One-key automatic signature method and system based on CPE program small file

Through one-click automatic signature method and system, the cumbersome problem of CPE program small file signature process is solved, and a fast and automatic signature process is realized, which improves efficiency and security, and supports cross-platform operations.

CN120196595AActive Publication Date: 2025-06-24GUANGZHOU TOZED KANGWEI INTELLIGENT TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510183050.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-06-24
Estimated Expiration
2045-02-19

AI Technical Summary

Technical Problem

The signature process of CPE program small files is cumbersome, requiring manual upload of the server, modifying the name, signing and downloading, especially in the case of frequent burning and multiple modifications, which leads to large workload and low efficiency.

Method used

It provides a one-click automatic signature method and system based on small CPE program files. It receives signature parameters through a graphical user interface, dynamically displays the key list, standardizes file renaming, automatically uploads it to the Linux server for signature using the cross-platform file transfer protocol, and automatically downloads the signed file after the signature is successful.

Benefits of technology

It realizes fast and automatic signature of small files, reduces the steps of manual operation by users, improves signature efficiency, supports Windows platform operation, is compatible with Linux environments, and enhances security and passes legality checks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120196595A_ABST
    Figure CN120196595A_ABST
Patent Text Reader

Abstract

The invention discloses a one-key automatic signature method and system based on a CPE program small file, and relates to the field of CPE programs.The method comprises the steps that signature parameters input by a user are received through a graphical interface, and the signature parameters comprise a signature branch, a secret key list, storage capacity and a to-be-signed module path; and dynamically matching the key list according to the signature branch, and converting the parameter into a digital identifier which can be identified by the server side. And uploading the to-be-signed file to the Linux server through an SCP protocol after the to-be-signed file is subjected to standardized renaming, and calling a server signature interface to execute signature. And after the signature succeeds, the system renames the file and automatically downloads the file to a local specified path. The system is composed of a parameter input module, a dynamic display module, a file processing module, a signature execution module and a security verification module, automation, cross-platform compatibility and secure transmission of small file signature are achieved, the tedious process of small file burning signature of CPE equipment is remarkably simplified, and signature efficiency and security are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of CPE programs, and more specifically, to a one-key automatic signature method and system for CPE program small files. Background Art

[0002] Customer Premise Equipment (CPE) refers to the equipment located at the user's site and owned by the user, which is used to connect to the service provider's network. CPE usually includes various types of network devices, such as routers, switches, modems, gateways, wireless access points, etc. These devices are usually responsible for guiding the Internet or other communication services from the service provider's network to the internal network of the user's home or office. The function of CPE is to ensure that users can access the external network and process data transmission within the local area network.

[0003] As the era of Internet of Everything is approaching, CPE is in increasing demand due to its advantages such as easy portability, easy setup, and high speed. Adhering to the concepts of customer first and service first, it is crucial to provide high-quality services to customers. Especially in the early stage, front-line technical support cooperates with R & D colleagues to carry out various optimizations in the customer's live network environment, and various temporary modifications to the current environment need to be provided. The temporary modifications are usually for quickly responding to front-line tests and saving time, and need to be burned into the CPE in the form of small files. After this important step of signature, front-line personnel can use them normally. This small file is different from the complete firmware burned into the CPE. The complete firmware is burned less frequently, so the signature times are few. However, as a "patch", the small file is burned more frequently, and it needs to be signed before each burn. Moreover, the signature may also involve multiple processes such as renaming, which generally makes the signature process of the small file very complicated.

[0004] More specifically, the signature of the small file requires uploading to the server. Modify the name, input it in sequence and then perform the signature action, and finally download the signed small file. As there are more places to modify, the repetitive signature workload is also increased. Therefore, the present invention proposes a one-key automatic signature method and system for CPE program small files. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a one-key automatic signature method and system for CPE program small files to solve the problems mentioned in the background art.

[0006] To achieve the above object, the present invention adopts the following technical solutions:

[0007] A one-key automatic signature method for CPE program small files includes the following steps:

[0008] S1: Receive the signature parameters input by the user through the graphical user interface, including signature branch parameters, key list parameters, storage capacity parameters, and the path of the module to be signed.

[0009] S2: Dynamically display the corresponding key list parameters according to the signature branch parameters, and convert the key list parameters and storage capacity parameters into digital identification parameters recognizable by the server side.

[0010] S3: Perform a standardized renaming process on the original file of the module to be signed to generate a target file name that conforms to the server naming rules.

[0011] S4: Automatically upload the renamed file to the Linux server through the cross-platform file transfer protocol, and call the server signature interface to perform the signature operation. The signature interface selects the corresponding signature algorithm according to the digital identification parameters.

[0012] S5: In response to the signature success information returned by the server, append an extension name containing the key identifier and timestamp to the signed file, and automatically download it to the local specified path through the cross-platform file transfer protocol.

[0013] In an alternative embodiment, the parameter conversion in step S2 specifically includes:

[0014] Map the key list parameters to predefined integer encodings, and convert the storage capacity parameters into server-side storage partition configuration identifiers.

[0015] In an alternative embodiment, step S3 further includes:

[0016] According to the type of the module to be signed selected by the user, match the preset module naming rule library, and perform legality verification and standardized renaming on the file name.

[0017] In an alternative embodiment, the cross-platform file transfer protocol in step S4 is an encapsulated transmission module based on the SCP protocol, and the server IP address, account, and password are built into the tool in an encrypted form.

[0018] In an alternative embodiment, the extension name generation rule in step S5 is:

[0019] Concatenate the key list parameter name and the current date in the format of "key_yearmonthday-sign" to the end of the original file name.

[0020] More specifically, the method is applied to small CPE program files. The small CPE program files are different from the CPE overall firmware and are program patches used to be burned into the CPE. The size of the small files is less than 20% of the size of the overall firmware.

[0021] In addition, for greater precision, the CPE program small files can also be defined as files with a file size smaller than a preset value T. For example, T can be set to 16MB (the current largest small file is around 15MB).

[0022] The present invention also discloses a one-key automatic signature system based on CPE program small files, including:

[0023] A parameter input module, configured to receive signature branch parameters, key list parameters, storage capacity parameters, and module paths through a graphical interface;

[0024] A dynamic display module, configured to dynamically update the optional parameters of the key list according to the signature branch parameters;

[0025] A file processing module, configured to perform standardized file renaming and cross-platform file transfer based on the SCP protocol;

[0026] A signature execution module, configured to send a signature request carrying digital identity parameters to a Linux server and parse the signature result returned by the server;

[0027] A security verification module, configured to perform a legality check on the signed file and feedback the signature status on the graphical interface.

[0028] In an alternative embodiment, the parameter input module includes:

[0029] A drop-down menu component, configured to select signature branch parameters and key list parameters;

[0030] A path selection button, configured to trigger a file browser to select the module path to be signed.

[0031] In an alternative embodiment, the security verification module further includes:

[0032] A regular expression matching unit, configured to detect whether the information returned by the server contains a predefined signature success identifier;

[0033] An exception handling unit, configured to automatically retry the upload operation and record error logs when the signature fails.

[0034] In an alternative embodiment, it further includes an extensible interface module, configured to:

[0035] Dynamically load newly added signature algorithm parameters and storage capacity types through a configuration file without modifying the program code.

[0036] The advantages of the present invention over the prior art are:

[0037] The present invention can complete the quick signature of small files through an automated process, eliminating the need for users to perform manual operations. Additionally, the original signature was completed on the Linux platform, but this tool can complete the signature on the Windows platform, resolving compatibility issues between the Windows and Linux environments. The present invention can also be configured to support graphical operations and displays, optimizing from command-line operations to graphical interface operations, making it more user-friendly. The present invention can internally store sensitive parameters such as passwords and perform signature legality checks on small files, greatly ensuring security. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 is a flowchart of the method of the present invention;

[0039] Figure 2 is a structural diagram of the system of the present invention;

[0040] Figure 3 is a flowchart of an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0041] The following describes the specific embodiments of the present invention in conjunction with the accompanying drawings.

[0042] As Figure 1 shown in the schematic diagram of the method of the present invention, it includes the following steps:

[0043] S1: Receive signature parameters input by the user through a graphical user interface, including signature branch parameters, key list parameters, storage capacity parameters, and the path of the module to be signed;

[0044] S2: Dynamically display the corresponding key list parameters according to the signature branch parameters, and convert the key list parameters and storage capacity parameters into digital identification parameters recognizable by the server side;

[0045] S3: Perform a standardized renaming process on the original file of the module to be signed to generate a target file name that conforms to the server naming rules;

[0046] S4: Automatically upload the renamed file to the Linux server through a cross-platform file transfer protocol, and call the server signature interface to execute the signature operation. The signature interface selects the corresponding signature algorithm according to the digital identification parameters;

[0047] S5: In response to the signature success information returned by the server, append an extension name containing the key identifier and timestamp to the signed file, and automatically download it to the local specified path through the cross-platform file transfer protocol.

[0048] In an alternative embodiment, the parameter conversion in step S2 specifically includes:

[0049] Map the key list parameter to a predefined integer encoding and convert the storage capacity parameter into a server-side storage partition configuration identifier.

[0050] In an alternative embodiment, step S3 further includes:

[0051] According to the type of the module to be signed selected by the user, match the preset module naming rule library to perform a legality check and a standardized rename on the file name.

[0052] In an alternative embodiment, in step S4, the cross-platform file transfer protocol is an encapsulated transfer module based on the SCP protocol, and the server IP address, account, and password are built into the tool in an encrypted form.

[0053] In an alternative embodiment, the extension name generation rule in step S5 is:

[0054] Concatenate the key list parameter name and the current date in the format of "key_yearmonthday-sign" to the end of the original file name.

[0055] As Figure 2 shown in the structural schematic diagram of the system of the present invention, it includes:

[0056] A parameter input module for receiving signature branch parameters, key list parameters, storage capacity parameters, and module paths through a graphical interface;

[0057] A dynamic display module for dynamically updating the optional parameters of the key list according to the signature branch parameters;

[0058] A file processing module for performing a standardized rename on the file and a cross-platform file transfer based on the SCP protocol;

[0059] A signature execution module for sending a signature request carrying digital identification parameters to a Linux server and parsing the signature result returned by the server;

[0060] A security verification module for performing a legality check on the signed file and feeding back the signature status on the graphical interface.

[0061] In an alternative embodiment, the parameter input module includes:

[0062] A drop-down menu component for selecting signature branch parameters and key list parameters;

[0063] A path selection button for triggering a file browser to select the path of the module to be signed.

[0064] In an alternative embodiment, the security verification module further includes:

[0065] A regular expression matching unit for detecting whether the server return information contains a predefined signature success identifier;

[0066] An exception handling unit for automatically retrying the upload operation and recording error logs when the signature fails.

[0067] In an alternative embodiment, it further includes an extensible interface module for:

[0068] Dynamically loading newly added signature algorithm parameters and storage capacity types through a configuration file without modifying the program code.

[0069] As Figure 3 shown in a more specific embodiment. In this specific embodiment:

[0070] The process includes:

[0071] Selecting signature branch parameters:

[0072] The user selects appropriate signature branch parameters through a graphical interface. Currently, multiple options are provided, such as "un30_wifi6_sign", "un30_sign", and "MX0268_sign". These branch parameters represent different signature environments, meaning that each branch uses a different signature algorithm, but for the user, the operation interface of the tool does not differ much. For example, the user currently selects "MX0268_sign" as the signature branch parameter.

[0073] Displaying the key list:

[0074] According to the signature branch selected by the user, the system automatically displays the corresponding key list. For example, if the user selects "MX0268_sign", the system will display the matching key parameters, such as "common", "IN0345", "NG0002", "TN0303", "GH0153", and "SC001". In this example, the user selects the "common" key parameter.

[0075] Selecting the storage capacity (Flash) parameter:

[0076] The user can select the storage capacity type of the CPE device. Common options include "2G FLASH" or "4GFLASH", and the specific selection depends on the hardware configuration of the target device. For example, the user selects "2GFLASH" as the storage capacity.

[0077] Selecting the path of the module to be signed:

[0078] The system supports signing multiple modules. Currently, there are four modules available for selection: "nr", "v3", "ps", and "dsp". Each module represents a different functional component or program module in the CPE. The user selects the "nr" module and chooses the path of this module in the file browser, which is the folder path where the module is located.

[0079] Click the Sign button:

[0080] After completing the above settings, the user clicks the "Sign" button to start the signing process. The specific steps of the signing process are as follows:

[0081] Load the signing configuration:

[0082] The system loads the relevant signing configuration according to the signing branch (such as "MX0268_sign") and key (such as "common") selected by the user.

[0083] Rename the file:

[0084] According to the module type selected by the user (for example, selecting the "nr" module), the system performs a standardized renaming process on the file to be signed to ensure that the file name conforms to the server naming rules. For example, the original file name might be "nr_module.bin", and the system will rename it to "SC9600_Orca_NR_phy_modem.bin".

[0085] Upload the file to the server:

[0086] The renamed file will be uploaded to the specified Linux server path (such as " / home / work / cp_sign / ") via SCP (Secure Copy Protocol).

[0087] Parameter conversion and signing request:

[0088] The system converts the "key" and "storage capacity" parameters selected by the user into digital identifiers (for example, "common" is mapped to 1, and "2G FLASH" is mapped to 1), and sends these parameters together with the file to be signed to the signing interface of the server to start the signing operation.

[0089] Confirm the signing result:

[0090] After the server finishes the signing operation, it returns the signing result information. If the returned information contains "Currentsign result:Success", it means the signing is successful. Otherwise, the system will prompt that the signing fails, and the user can adjust the operation according to the prompt.

[0091] File renaming and download:

[0092] If the signature is successful, the system will further rename the signed file according to the module selected by the user and the current date (for example, the date is "20250120"). The new file name format is "SC9600_Orca_NR_phy_modem_common_20250120-sign.bin". The renamed file will be automatically downloaded to the local path specified by the user (such as the "cp_sign" directory) via the SCP protocol to complete the signature process.

[0093] Among them:

[0094] The signature branch parameter specifies the selection of the signature environment or signature algorithm. Different branch parameters may correspond to different signature strategies or security requirements.

[0095] The key list parameter is used to select the key related to the signature. Each key represents a specific security identity to ensure the uniqueness and security of the signature process.

[0096] The storage capacity parameter specifies the storage capacity type of the CPE device, such as 2GB, 4GB, etc., to ensure that the signature process matches the device hardware configuration.

[0097] The SCP protocol is the Secure Copy Protocol, a protocol for securely transferring files between computers and is commonly used for remote file transfer.

[0098] The module type is the classification of different functional modules in the CPE. The user can select the module to be signed according to actual needs to ensure the accuracy of the firmware update.

[0099] During the signature process, the file name needs to follow specific rules and formats so that the system can correctly identify and perform the corresponding signature operations.

[0100] As described above, it is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. A one-key automatic signing method based on a CPE program small file, characterized in that: The following steps are involved: S1: receiving signature parameters input by the user through a graphical user interface, including signature branch parameters, key list parameters, storage capacity parameters and the path of the module to be signed; S2: dynamically displaying corresponding key list parameters according to the signature branch parameters, and converting the key list parameters and storage capacity parameters into digital identification parameters recognizable by the server; S3: Perform standardized renaming on the original file of the signature module to generate a target file name that complies with the server naming rules; S4: Automatically upload the renamed file to the Linux server through the cross-platform file transfer protocol, and call the server signature interface to perform the signature operation, wherein the signature interface selects a corresponding signature algorithm according to the digital identification parameters; S5: In response to the signature success information returned by the server, an extension including a key identifier and a timestamp is added to the signed file, and the file is automatically downloaded to a local designated path via the cross-platform file transfer protocol.

2. The method according to claim 1, characterized in that: The parameter conversion in step S2 specifically includes: Maps key list parameters to predefined integer encodings and converts storage capacity parameters to server-side storage bucket configuration identifiers.

3. The method according to claim 1, characterized in that: Step S3 further comprises: According to the type of module to be signed selected by the user, the preset module naming rule library is matched to verify the legitimacy of the file name and rename it in a standardized manner.

4. The method according to claim 1, characterized in that: In step S4, the cross-platform file transfer protocol is an encapsulation transmission module based on the SCP protocol, and the server IP address, account number and password are embedded in the tool in an encrypted form.

5. The method according to claim 1, characterized in that The extension generation rule in step S5 is: Concatenate the key list parameter name and the current date to the end of the original file name in the format of "key_year-month-day-sign".

6. The method according to any one of claims 1 to 5, characterized in that: The method is applied to a small CPE program file. The small CPE program file is different from the overall CPE firmware and is a program patch for burning into the CPE. The size of the small CPE program file is less than 20% of the size of the overall firmware.

7. A one-key automatic signature system based on CPE program small files, characterized in that: include: A parameter input module, used to receive signature branch parameters, key list parameters, storage capacity parameters and module path through a graphical interface; Dynamic display module, used to dynamically update the optional parameters of the key list according to the signature branch parameters; File processing module, used to perform standardized file renaming and cross-platform file transfer based on SCP protocol; The signature execution module is used to send a signature request carrying digital identification parameters to the Linux server and parse the signature result returned by the server; The security verification module is used to check the legitimacy of the signed file and feedback the signature status in the graphical interface.

8. The system according to claim 7, characterized in that The parameter input module comprises: Drop-down menu component, used to select signature branch parameters and key list parameters; The path selection button is used to trigger the file browser to select the path of the module to be signed.

9. The system according to claim 7, characterized in that The security verification module further comprises: A regular expression matching unit, used to detect whether the information returned by the server contains a predefined signature success identifier; Exception handling unit, used to automatically retry the upload operation and record the error log when the signature fails.

10. The system according to claim 7, characterized in that Also includes expandable interface modules for: New signature algorithm parameters and storage capacity types are dynamically loaded through the configuration file without modifying the program code.

Citation Information

Patent Citations

  • Automatic notification method and apparatus of signature message, and server

    CN107231367A

  • Firmware security upgrading system

    CN110795126A

  • Batch signature method and device for Windows system upgrade and computer equipment

    CN113296812A

  • Method and system for uniformly signing product firmware

    CN118656879A

  • Method for making a digital signature

    EP2717191A1