Bluetooth equipment firmware wireless upgrading method and device, equipment and storage medium

By obtaining Bluetooth device identification information and using cloud servers and asymmetric encryption technology to establish an encrypted Bluetooth communication link, the management difficulties and security issues in the Bluetooth device firmware upgrade process are solved, and efficient and secure firmware upgrades are achieved.

CN120640273APending Publication Date: 2025-09-12CHINA MERCHANTS BANK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510853462.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

The Bluetooth device firmware upgrade process faces problems such as the wide and dispersed distribution of devices, difficulty in firmware version management, high upgrade time and cost, poor transparency and security, and high learning costs for upgrade tools.

Method used

By obtaining the device identification information of the Bluetooth device, using the cloud server to obtain the corresponding firmware file, generating an asymmetric encryption key and establishing an encrypted Bluetooth communication link, splitting the firmware file and transmitting it to the device through the encrypted link, combined with a multi-layer defense strategy to ensure security and integrity.

Benefits of technology

It simplifies the upgrade operation, improves the upgrade efficiency, reduces the operation difficulty, ensures the security and integrity of the firmware file during the transmission process, and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120640273A_ABST
    Figure CN120640273A_ABST
Patent Text Reader

Abstract

The invention discloses a Bluetooth equipment firmware wireless upgrading method and device, equipment and a storage medium, and relates to the technical field of wireless upgrading, and the method comprises the steps: obtaining equipment identification information of to-be-upgraded Bluetooth equipment; acquiring a corresponding firmware file from a cloud server according to the equipment identification information; generating an asymmetric encryption key, sending the asymmetric encryption key to the Bluetooth device, and receiving a device public key returned by the Bluetooth device based on the asymmetric encryption key; generating a session key based on the equipment public key, and establishing an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth equipment based on the session key; a firmware file is transmitted to a Bluetooth device through an encrypted Bluetooth communication link to execute an upgrading operation, the firmware file is deployed in a cloud service, a terminal is connected with the Bluetooth device through Bluetooth, a corresponding firmware version file is obtained according to a device type, and meanwhile, various security technologies are used for guaranteeing the security of firmware in a wireless transmission process. The upgrading operation is simplified, the operation difficulty is reduced, and the upgrading efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of wireless upgrade technology, and in particular to a method, apparatus, device and storage medium for wirelessly upgrading firmware of a Bluetooth device. Background Art

[0002] The firmware of a Bluetooth device can be thought of as a simple operating system running on the device. It is a set of pre-installed instructions inside the device, which opens corresponding interfaces for external calls to control the hardware to perform related operations.

[0003] As business develops, Bluetooth devices need to support new functions and fix and optimize related problems, and the Bluetooth device firmware needs to be upgraded. However, the current upgrade solution has problems such as wide and scattered device distribution, difficult firmware version management, high time cost for firmware upgrades, questionable firmware transparency and security, and high cost of learning upgrade tools.

[0004] The above content is only used to assist in understanding the technical solution of this application and does not constitute an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of this application is to provide a method, apparatus, device and storage medium for wireless firmware upgrade of Bluetooth devices, aiming to solve the technical problems of poor security and low efficiency faced by Bluetooth devices during firmware upgrades.

[0006] To achieve the above objectives, the present application proposes a method for wirelessly upgrading Bluetooth device firmware, the method comprising:

[0007] Get the device identification information of the Bluetooth device to be upgraded;

[0008] Obtaining the corresponding firmware file from the cloud server according to the device identification information;

[0009] Generate an asymmetric encryption key and send it to the Bluetooth device, and receive a device public key returned by the Bluetooth device based on the asymmetric encryption key;

[0010] generating a session key based on the device public key, and establishing an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth device based on the session key;

[0011] The firmware file is transmitted to the Bluetooth device via the encrypted Bluetooth communication link to perform an upgrade operation.

[0012] In one embodiment, the step of transmitting the firmware file to the Bluetooth device via the encrypted Bluetooth communication link includes:

[0013] Splitting the firmware file into a preset number of data blocks;

[0014] transmitting each of the data blocks to the Bluetooth device in sequence via the encrypted Bluetooth communication link, so that the Bluetooth device performs a cyclic redundancy check on each data block to obtain a check result;

[0015] When all data blocks have passed verification, it is determined that the firmware file transfer is completed.

[0016] In one embodiment, the step of sequentially transmitting each of the data blocks to the Bluetooth device via the encrypted Bluetooth communication link includes:

[0017] defining a transmission window based on a transmission period of the data block;

[0018] monitoring a packet loss rate of each of the transmission windows;

[0019] When the packet loss rate of a plurality of consecutive transmission windows exceeds a preset threshold, performing a channel switching operation: scanning available channels and switching to a channel with lower interference intensity to establish a connection;

[0020] When the response delay after the channel switching does not meet the stability condition, the transmission of the data block is suspended.

[0021] In one embodiment, the step of obtaining the corresponding firmware file from the cloud server according to the device identification information includes:

[0022] Parsing the structured region code in the device identification information, wherein the region code includes multiple levels of administrative hierarchy identification;

[0023] Performing a multi-level matching query in a policy library according to the administrative level identifier;

[0024] When the global distribution policy is matched, the standard version firmware address is obtained and downloaded;

[0025] When a region-specific policy is matched, obtain the customized firmware address bound to the policy;

[0026] When multiple levels of policies are matched simultaneously, the download address is selected based on the rule that the region-specific policy takes precedence over the global distribution policy.

[0027] In one embodiment, after the step of obtaining the corresponding firmware file from the cloud server according to the device identification information, the method further includes:

[0028] Generate a dynamic access token based on the device identification information to perform authority authentication and obtain an authority authentication result;

[0029] When the authority authentication result is authentication passed, determining a hash value of the firmware file;

[0030] Compare the hash value with the pre-stored reference value in the cloud to obtain a comparison result;

[0031] When the comparison result is that the comparison passes, it is determined that the firmware file passes the integrity check.

[0032] In one embodiment, the method further comprises:

[0033] Starting a file monitoring module to continuously monitor the access process of the firmware file;

[0034] Extracting the digital signature information of the access process, and comparing the digital signature information with a preset authorization whitelist to generate a process authorization verification result;

[0035] When the process authorization verification result is unauthorized access, outputting a tampering monitoring alarm signal;

[0036] Based on the tampering monitoring alarm signal, the firmware file is deleted and a security alarm log is updated, wherein the log includes an ID of the unauthorized process, an access timestamp, and an operation type.

[0037] In one embodiment, after the step of comparing the digital signature information with a preset authorization whitelist to generate a process authorization verification result, the method further includes:

[0038] When the process authorization check result is failed, continuously collecting the memory write operation frequency and sensitive application programming interface call sequence of the access process of the firmware file;

[0039] determining a behavior risk index based on the memory write operation frequency and the sensitive application programming interface call sequence;

[0040] When the behavior risk index exceeds a dynamic threshold, stopping the access process of the firmware file and generating a process memory snapshot;

[0041] extracting high-risk feature data based on the memory snapshot;

[0042] Uploading the high-risk feature data and the corresponding behavior pattern hash value to the cloud threat intelligence library triggers the synchronous update of the preset authorization whitelist policy.

[0043] In addition, to achieve the above-mentioned purpose, the present application also proposes a Bluetooth device firmware wireless upgrade device, the device comprising:

[0044] An information acquisition module is used to obtain device identification information of the Bluetooth device to be upgraded;

[0045] A firmware download module, configured to obtain the corresponding firmware file from the cloud server according to the device identification information;

[0046] A link building module, configured to perform an asymmetric encryption public key exchange with the Bluetooth device; generate a session key based on the asymmetric encryption public key, and establish an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth device based on the session key;

[0047] A transmission module is used to transmit the firmware file to the Bluetooth device through the encrypted Bluetooth communication link to perform an upgrade operation.

[0048] In addition, to achieve the above-mentioned purpose, the present application also proposes a Bluetooth device firmware wireless upgrade device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the computer program is configured to implement the steps of the Bluetooth device firmware wireless upgrade method as described above.

[0049] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and stores a computer program on the storage medium. When the computer program is executed by the processor, the steps of the Bluetooth device firmware wireless upgrade method as described above are implemented.

[0050] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the Bluetooth device firmware wireless upgrade method as described above.

[0051] One or more technical solutions proposed in this application have at least the following technical effects:

[0052] Obtain the device identification information of the Bluetooth device to be upgraded; obtain the corresponding firmware file from the cloud server based on the device identification information; generate an asymmetric encryption key and send it to the Bluetooth device, and receive the device public key returned by the Bluetooth device based on the asymmetric encryption key; generate a session key based on the device public key, and establish an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth device based on the session key; transmit the firmware file to the Bluetooth device via the encrypted Bluetooth communication link to perform the upgrade operation, deploy the firmware file on the cloud service, connect the terminal to the Bluetooth device via Bluetooth, and obtain the corresponding firmware version file based on the device type. At the same time, various security technologies are used to ensure the security of the firmware during wireless transmission. This simplifies the upgrade operation, reduces the operational difficulty, and improves the upgrade efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0054] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0055] Figure 1 A flowchart of the first embodiment of the method for wirelessly upgrading firmware of a Bluetooth device provided in this application;

[0056] Figure 2 A diagram of the firmware verification and management system provided in Example 1 of the method for wirelessly upgrading firmware of a Bluetooth device of this application;

[0057] Figure 3 A diagram showing the firmware security mechanism structure provided in Example 1 of the method for wirelessly upgrading firmware of a Bluetooth device of this application;

[0058] Figure 4 A schematic diagram of the full-link firmware upgrade process provided in Example 1 of the method for wirelessly upgrading firmware of a Bluetooth device of this application;

[0059] Figure 5 A flowchart of the second embodiment of the method for wirelessly upgrading firmware of a Bluetooth device provided in this application;

[0060] Figure 6 This is a schematic diagram of the module structure of the device for wirelessly upgrading firmware of a Bluetooth device according to an embodiment of the present application;

[0061] Figure 7 This is a schematic diagram of the device structure of the hardware operating environment involved in the Bluetooth device firmware wireless upgrade method in the embodiment of the present application.

[0062] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0063] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.

[0064] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.

[0065] It should be noted that the execution subject of this embodiment may be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, mobile phone, etc., or an electronic device capable of implementing the above functions, a Bluetooth device firmware wireless upgrade device, a mobile service terminal, etc. The following uses a Bluetooth device firmware wireless upgrade device as an example to illustrate this embodiment and the following embodiments.

[0066] Based on this, the embodiment of the present application provides a method for wirelessly upgrading the firmware of a Bluetooth device, referring to Figure 1 , Figure 1 This is a flowchart of the first embodiment of the method for wirelessly upgrading Bluetooth device firmware according to the present application.

[0067] In this embodiment, the method for wirelessly upgrading Bluetooth device firmware includes steps S10 to S30:

[0068] Step S10, obtaining device identification information of the Bluetooth device to be upgraded;

[0069] It should be noted that the execution entity of this application is the business PAD, which is a mobile business terminal;

[0070] Bluetooth devices to be upgraded are those used with exhibition PADs and require firmware upgrades. These devices communicate with exhibition PADs using the Bluetooth protocol, and their firmware needs to be updated based on business development needs or performance optimization requirements.

[0071] Device identification information is a set of parameters carried by a Bluetooth device that uniquely identifies it. This information can include key information such as the device serial number, MAC address, device model, and region code. This information is stored in a specific data format in the Bluetooth device's internal storage area.

[0072] When the exhibition PAD successfully establishes a connection with the Bluetooth device to be upgraded through the Bluetooth protocol, the corresponding read instruction is called through the Bluetooth communication interface. The Bluetooth device will send the pre-stored device identification information to the exhibition PAD according to the protocol specification, thereby completing the process of obtaining the device identification information.

[0073] like Figure 2 As shown in the figure, this solution builds a firmware verification and management system to enhance the reliability and security of the firmware. The picture list shows: management of brand, version number, status (released / valid / invalid), release range, support for log creation, data storage and file attribute (file name / size) operations.

[0074] Image upload: Configure name, number, group and file upload function.

[0075] Version release information: Control bank policies (head office level), branch policies (regional level), and executive bureau releases (regulatory instructions), and release strategies are orchestrated through the system.

[0076] Image status: tracking type, status (published / valid / invalid) and associated relationships.

[0077] The bottom front-end capabilities cover basic services such as gallery management and API interfaces.

[0078] Multi-level strategy release system (bank / branch / executive bureau), complete file attribute parameters (file name + size), and status life cycle (release → valid → invalid) three-layer labeling.

[0079] System functions include: Firmware visual management: provides firmware version management and visual operation functions, including version list display, conditional filtering, uploading, status change and version information editing.

[0080] Dynamic firmware release mechanism: Firmware release strategies support flexible configuration by branch, device number, etc., ensuring that firmware upgrades are continuous and controllable.

[0081] like Figure 3 As shown in Figure 1, firmware security is the cornerstone of system protection, as it is often the primary target of malicious attacks. To build an impenetrable line of defense, we implemented a comprehensive multi-layered defense strategy:

[0082] Access control: strict authentication mechanism.

[0083] Firmware security check: Perform integrity check on the firmware to ensure that the downloaded firmware is safe and reliable.

[0084] File anti-tampering monitoring: Monitor downloaded files to ensure they are not tampered with before and during transmission.

[0085] Encrypted transmission: Bluetooth channel encryption technology is used to ensure the transmission process is safe and reliable.

[0086] like Figure 4 As shown, firmware is uploaded from the management platform to cloud storage via the network. The server then performs policy matching (including bank / branch policies) through data interaction with the database. The firmware information is then distributed to business PAD / VTM terminals via the network. Finally, the hardware device is upgraded via Bluetooth transmission (supplemented by a backup network download channel), forming a closed-loop link from policy decision-making to terminal execution. While maintaining security and controllability, Bluetooth wireless transmission eliminates the traditional, cumbersome wired update method, improving efficiency and user experience.

[0087] Step S20, obtaining the corresponding firmware file from the cloud server according to the device identification information;

[0088] It should be noted that a cloud server is a remote server system built by enterprises or developers to centrally store and manage the firmware resources of various Bluetooth devices. It has features such as large storage capacity and high concurrency processing. It can provide firmware download services based on client requests and also supports firmware file version management and access control.

[0089] After obtaining the device identification information, the Exhibition PAD establishes a TCP / IP connection with the cloud server via a network communication module (such as a 4G / 5G network or Wi-Fi). Then, according to the established communication protocol and data format, the device identification information is sent as a parameter to the cloud server, requesting the firmware file that matches the device. After receiving the request, the cloud server uses its internal query algorithm and matching rules to locate and extract the firmware file that matches the device identification information from the numerous stored firmware file libraries, and then transmits the file to the Exhibition PAD.

[0090] In a feasible implementation, step S20 may include steps A11 to A15:

[0091] Step A11: Parsing the structured region code in the device identification information, wherein the region code includes multiple levels of administrative hierarchy identification;

[0092] It should be noted that the parsing process is to decompose and convert the area code field in the device identification information through a specific code parsing algorithm to extract the multi-level administrative area information contained therein.

[0093] A structured region code is a code within device identification information that is organized according to certain rules and formats and can represent the geographical region to which the device belongs. For example, the code may be a combination of country codes, provincial codes, city codes, and district / county codes, arranged in that order.

[0094] The multi-level administrative hierarchy identifier represents the regional codes of different administrative levels, such as the country, province, city, district, and county where the device is located. These codes comply with the national or regional administrative division coding standards and are used to accurately locate the geographical location of the device.

[0095] Step A12: Perform multi-level matching query in the policy database according to the administrative level identifier;

[0096] It should be noted that the policy library is a database of firmware distribution policies stored in the cloud server. It defines the firmware distribution rules and policy sets for different regions, different device types, different business requirements, etc.

[0097] Multi-level matching queries search the policy library sequentially based on the device's administrative hierarchy, from highest to lowest (e.g., from national to county). First, the policy library searches for a corresponding national distribution policy based on the country code. Then, the policy library searches for a provincial policy based on the province code. This process continues until the lowest county-level policy is found, ultimately determining the firmware distribution policy applicable to the device's region.

[0098] Step A13: When the global distribution policy is matched, obtain the standard version firmware address and download it;

[0099] It should be noted that the global distribution policy is a general distribution policy applicable to all regions and device types. When no special distribution policy is defined for the region where the device is located, this policy is used as the default policy.

[0100] The standard version firmware address is the storage path or network address of the standard version firmware file stored on the cloud server. Standard version firmware is a verified, universal firmware version suitable for most scenarios.

[0101] After receiving the standard version firmware address returned by the cloud server, the business PAD initiates a download request to the address through the network communication module, and downloads the firmware file from the cloud server to the local storage area according to HTTP or other file transfer protocols.

[0102] Step A14: When a region-specific policy is matched, obtain the customized firmware address bound to the policy;

[0103] It should be noted that a region-specific policy is a personalized firmware distribution policy developed for a specific administrative region to meet the region's special business needs, policies and regulations, or network environment requirements.

[0104] The customized firmware address is the network address of the customized firmware file stored on a cloud server, associated with a region-specific policy. Customized firmware is a modified version of the standard firmware that adds or removes features, adjusts parameters, or enhances security based on the needs of a specific region.

[0105] Step A15: When multiple levels of policies are matched simultaneously, the download address is selected according to the rule that the region-specific policy takes precedence over the global distribution policy.

[0106] It should be noted that when a device complies with multiple distribution policies at different levels (such as both a global policy and a region-specific policy), the customized firmware address corresponding to the region-specific policy will be prioritized for firmware download. This is because the region-specific policy is more closely aligned with the actual usage environment and business requirements of the specific region where the device is located, and can better ensure the applicability and performance of the firmware after the upgrade.

[0107] Furthermore, after step 15, the following steps may be performed: collecting device operating environment parameters, including the current network type (such as 4G / 5G / Wi-Fi and its signal strength), electromagnetic interference detection value (obtained through the device's built-in electromagnetic sensor), and power status (battery percentage, whether it is charging). This serves as the basis for subsequent firmware version adaptation, ensuring that the most appropriate firmware version is provided for the device in different operating environments, improving the stability and success rate of firmware upgrades, and enhancing the user experience.

[0108] Step S30, generating an asymmetric encryption key and sending it to the Bluetooth device, and receiving a device public key returned by the Bluetooth device based on the asymmetric encryption key;

[0109] It's important to note that an asymmetric encryption key is a pair of keys, consisting of a public key and a private key, generated using an asymmetric encryption algorithm (such as RSA or ECC). The public key can be publicly distributed, while the private key is kept strictly confidential by the generator. Asymmetric encryption algorithms have the characteristic that data encrypted with the public key can only be decrypted with the corresponding private key, and vice versa.

[0110] The encryption module built into the business PAD calls the asymmetric encryption algorithm library to generate a unique asymmetric encryption key pair (public key and private key) according to the parameters and processes specified by the algorithm, and saves the private key.

[0111] The business PAD sends the generated public key part to the Bluetooth device to be upgraded through the established Bluetooth communication link in accordance with the data format and transmission rules specified by the Bluetooth protocol.

[0112] After the Bluetooth device receives the public key sent by the exhibition PAD, it uses its own built-in encryption module and key generation algorithm (also based on an asymmetric encryption system) and combines it with the public key received from the exhibition PAD to generate the device public key corresponding to the Bluetooth device, and sends the device public key back to the exhibition PAD in accordance with the Bluetooth protocol specification.

[0113] Step S40: Generate a session key based on the device public key, and establish an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth device based on the session key;

[0114] It's important to note that a session key is a symmetric encryption key used during a communication session to encrypt and decrypt data transmitted during that session. Compared to asymmetric encryption keys, session keys are typically shorter and faster, making them suitable for encrypting large amounts of data.

[0115] After receiving the device public key returned by the Bluetooth device, the business PAD uses the device public key and its previously generated asymmetric encryption private key (as well as other negotiation parameters that may be involved) to calculate and generate a unique session key through the key negotiation algorithm.

[0116] The business PAD and Bluetooth device each use the generated session key to encrypt data transmitted over the Bluetooth communication link. On the data sending end, the original data is encrypted using the session key before being sent over the Bluetooth link. On the data receiving end, upon receiving the encrypted data, the same session key is used to decrypt it and restore the original data content, thus establishing a secure encrypted Bluetooth communication link.

[0117] Step S50: transmitting the firmware file to the Bluetooth device via the encrypted Bluetooth communication link to perform an upgrade operation.

[0118] It should be noted that the Zhanye PAD transmits the complete and accurate firmware file previously obtained from the cloud server to the Bluetooth device via an established encrypted Bluetooth communication link. After receiving the firmware file, the Bluetooth device follows the instructions of the firmware upgrade program to store, verify, and flash the firmware, completing the device firmware upgrade process and enabling updated and optimized device functions.

[0119] In a feasible implementation, step S50 may include steps A21 to A23:

[0120] Step A21: dividing the firmware file into a preset number of data blocks;

[0121] It should be noted that an appropriate number of data blocks is pre-set based on the Bluetooth device's data processing capabilities and the transmission characteristics of the communication link. The firmware file is then divided equally or according to a specific rule into multiple data blocks of appropriate size to facilitate subsequent transmission and verification operations. Each data block has a clear sequence number and identifier to ensure transmission order and integrity.

[0122] Step A22: transmitting each data block in sequence to the Bluetooth device via the encrypted Bluetooth communication link, so that the Bluetooth device performs a cyclic redundancy check on each data block to obtain a check result;

[0123] It should be noted that the sequential transmission of each data block means that the business PAD sends each data block one by one to the Bluetooth device through the encrypted Bluetooth communication link according to the sequence number of the data block. During the transmission process, each data block is attached with corresponding transmission control information, such as sequence number, length, checksum, etc.

[0124] Cyclic Redundancy Check (CRC) is a checksum algorithm used by Bluetooth devices to verify each data block after it receives it. The CRC algorithm calculates a checksum based on the contents of the data block and compares it with the checksum carried in the data block. If the two match, the data block is considered to have been transmitted correctly; otherwise, a transmission error has occurred.

[0125] Furthermore, step A22 includes:

[0126] Defining a transmission window based on the transmission period of a data block;

[0127] Monitor the packet loss rate of each transmission window;

[0128] When the packet loss rate of multiple consecutive transmission windows exceeds a preset threshold, a channel switching operation is performed: available channels are scanned and a channel with lower interference intensity is switched to establish a connection;

[0129] When the response delay does not meet the stability condition after the channel switching, the transmission of the data block is suspended.

[0130] It should be noted that the transmission window is defined based on the transmission period of the data block, that is, a transmission cycle time is determined according to the transmission rate of the data block and the characteristics of the Bluetooth link. Within each transmission cycle, a transmission window is defined, which stipulates the number of data blocks or the upper limit of data volume that can be transmitted within a certain period of time.

[0131] At the end of each transmission window, the difference between the number of data blocks actually successfully transmitted and the number of data blocks that should have been transmitted is counted to calculate the packet loss rate. The packet loss rate is calculated as follows: Packet loss rate = (number of data blocks that should have been transmitted - number of data blocks successfully received) / number of data blocks that should have been transmitted × 100%.

[0132] When the packet loss rate of multiple consecutive transmission windows exceeds a preset threshold, a channel switching operation is performed to scan available channels. The steps of switching to a channel with lower interference intensity to establish a connection include pre-setting a reasonable packet loss rate threshold (such as 10%). When the packet loss rate of multiple consecutive transmission windows (such as 3) exceeds the threshold, it is determined that the current Bluetooth channel is severely interfered with. At this time, the Bluetooth device starts the channel scanning function, detects the available Bluetooth channels around it, and evaluates the interference intensity of each channel (such as through parameters such as signal strength indication and noise level). Then, the channel with the lowest interference intensity is selected, and negotiates with the business PAD to switch to this channel to re-establish the connection to improve the transmission quality.

[0133] After the channel switch is complete, the new channel response delay is measured by sending test packets or monitoring the link response time. If the response delay exceeds the preset stability condition (for example, the delay is greater than 100 milliseconds), the channel condition is considered to be unstable. To ensure the reliability and accuracy of data transmission, the transmission of subsequent data blocks is suspended until the channel conditions improve or other measures are taken before resuming transmission.

[0134] Step A23: When all data blocks have passed verification, it is determined that the firmware file transfer is completed.

[0135] It should be noted that the Bluetooth device performs a cyclic redundancy check on each received data block. If the check results for all data blocks indicate that the transmission is correct, the entire firmware file is considered to have been completely and accurately transmitted to the device. At this point, the Bluetooth device sends a transmission completion confirmation message to the Exhibition PAD, and both parties terminate the data transmission process and prepare to enter the subsequent stages of the firmware upgrade, such as firmware storage, verification, and flashing.

[0136] Furthermore, step A23 may include:

[0137] The Zhanye PAD sends a firmware file hash value query request to the cloud server. The cloud server retrieves the firmware file's hash value record from the blockchain and returns it to the Zhanye PAD. The Zhanye PAD performs a hash calculation on the complete firmware file received locally and compares the calculation result with the blockchain hash value obtained from the cloud for verification. If the two are consistent, verification passes and subsequent upgrade operations are performed. If they are inconsistent, an alarm is triggered, the upgrade is rejected, and the verification failure information is reported to the cloud server. A detailed verification failure log is also recorded, including the time, device information, and hash value comparison results, to facilitate subsequent troubleshooting, ensure the integrity and authenticity of the firmware file, prevent firmware tampering, and improve the security of firmware upgrades.

[0138] It's important to note that to improve system operation and maintenance efficiency, a comprehensive set of logging and error code specifications has been developed. This ensures that every possible abnormality encountered during the upgrade process is thoroughly recorded, providing accurate clues for troubleshooting. Using session identifiers (SessionId), hardware call requests are chained layer by layer, improving maintainability.

[0139] This solution's convenient wireless upgrade strategy, while maintaining security and controllability, eliminates the traditional, cumbersome wired update method through network and Bluetooth wireless transmission, improving the user experience. Access control, firmware security detection, file tamper-proof monitoring, and Bluetooth encrypted transmission ensure the security of firmware files during download, storage, and Bluetooth transmission. This solution simplifies firmware upgrades, allowing users to simply connect a Bluetooth device, automatically match the firmware version, and click to upgrade. Subsequent steps are automatically handled by the system, reducing operational difficulty and improving upgrade efficiency. The client's near-real-time log collection strategy enables full-link monitoring of firmware upgrades, making it easier to troubleshoot and locate any subsequent upgrade errors.

[0140] This embodiment provides a method for wirelessly upgrading Bluetooth device firmware, which includes obtaining device identification information of the Bluetooth device to be upgraded; obtaining the corresponding firmware file from a cloud server based on the device identification information; generating an asymmetric encryption key and sending it to the Bluetooth device, and receiving the device public key returned by the Bluetooth device based on the asymmetric encryption key; generating a session key based on the device public key, and establishing an encrypted Bluetooth communication link between a mobile service terminal and the Bluetooth device based on the session key; transmitting the firmware file to the Bluetooth device via the encrypted Bluetooth communication link to perform the upgrade operation, deploying the firmware file on a cloud service, connecting the terminal to the Bluetooth device via Bluetooth, and obtaining the corresponding firmware version file based on the device type. Various security technologies are used to ensure the security of the firmware during wireless transmission. This method simplifies the upgrade operation, reduces operational difficulty, and improves upgrade efficiency.

[0141] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 5 After step S20, steps S201 to S204 are included:

[0142] Step S201: Generate a dynamic access token based on the device identification information to perform authorization authentication and obtain an authorization authentication result;

[0143] It's important to note that device identification information is the unique identifier of a Bluetooth device and contains various key device information. A dynamic access token is an authentication credential with dynamic elements such as a timestamp and random number. It's generated based on the device identification information and effectively prevents access requests from unauthorized devices. By matching the device identification information with pre-set authentication rules, the system authenticates the device requesting access and ultimately determines whether the device is authorized to access the firmware file, ensuring that only authorized devices can access the subsequent firmware file acquisition process.

[0144] Step S202: When the authority authentication result is authentication passed, determine the hash value of the firmware file;

[0145] It's important to note that a hash value is a unique and irreversible summary value calculated using a specific algorithm. Once the device passes authentication, the system performs a hash operation on the firmware file to obtain its hash value, which is then compared against a pre-stored baseline hash value in the cloud. This ensures the integrity and authenticity of the firmware file and prevents tampering during transmission or storage.

[0146] Step S203: Compare the hash value with the pre-stored reference value in the cloud to obtain a comparison result;

[0147] It should be noted that the pre-stored cloud-based benchmark value refers to the hash value pre-calculated and stored when the firmware file is uploaded to the cloud. The locally calculated hash value of the firmware file is compared bit by bit with the cloud-based benchmark hash value. If the two match, the firmware file has not been tampered with, and its integrity and authenticity are verified. Otherwise, the file may have been damaged or maliciously tampered with during transmission or storage, and the comparison result will fail.

[0148] Step S204: When the comparison result is passed, it is determined that the firmware file passes the integrity check.

[0149] It should be noted that when the local hash value matches the cloud-based benchmark hash value, the integrity and authenticity of the firmware file are confirmed, and the firmware file is determined to have passed the integrity check. This provides a reliable foundation for subsequent firmware upgrade operations, ensuring that the firmware file used for the upgrade is accurate.

[0150] In a feasible implementation manner, step S204 may include steps A31 to A32:

[0151] Step A31: starting a file monitoring module locally on the mobile terminal to continuously monitor the access process of the firmware file;

[0152] It should be noted that the file monitoring module is a program component running locally on the mobile terminal. Its function is to monitor access to firmware files in real time. This module tracks and records all processes attempting to access firmware files, including state changes such as process start, run, and stop, as well as operations such as reading and writing firmware files, to promptly detect potential abnormal access behavior.

[0153] Step A32: extracting the digital signature information of the access process, and comparing the digital signature information with the preset authorization whitelist to generate a process authorization verification result;

[0154] It's important to note that a digital signature is an electronic signature generated by encrypting data with a private key. It identifies the signatory and their approval of the data content. Each access process has a corresponding digital signature. The system extracts this information and compares it with a pre-set authorization whitelist. This pre-set authorization whitelist contains the digital signatures of all processes permitted to access firmware files. This comparison determines whether the accessing process is legitimately authorized and generates a corresponding process authorization verification result, which determines whether the process is authorized to access the firmware files.

[0155] Step A33: When the process authorization verification result is unauthorized access, output a tampering monitoring alarm signal;

[0156] It should be noted that if the process authorization check result shows that the access process is unauthorized, it indicates that an illegal process is attempting to access the firmware file, which may mean that the firmware file is at risk of tampering. In this case, the system will immediately output a tampering detection alarm signal to remind relevant personnel to take timely measures to prevent illegal tampering of the firmware file and ensure the security of the firmware upgrade.

[0157] Step A34: Based on the tampering monitoring alarm signal, the firmware file is deleted and the security alarm log is updated, wherein the log includes the ID of the unauthorized process, the access timestamp and the operation type.

[0158] It should be noted that upon receiving a tampering detection alarm signal, the system will quickly delete the firmware file at risk of tampering, preventing further operation of the file by illegal processes and eliminating security risks at the source. At the same time, the system will update the security alarm log, recording in detail the unauthorized process ID (used to uniquely identify the illegal process), the access timestamp (recording the specific time when the illegal access occurred), and the operation type (such as illegal read, write, etc.). This information facilitates subsequent security analysis and tracing, providing a strong basis for finding and addressing security threats.

[0159] Furthermore, after the step of comparing the digital signature information with the preset authorization whitelist to generate a process authorization verification result, the method further includes:

[0160] When the process authorization verification result fails, the memory write operation frequency of the firmware file access process and the sensitive application programming interface call sequence are continuously collected;

[0161] Determine a behavioral risk index based on the frequency of memory write operations and sensitive application programming interface call sequences;

[0162] When the behavior risk index exceeds the dynamic threshold, the firmware file access process is stopped and a process memory snapshot is generated;

[0163] Extract high-risk feature data based on memory snapshots;

[0164] Upload high-risk feature data and corresponding behavior pattern hash values ​​to the cloud threat intelligence library to trigger the synchronous update of the preset authorization whitelist policy.

[0165] It should be noted that when a process fails authorization verification, the memory write frequency and sensitive application programming interface call sequence of the process accessing firmware files are continuously collected. The memory write frequency reflects the speed and frequency of memory writes by the process, which may indicate an intent to tamper with firmware file-related data. The sensitive application programming interface call sequence records which sensitive APIs, such as file operation APIs and encryption and decryption APIs, are called by the process during execution, potentially impacting system security and firmware files. This information helps analyze process behavior patterns and potential risks.

[0166] Determines a behavioral risk index based on the frequency of memory write operations and the sequence of sensitive application programming interface calls. Using a pre-defined algorithm and risk assessment model, this algorithm comprehensively considers the degree of abnormality in the frequency of memory write operations and the riskiness of sensitive API calls, calculating a quantitative behavioral risk index to measure the potential threat posed by the access process to firmware file security.

[0167] When the behavioral risk index exceeds the dynamic threshold, the process accessing the firmware file is stopped and a process memory snapshot is generated. The dynamic threshold is a risk assessment criterion that is dynamically adjusted based on the system's real-time security status and historical data. When the behavioral risk index exceeds this threshold, it indicates that the process's abnormal behavior has reached a level that could pose a serious threat to the firmware file. At this point, the system immediately stops the access process to prevent it from further potentially damaging operations on the firmware file. It also generates a process memory snapshot, recording the process's memory state at the time of the stop, including information such as the data in memory and the location of the instruction pointer, providing detailed on-site data for subsequent analysis.

[0168] Extract high-risk signature data based on memory snapshots. Through in-depth analysis of memory snapshots, high-risk signature data is extracted, such as abnormal code snippets, tampered file content, malicious configuration parameters, etc. These high-risk signature data are key evidence for identifying and analyzing security threats.

[0169] Uploading high-risk signature data and corresponding behavioral pattern hash values ​​to the cloud-based threat intelligence library triggers a synchronous update of the pre-set authorization whitelist policy. The cloud-based threat intelligence library is a platform for centralized storage and analysis of security threat information. Uploading extracted high-risk signature data and behavioral pattern hash values ​​to the library enriches cloud-based security threat intelligence and triggers a synchronous update of the pre-set authorization whitelist policy. Based on the uploaded high-risk signature information, the cloud updates the authorization whitelist policy and adds processes or behaviors with similar risk characteristics to a prohibited access list, thereby improving the security protection capabilities of the entire system and preventing similar security threats from recurring.

[0170] This embodiment provides a method for wirelessly updating Bluetooth device firmware. It uses dynamic access tokens for permission authentication, ensuring that only authorized devices can access firmware files and preventing malicious access by unauthorized devices. Furthermore, through hash value integrity verification and comparison of digital signature information with an authorized whitelist, it accurately detects whether the firmware file has been tampered with and the legitimacy of the access process. This effectively prevents malicious tampering and unauthorized access, ensures the security and integrity of firmware files during transmission and storage, and reduces security risks.

[0171] It should be noted that the above examples are only used to understand this application and do not constitute a limitation on the method for wirelessly upgrading Bluetooth device firmware in this application. More simple transformations based on this technical concept are all within the scope of protection of this application.

[0172] This application also provides a Bluetooth device firmware wireless upgrade device, please refer to Figure 6 , the Bluetooth device firmware wireless upgrade device includes:

[0173] An information acquisition module 10 is used to obtain device identification information of the Bluetooth device to be upgraded;

[0174] The firmware download module 20 is used to obtain the corresponding firmware file from the cloud server according to the device identification information;

[0175] The link establishment module 30 is configured to generate an asymmetric encryption key and send it to the Bluetooth device, and receive a device public key returned by the Bluetooth device based on the asymmetric encryption key; generate a session key based on the device public key, and establish an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth device based on the session key;

[0176] The transmission module 40 is configured to transmit the firmware file to the Bluetooth device via an encrypted Bluetooth communication link to perform an upgrade operation.

[0177] The Bluetooth device firmware wireless upgrade device provided in this application utilizes the Bluetooth device firmware wireless upgrade method described in the aforementioned embodiments, thereby resolving the technical issues of poor security and low efficiency faced by Bluetooth devices during firmware upgrades. Compared to the prior art, the Bluetooth device firmware wireless upgrade device provided in this application achieves the same beneficial effects as the Bluetooth device firmware wireless upgrade method described in the aforementioned embodiments. Other technical features of the Bluetooth device firmware wireless upgrade device are the same as those disclosed in the aforementioned embodiments and are not further detailed here.

[0178] In one embodiment, the transmission module 40 is further configured to divide the firmware file into a preset number of data blocks;

[0179] Transmitting each data block to the Bluetooth device in sequence via an encrypted Bluetooth communication link, so that the Bluetooth device performs a cyclic redundancy check on each data block to obtain a check result;

[0180] When all data blocks are verified to be passed, the firmware file transfer is determined to be complete.

[0181] In one embodiment, the transmission module 40 is further configured to define a transmission window based on a transmission period of a data block;

[0182] Monitor the packet loss rate of each transmission window;

[0183] When the packet loss rate of multiple consecutive transmission windows exceeds a preset threshold, a channel switching operation is performed: available channels are scanned and a channel with lower interference intensity is switched to establish a connection;

[0184] When the response delay does not meet the stability condition after the channel switching, the transmission of the data block is suspended.

[0185] In one embodiment, the firmware download module 20 is further configured to parse the structured region code in the device identification information, wherein the region code includes multiple levels of administrative hierarchy identification;

[0186] Perform multi-level matching queries in the policy database based on administrative level identification;

[0187] When the global distribution policy is matched, the standard version firmware address is obtained and downloaded;

[0188] When a region-specific policy is matched, obtain the customized firmware address bound to the policy;

[0189] When multiple levels of policies are matched simultaneously, the download address is selected based on the rule that the region-specific policy takes precedence over the global distribution policy.

[0190] In one embodiment, the firmware download module 20 is further configured to generate a dynamic access token based on the device identification information to perform authorization authentication and obtain an authorization authentication result;

[0191] When the authority authentication result is authentication passed, determining the hash value of the firmware file;

[0192] Compare the hash value with the pre-stored benchmark value in the cloud to obtain the comparison result;

[0193] When the comparison result is passed, it is determined that the firmware file passes the integrity check.

[0194] In one embodiment, the firmware download module 20 is further configured to start a file monitoring module to continuously monitor the access process of the firmware file;

[0195] Extract the digital signature information of the access process and compare the digital signature information with the preset authorization whitelist to generate the process authorization verification result;

[0196] When the process authorization verification result is unauthorized access, a tampering monitoring alarm signal is output;

[0197] Based on the tamper detection alarm signal, the firmware file is deleted and the security alarm log is updated. The log contains the ID of the unauthorized process, the access timestamp and the operation type.

[0198] In one embodiment, the firmware download module 20 is further configured to continuously collect the memory write operation frequency and sensitive application programming interface call sequence of the firmware file access process when the process authorization check result is failed;

[0199] Determine a behavioral risk index based on the frequency of memory write operations and sensitive application programming interface call sequences;

[0200] When the behavior risk index exceeds the dynamic threshold, the firmware file access process is stopped and a process memory snapshot is generated;

[0201] Extract high-risk feature data based on memory snapshots;

[0202] Upload high-risk feature data and corresponding behavior pattern hash values ​​to the cloud threat intelligence library to trigger the synchronous update of the preset authorization whitelist policy.

[0203] The present application provides a Bluetooth device firmware wireless upgrade device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the Bluetooth device firmware wireless upgrade method in the above-mentioned embodiment 1.

[0204] Reference below Figure 7 , which shows a schematic diagram of the structure of a Bluetooth device firmware wireless upgrade device suitable for implementing the embodiments of the present application. The Bluetooth device firmware wireless upgrade device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The Bluetooth device firmware wireless upgrade device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0205] like Figure 7As shown, the Bluetooth device firmware wireless upgrade device may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. Various programs and data required for the operation of the Bluetooth device firmware wireless upgrade device are also stored in RAM 1004. The processing device 1001, ROM 1002, and RAM 1004 are connected to each other via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the Bluetooth device firmware wireless upgrade device to communicate with other devices wirelessly or by wire to exchange data. Although the figure shows a Bluetooth device firmware wireless upgrade device with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems may be implemented or have instead.

[0206] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.

[0207] The Bluetooth device firmware wireless upgrade device provided in this application utilizes the Bluetooth device firmware wireless upgrade method described in the aforementioned embodiment, thereby resolving the technical issues of poor security and low efficiency faced by Bluetooth devices during firmware upgrades. Compared to the prior art, the Bluetooth device firmware wireless upgrade device provided in this application achieves the same beneficial effects as the Bluetooth device firmware wireless upgrade method described in the aforementioned embodiment. Other technical features of the Bluetooth device firmware wireless upgrade device are the same as those disclosed in the aforementioned embodiment and are not further detailed here.

[0208] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0209] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0210] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, a computer program) stored thereon, wherein the computer-readable program instructions are used to execute the method for wirelessly upgrading firmware of a Bluetooth device in the above-mentioned embodiment.

[0211] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0212] The computer-readable storage medium may be included in the Bluetooth device firmware wireless upgrade device; or may exist independently without being assembled into the Bluetooth device firmware wireless upgrade device.

[0213] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the Bluetooth device firmware wireless upgrade device, it enables: obtaining the device identification information of the Bluetooth device to be upgraded; obtaining the corresponding firmware file from the cloud server based on the device identification information; generating an asymmetric encryption key and sending it to the Bluetooth device and receiving the device public key returned by the Bluetooth device based on the asymmetric encryption key; generating a session key based on the device public key, and establishing an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth device based on the session key; transmitting the firmware file to the Bluetooth device through the encrypted Bluetooth communication link to perform the upgrade operation.

[0214] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0215] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0216] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.

[0217] The computer-readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned method for wirelessly updating Bluetooth device firmware. This computer-readable storage medium can address the technical issues of poor security and low efficiency faced by Bluetooth devices during firmware updates. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the method for wirelessly updating Bluetooth device firmware provided in the aforementioned embodiments, and are not further elaborated here.

[0218] The present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned method for wirelessly upgrading Bluetooth device firmware when executed by a processor.

[0219] The computer program product provided in this application can address the technical issues of poor security and low efficiency faced by Bluetooth devices during firmware upgrades. Compared to the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the Bluetooth device wireless firmware upgrade method provided in the aforementioned embodiment, and are not further elaborated here.

[0220] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.

Claims

1. A method for wirelessly upgrading firmware of a Bluetooth device, characterized in that: The method for wirelessly upgrading Bluetooth device firmware includes: Get the device identification information of the Bluetooth device to be upgraded; Obtaining the corresponding firmware file from the cloud server according to the device identification information; Generate an asymmetric encryption key and send it to the Bluetooth device, and receive a device public key returned by the Bluetooth device based on the asymmetric encryption key; generating a session key based on the device public key, and establishing an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth device based on the session key; The firmware file is transmitted to the Bluetooth device via the encrypted Bluetooth communication link to perform an upgrade operation.

2. The method for wirelessly upgrading Bluetooth device firmware according to claim 1, wherein: The step of transmitting the firmware file to the Bluetooth device through the encrypted Bluetooth communication link comprises: Splitting the firmware file into a preset number of data blocks; transmitting each of the data blocks to the Bluetooth device in sequence via the encrypted Bluetooth communication link, so that the Bluetooth device performs a cyclic redundancy check on each data block to obtain a check result; When all data blocks have passed verification, it is determined that the firmware file transfer is completed.

3. The method for wirelessly upgrading Bluetooth device firmware according to claim 2, wherein: The step of sequentially transmitting each of the data blocks to the Bluetooth device via the encrypted Bluetooth communication link comprises: defining a transmission window based on a transmission period of the data block; monitoring a packet loss rate of each of the transmission windows; When the packet loss rate of a plurality of consecutive transmission windows exceeds a preset threshold, performing a channel switching operation: scanning available channels and switching to a channel with lower interference intensity to establish a connection; When the response delay after the channel switching does not meet the stability condition, the transmission of the data block is suspended.

4. The method for wirelessly upgrading Bluetooth device firmware according to claim 1, wherein: The step of obtaining the corresponding firmware file from the cloud server according to the device identification information includes: Parsing the structured region code in the device identification information, wherein the region code includes multiple levels of administrative hierarchy identification; Performing a multi-level matching query in a policy library according to the administrative level identifier; When the global distribution policy is matched, the standard version firmware address is obtained and downloaded; When a region-specific policy is matched, obtain the customized firmware address bound to the policy; When multiple levels of policies are matched simultaneously, the download address is selected based on the rule that the region-specific policy takes precedence over the global distribution policy.

5. The method for wirelessly upgrading Bluetooth device firmware according to claim 1, wherein: After the step of obtaining the corresponding firmware file from the cloud server according to the device identification information, the method further includes: Generate a dynamic access token based on the device identification information to perform authority authentication and obtain an authority authentication result; When the authority authentication result is authentication passed, determining a hash value of the firmware file; Compare the hash value with the pre-stored reference value in the cloud to obtain a comparison result; When the comparison result is that the comparison passes, it is determined that the firmware file passes the integrity check.

6. The method for wirelessly upgrading Bluetooth device firmware according to claim 5, wherein: The method further comprises: Starting a file monitoring module to continuously monitor the access process of the firmware file; Extracting the digital signature information of the access process, and comparing the digital signature information with a preset authorization whitelist to generate a process authorization verification result; When the process authorization verification result is unauthorized access, outputting a tampering monitoring alarm signal; Based on the tampering monitoring alarm signal, the firmware file is deleted and a security alarm log is updated, wherein the log includes an ID of the unauthorized process, an access timestamp, and an operation type.

7. The method for wirelessly upgrading Bluetooth device firmware according to claim 6, wherein: After the step of comparing the digital signature information with the preset authorization whitelist to generate a process authorization verification result, the method further includes: When the process authorization check result is failed, continuously collecting the memory write operation frequency and sensitive application programming interface call sequence of the access process of the firmware file; determining a behavior risk index based on the memory write operation frequency and the sensitive application programming interface call sequence; When the behavior risk index exceeds a dynamic threshold, stopping the access process of the firmware file and generating a process memory snapshot; extracting high-risk feature data based on the memory snapshot; Uploading the high-risk feature data and the corresponding behavior pattern hash value to the cloud threat intelligence library triggers the synchronous update of the preset authorization whitelist policy.

8. A Bluetooth device firmware wireless upgrade device, characterized in that: The device comprises: An information acquisition module is used to obtain device identification information of the Bluetooth device to be upgraded; A firmware download module, configured to obtain the corresponding firmware file from the cloud server according to the device identification information; A link building module, configured to perform an asymmetric encryption public key exchange with the Bluetooth device; generate a session key based on the asymmetric encryption public key, and establish an encrypted Bluetooth communication link between the mobile service terminal and the Bluetooth device based on the session key; A transmission module is used to transmit the firmware file to the Bluetooth device through the encrypted Bluetooth communication link to perform an upgrade operation.

9. A Bluetooth device firmware wireless upgrade device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the method for wirelessly upgrading firmware of a Bluetooth device according to any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the method for wirelessly upgrading Bluetooth device firmware according to any one of claims 1 to 7 are implemented.