接收到来自主模块的个性化信息的步骤, 如果是, 则执行步骤 105; 如果到达该预定时间后子模块依然没有接收 到来自主模块的个性化信息, 直接执行步骤 107, 也就是认为自己没有 通过验证, 从而停止工作。
除了在子模块中设置个性化信息之外, 也可以对主模块设置一个个 性化信息, 这样可以有效防止通过更换设备中的主模块并重新进行器件 的逻辑绑定来达到在新设备中再次使用该器件。
如图 2所示, 本发明的第二实施例包括如下步骤。
在步骤 201 , 在设备内部设置一个主模块, 该主模块可以单独设置, 也可以和设备内的某一个具体器件集成在一起。
在步骤 202, 在设备内部设置需要绑定的子模块, 也就是确定设备 内哪些器件需要进行绑定。
在步骤 203 , 为主模块设置一个个性化信息, 为每一个子模块设置 一个标识和一个个性化信息, 将子模块的个性化信息保存在子模块中, 并在主模块中保存包含子模块标识和个性化信息的对应关系的列表。
通过前述步骤 201至 203 , 即完成了器件的逻辑绑定。 下面对经过 逻辑绑定的器件进行验证。
在步骤 204, 当主模块和子模块上电运行后, 主模块判断接收到来 自外界输入的个性化信息是否和自己保存的个性化信息一致, 如果是, 执行步骤 205及其后续步骤,否则在步骤 209中停止工作,结束本流程。
在步骤 205 , 主模块向每一个子模块分别发送对应该子模块标识的 个性化信息。
在步骤 206, 子模块判断接收自主模块的个性化信息是否和自己保 存的个性化信息一致, 如果一致, 则认为自己通过验证, 在步骤 207正 常工作; 否则认为自己没有通过验证, 在步骤 208停止工作。
在第二实施例中, 外界输入可以是用户手动通过设备的输入单元来 输入, 例如通过移动终端的键盘输入。 或者, 在需要验证的设备外另外 单独设置一个验证设备, 由该验证设备保存需要验证的设备的主模块的 个性化信息, 并向需要验证的设备的主模块发送个性化信息。 或者, 由 设备内部的程序模块保存主模块的个性化信息, 并向主模块发送个性化 信息。
当然, 也可以在主模块中设置一个预定时间, 并且在步骤 204中主 模块上电后, 增加一个判断是否在预定时间内接收到来自外界输入的个 性化信息的步骤, 如果是, 则执行步驟 204中的判断步骤; 如果到达该 预定时间后主模块依然没有接收到来自外界输入的个性化信息, 直接执 行步骤 209, 也就是停止工作, 结束本流程。
同样, 在步骤 207和步骤 208之后子模块可以返回一个相应的通知 消息, 另外在步骤 209之后主模块也可以生成一个表明自己验证失败的 通知消息, 主模块可以将所有的这些通知消息通过输出设备输出给用 户。
对于子模块而言, 主模块在发送个性化信息的时候也可以用一个对 应于个性化信息的验证信息来代替。 例如对个性化信息和一个随机数进 行联合运算, 将得到的运算结果作为验证信息发送给子模块, 子模块比 较该验证信息是否和自己保存的个性化信息相匹配。 为此在第一实施例 的基础上提出了第三实施例, 其具体流程如图 3所示。 其进行器件逻辑 绑定的步驟 301至 303和第一实施例的步骤 101至 103完全相同, 这里 省略其详细描述。 下面从步骤 304开始说明其验证过程。
在步骤 304, 当主模块和子模块上电运行后, 经过一个预先设置的 时间, 主模块向每一个子模块分别发送请求获取随机数的请求消息。
在步骤 305, 子模块在接收到该请求消息后 , 分别生成一个随机数, 然后将该随机数发送给主模块。
在步骤 306, 主模块根据接收来自子模块的随机数和保存的对应该 子模块的个性化信息进行联合计算, 得到一个计算结果, 也就是对应个 性化信息的验证信息。
在步骤 307, 主模块向每一个子模块分别发送验证信息。 子模块在接收到验证信息之后, 比较主模块发送的验证信息是否和 自己保存的个性化信息匹配, 具体地说包含如下步骤:
在步骤 308, 子模块根据自己保存的随机数和自己生成的个性化信 息进行相同或对应的联合计算, 得到一个计算结果, 也就是对应自己保 存的个性化信息的验证信息。
在步骤 309, 子模块判断接收来自主模块的验证信息是否和自己生 成的验证信息相同或者满足对应关系, 如果是, 则认为自己通过验证, 在步骤 310正常工作; 否则认为自己没有通过验证, 在步骤 311停止工 作。
步骤 308中的对应的联合计算是指主模块进行的计算和子模块进行 的计算可以不同, 只要它们满足预定的对应关系即可, 比如计算的结果 相差整数倍, 或者相差一个固定的偏移量, 等等。 这样在步骤 309中子 模块判断自己得到的验证信息和接收自主模块的验证信息是否满足预 定对应关系即可确定自己是否通过验证。 所述联合计算还可以是摘要计 算或者加密计算, 例如, 对于个性化信息与随机数的计算, 可以是将个 性化信息作为密钥来加密随机数实现, 即主模块使用对应于子模块的个 性化信息来加密随机数, 然后将该计算结果发送给子模块, 子模块收到 该计算结果后, 使用自己的个性化信息进行解密, 判断解密后的结果与 自己保存的随机数是否相同,如果是,则认为自己通过验证,在步骤 310 正常工作; 否则认为自己没有通过验证, 在步骤 311停止工作。
同样, 对于主模块, 外界在发送个性化信息的时候也可以用一个对 应于个性化信息的验证信息来代替。 例如对个性化信息和一个随机数进 行联合运算, 将得到的运算结果作为验证信息发送给主模块, 主模块比 较该验证信息是否和自己保存的个性化信息相匹配。 为此在第二实施例 的基础上提出了第四实施例, 这里的外界输入以验证设备为例, 其具体 流程如图 4所示。 其进行器件逻辑绑定的步驟 401至 403和第二实施例 的步骤 201至 203完全相同, 这里省略其详细描述。 下面从步骤 404开 始说明其验证过程。
在步骤 404, 当主模块和子模块上电运行后, 主模块生成一个随机 数, 并向验证设备发送该随机数和一个请求获取验证信息的请求消息。
在步骤 405 , 验证设备在接收到该请求消息和随机数之后, 对自己 保存的对应该设备的主模块的个性化信息和随机数进行联合计算, 得到 一个计算结果, 也就是验证信息。
在步驟 406, 验证设备将自己生成的验证信息发送给需要验证的设 备的主模块。
在步骤 407, 主模块在接收到验证信息之后, 对自己保存的个性化 信息和自己生成的随机数进行相同或对应的联合计算, 得到对应于自己 保存的个性化信息的验证信息。
在步骤 408, 主模块判断接收到来自外界输入的验证信息是否和自 己生成的验证信息相同或者满足对应关系, 如果是, 执行步骤 409及其 后续步骤, 否则在步骤 413中停止工作, 结束本流程。
在步驟 409, 主模块向每一个子模块分别发送对应该子模块标识的 个性化信息。
在步骤 410, 子模块判断接收来自主模块的个性化信息是否和自己 保存的个性化信息一致, 如果一致, 则认为自己通过验证, 在步骤 411 正常工作; 否则认为自己没有通过验证, 在步骤 412停止工作。
当然, 在第四实施例中, 对于子模块也可以和第三实施例类似, 采 用个性化信息和随机数计算得到的验证信息来进行验证。
在上述实施例中, 子模块可以先向主模块发送一个请求个性化信息 或验证信息的请求消息, 主模块在接收到该请求消息之后再发送个性化 信息或验证信息。 同样, 主模块也可以先向验证设备发送一个请求个性 化信息或验证信息的请求消息, 或者通过输出单元提示用户输入一个个 性化信息或验证信息, 或者, 在设备上电后, 主模块等待外界在一个设 定的时间内输入该主模块相应的个性化信息。
另外, 子模块的验证所需的随机数也可以由主模块产生并由主模块 发送给子模块, 而主模块的验证所需的随机数也可以由外界产生并由外 界发送给主模块, 这里的外界包括验证设备、 用户输入和程序模块等情 况。
主模块和子模块交互信息时, 可以经过一个主控程序模块在中间来 传递相应的交互信息,这样,主模块和各个子模块就可以间接交互信息, 从而可以降低电路设计的复杂度。 这样的情况下, 子模块验证自身失败 后, 可以直接向主控程序模块返回验证失败信息, 并由主控程序模块直 接输出给用户, 从而, 不需要再向主模块返回这个失败信息。
在本发明中, 可以在子模块中设置一个维护密码, 通过该维护密码 可以控制设置、 更改和清除子模块中的个性化信息, 以及通过该维护密 码重新设置维护密码。 当子模块更改了个性化信息之后, 将更改后的个 性化信息发送给主模块, 主模块更新自己保存的相应子模块个性化信 息。 并且, 可以设置最大维护密码输入错误次数, 当用户第一次输入维 护密码错误后可以重新输入, 但是如果经过限制次数的输入依然不能正 确输入维护密码, 那么子模块将拒绝对输入的维护密码进行响应或者自 动报废。
和子模块设置维护密码相似,可以在主模块中也设置一个维护密码, 通过该维护密码可以由用户设置、 更改和清除主模块中的个性化信息, 以及通过该维护密码重新设置维护密码, 并且可 通过该维护密码获取 主模块保存的列表信息。 并且, 可以设置最大维护密码输入错误次数, 当用户第一次输入维护密码错误后可以重新输入, 但是如果经过限制次 数的输入依然不能正确输入维护密码, 那么主模块将拒绝对用户输入维 护密码进行响应。
对于主模块, 还可以设置一个超级维护密码, 通过该超级维护密码 可以设置、 更改和清除主模块的维护密码, 以及通过该超级维护密码重 新设置超级维护密码。并且,可以设置超级维护密码输入错误限制次数, 当用户第一次输入超级维护密码错误后可以重新输入, 但是如果经过限 制次数的输入依然不能正确输入超级维护密码, 那么主模块将拒绝对用 户输入的超级密码进行响应。在实际情况中,用户有可能忘记维护密码, 这时通过提供一个超级密码给用户提供了补救的机会。
子模块和主模块的维护密码的初始值可以是空, 只有在进行器件逻 辑绑定时才进行设置。 具体地说, 主模块对子模块执行绑定操作时, 设 置子模块的维护密码, 并且设置子模块的个性化信息。 当然, 如果主模 块和子模块交互信息是经过一个主控程序模块在中间来传递相应的交 互信息来完成的话, 各个子模块的维护密码以及个性化信息也可以由主 控程序模块来设置, 并分别保存在各个子模块以及主模块中。
而对于主模块而言, 在主模块对子模块进行绑定操作之前, 由外界 设置主模块的维护密码, 并且设置主模块的个性化信息。
在本发明中,对于子模块可以设置一个最大验证信息输入错误次数, 当主模块第一次输入验证信息错误后可以重新输入, 但是如果经过限制 次数依然不能正确输入验证信息, 那么子模块将拒绝主模块的输入。 同 样, 对于主模块也可以设置一个最大验证信息输入错误次数, 当外界第 一次输入验证信息错误后可以重新输入, 但是如果经过限制次数依然不 能正确输入验证信息 , 那么主模块将拒绝外界的输入。
另外, 无论是对于子模块还是主模块, 还可以通过输入正确的个性 化信息来修改原来的个性化信息。
本发明的个性化信息、 维护密码和超级维护密码通过逻辑电路实现 访问控制存取, 这种存取技术已经在 IC卡领域得到大量应用, 这里不 再赘述。 包含电子器件的产品, 例如移动电话、 电脑、 家电产品甚至汽车等等, 因此本发明的应用前景非常广泛。
总之, 以上所述仅为本发明的较佳实施例而已, 并非用于限定本发 明的保护范围。

Claims

权利要求书
1. 一种在设备中逻辑绑定和验证器件的方法, 至少包括如下步骤: a. 将设备中的器件设置为子模块, 并在设备中设置一个主模块, 每 一个子模块分别保存一个个性化信息, 并且在主模块中保存该子模块的 个性化信息;
b. 当需要对子模块进行验证时,主模块向子模块发送对应自己保存 的该子模块的个性化信息的验证信息;
c 子模块接收到所述验证信息后, 判断所接收的验证信息和自己保 存的个性化信息是否匹配, 如果是, 则正常工作, 否则停止工作。
2. 根据权利要求 1所述的在设备中逻辑绑定和验证器件的方法,其 特征是, 为每一个子模块设置一个用于标识该子模块的标识, 主模块进 一步保存子模块的个性化信息和子模块的标识之间的对应关系, 步骤 b 中主模块向子模块发送验证信息包括: 主模块根据所述对应关系确定子 模块的个性化信息, 然后向子模块标识对应的子模块发送对应该子模块 的个性化信息的验证信息。
3. 根据权利要求 1所述的在设备中逻辑绑定和验证器件的方法,其 特征是, 该方法进一步包括在主模块中设置一个个性化信息, 在步骤 b 之前进一步包括:
通过设备的输入单元或者通过该设备外的验证设备向主模块输入验 证信息, 主模块判断所接收的验证信息和自己保存的个性化信息是否匹 配, 如果是, 执行步骤 b, 否则主模块停止工作。
4. 根据权利要求 3所述的在设备中逻辑绑定和验证器件的方法,其 特征是,进一步包括在主模块和 /或子模块中设置一个最大验证信息输入 错误次数,当主模块和 /或子模块接收到的输入验证信息的错误次数达到 所述最大验证信息输入错误次数, 主模块和 /或子模块停止工作。
5. 根据权利要求 3所述的在设备中逻辑绑定和验证器件的方法,其 特征是, 进一步包括在主模块和 /或子模块中设置维护密码, 并进一步包 括通过输入维护密码设置、 更改或清除个性化信息的步骤。
6. 根据权利要求 5所述的在设备中逻辑绑定和验证器件的方法,其 特征是, 进一步包括设置一个最大维护密码输入错误次数, 当主模块和 /或子模块接收到的维护密码的错误次数达到所述最大维护密码输入错 误次数, 主模块和 /或子模块停止对再次输入的维护密码进行响应。
7. 根据权利要求 5所述的在设备中逻辑绑定和验证器件的方法,其 特征是, 进一步包括在主模块中设置一个超级维护密码, 并进一步包括 通过输入超级维护密码设置、 更改或清除主模块中的维护密码的步骤。
8. 根据权利要求 5所述的在设备中逻辑绑定和验证器件的方法,其 特征是, 所述主模块和 /或子模块的维护密码的初始值为空, 该方法进一 步包括在设置主模块和 /或子模块的个性化信息时设置主模块 /子模块的 维护密码。
9. 根据权利要求 3所述的在设备中逻辑绑定和验证器件的方法,其 特征是,所述主模块和 /或子模块接收的验证信息是个性化信息和一个随 机数的联合计算结果,所述主模块和 /或子模块判断验证信息和自己保存 的个性化信息是否匹配包括:
主模块和 /或子模块对自己保存的个性化信息和所述随机数进行相 同或对应的联合计算, 并比较所得到的联合计算结果和所接收的验证信 息是否相同或者满足预定对应关系。
10. 根据权利要求 3所述的在设备中逻辑绑定和验证器件的方法, 其特征是, 进一步包括在主模块和 /或子模块中设置一个预定时间的步 骤,并进一步包括主模块和 /或子模块判断是否在预定时间内接收到验证 信息, 如果是, 执行步骤 C , 否则停止工作。
11. 根据权利要求 1所述的在设备中逻辑绑定和验证器件的方法, 其特征是, 该设备进一步包括一个主控程序模块, 所述主控程序模块用 于传递主模块和子模块之间交互的消息。
12. 根据权利要求 1所述的在设备中逻辑绑定和验证器件的方法, 其特征是, 所述主模块在设备中单独设置, 或者和设备中的一个器件集 成在一起。
13、 根据权利要求 1所述的在设备中逻辑绑定和验证器件的方法, 其特征是, 所述子模块停止工作的同时进一步包括: 子模块向主模块返 回表示自己为非法使用状态的通知消息, 主模块将该消息通过输出设备 输出给用户。
14、 根据权利要求 3所述的在设备中逻辑绑定和验证器件的方法, 其特征是, 所述主模块停止工作的同时进一步包括: 主模块通过输出设 备向用户输出表示自己为非法使用状态的通知消息。
PCT/CN2005/001136 2004-07-28 2005-07-28 A method for logically binding and verifying devices in an apparatus Ceased WO2006010332A1 (en)

Priority Applications (4)

Application Number Priority Date Filing Date Title
DE602005021341T DE602005021341D1 (de) 2004-07-28 2005-07-28 Verfahren zur logischen bindung und verifizierung von geräten in einer vorrichtung
EP05772421A EP1744574B2 (en) 2004-07-28 2005-07-28 A method for logically binding and verifying devices in an apparatus
AT05772421T ATE468676T1 (de) 2004-07-28 2005-07-28 Verfahren zur logischen bindung und verifizierung von geräten in einer vorrichtung
US11/609,571 US7634658B2 (en) 2004-07-28 2006-12-12 Method for logically binding and verifying a subassembly in equipment

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200410071100.X 2004-07-28
CNB200410071100XA CN100337502C (zh) 2004-07-28 2004-07-28 一种在设备中逻辑绑定和验证器件的方法

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US11/609,571 Continuation US7634658B2 (en) 2004-07-28 2006-12-12 Method for logically binding and verifying a subassembly in equipment

Publications (1)

Publication Number Publication Date
WO2006010332A1 true WO2006010332A1 (en) 2006-02-02

Family

ID=35785904

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2005/001136 Ceased WO2006010332A1 (en) 2004-07-28 2005-07-28 A method for logically binding and verifying devices in an apparatus

Country Status (6)

Country Link
US (1) US7634658B2 (zh)
EP (1) EP1744574B2 (zh)
CN (1) CN100337502C (zh)
AT (1) ATE468676T1 (zh)
DE (1) DE602005021341D1 (zh)
WO (1) WO2006010332A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1744574B2 (en) 2004-07-28 2013-01-02 Huawei Technologies Co., Ltd. A method for logically binding and verifying devices in an apparatus

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101968914B (zh) * 2010-08-30 2013-07-03 夏爵裕 制作gem通用智能模块cpu的方法及汽车防盗抢报警装置
CN106230604A (zh) * 2016-09-26 2016-12-14 浙江昱能科技有限公司 一种电子设备监控方法及系统

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020129284A1 (en) 2001-03-12 2002-09-12 Takashi Kobayashi Information processing system having fortified password function and method thereof
US6463540B1 (en) 1998-11-03 2002-10-08 Hewlett-Packard Company Securing method for computer bus devices
US20030009680A1 (en) * 2001-06-29 2003-01-09 Antti Kiiveri Method for protecting electronic device, and electronic device
JP2003219475A (ja) * 2002-01-22 2003-07-31 Toshiba Corp 通信端末及び無線通信端末
CN1487763A (zh) * 2002-07-04 2004-04-07 ���Ͽع����޹�˾ 保证移动通信终端安全的方法
CN1620165A (zh) * 2003-11-21 2005-05-25 华为技术有限公司 一种移动终端用户合法性的验证方法
CN1620166A (zh) * 2003-11-21 2005-05-25 华为技术有限公司 一种验证移动终端用户合法性的方法

Family Cites Families (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US4295039A (en) * 1979-12-03 1981-10-13 International Business Machines Corporation Method and apparatus for achieving secure password verification
ES2084846T3 (es) * 1992-01-22 1996-05-16 Siemens Nixdorf Inf Syst Procedimiento para la autentificacion mutua de una tarjeta de chip y un terminal.
US5537544A (en) * 1992-09-17 1996-07-16 Kabushiki Kaisha Toshiba Portable computer system having password control means for holding one or more passwords such that the passwords are unreadable by direct access from a main processor
SE470519B (sv) 1992-11-09 1994-06-27 Ericsson Telefon Ab L M Anordning för tillhandahållande av tjänster såsom telefonkommunikation datakommunikation, etc omfattande en terminalenhet och en accessenhet
DE4242151C1 (de) 1992-12-14 1994-03-24 Detecon Gmbh Verfahren zur Sicherung eines Mobilfunkgerätes gegen unerlaubte Benutzung
US5590198A (en) * 1995-12-19 1996-12-31 Pitney Bowes Inc. Open metering system with super password vault access
US5774545A (en) * 1996-03-28 1998-06-30 Lucent Technologies Inc. Method and apparatus for enhancing security in and discouraging theft of VLSI and ULSI devices
JPH1049493A (ja) 1996-08-06 1998-02-20 Nec Niigata Ltd コンピュータシステム
US6032257A (en) 1997-08-29 2000-02-29 Compaq Computer Corporation Hardware theft-protection architecture
DE19921533C1 (de) 1999-05-11 2001-01-04 Mannesmann Vdo Ag Kommunikationssystem eines Kraftfahrzeuges
GB2363218A (en) 2000-06-07 2001-12-12 Ubinetics Ltd A method of accessing application data for a peripheral device
JP2002183090A (ja) * 2000-12-15 2002-06-28 Nec Yonezawa Ltd コンピュータのパスワード認証による起動方法及びその装置並びにプログラム記憶媒体
TW588243B (en) * 2002-07-31 2004-05-21 Trek 2000 Int Ltd System and method for authentication
US7006481B2 (en) 2002-10-10 2006-02-28 Interdigital Technology Corporation System and method for integrating WLAN and 3G
JP2005012663A (ja) * 2003-06-20 2005-01-13 Sanyo Electric Co Ltd 認証システム及びid発生装置
JP2005151368A (ja) * 2003-11-19 2005-06-09 Matsushita Electric Ind Co Ltd 認証システム
US7426643B2 (en) * 2004-06-22 2008-09-16 Hewlett-Packard Development Company, L.P. Input device feature
US7480931B2 (en) * 2004-07-24 2009-01-20 Bbs Technologies, Inc. Volume mount authentication
CN100337502C (zh) 2004-07-28 2007-09-12 华为技术有限公司 一种在设备中逻辑绑定和验证器件的方法

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6463540B1 (en) 1998-11-03 2002-10-08 Hewlett-Packard Company Securing method for computer bus devices
US20020129284A1 (en) 2001-03-12 2002-09-12 Takashi Kobayashi Information processing system having fortified password function and method thereof
US20030009680A1 (en) * 2001-06-29 2003-01-09 Antti Kiiveri Method for protecting electronic device, and electronic device
JP2003219475A (ja) * 2002-01-22 2003-07-31 Toshiba Corp 通信端末及び無線通信端末
CN1487763A (zh) * 2002-07-04 2004-04-07 ���Ͽع����޹�˾ 保证移动通信终端安全的方法
CN1620165A (zh) * 2003-11-21 2005-05-25 华为技术有限公司 一种移动终端用户合法性的验证方法
CN1620166A (zh) * 2003-11-21 2005-05-25 华为技术有限公司 一种验证移动终端用户合法性的方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP1744574A4

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1744574B2 (en) 2004-07-28 2013-01-02 Huawei Technologies Co., Ltd. A method for logically binding and verifying devices in an apparatus

Also Published As

Publication number Publication date
US7634658B2 (en) 2009-12-15
US20070143609A1 (en) 2007-06-21
EP1744574B1 (en) 2010-05-19
DE602005021341D1 (de) 2010-07-01
CN100337502C (zh) 2007-09-12
CN1728850A (zh) 2006-02-01
ATE468676T1 (de) 2010-06-15
EP1744574A4 (en) 2007-05-16
EP1744574B2 (en) 2013-01-02
EP1744574A1 (en) 2007-01-17

Similar Documents

Publication Publication Date Title
CN101166085B (zh) 远程解锁方法和系统
EP3706019B1 (en) Hardware-enforced access protection
EP3319032B1 (en) Method for processing data, wearable electronic equipment and system
CN103218571A (zh) 在处理器之间验证数据的系统及方法
CN107113175A (zh) 多用户强认证令牌
CN101494541B (zh) 一种实现对pin码进行安全保护的系统及方法
EP2378414A2 (en) Remote update method for firmware
CN101490698A (zh) 计算机系统的组件认证
CN205540702U (zh) 电子设备
CN102215221A (zh) 从移动设备对计算机的安全远程唤醒、引导及登录的方法和系统
EP3267352B1 (en) Secure operation apparatuses and methods therefor
CN110310406A (zh) 一种智能门锁的开锁方法及智能门锁
US20230093992A1 (en) Secure Communication in a Computing System
CN106295404A (zh) 基于安全内核的一体化soc芯片
CN107431626B (zh) 连接装置的认证链接
CN111628863A (zh) 一种数据签名的方法、装置、电子设备及存储介质
CN101478547A (zh) 对智能密码钥匙进行可信数字签名的装置及其工作方法
CN103370713B (zh) 用于编程移动终端设备芯片的方法
CN1705263B (zh) 移动终端用户的合法性验证方法及其移动终端
EP2884786B1 (en) Restricting software to authorized wireless environments
CN103336918B (zh) 电子盘系统授权方法和装置
EP2779568B1 (en) Access control method
CN104376251A (zh) 计算机、实现计算机开机控制的系统及方法
EP1744574B2 (en) A method for logically binding and verifying devices in an apparatus
CN100535918C (zh) 加气站管理系统的加密锁系统

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A1

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KM KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NG NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SM SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A1

Designated state(s): BW GH GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LT LU LV MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
WWE Wipo information: entry into national phase

Ref document number: 2005772421

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 11609571

Country of ref document: US

WWP Wipo information: published in national office

Ref document number: 2005772421

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

WWP Wipo information: published in national office

Ref document number: 11609571

Country of ref document: US