Method, device and medium for system update

By decrypting the upgrade package in a Trusted Execution Environment (TEE) and generating a communication key using a symmetric encryption algorithm, the security problem during the transmission of the system upgrade package is solved, achieving the security and confidentiality of the upgrade package and ensuring the integrity and security of the system.

CN114625387BActive Publication Date: 2025-11-11SHANGHAI PATEO ELECTRONIC EQUIPMENT MANUFACTURING CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202011452843.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-11
Publication Date
2025-11-11
Estimated Expiration
2040-12-11

AI Technical Summary

Technical Problem

The existing system upgrade packages are easily intercepted and tampered with by third parties during transmission, resulting in insufficient confidentiality. Furthermore, the security level of encryption or decryption operations in untrusted environments is low, making it impossible to guarantee the security of the upgrade packages.

Method used

In the Trusted Execution Environment (TEE), the encrypted upgrade package is decrypted by the first trusted application, and a communication key is generated by combining symmetric encryption and hash algorithms to ensure that the upgrade package is decrypted and verified in the TEE, thus preventing the key from being intercepted or tampered with.

Benefits of technology

The upgrade package enhances security and confidentiality, ensuring system security and integrity, preventing key interception or tampering, and protecting system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114625387B_ABST
    Figure CN114625387B_ABST
Patent Text Reader

Abstract

This application discloses a method, apparatus, and medium for system updates. The method includes: obtaining version number information of a file to be updated; determining whether an upgrade package exists based on the version number information; if an upgrade package exists, obtaining the encrypted upgrade package; decrypting the encrypted upgrade package through a first trusted application in a Trusted Execution Environment (TEE) to obtain the upgrade package; and performing a system update based on the upgrade package. Implementing this application embodiment allows system updates to be completed based on a trusted environment, improving the security and confidentiality of the upgrade package and ensuring system security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus and medium for system updating. Background Technology

[0002] With the continuous development of computer technology, terminal devices such as computers and smartphones are becoming increasingly popular. To meet the ever-changing needs, the systems on these devices often require upgrades and updates. Currently, system upgrades are mainly performed by downloading upgrade packages from the internet. However, due to insufficient confidentiality during transmission, upgrade packages are easily intercepted and tampered with by third parties, affecting system security.

[0003] To address the aforementioned issues, encryption of the upgrade package is typically employed to enhance its security. However, current solutions require multiple negotiations between the terminal and the server to obtain the key for encryption and decryption. This process can easily lead to key leakage, compromising the confidentiality of the upgrade package. Furthermore, encrypting or decrypting the upgrade package in an untrusted environment results in a lower level of security, failing to guarantee the upgrade package's security. Summary of the Invention

[0004] This application provides a method, apparatus, and medium for system updates, which can complete system updates based on a trusted environment, improve the security and confidentiality of upgrade packages, and ensure system security.

[0005] In a first aspect, embodiments of this application provide a method for system updating, comprising the following steps:

[0006] Get the version number information of the file to be updated;

[0007] Determine if an upgrade package exists based on the version number information;

[0008] If an upgrade package exists, retrieve the encrypted upgrade package;

[0009] In the Trusted Execution Environment (TEE), the first trusted application decrypts the encrypted upgrade package to obtain the upgrade package.

[0010] System updates are performed based on the upgrade package.

[0011] Secondly, embodiments of this application provide a system update apparatus, including a communication interface and a processor;

[0012] The communication interface obtains the version number information of the file to be updated and sends the version number information to the processor;

[0013] The processor receives version number information and determines whether an upgrade package exists based on the version number information; if an upgrade package exists, the determination result is sent to the communication interface.

[0014] When the communication interface receives the judgment result, it obtains the encrypted upgrade package and sends the encrypted upgrade package to the Trusted Execution Environment (TEE) in the processor.

[0015] After the processor obtains the encrypted upgrade package, it decrypts the encrypted upgrade package in the TEE through the first trusted application to obtain the upgrade package; and performs a system update based on the upgrade package.

[0016] Thirdly, embodiments of this application provide an electronic device including a processor, a memory, and a bus, wherein the processor and the memory are connected via the bus, the memory is used to store a set of program code, and the processor is used to call the program code stored in the memory to execute the method described in the first aspect.

[0017] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program, the computer program including program instructions, which, when executed by a processor, perform the method described in the first aspect.

[0018] By implementing the embodiments of this application, during the system update process, the two communicating parties do not need to conduct multiple data transmissions to negotiate the key, which can effectively prevent the key from being intercepted or tampered with and ensure data security. At the same time, the upgrade package is transmitted after being encrypted, and the encrypted upgrade package is decrypted and verified in a trusted execution environment, which can ensure the security and integrity of the upgrade package, thereby protecting system security. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a flowchart illustrating a system connection and communication method provided in an embodiment of this application;

[0021] Figure 2 This is a flowchart illustrating a system update method provided in an embodiment of this application;

[0022] Figure 3 This is a flowchart illustrating a method for generating a symmetric key according to an embodiment of this application;

[0023] Figure 4 This is a flowchart illustrating another system update method provided in an embodiment of this application;

[0024] Figure 5 This is a flowchart illustrating a method for verifying an upgrade package provided in an embodiment of this application;

[0025] Figure 6 This is a flowchart illustrating another method for verifying an upgrade package provided in an embodiment of this application;

[0026] Figure 7 This is a schematic diagram illustrating the composition of a system update apparatus provided in an embodiment of this application;

[0027] Figure 8 This is a schematic diagram illustrating the composition of another system update apparatus provided in an embodiment of this application;

[0028] Figure 9 This is a schematic diagram illustrating the composition of another system update apparatus provided in an embodiment of this application;

[0029] Figure 10 This is a schematic diagram of the composition of an electronic device provided in an embodiment of this application. Detailed Implementation

[0030] The embodiments of this application will now be described with reference to the accompanying drawings.

[0031] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover a non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0032] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0033] For ease of understanding, the terms used in the embodiments of this application are explained below.

[0034] A Trusted Execution Environment (TEE) is a secure area within the processor that runs in an isolated execution environment alongside the operating system (OS). It ensures the confidentiality and integrity of computer programs and data loaded within the TEE. By using both hardware and software to protect data and programs, it is more secure than a typical Rich Execution Environment (REE).

[0035] Trusted Applications (TAs) are applications running within a TEE (Trusted Equipment Environment). These applications have full access to and use of the device's processor and memory, while hardware isolation protects them from user-installed applications running on the main operating system. Trusted applications are cryptographically isolated from each other, preventing unauthorized reading and manipulation of data from other trusted applications. Furthermore, trusted applications undergo integrity verification before execution to ensure they have not been tampered with, thus preventing tampering, phishing, and replay attacks.

[0036] Symmetrical encryption, also known as single-key encryption, is an encryption method that uses a single-key cryptosystem where the same key can be used for both encryption and decryption. In symmetric encryption algorithms, the sender processes the plaintext and encryption key together using a special encryption algorithm, transforming it into complex ciphertext before sending it. The receiver, upon receiving the ciphertext, needs to use the key and the inverse algorithm of the same encryption method to decrypt it and recover the readable plaintext. Commonly used symmetric encryption algorithms include the Advanced Encryption Standard (AES) and the Data Encryption Standard (DES).

[0037] Asymmetric encryption, also known as public-key encryption, is an encryption algorithm that uses different keys for encryption and decryption. Unlike symmetric encryption algorithms, asymmetric encryption algorithms require two keys: a public key and a private key. The public and private keys are a pair; if data is encrypted using the public key, it can only be decrypted using the corresponding private key; conversely, if data is encrypted using the private key, it can only be decrypted using the corresponding public key. Commonly used asymmetric encryption algorithms include RSA (RSA algorithm).

[0038] A hash algorithm, also known as a hash function, digest generation algorithm, or hash algorithm, is a method for creating a digital fingerprint from data. A hash algorithm scrambles and mixes data to create a new hash value. Hash algorithms are primarily used to ensure data authenticity. The sender sends the original message along with the hash value, and the receiver uses the same hash function to verify the authenticity and integrity of the original data. Commonly used hash algorithms include Hash-based Message Authentication Code (HMAC) and Secure Hash Algorithm (SHA).

[0039] Below, in conjunction with Figures 1-6 The steps described herein provide a detailed explanation of the system update method provided in the embodiments of this application.

[0040] Before a system update, both communicating parties need to establish a connection and complete identity verification to lay the foundation for the transmission of the upgrade package. Please refer to [link / reference needed]. Figure 1 The following is a flowchart illustrating a system connection and communication method provided in an embodiment of this application, which may include the following steps:

[0041] S101 initiates an HTTPS request, sending SSL protocol version information to the server.

[0042] In one possible implementation, the terminal initiates an HTTPS request and sends the SSL protocol version information to the server. Here, the terminal is an entity on the user side used to receive or transmit signals; it can also be called a user client or user equipment (UE). It can be deployed on land, including indoors or outdoors, handheld, wearable, or vehicle-mounted; it can also be deployed on water (such as on ships); and it can be deployed in the air (e.g., on airplanes, balloons, and satellites). It can also be called a user terminal, terminal equipment, access terminal equipment, vehicle-mounted terminal, UE unit, UE station, mobile station, mobile station, remote station, remote terminal equipment, mobile device, UE terminal equipment, mobile terminal, wireless communication equipment, UE agent, or UE device, etc. The terminal can be fixed or mobile. Specific forms include mobile phones, tablets, computers with wireless transceiver capabilities, vehicle-mounted terminal equipment, wireless terminals in smart homes, wearable terminal devices, etc.

[0043] S102, Obtain the CA certificate sent by the server.

[0044] It should be noted that a CA certificate contains information such as the server's public key, signature, and certificate validity period. The signature is obtained by encrypting the message digest of the CA certificate with the CA's private key and is used to verify the legitimacy of the certificate, thereby determining whether the server's identity is legitimate. The message digest information can be calculated using a hash function.

[0045] S103, verify the validity of the server certificate. If valid, continue execution.

[0046] In one possible implementation, the terminal can determine whether a certificate has expired by using information such as the certificate's validity period carried in the CA certificate. When the certificate is valid, the terminal can read the plaintext information of the CA certificate, calculate a message digest using the same hash function, and then decrypt the obtained signature using the CA's public key to obtain the CA certificate message digest sent by the server. By comparing the contents of the two message digests, the terminal verifies the legitimacy of the server certificate. If the contents match, the server certificate is valid, completing the certificate legitimacy check and server authentication. Once the server certificate legitimacy check passes, the server's public key from the CA certificate is retrieved.

[0047] S104, Send the client certificate, which includes the encrypted client public key.

[0048] S105, the server obtains the client's public key by decrypting the private key on the server side.

[0049] After the terminal authenticates the server, the server can also authenticate the terminal, thereby further ensuring data security.

[0050] In one possible implementation, the terminal can be verified using a client certificate. The terminal encrypts its client public key using the server's public key obtained in step S103, and sends the encrypted client public key along with the certificate to the server. Upon receiving the client certificate, the server can decrypt it using its private key stored on the server to obtain the client public key. Because public and private keys are used in pairs in asymmetric encryption algorithms, information encrypted by the terminal using the server's public key can only be decrypted using the server's private key, thus ensuring the legitimacy of the identities of both parties in the data transmission.

[0051] S106, Send the supported symmetric encryption scheme to the server.

[0052] S107, Obtain the symmetric encryption scheme selected by the server.

[0053] To ensure communication security, the data transmitted during communication needs to be encrypted. Therefore, the terminal and the server need to negotiate and agree on the encryption scheme to be used in subsequent communication.

[0054] In one possible implementation, after selecting an encryption scheme, the server can encrypt the selected scheme using the client's public key obtained in step S105 to prevent the selected encryption scheme from being intercepted and tampered with by a third party. Upon receiving the encrypted symmetric encryption scheme, the terminal decrypts it using the client's private key to obtain the symmetric encryption scheme selected by the server.

[0055] S108: Generate and encrypt the communication key according to the selected symmetric encryption scheme.

[0056] S109, send the encrypted communication key to the server.

[0057] In one possible implementation, the terminal can generate a communication key based on the symmetric encryption scheme selected by the server, encrypt the communication key using the server's public key, and send the ciphertext to the server.

[0058] S110, the server decrypts the encrypted information to obtain the communication key.

[0059] After receiving the ciphertext, the server decrypts it using its private key to obtain the communication key. In subsequent communications, the server can use the communication key and a selected symmetric encryption scheme to encrypt the transmitted information and protect data security.

[0060] By implementing the above method, a communication link can be established between the terminal and the server to transmit data; and in this process, two-way authentication between the terminal and the server, as well as between the server and the terminal, can be completed, further ensuring the security of the upgrade package during transmission.

[0061] The system update method provided in this application can be executed on a terminal to update the terminal system; it can also be executed on a server to update the server system. For ease of understanding, the following embodiments use a terminal as the execution subject to explain the system update method provided in this application.

[0062] Please see Figure 2 The following is a flowchart illustrating a system update method provided in this application embodiment, which may include the following steps:

[0063] S201, retrieve the version number information of the file to be updated.

[0064] S202, determine whether an upgrade package exists based on the version number information.

[0065] It should be noted that the release of the upgrade package can be handled by a third-party server. The released upgrade package and its version number information can be stored on a server with which a communication link has been established with the terminal. The terminal sends the version number information of the file to be updated to the server and checks whether an upgrade package with a higher version number exists. For example, if the version number of the file to be updated is V1.0, and an upgrade package with version number V1.1 exists, then a system update operation can be performed.

[0066] The device used to detect upgrade package information can be a terminal or a server; this embodiment does not limit the specific device. When the terminal performs upgrade package information detection, it can complete the detection by receiving the latest version number information sent by the server. When the server performs upgrade package information detection, it can send the detection results to the terminal, and the terminal can determine whether a system update is needed based on the obtained detection results.

[0067] S203, when an upgrade package exists, retrieve the encrypted upgrade package.

[0068] In one possible implementation, the encrypted upgrade package is obtained by encrypting the upgrade package using a preset symmetric encryption algorithm.

[0069] The preset symmetric encryption algorithm can be a symmetric encryption algorithm pre-installed in the terminal and server, or it can be negotiated by the terminal and server through network communication. The preset symmetric encryption algorithm can be a symmetric encryption algorithm such as AES, DES, and Blowfish. The embodiments of this application do not limit the method and specific category of determining the preset symmetric encryption algorithm.

[0070] It should be noted that the terminal can obtain the encrypted upgrade package through the download address of the upgrade package, or it can obtain it through the push information from the server. When the server performs a system update, since the third-party server will upload the upgrade package to the server, the server can directly obtain the encrypted upgrade package through the data uploaded by the third-party server. This application embodiment does not limit the method of obtaining the encrypted upgrade package.

[0071] S204. In the Trusted Execution Environment (TEE), the first trusted application decrypts the encrypted upgrade package to obtain the upgrade package.

[0072] In one possible implementation, a first trusted application can calculate a symmetric key based on a preset symmetric encryption algorithm; the encrypted upgrade package can then be decrypted using the symmetric key to obtain the upgrade package.

[0073] The first trusted application is an application running in the TEE. The hardware protection mechanism provided by the TEE can ensure that the program and data of the trusted application are not stolen or damaged, thereby ensuring the security of the upgrade package.

[0074] Please see Figure 3 The following is a flowchart illustrating a method for generating a symmetric key according to an embodiment of this application, which may include the following steps:

[0075] S2041, generate the base key through a third trusted application.

[0076] The third trusted application is an application running in a TEE (Trusted Application Environment). This application can randomly generate a string of a preset length as the base key for calculating the symmetric key. The preset length can be 20 bytes or other lengths; this embodiment does not limit this. The device generating the base key can be a terminal, a server, or a third device other than a terminal or server; this embodiment does not limit this either. After the base key is generated, it can be sent to the terminal and / or server for storage.

[0077] S2042, calculate the integer time counter based on the current time information and the preset time interval.

[0078] It should be noted that the calculation method for an integer time counter can be expressed by the formula:

[0079] TC = [T / TI]

[0080] Where TC is an integer time counter; T is the current time information, which can be calculated by converting the current time to a Unix timestamp. The Unix timestamp is the total number of seconds from 00:00:00 on January 1, 1970 to the current time, without considering leap seconds; TI is the preset time interval, which can be set according to the validity period of the upgrade package. For example, if the validity period of the upgrade package is set to one hour, then TI = 3600.

[0081] S2043 calculates the symmetric key based on version number information, basic key, and integer time counter using a preset symmetric encryption algorithm.

[0082] The preset symmetric encryption algorithm can be an AES algorithm, a DES algorithm, or other algorithms, and the symmetric key is calculated by an HMAC hash algorithm or other methods. The specific type of HMAC hash algorithm can be a message digest algorithm (MD5) or a secure hash algorithm (SHA-256), etc. The embodiments of this application are not limited to these algorithms.

[0083] Taking the HMAC hash algorithm as an example, the calculation method of the symmetric key can be expressed by the formula:

[0084] HMAC(K,M)=H(K XOR opad,H(K XOR ipad,M))

[0085] Wherein, K is the base key calculated in step S2041. The length of K can be preset during calculation. When the base key length is insufficient, it can be padded with zeros to reach the preset K value length. M is the text content obtained based on the version number information and the integer time counter, which can be obtained by concatenating the version number information and the integer time counter. H is the hash algorithm, such as MD5, SHA-256, etc. opad is the external padding constant. ipad is the internal padding constant. XOR is the XOR operation.

[0086] It should be noted that calculating the symmetric key based on the integer time counter obtained in step S2042 allows for checking whether the acquired upgrade package is within its lifecycle while calculating the symmetric key, thereby further ensuring the data security of the upgrade package. The lifecycle length is a preset time interval. For example, if the preset time interval is set to one hour, and the encryption time is 8:12:15 AM on August 24, 2020, then the current time information in the integer time counter is 1598227935, and the integer time counter value is [1598227935 / 3600] = 443952. If the upgrade package is acquired at 8:30:35 AM on August 24, 2020, then the current time information in the integer time counter is 1598229035, and the integer time counter value is [1598229035 / 3600] = 443952. This is consistent with the integer time counter value at the time of encryption. If the values ​​are the same, the symmetric key calculated based on this will also be the same, and the upgrade package can be decrypted. If the upgrade package is not obtained within the preset time interval, for example, if the upgrade package is obtained at 9:15:20 on August 24, 2020, then the current time information in the integer time counter is 1598231720, and the integer time counter is [1598231720 / 3600] = 443953, which is different from the integer time counter value when encryption was performed. Therefore, the calculated symmetric key cannot decrypt the upgrade package, thus ensuring the timeliness of the upgrade package and further strengthening the protection of the upgrade package.

[0087] Since a symmetric encryption algorithm is used to encrypt the upgrade package, the calculated symmetric key is also the key used to encrypt the upgrade package. After calculating the symmetric key, the symmetric key and the encrypted upgrade package can be sent to a first trusted application to decrypt the encrypted upgrade package. Alternatively, the encrypted upgrade package download path can be sent to the first trusted application; this embodiment does not limit the method used.

[0088] By implementing the above method, a symmetric key can be generated based on version number and time information, eliminating the need for multiple communication interactions between the terminal and server to negotiate the key. This effectively prevents the key from being intercepted and tampered with, thereby improving the security of the upgrade package. Furthermore, decrypting the upgrade package within the TEE further protects the key from eavesdropping or theft, ensuring data security.

[0089] S205, system update based on upgrade package.

[0090] After the upgrade package is decrypted, the system files can be updated based on the decrypted upgrade package.

[0091] To further enhance the protection of the upgrade package, an integrity check can be performed on the decrypted upgrade package to prevent tampering and ensure system security. Please refer to [link / reference]. Figure 4 This is a flowchart illustrating another system update method provided in an embodiment of this application, wherein steps S401-S404 are... Figure 2 Steps S201-S204 are the same and will not be repeated here. After step S404, the following steps may also be included:

[0092] S405 verifies the legitimacy of the upgrade package through a second trusted application in the TEE.

[0093] In one possible implementation, after the upgrade package is decrypted by the first trusted application and before the upgrade package is validated, a first digest of the upgrade package can be obtained. The first digest is calculated based on the upgrade package using a preset digest generation algorithm and is used to identify the content of the upgrade package.

[0094] It should be noted that the digest information is a fixed-length hash value, also known as a fingerprint, obtained by performing a one-way hash operation on the input data using a digest generation algorithm. Since the digest generation algorithm is one-way, it can only calculate the digest information based on the input data and cannot reverse-engineer the input data from the digest information. The preset digest generation algorithm can be SHA-256, MD5, or other algorithms; this application does not limit the specific algorithms used.

[0095] In one possible implementation, after obtaining the first digest information and before verifying the legitimacy of the upgrade package, a digest signature of the upgrade package can also be obtained. The digest signature is obtained by encrypting the first digest information of the upgrade package using an asymmetric private key.

[0096] The asymmetric private key used for encryption can be the server's private key. The asymmetric encryption algorithm can be RSA, ElGamal, or other algorithms, and this application does not limit the specific algorithms used.

[0097] In another possible implementation, the digest signature of the upgrade package can be obtained after the upgrade package is decrypted by the first trusted application and before the upgrade package is validated, so as to obtain the first digest information of the upgrade package by decrypting the digest signature.

[0098] Once the first digest information and / or digest signature of the upgrade package are obtained, the legitimacy of the upgrade package can be verified by comparing whether the digest information before and after the upgrade package is transmitted.

[0099] Please see Figure 5 The following is a flowchart illustrating a method for verifying an upgrade package provided in an embodiment of this application, which may include the following steps:

[0100] S4051, based on the upgrade package, calculates the second digest information of the upgrade package using a preset digest generation algorithm.

[0101] The preset digest generation algorithm is the digest generation algorithm used when generating the first digest information of the upgrade package. It can be a digest generation algorithm preset in the terminal and server, or it can be obtained by the terminal and server through network communication. This application embodiment does not limit it.

[0102] S4052, determine whether the first digest information and the second digest information are the same. When the first digest information and the second digest information are the same, the upgrade package passes the legality check.

[0103] It should be noted that when only the first digest of the upgrade package is obtained, decryption is unnecessary. The integrity of the upgrade package can be checked by comparing the first and second digests. Since the first digest is obtained before transmission using a digest generation algorithm, while the second digest is calculated after transmission using the same algorithm, and this algorithm is unidirectional, a match between the first and second digests indicates that the content of the upgrade package has not changed during transmission. This ensures the upgrade package has not been tampered with and guarantees system security.

[0104] When the obtained data is the digest signature of the upgrade package, it needs to be decrypted to obtain the first digest information of the upgrade package. Please refer to [link / reference]. Figure 6 This is a flowchart illustrating another method for verifying an upgrade package provided in an embodiment of this application, wherein steps S4055-S4056 are... Figure 5 Steps S4051-S4052 are the same and will not be described again here. Before step S4055, the following steps are also included:

[0105] S4053, obtain the asymmetric public key, and verify the legitimacy of the asymmetric public key based on the pre-configured root certificate.

[0106] The asymmetric public key can be the server public key obtained in step S102, which can decrypt the digest signature encrypted with the server private key; the asymmetric public key and asymmetric private key can also be other pairs of public and private keys, which are not limited in this application embodiment.

[0107] Root certificates can be pre-configured on terminals and servers. Root certificates can be used to check the legitimacy of asymmetric public keys, thereby ensuring the legitimacy of asymmetric public keys and protecting data security.

[0108] S4054: When the asymmetric public key is determined to be valid, the digest signature is decrypted using the asymmetric public key to obtain the first digest information.

[0109] It should be noted that since the digest signature is encrypted using an asymmetric private key, the asymmetric public key that is paired with the asymmetric private key is needed to decrypt the digest signature in order to obtain the first digest information.

[0110] By implementing the above method, the upgrade package can be validated by a trusted application in the TEE, and the integrity of the upgrade package can be checked, thereby ensuring that the content of the upgrade package has not been tampered with during transmission and further ensuring data security.

[0111] The apparatus involved in the embodiments of this application is described below with reference to the accompanying drawings.

[0112] Please see Figure 7 This is a schematic diagram of the composition of a system update device provided in an embodiment of this application. The system update device 700 may include a processor 710 and a communication interface 720.

[0113] The communication interface 720 obtains the version number information of the file to be updated and sends the version number information to the processor 710;

[0114] The processor 710 receives the version number information and determines whether an upgrade package exists based on the version number information; if an upgrade package exists, the determination result is sent to the communication interface 720.

[0115] When the communication interface 720 receives the judgment result, it obtains the encrypted upgrade package and sends the encrypted upgrade package to the Trusted Execution Environment (TEE) in the processor 710.

[0116] After the processor 710 obtains the encrypted upgrade package, it decrypts the encrypted upgrade package in the TEE through the first trusted application to obtain the upgrade package; and performs a system update based on the upgrade package.

[0117] The upgraded package, after being encrypted, is obtained by encrypting the upgraded package using a preset symmetric encryption algorithm.

[0118] The processor 710 decrypts the encrypted upgrade package in the TEE through a first trusted application to obtain the upgrade package. The method may be as follows: the first trusted application calculates a symmetric key based on a preset symmetric encryption algorithm; and the symmetric key is used to decrypt the encrypted upgrade package to obtain the upgrade package.

[0119] The method for calculating the symmetric key through the first trusted application and based on the preset symmetric encryption algorithm can be as follows: the processor 710 generates a base key through the third trusted application; calculates an integer time counter based on the current time information and the preset time interval; and calculates the symmetric key based on the version number information, the base key, and the integer time counter using the preset symmetric encryption algorithm.

[0120] In another possible implementation, the processor 710 can also verify the legitimacy of the upgrade package through a second trusted application in the TEE; if the verification passes, the system is updated based on the upgrade package.

[0121] The communication interface 720 can also obtain the first digest information of the upgrade package. The first digest information is calculated based on the upgrade package using a preset digest generation algorithm and is used to identify the content of the upgrade package.

[0122] The communication interface 720 can also obtain the digest signature of the upgrade package, which is obtained by encrypting the first digest information of the upgrade package using an asymmetric private key.

[0123] After obtaining the first digest information and / or the digest signature of the upgrade package, the communication interface 720 sends the first digest information and / or the digest signature of the upgrade package to the processor 710.

[0124] In one possible implementation, after receiving the first digest information of the upgrade package sent by the communication interface 720, the processor 710 can calculate the second digest information of the upgrade package based on the upgrade package using a preset digest generation algorithm; determine whether the first digest information and the second digest information are the same; when the first digest information and the second digest information are the same, the upgrade package passes the validity check.

[0125] In another possible implementation, after receiving the digest signature of the upgrade package sent by the communication interface 720, the processor 710 can obtain the asymmetric public key through the communication interface 720 and verify the legality of the asymmetric public key according to the pre-configured root certificate. When the asymmetric public key is found to be legal, the processor 710 uses the asymmetric public key to decrypt the digest signature to obtain the first digest information. Based on the upgrade package, the processor 710 calculates the second digest information of the upgrade package using a preset digest generation algorithm. The processor 710 then determines whether the first digest information and the second digest information are the same. If the first digest information and the second digest information are the same, the upgrade package passes the legality verification.

[0126] The specific functional implementation of the system update device 700 can be found in [reference needed]. Figures 1-6 The corresponding methods and steps will not be repeated here.

[0127] Please see Figure 8This is a schematic diagram illustrating the composition of another system update apparatus provided in an embodiment of this application. The system update apparatus 800 may include:

[0128] Version number acquisition module 801 is used to obtain the version number information of the file to be updated;

[0129] The judgment module 802 is used to determine whether an upgrade package exists based on the version number information;

[0130] The upgrade package acquisition module 803 is used to acquire the encrypted upgrade package when the upgrade package exists.

[0131] The upgrade package decryption module 804 is used to decrypt the encrypted upgrade package through the first trusted application in the Trusted Execution Environment (TEE) to obtain the upgrade package.

[0132] System update module 805 is used to perform system updates based on upgrade packages.

[0133] Optionally, the upgrade package decryption module 804 may include:

[0134] The symmetric key calculation unit 8041 is used to calculate the symmetric key through a first trusted application based on a preset symmetric encryption algorithm;

[0135] The upgrade package decryption unit 8042 is used to decrypt the encrypted upgrade package using a symmetric key to obtain the upgrade package.

[0136] Optionally, the symmetric key computation unit 8041 may include:

[0137] The basic key generation subunit 80411 is used to generate a basic key through a third trusted application;

[0138] The integer time counter calculation subunit 80412 is used to calculate the integer time counter based on the current time information and the preset time interval;

[0139] The symmetric key calculation subunit 80413 is used to calculate the symmetric key based on version number information, basic key and integer time counter, using a preset symmetric encryption algorithm.

[0140] The specific functional implementation of the system update device 800 can be found in [reference needed]. Figures 1-3 The corresponding methods and steps will not be repeated here.

[0141] Please see Figure 9 This is a schematic diagram illustrating the composition of another system update apparatus provided in an embodiment of this application. Figure 8Compared to the corresponding system update device 800, modules 901-904 are identical to modules 801-804 in the system update device 800. In addition, the system update device 900 may further include:

[0142] The upgrade package verification module 905 is used to verify the legitimacy of the upgrade package through the second trusted application in the TEE;

[0143] System update module 906 is used to perform a system update based on the upgrade package when the verification passes.

[0144] Optionally, the system update device 900 may also include:

[0145] The digest signature acquisition module 907 is used to acquire the digest signature of the upgrade package. The digest signature is obtained by encrypting the first digest information of the upgrade package using an asymmetric private key.

[0146] The first summary information acquisition module 908 is used to acquire the first summary information of the upgrade package. The first summary information is calculated based on the upgrade package through a preset summary generation algorithm and is used to identify the content of the upgrade package.

[0147] Optionally, the upgrade package verification module 905 may also include:

[0148] Verification unit 9051 is used to obtain the asymmetric public key and verify its legitimacy based on the pre-configured root certificate.

[0149] The first digest information acquisition unit 9052 is used to decrypt the digest signature using the asymmetric public key when the asymmetric public key is determined to be valid, and obtain the first digest information.

[0150] The second digest information calculation unit 9053 is used to calculate the second digest information of the upgrade package based on the upgrade package and through a preset digest generation algorithm;

[0151] The upgrade package verification unit 9054 is used to determine whether the first digest information and the second digest information are the same. When the first digest information and the second digest information are the same, the upgrade package passes the legality verification.

[0152] The specific functional implementation of the system update device 900 can be found in [reference needed]. Figures 1-6 The corresponding methods and steps will not be repeated here.

[0153] Please see Figure 10 This is a schematic diagram illustrating the composition of an electronic device provided in an embodiment of this application. It may include:

[0154] The system includes a processor 110, a memory 120, and a communication interface 130. The processor 110, memory 120, and communication interface 130 are connected via a bus 140. The memory 120 stores instructions, and the processor 110 executes the instructions stored in the memory 120 to achieve the above-mentioned functions. Figures 1-6 The corresponding methods and steps.

[0155] The processor 110 executes the instructions stored in the memory 120 to control the communication interface 130 to receive and send signals, thus completing the steps in the above method. The memory 120 may be integrated into the processor 110 or may be disposed separately from the processor 110.

[0156] As one implementation method, the functionality of the communication interface 130 can be implemented using a transceiver circuit or a dedicated transceiver chip. The processor 110 can be implemented using a dedicated processing chip, processing circuit, processor, or general-purpose chip.

[0157] As another implementation method, the apparatus provided in this application embodiment can be implemented using a general-purpose computer. The program code that implements the functions of the processor 110 and communication interface 130 is stored in the memory 120, and the general-purpose processor implements the functions of the processor 110 and communication interface 130 by executing the code in the memory 120.

[0158] For the concepts, explanations, detailed descriptions, and other steps related to the technical solutions provided in the embodiments of this application, please refer to the descriptions of the method steps performed by the device in the foregoing method or other embodiments, which will not be repeated here.

[0159] As another implementation of this embodiment, a computer-readable storage medium is provided, on which instructions are stored, which, when executed, perform the methods in the above-described method embodiments.

[0160] As another implementation of this embodiment, a computer program product containing instructions is provided, which, when executed, perform the method in the above method embodiment.

[0161] Those skilled in the art will understand that, for ease of explanation, Figure 10 Only one memory and processor are shown in the illustration. In a real terminal or server, multiple processors and memories may exist. Memory can also be called storage medium or storage device, etc., and this application does not limit this.

[0162] It should be understood that in the embodiments of this application, the processor may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0163] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0164] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) is integrated into the processor.

[0165] It should be noted that the memories described herein are intended to include, but are not limited to, these and any other suitable types of memories.

[0166] In addition to the data bus, this bus may also include a power bus, a control bus, and a status signal bus. However, for clarity, all buses are labeled "bus" in the diagram.

[0167] It should also be understood that the first, second, third, fourth and various numerical designations used herein are merely for descriptive convenience and are not intended to limit the scope of this application.

[0168] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0169] In implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software. The steps of the method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are omitted here.

[0170] In the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0171] Those skilled in the art will recognize that the various illustrative logical blocks (ILBs) and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0172] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0173] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0174] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0175] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0176] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for system updating, characterized in that, Includes the following steps: Get the version number information of the file to be updated; Determine whether an upgrade package exists based on the version number information; If the upgrade package exists, obtain the encrypted upgrade package; In a Trusted Execution Environment (TEE), the encrypted upgrade package is decrypted by a first trusted application to obtain the upgrade package. Specifically, the first trusted application calculates a symmetric key based on a preset symmetric encryption algorithm, including generating a base key through a third trusted application. Based on the current time information and a preset time interval, an integer time counter is calculated, wherein the preset time interval is determined by the validity period of the upgrade package; based on the version number information, the base key, and the integer time counter, the symmetric key is calculated using the preset symmetric encryption algorithm; The validity period of the upgrade package and the integer time counter are used to determine whether the upgrade package is in its lifecycle. If the upgrade package is in its lifecycle, the encrypted upgrade package is decrypted using the symmetric key to obtain the upgrade package. The system is updated based on the upgrade package.

2. The method according to claim 1, wherein the encrypted upgrade package is obtained by encrypting the upgrade package using a preset symmetric encryption algorithm.

3. The method according to claim 2, wherein before performing the system update based on the upgrade package, the method further comprises: The upgrade package is validated using the second trusted application within the TEE. If the verification passes, the system update based on the upgrade package will be performed.

4. The method according to claim 3, wherein after the encrypted upgrade package is decrypted by a first trusted application in the Trusted Execution Environment (TEE) to obtain the upgrade package, and before the legality verification of the upgrade package is performed by a second trusted application in the TEE, the method further comprises: Obtain first digest information of the upgrade package. The first digest information is calculated based on the upgrade package using a preset digest generation algorithm and is used to identify the content of the upgrade package.

5. The method according to claim 4, wherein after obtaining the first digest information of the upgrade package and before performing legality verification on the upgrade package through the second trusted application in the TEE, the method further comprises: Obtain the digest signature of the upgrade package, which is obtained by encrypting the first digest information of the upgrade package using an asymmetric private key.

6. The method according to claim 4, wherein the legality verification of the upgrade package via a second trusted application in the TEE includes: Based on the upgrade package, the second digest information of the upgrade package is calculated using the preset digest generation algorithm; Determine whether the first digest information and the second digest information are the same. If the first digest information and the second digest information are the same, the upgrade package passes the legality verification.

7. The method according to claim 5, wherein the legality verification of the upgrade package via a second trusted application in the TEE includes: Obtain the asymmetric public key and verify its legitimacy based on the pre-configured root certificate; When the asymmetric public key is determined to be valid, the digest signature is decrypted using the asymmetric public key to obtain the first digest information; Based on the upgrade package, the second digest information of the upgrade package is calculated using the preset digest generation algorithm; Determine whether the first digest information and the second digest information are the same. If the first digest information and the second digest information are the same, the upgrade package passes the legality verification.

8. A system update apparatus, characterized in that, The device includes a communication interface and a processor; The communication interface obtains the version number information of the file to be updated and sends the version number information to the processor; The processor receives the version number information and determines whether an upgrade package exists based on the version number information; When the upgrade package exists, the determination result will be sent to the communication interface; When the communication interface receives the judgment result, it obtains the encrypted upgrade package and sends the encrypted upgrade package to the Trusted Execution Environment (TEE) in the processor. After the processor obtains the encrypted upgrade package, it decrypts the encrypted upgrade package in the TEE through a first trusted application to obtain the upgrade package. Specifically, the processor calculates a symmetric key based on a preset symmetric encryption algorithm through the first trusted application, including generating a base key through a third trusted application. Based on the current time information and a preset time interval, an integer time counter is calculated, wherein the preset time interval is determined by the validity period of the upgrade package; based on the version number information, the base key, and the integer time counter, the symmetric key is calculated using the preset symmetric encryption algorithm; The system determines whether the upgrade package is in its lifecycle based on the validity period of the upgrade package and the integer time counter; if the upgrade package is in its lifecycle, the encrypted upgrade package is decrypted using the symmetric key to obtain the upgrade package; and the system is updated based on the upgrade package.

9. An electronic device, characterized in that, The device includes a processor, a memory, and a bus, wherein the processor and the memory are connected via the bus, the memory is used to store a set of program code, and the processor is used to call the program code stored in the memory to execute the method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions that, when executed by a processor, perform the method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Device and method for generating transmission key

    CN101807997A

  • Token generation method and communication system based on same

    CN105847000A

  • Secure upgrading method, secure upgrading apparatus, upgrading server, upgrading device and medium

    CN108566381A

  • Equipment upgrading method, server and computer readable storage medium

    CN109992286A

  • Data processing method, device and equipment based on block chain

    CN111680305A