Television starting method, device and equipment based on national cryptographic algorithm and storage medium

By using the SM2 national cryptographic algorithm to generate and verify dynamic signature files in smart TVs, security vulnerabilities in the secure startup and upgrade process of smart TVs are resolved, enabling secure startup and upgrades based on the national cryptographic algorithm and ensuring the security and controllability of the device.

CN121690584APending Publication Date: 2026-03-17SHENZHEN COOCAA NETWORK TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511532115.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing smart TVs have security vulnerabilities during secure startup and upgrade processes, making them susceptible to malicious attacks, and lack a controllable secure startup and upgrade mechanism.

Method used

The SM2 national cryptographic algorithm is used to generate a dynamic signature file, which is stored in the device's trusted execution environment and verified before startup and software upgrades to ensure the uniqueness and timeliness of the device identifier and timestamp, and to prevent malicious operations.

Benefits of technology

It enables secure booting and upgrading of smart TVs, replacing the Android RSA certificate trust system with a national cryptographic certificate trust system, ensuring the security of the device boot process and the reliability of software upgrades, and preventing the installation of malicious software and unauthorized code execution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690584A_ABST
    Figure CN121690584A_ABST
Patent Text Reader

Abstract

The invention relates to a television starting method and device based on a cryptographic algorithm, equipment and a storage medium. The method comprises the following steps: when the television equipment is powered on, collecting an equipment identifier and a running timestamp of the television equipment, generating a dynamic signature file by utilizing an SM2 algorithm based on the equipment identifier and the running timestamp, storing the dynamic signature file in an equipment trusted execution environment, and verifying the dynamic signature file before an operating system of the television equipment is started, and if the verification is passed, starting an operating system, verifying the to-be-upgraded software package before software upgrading of the television equipment, and if the verification is passed, carrying out software upgrading. According to the application, an Android RSA certificate trust system is replaced by a state secret certificate trust system, and signature and signature verification are carried out on core scenes such as smart television security startup, smart television OTA upgrade, smart television application trusted release, smart television application upgrade and the like, so that security startup and autonomous controllability of the smart television starting from a chip TEE trust root are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a television startup method, apparatus, device, and storage medium based on Chinese cryptographic algorithms. Background Technology

[0002] Currently, most TV manufacturers develop their systems based on the Android system, and the secure boot of TVs relies on international cryptographic algorithms, which may pose security vulnerabilities and make them susceptible to malicious attacks. For example, smart TVs may be infected with malware from unknown sources, leading to control of the voice assistant, or unsigned malware may be installed. Furthermore, digital TV service providers only develop apps or make minor modifications to the underlying system on top of Android, lacking a controllable secure boot and upgrade mechanism.

[0003] Therefore, how to improve the accuracy and personalization of recommendation results has become a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0004] In view of the above, this application provides a television startup method, apparatus, device and storage medium based on national cryptographic algorithms, the purpose of which is to solve the above-mentioned technical problems.

[0005] Firstly, this application provides a television startup method based on a national cryptographic algorithm, the method comprising:

[0006] When the television device is powered on, collect the device identifier and running timestamp of the television device;

[0007] Based on the device identifier and the runtime timestamp, a dynamic signature file is generated using the SM2 algorithm and stored in the device's trusted execution environment;

[0008] Before the operating system of the television device starts, the dynamic signature file is verified. If the verification passes, the operating system is started.

[0009] Before upgrading the software of the television device, the software package to be upgraded is verified. If the verification is successful, the software upgrade is performed. The software package to be upgraded is signed with the SM2 algorithm and bound to the device identifier.

[0010] Secondly, this application provides a television startup device based on Chinese national cryptographic algorithms, which includes:

[0011] Data Acquisition Module: Used to acquire the device identifier and running timestamp of the television device when it is powered on;

[0012] Generation module: used to generate a dynamic signature file based on the device identifier and the running timestamp using the SM2 algorithm and store it in the device's trusted execution environment;

[0013] Startup module: used to verify the dynamic signature file before the operating system of the TV device starts; if the verification is successful, the operating system is started.

[0014] Upgrade module: Used to verify the software package to be upgraded before the software upgrade of the TV device. If the verification is successful, the software upgrade is performed. The software package to be upgraded is signed with the SM2 algorithm and bound to the device identifier.

[0015] Thirdly, this application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0016] Memory, used to store computer programs;

[0017] When a processor executes a program stored in memory, it implements the steps of the television startup method based on the national cryptographic algorithm described in any embodiment of the first aspect.

[0018] Fourthly, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the television startup method based on the national cryptographic algorithm as described in any embodiment of the first aspect.

[0019] The technical solutions provided in this application have the following advantages compared with the prior art:

[0020] This application enables secure booting and upgrading of Android smart TVs based on the SM2 national cryptographic algorithm. It replaces the Android RSA certificate trust system with the national cryptographic certificate trust system, enabling signature and verification in core scenarios such as secure booting of smart TVs, OTA upgrades of smart TVs, trusted release of smart TV applications, and application upgrades of smart TVs. This allows for secure booting of smart TVs from the chip's TEE trust root and ensures autonomous control. Attached Figure Description

[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0022] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart illustrating a preferred embodiment of the television startup method based on the national cryptographic algorithm of this application;

[0024] Figure 2 This is a schematic diagram of a preferred embodiment of the television startup device based on the national cryptographic algorithm of this application;

[0025] Figure 3 This is a schematic diagram of a preferred embodiment of the electronic device of this application;

[0026] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without inventive effort are within the scope of protection of this application.

[0028] It should be noted that the use of terms such as "first" and "second" in this application is for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of those features. Furthermore, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, such a combination of technical solutions should be considered non-existent and not within the scope of protection claimed in this application.

[0029] Reference Figure 1 The diagram shown is a flowchart illustrating an embodiment of the television startup method based on Chinese cryptographic algorithms of this application. This method is executed by an electronic device, such as a television device, which can be implemented by a software system and / or a hardware system. The television startup method based on Chinese cryptographic algorithms includes:

[0030] Step S10: When the TV device is powered on, collect the device identifier and running timestamp of the TV device;

[0031] Step S20: Based on the device identifier and the running timestamp, generate a dynamic signature file using the SM2 algorithm and store it in the device's trusted execution environment;

[0032] Step S30: Before the operating system of the TV device starts, the dynamic signature file is verified. If the verification passes, the operating system is started.

[0033] Step S40: Before the software upgrade of the TV device, the software package to be upgraded is verified. If the verification is successful, the software upgrade is performed. The software package to be upgraded is signed with the SM2 algorithm and bound to the device identifier.

[0034] When the TV device powers on, the system collects the device's unique hardware identifier and current running timestamp. This is to generate a dynamic signature file closely related to the device's state, ensuring the signature's uniqueness and timeliness, and preventing attackers from using expired or generic signature files for malicious operations. Specifically, upon power-on, the system's underlying hardware triggers a power-on self-test (POST) program, waking up the secure boot module. The secure boot module calls the device's underlying firmware interface to collect the device's unique hardware identifier (such as the device serial number and CPUID). Simultaneously, it obtains the precise current running timestamp from the system's real-time clock or system startup timestamp generator. The collected device identifier and running timestamp are converted into a format suitable for SM2 algorithm processing (such as a byte stream or string). The SM2 signature function in the secure boot module is then called to sign the combined raw data, generating a signature value. A dynamic signature file is generated based on the signature value group and stored in the device's Trusted Execution Environment (TEE). The dynamic signature file is tightly bound to the TV device's state; any tampering with the device identifier or timestamp will cause signature verification to fail, ensuring the security of the device startup and software upgrade processes.

[0035] In smart TV devices, a Trusted Execution Environment (TEE) provides a secure and isolated execution space for storing sensitive data and performing critical security operations. Storing dynamic signature files in the TEE can prevent the signature files from being tampered with or stolen, ensuring the integrity and confidentiality of the signature files.

[0036] During the television equipment production stage, a Trusted Execution Environment (TEE) is pre-configured, and keys and certificates related to the SM2 algorithm are set up. When a dynamic signature file needs to be generated, the security service in the TEE is called, and the signature value is used as input. The TEE performs integrity verification and format verification on the input data to ensure that the data meets the requirements. The verified data is converted into the internal storage format of the TEE and a unique storage identifier is generated to store the dynamic signature file in the dedicated secure storage area of ​​the TEE.

[0037] Verifying the integrity and validity of the dynamic signature file during the TV device startup process ensures the security of the startup process. If the signature file is tampered with or invalidated, the device will refuse to boot, preventing the execution of malware or unauthorized code. During device startup, the underlying system firmware calls the secure boot module. This module reads the dynamic signature file from the trusted execution environment, extracts the signature value from the file, and verifies the signature value using the TV device's pre-installed SM2 public key. If the verification passes, the operating system is allowed to boot; otherwise, the startup process is terminated, and a security alarm is triggered. This ensures that only verified dynamic signature files allow the operating system to boot, preventing the execution of malware or unauthorized code.

[0038] Verifying the integrity and validity of the software package to be upgraded during device software upgrades ensures the security of the upgrade process, prevents malicious software or unauthorized packages from being installed on the device, and protects the device from security threats. Before releasing a software upgrade package, the manufacturer uses the SM2 algorithm to sign the package and binds the device identifier to the package; that is, the package to be upgraded is obtained by signing with the SM2 algorithm, and the package to be upgraded is bound to the device identifier. When the TV device detects a software upgrade, it downloads the package and its signature information from the upgrade server. The TV device calls the secure boot module to verify the signature of the package. If the verification passes, the software upgrade operation is allowed; otherwise, the upgrade process is terminated, and a security alarm is triggered. This ensures that only verified packages can be installed on the device, preventing the installation of malicious software or unauthorized packages.

[0039] This application enables secure booting and upgrading of Android smart TVs based on the SM2 national cryptographic algorithm. It replaces the Android RSA certificate trust system with the national cryptographic certificate trust system, enabling signature and verification in core scenarios such as secure booting of smart TVs, OTA upgrades of smart TVs, trusted release of smart TV applications, and application upgrades of smart TVs. This allows for secure booting of smart TVs from the chip's TEE trust root and ensures autonomous control.

[0040] In one embodiment, verifying the dynamic signature file includes:

[0041] The integrity of the dynamic signature file is verified;

[0042] If the integrity verification passes, verify whether the device status recorded in the dynamic signature file is consistent with the current status of the television device;

[0043] If they match, the dynamic signature file verification is successful.

[0044] Verifying the integrity of a dynamic signature file aims to ensure that the file has not been maliciously modified since its creation, guaranteeing that subsequent verification processes are conducted reliably and avoiding incorrect security judgments based on compromised files. For example, a hash value is calculated for the dynamic signature file during its generation and securely stored in a trusted execution environment. During verification, the hash value of the dynamic signature file is recalculated and compared with the hash value stored in the trusted execution environment. If they match, the integrity verification passes.

[0045] The dynamic signature file records the device's state at a specific moment (device identifier and runtime timestamp). Verifying its consistency with the current state of the television device ensures that the file is up-to-date and closely associated with the current device, preventing attackers from using outdated signature files or those associated with other devices for unauthorized operations. After the integrity verification passes, the recorded device identifier and runtime timestamp are extracted from the dynamic signature file. Simultaneously, the current device identifier (by calling the firmware interface) and the current runtime timestamp (from the real-time clock or system timestamp generator) are obtained from the device's underlying firmware, and these two are compared item by item. For example, the device identifier recorded in the dynamic signature file might be "N1234567890" and the runtime timestamp might be "2025-09-11 10:00:00.123456". The device identifier of the current device is also "N1234567890", and the current running timestamp is "2025-09-11 10:00:00.123457". Considering the possible slight error in the timestamp, within the allowable error range (such as 1 second), the device status is determined to be consistent, and the dynamic signature file verification is confirmed to be successful.

[0046] In one embodiment, the software package to be upgraded includes an application package or an OTA package, and the verification of the software package to be upgraded includes:

[0047] The integrity of the software package to be upgraded is verified, and the integrity verification result is obtained.

[0048] The signature information of the software package to be upgraded is verified to obtain the signature verification result;

[0049] Verify the binding relationship between the software package to be upgraded and the device identifier to obtain the binding verification result;

[0050] If the integrity verification result, the signature verification result, and the binding verification result all indicate that the verification is successful, then the software package to be upgraded is determined to have passed verification.

[0051] The main purpose of integrity verification is to ensure that the software package to be upgraded has not been tampered with or corrupted during download, transmission, or storage. During the package creation phase, the manufacturer uses a hash algorithm to calculate a hash value for the package and releases this hash value along with the package. On the television device, after downloading the upgrade package, the same hash algorithm is used to recalculate the hash value of the downloaded package. The recalculated hash value is then compared with the hash value released by the manufacturer. If they match, the integrity verification passes; otherwise, it fails.

[0052] The purpose of signature verification is to confirm the trustworthiness of the upgrade software package's origin. By verifying the signature information, it can be ensured that the package is released by a legitimate manufacturer, preventing malicious software or unauthorized packages from being installed on the TV device. When releasing the package, the manufacturer digitally signs the package using its own private key (a private key using the SM2 algorithm) and attaches the signature information to the package. The TV device obtains the manufacturer's public key (which can be obtained through pre-installed or secure channels) and uses this public key to verify the signature information of the upgrade software package. If the verification passes, the signature verification is successful; otherwise, the verification fails. Signature verification ensures the trustworthiness of the package's origin, preventing malicious software or unauthorized packages from being installed on the TV device, protecting device security and user interests.

[0053] The purpose of binding relationship verification is to ensure a unique correspondence between the upgrade software package and the television device. Verifying the binding relationship prevents the software package from being illegally transferred to other devices. When creating the software package, the manufacturer binds the device identifier (such as the device serial number, unique identification code, etc.) to the software package and signs it during the signing process. The television device verifies the signature information, parses the bound device identifier, and compares it with its own device identifier. If they match, the binding relationship verification passes; otherwise, the verification fails.

[0054] If the integrity verification result, signature verification result, and binding verification result all indicate that the verification is successful, then the upgrade package is deemed to have passed the verification. This comprehensive determination ensures that only rigorously verified packages can be installed and used, effectively preventing malware, unauthorized packages, and illegally transferred packages from entering the device, thus protecting device security and user interests.

[0055] Furthermore, the method also includes:

[0056] If any of the integrity verification result, the signature verification result, and the binding verification result fails, then the verification of the software package to be upgraded is determined to have failed.

[0057] If any of the integrity verification result, signature verification result, or binding verification result fails, it means that the security and reliability of the software package to be upgraded cannot be guaranteed, and therefore the upgrade process needs to be terminated.

[0058] In one embodiment, generating a dynamic signature file using the SM2 algorithm based on the device identifier and the runtime timestamp includes:

[0059] Combine the device identifier with the running timestamp to form a signature data block;

[0060] The signature value is obtained by signing the signed data block using the SM2 algorithm.

[0061] The device identifier, the runtime timestamp, and the signature value are encapsulated into a dynamic signature file.

[0062] Combining the device identifier and runtime timestamp into a signature data block aims to provide the signature file with uniqueness and timeliness. Specifically, the two can be concatenated into a string separated by a colon. For example, if the device identifier is SN1234567890 and the runtime timestamp is 2025-09-11 10:00:00.123456, the result would be SN1234567890:2025-09-11 10:00:00.123456. This combined data block completely preserves the device identifier and runtime timestamp information, avoids content obfuscation, and provides data in a suitable format for subsequent signature algorithm processing.

[0063] The SM2 algorithm is used to sign the combined signature data block to obtain a signature value. The reliability and security of the SM2 algorithm provide proof of the immutability of the signature data block. The signature value is stored in binary form and can be encoded and converted as needed, providing crucial security verification information for dynamic signature files.

[0064] Encapsulating the device identifier, runtime timestamp, and signature value into a dynamic signature file integrates all relevant information for easy storage and verification. A clearly marked format is used, such as device identifier: N1234567890, runtime timestamp: 2025-09-11 10:00:00.123456, and signature value: SIG_ABCDEF1234567890. Combining these three elements into the file content not only facilitates storage but also makes subsequent parsing and information extraction easier, ensuring the integrity and usability of the dynamic signature file and providing reliable verification for secure device startup and software upgrades.

[0065] In one embodiment, the method further includes:

[0066] If the dynamic signature file fails verification, the operating system will not be started.

[0067] If the software package to be upgraded fails verification, the software upgrade operation will be refused.

[0068] Dynamic signature files are used to verify the device's boot security and state consistency. If verification fails, it indicates the device may be in an insecure state, such as due to tampering with the signature file, mismatched device identification, or expired timestamps. Continuing to boot the operating system in this situation could lead to malicious code execution or data leakage. Therefore, booting the operating system must be refused.

[0069] Verification of the upgrade package aims to ensure its integrity, provenance, and compatibility with the device. Failure to verify may indicate package tampering, invalid signature, or mismatch with the device. Performing the upgrade under these circumstances poses security risks, such as device compromise or user data leakage; therefore, the upgrade operation must be rejected.

[0070] Reference Figure 2 The diagram shown is a functional module schematic of the television startup device 100 based on the national cryptographic algorithm of this application.

[0071] The television startup device 100 based on the national cryptographic algorithm described in this application is installed in an electronic device. Depending on the functions implemented, the television startup device 100 based on the national cryptographic algorithm includes a data acquisition module 110, a generation module 120, a startup module 130, and an upgrade module 140. These modules can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, and are stored in the memory of the electronic device.

[0072] In this embodiment, the functions of each module / unit are as follows:

[0073] Acquisition module 110: Used to acquire the device identifier and running timestamp of the television device when it is powered on;

[0074] Generation module 120: Used to generate a dynamic signature file based on the device identifier and the running timestamp using the SM2 algorithm and store it in the device's trusted execution environment;

[0075] Startup module 130: used to verify the dynamic signature file before the operating system of the TV device starts, and start the operating system if the verification is successful;

[0076] Upgrade module 140: used to verify the software package to be upgraded before the software upgrade of the TV device. If the verification is successful, the software upgrade is performed. The software package to be upgraded is signed by the SM2 algorithm and bound to the device identifier.

[0077] The specific implementation of the TV startup device based on the national cryptographic algorithm in this application is largely the same as the specific implementation of the TV startup method based on the national cryptographic algorithm described above, and will not be repeated here.

[0078] Reference Figure 3 The diagram shown is a schematic representation of a preferred embodiment of the electronic device of this application.

[0079] The electronic device includes a processor 111, a communication interface 112, a memory 113, and a communication bus 114, wherein the processor 111, the communication interface 112, and the memory 113 communicate with each other through the communication bus 114.

[0080] The memory 113 is used to store computer programs, such as a TV boot program based on the national cryptographic algorithm;

[0081] In some embodiments, the processor 111 may be a central processing unit (CPU), controller, microcontroller, microprocessor, or other data processing chip. The processor 111 is typically used to control the overall operation of the electronic device, such as performing data interaction or communication-related control and processing. In this embodiment, the processor 111 is used to run program code stored in the memory 113 or process data.

[0082] The communication interface 112 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The communication interface 112 may also be used to establish a communication connection between the electronic device and other electronic devices.

[0083] The memory 113 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 113 may be an internal storage unit of the electronic device, such as the hard disk or memory of the electronic device. In other embodiments, the memory 113 may also be an external storage device of the electronic device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc. of the electronic device. Of course, the memory 113 may include both internal storage units and external storage devices of the electronic device. In this embodiment, the memory 113 is typically used to store the operating system and various computer programs installed on the electronic device, such as the program code of a TV boot program based on national cryptographic algorithms. In addition, the memory 113 may also be used to temporarily store various types of data that have been output or will be output.

[0084] Figure 3 Only an electronic device with components 111-114 is shown; however, it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead.

[0085] In one embodiment of this application, when the processor 111 executes the program stored in the memory 113, it implements the television startup method based on the national cryptographic algorithm provided in any of the foregoing method embodiments, including:

[0086] When the television device is powered on, collect the device identifier and running timestamp of the television device;

[0087] Based on the device identifier and the runtime timestamp, a dynamic signature file is generated using the SM2 algorithm and stored in the device's trusted execution environment;

[0088] Before the operating system of the television device starts, the dynamic signature file is verified. If the verification passes, the operating system is started.

[0089] Before upgrading the software of the television device, the software package to be upgraded is verified. If the verification is successful, the software upgrade is performed. The software package to be upgraded is signed with the SM2 algorithm and bound to the device identifier.

[0090] For a detailed explanation of the above steps, please refer to the above. Figure 1A flowchart illustrating an embodiment of a television startup method based on Chinese cryptographic algorithms.

[0091] Furthermore, this application also proposes a computer-readable storage medium that is both non-volatile and volatile. This computer-readable storage medium is any one or any combination of several of the following: hard disk, multimedia card, SD card, flash memory card, SMC, read-only memory (ROM), erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), USB memory, etc. The computer-readable storage medium includes a data storage area and a program storage area. The program storage area stores a television boot program based on a national cryptographic algorithm. When the television boot program based on the national cryptographic algorithm is executed by the processor, it performs the following operations:

[0092] When the television device is powered on, collect the device identifier and running timestamp of the television device;

[0093] Based on the device identifier and the runtime timestamp, a dynamic signature file is generated using the SM2 algorithm and stored in the device's trusted execution environment;

[0094] Before the operating system of the television device starts, the dynamic signature file is verified. If the verification passes, the operating system is started.

[0095] Before upgrading the software of the television device, the software package to be upgraded is verified. If the verification is successful, the software upgrade is performed. The software package to be upgraded is signed with the SM2 algorithm and bound to the device identifier.

[0096] The specific implementation of the computer-readable storage medium in this application is largely the same as the specific implementation of the television startup method based on the national cryptographic algorithm described above, and will not be repeated here.

[0097] It should be noted that the sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, apparatus, article, or method. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.

[0098] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware simulation platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device to execute the methods described in the various embodiments of this application.

[0099] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A television starting method based on a national secret algorithm, characterized in that, The method comprises: collecting a device identifier and a running timestamp of the television device when the television device is powered on; generating a dynamic signature file based on the device identifier and the running timestamp using an SM2 algorithm and storing the dynamic signature file in a device trusted execution environment; verifying the dynamic signature file before starting an operating system of the television device, and starting the operating system if the verification is passed; verifying a software package to be upgraded before software upgrading of the television device, and performing the software upgrading if the verification is passed.

2. The method for starting television based on the national secret algorithm of claim 1, wherein, The verification of the dynamic signature file comprises: verifying the integrity of the dynamic signature file; verifying whether a device state recorded in the dynamic signature file is consistent with a current state of the television device if the integrity verification is passed; determining that the verification of the dynamic signature file is passed if the consistency is verified.

3. The method for starting television based on the SM algorithm according to claim 1, characterized in that, The software package to be upgraded is signed by the SM2 algorithm, and the software package to be upgraded is bound to the device identifier.

4. The method of claim 1, wherein the SM algorithm-based television start-up method is characterized by, The software package to be upgraded comprises an application package or an OTA package, and the verification of the software package to be upgraded comprises: verifying the integrity of the software package to be upgraded to obtain an integrity verification result; verifying signature information of the software package to be upgraded to obtain a signature verification result; verifying a binding relationship between the software package to be upgraded and the device identifier to obtain a binding verification result; and determining that the verification of the software package to be upgraded is passed if the integrity verification result, the signature verification result, and the binding verification result all indicate that the verification is passed.

5. The method of claim 4, wherein the SM algorithm is SM2. The method further comprises: determining that the verification of the software package to be upgraded is not passed if any of the integrity verification result, the signature verification result, and the binding verification result is not passed.

6. The method of claim 5, wherein the SM algorithm-based television start-up method is characterized by, The generation of the dynamic signature file based on the device identifier and the running timestamp using the SM2 algorithm comprises: combining the device identifier and the running timestamp into a signature data block; signing the signature data block using the SM2 algorithm to obtain a signature value; encapsulating the device identifier, the running timestamp, and the signature value into the dynamic signature file.

7. The method according to any one of claims 1 to 6, wherein the method is based on a national encryption algorithm. The method further comprises: refusing to start the operating system if the verification of the dynamic signature file is not passed; and refusing to perform the software upgrading operation if the verification of the software package to be upgraded is not passed.

8. A television starting device based on a national secret algorithm, characterized in that, The apparatus comprises: a collection module configured to collect a device identifier and a running timestamp of the television device when the television device is powered on; a generation module configured to generate a dynamic signature file based on the device identifier and the running timestamp using an SM2 algorithm and store the dynamic signature file in a device trusted execution environment; a starting module configured to verify the dynamic signature file before starting an operating system of the television device, and start the operating system if the verification is passed; an upgrading module configured to verify a software package to be upgraded before software upgrading of the television device, and perform the software upgrading if the verification is passed, wherein the software package to be upgraded is signed by the SM2 algorithm and is bound to the device identifier.

9. An electronic device, comprising: The apparatus comprises a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus. a memory for storing a computer program; a processor for implementing the method of starting a television based on a national secret algorithm according to any one of claims 1 to 7 when executing the program stored in the memory.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method of starting a television based on a national secret algorithm according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Reinstalling prevention method, device and system

    CN108241798A

  • Terminal startup method, terminal, and signature device

    CN109492370A

  • Safe starting method of advanced safety chip and intelligent television

    CN113032031A

  • Application operation environment detection method and device

    CN116956298A

  • Software integrity protection method and apparatus, and software integrity verification method and apparatus

    US20220224546A1