Authentication method and apparatus
View Patent ↗This application provides example authentication methods and apparatuses. One example authentication method is used for a terminal device. The method includes receiving, by the first service unit, a first request from a second device, wherein the first request is used to request a first seed. The first service unit sends the first request to the first authentication unit. The first authentication unit sends a first response to the first service unit, wherein the first response comprises the first seed. The first service unit sends the first response to the second device. The first service unit receives a second seed from the second device. The first service unit sends the second seed to the first authentication unit. The first authentication unit determines a third seed based on a first key and the second seed, wherein the first key is determined based on the first seed.
1 . An authentication method, applied to a first device, wherein the first device comprises a transceiver, a first service processor storing service information of the first device, and a first authentication processor, wherein an authentication operation in the first authentication processor is isolated from the service information in the first service processor, and wherein the method comprises:
receiving, by the first service processor through the transceiver, a first request from a second device, wherein the first request is used to request a first seed;
sending, by the first service processor, the first request to the first authentication processor;
sending, by the first authentication processor, a first response to the first service processor, wherein the first response comprises the first seed;
sending, by the first service processor through the transceiver, the first response to the second device;
receiving, by the first service processor through the transceiver, a second seed from the second device;
sending, by the first service processor, the second seed to the first authentication processor;
determining, by the first authentication processor, a third seed based on a first key and the second seed, wherein the first key is determined based on the first seed;
determining, by the first authentication processor, a matching result between the third seed and the first seed;
sending, by the first authentication processor, the matching result to the first service processor; and
sending, by the first service processor through the transceiver, the matching result to the second device.
2 . The authentication method according to claim 1 , wherein the method further comprises:
determining, by the first authentication processor, the first key based on a first key material, a first key generation algorithm, and the first seed, wherein the first key material and the first key generation algorithm are stored in the first authentication processor.
3 . The authentication method according to claim 2 , wherein the first request comprises an access level, and before the determining, by the first authentication processor, the first key based on a first key material, a first key generation algorithm, and the first seed, the method further comprises:
determining, by the first authentication processor, the first key material and the first key generation algorithm based on the access level.
4 . The authentication method according to claim 1 , wherein:
the sending, by the first service processor, the second seed to the first authentication processor comprises:
sending, by the first service processor, the second seed and identification information to the first authentication processor, wherein the identification information corresponds to the first key; and
before the determining, by the first authentication processor, a third seed based on a first key and the second seed, the method further comprises:
determining, by the first authentication processor, the first key based on the identification information.
5 . The authentication method according to claim 4 , wherein the method further comprises:
sending, by the first authentication processor, the identification information to the first service processor, wherein the identification information is determined based on the first key.
6 . The authentication method according to claim 1 , wherein the method further comprises:
deleting, by the first authentication processor, the first key.
7 . An authentication method, applied to a second device, wherein the second device comprises a transceiver, a second service processor storing service information of the second device, and a second authentication processor, wherein an authentication operation in the second authentication processor is isolated from the service information in the second service processor, and wherein the method comprises:
sending, by the second authentication processor, a first request to the second service processor, wherein the first request is used to request a first seed;
sending, by the second service processor through the transceiver, the first request to a first device;
receiving, by the second service processor through the transceiver, a first response from the first device, wherein the first response comprises the first seed;
sending, by the second service processor, the first response to the second authentication processor;
sending, by the second authentication processor, a second seed to the second service processor, wherein the second seed is determined based on the first seed and a second key, and the second key is determined based on the first seed;
sending, by the second service processor through the transceiver, the second seed to the first device; and
receiving, by the second service processor through the transceiver, a matching result from the first device.
8 . The authentication method according to claim 7 , wherein the method further comprises:
determining, by the second authentication processor, the second key based on a second key material, a second key generation algorithm, and the first seed, wherein the second key material and the second key generation algorithm are stored in the second authentication processor.
9 . The authentication method according to claim 7 , wherein the method further comprises:
deleting, by the second authentication processor, the second key.
10 . An authentication apparatus, wherein the authentication apparatus comprises a transceiver, a first service processor configured to store service information of the authentication apparatus, and a first authentication processor, and wherein:
an authentication operation in the first authentication processor is isolated from the service information in the first service processor;
the first service processor is configured to receive a first request from a second device through the transceiver, wherein the first request is used to request a first seed;
the first service processor is further configured to send the first request to the first authentication processor;
the first authentication processor is configured to send a first response to the first service processor, wherein the first response comprises the first seed;
the first service processor is further configured to send the first response to the second device through the transceiver;
the first service processor is further configured to receive a second seed from the second device through the transceiver;
the first service processor is further configured to send the second seed to the first authentication processor;
the first authentication processor is further configured to determine a third seed based on a first key and the second seed, wherein the first key is determined based on the first seed;
the first authentication processor is further configured to determine a matching result between the third seed and the first seed;
the first authentication processor is further configured to send the matching result to the first service processor; and
the first service processor is further configured to send the matching result to the second device through the transceiver.
11 . The authentication apparatus according to claim 10 , wherein the first authentication processor is further configured to determine the first key based on a first key material, a first key generation algorithm, and the first seed, wherein the first key material and the first key generation algorithm are stored in the first authentication processor.
12 . The authentication apparatus according to claim 11 , wherein the first request comprises an access level, and the first authentication processor is further configured to determine the first key material and the first key generation algorithm based on the access level.
13 . The authentication apparatus according to claim 10 , wherein:
the first service processor is further configured to send the second seed and identification information to the first authentication processor, wherein the identification information corresponds to the first key; and
the first authentication processor is further configured to determine the first key based on the identification information.
14 . The authentication apparatus according to claim 13 , wherein the first authentication processor is further configured to send the identification information to the first service processor, and wherein the identification information is determined based on the first key.
15 . The authentication apparatus according to claim 10 , wherein the first authentication processor is further configured to delete the first key.
16 . An authentication apparatus, wherein the authentication apparatus comprises a transceiver, a second service processor configured to service information of the authentication apparatus, and a second authentication processor, and wherein:
an authentication operation in the second authentication processor is isolated from the service information in the second service processor;
the second authentication processor is configured to send a first request to the second service processor, wherein the first request is used to request a first seed;
the second service processor is configured to send the first request to a first device through the transceiver;
the second service processor is further configured to receive a first response from the first device through the transceiver, wherein the first response comprises the first seed;
the second service processor is further configured to send the first response to the second authentication processor;
the second authentication processor is further configured to send a second seed to the second service processor, wherein the second seed is determined based on the first seed and a second key, and the second key is determined based on the first seed;
the second service processor is further configured to send the second seed to the first device through the transceiver; and
the second service processor is further configured to receive a matching result sent by the first device through the transceiver.
17 . The authentication apparatus according to claim 16 , wherein the second authentication processor is further configured to determine the second key based on a second key material, a second key generation algorithm, and the first seed, and wherein the second key material and the second key generation algorithm are stored in the second authentication processor.
18 . The authentication apparatus according to claim 16 , wherein the second authentication processor is further configured to delete the second key.