An information processing method
By obtaining and comparing the version number of the firmware system image, generating physical attack detection results, and controlling the boot process of electronic devices, solving the brushback attack problem caused by automatic recovery of firmware system, ensuring the security and data protection of electronic devices.
Patent Information
- Application Number
- CN202111138402.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-27
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-09-27
AI Technical Summary
In the prior art, the automatic recovery method of the firmware system may lead to a system flashback attack, modified to an old version with security vulnerabilities, resulting in data leakage of electronic equipment.
By obtaining the firmware system image version number in the serial peripheral interface memory and the secure storage module, a physical attack detection result is generated, and the startup process of the electronic device is controlled based on the detection result, ensuring the consistency and security of the version number.
Effectively prevent data leakage caused by attackers through physical attacks on SPI memory, protect the security of electronic devices, and avoid brushback attacks and data leakage.
Smart Images

Figure CN113849821B_ABST
Abstract
Description
Technical Field
[0001] This application relates to, but is not limited to, the field of computer technology, and in particular, to an information processing method. Background Art
[0002] In order to ensure the stability and security of the firmware system, the industry adopts the method of platform firmware recovery. When it is found that the firmware is damaged or tampered with, it will be automatically restored. Currently, the automatic restoration method is very likely to modify the system firmware to an old version with security vulnerabilities, resulting in a downgrade attack. Summary of the Invention
[0003] Embodiments of this application are expected to provide an information processing method.
[0004] The technical solution of this application is implemented as follows: An information processing method, the method includes:
[0005] If the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory; obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device; based on the first association relationship between the first security version number and the second security version number, generate a detection result of a physical attack on the serial peripheral interface memory; based on the detection result, perform power-on control on the electronic device.
[0006] An information processing device, the device includes: an acquisition module, configured to obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory if the power-on self-check of the firmware system of the electronic device is completed;
[0007] The acquisition module is further configured to obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device;
[0008] A generation module, configured to generate a detection result of a physical attack on the serial peripheral interface memory based on the first association relationship between the first security version number and the second security version number;
[0009] A processing module, configured to perform power-on control on the electronic device based on the detection result.
[0010] An electronic device, the electronic device includes: a processor, a memory, and a communication bus;
[0011] The communication bus is used to implement a communication connection between the processor and the memory;
[0012] The processor is configured to execute a program for information processing stored in the memory to implement the steps of the information processing method as described above.
[0013] A computer storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the information processing method as described above.
[0014] In the information processing method provided by the embodiments of the present application, if the power-on self-check of the firmware system of the electronic device is completed, the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory is obtained; the second security version number of the firmware system image stored in the secure storage module of the electronic device is obtained; based on the first association relationship between the first security version number and the second security version number, a detection result of a physical attack on the serial peripheral interface memory is generated; based on the detection result, power-on control of the electronic device is performed; that is to say, the electronic device effectively detects the security version number of the firmware system image stored in the main area of the serial peripheral interface memory and the security version number of the firmware system image stored in the secure storage module, generates a detection result of whether a physical attack has occurred on the Serial Peripheral Interface (SPI) memory, and then based on the detection result, controls the power-on of the electronic device; in this way, it is avoided that an attacker causes data leakage in the electronic device through a physical attack on the SPI memory, protecting the security of the electronic device. Description of the Drawings
[0015] Figure 1 It is a schematic flowchart of an information processing method provided by an embodiment of the present application;
[0016] Figure 2 It is a schematic flowchart of another information processing method provided by an embodiment of the present application;
[0017] Figure 3 It is a schematic flowchart of yet another information processing method provided by an embodiment of the present application;
[0018] Figure 4 It is a schematic flowchart of an information processing method provided by another embodiment of the present application;
[0019] Figure 5 It is a schematic flowchart of another information processing method provided by another embodiment of the present application;
[0020] Figure 6 It is a schematic flowchart of yet another information processing method provided by another embodiment of the present application;
[0021] Figure 7 It is a schematic flowchart of an information processing method provided by yet another embodiment of the present application;
[0022] Figure 8 Schematic structural diagram of an information processing device provided by an embodiment of the present application;
[0023] Figure 9 Schematic structural diagram of an electronic device provided by an embodiment of the present application. Specific embodiments
[0024] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0025] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having", and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.
[0026] Referring to the embodiments mentioned herein means that specific features, structures or characteristics described in connection with the embodiments may be included in at least one embodiment of the present application. The phrase appears in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.
[0027] An embodiment of the present application provides an information processing method, which is applied to an electronic device. Referring to Figure 1 As shown, the method includes the following steps:
[0028] Step 101: If the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory.
[0029] In the embodiments of the present application, the firmware system includes, but is not limited to, a Basic Input Output System (BIOS) chip or a memory storing Basic Input Output System data, a Unified Extensible Firmware Interface (UEFI) chip, an Extensible Firmware Interface (EFI) chip, etc.
[0030] In the embodiments of the present application, the Serial Peripheral Interface (SPI) is a synchronous peripheral interface. The SPI is used to enable the firmware system to communicate with various peripheral devices in a serial manner, and then exchange information. Here, the peripheral devices include a Random Access Memory (RAM), a network controller, a Liquid Crystal Display (LCD) display driver, an analog to digital converter (A / D), and a Microcontroller Unit (MCU), etc.
[0031] In the embodiments of the present application, the SPI memory includes a main area and a backup area. Among them, the main area is used to store the secure version number of the firmware system image, and the backup area is used to store the secure version number of the backup firmware system image. The secure version number of the firmware system image is the same as the secure version number of the backup firmware system image.
[0032] In the embodiments of the present application, the Secure Version Number (SVN) is used to indicate that the update of the firmware system image includes updates that improve security and / or fix errors that pose security risks. Here, the first secure version number is the secure version number of the firmware system image stored in the main area of the SPI memory, and the first secure version number can be expressed as SPI_MAIN_BIOS_SVN.
[0033] In other embodiments of the present application, the electronic device can utilize the Replay Protection Monotonic Counter (RPMC) function in the SPI memory to record the secure version number of the firmware system image. Here, register access to the RPMC counter does not support decrement commands. Through read / increment operations, the purpose of directly using the register to implement the SVN of the firmware system image can be achieved.
[0034] In the embodiments of the present application, the function of the power-on self-test (POST) of the firmware system of the electronic device is to detect whether the key devices in the firmware system exist and can work properly. Here, the key devices include, but are not limited to, memory, graphics card, central processing unit (CPU), keyboard, floppy drive, hard disk, etc. It should be noted that the power-on self-test process of the firmware system of the electronic device is very fast, and users can hardly perceive this process.
[0035] In the embodiments of the present application, the firmware system image is the storage form of the files of the firmware system. The firmware system image can be understood as an exact copy of the files of the firmware system stored on one disk existing on another disk. The firmware system image includes, but is not limited to, BIOS image, UEFI image, and EFI image.
[0036] In the embodiments of the present application, the electronic device may include mobile terminal devices such as tablet computers, laptop computers, personal digital assistants (PDAs), etc., fixed terminal devices such as desktop computers, and servers. Here, the electronic device includes a firmware system, and the firmware system is used to boot the operating system (OS) in the electronic device.
[0037] In practical applications, after the electronic device is powered on, the firmware system of the electronic device performs a power-on self-test. And when the power-on self-test is completed, the electronic device obtains the first security version number of the firmware system image currently stored in the main area of the SPI memory.
[0038] Step 102: Obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device.
[0039] In the embodiments of the present application, the secure storage module can be understood as a storage module whose stored data in the storage block cannot be modified through a software or hardware burner. Here, the secure storage module includes an embedded controller (EC), a flash memory (FLASH), or an electrically erasable programmable read-only memory (EEPROM). Here, the embedded controller in the present application includes, but is not limited to, a traditional EC, or a controller (Embedded controller Super Input / Output, ESIO) that combines input / output functions and the functions of an embedded controller.
[0040] In the embodiments of the present application, the second security version number is the security version number of the firmware system image stored in the secure storage module of the electronic device, and the second security version number can be expressed as SPI_MAIN_BIOS_SVN_ARB. Here, the first security version number and the second security version number may be the same, or they may be different. For example, in the case where the firmware system involves a security update, the first security version number of the firmware system image stored in the main area may be greater than or equal to the second security version number of the firmware system image stored in the secure storage module. For another example, in the case where the firmware system involves a version rollback, the first security version number of the firmware system image stored in the main area may be less than the second security version number of the firmware system image stored in the secure storage module.
[0041] In the embodiments of the present application, when the power-on self-check of the firmware system of the electronic device is completed and the electronic device obtains the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory, the electronic device obtains the second security version number of the firmware system image stored in the secure storage module of the electronic device, so that the electronic device generates different detection results according to the association relationship between the first security version number and the second security version number.
[0042] Step 103: Generate a detection result that a physical attack has occurred on the serial peripheral interface memory based on the first association relationship between the first security version number and the second security version number.
[0043] In the embodiments of the present application, the first association relationship can represent the magnitude relationship between the first security version number and the second security version number, and the first association relationship can also represent the timeliness relationship between the first security version number and the second security version number. Here, the timeliness relationship refers to the sequence relationship of the update times of the firmware system image stored in the main area of the SPI and the firmware system image stored in the secure storage module. The present application does not make specific limitations on this.
[0044] In the embodiments of the present application, a physical attack on the serial peripheral interface memory includes a physical attack on the storage area in the serial peripheral interface memory, or no physical attack on the storage area in the serial peripheral interface memory. Exemplarily, a physical attack on the storage area in the serial peripheral interface memory can be understood as that the data stored in the storage area in the serial peripheral interface memory has been modified through a software or hardware burner; no physical attack on the storage area in the serial peripheral interface memory can be understood as that the data stored in the storage area in the serial peripheral interface memory has not been modified through a software or hardware burner.
[0045] In an embodiment of the present application, when the electronic device obtains the second security version number of the firmware system image stored in the secure storage module of the electronic device, it obtains the first association relationship between the first security version number and the second security version number, and generates a detection result of a physical attack on the serial peripheral interface memory based on the first association relationship.
[0046] Step 104: Perform power-on control on the electronic device based on the detection result.
[0047] In an embodiment of the present application, after the electronic device generates a detection result of a physical attack on the serial peripheral interface memory based on the first association relationship between the first security version number and the second security version number, it performs power-on control on the electronic device based on the detection result.
[0048] The information processing method provided by the embodiment of the present application, if the power-on self-check of the firmware system of the electronic device is completed, obtains the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory; obtains the second security version number of the firmware system image stored in the secure storage module of the electronic device; generates a detection result of a physical attack on the serial peripheral interface memory based on the first association relationship between the first security version number and the second security version number; performs power-on control on the electronic device based on the detection result; that is, the electronic device generates a detection result of whether a physical attack occurs on the SPI memory by effectively detecting the security version number of the firmware system image stored in the main area of the serial peripheral interface memory and the security version number of the firmware system image stored in the secure storage module, and then performs control on the power-on of the electronic device based on the detection result; thus, it avoids data leakage in the electronic device caused by an attacker using a physical attack on the SPI memory and protects the security of the electronic device.
[0049] An embodiment of the present application provides an information processing method, which is applied to an electronic device. Refer to Figure 2 As shown, the method includes the following steps:
[0050] Step 201: If the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory.
[0051] Step 202: Obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device.
[0052] Step 203: Obtain the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory.
[0053] In an embodiment of the present application, the serial peripheral interface memory includes a main area and a backup area. The main area is used to store the security version number of the firmware system image, and the backup area is used to store the security version number of the backup firmware system image. The security version number of the firmware system image is the same as the security version number of the backup firmware system image.
[0054] In an embodiment of the present application, the third security version number is the security version number of the backup firmware system image stored in the backup area of the SPI memory, and the third security version number can be expressed as SPI_BAK_BIOS_SVN.
[0055] Step 204: Obtain the fourth security version number of the backup firmware system image stored in the secure storage module.
[0056] In an embodiment of the present application, the fourth security version number is the security version number of the firmware system image stored in the secure storage module of the electronic device, and the fourth security version number can be expressed as SPI_BAK_BIOS_SVN_ARB. Here, the third security version number and the fourth security version number may be the same, or they may be different. For example, in the case where the firmware system involves a security update, the third security version number of the backup firmware system image stored in the backup area may be greater than the fourth security version number of the backup firmware system image stored in the secure storage module. For another example, in the case where the firmware system involves a version rollback, the third security version number of the backup firmware system image stored in the backup area may be less than the fourth security version number of the backup firmware system image stored in the secure storage module.
[0057] Step 205: If the first association relationship between the first security version number and the second security version number indicates that the first security version number is less than the second security version number, and the second association relationship between the third security version number and the fourth security version number indicates that the third security version number is greater than or equal to the fourth security version number, generate a detection result that the main area of the serial peripheral interface memory has been physically attacked.
[0058] In an embodiment of the present application, the second association relationship can indicate the magnitude relationship between the third security version number and the fourth security version number, and the second association relationship can also indicate the timeliness relationship between the third security version number and the fourth security version number. Here, the timeliness relationship refers to the chronological relationship between the update times of the backup firmware system image stored in the backup area of the SPI and the backup firmware system image stored in the secure storage module. Regarding this, the present application does not make specific limitations.
[0059] In an embodiment of the present application, first, if the power-on self-check of the firmware system of the electronic device is completed, the electronic device obtains the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory; obtains the second security version number of the firmware system image stored in the secure storage module of the electronic device; obtains the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory; obtains the fourth security version number of the backup firmware system image stored in the secure storage module. Secondly, the electronic device obtains the first association relationship between the first security version number and the second security version number, and the second association relationship between the third security version number and the fourth security version number; if the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, at this time, the electronic device generates a detection result that the main area of the SPI memory has been physically attacked.
[0060] In other embodiments of the present application, if the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, the electronic device replaces the backup firmware system image with the fourth security version number stored in the secure storage module with the backup firmware system image with the third security version number stored in the backup area of the serial peripheral interface memory; in this way, it is ensured that the security version number of the backup firmware system image stored in the secure storage module is consistent with the security version number of the backup firmware system image stored in the backup area of the SPI memory; further ensuring that in the case of a security update of the firmware system again, the security version number of the backup firmware system image stored in the secure storage module is the latest security version number.
[0061] Step 206: Use the backup firmware system image stored in the backup area to restore the firmware system image stored in the main area, and after the restoration is completed, control the electronic device to power on.
[0062] In an embodiment of the present application, when the electronic device generates a detection result that the main area of the serial peripheral interface memory has been physically attacked, the electronic device uses the backup firmware system image stored in the backup area to restore the firmware system image stored in the main area, and after the restoration is completed, controls the electronic device to power on.
[0063] As described above, in the embodiment of the present application, the electronic device determines that the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, indicating that during the automatic recovery process of the firmware system image, the firmware system image stored in the main area of the SPI memory is modified to an old version with security vulnerabilities, resulting in a version rollback and a flashback attack, which means that the main area of the SPI memory has been physically attacked; the backup firmware system image stored in the backup area of the SPI memory is normal, which means that the backup area of the SPI memory has not been physically attacked; at this time, the firmware system image stored in the main area is restored by using the backup firmware system image stored in the backup area; thus, when the electronic device effectively detects the security version numbers of the firmware system image and the backup firmware system image and determines that the main area of the SPI memory has been physically attacked but the backup area has not been physically attacked, it ensures that the security version number of the firmware system image stored in the main area of the SPI memory is the same as the security version number of the backup firmware system image stored in the backup area, so as to control the power-on of the electronic device through the restored firmware system image stored in the main area; thus, it avoids the attacker from continuing to execute attack operations on the electronic device by taking advantage of the security vulnerabilities existing in the old version of the firmware system image stored in the main area, thereby causing data leakage.
[0064] It should be noted that for the description of the same steps and the same content in this embodiment and other embodiments, reference may be made to the description in other embodiments, which will not be repeated here.
[0065] An embodiment of the present application provides an information processing method, which is applied to an electronic device. Refer to Figure 3 As shown, the method includes the following steps:
[0066] Step 301: If the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory.
[0067] Step 302: Obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device.
[0068] Step 303: Obtain the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory.
[0069] Step 304: Obtain the fourth security version number of the backup firmware system image stored in the secure storage module.
[0070] Step 305: If the first association relationship between the first security version number and the second security version number indicates that the first security version number is less than the second security version number, and the second association relationship between the third security version number and the fourth security version number indicates that the third security version number is less than the fourth security version number, generate a detection result that both the main area and the backup area of the serial peripheral interface memory have been physically attacked.
[0071] In the embodiments of the present application, first, if the power-on self-check of the firmware system of the electronic device is completed, the electronic device obtains the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory; obtains the second security version number of the firmware system image stored in the secure storage module of the electronic device; obtains the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory; and obtains the fourth security version number of the backup firmware system image stored in the secure storage module. Secondly, the electronic device obtains the first association relationship between the first security version number and the second security version number, and the second association relationship between the third security version number and the fourth security version number; if the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number, at this time, the electronic device generates a detection result that both the main area and the backup area of the SPI memory have been physically attacked.
[0072] Step 306: Record the detection result that both the main area and the backup area have been physically attacked, and prohibit the electronic device from booting.
[0073] In the embodiments of the present application, when the electronic device generates a detection result that both the main area and the backup area of the serial peripheral interface memory have been physically attacked, the electronic device records the detection result that both the main area and the backup area have been physically attacked, and prohibits the electronic device from booting.
[0074] As can be seen from the above, in the embodiments of the present application, the electronic device determines that the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number. This shows that during the automatic recovery process of the firmware system image, both the firmware system image stored in the main area of the SPI memory and the backup firmware system image in the backup area are modified to an old version with security vulnerabilities, resulting in a version rollback and a rollback attack. That is to say, both the main area and the backup area of the SPI memory are physically attacked. At this time, the electronic device records the detection result that both the main area and the backup area are physically attacked and prohibits the electronic device from powering on. In this way, by effectively detecting the security version numbers of the firmware system image and the backup firmware system image, when the electronic device determines that both the main area and the backup area of the SPI memory are physically attacked, it prohibits the electronic device from powering on, avoiding attackers from continuing to perform attack operations on the electronic device by exploiting security vulnerabilities in the old version, thereby preventing data leakage.
[0075] It should be noted that for the descriptions of the same steps and the same content in this embodiment and other embodiments, reference can be made to the descriptions in other embodiments, and details will not be repeated here.
[0076] An embodiment of the present application provides an information processing method applied to an electronic device. Referring to Figure 4 as shown, the method includes the following steps:
[0077] Step 401: If the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory.
[0078] Step 402: Obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device.
[0079] Step 403: Obtain the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory.
[0080] Step 404: Obtain the fourth security version number of the backup firmware system image stored in the secure storage module.
[0081] Step 405: If the first association relationship between the first security version number and the second security version number indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship between the third security version number and the fourth security version number indicates that the third security version number is less than the fourth security version number, generate a detection result that the backup area of the serial peripheral interface memory is physically attacked.
[0082] In an embodiment of the present application, first, if the power-on self-check of the firmware system of the electronic device is completed, the electronic device obtains the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory; obtains the second security version number of the firmware system image stored in the secure storage module of the electronic device; obtains the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory; obtains the fourth security version number of the backup firmware system image stored in the secure storage module. Secondly, the electronic device obtains the first association relationship between the first security version number and the second security version number, and the second association relationship between the third security version number and the fourth security version number; if the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number, at this time, the electronic device generates a detection result that the backup area of the SPI memory has been physically attacked.
[0083] In other embodiments of the present application, if the first association relationship indicates that the first security version number is greater than or equal to the second security version number, the electronic device replaces the firmware system image with the second security version number stored in the secure storage module with the firmware system image with the first security version number stored in the main area of the serial peripheral interface memory; in this way, it is ensured that the security version number of the firmware system image stored in the secure storage module is consistent with the security version number of the firmware system image stored in the main area of the SPI memory, and it is ensured that in the case of a security update of the firmware system again, the security version number of the firmware system image stored in the secure storage module is the latest security version number.
[0084] Step 406: Control the electronic device to power on based on the detection result that the backup area has been physically attacked, and use the firmware system image stored in the main area to restore the backup firmware system image stored in the backup area.
[0085] In an embodiment of the present application, when the electronic device generates a detection result that the backup area of the serial peripheral interface memory has been physically attacked, the electronic device controls the electronic device to power on based on the detection result that the backup area has been physically attacked, and uses the firmware system image stored in the main area to restore the backup firmware system image stored in the backup area.
[0086] As can be seen from the above, in the embodiment of the present application, the electronic device determines that the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number. This shows that during the automatic recovery process of the firmware system image, the firmware system image stored in the main area of the SPI memory is normal, which means that the main area of the SPI memory has not been physically attacked; the backup firmware system image stored in the backup area of the SPI memory has been modified to an old version with security vulnerabilities, resulting in version rollback and flashback attack, which means that the backup area of the SPI memory has been physically attacked; at this time, the electronic device determines that the physical attack on the backup area of the SPI memory is a physical attack with relatively low security; further, the electronic device controls the electronic device to power on and uses the firmware system image stored in the main area to restore the backup firmware system image stored in the backup area. In this way, when the electronic device effectively detects the security version numbers of the firmware system image and the backup firmware system image and determines that the main area of the SPI memory has not been physically attacked but the backup area has been physically attacked, it controls the electronic device to power on through the firmware system image stored in the main area and ensures that the security version number of the backup firmware system image stored in the backup area of the SPI memory is the same as that of the firmware system image stored in the main area; in this way, it avoids attackers from continuing to perform attack operations on the electronic device by taking advantage of the security vulnerabilities existing in the old version of the backup firmware system image stored in the backup area, thereby causing data leakage.
[0087] It should be noted that the descriptions of the same steps and the same content in this embodiment and other embodiments can be referred to the descriptions in other embodiments, and will not be repeated here.
[0088] An embodiment of the present application provides an information processing method, which is applied to an electronic device. Referring to Figure 5 as shown, the method includes the following steps:
[0089] Step 501, if the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory.
[0090] Step 502, obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device.
[0091] Step 503, obtain the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory.
[0092] Step 504, obtain the fourth security version number of the backup firmware system image stored in the secure storage module.
[0093] Step 505: If the first association relationship between the first security version number and the second security version number indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship between the third security version number and the fourth security version number indicates that the third security version number is greater than or equal to the fourth security version number, generate a detection result that neither the main area nor the backup area of the serial peripheral interface memory has been physically attacked.
[0094] In the embodiments of the present application, first, if the power-on self-check of the firmware system of the electronic device is completed, the electronic device obtains the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory; obtains the second security version number of the firmware system image stored in the secure storage module of the electronic device; obtains the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory; obtains the fourth security version number of the backup firmware system image stored in the secure storage module. Secondly, the electronic device obtains the first association relationship between the first security version number and the second security version number, and the second association relationship between the third security version number and the fourth security version number; if the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, at this time, the electronic device generates a detection result that neither the main area nor the backup area of the SPI memory has been physically attacked.
[0095] In other embodiments of the present application, if the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, the electronic device replaces the firmware system image with the second security version number stored in the secure storage module with the firmware system image with the first security version number stored in the main area of the serial peripheral interface memory; replaces the backup firmware system image with the fourth security version number stored in the secure storage module with the backup firmware system image with the third security version number stored in the backup area of the serial peripheral interface memory; in this way, it is ensured that the security version number of the firmware system image stored in the secure storage module is consistent with the security version number of the firmware system image stored in the main area of the SPI memory, and the security version number of the backup firmware system image stored in the secure storage module is consistent with the security version number of the backup firmware system image stored in the backup area of the SPI memory, ensuring that in the case of a security update of the firmware system again, the security version numbers of the firmware system image and the backup firmware system image stored in the secure storage module are the latest security version numbers.
[0096] Step 506: Based on the detection result that neither the main area nor the backup area has been physically attacked, control the electronic device to boot.
[0097] In the embodiment of the present application, when the detection result that neither the main area nor the backup area of the serial peripheral interface memory is physically attacked is generated by the electronic device, the electronic device is controlled to perform a boot operation.
[0098] As can be seen from the above, in the embodiment of the present application, when the electronic device determines that the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, it means that during the automatic recovery process of the firmware system image, the firmware system image stored in the main area of the SPI memory and the backup firmware system image in the backup area are both normal, that is, it means that neither the main area nor the backup area of the SPI memory is physically attacked; further, the electronic device controls the electronic device to perform a boot operation. In this way, when the electronic device effectively detects the security version numbers of the firmware system image and the backup firmware system image and determines that neither the main area nor the backup area of the SPI memory is physically attacked, the electronic device is controlled to boot; in this way, the security of the electronic device is ensured and data leakage in the electronic device is avoided.
[0099] It should be noted that for the description of the same steps and the same content in this embodiment and other embodiments, reference may be made to the description in other embodiments, and details are not described herein again.
[0100] An embodiment of the present application provides an information processing method, which is applied to an electronic device. Referring to Figure 6 as shown, the method includes the following steps:
[0101] Step 601: If the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory.
[0102] Step 602: Obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device.
[0103] Step 603: Obtain the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory.
[0104] Step 604: Obtain the fourth security version number of the backup firmware system image stored in the secure storage module.
[0105] Step 605: If the first association relationship between the first security version number and the second security version number indicates that the first security version number is greater than or equal to the second security version number, obtain the first version number of the firmware system image stored in the main area.
[0106] In the embodiments of the present application, the version number is used to indicate that the update of the firmware system image does not involve an update that improves security and / or fixes errors that pose security risks. Here, the first version number is the version number of the firmware system image stored in the main area of the SPI memory, and the first version number can be expressed as SPI_MAIN_BIOS_VER.
[0107] Step 606: Obtain the second version number of the firmware system image stored in the secure storage module.
[0108] In the embodiments of the present application, the second version number is the version number of the firmware system image stored in the secure storage module, and the second version number can be expressed as SPI_MAIN_BIOS_VER_ARB.
[0109] Step 607: If the first version number is less than the second version number, generate a detection result that the main area of the serial peripheral interface memory has been physically attacked but the security of the firmware system has not been reduced.
[0110] In the embodiments of the present application, if the power-on self-test of the firmware system of the electronic device is completed, the electronic device obtains the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory; obtains the second security version number of the firmware system image stored in the secure storage module of the electronic device; obtains the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory; obtains the fourth security version number of the backup firmware system image stored in the secure storage module; if the first association relationship between the first security version number and the second security version number indicates that the first security version number is greater than or equal to the second security version number, obtains the first version number of the firmware system image stored in the main area; obtains the second version number of the firmware system image stored in the secure storage module; if the first version number is less than the second version number, at this time, the electronic device generates a detection result that the main area of the serial peripheral interface memory has been physically attacked but the security of the firmware system has not been reduced.
[0111] Step 608: Based on the detection result that the main area has been physically attacked but the security of the firmware system has not been reduced, control the electronic device to power on.
[0112] In the embodiments of the present application, when the electronic device generates a detection result that the main area of the serial peripheral interface memory has been physically attacked but the security of the firmware system has not been reduced, control the electronic device to perform a power-on operation.
[0113] As can be seen from the above, in the embodiment of the present application, when the electronic device determines that the first association relationship indicates that the first security version number is greater than or equal to the second security version number and the first version number is less than the second version number, it means that during the automatic recovery process of the firmware system image, the main area of the SPI memory has been physically attacked, but the security of the firmware system is not reduced; further, the electronic device controls the electronic device to perform a power-on operation. In this way, when the electronic device effectively detects the security version number and version number of the firmware system image and determines that the main area of the SPI memory has been physically attacked but the security of the firmware system is not reduced, it controls the electronic device to power on, records the detection result, and timely reminds the user; in this way, the security of the electronic device is ensured, and the leakage of security data in the electronic device is avoided.
[0114] It should be noted that for the descriptions of the same steps and the same content in this embodiment and other embodiments, reference may be made to the descriptions in other embodiments, and details are not described herein again.
[0115] An embodiment of the present application provides an information processing method, which is applied to an electronic device. Refer to Figure 7 As shown, the method includes the following steps 701 to step 705; or steps 701 to step 704, step 706; or steps 701 to step 702, and steps 707 to step 710; or steps 701 to step 702, steps 707 to step 709, and steps 711 to step 714; or steps 701 to step 702, steps 707 to step 709, steps 711 to step 713, and steps 715 to step 716:
[0116] Step 701: If the power-on self-check of the firmware system of the electronic device is completed, the electronic device obtains the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory and the second security version number of the firmware system image stored in the secure storage module of the electronic device.
[0117] Step 702: The electronic device determines whether the first security version number is greater than or equal to the second security version number.
[0118] In the embodiment of the present application, the electronic device determines whether the first security version number is greater than or equal to the second security version number. If not, step 703 is executed; if so, step 707 is executed.
[0119] Step 703: Obtain the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory and the fourth security version number of the backup firmware system image stored in the secure storage module.
[0120] Step 704: The electronic device determines whether the third security version number is greater than or equal to the fourth security version number.
[0121] In the embodiments of the present application, the electronic device determines whether the third security version number is greater than or equal to the fourth security version number. If so, step 705 is executed; if not, step 706 is executed.
[0122] Step 705: The electronic device generates a detection result that the main area of the serial peripheral interface memory has been physically attacked, and restores the firmware system image stored in the main area with the backup firmware system image stored in the backup area. After the restoration is completed, the electronic device is controlled to power on.
[0123] Step 706: The electronic device generates a detection result that both the main area and the backup area of the serial peripheral interface memory have been physically attacked, records the detection result that both the main area and the backup area have been physically attacked, and prohibits the electronic device from powering on.
[0124] Step 707: The electronic device replaces the firmware system image with the second security version number stored in the secure storage module with the firmware system image with the first security version number stored in the main area of the serial peripheral interface memory.
[0125] Step 708: The electronic device obtains the first version number of the firmware system image stored in the main area and the second version number of the firmware system image stored in the secure storage module.
[0126] Step 709: The electronic device determines whether the first version number is greater than or equal to the second version number.
[0127] In the embodiments of the present application, the electronic device determines whether the first version number is greater than or equal to the second version number. If not, step 710 is executed; if so, step 711 is executed.
[0128] Step 710: The electronic device generates a detection result that the main area of the serial peripheral interface memory has been physically attacked but the security of the firmware system has not been reduced. Based on the detection result that the main area has been physically attacked but the security of the firmware system has not been reduced, the electronic device is controlled to power on.
[0129] Step 711: The electronic device replaces the firmware system image with the second version number stored in the secure storage module with the firmware system image with the first version number stored in the main area of the serial peripheral interface memory.
[0130] Step 712: The electronic device obtains the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory and the fourth security version number of the backup firmware system image stored in the secure storage module.
[0131] Step 713: The electronic device determines whether the third security version number is greater than or equal to the fourth security version number.
[0132] In the embodiment of the present application, the electronic device determines whether the third security version number is greater than or equal to the fourth security version number. If not, step 714 is executed; if so, step 715 is executed.
[0133] Step 714: The electronic device generates a detection result that the backup area of the serial peripheral interface memory has been physically attacked. Based on the detection result that the backup area has been physically attacked, the electronic device is controlled to power on, and the firmware system image stored in the main area is used to restore the backup firmware system image stored in the backup area.
[0134] Step 715: The electronic device replaces the backup firmware system image with the fourth security version number stored in the secure storage module with the backup firmware system image with the third security version number stored in the backup area of the serial peripheral interface memory.
[0135] Step 716: The electronic device generates a detection result that neither the main area nor the backup area of the serial peripheral interface memory has been physically attacked. Based on the detection result that neither the main area nor the backup area has been physically attacked, the electronic device is controlled to perform a power-on operation.
[0136] As can be seen from the above, in the embodiment of the present application, the electronic device generates a detection result of whether a physical attack has occurred in the main area and the backup area of the SPI memory by effectively detecting the security version number of the firmware system image and the security version number of the backup firmware system image, and then controls the power-on of the electronic device based on the detection result; in this way, the security of the electronic device is ensured, and the attacker is prevented from continuing to attack the electronic device by taking advantage of the security vulnerabilities existing in the old version of the backup firmware system image stored in the backup area, and data leakage in the electronic device is avoided.
[0137] It should be noted that the descriptions of the same steps and the same content in this embodiment and other embodiments can be referred to the descriptions in other embodiments, and will not be repeated here.
[0138] An embodiment of the present application provides an information processing device, which can be applied to Figures 1 - 6 In the corresponding information processing method provided by the embodiment, refer to Figure 8 As shown, the information processing device 8 includes:
[0139] An acquisition module 801, configured to obtain a first security version number of a firmware system image stored in a main area of a serial peripheral interface memory if the power-on self-check of the firmware system of the electronic device is completed;
[0140] The acquisition module 801 is further configured to obtain a second security version number of a firmware system image stored in a secure storage module of the electronic device;
[0141] A generating module 802, configured to generate a detection result of a physical attack on a serial peripheral interface memory based on a first association relationship between a first security version number and a second security version number;
[0142] A processing module 803, configured to perform power-on control on the electronic device based on the detection result.
[0143] In other embodiments of the present application, an obtaining module 801 is further configured to obtain a third security version number of a backup firmware system image stored in a backup area of the serial peripheral interface memory; obtain a fourth security version number of the backup firmware system image stored in the secure storage module; the generating module 802 is further configured to generate a detection result based on the first association relationship and a second association relationship between the third security version number and the fourth security version number.
[0144] In other embodiments of the present application, the generating module 802 is further configured to, if the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, generate a detection result of a physical attack on the main area of the serial peripheral interface memory.
[0145] In other embodiments of the present application, the processing module 803 is further configured to use the backup firmware system image stored in the backup area to restore the firmware system image stored in the main area, and control the electronic device to power on after the restoration is completed.
[0146] In other embodiments of the present application, the generating module 802 is further configured to, if the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number, generate a detection result of physical attacks on both the main area and the backup area of the serial peripheral interface memory.
[0147] In other embodiments of the present application, the processing module 803 is further configured to record the detection result of physical attacks on both the main area and the backup area, and prohibit the electronic device from powering on.
[0148] In other embodiments of the present application, the generating module 802 is further configured to, if the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number, generate a detection result of a physical attack on the backup area of the serial peripheral interface memory.
[0149] In other embodiments of the present application, the processing module 803 is further configured to control the electronic device to power on based on the detection result of a physical attack on the backup area, and use the firmware system image stored in the main area to restore the backup firmware system image stored in the backup area.
[0150] In other embodiments of the present application, the generating module 802 is further configured to generate a detection result that neither the main area nor the backup area of the serial peripheral interface memory has been physically attacked if the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number; the processing module 803 is further configured to control the electronic device to power on based on the detection result that neither the main area nor the backup area has been physically attacked.
[0151] In other embodiments of the present application, the obtaining module 801 is further configured to obtain the first version number of the firmware system image stored in the main area if the first association relationship indicates that the first security version number is greater than or equal to the second security version number; obtain the second version number of the firmware system image stored in the secure storage module; the generating module 802 is further configured to generate a detection result that the main area of the serial peripheral interface memory has been physically attacked but the security of the firmware system has not been compromised if the first version number is less than the second version number; the processing module 803 is further configured to control the electronic device to power on based on the detection result that the main area has been physically attacked but the security of the firmware system has not been compromised.
[0152] An embodiment of the present application provides an electronic device, which can be applied to Figures 1 - 6 In a corresponding information display method provided by an embodiment, refer to Figure 9 As shown, the electronic device 9 includes: a processor 901, a memory 902, and a communication bus 903, where:
[0153] If the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory;
[0154] Obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device;
[0155] Generate a detection result of a physical attack on the serial peripheral interface memory based on the first association relationship between the first security version number and the second security version number;
[0156] Control the power-on of the electronic device based on the detection result.
[0157] In other embodiments of the present application, the processor 901 is configured to execute the information processing program stored in the memory 902 to implement the following steps:
[0158] Obtain the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory; obtain the fourth security version number of the backup firmware system image stored in the secure storage module; generate a detection result based on the first association relationship and the second association relationship between the third security version number and the fourth security version number.
[0159] In other embodiments of the present application, the processor 901 is configured to execute the information processing program stored in the memory 902 to implement the following steps:
[0160] If the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, generate a detection result that the main area of the serial peripheral interface memory has been physically attacked.
[0161] In other embodiments of the present application, the processor 901 is configured to execute the information processing program stored in the memory 902 to implement the following steps:
[0162] Restore the firmware system image stored in the main area with the backup firmware system image stored in the backup area, and control the electronic device to power on after the restoration is completed.
[0163] In other embodiments of the present application, the processor 901 is configured to execute the information processing program stored in the memory 902 to implement the following steps:
[0164] If the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number, generate a detection result that both the main area and the backup area of the serial peripheral interface memory have been physically attacked.
[0165] In other embodiments of the present application, the processor 901 is configured to execute the information processing program stored in the memory 902 to implement the following steps:
[0166] Record the detection result that both the main area and the backup area have been physically attacked, and prohibit the electronic device from powering on.
[0167] In other embodiments of the present application, the processor 901 is configured to execute the information processing program stored in the memory 902 to implement the following steps:
[0168] If the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number, generate a detection result that the backup area of the serial peripheral interface memory has been physically attacked.
[0169] In other embodiments of the present application, the processor 901 is configured to execute the information processing program stored in the memory 902 to implement the following steps:
[0170] Control the electronic device to power on based on the detection result that the backup area has been physically attacked, and restore the backup firmware system image stored in the backup area with the firmware system image stored in the main area.
[0171] In other embodiments of the present application, the processor 901 is configured to execute an information processing program stored in the memory 902 to implement the following steps:
[0172] If the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, generate a detection result that neither the main area nor the backup area of the serial peripheral interface memory has been physically attacked; based on the detection result that neither the main area nor the backup area has been physically attacked, control the electronic device to power on.
[0173] In other embodiments of the present application, the processor 901 is configured to execute an information processing program stored in the memory 902 to implement the following steps:
[0174] If the first association relationship indicates that the first security version number is greater than or equal to the second security version number, obtain the first version number of the firmware system image stored in the main area; obtain the second version number of the firmware system image stored in the secure storage module; if the first version number is less than the second version number, generate a detection result that the main area of the serial peripheral interface memory has been physically attacked but the security of the firmware system is not reduced; based on the detection result that the main area has been physically attacked but the security of the firmware system is not reduced, control the electronic device to power on.
[0175] As an example, the processor 901 may be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or any conventional processor, etc.
[0176] It should be noted that for the specific implementation process of the steps executed by the processor in this embodiment, reference may be made to Figures 1 - 6 the implementation process in the information display method provided in the corresponding embodiment, which will not be elaborated here.
[0177] Embodiments of the present application provide a computer-readable storage medium, which stores one or more programs that can be executed by one or more processors to implement Figures 1 - 6 the implementation process in the information display method provided in the corresponding embodiment, which will not be elaborated here.
[0178] The description of the above device embodiments is similar to the description of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0179] It should be noted that in the embodiments of the present application, if the above-mentioned information processing method is implemented in the form of software function modules and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application essentially or the part that contributes to the related technology can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a terminal device to execute all or part of the methods of the various embodiments of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), magnetic disks, or optical discs and other various media that can store program codes. In this way, the embodiments of the present application are not limited to any specific combination of hardware and software.
[0180] The embodiments of the present application provide a computer storage medium. The computer storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the information processing method in any of the above embodiments.
[0181] It should be pointed out here that the descriptions of the above storage medium and device embodiments are similar to those of the above method embodiments and have beneficial effects similar to those of the method embodiments. For the technical details not disclosed in the storage medium and device embodiments of the present application, please refer to the descriptions of the method embodiments of the present application for understanding.
[0182] The above computer storage medium / memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM), etc.; it can also be various terminals including one or any combination of the above memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0183] It should be understood that the "one embodiment" or "an embodiment" or "the embodiments of the present application" or "the foregoing embodiments" or "some embodiments" or "some implementation manners" mentioned throughout the specification mean that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the "in one embodiment" or "in an embodiment" or "the embodiments of the present application" or "the foregoing embodiments" or "some embodiments" or "some implementation manners" that appear throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics may be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution, and the order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The sequence numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.
[0184] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the couplings between the components shown or discussed, or direct couplings, or communication connections can be through some interfaces, and the indirect couplings or communication connections of devices or units can be electrical, mechanical or other forms.
[0185] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units; they can be located in one place or distributed to multiple network units; some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0186] In addition, each functional unit in the embodiments of the present application can be all integrated in one processing unit, or each unit can be separately used as one unit, or two or more units can be integrated in one unit; the above integrated units can be implemented in the form of hardware, or in the form of hardware plus software functional units.
[0187] The methods disclosed in several method embodiments provided by the present application can be combined arbitrarily without conflict to obtain new method embodiments.
[0188] The features disclosed in several method or device embodiments provided by the present application can be combined arbitrarily without conflict to obtain new method embodiments or device embodiments.
[0189] Those of ordinary skill in the art can understand that all or part of the steps to implement the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes: various media such as removable storage devices, read-only memory (ROM), magnetic disks, or optical discs that can store program codes.
[0190] Alternatively, if the above integrated units of the present application are implemented in the form of software function modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application, in essence or the part that contributes to the related art, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present application. And the foregoing storage medium includes: various media such as removable storage devices, ROM, magnetic disks, or optical discs that can store program codes.
[0191] It should be noted that the drawings in the embodiments of the present application are only for illustrating the schematic positions of the respective components on the terminal device and do not represent their actual positions in the terminal device. The actual positions of the components or each region can be changed or offset according to the actual situation (for example, the structure of the terminal device). Moreover, the ratios of different parts in the terminal device in the figure do not represent the actual ratios.
[0192] The above is only the implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claimed rights.
Claims
1. An information processing method, the method comprising: If the power-on self-check of the firmware system of the electronic device is completed, obtain the first security version number of the firmware system image stored in the main area of the serial peripheral interface memory; Obtain the second security version number of the firmware system image stored in the secure storage module of the electronic device; Generate a detection result of a physical attack on the serial peripheral interface memory based on a first association relationship between the first security version number and the second security version number; Perform power-on control on the electronic device based on the detection result; Wherein, the performing power-on control on the electronic device based on the detection result includes one of the following: When the detection result is that the main area of the serial peripheral interface memory has been physically attacked, restore the firmware system image stored in the main area with the backup firmware system image stored in the backup area of the serial peripheral interface memory, and control the electronic device to power on after the restoration is completed; When the detection result is that both the main area and the backup area of the serial peripheral interface memory have been physically attacked, record the detection result that both the main area and the backup area have been physically attacked, and prohibit the electronic device from powering on; When the detection result is that the backup area of the serial peripheral interface memory has been physically attacked, control the electronic device to power on, and restore the backup firmware system image stored in the backup area with the firmware system image stored in the main area; When the detection result is that neither the main area nor the backup area of the serial peripheral interface memory has been physically attacked, control the electronic device to power on; When the detection result is that the main area of the serial peripheral interface memory has been physically attacked but the security of the firmware system is not reduced, control the electronic device to power on.
2. The method according to claim 1, wherein the generating a detection result of a physical attack on the serial peripheral interface memory based on a first association relationship between the first security version number and the second security version number includes: Obtain the third security version number of the backup firmware system image stored in the backup area of the serial peripheral interface memory; Obtain the fourth security version number of the backup firmware system image stored in the secure storage module; Generate the detection result based on the first association relationship and a second association relationship between the third security version number and the fourth security version number.
3. The method according to claim 2, wherein the generating the detection result based on the first association relationship and a second association relationship between the third security version number and the fourth security version number includes: If the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, generate a detection result that the main area of the serial peripheral interface memory has been physically attacked.
4. The method according to claim 2, wherein generating the detection result based on the first association relationship and the second association relationship between the third security version number and the fourth security version number comprises: If the first association relationship indicates that the first security version number is less than the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number, generate a detection result that both the main area and the backup area of the serial peripheral interface memory have been physically attacked.
5. The method according to claim 2, wherein generating the detection result based on the first association relationship and the second association relationship between the third security version number and the fourth security version number comprises: If the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is less than the fourth security version number, generate a detection result that the backup area of the serial peripheral interface memory has been physically attacked.
6. The method according to claim 2, wherein generating the detection result based on the first association relationship and the second association relationship between the third security version number and the fourth security version number comprises: If the first association relationship indicates that the first security version number is greater than or equal to the second security version number, and the second association relationship indicates that the third security version number is greater than or equal to the fourth security version number, generate a detection result that neither the main area nor the backup area of the serial peripheral interface memory has been physically attacked.
7. The method according to claim 1, wherein generating the detection result that the serial peripheral interface memory has been physically attacked based on the first association relationship between the first security version number and the second security version number comprises: If the first association relationship indicates that the first security version number is greater than or equal to the second security version number, obtain the first version number of the firmware system image stored in the main area; Obtain the second version number of the firmware system image stored in the security storage module; If the first version number is less than the second version number, generate a detection result that the main area of the serial peripheral interface memory has been physically attacked but the security of the firmware system is not compromised.
Citation Information
Patent Citations
Secure replay protected storage
CN103988185A
Method for providing anti-rollback protection in device which has no internal non-volatile memory
CN104798040A