Flash package encryption method, device, electronic device and computer storage medium

By encrypting the partition files of the flash package features, signatures and partition identification data, the problem of easy mixed use and illegal modification of the flash package is solved, and the secure encryption and legal installation of the flash package is realized.

CN114424193BActive Publication Date: 2025-08-26SHENZHEN HEYTAP TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201980100601.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-11-27
Publication Date
2025-08-26
Estimated Expiration
2039-11-27

AI Technical Summary

Technical Problem

The existing flash package encryption method requires the user to manually enter the password to verify, and it cannot identify whether the flash package has been illegally modified. Different versions of flash packages are easy to mix and affect the interests of operators.

Method used

Each partition file in the flash package is encrypted with feature data, signature data and partition identification data, and generate feature encryption data, signature encryption data and partition identification encryption data, and confirm the version information and security of the flash package through the identity identification code.

Benefits of technology

It realizes the secure encryption of the flash package, prevents the mixed use of different versions, ensures the security and legal installation of the flash package, and protects the interests of the operator.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114424193B_ABST
    Figure CN114424193B_ABST
Patent Text Reader

Abstract

A flash package encryption method, device, electronic device, and computer storage medium are disclosed. The method encrypts the characteristic data of each partition file in the flash package to obtain characteristic encrypted data; processes the signature data of each partition file in the flash package to obtain signature encrypted data; and processes the partition identification data of each partition file in the flash package to obtain partition identification encrypted data. The encrypted flash package is determined based on the characteristic encrypted data, signature encrypted data, and partition identification encrypted data. An identity code containing version information can be used to confirm whether the flash package can be installed on the current terminal, thereby protecting the security of the flash package while preventing the mixing of different versions of the flash package.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a flash package encryption method, device, electronic device and computer storage medium. Background Art

[0002] With the development of technology, terminals need to install flashing packages to update the operating system. Due to the diversification of the market, users can be divided into many categories. Different types of users require different versions of flashing packages to obtain operating systems with different permissions. If the operator's system is installed on the terminal of an ordinary user, it may harm the interests of the operator.

[0003] Therefore, different versions of flash packages need to be encrypted to avoid the above situation. The currently commonly used encryption method requires users to manually enter a preset password for verification, but this is very inconvenient and cannot identify whether the flash package has been illegally modified. Summary of the Invention

[0004] Based on the above problems, this application proposes a flash package encryption method, device, electronic device and computer storage medium, which can protect the security of the flash package while preventing different versions of flash packages from being mixed.

[0005] A first aspect of an embodiment of the present application provides a flash package encryption method, the method comprising:

[0006] Encrypting characteristic data of each partition file in the flash package to obtain characteristic encrypted data, wherein the characteristic data includes any fragment of each partition file;

[0007] Processing the signature data of each partition file in the flash package to obtain signature encryption data, wherein the signature data is used to represent the version information of the flash package;

[0008] Processing the partition identification data of each partition file in the flash package to obtain partition identification encrypted data, wherein the partition identification data is used to indicate the type of each partition file;

[0009] The encrypted flashing package is determined according to the feature encrypted data, the signature encrypted data and the partition identifier encrypted data.

[0010] A second aspect of the present application provides a flash package encryption device, the device comprising a processing unit and a communication unit, wherein:

[0011] The processing unit is configured to encrypt characteristic data of each partition file in the flash package to obtain characteristic encrypted data, wherein the characteristic data includes any segment of each partition file;

[0012] Processing the signature data of each partition file in the flash package to obtain signature encryption data, wherein the signature data is used to represent the version information of the flash package;

[0013] Processing the partition identification data of each partition file in the flash package to obtain partition identification encrypted data, wherein the partition identification data is used to indicate the type of each partition file;

[0014] The encrypted flashing package is determined according to the feature encrypted data, the signature encrypted data and the partition identifier encrypted data.

[0015] A third aspect of an embodiment of the present application provides an electronic device, comprising a multi-core processor, a communication interface and a memory, wherein the multi-core processor, the communication interface and the memory are interconnected, wherein the memory is used to store a computer program, the computer program includes program instructions, and the multi-core processor is configured to call the program instructions to execute the method described in any step of the first aspect of the embodiment of the present application.

[0016] A fourth aspect of an embodiment of the present application provides a computer storage medium, which stores a computer program. The computer program includes program instructions, which, when executed by a processor, enable the processor to execute the method described in any step of the first aspect of the embodiment of the present application.

[0017] A fifth aspect of the present application provides a computer program product, wherein the computer program product includes a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a computer to execute some or all of the steps described in any method of the first aspect of the present application. The computer program product may be a software installation package.

[0018] By implementing the above application embodiments, the following beneficial effects can be achieved:

[0019] The above-mentioned flash package encryption method, device, electronic device and computer storage medium encrypt the characteristic data of each partition file in the flash package to obtain characteristic encrypted data, wherein the characteristic data includes any fragment of each partition file; processes the signature data of each partition file in the flash package to obtain signature encrypted data, wherein the signature data is used to represent the version information of the flash package; processes the partition identification data of each partition file in the flash package to obtain partition identification encrypted data, wherein the partition identification data is used to represent the type of each partition file; and determines the encrypted flash package based on the characteristic encrypted data, the signature encrypted data and the partition identification encrypted data. Whether the flash package can be installed on the current terminal can be confirmed by an identity code containing version information, thereby protecting the security of the flash package while preventing the mixing of different versions of the flash package. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0021] Figure 1 A schematic diagram of the contents of the flash package provided in an embodiment of the present application;

[0022] Figure 2 This is a system architecture diagram of the flash package encryption method provided in an embodiment of the present application;

[0023] Figure 3 A schematic diagram of a flash package encryption method provided in an embodiment of the present application;

[0024] Figure 4 A schematic diagram of the structure of an encrypted flash package provided in an embodiment of the present application;

[0025] Figure 5 A flowchart of another flash package encryption method provided in an embodiment of the present application;

[0026] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application;

[0027] Figure 7 This is a block diagram of the structural units of a flash package encryption device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0028] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0029] The terms "first," "second," and so on, in the description and claims of the present invention and the accompanying drawings are used to distinguish between different objects, not to describe a specific order. Furthermore, the terms "including," "having," and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.

[0030] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0031] The electronic devices and terminals involved in the embodiments of the present application may include various handheld devices, vehicle-mounted devices, wearable devices, computing devices or other processing devices connected to a wireless modem with wireless communication functions, as well as various forms of user equipment (UE), mobile stations (MS), terminal devices, etc.

[0032] Currently, if Figure 1 As shown, Figure 1 Schematic diagram of the contents of the flash package provided in the embodiment of the present application. The flash package may be an application program for rewriting the contents of the terminal's memory (Read Only Memory, ROM) storing the firmware code. Figure 1 Including all partition files of the flash package. Taking the Android system as an example, all files can be classified into boot boot (Little Kernel, LK) partition files, operating system Linux kernel partition files, Android system framework partition files and user data partition files, etc., which are not listed here one by one. Figure 1The flash package in the package is not encrypted, and any partition file in the package can be modified directly. It is possible that a flash package with specific permissions will be installed on a user terminal that cannot use the specific permissions, such as installing an operator version of the flash package on an ordinary user's terminal, which will cause losses to the operator.

[0033] Based on the above problems, the embodiments of the present application provide a flash package encryption method, device, electronic device and computer storage medium. Figure 2 The system architecture of the flash package encryption method in the embodiment of this application is described in detail. Figure 2 The system architecture diagram of the flash package encryption method provided in the embodiment of the present application includes: a user terminal 210 and a server 220. The above-mentioned user terminal 210 can be any electronic device with a network connection function. The above-mentioned server 220 can have a built-in database to encrypt the flash package and save the encrypted flash package data in the database. The above-mentioned user terminal 210 can be connected to the above-mentioned server 220 by wire or wirelessly. When decrypting the encrypted flash package, the above-mentioned server 220 can obtain the identification of the above-mentioned user terminal 210 and determine whether the above-mentioned encrypted flash package can be decrypted and installed on the user terminal 210.

[0034] It can be seen that the above system structure can confirm whether the flash package can be installed on the current terminal through the identity identification code containing version information, while protecting the security of the flash package and preventing different versions of the flash package from being mixed.

[0035] The following combination Figure 3 A flash package encryption method in an embodiment of the present application is described in detail. Figure 3 A flowchart of a flash package encryption method provided in an embodiment of the present application specifically includes the following steps:

[0036] Step 301: Encrypt the characteristic data of each partition file in the flash package to obtain characteristic encrypted data.

[0037] Among them, each of the above-mentioned partition files corresponds to a characteristic data, and the above-mentioned characteristic data can be any fragment of the partition file. The characteristic data of the preset address of each partition file in the flashing package can be obtained first. The above-mentioned preset address is used to indicate the position of the above-mentioned characteristic data in the corresponding above-mentioned partition file. For example, the 256KB fragment of the partition file header can be set as the preset address. At this time, the 256KB data at the header of each partition file is the characteristic data.

[0038] The characteristic data of each partition file can be encrypted by an asymmetric encryption algorithm (RSA algorithm) to obtain a characteristic encrypted data. Specifically, Figure 1 Take the flashing package in as an example to illustrate, first, you can create a new empty file in ofp format and name it rom, that is, rom.ofp file, then read the 256KB data at the header of the boot partition file, encrypt it with the RSA algorithm, and save the characteristic encrypted data corresponding to the above boot partition file to the front of the above rom.ofp file, and save the remaining data in the above boot partition file except the above characteristic data to the back of the above rom.ofp file. Similarly, you can encrypt the 256KB data at the header of the operating system Linux kernel partition file, the 256KB data at the header of the Android system framework partition file, and the 256KB data at the header of the user data partition file in turn to obtain the corresponding characteristic encrypted data, and save the above characteristic encrypted data in the above rom.ofp file in turn. The remaining data of all the above partition files except the encrypted characteristic data are also appended and saved to the back of the above rom.ofp file.

[0039] The characteristic data of each partition file in the flashing package is encrypted by the above-mentioned server to obtain characteristic encrypted data. The characteristic data of each partition file is unique, which can avoid confusion between encrypted characteristic data. There is no need to encrypt all the data of the partition file, which can greatly improve the efficiency of the encryption step.

[0040] Step 302: Process the signature data of each partition file in the flash package to obtain signature encrypted data.

[0041] Among them, the above-mentioned signature data can be the data brought by each of the above-mentioned partition files, which is used to indicate the source of the flashing package. It should be noted that the above-mentioned signature data is signature data generated by the RSA algorithm and can be represented by a character string.

[0042] Among them, the signature data of each partition file in the above-mentioned flash package can be obtained and merged to obtain a full signature data. Specifically, a new full signature file AllSignatureFile can be created, and then the signature data of each partition file can be extracted, combined into a full signature data and saved to the above-mentioned AllSignatureFile file. The above-mentioned AllSignatureFile file can be appended and saved to the back of the above-mentioned rom.ofp file. Then, the above-mentioned full signature data can be encrypted by a hash algorithm to obtain the above-mentioned signature encryption data. The above-mentioned signature encryption data may include version identification information. It should be noted that the above-mentioned hash algorithm can be a SHA256 algorithm. The hash value used by the SHA256 algorithm is 256 bits. The SHA256 algorithm can obtain 256Bit binary data, that is, 64 characters. The 64 characters are the above-mentioned signature encryption data, which is used to represent the version information of the flash package.

[0043] By processing the signature data of each partition file in the flash package through the above-mentioned server to obtain signature encryption data, the version information of the flash package can be encrypted to prevent different versions of flash packages from being mixed.

[0044] Step 303: Process the partition identification data of each partition file in the flashing package to obtain partition identification encrypted data.

[0045] Among them, the above-mentioned partition identification data can be a structure variable. Specifically, the partition name, partition offset address and partition checksum of each partition file in the above-mentioned flashing package can be obtained first; the partition name, partition offset address and partition checksum of each partition file are merged into structure variable data; the above-mentioned structure variable data is encrypted by the RSA algorithm to obtain the above-mentioned partition identification encrypted data. The above-mentioned partition offset address can be used to indicate the position of the above-mentioned partition file in the rom.ofp file, and the above-mentioned partition checksum can be used to indicate the integrity of the transmission of the above-mentioned partition file. The above-mentioned structure variable data includes the identification information of each of the above-mentioned partition files. The above-mentioned partition identification encrypted data can finally be saved in the database of the server, and can be called during decryption to determine the decryption path of each partition file.

[0046] By processing the partition identification data of each partition file in the flashing package through the above-mentioned server to obtain partition identification encrypted data, the partition files in the flashing package can be prevented from being tampered with, thereby greatly improving the security of the flashing package.

[0047] Step 304: Determine the encrypted flashing package based on the feature encrypted data, the signature encrypted data, and the partition identifier encrypted data.

[0048] The encrypted feature data can be saved to the header of a preset format file, and the encrypted signature data and partition identification data can be saved to the tail of the preset format file. The preset format file is used to represent the encrypted flash package. The rom.ofp file obtained after the above steps is the encrypted flash package.

[0049] To explain the above flash package encryption method in more detail, Figure 4 The structure of the encrypted flash package in the embodiment of the present application is described. Figure 4 This is a structural diagram of an encrypted flash package. As shown in the figure, the leftmost part is the structure of the encrypted flash package, including the boot partition, the operating system Linux kernel partition, the Android system framework partition, and the user data partition. Each partition consists of three parts. The first part is the encrypted 256kb binary data, the second part is the remaining data in the partition, which can be compiled and converted into binary data by the server, and the third part is the RSA signature, which is used to verify the source of the partition file. That is, the RSA signature can be used to determine whether the partition file has been tampered with. If the flash package is generated by OPPO, the RSA signature here can verify whether the data in each partition is generated by OPPO.

[0050] The RSA signatures of each partition can be combined into a full signature data AllSignatureFile, and a 256-bit version identity signal code can be obtained according to the Hash 256 algorithm. The above version identity signal code is the signature encrypted data. It should be noted that the above flash package structure also includes the full signature data and partition identification encrypted data at the end of the flash package. The partition identification encrypted data includes the name, offset address, file length, checksum and other information of each partition.

[0051] Through the structure of the flash package above, the encrypted file format and the offset address of the encrypted area can be unified, making it convenient for the user terminal to use the same standard for decryption, improving security while also enhancing convenience. Figure 5 Another flash package encryption method in the embodiment of this application is described in detail. Figure 5 A flowchart of another flash package encryption method provided in an embodiment of the present application specifically includes the following steps:

[0052] Step 501: Encrypt the characteristic data of each partition file in the flash package to obtain characteristic encrypted data.

[0053] Step 502: Process the signature data of each partition file in the flash package to obtain signature encryption data.

[0054] Step 503: Process the partition identification data of each partition file in the flashing package to obtain partition identification encrypted data.

[0055] Step 504: Determine the encrypted flash package based on the feature encrypted data, the signature encrypted data, and the partition identifier encrypted data.

[0056] Step 505: Obtain the preset version identifier of the user terminal.

[0057] Among them, this step is performed before the user terminal installs the encrypted flashing package. The above-mentioned preset version identifier can be used to indicate the version information of the flashing package that can be installed by the above-mentioned user terminal. The above-mentioned preset version identifier can include enterprise customized version identifier, operator version identifier, ordinary version identifier, etc., which is not specifically limited here.

[0058] Step 506: Determine whether the version identification information has a version correspondence relationship with the preset version identification.

[0059] Among them, the above-mentioned version identification information can be used to represent the version information corresponding to the current flashing package. When the version of the above-mentioned version identification information and the version of the above-mentioned preset version identification are the same, it can be determined that there is a version correspondence relationship.

[0060] Among them, when it is determined that the above-mentioned version identification information has a version correspondence with the above-mentioned preset version identification, step 507 can be executed; when it is determined that the above-mentioned version identification information has no version correspondence with the above-mentioned preset version identification, the encrypted flashing package cannot be decrypted.

[0061] Step 507: perform a decryption step on the encrypted flashing package to obtain the flashing package.

[0062] Among them, the above-mentioned decryption step can be to send a key to the user terminal, and the above-mentioned key is an RSA password. The above-mentioned RSA password can be used to decrypt the above-mentioned partition identification encrypted data, and obtain the partition identification data of each partition file such as partition name, offset address, checksum, etc., and then find the position of the corresponding partition file in the rom.ofp file according to the offset address of each partition file. After finding the corresponding partition file, the characteristic encrypted data of the partition file is decrypted to restore the partition file. Similarly, each partition file can be restored to complete the decryption of the flashing package and obtain the original flashing package.

[0063] By performing a decryption step on the encrypted flash package to obtain the flash package, the partition identification encrypted data and the feature encrypted data can be decrypted, and the decryption of the flash package can be completed safely.

[0064] Step 508: Burn the partition file into the user terminal according to the signature data.

[0065] Among them, step 508 can be executed after decrypting the encrypted flashing package. The above signature data includes the source information of the partition file. The above signature data can be used to verify whether the partition location to be installed is the partition corresponding to the signature data. If so, the installation is completed. If the verification fails, the installation cannot be completed.

[0066] By burning the partition file into the user terminal according to the signature data, it can be ensured that the data of the flashing package has not been illegally tampered with, which greatly improves the security of the flashing package.

[0067] The steps not described above can be found in Figure 3 The method steps in will not be repeated here.

[0068] With the above Figure 3 、 Figure 5 For details on the embodiment shown, please refer to Figure 6 , Figure 6 This is a structural diagram of an electronic device 600 provided in an embodiment of the present application. As shown in the figure, the electronic device 600 includes an application processor 601, a communication interface 602 and a memory 603. The application processor 601, the communication interface 602 and the memory 603 are interconnected via a bus 604. The bus 604 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus 604 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 The method is represented by only one thick line, but does not mean that there is only one bus or one type of bus. The memory is used to store a computer program, the computer program includes program instructions, and the application processor is configured to call the program instructions to perform the following steps: encrypting the characteristic data of each partition file in the flash package to obtain characteristic encrypted data, the characteristic data including any fragment of each partition file;

[0069] Processing the signature data of each partition file in the flash package to obtain signature encryption data, wherein the signature data is used to represent the version information of the flash package;

[0070] Processing the partition identification data of each partition file in the flash package to obtain partition identification encrypted data, wherein the partition identification data is used to indicate the type of each partition file;

[0071] The encrypted flashing package is determined according to the feature encrypted data, the signature encrypted data and the partition identifier encrypted data.

[0072] In one possible example, in the aspect of encrypting the characteristic data of each partition file in the flash package to obtain the characteristic encrypted data, the instructions in the program are specifically used to perform the following operations: obtaining characteristic data of a preset address of each partition file in the flash package;

[0073] The characteristic data is encrypted by an asymmetric encryption algorithm to obtain the characteristic encrypted data.

[0074] In one possible example, in processing the signature data of each partition file in the flash package to obtain the signature encrypted data, the instructions in the program are specifically used to perform the following operations: obtain the signature data of each partition file in the flash package and merge them to obtain a full signature data;

[0075] The full signature data is encrypted using a hash algorithm to obtain the signature encrypted data, where the signature encrypted data includes version identification information.

[0076] In one possible example, in processing the partition identification data of each partition file in the flash package to obtain the partition identification encrypted data, the instructions in the program are specifically used to perform the following operations: obtaining the partition name, partition offset address, and partition checksum of each partition file in the flash package;

[0077] Merge the partition name, partition offset address and partition checksum of each partition file into structure variable data;

[0078] The structure variable data is encrypted using an asymmetric encryption algorithm to obtain the partition identification encrypted data.

[0079] In one possible example, in terms of determining the encrypted flashing package based on the feature encryption data, the signature encryption data, and the partition identification encryption data, the instructions in the program are specifically used to perform the following operations: saving the feature encryption data to the header of a preset format file, saving the signature encryption data and the partition identification data to the end of the preset format file, and the preset format file is used to represent the encrypted flashing package.

[0080] In one possible example, after determining the encrypted flash package according to the feature encrypted data, the signature encrypted data, and the partition identifier encrypted data, the instructions in the program are further configured to perform the following operations: before installing the encrypted flash package on the user terminal, obtaining a preset version identifier of the user terminal;

[0081] Determine whether the version identification information has a version correspondence relationship with the preset version identification;

[0082] If so, a decryption step is performed on the encrypted flash package to obtain the flash package.

[0083] In one possible example, after performing the decryption step on the encrypted flash package to obtain the flash package, the instructions in the program are further used to perform the following operations: burning the partition file to the user terminal according to the signature data.

[0084] The above mainly introduces the solution of the embodiment of the present application from the perspective of the execution process of the method side. It is understandable that, in order to realize the above functions, the electronic device includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiment provided herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in a hardware or computer software driven hardware manner depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0085] The embodiment of the present application can divide the functional units of the electronic device according to the above method example. For example, each functional unit can be divided according to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional units. It should be noted that the division of units in the embodiment of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.

[0086] Figure 7 This is a block diagram of the functional units of a flash package encryption device 700 provided in an embodiment of the present application. This flash package encryption device 700 is applied to an electronic device and includes a processing unit 701, a communication unit 702, and a storage unit 703. The processing unit 701 is configured to execute any of the steps in the aforementioned method embodiments and, when performing data transmissions such as sending, can optionally invoke the communication unit 702 to complete the corresponding operation. This is described in detail below.

[0087] The processing unit 701 is configured to encrypt characteristic data of each partition file in the flash package to obtain characteristic encrypted data, where the characteristic data includes any segment of each partition file;

[0088] Processing the signature data of each partition file in the flash package to obtain signature encryption data, wherein the signature data is used to represent the version information of the flash package;

[0089] Processing the partition identification data of each partition file in the flash package to obtain partition identification encrypted data, wherein the partition identification data is used to indicate the type of each partition file;

[0090] The encrypted flashing package is determined according to the feature encrypted data, the signature encrypted data and the partition identifier encrypted data.

[0091] In a possible example, in encrypting the characteristic data of each partition file in the flash package to obtain the characteristic encrypted data, the processing unit 701 is specifically configured to: obtain characteristic data of a preset address of each partition file in the flash package;

[0092] The characteristic data is encrypted by an asymmetric encryption algorithm to obtain the characteristic encrypted data.

[0093] In one possible example, in processing the signature data of each partition file in the flash package to obtain the signature encrypted data, the processing unit 701 is specifically configured to: obtain the signature data of each partition file in the flash package and merge them to obtain a full signature data;

[0094] The full signature data is encrypted using a hash algorithm to obtain the signature encrypted data, where the signature encrypted data includes version identification information.

[0095] In a possible example, in processing the partition identification data of each partition file in the flashing package to obtain the partition identification encrypted data, the processing unit 701 is specifically used to: obtain the partition name, partition offset address and partition checksum of each partition file in the flashing package;

[0096] Merge the partition name, partition offset address and partition checksum of each partition file into structure variable data;

[0097] The structure variable data is encrypted using an asymmetric encryption algorithm to obtain the partition identification encrypted data.

[0098] In one possible example, in terms of determining the encrypted flashing package based on the feature encryption data, the signature encryption data and the partition identification encryption data, the processing unit 701 is specifically used to: save the feature encryption data to the header of a preset format file, save the signature encryption data and the partition identification data to the end of the preset format file, and the preset format file is used to represent the encrypted flashing package.

[0099] In one possible example, after determining the encrypted flash package according to the feature encrypted data, the signature encrypted data, and the partition identifier encrypted data, the processing unit 701 is further specifically configured to: before installing the encrypted flash package on the user terminal, obtain a preset version identifier of the user terminal;

[0100] Determine whether the version identification information has a version correspondence relationship with the preset version identification;

[0101] If so, a decryption step is performed on the encrypted flash package to obtain the flash package.

[0102] In a possible example, after performing the decryption step on the encrypted flashing package to obtain the flashing package, the processing unit 701 is further specifically used to: burn the partition file into the user terminal according to the signature data.

[0103] An embodiment of the present application also provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute part or all of the steps of any method described in the above method embodiments, and the above computer includes an electronic device.

[0104] The present application also provides a computer program product comprising a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a computer to perform some or all of the steps of any of the methods described in the above method embodiments. The computer program product may be a software installation package, and the computer may comprise an electronic device.

[0105] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.

[0106] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0107] In the several embodiments provided in this application, it should be understood that the disclosed devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical or other forms.

[0108] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0109] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0110] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the above-mentioned methods of each embodiment of the present application. The aforementioned memory includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0111] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program. The program can be stored in a computer-readable memory, and the memory can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0112] The above is a detailed introduction to the embodiments of the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of ​​the present application. At the same time, for those skilled in the art, according to the idea of ​​the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A flash package encryption method, characterized in that: The method comprises: Encrypting characteristic data of each partition file in the flash package to obtain characteristic encrypted data, wherein the characteristic data includes any fragment of each partition file; Processing the signature data of each partition file in the flash package to obtain encrypted signature data, wherein the signature data is used to represent the version information of the flash package, wherein the signature data of each partition file in the flash package is obtained and combined to obtain a full signature data; encrypting the full signature data using a hash algorithm to obtain the encrypted signature data, wherein the encrypted signature data includes version identification information; Processing partition identification data of each partition file in the flash package to obtain partition identification encrypted data, wherein the partition identification data is used to indicate the type of each partition file, wherein a partition name, a partition offset address, and a partition checksum of each partition file in the flash package are obtained; merging the partition name, partition offset address, and partition checksum of each partition file into structure variable data; and encrypting the structure variable data using an asymmetric encryption algorithm to obtain the partition identification encrypted data; The encrypted flashing package is determined according to the feature encrypted data, the signature encrypted data and the partition identifier encrypted data.

2. The method according to claim 1, characterized in that The step of encrypting the characteristic data of each partition file in the flash package to obtain characteristic encrypted data includes: Obtaining characteristic data of a preset address of each partition file in the flash package; The characteristic data is encrypted by an asymmetric encryption algorithm to obtain the characteristic encrypted data.

3. The method according to claim 1 or 2, characterized in that The step of determining the encrypted flash package according to the feature encrypted data, the signature encrypted data, and the partition identifier encrypted data includes: The characteristic encryption data is saved to the header of a preset format file, and the signature encryption data and the partition identification data are saved to the tail of the preset format file. The preset format file is used to represent the encrypted flash package.

4. The method according to claim 3, characterized in that After determining the encrypted flash package according to the feature encrypted data, the signature encrypted data, and the partition identifier encrypted data, the method further includes: Before installing the encrypted flash package on the user terminal, obtaining a preset version identifier of the user terminal; Determine whether the version identification information has a version correspondence relationship with the preset version identification; If so, a decryption step is performed on the encrypted flash package to obtain the flash package.

5. The method according to claim 4, characterized in that The preset version identifier includes 256 bits of binary data, and the version identifier information includes 256 bits of binary data; and determining whether the version identifier information has a version correspondence relationship with the preset version identifier includes: By comparing the preset version identifier and the 256-bit binary data of the version identifier information one by one, it is determined whether the version identifier information has a version correspondence relationship with the preset version identifier.

6. The method according to claim 4, characterized in that After determining whether the version identification information has a version correspondence relationship with the preset version identification, the method further includes: If there is no version correspondence between the version identification information and the preset version identification, a prompt message is displayed on the user terminal, where the prompt message is used to indicate that the decryption fails.

7. The method according to claim 4, characterized in that After performing the decryption step on the encrypted flash package to obtain the flash package, the method further includes: Burn the partition file into the user terminal according to the signature data.

8. A flash package encryption device, characterized in that: The device comprises a processing unit and a communication unit, wherein, The processing unit is configured to encrypt characteristic data of each partition file in the flash package to obtain characteristic encrypted data, wherein the characteristic data includes any segment of each partition file; Processing the signature data of each partition file in the flash package to obtain encrypted signature data, wherein the signature data is used to represent the version information of the flash package, wherein the signature data of each partition file in the flash package is obtained and combined to obtain a full signature data; encrypting the full signature data using a hash algorithm to obtain the encrypted signature data, wherein the encrypted signature data includes version identification information; Processing partition identification data of each partition file in the flash package to obtain partition identification encrypted data, wherein the partition identification data is used to indicate the type of each partition file, wherein a partition name, a partition offset address, and a partition checksum of each partition file in the flash package are obtained; merging the partition name, partition offset address, and partition checksum of each partition file into structure variable data; and encrypting the structure variable data using an asymmetric encryption algorithm to obtain the partition identification encrypted data; The encrypted flashing package is determined according to the feature encrypted data, the signature encrypted data and the partition identifier encrypted data.

9. An electronic device, characterized in that: The method comprises a multi-core processor, a communication interface and a memory, wherein the multi-core processor, the communication interface and the memory are interconnected, wherein the memory is used to store a computer program, the computer program includes program instructions, and the multi-core processor is configured to call the program instructions to execute the method according to any one of claims 1 to 7.

10. A computer storage medium, characterized in that The computer storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor executes the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and system for remotely upgrading device

    CN108111507A

  • Upgrade package encryption and decryption method, electronic device and storage medium

    CN110022558A