A software program running inspection method, an electronic device, and a storage medium
By generating a random first set of security verification codes and processing the input security verification code according to preset rules during the software program operation process, the error and complexity of software program operation checks in the prior art are solved, and precise monitoring and security improvement of the operation of software program are achieved.
Patent Information
- Application Number
- CN201980094854.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-04-16
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2039-04-16
AI Technical Summary
In the prior art, software program operation inspection methods have problems of error and complexity, and it is impossible to accurately check the actual operation process of software programs and the inspection cost when processing complex programs increases.
By generating a random first security verification code set and processing the input security verification code according to preset rules during the software program operation, the second security verification code is obtained. By comparing the relationship between the first security verification code set and the second security verification code, it is determined whether the software program is running correctly.
It realizes accurate monitoring of the operation of software programs, reduces the complexity of the inspection method, and as the program complexity increases, the complexity of the inspection method is almost unchanged, improving safety.
Smart Images

Figure CN113646760B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a software program running inspection method, an electronic device, and a storage medium. Background Art
[0002] With the continuous evolution of Internet and communication technologies, cyber security is gradually becoming the focus of public attention, and the security of the sub-processes of software programs is an important link. A large number of attacks come from tampering with or bypassing the inspection of the normal sub-processes of software programs to achieve the purpose of illegally running the programs.
[0003] In the prior art, the method for inspecting the running of software programs is mainly based on the inspection of a vector table. Its basic idea is to use a tool to pre-analyze all possible running result vector tables during the running of the software program, or statically generate the possible running result vector tables of the program, and then check whether it runs according to the pre-set vector table during the running of the program.
[0004] The inspection method through the vector table in the prior art faces the following two problems: 1) Inspection error: Since the vector table generated by the tool only represents all possible relationships and cannot reflect the exact relationship during actual running, it can only detect illegal jumps but cannot accurately detect the process requirements of the actual program running. For example, a key function call is skipped and the program goes to an incorrect branch, but it is still a legal branch, and this situation cannot be detected. 2) Inspection complexity: In order to detect all possible jump relationships, the vector table will increase as the complexity of the program increases.
[0005] Therefore, the above problems existing in the prior art need to be improved. Summary of the Invention
[0006] An embodiment of the present invention provides a software program running inspection method, which can detect whether the software program runs correctly by comparing the second security verification code generated during the running of the software with the pre-generated first set of security verification codes.
[0007] The first aspect of the present application provides a method for checking the operation of a software program, characterized in that the software program includes at least one sub-process, each of the at least one sub-process corresponding to a security operation, the software program running on a processor, and the method includes: generating a first set of security verification codes, the first set of security verification codes being a randomly generated set before the software program runs, the first set of security verification codes including at least one first security verification code, wherein the at least one first security verification code corresponds one-to-one with the sub-processes in the software program; for each sub-process run, processing the input security verification code according to a first preset rule to obtain a second security verification code; the first preset rule may be a mathematical algorithm, wherein each run sub-process in the software program corresponds to one of the input security verification codes and one of the second security verification codes, and the input security verification code is equal to the first security verification code corresponding to the sub-process when the sub-process runs correctly; when the relationship between the first set of security verification codes and the second security verification codes conforms to a preset relationship, it is determined that the software program runs correctly.
[0008] In this embodiment, through the first set of security verification codes randomly generated before the software program runs, all sub-processes that should be executed under normal operation of the software program are known. During the actual operation of the software, for each sub-process run, the input security verification code is processed according to the first preset rule to obtain a second security verification code, which reflects the execution situation of the sub-processes in the software program. Thus, when the relationship between the first set of security verification codes and the second security verification codes conforms to the preset relationship, it is determined that the software program runs correctly, realizing the monitoring of the software program operation situation. Since the first set of security verification codes is randomly generated each time the software runs, the security is further increased to prevent the first set of security verification codes from being stolen and thus forging the first set of security verification codes to avoid the inspection process.
[0009] Combined with the first aspect above, in a first possible implementation manner, for each running of a sub-process, the input security verification code is verified according to a first preset rule to obtain a second security verification code, including: when the software program runs to the first sub-process, obtaining the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and an initial verification code, where the initial verification code is a verification code randomly generated before the software program runs, and there is no corresponding relationship between the initial verification code and the sub-processes of the software program. The first sub-process is a sub-process of the software program. When the first sub-process runs correctly, the input security verification code corresponding to the first sub-process is the first security verification code corresponding to the first sub-process; processing the initial verification code, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the input verification code corresponding to the first sub-process according to the first preset rule to obtain the second security verification code corresponding to the first sub-process.
[0010] In this embodiment, the second security verification code corresponding to each running sub-process is obtained by processing the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the initial verification code according to the first preset rule. Therefore, the second security verification code reflects the association relationship between the sub-processes that have run. Among them, when the sub-process runs correctly, the input security verification code corresponding to the sub-process is the first security verification code corresponding to the process. Therefore, only when each running sub-process runs correctly, the second security verification code and the set of first security verification codes will conform to the preset relationship, so that it is possible to control whether each sub-process of the software program runs correctly by comparing the second security verification code with the first security verification code.
[0011] Combined with the first possible implementation manner of the first aspect above, in a second possible implementation manner, when the relationship between the set of first security verification codes and the second security verification code conforms to the preset relationship, it is determined that the software program runs correctly, including: processing the initial verification code, the first security verification code corresponding to the first sub-process, and the first security verification codes corresponding to all the sub-processes before the first sub-process according to the first preset rule to obtain a first preset result value corresponding to the first sub-process; among them, for each sub-process that needs to be monitored during the running of the software program, there is a corresponding preset result value in the same processing manner. The first preset result value can be stored in a hardware logic register. When the software program runs to the first sub-process, when the first preset result value is equal to the second security verification code corresponding to the first sub-process, it is determined that the first sub-process runs correctly.
[0012] In this embodiment, the first sub - process is a sub - process of a software program. By calculating the preset result values corresponding to each sub - process, when the software program runs to a sub - process, it determines whether the sub - process runs correctly by comparing the second security verification code corresponding to the sub - process with the preset result value corresponding to the sub - process. Thus, real - time detection of the software process operation is achieved, which can make a timely judgment when a sub - process runs incorrectly. At the same time, when it is detected that a sub - process runs incorrectly, the subsequent software program operation check method can be stopped, and it can be directly determined that the software program runs incorrectly.
[0013] Combined with the first possible implementation manner of the above - mentioned first aspect, in the third possible implementation manner, when the relationship between the first security verification code set and the second security verification code conforms to a preset relationship, it is determined that the software program runs correctly, including: processing the initial verification code and all the first security verification codes in the first security verification code set according to the first preset rule to obtain a first total preset result value, and the first total preset result value can be stored in a hardware logic register; when the software program runs to the end, when the first total preset result value is equal to the second security verification code corresponding to the last - running sub - process of the software program, it is determined that the software program runs correctly.
[0014] In this embodiment, before the software program runs, the initial verification code and all the first security verification codes in the first security verification code set are processed according to the first preset rule to obtain a first total preset result value, which is the first total preset result value when the software program runs normally. Then, when the software program runs to the end, the second security verification code corresponding to the last - running sub - process of the software program is compared with the first total preset result value. Since the second security verification code corresponding to the last - running sub - process of the software program is obtained by processing the initial verification code and the input security verification codes corresponding to all sub - processes according to the first preset rule, when the software program runs correctly, the input security verification code is equal to the first security verification code, and the first total preset result value is equal to the second security verification code corresponding to the last - running sub - process of the software program. It is possible to determine whether all sub - processes of the entire software program run correctly only through one comparison after the software program runs to the end.
[0015] Combined with the first possible implementation manner of the above first aspect, in the fourth possible implementation manner, the output of the first preset rule is equal to the input of the first preset rule. The first preset rule can be that the input is equal to the output, or the input and output conform to a specific relationship. Then, processing the input security verification code corresponding to the sub-process according to the first preset rule to obtain a second security verification code, including: when the software program runs to the first sub-process, using the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process; when the relationship between the first security verification code set and the second security verification code conforms to a preset relationship, determining that the software program runs correctly, including: processing all the first security verification codes and the initial verification code in the first security verification code set according to a second preset rule to obtain a second total preset result value; where the second preset rule can be exclusive OR, addition, subtraction, multiplication or division, and the second preset rule is stored in a software variable or a hardware logic register of the software program; after the software program runs, processing all the second security verification codes and the initial verification code according to the second preset rule to obtain a verification total result value; when the second total preset result value is equal to the verification total result value and conforms to the preset relationship, determining that the software program runs correctly.
[0016] In this embodiment, the first preset rule is an input-output rule, directly using the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process. Thus, when the software program runs to the end, a second security verification code set is obtained. Then, processing the second security verification code set according to the second preset rule to obtain a verification total result value. Before the software program runs, processing the first security verification code set according to the same second preset rule to obtain a second total preset result value. Therefore, only by comparing that the second total preset result value is equal to the verification total result value and conforms to the preset relationship can it be determined that the software program runs normally.
[0017] Combined with the above first aspect and the first to fourth possible implementation manners of the first aspect, in the fifth possible implementation manner, the method further includes: a hardware logic circuit determines whether the relationship between the first security verification code set and the second security verification code conforms to the preset relationship, where the hardware logic circuit can be a hardware circuit capable of reading codes and executing programs; or a processing core with its own register; or a chip, such as an SoC or a processor; the above when the relationship between the first security verification code set and the second security verification code conforms to the preset relationship, determining that the software program runs correctly, specifically including: when the relationship between the first security verification code set and the second security verification code conforms to the preset relationship, the hardware logic circuit determines that the software program runs correctly; the hardware logic circuit is independent of the processor.
[0018] In this embodiment, the comparison between the first set of security verification codes and the second security verification code is performed through a hardware logic circuit, so that even if the sub-process of the software program is tampered with or bypassed, the operation of the hardware logic circuit cannot be bypassed. Therefore, storing in the hardware logic register makes the comparison between the first set of security verification codes and the second security verification code have a higher security level, further improving the security performance.
[0019] Combined with the first aspect and the first to third possible implementation manners of the first aspect, in the sixth possible implementation manner, the first preset rule is stored in a software variable or a hardware logic register of the software program, where the first preset rule is exclusive OR, addition, subtraction, multiplication or division.
[0020] In this embodiment, the first preset rule is stored in the software variable of the software program, so that the processor can obtain the first preset rule for calculation during operation. Further, if the first preset rule is stored in the hardware logic register, it can make the first preset rule have a higher security level. Even if the software program is tampered with, the hardware logic register cannot be bypassed, further improving the security.
[0021] Combined with the first aspect and the first to seventh possible implementation manners of the first aspect, in the eighth possible implementation manner, the first security verification code, the second security verification code and the initial verification code include: symbols or random numbers.
[0022] In the embodiment of the present application, since the first security verification code in the first set of security verification codes is randomly generated before the software program runs, the first security verification code can be a randomly generated symbol or random number to facilitate calculation by the first preset rule or the second preset rule.
[0023] Combined with the first aspect and the first to seventh possible implementation manners of the first aspect, in the eighth possible implementation manner, the partial sub-process is a sub-process that is repeatedly or used in multiple places in the software program, or the partial sub-process is a sub-process of some deterministic steps in a software program with an uncertain running program.
[0024] In this embodiment, the sub-process monitored by the software program running check method is not all sub-processes of the software program, but partial sub-processes of the program running. It can be partial sub-processes that affect the running security of the software program, or sub-processes that are repeatedly or used in multiple places in the software program, or partial sub-processes of some deterministic steps in a software program with an uncertain running program, thereby saving computing power and not requiring monitoring of all sub-processes. At the same time, the correct operation of the correct software program is ensured by monitoring partial sub-processes.
[0025] Combined with the above first aspect and the first to eighth possible implementation manners of the first aspect, in the ninth possible implementation manner, the software program includes secure boot or protocol authentication; the partial sub-processes include: start initialization, read Flash data, verification of key Key and parameters, system initialization, verification of code, and start end process.
[0026] In this embodiment, secure boot or protocol authentication is a typical scenario with requirements for the secure operation of the software program. The sub-processes affecting the secure operation of secure boot or protocol authentication include start initialization, read Flash data, verification of key Key and parameters, system initialization, verification of code, and start end process. Thus, by controlling the above sub-processes, it is possible to monitor whether the entire secure boot or protocol authentication runs correctly.
[0027] The second aspect of this application provides a software program running inspection device. The software program inspected by the software program running inspection device includes at least one sub-process, and each sub-process in the at least one sub-process corresponds to a security operation. The software program runs on a processor. The device includes: a generation unit for generating a first set of security verification codes, which is a randomly generated set before the software program runs, and the first set of security verification codes contains at least one first security verification code, where the at least one first security verification code corresponds one-to-one with the sub-processes in the software program; an acquisition unit for, each time a sub-process runs, processing the input security verification code according to a first preset rule to obtain a second security verification code; where each run sub-process in the software program corresponds to an input security verification code and a second security verification code, and the input security verification code is equal to the first security verification code generated by the generation unit corresponding to the sub-process when the sub-process runs correctly; a judgment unit for, when the relationship between the first set of security verification codes generated by the generation unit and the second security verification codes obtained by the acquisition unit conforms to a preset relationship, determining that the software program runs correctly.
[0028] In this embodiment, by means of the first set of security verification codes randomly generated by the generation unit before the software program runs, all the sub-processes that should be executed when the software program runs normally are known. During the actual operation of the software, for each sub-process that runs, the acquisition unit processes the input security verification code according to the first preset rule to obtain a second security verification code, which reflects the execution status of the sub-processes in the software program. Thus, when the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship, the judgment unit determines that the software program runs correctly, realizing the monitoring of the running status of the software program. Since the first set of security verification codes is randomly generated each time the software runs, the security is further enhanced, preventing the first set of security verification codes from being stolen, and thus forging the first set of security verification codes to avoid the inspection process.
[0029] Combined with the second aspect above, in the first possible implementation manner, the acquisition unit is further configured to: when the software program runs to the first sub-process, acquire the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the initial verification code, where the initial verification code has no correspondence with the sub-processes of the software program, the first sub-process is a sub-process of the software program, and when the first sub-process runs correctly, the input security verification code corresponding to the first sub-process is the first security verification code corresponding to the first sub-process; process the initial verification code, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the input verification code corresponding to the first sub-process according to the first preset rule to obtain the second security verification code corresponding to the first sub-process.
[0030] In this embodiment, the second security verification code corresponding to each run sub-process is obtained by the acquisition unit processing the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the initial verification code according to the first preset rule. Therefore, the second security verification code reflects the association relationship between the sub-processes that have run. Among them, when the sub-process runs correctly, the input security verification code corresponding to the sub-process is the first security verification code corresponding to the process. Therefore, only when each run sub-process runs correctly, the second security verification code and the first set of security verification codes will conform to the preset relationship, so that it is possible to check whether each sub-process of the software program runs correctly by comparing the second security verification code with the first security verification code.
[0031] Combined with the first possible implementation manner of the second aspect above, in the second possible implementation manner, the determining unit is further configured to: process the initial verification code, the first security verification code corresponding to the first sub-process, and the first security verification codes corresponding to all the sub-processes before the first sub-process according to the first preset rule to obtain a first preset result value corresponding to the first sub-process; when the software program runs to the first sub-process, when the first preset result value is equal to the second security verification code corresponding to the first sub-process, it is determined that the first sub-process runs correctly.
[0032] In this embodiment, the first sub-process is a sub-process of the software program. The determining unit calculates the preset result value corresponding to each sub-process. When the software program runs to a sub-process, by comparing the second security verification code corresponding to the sub-process with the preset result value corresponding to the sub-process, it is determined whether the sub-process runs correctly, thereby realizing the real-time detection of the software process operation, being able to make a judgment in time when a certain sub-process runs incorrectly, and at the same time, when it is detected that a sub-process runs incorrectly, the subsequent software program running check method can be stopped from being executed, and it is directly determined that the software program runs incorrectly.
[0033] Combined with the first possible implementation manner of the second aspect above, in the third possible implementation manner, the determining unit is further configured to: process the initial verification code and all the first security verification codes in the first security verification code set according to the first preset rule to obtain a first total preset result value; when the software program runs to the end, when the first total preset result value is equal to the second security verification code corresponding to the last running sub-process of the software program, it is determined that the software program runs correctly.
[0034] In this embodiment, before the software program runs, the determining unit processes the initial verification code and all the first security verification codes in the first security verification code set according to the first preset rule to obtain a first total preset result value, which is the first total preset result value when the software program runs normally. Then, when the software program runs to the end, the second security verification code corresponding to the last running sub-process of the software program is compared with the first total preset result value. Since the second security verification code corresponding to the last running sub-process of the software program is obtained by processing the initial verification code and the input security verification codes corresponding to all the sub-processes according to the first preset rule, when the software program runs correctly, the input security verification code is equal to the first security verification code, and the first total preset result value is equal to the second security verification code corresponding to the last running sub-process of the software program. It is possible to determine whether all the sub-processes of the entire software program run correctly only through one comparison after the software program runs to the end.
[0035] Combined with the first possible implementation manner of the second aspect above, in the fourth possible implementation manner, the obtaining unit is further configured to: when the software program runs to the first sub-process, use the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process; the determining unit is further configured to: process all the first security verification codes and the initial verification code in the first set of security verification codes according to a second preset rule to obtain a second total preset result value; after the software program runs to completion, process all the second security verification codes and the initial verification code according to the second preset rule to obtain a verification total result value; when the second total preset result value is equal to the verification total result value and conforms to the preset relationship, determine that the software program runs correctly.
[0036] In this embodiment, the first preset rule is an input-output rule, and directly uses the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process, so that at the end of the software program running, a second set of security verification codes is obtained, and then the second set of security verification codes is processed according to the second preset rule to obtain a verification total result value. Before the software program runs, the first set of security verification codes is processed according to the same second preset rule to obtain a second total preset result value. Therefore, it is only necessary to compare that the second total preset result value is equal to the verification total result value and conforms to the preset relationship to determine that the software program runs normally.
[0037] Combined with the second aspect above and the first to fourth possible implementation manners of the second aspect, in the fifth possible implementation manner, the determining unit is further configured to: determine whether the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship through a hardware logic circuit; when the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship, the hardware logic circuit determines that the software program runs correctly; the hardware logic circuit is independent of the processor.
[0038] In this embodiment, the comparison between the first set of security verification codes and the second security verification code is performed by a hardware logic circuit, so that even if the sub-process of the software program is tampered with or bypassed, the operation of the hardware logic circuit will not be bypassed. Therefore, storing in the hardware logic register will make the comparison between the first set of security verification codes and the second security verification code have a higher security level, further improving the security performance.
[0039] Combined with the second aspect above and the first to third possible implementation manners of the second aspect, in the sixth possible implementation manner, the first preset rule is stored in a software variable or a hardware logic register of the software program, where the first preset rule is exclusive OR, addition, subtraction, multiplication, or division.
[0040] In this embodiment, the first preset rule is stored in a software variable of the software program, so that the processor can obtain the first preset rule for calculation during operation. Further, if the first preset rule is stored in a hardware logic register, the first preset rule can have a higher security level. Even if the software program is tampered with, the hardware logic register cannot be bypassed, further enhancing security.
[0041] Combined with the above second aspect and the first to sixth possible implementation manners of the second aspect, in the seventh possible implementation manner, the first security verification code, the second security verification code, and the initial verification code include: symbols or random numbers.
[0042] In the embodiment of the present application, since the first security verification code in the first security verification code set is randomly generated before the software program runs, the first security verification code can be a randomly generated symbol or random number to facilitate the calculation of the first preset rule or the second preset rule.
[0043] Combined with the above second aspect and the first to seventh possible implementation manners of the second aspect, in the eighth possible implementation manner, the partial sub-process is a sub-process repeatedly or used in multiple places in the software program, or the partial sub-process is a sub-process of some deterministic steps in a software program with an uncertain running program.
[0044] Combined with the above second aspect and the first to eighth possible implementation manners of the second aspect, in the ninth possible implementation manner, the software program includes secure startup or protocol authentication; the partial sub-processes include: startup initialization, reading Flash data, verification of the key Key and parameters, system initialization, verification of code, and startup end process.
[0045] In this embodiment, secure startup or protocol authentication is a typical scenario with requirements for the running security of the software program. The sub-processes affecting the running security of secure startup or protocol authentication include startup initialization, reading Flash data, verification of the key Key and parameters, system initialization, verification of code, and startup end process. Thus, by controlling the above sub-processes, it is possible to monitor whether the entire secure startup or protocol authentication runs correctly.
[0046] A third aspect of the present application provides an electronic device, which includes a transmission interface and a processor. The processor is configured to: generate a first set of security verification codes, which is a randomly generated set before the software program runs, and the first set of security verification codes includes at least one first security verification code, where the at least one first security verification code corresponds one-to-one with the sub-processes in the software program; for each sub-process run, process the input security verification code according to a first preset rule to obtain a second security verification code; the first preset rule can be a mathematical algorithm, where each run sub-process in the software program corresponds to an input security verification code and a second security verification code, and the input security verification code is equal to the first security verification code corresponding to the sub-process when the sub-process runs correctly; when the relationship between the first set of security verification codes generated by the processor and the second security verification codes conforms to a preset relationship, it is determined that the software program runs correctly.
[0047] In this embodiment, all sub-processes that should be executed under normal operation of the software program are known through the first set of security verification codes randomly generated before the software program runs. During the actual operation of the software, for each sub-process run, the input security verification code is processed according to the first preset rule to obtain a second security verification code, which reflects the execution situation of the sub-process in the software program. Thus, when the relationship between the first set of security verification codes and the second security verification codes conforms to the preset relationship, it is determined that the software program runs correctly, realizing the monitoring of the software program operation situation. Since the first set of security verification codes is randomly generated each time the software runs, the security is further increased to prevent the first set of security verification codes from being stolen and thus forging the first set of security verification codes to avoid the inspection process.
[0048] Combined with the above third aspect, in a first possible implementation manner, the processor is further configured to: when the software program runs to the first sub-process, obtain the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all sub-processes that have run before the first sub-process, and an initial verification code, where the initial verification code is a randomly generated verification code before the software program runs, and the initial verification code has no correspondence with the sub-processes of the software program, the first sub-process is a sub-process of the software program, and when the first sub-process runs correctly, the input security verification code corresponding to the first sub-process is the first security verification code corresponding to the first sub-process; process the initial verification code, the input security verification codes corresponding to all sub-processes that have run before the first sub-process, and the input verification code corresponding to the first sub-process according to the first preset rule to obtain the second security verification code corresponding to the first sub-process.
[0049] In this embodiment, the second security verification code corresponding to each executed sub-process is obtained by processing the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes executed before the first sub-process, and the initial verification code according to a first preset rule. Therefore, the second security verification code reflects the association relationship between the executed sub-processes. When a sub-process runs correctly, the input security verification code corresponding to the sub-process is the first security verification code corresponding to the process. Therefore, only when each executed sub-process runs correctly, the second security verification code and the set of first security verification codes will conform to the preset relationship, so that it is possible to check whether each sub-process of the software program runs correctly by comparing the second security verification code with the first security verification code.
[0050] Combined with the first possible implementation manner of the third aspect above, in the second possible implementation manner, the processor is further configured to: process the initial verification code, the first security verification code corresponding to the first sub-process, and the first security verification codes corresponding to all the sub-processes before the first sub-process according to the first preset rule to obtain a first preset result value corresponding to the first sub-process; wherein, for each sub-process to be monitored during the running of the software program, there is a corresponding preset result value in the same processing manner. The first preset result value can be stored in a hardware logic register. When the software program runs to the first sub-process, when the first preset result value is equal to the second security verification code corresponding to the first sub-process, it is determined that the first sub-process runs correctly.
[0051] In this embodiment, the first sub-process is a sub-process of the software program. By calculating the preset result value corresponding to each sub-process, when the software program runs to a sub-process, it is judged whether the sub-process runs correctly by comparing the second security verification code corresponding to the sub-process with the preset result value corresponding to the sub-process, thus realizing the real-time detection of the software process running, being able to make a judgment in time when a sub-process runs wrongly, and at the same time, when it is detected that a sub-process runs wrongly, the subsequent software program running check method can be stopped from being executed, and it is directly determined that the software program runs wrongly.
[0052] Combined with the first possible implementation manner of the third aspect above, in the third possible implementation manner, the processor is further configured to: process the initial verification code and all the first security verification codes in the first security verification code set according to the first preset rule to obtain a first total preset result value; the first total preset result value can be stored in a hardware logic register. When the software program runs to the end, when the first total preset result value is equal to the second security verification code corresponding to the last executed sub-process of the software program, it is determined that the software program runs correctly.
[0053] In this embodiment, before the software program runs, the initial verification code and all the first security verification codes in the first security verification code set are processed according to the first preset rule to obtain a first total preset result value, which is the first total preset result value when the software program runs normally. Then, when the software program ends, the second security verification code corresponding to the last running sub-process of the software program is compared with the first total preset result value. Since the second security verification code corresponding to the last running sub-process of the software program is obtained by processing the initial verification code and the input security verification codes corresponding to all sub-processes according to the first preset rule, when the software program runs correctly and the input security verification code is equal to the first security verification code, the first total preset result value is equal to the second security verification code corresponding to the last running sub-process of the software program. After the software program runs, it is only necessary to perform one comparison to determine whether all sub-processes of the entire software program run correctly.
[0054] Combined with the first possible implementation manner of the above third aspect, in the fourth possible implementation manner, if the output of the first preset rule pre-stored by the processor is equal to the input of the first preset rule, the processor is further configured to: when the software program runs to the first sub-process, use the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process; process all the first security verification codes in the first security verification code set and the initial verification code according to the second preset rule to obtain a second total preset result value; where the second preset rule may be exclusive OR, addition, subtraction, multiplication or division, and the second preset rule is stored in the software variable or hardware logic register of the software program; after the software program ends, process all the second security verification codes and the initial verification code according to the second preset rule to obtain a verification total result value; when the second total preset result value is equal to the verification total result value and conforms to the preset relationship, it is determined that the software program runs correctly.
[0055] In this embodiment, the first preset rule is an input-output rule, and the input security verification code corresponding to the first sub-process is directly used as the second security verification code corresponding to the first sub-process. Thus, when the software program ends, a second security verification code set is obtained. Then, the second security verification code set is processed according to the second preset rule to obtain a verification total result value. Before the software program runs, the first security verification code set is processed according to the same second preset rule to obtain a second total preset result value. Therefore, it is only necessary to compare whether the second total preset result value is equal to the verification total result value and conforms to the preset relationship to determine whether the software program runs normally.
[0056] Combined with the above-mentioned third aspect and the first to fourth possible implementation manners of the third aspect, in the fifth possible implementation manner, the electronic device further includes a hardware logic circuit, which is independent of the processor, and the hardware logic circuit is used for: determining whether the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship; wherein, the hardware logic circuit can be a hardware circuit capable of reading codes and executing programs; it can also be a processing core with its own register; or a chip, such as an SoC or a processor; when the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship, the hardware logic circuit determines that the software program is running correctly.
[0057] In this embodiment, the comparison between the first set of security verification codes and the second security verification code is performed by the hardware logic circuit, so that even if the sub-process of the software program is tampered with or bypassed, the operation of the hardware logic circuit cannot be bypassed. Therefore, storing in the hardware logic register will make the comparison between the first set of security verification codes and the second security verification code have a higher security level, further improving the security performance.
[0058] Combined with the above-mentioned third aspect and the first to third possible implementation manners of the third aspect, in the sixth possible implementation manner, the first preset rule is stored in a software variable or a hardware logic register of the software program, wherein the first preset rule is exclusive OR, addition, subtraction, multiplication or division.
[0059] In this embodiment, the first preset rule is stored in the software variable of the software program, so that the processor can obtain the first preset rule for calculation when working. Further, if the first preset rule is stored in the hardware logic register, it can make the first preset rule have a higher security level. Even if the software program is tampered with, the hardware logic register cannot be bypassed, further improving the security.
[0060] Combined with the above-mentioned third aspect and the first to sixth possible implementation manners of the third aspect, in the seventh possible implementation manner, the first security verification code, the second security verification code and the initial verification code include: symbols or random numbers.
[0061] In the embodiment of the present application, since the first security verification code in the first set of security verification codes is randomly generated before the software program runs, the first security verification code can be a randomly generated symbol or random number to facilitate calculation by the first preset rule or the second preset rule.
[0062] Combined with the above-mentioned third aspect and the first to seventh possible implementation manners of the third aspect, in the eighth possible implementation manner, this part of the sub-process is a sub-process that is repeatedly or used in multiple places in the software program, or this part of the sub-process is a sub-process of some deterministic steps in a software program with an uncertain running program.
[0063] In this embodiment, the sub-process monitored by the software program running check method is not all the sub-processes of the software program, but some sub-processes of the program running, which can be some sub-processes that affect the running safety of the software program, or sub-processes that are repeatedly or used in multiple places in the software program, or sub-processes of some deterministic steps in a software program with an uncertain running program, thus saving computing power and not requiring monitoring of all sub-processes. At the same time, the correct running of the correct software program is ensured by monitoring some sub-processes.
[0064] Combined with the above-mentioned third aspect and the first to eighth possible implementation manners of the third aspect, in the ninth possible implementation manner, the software program includes secure boot or protocol authentication; this part of the sub-processes includes: startup initialization, reading Flash data, verification of key Key and parameters, system initialization, verification of code, and startup end process.
[0065] In this embodiment, secure boot or protocol authentication is a typical scenario with requirements for the running safety of the software program. The sub-processes that affect the running safety of secure boot or protocol authentication include startup initialization, reading Flash data, verification of key Key and parameters, system initialization, verification of code, and startup end process. Therefore, the correct running of the entire secure boot or protocol authentication can be monitored by controlling the above sub-processes.
[0066] The fourth aspect of this application provides a computer-readable storage medium, including instructions, which when running on a computer device or a processor, cause the computer device or the processor to execute the method described in the first aspect or any one of the possible implementation manners of the first aspect.
[0067] The fifth aspect of this application provides a computer program product containing instructions, which when running on a computer or a processor, cause the computer or the processor to execute the method in the above-mentioned first aspect or any one of the possible implementation manners of the first aspect.
[0068] From the above technical solutions, it can be seen that the embodiments of this application have the following advantages:
[0069] In an embodiment of the present invention, a method for checking the running of a software program, an electronic device, and a storage medium are provided. The software program includes at least one sub-process, and each sub-process in the at least one sub-process corresponds to a security operation. The software program runs on a processor. The method includes: generating a first set of security verification codes, which is a randomly generated set before the software program runs. The first set of security verification codes contains at least one first security verification code, where the at least one first security verification code corresponds one-to-one with the sub-processes in the software program; for each sub-process run, processing the input security verification code corresponding to the sub-process according to a first preset rule to obtain a second security verification code; the input security verification code is equal to the first security verification code corresponding to the sub-process when the sub-process runs correctly; when the relationship between the first set of security verification codes and the second security verification code conforms to a preset relationship, it is determined that the software program runs correctly. Among them, the first set of security verification codes is generated before the software program runs; during the running of the software program, for each sub-process run, processing the input security verification code corresponding to the sub-process according to the first preset rule to obtain a second security verification code; the input security verification code is equal to the first security verification code corresponding to the sub-process when the sub-process runs correctly; therefore, if the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship, it can be determined that the software program runs correctly. If the first set of security verification codes and the second security verification code do not conform to the preset relationship, it is determined that the software program runs abnormally. The above method can accurately check whether all sub-processes of the software program run correctly, and greatly reduces the complexity of the checking method. It can be achieved only by adding the first set of security verification codes and calculating according to the first preset rule. The code amount is small, and as the program complexity increases, the complexity of the checking method hardly changes. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] Figure 1a It is a schematic diagram of an embodiment of the method for checking the running of a software program in an embodiment of the present invention;
[0071] Figure 1b It is a schematic diagram of another embodiment of the method for checking the running of a software program in an embodiment of the present invention;
[0072] Figure 2 It is a schematic diagram of another embodiment of the method for checking the running of a software program in an embodiment of the present invention;
[0073] Figure 3 It is a schematic diagram of another embodiment of the method for checking the running of a software program in an embodiment of the present invention;
[0074] Figure 4 It is a schematic diagram of another embodiment of the method for checking the running of a software program in an embodiment of the present invention;
[0075] Figure 5 Schematic diagram of another embodiment of the software program running check method in the embodiment of the present invention;
[0076] Figure 6 Schematic diagram of the embodiment of the software program running check device in the embodiment of the present invention;
[0077] Figure 7 Schematic diagram of the embodiment of the electronic device in the embodiment of the present invention. Detailed implementation manners
[0078] The embodiment of the present invention provides a software program running check method, an electronic device and a storage medium, which can detect whether the software program runs correctly by comparing the second security verification code generated during the software running process with the pre-generated first security verification code set.
[0079] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0080] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above accompanying drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order different from that shown or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0081] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the relationship between associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Here, A and B can be singular or plural. The character " / " generally indicates an "or" relationship between the associated objects before and after. "At least one (item) of the following" or a similar expression means any combination of these items, including any combination of a single item or multiple items. For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a, b, and c", where a, b, and c can be single or multiple.
[0082] With the continuous evolution of Internet and communication technologies, cyber security is gradually becoming the focus of public attention, and the security of software sub-processes is an important link. A large number of attacks come from tampering with or bypassing the normal sub-processes of software to achieve the purpose of illegally running programs.
[0083] Currently, the commonly used method for software program run-time inspection is mainly based on the inspection of the vector table. The basic idea is to first analyze the possible run-time result vector table with the help of tools or statically generate the possible run-time result vector table of the program, and then check whether the program runs according to the pre-set vector table during program execution. According to the accuracy requirements, the size of the vector table is adjusted accordingly.
[0084] The currently commonly used method is to generate a program run vector table and then check the program in real time during program execution. Its basic principle mainly includes the following steps:
[0085] 1). First, statically analyze the software program with a tool to extract the possible call and jump relationships during the run-time of each function in the program and store them as a vector table.
[0086] 2). During program execution, by monitoring the program stack, the actual function call and jump relationships during program execution can be obtained. By comparing with the vector table stored in step 1), it can be known whether it is legal, thus achieving the purpose of program run-time inspection.
[0087] The above technical solutions mainly have the following two disadvantages:
[0088] 1) Error in checking: Since the vector table generated by the tool only represents all possible relationships and cannot reflect the exact relationship during actual operation, it can only detect illegal jumps and cannot accurately detect the flow requirements of the actual program operation. For example, if a key function call is skipped and the program branches to an incorrect branch, but it is still a legal branch, this situation cannot be detected.
[0089] 2) Cost of checking: In order to detect all possible jump relationships, the vector table will increase as the complexity of the program increases, and thus the cost of the vector table itself will also increase.
[0090] To overcome the above deficiencies, the embodiments of the present application provide a software program running check method. By comparing the second security verification code generated during the software running process with the pre-generated first security verification code set, it is possible to check whether each software program to be checked runs in the expected manner, whether the execution of each sub-process or function is not illegally bypassed, and whether the process is not illegally tampered with, so as to monitor whether the software program runs correctly. At the same time, the complexity of the software program running check method provided by the embodiments of the present application does not increase as the software complexity increases. The method provided by the embodiments of the present application can be applied to embedded software, such as application programs (apps) in intelligent terminals (mobile phones, tablet computers), or embedded software set in a TV set-top box. By using the software program running check method of the present application, it is ensured that during the running process of the app or the TV set-top box program, the sub-processes of the software program are not tampered with or bypassed, and its correct operation is guaranteed. Further, the software program running check method provided by the embodiments of the present application can be a boot program. Optionally, when the running environment of the software program running check method provided by the embodiments of the present application is a personal computer (PC), it can also be a basic input output system (BIOS) program. To facilitate understanding of the specific implementation manner of the software program running check method provided by the embodiments of the present application, the technical solutions of the present application will be described in detail below with reference to the accompanying drawings.
[0091] In the embodiments of the present application, the software program is applied to scenarios with security requirements. The software program includes at least one sub-process, and each sub-process in at least one sub-process corresponds to a security operation. The software program runs on a processor.
[0092] Please refer to Figure 1a As shown in Figure 1a , the software program running check method provided by the embodiments of the present application includes the following steps.
[0093] 101. Generate a set of first security verification codes.
[0094] In this embodiment, the first set of security verification codes is a set pre-generated before the software program runs. The first set of security verification codes contains at least one first security verification code. One first security verification code corresponds to one sub-process in the software program. Optionally, the method for generating the first set of security verification codes may include the following two steps: 1) Obtain the target sub-process of the software program running. The target sub-process is a sub-process during the running of the software program; 2) Generate a target security verification code corresponding to the target sub-process as the first security verification code corresponding to the target sub-process. When the software program includes multiple sub-processes, the multiple first security verification codes corresponding to the multiple sub-processes form the first set of security verification codes. Among them, the above at least one first security verification code corresponds one-to-one with the sub-processes in the software program. Further, the above first security verification code may include randomly generated symbols or random numbers.
[0095] 102. For each sub-process run, process the input security verification code corresponding to the sub-process according to the first preset rule to obtain a second security verification code.
[0096] In this embodiment, at least one second security verification code corresponds one-to-one with at least one run sub-process. Among them, each run sub-process during the running of the software program corresponds to an input security verification code and a second security verification code. During the running of the software, input the input security verification code in each running sub-process, and then process the input security verification code through the first preset rule to obtain the second security verification code. When the sub-process runs correctly, the input security verification code corresponding to the sub-process is the first security verification code corresponding to the sub-process.
[0097] 103. When the relationship between the first set of security verification codes and the second security verification codes conforms to the preset relationship, it is determined that the software program runs correctly.
[0098] In this embodiment, since the second security verification code corresponding to each sub-process is obtained by processing the input security verification code through the first preset rule in each run sub-process, the second security verification code reflects the relationship between all the run sub-processes. When the sub-processes of the software program run correctly, the input security verification code input in the sub-process is the first security verification code corresponding to the sub-process. Therefore, when all the sub-processes of the software program run correctly, the relationship between the first set of verification codes and the second security verification codes should conform to the preset relationship. Therefore, by comparing whether the relationship between the first set of security verification codes and the second security verification codes conforms to the preset relationship, it can be determined whether the software program runs correctly.
[0099] It should be noted that the embodiments of the present application do not limit the above first preset rule and preset relationship. The first preset rule can be any algorithm, and the preset relationship can be any mathematical relationship. When the software program runs correctly, the first security verification code corresponding to each sub-process is processed by the first preset rule to obtain the second security verification code corresponding to the sub-process. Therefore, when the software program runs correctly, the second security verification code corresponding to each run sub-process is obtained by processing the corresponding first security verification code according to the first preset rule, which conforms to the input and output relationship in the first preset rule. Therefore, the preset relationship is the input and output relationship in the first preset rule, where the first security verification code set is the input and the second security verification code is the output.
[0100] In this embodiment, according to the sub-processes that need to be passed through when the software program works normally, the first security verification code corresponding to each sub-process is randomly generated to form a first security verification code set; then, during the specific operation of the software, when each sub-process runs correctly, the first security verification code corresponding to the sub-process in the first security verification code set is input, and after being processed by the first preset rule, it is output as the second security verification code corresponding to the sub-process. Then, by comparing whether the first security verification code set and the second security verification code set conform to the preset relationship, it is judged whether the software program runs correctly.
[0101] Through the above method, it can be judged whether the software program runs according to the preset sub-processes, thus forming an inspection chain to accurately judge whether each sub-process of the software runs correctly. If the software program goes to the wrong but still legal branch sub-process during operation, the first security verification code in the first security verification code set will not be input in the sub-process of the wrong branch, resulting in the non-conformity of the first security verification code set and the second security verification code with the preset relationship, so that the software program can be inspected in this case; at the same time, with the increase of the sub-processes of the software program in the above manner, only the corresponding first security verification code needs to be added to the first security verification code set; at the same time, each first verification code set is associated and bound with a running branch of the software program, where each running branch contains at least one sub-process, and at least one sub-process corresponds one-to-one with the first verification code in the first verification code set; for a software program process with multiple running branches, a corresponding first security verification code set can be set for the sub-processes of each running branch respectively, so as to realize the inspection of each running branch, with less increase in code volume, and with the increase of the complexity of the software program, the complexity of the first security verification code set remains almost unchanged. At the same time, since the first security verification codes in the first security verification code set are randomly generated before the software program runs, they are not easily predictable and tampered with, improving the security.
[0102] Further, please refer to Figure 1bFor the specific method of obtaining the second security verification code in the above step 102, the following will be further described in conjunction with Figure 1b for a more detailed explanation.
[0103] 1021. When the software program runs to the first sub-process, obtain the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all sub-processes that have run before the first sub-process, and the initial verification code.
[0104] In this embodiment, the first sub-process is a sub-process in the software program. The initial verification code has no correspondence with the sub-processes of the software program. The input security verification code is the first security verification code input when the software program runs to the first sub-process. If the software program runs correctly, the input security verification code corresponding to the first sub-process is the first security verification code corresponding to the first sub-process in the first security verification code set.
[0105] 1022. Process the initial verification code, the input security verification codes corresponding to all sub-processes that have run before the first sub-process, and the input security verification code corresponding to the first sub-process according to the first preset rule to obtain the second security verification code corresponding to the first sub-process.
[0106] In this embodiment, for example, the first preset rule is the algorithm f(x), and the initial verification code is x 0 , the input security verification codes corresponding to all sub-processes that have run before the first sub-process are x 1 to x n , the input security verification code corresponding to the first sub-process is x n+1 , then the second security verification code corresponding to the first sub-process is f(x 0 , x 1 , …, x n , x n+1 ).
[0107] In the above method, the initial verification code does not correspond to the sub-processes in the software program and is used as the first element in the calculation of the first preset rule, avoiding the calculation of the first preset rule for null values and improving the stability of the calculation of the first preset rule.
[0108] It should be noted that in the above method, for the detection of whether the software program runs correctly, according to different security requirements during the operation of the software program, it can be divided into real-time determination of whether the sub-process runs correctly during the operation of the software program, or determination of whether all sub-processes run correctly after the software program runs. For the convenience of understanding, the following will elaborate on these two situations in detail.
[0109] I. Real-time determination of whether the sub-process runs correctly during the operation of the software program.
[0110] In this case, when each sub-process of the software program runs, it is determined whether the sub-process runs correctly to determine in real time whether the sub-process of the software program runs correctly. For ease of understanding, the following further describes this case by taking the software program running in real time to the first sub-process as an example with reference to the accompanying drawings. Please refer to Figure 2 , such as Figure 2 shown, this case includes the following steps.
[0111] 201. Generate the first set of security verification codes.
[0112] In this embodiment, this step is the same as step 101 and will not be elaborated here.
[0113] 202. Process the initial verification code, the first security verification code corresponding to the first sub-process, and the first security verification codes corresponding to all sub-processes before the first sub-process according to the first preset rule to obtain the first preset result value corresponding to the first sub-process.
[0114] In this embodiment, for example, the first preset rule is the algorithm f(x), the initial verification code is x 0 , the first security verification codes corresponding to all sub-processes before the first sub-process are x 1 ’ to x n ’, and the first security verification code corresponding to the first sub-process is x n+1 ’, then the first preset result value corresponding to the first sub-process is f(x 0 ’, x 1 ’, …, x n ’, x n+1 ’).
[0115] 203. When the software program runs to the first sub-process, obtain the second security verification code corresponding to the first sub-process.
[0116] In this embodiment, for example, the first preset rule is the algorithm f(x), the initial verification code is x 0 , the input security verification codes corresponding to all sub-processes that have run before the first sub-process are x 1 to x n , and the input security verification code corresponding to the first sub-process is x n+1 , then the second security verification code corresponding to the first sub-process is f(x 0 , x 1 , …, x n , x n+1 ).
[0117] 204. If the first preset result value corresponding to the first sub-process is equal to the second security verification code corresponding to the first sub-process, determine that the first sub-process runs correctly.
[0118] In this embodiment, the first preset result value corresponding to the first sub - process is:
[0119] f(x 0 ’, x 1 ’, …, x n ’, x n+1 ’);
[0120] The second security verification code corresponding to the first sub - process is:
[0121] f(x 0 , x 1 , …, x n , x n+1 );
[0122] If the software program runs correctly, the input security verification code corresponding to each sub - process is equal to the first security verification code corresponding to the sub - process. Then x 0 ’, x 1 ’, …, x n ’, x n+1 ’ are respectively equal to x 0 , x 1 , …, x n , x n+1 . Since the first preset rule f(x) is the same algorithm, when the first sub - process runs correctly, the first preset result value corresponding to the first sub - process is equal to the second security verification code corresponding to the first sub - process, thus conforming to the preset relationship.
[0123] It should be noted that during the running of the software program, if it is detected that the second security verification code corresponding to the first sub - process is different from the first preset result value corresponding to the first sub - process, it is determined that the software program runs abnormally. At this time, the subsequent judgment steps of the sub - processes do not need to be executed, and it is directly determined that the software program runs abnormally.
[0124] In this embodiment, in each sub - process of the software program running, the first preset result value corresponding to the sub - process is generated. When the software program is running and reaches a sub - process, the second security verification code corresponding to the sub - process is compared with the first preset result value corresponding to the sub - process. If the two are the same, it is determined that the sub - process runs normally, thus realizing the real - time monitoring of each sub - process during the running of the software program. When one of the sub - processes runs wrongly, it can be discovered in time, and the wrongly - running sub - process can be accurately located, preventing the software program from continuing to run after running the wrong sub - process.
[0125] It should be noted that since the above method requires a comparison and judgment to be made in each sub - process of the software program running, it requires a large amount of work. At the same time, the time required for the comparison and judgment will also slow down the running speed of the software program. Therefore, in some scenarios where there are requirements for the running speed of the software program, the following solution can be adopted.
[0126] 2. After the software program finishes running, determine whether all sub - processes have run correctly.
[0127] In this case, only after the software program finishes running, a judgment is made once. By analyzing whether all sub - processes in the software program are running normally, it is determined whether the entire software program is running normally. For the convenience of understanding, the following will further explain this case with reference to the attached drawings. Please refer to Figure 3 , such as Figure 3 shown, this case includes the following steps.
[0128] 301. Generate the first set of security verification codes.
[0129] In this embodiment, this step is the same as step 101, and will not be elaborated here.
[0130] 302. Process the initial verification code and all the first security verification codes in the first set of security verification codes according to the first preset rule to obtain the first total preset result value.
[0131] In this embodiment, for example, the first preset rule is f(x), the initial verification code is x 0 ’, there are a total of n sub - processes in the software program, and these n sub - processes respectively correspond to the first security verification codes x 1 ’ to x n ’, then the first total preset result value is f(x 0 ’, x 1 ’, …, x n )
[0132] 303. For each sub - process run, process the input security verification code corresponding to this sub - process according to the first preset rule to obtain the second security verification code.
[0133] In this embodiment, the step of obtaining the second security verification code is the same as the above step 102 and its detailed steps 1021 to 1022; for example, the first preset rule is the algorithm f(x), the initial verification code is x 0 , after the software program finishes running, the input security verification codes corresponding to all the sub - processes that have run are respectively x 1 to x n , then the second security verification code corresponding to the last sub - process is: f(x 0 , x 1 , …, x n ).
[0134] When the software program ends, if the first total preset result value is equal to the second security verification code corresponding to the last sub-process of the software program, it is determined that the software program runs correctly.
[0135] In this embodiment, the second security verification code is obtained by processing the initial verification code, the input security verification code corresponding to the current sub-process, and the input security verification codes corresponding to all sub-processes that have run before the current sub-process according to the first preset rule. Therefore, the second security verification code reflects the connection between the current sub-process and all sub-processes that have run before the current sub-process. When the software program ends, if the second security verification code f(x 0 , x 1 , …, x n ) corresponding to the last sub-process is equal to the first total preset result value f(x 0 ’, x 1 ’, …, x n ’), it indicates that all sub-processes of the software program run according to the preset, and thus it can be determined that the software program runs correctly.
[0136] In this embodiment, only one comparison judgment is made when the software runs to determine whether the entire software program runs correctly. Its advantage is that after generating the first set of security verification codes, only one first total preset result value needs to be generated. No additional comparison operations are performed during the running of the software program. Only after the software program ends, it is determined whether the second security verification code corresponding to the last sub-process is equal to the first total preset result value to determine whether the software program runs correctly. Regardless of how many sub-processes the software program has, only one comparison judgment needs to be executed. As the complexity of the software program increases, the occupancy of the processor computing power resources is small.
[0137] It should be noted that the above first preset rule can be any operation rule such as exclusive OR, addition, subtraction, multiplication, or division. In this regard, the embodiments of the present application do not make any limitations.
[0138] Optionally, the above first preset rule can also be: input equals output. At this time, the software program running check method provided by the embodiments of the present application includes the following steps. For the convenience of understanding, the following further describes this situation in conjunction with the drawings. Please refer to Figure 4 , as Figure 4 shown, this situation includes the following steps n
[0139] 401. Generate the first set of security verification codes.
[0140] In this embodiment, this step is the same as step 101 and will not be elaborated here.
[0141] 402. Process all the first security verification codes and the initial verification code in the first security verification code set according to the second preset rule to obtain a second total preset result value.
[0142] In this embodiment, for example, the second preset rule is the algorithm f(x), and the initial verification code is x 0 ’, and all the first security verification codes in the first security verification code set are x 1 ’ to x n ’, then the second total preset result value is f(x 0 ’, x 1 ’, …, x n ’).
[0143] 403. Every time a sub - process runs, process the input security verification code corresponding to the sub - process according to the first preset rule to obtain a second security verification code.
[0144] In this embodiment, when the software program runs to the first sub - process, use the input security verification code corresponding to the first sub - process as the second security verification code corresponding to the first sub - process. Operate in this way for each sub - process during the running of the software program. Thus, when the software program finishes running, a second security verification code set composed of the second security verification codes corresponding to each sub - process that the software program has run through is obtained.
[0145] Among them, the first sub - process is a sub - process during the running of the software program. In this case, the first preset rule is that the input is equal to the output, that is, the output of the first preset rule is equal to the input of the first preset rule. Therefore, when the software program runs to the first sub - process, directly use the input security verification code corresponding to the first sub - process as the second security verification code corresponding to the first sub - process. When the software program runs correctly, the input security verification code corresponding to the first sub - process is equal to the first security verification code corresponding to the first sub - process. That is, if the first sub - process runs correctly, the first verification code corresponding to the first sub - process is equal to the second security verification code corresponding to the first sub - process.
[0146] 404. After the software program finishes running, process all the second security verification codes and the initial verification code according to the second preset rule to obtain a total result value.
[0147] In this embodiment, for example, the second preset rule is the algorithm f(x), and the initial verification code is x 0 , and all the second security verification codes in the second security verification code set are x 1 to x n , then the total result value is f(x 0 , x 1 , …, x n ).
[0148] 405. If the second total preset result value is equal to the total result value, it is determined that the software program is running correctly.
[0149] In this embodiment, the first preset rule is that the input is equal to the output. During the running of the software program, there is no need to perform calculations, and the input security verification code can be directly output as the second security verification code, further reducing the calculation amount during the running of the software program. Before the software runs, all the first security verification codes in the first security verification code set are processed through the second preset rule to obtain the second total preset result value; when the software program runs to completion, all the second security verification codes in the second security verification code set are processed through the second preset rule to obtain the total result value; if a sub - process of the software program is bypassed or tampered with, the second security verification code corresponding to this sub - process is not equal to the first security verification code, resulting in the final total result value not being equal to the second total preset result value, thereby monitoring whether the software program is running correctly.
[0150] It should be noted that the above - mentioned second preset rule can be any operation rule such as exclusive - OR, addition, subtraction, multiplication, or division. In this regard, the embodiments of the present application do not make any limitations.
[0151] Optionally, the above - mentioned first preset rule and second preset rule are stored in software variables or hardware logic registers of the software program. Among them, the calculation of the first preset rule and the second preset rule is triggered by a hardware logic circuit. In an optional case, the hardware logic register is a part of the hardware logic circuit, or the hardware logic register can also be outside the hardware logic circuit and independent of the processor running the software program. Even if a sub - process of the software program is tampered with or bypassed, the operation of the hardware logic circuit will not be bypassed. Therefore, storing in the hardware logic register will make the first preset rule and the second preset rule have a higher security level; in each sub - process of the software program running, the input security verification code corresponding to this sub - process is input into the software variable or hardware logic register, and thus the processing of the input security verification code by the first preset rule and the processing of the second security verification code by the second preset rule can be achieved. In an optional case, the steps of determining whether the second security verification code and the first security verification code set conform to the preset relationship and determining whether the software program is running correctly are executed by a hardware logic circuit, and the hardware logic circuit is independent of the processor running the software program. Determining whether the software program is running normally is completed by a hardware circuit independent of the processor, and the determination process is not easily bypassed, ensuring that the method for running inspection cannot be bypassed or tampered with, and improving the stability of the method.
[0152] Regarding the specific working mode of storing the above - mentioned first preset rule in the hardware logic register, the following will be described in detail, which specifically includes the following two steps:
[0153] 1. For each sub - process run, input the input security verification code into the hardware logic register of the hardware logic circuit.
[0154] In this embodiment, if the sub - process runs correctly, the input security verification code input into the hardware logic register is the first security verification code corresponding to the sub - process.
[0155] 2. The hardware logic circuit processes the input security verification code according to a pre - stored first preset rule to obtain a second security verification code.
[0156] In this embodiment, the first preset rule is stored in the hardware logic register of the hardware logic circuit. The hardware logic circuit processes the input security verification code to obtain the second security verification code corresponding to the sub - process. Since the hardware logic circuit is a hardware condition and cannot be tampered with or bypassed at the software level, the security of the software program running check method is further improved.
[0157] It should be noted that the above - mentioned hardware logic circuit can be a hardware circuit capable of reading code and executing programs; it can also be a processing core with its own register; or a chip, such as an SoC or a processor. Whether the logic register is a hardware circuit, a processing core or a chip, it is independent of the processor running the software program. Thus, even if the processor running the software program is tampered with, the hardware logic circuit can still process the input security verification code according to the first preset rule, so as to execute the software program running check method provided in the embodiments of the present application, further ensuring security.
[0158] Furthermore, the method of executing the second preset rule in the hardware logic circuit is similar to the above, and can be understood in combination with the above examples and steps 401 to 405, which will not be elaborated here.
[0159] It should be noted that the sub - processes mentioned in the above method can be some sub - processes related to the running security of the software program during the running of the software program. By controlling the running of some sub - processes, the correct running of the software program is ensured, and the situation of wasting computing power resources due to too many sub - processes causing too large a computational amount is avoided. Further, this part of the sub - processes can be sub - processes that are repeated or used in multiple places in the software program, or this part of the sub - processes can also be part of the sub - processes of some deterministic steps in a software program with an uncertain running program. Furthermore, the software program can be any kind of software program, which is not limited in the embodiments of the present application.
[0160] Preferably, the software program running check method provided by the embodiments of the present application can be applied to all scenarios with strict security requirements for subprocesses. Among them, secure boot and protocol authentication are typical application scenarios. To facilitate understanding of the specific application scenarios of the present application. As an example, the following will, in conjunction with the accompanying drawings, elaborate on the specific application of the software program running check method provided by the embodiments of the present application in secure boot and protocol authentication.
[0161] Refer to Figure 5 , as Figure 5 shown, some subprocesses of secure boot and protocol authentication include startup initialization, reading Flash data, verification of key Key and parameters, system initialization, verification of code, and startup end process. The application of the software program running check method provided by the embodiments of the present application in secure boot and protocol authentication includes the following steps.
[0162] 501. Generate an initial verification code x 0 .
[0163] In this embodiment, as described above, input the initial verification code x 0 to avoid the situation of an empty set when the first preset rule processes the input security verification code.
[0164] 502. According to the 6 key subprocesses included in secure boot and protocol authentication, respectively generate corresponding first security verification codes x 1 to x 6 , and obtain the first security verification code set (x 1 , x 2 , x 3 , x 4 , x 5 , x 6 ).
[0165] In this embodiment, startup initialization corresponds to the first security verification code x 1 , reading Flash data corresponds to the first security verification code x 2 , verification of key Key and parameters corresponds to the first security verification code x 3 , system initialization corresponds to the first security verification code x 4 , verification of code corresponds to the first security verification code x 5 , startup end process corresponds to the first security verification code x 6 ; among them, x 1 to x 6 can be random numbers or symbols.
[0166] 503. According to the first preset rule, for the initial verification code x 0Process all the first security verification codes in the first security verification code set to obtain a first total preset result value.
[0167] In this embodiment, according to the first preset rule, for the initial verification code x 0 and the random numbers in the first security verification code set (x 1 , x 2 , x 3 , x 4 , x 5 , x 6 ), calculate to obtain a first result value. For example, if the first preset rule is f(x), then the first total preset result value is f(x 0 , x 1 , x 2 , x 3 , x 4 , x 5 , x 6 ), where the f(x) can be exclusive OR, addition, subtraction, multiplication, or division, or it can be other algorithms.
[0168] 504. When the secure startup and protocol authentication start running, for each sub-process run, process the input security verification code corresponding to the sub-process according to the first preset rule to obtain a second security verification code.
[0169] In this embodiment, if the software program runs correctly (the input security verification code is equal to the first security verification code), obtaining the second security verification code includes the following steps:
[0170] 5041. In the startup initialization step, obtain the initial verification code x 0 and the input security verification code x 1 corresponding to the startup initialization step;
[0171] 5042. According to the first preset rule f(x), process the initial verification code x 0 and the input security verification code x 1 corresponding to the startup initialization step to obtain the second security verification code y 1 = f(x 0 , x 1 );
[0172] 5043. In the step of reading Flash data, take the initial verification code x 0 , the input security verification code x 1 corresponding to the startup initialization step, and the input security verification code x 2 corresponding to the step of reading Flash data;
[0173] 5044. According to the first preset rule f(x), process the initial verification code x0 and start the input security verification code x corresponding to the initialization step 1 and the input security verification code x corresponding to the step of reading Flash data 2 are processed to obtain the second security verification code y corresponding to the step of reading Flash data 2 = f(x 0 , x 1 , x 2 );
[0174] 5045. In the verification step of the key Key and parameters, take the initial verification code x 0 and the input security verification code x corresponding to the start initialization step 1 and the input security verification code x corresponding to the step of reading Flash data 2 and the input security verification code x corresponding to the verification step of the key Key and parameters 3 ;
[0175] 5046. According to the first preset rule f(x), process the initial verification code x 0 and the input security verification code x corresponding to the start initialization step 1 and the input security verification code x corresponding to the step of reading Flash data 2 and the input security verification code x corresponding to the verification step of the key Key and parameters 3 to obtain the second security verification code y corresponding to the verification step of the key Key and parameters 3 = f(x 0 , x 1 , x 2 , x 3 );
[0176] 5047. In the system initialization step, take the initial verification code x 0 and the input security verification code x corresponding to the start initialization step 1 and the input security verification code x corresponding to the step of reading Flash data 2 and the input security verification code x corresponding to the verification step of the key Key and parameters 3 and the input security verification code x corresponding to the system initialization step 4 ;
[0177] 5048. According to the first preset rule f(x), process the initial verification code x 0 and the input security verification code x corresponding to the start initialization step 1 and the input security verification code x corresponding to the step of reading Flash data 2 and the input security verification code x corresponding to the verification step of the key Key and parameters 3The input security verification code x corresponding to the system initialization step 4 is processed to obtain the second security verification code y corresponding to the system initialization step 4 = f(x 0 , x 1 , x 2 , x 3 , x 4 );
[0178] 5049. In the code verification step, take the initial verification code x 0 , start the input security verification code x corresponding to the initialization step 1 , the input security verification code x corresponding to the step of reading Flash data 2 , the input security verification code x corresponding to the verification step of the key Key and parameters 3 , the input security verification code x corresponding to the system initialization step 4 and the input security verification code x corresponding to the code verification step 5 ;
[0179] 50410. According to the first preset rule f(x), for the initial verification code x 0 , the input security verification code x corresponding to the start of the initialization step 1 , the input security verification code x corresponding to the step of reading Flash data 2 , the input security verification code x corresponding to the verification step of the key Key and parameters 3 , the input security verification code x corresponding to the system initialization step 4 and the input security verification code x corresponding to the code verification step 5 are processed to obtain the second security verification code y corresponding to the system initialization step 5 = f(x 0 , x 1 , x 2 , x 3 , x 4 , x 5 );
[0180] 50411. In the code verification step, take the initial verification code x 0 , the input security verification code x corresponding to the start of the initialization step 1 , the input security verification code x corresponding to the step of reading Flash data 2 , the input security verification code x corresponding to the verification step of the key Key and parameters 3 , the input security verification code x corresponding to the system initialization step 4 , the input security verification code x corresponding to the code verification step 5 and the input security verification code x corresponding to the step of starting the end process6 ;
[0181] 50412. Process the initial verification code x according to the first preset rule f(x) 0 , start the input security verification code x corresponding to the initialization step 1 , read the input security verification code x corresponding to the Flash data reading step 2 , read the input security verification code x corresponding to the verification step of the key Key and parameters 3 , read the input security verification code x corresponding to the system initialization step 4 , read the input security verification code x corresponding to the code verification step 5 and the input security verification code x corresponding to the start end process step 6 to obtain the second security verification code y corresponding to the start end process step 6 = f(x 0 , x 1 , x 2 , x 3 , x 4 , x 5 , x 6 );
[0182] 505. When the software program runs to an end, if the first total preset result value is equal to the second security verification code corresponding to the start end process, it is determined that the software program runs correctly.
[0183] In this embodiment, the first total preset result value is f(x 0 , x 1 , x 2 , x 3 , x 4 , x 5 , x 6 ), and the second security verification code y corresponding to the start end process step 6 = f(x 0 , x 1 , x 2 , x 3 , x 4 , x 5 , x 6 ). When the software program runs correctly, the input security verification code corresponding to each sub - process is equal to the first security verification code corresponding to that sub - process. Thus, when the first total preset result value is equal to the second security verification code corresponding to the start end process, it can be determined that the software program runs normally. Since the calculation of the second security verification code connects each sub - process through the first preset rule f(x), once any sub - process of the software program is tampered with or bypassed, it will cause the second security verification code to be unequal to the first total preset result value, thereby accurately determining whether each sub - process of the software program runs correctly.
[0184] It should be noted that the methods used in the above steps 501 to 505 are the methods for determining whether all sub - processes are correctly run after the software programs provided in steps 301 to 304 are run to completion. In the actual working process, according to the usage requirements, the methods provided in steps 201 to 204 can also be used to determine in real - time whether the sub - processes are correctly run during the running of the software program, and the methods provided in 401 to 405 are used to detect whether the software program is correctly run, which will not be elaborated here.
[0185] It should be further noted that in any of the cases described in the embodiments of the present application, regarding the timing of processing the input security verification code according to the first preset rule to obtain the second security verification code corresponding to the current sub - process, it can start to be processed when it is detected that the current sub - process starts to run, or it can start to be processed during the running of the current sub - process, or it can start to be processed after the current sub - process runs to completion. The embodiments of the present application do not limit this.
[0186] In the embodiments of the present application, by designing some sub - processes that determine the security of software program running, and introducing the first security verification code to establish a definite relationship between each sub - process in advance to form a first security verification code set as an inspection chain. During the running of the software program, each sub - process uses the pre - allocated first security verification code for operation, so that each sub - process becomes an operation link in the inspection chain, and the result of the operation is checked at the end of the process. If the software program runs correctly, that is, each sub - process runs correctly, then the result of the final operation must satisfy the pre - determined relationship. As long as one of the sub - processes runs abnormally, the final check will fail.
[0187] The introduced random number or randomly generated symbol can make the final inspection result different each time the software runs, so that the value to be compared finally cannot be predicted. At the same time, the final comparison can be implemented in combination with hardware logic. The operation results of each sub - process are stored in the hardware logic register, and the comparison is triggered by hardware conditions, so that even if the final comparison of the software is tampered with or bypassed, the comparison of the hardware logic will not be bypassed. The above method can also be implemented through software variables. Through this solution, it is equivalent to adding a chain to specific sub - processes of the software program. As long as one of the sub - processes has a problem, it will cause an abnormality. For a software process with multiple running branches, each critical path can be designed as a chain for inspection. Thus, it can accurately check whether each sub - process of the software program runs correctly. At the same time, it reduces the complexity of the inspection method, only requires a certain number of random numbers / symbols and a negligible increase in code volume, and as the program complexity increases, the complexity of the inspection method remains almost unchanged.
[0188] An embodiment of the present application further provides a software program running inspection device. The software program inspected by the software program running inspection device includes at least one sub-process, and each sub-process in the at least one sub-process corresponds to a security operation. The software program runs on a processor. For ease of understanding, the following will be specifically described with reference to the accompanying drawings. Please refer to Figure 6 , as Figure 6 shown, the device includes:
[0189] A generating unit 601, which is used to generate a first set of security verification codes. The first set of security verification codes is a set randomly generated before the software program runs. The first set of security verification codes contains at least one first security verification code. Among them, the at least one first security verification code corresponds one-to-one with the sub-processes in the software program;
[0190] An obtaining unit 602, which is used to, for each sub-process run, process the input security verification code according to a first preset rule to obtain a second security verification code; wherein, each run sub-process in the software program corresponds to an input security verification code and a second security verification code. The input security verification code is equal to the first security verification code generated by the generating unit 601 corresponding to the sub-process when the sub-process runs correctly;
[0191] A judging unit 603, which is used to determine that the software program runs correctly when the relationship between the first set of security verification codes generated by the generating unit 601 and the second security verification codes obtained by the obtaining unit 602 conforms to a preset relationship.
[0192] In this embodiment, through the first set of security verification codes randomly generated by the generating unit 601 before the software program runs, all sub-processes that should be executed under normal operation of the software program are known. During the actual operation of the software, for each sub-process run, the obtaining unit 602 processes the input security verification code according to the first preset rule to obtain a second security verification code. The second security verification code reflects the execution situation of the sub-processes in the software program. Thus, when the relationship between the first set of security verification codes and the second security verification codes conforms to the preset relationship, the judging unit 603 determines that the software program runs correctly, realizing the monitoring of the running situation of the software program. Since the first set of security verification codes is randomly generated each time the software runs, the security is further increased to prevent the first set of security verification codes from being stolen, so as to forge the first set of security verification codes to avoid the inspection process.
[0193] Optionally, the obtaining unit 602 is further configured to: when the software program runs to the first sub-process, obtain the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the initial verification code, where the initial verification code has no correspondence with the sub-processes of the software program, the first sub-process is a sub-process of the software program, and when the first sub-process runs correctly, the input security verification code corresponding to the first sub-process is the first security verification code corresponding to the first sub-process generated by the generating unit 601; process the initial verification code, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the input verification code corresponding to the first sub-process according to the first preset rule to obtain the second security verification code corresponding to the first sub-process.
[0194] In this embodiment, the second security verification code corresponding to each run sub-process is obtained by the obtaining unit 602 processing the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the initial verification code according to the first preset rule. Therefore, the second security verification code reflects the association relationship between the run sub-processes. Among them, when the sub-process runs correctly, the input security verification code corresponding to the sub-process is the first security verification code corresponding to the process. Therefore, only when each run sub-process runs correctly, the second security verification code and the first security verification code set will conform to the preset relationship, so that it is possible to control whether each sub-process of the software program runs correctly by comparing the second security verification code with the first security verification code.
[0195] Optionally, the determining unit 603 is further configured to: process the initial verification code, the first security verification code corresponding to the first sub-process generated by the generating unit 601, and the first security verification codes corresponding to all the sub-processes before the first sub-process generated by the generating unit 601 according to the first preset rule to obtain the first preset result value corresponding to the first sub-process; when the software program runs to the first sub-process, when the first preset result value is equal to the second security verification code corresponding to the first sub-process obtained by the obtaining unit 602, determine that the first sub-process runs correctly.
[0196] In this embodiment, the first sub-process is a sub-process of the software program. The determining unit 603 calculates the preset result value corresponding to each sub-process. When the software program runs to a sub-process, it determines whether the sub-process runs correctly by comparing the second security verification code corresponding to the sub-process with the preset result value corresponding to the sub-process, thereby realizing the real-time detection of the software process operation, being able to make a judgment in time when a sub-process runs wrong, and at the same time, when detecting that a sub-process runs wrong, it is possible not to execute the subsequent software program running check method and directly determine that the software program runs wrong.
[0197] Optionally, the determination unit 603 is further configured to: process the initial verification code and all the first security verification codes in the first security verification code set generated by the generation unit 601 according to the first preset rule to obtain a first total preset result value; at the end of the software program operation, when the first total preset result value is equal to the second security verification code corresponding to the last running sub-process of the software program obtained by the acquisition unit 602, determine that the software program runs correctly.
[0198] In this embodiment, before the software program runs, the determination unit 603 processes the initial verification code and all the first security verification codes in the first security verification code set according to the first preset rule to obtain a first total preset result value, which is the first total preset result value when the software program runs normally. Then, at the end of the software program operation, the second security verification code corresponding to the last running sub-process of the software program is compared with the first total preset result value. Since the second security verification code corresponding to the last running sub-process of the software program is obtained by processing the initial verification code and the input security verification codes corresponding to all sub-processes according to the first preset rule, when the software program runs correctly, the input security verification code is equal to the first security verification code, and the first total preset result value is equal to the second security verification code corresponding to the last running sub-process of the software program. Therefore, after the software program runs, it is only necessary to perform one comparison to determine whether all sub-processes of the entire software program run correctly.
[0199] Optionally, the acquisition unit 602 is further configured to: when the software program runs to the first sub-process, use the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process; the determination unit 603 is further configured to: process the initial verification code and all the first security verification codes in the first security verification code set generated by the generation unit 601 according to the second preset rule to obtain a second total preset result value; after the software program runs, process the initial verification code and all the second security verification codes obtained by the acquisition unit 602 according to the second preset rule to obtain a verification total result value; when the second total preset result value is equal to the verification total result value and conforms to the preset relationship, determine that the software program runs correctly.
[0200] In this embodiment, the first preset rule is the input-output rule. The input security verification code corresponding to the first sub-process is directly used as the second security verification code corresponding to the first sub-process. Thus, at the end of the software program operation, a second security verification code set is obtained. Then, the second preset rule is used to process the second security verification code set to obtain the verification total result value. Before the software program runs, the first security verification code set is processed by the same second preset rule to obtain the second total preset result value. Therefore, it can be determined that the software program runs normally as long as it is compared that the second total preset result value is equal to the verification total result value and conforms to the preset relationship.
[0201] Optionally, the determination unit 603 is further configured to: judge whether the relationship between the first security verification code set generated by the generation unit 601 and the second security verification code obtained by the acquisition unit 602 conforms to the preset relationship through a hardware logic circuit; when the relationship between the first security verification code set and the second security verification code conforms to the preset relationship, the hardware logic circuit determines that the software program runs correctly; the hardware logic circuit is independent of the processor.
[0202] In this embodiment, the comparison between the first security verification code set and the second security verification code is performed by a hardware logic circuit, so that even if the sub-process of the software program is tampered with or bypassed, the work of the hardware logic circuit cannot be bypassed. Therefore, storing in the hardware logic register will make the comparison between the first security verification code set and the second security verification code have a higher security level, further improving the security performance.
[0203] Optionally, the first preset rule is stored in a software variable or a hardware logic register of the software program, where the first preset rule is exclusive OR, addition, subtraction, multiplication or division.
[0204] In this embodiment, the first preset rule is stored in the software variable of the software program, so that the processor can obtain the first preset rule for calculation when working. Further, if the first preset rule is stored in the hardware logic register, it can make the first preset rule have a higher security level. Even if the software program is tampered with, the hardware logic register cannot be bypassed, further improving the security.
[0205] Optionally, the first security verification code, the second security verification code and the initial verification code include: symbols or random numbers.
[0206] In the embodiment of the present application, since the first security verification code in the first security verification code set is randomly generated before the software program runs, the first security verification code can be a randomly generated symbol or random number to facilitate the calculation by the first preset rule or the second preset rule.
[0207] Optionally, this partial sub-process is a sub-process that is repeated or used in multiple places in the software program, or this partial sub-process is a sub-process of some deterministic steps in a software program with an uncertain running program.
[0208] Optionally, the software program includes secure boot or protocol authentication; this partial sub-process includes: boot initialization, reading Flash data, verification of key and parameters, system initialization, verification of code, and end process of boot.
[0209] In this embodiment, secure boot or protocol authentication is a typical scenario where security requirements are imposed on the running of the software program. The sub-processes that affect the secure running of secure boot or protocol authentication include boot initialization, reading Flash data, verification of key and parameters, system initialization, verification of code, and end process of boot. Thus, by controlling the above-mentioned sub-processes, it is possible to monitor whether the entire secure boot or protocol authentication runs correctly.
[0210] The embodiment of the present application also provides an electronic device. For ease of understanding, the following will be specifically described with reference to the accompanying drawings. Please refer to Figure 7 , as Figure 7 shown, the electronic device includes: a transmission interface 701, a processor 702, a hardware logic circuit 703, and a microcontroller 704. Optionally, the electronic device may further include a memory 705 or a hardware logic register (not shown in the figure). In an optional case, the hardware logic register is a part of the hardware logic circuit 703, or the hardware logic register may also be outside the hardware logic circuit 703 and independent of the processor 702 that runs the software program. Each part in the electronic device is coupled through a connector. It should be understood that in various embodiments of the present application, coupling means being interconnected in a specific manner, including being directly connected or indirectly connected through other devices. For example, it can be connected through various interfaces, transmission lines, or buses, etc. These interfaces are usually electrical communication interfaces, but mechanical interfaces or other forms of interfaces are not excluded. This embodiment does not make any limitations in this regard. The transmission interface may include a receiving interface and a sending interface. The processor 702 may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor; optionally, the processor 702 may be a processor group composed of multiple processors, and the multiple processors are coupled to each other through one or more buses.
[0211] A memory 705 can be used to store computer program instructions, including various computer program codes such as an operating system (OS), various user application programs, the software program to be inspected, and the program code for implementing the solution of this application; the memory can also be used to store video data, image data, etc.; the CPU can be used to execute the computer program codes stored in the memory to implement the method in the embodiments of this application. Optionally, the memory can be a non-volatile memory, such as an Embedded Multi Media Card (EMMC), a Universal Flash Storage (UFS), or a Read-Only Memory (ROM), or other types of static storage devices that can store static information and instructions, and can also be a volatile memory, such as a Random Access Memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can also be an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Compact Disc Read-Only Memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other computer-readable storage medium that can be used to carry or store program codes in the form of instructions or data structures and can be accessed by a computer, but not limited to this. The chip involved in the embodiments of this application is a system manufactured by an integrated circuit process on the same semiconductor substrate, also called a semiconductor chip, which can be a collection of integrated circuits formed on a substrate (usually a semiconductor material such as silicon) using an integrated circuit process, and its outer layer is usually encapsulated by a semiconductor packaging material. The integrated circuit can include various functional devices, and each type of functional device includes transistors such as logic gate circuits, Metal-Oxide-Semiconductor (MOS) transistors, bipolar transistors, or diodes, and can also include other components such as capacitors, resistors, or inductors. Each functional device can work independently or work under the action of necessary driver software, and can implement various functions such as communication, operation, or storage.
[0212] The processor 702 is configured to: generate a first set of security verification codes, which is a set randomly generated before the software program runs, and the first set of security verification codes includes at least one first security verification code, where the at least one first security verification code corresponds one-to-one with the sub-processes in the software program; for each sub-process run, process the input security verification code according to a first preset rule to obtain a second security verification code; the first preset rule can be a mathematical algorithm, where each run sub-process in the software program corresponds to an input security verification code and a second security verification code, and the input security verification code is equal to the first security verification code corresponding to the sub-process when the sub-process runs correctly; when the relationship between the first set of security verification codes generated by the processor 702 and the second security verification code conforms to a preset relationship, it is determined that the software program runs correctly.
[0213] In this embodiment, by generating a first set of security verification codes randomly before the software program runs, all the sub-processes that should be executed when the software program runs normally are known. During the actual operation of the software, for each sub-process run, the input security verification code is processed according to the first preset rule to obtain a second security verification code, which reflects the execution situation of the sub-process in the software program. Thus, when the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship, it is determined that the software program runs correctly, realizing the monitoring of the software program operation. Since the first set of security verification codes is randomly generated each time the software runs, the security is further enhanced to prevent the first set of security verification codes from being stolen, thereby forging the first set of security verification codes to avoid the inspection process.
[0214] Optionally, the processor 702 is further configured to: when the software program runs to the first sub-process, obtain the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and an initial verification code, which is a verification code randomly generated before the software program runs, where the initial verification code has no correspondence with the sub-processes of the software program, the first sub-process is a sub-process of the software program, and when the first sub-process runs correctly, the input security verification code corresponding to the first sub-process is the first security verification code corresponding to the first sub-process; process the initial verification code, the input security verification codes corresponding to all the sub-processes that have run before the first sub-process, and the input verification code corresponding to the first sub-process according to the first preset rule to obtain the second security verification code corresponding to the first sub-process.
[0215] In this embodiment, the second security verification code corresponding to each executed sub-process is obtained by processing the input security verification code corresponding to the first sub-process, the input security verification codes corresponding to all the sub-processes executed before the first sub-process, and the initial verification code according to a first preset rule. Therefore, the second security verification code reflects the association relationship between the executed sub-processes. When a sub-process runs correctly, the input security verification code corresponding to the sub-process is the first security verification code corresponding to the process. Therefore, only when each executed sub-process runs correctly, the second security verification code and the set of first security verification codes will conform to the preset relationship, so that it is possible to check whether each sub-process of the software program runs correctly by comparing the second security verification code with the first security verification code.
[0216] Optionally, the processor 702 is further configured to: process the initial verification code, the first security verification code corresponding to the first sub-process, and the first security verification codes corresponding to all the sub-processes before the first sub-process according to the first preset rule to obtain a first preset result value corresponding to the first sub-process; wherein, for each sub-process to be monitored during the running of the software program, there is a corresponding preset result value in the same processing manner, and the first preset result value can be stored in a hardware logic register. When the software program runs to the first sub-process, when the first preset result value is equal to the second security verification code corresponding to the first sub-process, it is determined that the first sub-process runs correctly.
[0217] In this embodiment, the first sub-process is a sub-process of the software program. By calculating the preset result value corresponding to each sub-process, when the software program runs to a sub-process, it is determined whether the sub-process runs correctly by comparing the second security verification code corresponding to the sub-process with the preset result value corresponding to the sub-process, thereby realizing the real-time detection of the software process operation, being able to make a judgment in time when a sub-process runs incorrectly, and at the same time, when it is detected that a sub-process runs incorrectly, the subsequent software program running check method can be stopped and it can be directly determined that the software program runs incorrectly.
[0218] Optionally, the processor 702 is further configured to: process the initial verification code and all the first security verification codes in the set of first security verification codes according to the first preset rule to obtain a first total preset result value; the first total preset result value can be stored in a hardware logic register. When the software program runs to the end, when the first total preset result value is equal to the second security verification code corresponding to the last executed sub-process of the software program, it is determined that the software program runs correctly.
[0219] In this embodiment, before the software program runs, the initial verification code and all the first security verification codes in the first security verification code set are processed according to a first preset rule to obtain a first total preset result value, which is the first total preset result value when the software program runs normally. Then, when the software program ends, the second security verification code corresponding to the last running sub-process of the software program is compared with the first total preset result value. Since the second security verification code corresponding to the last running sub-process of the software program is obtained by processing the initial verification code and the input security verification codes corresponding to all sub-processes according to the first preset rule, when the software program runs correctly and the input security verification code is equal to the first security verification code, the first total preset result value is equal to the second security verification code corresponding to the last running sub-process of the software program. After the software program runs, it is only necessary to perform one comparison to determine whether all sub-processes of the entire software program run correctly.
[0220] Optionally, if the output of the first preset rule pre-stored in the processor 702 is equal to the input of the first preset rule, the processor 702 is further configured to: when the software program runs to the first sub-process, use the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process; process all the first security verification codes in the first security verification code set and the initial verification code according to a second preset rule to obtain a second total preset result value; where the second preset rule may be exclusive OR, addition, subtraction, multiplication or division, and the second preset rule is stored in a software variable or a hardware logic register of the software program; after the software program runs, process all the second security verification codes and the initial verification code according to the second preset rule to obtain a verification total result value; when the second total preset result value is equal to the verification total result value and meets the preset relationship, it is determined that the software program runs correctly.
[0221] In this embodiment, the first preset rule is an input-output rule, and directly uses the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process, so that when the software program ends, a second security verification code set is obtained. Then, the second security verification code set is processed according to the second preset rule to obtain a verification total result value. Before the software program runs, the first security verification code set is processed according to the same second preset rule to obtain a second total preset result value. Therefore, it is only necessary to compare whether the second total preset result value is equal to the verification total result value and meets the preset relationship to determine whether the software program runs normally.
[0222] The hardware logic circuit 703 is independent of the processor 702, and the hardware logic circuit 703 is configured to: determine whether the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship; wherein, the hardware logic circuit 703 can be a hardware circuit capable of reading code and executing programs; it can also be a processing core with its own register; or a chip, such as an SoC or a processor; when the relationship between the first set of security verification codes and the second security verification code conforms to the preset relationship, the hardware logic circuit 703 determines that the software program is running correctly.
[0223] In this embodiment, the comparison between the first set of security verification codes and the second security verification code is performed by the hardware logic circuit 703, so that even if the sub-process of the software program is tampered with or bypassed, the operation of the hardware logic circuit 703 cannot be bypassed. Therefore, storing in the hardware logic register will make the comparison between the first set of security verification codes and the second security verification code have a higher security level, further improving the security performance.
[0224] Optionally, the first preset rule is stored in a software variable or a hardware logic register of the software program, wherein the first preset rule is exclusive OR, addition, subtraction, multiplication or division.
[0225] In this embodiment, the first preset rule is stored in the software variable of the software program, so that the processor 702 can obtain the first preset rule for calculation during operation. Further, if the first preset rule is stored in the hardware logic register, it can make the first preset rule have a higher security level. Even if the software program is tampered with, the hardware logic register cannot be bypassed, further improving the security.
[0226] Optionally, the first security verification code, the second security verification code and the initial verification code include: symbols or random numbers.
[0227] In the embodiment of the present application, since the first security verification code in the first set of security verification codes is randomly generated before the software program runs, the first security verification code can be a randomly generated symbol or random number for calculation by the first preset rule or the second preset rule.
[0228] Optionally, the partial sub-process is a sub-process that is repeated or used in multiple places in the software program, or the partial sub-process is a sub-process of some deterministic steps in a software program with uncertain running procedures.
[0229] In this embodiment, the sub-processes monitored by the software program running check method are not all the sub-processes of the software program, but some sub-processes of the program running. They can be some sub-processes that affect the running security of the software program, or sub-processes that are repeated or used in multiple places in the software program, or sub-processes of some deterministic steps in the software program with uncertain running processes, thus saving computing power and not requiring monitoring of all sub-processes. At the same time, by monitoring some sub-processes, the correct running of the software program is ensured.
[0230] Optionally, the software program includes secure boot or protocol authentication; the part of the sub-processes includes: startup initialization, reading Flash data, verification of key and parameters, system initialization, verification of code, and startup end process.
[0231] In this embodiment, secure boot or protocol authentication is a typical scenario with requirements for the running security of the software program. The sub-processes affecting the running security of secure boot or protocol authentication include startup initialization, reading Flash data, verification of key and parameters, system initialization, verification of code, and startup end process. Thus, by controlling the above sub-processes, it can be monitored whether the entire secure boot or protocol authentication runs correctly.
[0232] Through the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general hardware, and of course, it can also be implemented by dedicated hardware including application-specific integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally, functions completed by computer programs can be easily implemented by corresponding hardware, and the specific hardware structures for implementing the same function are also diverse, such as analog circuits, digital circuits, or dedicated circuits. However, for this application, in more cases, software program implementation is a better implementation method. Based on such an understanding, the technical solution of this application, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a floppy disk, USB flash drive, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disk, or optical disc of a computer, and includes several instructions to enable a computer device (a personal computer, a server, or a communication device, etc.) to execute the methods described in various embodiments of this application.
[0233] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product.
[0234] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer is a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium is any available medium that a computer can store or a data storage device such as a server or data center that includes one or more integrated available media. The available medium is a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state disk (SSD)).
[0235] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium, which can include: ROM, RAM, magnetic disk, optical disk, etc.
[0236] The above has introduced in detail the software program running inspection method, electronic device, and storage medium provided by the embodiments of the present invention. Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A method for checking the running of a software program, characterized in that, the software program includes at least one sub - process, and each sub - process in the at least one sub - process corresponds to a security operation. The software program runs on a processor, and the method includes: generating a first set of security verification codes, which is a randomly generated set before the software program runs. The first set of security verification codes contains at least one first security verification code, wherein the at least one first security verification code corresponds one - to - one with the sub - processes in the software program; for each sub - process run, processing the input security verification code according to a first preset rule to obtain a second security verification code; wherein, each run sub - process in the software program corresponds to an input security verification code and a second security verification code, and the input security verification code is equal to the first security verification code corresponding to the sub - process when the sub - process runs correctly; when the relationship between the first set of security verification codes and the second security verification codes conforms to a preset relationship, it is determined that the software program runs correctly; the step of, for each sub - process run, verifying the input security verification code according to a first preset rule to obtain a second security verification code includes: when the software program runs to the first sub - process, obtaining the input security verification code corresponding to the first sub - process, the input security verification codes corresponding to all the sub - processes that have run before the first sub - process, and an initial verification code, wherein the initial verification code has no correspondence with the sub - processes of the software program. The first sub - process is a sub - process of the software program, and when the first sub - process runs correctly, the input security verification code corresponding to the first sub - process is the first security verification code corresponding to the first sub - process; processing the initial verification code, the input security verification codes corresponding to all the sub - processes that have run before the first sub - process, and the input verification code corresponding to the first sub - process according to the first preset rule to obtain the second security verification code corresponding to the first sub - process.
2. The method according to claim 1, characterized in that, the step of when the relationship between the first set of security verification codes and the second security verification codes conforms to a preset relationship, determining that the software program runs correctly includes: processing the initial verification code, the first security verification code corresponding to the first sub - process, and the first security verification codes corresponding to all the sub - processes before the first sub - process according to the first preset rule to obtain a first preset result value corresponding to the first sub - process; when the software program runs to the first sub - process, when the first preset result value is equal to the second security verification code corresponding to the first sub - process, it is determined that the first sub - process runs correctly.
3. The method according to claim 1, characterized in that, the step of when the relationship between the first set of security verification codes and the second security verification codes conforms to a preset relationship, determining that the software program runs correctly includes: Process the initial verification code and all the first security verification codes in the first security verification code set according to the first preset rule to obtain a first total preset result value; When the software program finishes running, if the first total preset result value is equal to the second security verification code corresponding to the last running sub-process of the software program, it is determined that the software program runs correctly.
4. The method according to claim 1, wherein, if the output of the first preset rule is equal to the input of the first preset rule, then processing the input security verification code corresponding to the sub-process according to the first preset rule to obtain a second security verification code, includes: When the software program runs to the first sub-process, use the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process; The determination that the software program runs correctly when the relationship between the first security verification code set and the second security verification code conforms to a preset relationship includes: Process all the first security verification codes in the first security verification code set and the initial verification code according to the second preset rule to obtain a second total preset result value; After the software program finishes running, process all the second security verification codes and the initial verification code according to the second preset rule to obtain a verification total result value; When the second total preset result value is equal to the verification total result value and conforms to the preset relationship, it is determined that the software program runs correctly.
5. The method according to any one of claims 1 to 4, wherein, The method further includes: The hardware logic circuit determines whether the relationship between the first security verification code set and the second security verification code conforms to the preset relationship; The determination that the software program runs correctly when the relationship between the first security verification code set and the second security verification code conforms to a preset relationship specifically includes: When the relationship between the first security verification code set and the second security verification code conforms to the preset relationship, the hardware logic circuit determines that the software program runs correctly; The hardware logic circuit is independent of the processor.
6. The method according to any one of claims 1 to 3, wherein, The first preset rule is stored in a software variable or a hardware logic register of the software program, and the first preset rule is exclusive OR, addition, subtraction, multiplication or division.
7. The method according to any one of claims 1 to 4, wherein, The first security verification code, the second security verification code and the initial verification code include: symbols or random numbers.
8. The method according to any one of claims 1 to 4, wherein, Some sub-processes are sub-processes that are repeated or used in multiple places in the software program, or some sub-processes are sub-processes of some deterministic steps in a software program with an uncertain running program.
9. The method according to any one of claims 1 to 4, wherein, The software program includes secure boot or protocol authentication; some sub - processes include: startup initialization, reading Flash data, verification of key and parameters, system initialization, verification of code, and startup end process.
10. An electronic device, characterized in that, the electronic device includes: a transmission interface and a processor, and the processor is used for; generating a first set of security verification codes, the first set of security verification codes being a set randomly generated before the software program runs, the first set of security verification codes including at least one first security verification code, wherein the at least one first security verification code corresponds one - to - one with the sub - processes in the software program, the software program includes at least one sub - process, and each sub - process in the at least one sub - process corresponds to a security operation, and the software program runs on the processor; for each sub - process run, processing the input security verification code according to a first preset rule to obtain a second security verification code; wherein, during the running of the software program, each run sub - process corresponds to an input security verification code and a second security verification code, and the input security verification code is equal to the first security verification code corresponding to the sub - process when the sub - process runs correctly; when the relationship between the first set of security verification codes generated by the processor and the second security verification codes conforms to a preset relationship, it is determined that the software program runs correctly; the processor is further used for: when the software program runs to the first sub - process, obtaining the input security verification code corresponding to the first sub - process, the input security verification codes corresponding to all the sub - processes that have run before the first sub - process, and an initial verification code, wherein the initial verification code has no correspondence with the sub - processes of the software program, the first sub - process is a sub - process of the software program, and when the first sub - process runs correctly, the input security verification code corresponding to the first sub - process is the first security verification code corresponding to the first sub - process; processing the initial verification code, the input security verification codes corresponding to all the sub - processes that have run before the first sub - process, and the input verification code corresponding to the first sub - process according to the first preset rule to obtain the second security verification code corresponding to the first sub - process.
11. The electronic device according to claim 10, characterized in that, the processor is further used for: processing the initial verification code, the first security verification code corresponding to the first sub - process, and the first security verification codes corresponding to all the sub - processes before the first sub - process according to the first preset rule to obtain a first preset result value corresponding to the first sub - process; when the software program runs to the first sub - process, when the first preset result value is equal to the second security verification code corresponding to the first sub - process, it is determined that the first sub - process runs correctly.
12. The electronic device according to claim 10, characterized in that, the processor is further used for: processing the initial verification code and all the first security verification codes in the first set of security verification codes according to the first preset rule to obtain a first total preset result value; When the software program ends, if the first total preset result value is equal to the second security verification code corresponding to the last running sub-process of the software program, it is determined that the software program runs correctly.
13. The electronic device according to claim 10, wherein, if the output of the first preset rule pre-stored in the processor is equal to the input of the first preset rule, the processor is further configured to: when the software program runs to the first sub-process, use the input security verification code corresponding to the first sub-process as the second security verification code corresponding to the first sub-process; process all the first security verification codes in the first security verification code set and the initial verification code according to a second preset rule to obtain a second total preset result value; after the software program runs to the end, process all the second security verification codes and the initial verification code according to the second preset rule to obtain a verification total result value; if the second total preset result value is equal to the verification total result value and conforms to the preset relationship, it is determined that the software program runs correctly.
14. The electronic device according to any one of claims 10 to 13, wherein, the electronic device further includes a hardware logic circuit, and the hardware logic circuit is independent of the processor, wherein the hardware logic circuit is configured to: judge whether the relationship between the first security verification code set and the second security verification code conforms to the preset relationship; when the relationship between the first security verification code set and the second security verification code conforms to the preset relationship, the hardware logic circuit determines that the software program runs correctly.
15. The electronic device according to any one of claims 10 to 12, wherein, the electronic device further includes a hardware logic register, and the first preset rule is stored in a software variable of the software program or the hardware logic register, wherein the first preset rule is exclusive OR, addition, subtraction, multiplication or division.
16. The electronic device according to any one of claims 10 to 13, wherein, the first security verification code, the second security verification code and the initial verification code include: symbols or random numbers.
17. The electronic device according to any one of claims 10 to 13, wherein, some sub-processes are sub-processes that are repeated or used in multiple places in the software program, or some sub-processes are sub-processes of some deterministic steps in a software program with an uncertain running program.
18. The electronic device according to any one of claims 10 to 13, wherein, the software program includes secure startup or protocol authentication; some sub-processes include: startup initialization, reading Flash data, verification of keys and parameters, system initialization, verification of code, and startup end process.
19. A computer-readable storage medium, including instructions, wherein, when the instructions run on a computer device or a processor, the computer device or the processor is caused to execute the method according to any one of claims 1-9.
Citation Information
Patent Citations
Software vulnerability detection method, graded response method and software vulnerability detection system
CN107886000A