Data writing verification method, device, computer device, and storage medium
By monitoring and verifying the authenticity and functional conditions of the data storage device, the legality problem of the device when writing functional code is solved, ensuring data legality and device security.
Patent Information
- Application Number
- CN202210306366.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-25
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-03-25
AI Technical Summary
Existing devices lack legality verification when writing new functional codes, resulting in the use of pirated codes, harming the interests of manufacturers and posing security risks.
By monitoring the data writing function, verifying whether the data storage device is a genuine device, and checking its functional conditions to ensure the legality of functional data, including encryption logic matching and functional data correspondence verification.
Effectively ensure the legitimacy of functional data, protect the interests of manufacturers and improve the security of data receiving equipment.
Smart Images

Figure CN114722357B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data verification, and particularly to a verification method, device, computer device, and storage medium for data writing. Background Art
[0002] When existing devices need to replace the current function with a new function, it is necessary to rewrite the function code into the device's board through an external storage medium. However, when the existing device board writes a new function code, the legitimacy of the function code is not verified (for example, if the function code is pirated, it is not legitimate). This not only damages the interests of the device manufacturer, but also the illegal function code has certain security risks. For example, criminals can steal the hidden data of the device through the illegal function code. Summary of the Invention
[0003] The main purpose of this application is to provide a verification method, device, computer device, and storage medium for data writing, aiming to solve the drawback of potential security risks during existing data writing.
[0004] To achieve the above object, this application provides a verification method for data writing, including:
[0005] Monitoring whether the data writing function is triggered;
[0006] If the data writing function is triggered, verifying whether the data storage device is a genuine device, where the data storage device is a device for storing functional data;
[0007] If the data storage device is a genuine device, verifying whether the data storage device meets the functional conditions;
[0008] If the data storage device meets the functional conditions, writing the functional data into the data receiving device.
[0009] This application also provides a verification device for data writing, including:
[0010] A monitoring module, configured to monitor whether the data writing function is triggered;
[0011] A first verification module, configured to, if the data writing function is triggered, verify whether the data storage device is a genuine device, where the data storage device is a device for storing functional data;
[0012] A second verification module, configured to, if the data storage device is a genuine device, verify whether the data storage device meets the functional conditions;
[0013] A writing module, configured to, if the data storage device meets the functional conditions, write the functional data into the data receiving device.
[0014] The present application also provides a computer device, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps of any one of the above methods are implemented.
[0015] The present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in any one of the above are implemented.
[0016] A data writing verification method, device, computer device and storage medium provided in the present application. The verification system monitors in real time whether the data writing function is triggered. If the data writing function is triggered, it first verifies whether the data storage device is a genuine device, where the data storage device is a device for storing functional data. If the data storage device is a genuine device, it then verifies whether the data storage device meets the functional conditions. If the data storage device meets the functional conditions, it means that the functional data stored in the data storage device is legal and has a relatively high confidence level. Therefore, the functional data is written into the data receiving device. The present application effectively guarantees the legality of the functional data passing the verification by performing two verifications on the data storage device for genuine device and functional conditions, which can not only protect the legitimate interests of the producers of the functional data, but also improve the security guarantee for the data receiving device. Description of the Drawings
[0017] Figure 1 is a schematic diagram of the steps of the data writing verification method in an embodiment of the present application;
[0018] Figure 2 is a block diagram of the overall structure of the data writing verification device in an embodiment of the present application;
[0019] Figure 3 is a schematic block diagram of the structure of a computer device in an embodiment of the present application.
[0020] The realization, functional features and advantages of the purpose of the present application will be further described with reference to the embodiments and the accompanying drawings. Detailed Embodiments
[0021] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0022] Referring to Figure 1 , an embodiment of the present application provides a data writing verification method, including:
[0023] S1: Monitoring whether the data writing function is triggered;
[0024] S2: If the data writing function is triggered, check whether the data storage device is a genuine device, where the data storage device is a device for storing functional data;
[0025] S3: If the data storage device is a genuine device, check whether the data storage device meets the functional conditions;
[0026] S4: If the data storage device meets the functional conditions, write the functional data to the data receiving device.
[0027] In this embodiment, the verification system of the data receiving device monitors in real time whether there is a data storage device communicating with the data receiving device, so as to trigger the data writing function of the data receiving device (for example, the data storage device is a small single-chip microcomputer board, and the data receiving device is a device board; the corresponding function codes and data are stored in the small single-chip microcomputer board. When the small single-chip microcomputer board is inserted into the device board and communicates with the device board through USB to serial port, and wants to write the function data in the small single-chip microcomputer board into the device board, the data writing function will be triggered). After the data writing function is triggered, the verification system needs to verify the legality of the data storage device (that is, whether the data storage device is a pirated device) and compliance (that is, whether the function data in the data storage device corresponds to the currently required function and meets the expected specifications). Specifically, the data receiving device first generates an initial verification command and sends the initial verification command to the data storage device. Then, the data receiving device receives a feedback verification command, and the feedback verification instruction is the feedback information generated by the data storage device according to the initial verification command. The verification system identifies whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command. If the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device, it means that the data storage device is a legal device manufactured or authorized by the manufacturer, so it is determined that the data storage device is a genuine device. On the premise that the data storage device is a genuine device, it is also necessary to further verify whether the current function data in the data storage device is the required function (for example, the data receiving device can implement three functions A, B, and C, and different functions correspond to different function data. Assuming that function A needs to be implemented currently, it is necessary to verify whether the function data in the data storage device corresponds to function A). Specifically, the verification system splices the Ethernet MAC address and a preset first key value (the first key value is associated with the function, that is, different functions correspond to different first key values) to obtain a secondary verification command. Then the secondary verification command is encrypted to obtain a tertiary verification command. The verification system filters out 16-bit data from the 6th to 21st bits in the feedback verification command as verification data, and judges whether the verification data is the same as the tertiary verification command. If the verification data is the same as the tertiary verification command, it means that the function data currently stored in the data storage device corresponds to the required function, and the verification system determines that the data storage device meets the function conditions. After both verifications pass, the verification system writes the function input in the data storage device into a preset area of the data receiving device. Preferably, different types of function data correspond to different writing areas, and a mapping relationship is established between the type of function data and the writing area (for example, function data A corresponds to writing area A, and function data B corresponds to writing area B). When writing the function data into the data receiving device, the verification system finds the corresponding writing area on the data receiving device according to the type of function data, and then writes the function data into the corresponding writing area.
[0028] In this embodiment, the verification system performs two verifications on the data storage device for the legitimate device and functional conditions, thereby effectively ensuring the legality of the functional data passing the verification, which can not only guarantee the legitimate interests of the functional data producer, but also improve the security guarantee for the data receiving device.
[0029] Further, the step of verifying whether the data storage device is a legitimate device includes:
[0030] S201: The data receiving device generates an initial verification command and sends the initial verification command to the data storage device;
[0031] S202: The data receiving device receives a feedback verification command, and the feedback verification instruction is feedback information generated by the data storage device according to the initial verification command;
[0032] S203: Identify whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command;
[0033] S204: If the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device, it is determined that the data storage device is a legitimate device.
[0034] In this embodiment, when triggering the data writing function of the data receiving device, the data receiving device automatically generates an initial verification command. The generation logic of the initial verification command is as follows: The data receiving device first splices 5-bit fixed header data and the Ethernet MAC address in sequence to obtain the first 17-bit data, and then performs sha256 encryption on the first 17-bit data to obtain the first output data. The verification system selects the first 2 bits of the first output data as the 18th bit of the first 17-bit data, and then takes the 2-4th bits of the first output data as the 19th bit of the first 17-bit data, thereby forming the first 19-bit data. Further, the verification system performs sha256 encryption on the first 19-bit data to obtain the second output data. The verification system takes the 1-2 bits of the second output data as the 20th bit of the first 19-bit data, and then takes the 2-4th bits of the second output data as the 21st bit of the first 19-bit data, and finally forms the initial verification command of 21-bit data. The verification system sends the initial verification command to the data storage device. If the current data storage device is a legitimate device manufactured by the manufacturer, the data storage device will encrypt the initial verification command into a correct verification command according to the encryption logic set by the manufacturer; if the current data storage device is an illegal device (that is, not a legitimate device manufactured by the manufacturer), either it cannot encrypt and feedback the initial verification command, or the encryption logic of the data storage device is different from the encryption logic set by the manufacturer, so that the feedback verification command cannot pass the verification.
[0035] Preferably, the encryption logic of the legal data storage device for the initial verification command is as follows: The 21-bit initial verification command sent by the data receiving device is encrypted by Sha256 to obtain the third transferred data. Then, the 1st - 2nd bits of data are taken from the third transferred data as the 22nd bit of the initial verification command, and the 2nd - 4th bits of the third transferred data are taken as the 23rd bit of the initial verification command, thus obtaining 23-bit data. The data storage device encrypts the 23-bit data by sha256 to obtain the fourth transferred data. Then, the 1st - 2nd bits of data are taken from the fourth transferred data as the 24th bit of the 23-bit data, and the 2nd - 4th bits of the fourth transferred data are selected as the 25th bit of the 23-bit data, thus obtaining a feedback verification command with a total length of 25 bits.
[0036] The data receiving device determines whether it has received the feedback verification instruction returned by the data storage device within a preset time period after the initial verification command is sent. If the data receiving device has not received the feedback verification instruction returned by the data storage device within the preset time period after the initial verification command is sent, it is determined that the current data storage device is an illegal device. If the data receiving device receives the feedback verification command sent by the data storage device within the preset time period after the initial verification command is sent, it further determines whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command. If the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device, it is determined that the data storage device is a genuine device manufactured by the original manufacturer, and the current data storage device is legal.
[0037] Furthermore, the length of the feedback verification command is 25 bits. The step of determining whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command includes:
[0038] S20401: Encrypt the first 23 bits of the first data of the feedback verification command to obtain the second data;
[0039] S20402: Select the data ranked first and second in the second data as the third data, and select the data ranked third and fourth in the second data as the fourth data;
[0040] S20403: Determine whether the third data is the same as the 24th bit of the feedback verification command, and determine whether the fourth data is the same as the 25th bit of the feedback verification command;
[0041] S20404: If the third data is the same as the 24th bit data of the feedback verification command, and the fourth data is the same as the 25th bit data of the feedback verification command, it is determined that the first encryption logic is consistent with the second encryption logic.
[0042] In this embodiment, after receiving the feedback verification command, the data receiving device first performs sha256 encryption on the first 23-bit first data of the feedback verification command to obtain the second data. Then, the data receiving device screens and sorts the first and second data from the second data as the third data, and uses the third and fourth data sorted in the second data as the fourth data. The data receiving device compares the third data with the 24th bit data of the feedback verification command, and compares the fourth data with the 25th bit data of the feedback verification command to determine whether the third data is the same as the 24th bit data and whether the fourth data is the same as the 25th bit data. If the third data is the same as the 24th bit data of the feedback verification command, and the fourth data is the same as the 25th bit data of the feedback verification command, it indicates that the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device.
[0043] Further, the length of the feedback verification command is 25 bits, and the feedback verification command sequentially includes 5-bit fixed header data and 12-bit Ethernet MAC address. The steps of verifying whether the data storage device meets the functional conditions include:
[0044] S301: Concatenate the Ethernet MAC address and the first key value to obtain a secondary verification command;
[0045] S302: Encrypt the secondary verification command to obtain a tertiary verification command;
[0046] S303: Screen 16-bit data from the 6th bit to the 21st bit from the feedback verification command as verification data, and determine whether the verification data is the same as the tertiary verification command;
[0047] S304: If the verification data is the same as the tertiary verification command, it is determined that the data storage device meets the functional conditions.
[0048] In this embodiment, the data receiving device splices the Ethernet MAC address and a preset first key value (the first key value corresponds to the function type and the type of function data. For example, function data A corresponds to the first key value A, and function data B corresponds to the first key value B) in sequence to obtain a secondary verification command. Then, the secondary verification command is encrypted through the sha256 encryption algorithm to obtain a tertiary verification instruction. Next, the data receiving device selects 16-bit data from the 6th to the 21st bit in the feedback verification command as verification data, and compares the tertiary verification command with the verification data to determine whether they are the same. If the verification data is the same as the tertiary verification command, it is determined that the data storage device meets the function conditions, that is, the function data stored in the data storage device corresponds to the function currently required by the data receiving device.
[0049] Further, after the step of writing the function data into the data receiving device, it includes:
[0050] S5: Obtain the CPU ID of the data receiving device, and splice the CPU ID and a second key value in sequence to obtain an initial startup password;
[0051] S6: Encrypt the initial startup password using the shA256 encryption algorithm to obtain a secondary startup password;
[0052] S7: Screen out the lower 8-bit data and the higher 8-bit data from the secondary startup password respectively, and splice the lower 8-bit data and the higher 8-bit data to obtain a final startup password;
[0053] S8: Write the final startup password into the MCU register of the data receiving device.
[0054] In this embodiment, after writing the function data into the device, the verification system obtains the CPU ID of the data receiving device, and splices the CPU ID and a preset second key value (the second key value is customized by the manufacturer) in sequence to obtain an initial startup password. Then, the initial startup password is encrypted using the shA256 encryption algorithm to obtain a secondary startup password. The verification system screens out the lower 8-bit data and the higher 8-bit data from the secondary startup password respectively, and splices the lower 8-bit data and the higher 8-bit data to obtain a final startup password. Finally, the verification system writes the final startup password into the MCU register of the data receiving device; the final startup password generated by the verification system is used to verify the legitimacy of the operator of the data receiving device each time the data receiving device is powered on, so as to prevent the data receiving device from being misappropriated.
[0055] Further, after the step of writing the final startup password into the MCU register of the data receiving device, it includes:
[0056] S9: When the data receiving device is powered on, collect the third key value input by the user;
[0057] S10: Sequentially splice the CPU ID and the third key value to obtain an initial input password;
[0058] S11: Use the shA256 encryption algorithm to encrypt the initial input password to obtain a final input password;
[0059] S12: Determine whether the final input password is the same as the final power-on password;
[0060] S13: If the final input password is not the same as the final power-on password, control the data receiving device to restart the system.
[0061] In this embodiment, each time the data receiving device is powered on, the user (i.e., the operator of the data receiving device) needs to input a third key value (equivalent to the power-on password) to the data receiving device. The verification system retrieves the CPU ID of the data receiving device and sequentially splices the CPU ID and the third key value to obtain an initial input password. Then, the verification system uses the shA256 encryption algorithm to perform shA256 encryption on the initial input password to obtain a final input password. The verification system determines whether the final input password is the same as the final power-on password stored in the MCU register. If the final input password is not the same as the final power-on password, it means that the user is illegally using the data receiving device and the data receiving device may have been stolen. Therefore, the verification system controls the data receiving device to restart the system and waits for the user to input the third key value again until the verification passes. If the verification fails, the data receiving device will keep restarting the system.
[0062] Further, after the step of writing the function data into the data receiving device, the following steps are further included:
[0063] S14: Obtain the initial write count of the data storage device;
[0064] S15: Update the initial write count to obtain the current write count.
[0065] In this embodiment, after writing the functional data of the data storage device into the data receiving device, the verification system will obtain the initial write count of the data storage device (i.e., the remaining write count of the data storage device currently), and then subtract one from the initial write count to update the initial write count, and the updated value is the current write count. Preferably, each time the data storage device is connected to the data receiving device, the verification system will verify the write count of the data storage device. If the current write count of the data storage device is 0, the data storage device is not allowed to write the functional data into the data receiving device. After the manufacturer initializes the write count of the data storage device, the data storage device can be used normally.
[0066] Referring to Figure 2 , in an embodiment of the present application, a verification device for data writing is further provided, including:
[0067] Monitoring module 1, configured to monitor whether the data writing function is triggered;
[0068] First verification module 2, configured to verify whether the data storage device is a genuine device if the data writing function is triggered, where the data storage device is a device for storing functional data;
[0069] Second verification module 3, configured to verify whether the data storage device meets the functional conditions if the data storage device is a genuine device;
[0070] Writing module 4, configured to write the functional data into the data receiving device if the data storage device meets the functional conditions.
[0071] Further, the first verification module 2 includes:
[0072] Generating unit, configured to generate an initial verification command and send the initial verification command to the data storage device;
[0073] Receiving unit, configured to receive a feedback verification command, where the feedback verification instruction is feedback information generated by the data storage device according to the initial verification command;
[0074] Identifying unit, configured to identify whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command;
[0075] First determination unit, configured to determine that the data storage device is a genuine device if the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device.
[0076] Further, the length of the feedback verification command is 25 bits, and the identifying unit includes:
[0077] An encryption subunit, configured to encrypt the first 23 bits of the first data of the feedback check command to obtain second data;
[0078] A screening subunit, configured to screen the data ranked first and second in the second data as third data, and use the data ranked third and fourth in the second data as fourth data;
[0079] A judgment subunit, configured to judge whether the third data is the same as the 24th bit data of the feedback check command, and judge whether the fourth data is the same as the 25th bit data of the feedback check command;
[0080] A determination subunit, configured to determine that the first encryption logic is consistent with the second encryption logic if the third data is the same as the 24th bit data of the feedback check command, and the fourth data is the same as the 25th bit data of the feedback check command.
[0081] Further, the length of the feedback check command is 25 bits, and the feedback check command sequentially includes 5 bits of fixed header data and 12 bits of Ethernet MAC address. The second check module 3 includes:
[0082] A splicing unit, configured to splice the Ethernet MAC address and the first key value to obtain a secondary check command;
[0083] An encryption unit, configured to encrypt the secondary check command to obtain a tertiary check command;
[0084] A judgment unit, configured to screen 16 bits of data from the 6th bit to the 21st bit in the feedback check command as verification data, and judge whether the verification data is the same as the tertiary check command;
[0085] A second determination unit, configured to determine that the data storage device meets the functional conditions if the verification data is the same as the tertiary check command.
[0086] Further, the check device further includes:
[0087] A first splicing module 5, configured to obtain the CPU ID of the data receiving device, and sequentially splice the CPU ID with the second key value to obtain an initial startup password;
[0088] A first encryption module 6, configured to encrypt the initial startup password using the shA256 encryption algorithm to obtain a secondary startup password;
[0089] A screening module 7, configured to respectively screen out the lower 8-bit data and the higher 8-bit data from the secondary startup password, and splice the lower 8-bit data and the higher 8-bit data to obtain the final startup password;
[0090] A storage module 8, configured to write the final startup password into the MCU register of the data receiving device.
[0091] Furthermore, the verification device further includes:
[0092] An acquisition module 9, configured to acquire a third key value input by a user when the data receiving device is powered on;
[0093] A second splicing module 10, configured to sequentially splice the CPU ID and the third key value to obtain an initial input password;
[0094] A second encryption module 11, configured to encrypt the initial input password using the SHA256 encryption algorithm to obtain a final input password;
[0095] A judgment module 12, configured to judge whether the final input password is consistent with the final startup password;
[0096] A restart module 13, configured to control the data receiving device to restart the system if the final input password is inconsistent with the final startup password.
[0097] Furthermore, the verification device further includes:
[0098] An acquisition module 14, configured to acquire the initial write count of the data storage device;
[0099] An update module 15, configured to update the initial write count to obtain the current write count.
[0100] In this embodiment, each module, unit, and subunit in the verification device for data writing is used to correspondingly execute each step in the above data writing verification method, and the specific implementation process thereof will not be elaborated herein.
[0101] A data writing verification device provided in this embodiment. The verification system monitors in real time whether the data writing function is triggered. If the data writing function is triggered, it first verifies whether the data storage device is a genuine device, where the data storage device is a device for storing functional data. If the data storage device is a genuine device, it then verifies whether the data storage device meets the functional conditions. If the data storage device meets the functional conditions, it indicates that the functional data stored in the data storage device is legal and has a relatively high confidence level. Therefore, the functional data is written into the data receiving device. Through two verifications of the data storage device for genuine device and functional conditions, this application effectively guarantees the legality of the functional data passing the verification, which can not only guarantee the legitimate interests of the producers of the functional data, but also improve the security guarantee for the data receiving device.
[0102] Referring to Figure 3 , an embodiment of this application also provides a computer device, which can be a server, and its internal structure can be as Figure 3 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as functional data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a data writing verification method.
[0103] The steps for the above-mentioned processor to execute the above-mentioned data writing verification method are as follows:
[0104] S1: Monitor whether the data writing function is triggered;
[0105] S2: If the data writing function is triggered, verify whether the data storage device is a genuine device, where the data storage device is a device for storing functional data;
[0106] S3: If the data storage device is a genuine device, verify whether the data storage device meets the functional conditions;
[0107] S4: If the data storage device meets the functional conditions, write the functional data into the data receiving device.
[0108] Further, the step of verifying whether the data storage device is a genuine device includes:
[0109] S201: The data receiving device generates an initial verification command and sends the initial verification command to the data storage device;
[0110] S202: The data receiving device receives a feedback verification command, and the feedback verification instruction is feedback information generated by the data storage device according to the initial verification command;
[0111] S203: Identify whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command;
[0112] S204: If the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device, it is determined that the data storage device is a legitimate device.
[0113] Further, the length of the feedback verification command is 25 bits. The step of identifying whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command includes:
[0114] S20401: Encrypt the first 23 bits of the first data of the feedback verification command to obtain second data;
[0115] S20402: Select the data ranked first and second in the second data as third data, and select the data ranked third and fourth in the second data as fourth data;
[0116] S20403: Determine whether the third data is the same as the 24th bit data of the feedback verification command, and determine whether the fourth data is the same as the 25th bit data of the feedback verification command;
[0117] S20404: If the third data is the same as the 24th bit data of the feedback verification command, and the fourth data is the same as the 25th bit data of the feedback verification command, it is determined that the first encryption logic is consistent with the second encryption logic.
[0118] Further, the length of the feedback verification command is 25 bits. The feedback verification command sequentially includes 5 bits of fixed header data and 12 bits of Ethernet MAC address. The step of verifying whether the data storage device meets the functional conditions includes:
[0119] S301: Concatenate the Ethernet MAC address and the first key value to obtain a secondary verification command;
[0120] S302: Encrypt the secondary verification command to obtain a tertiary verification command;
[0121] S303: Screen the 16-bit data from the 6th to the 21st bit in the feedback verification command as verification data, and determine whether the verification data is the same as the triple verification command;
[0122] S304: If the verification data is the same as the triple verification command, it is determined that the data storage device meets the functional conditions.
[0123] Further, after the step of writing the functional data into the data receiving device, it includes:
[0124] S5: Obtain the CPU ID of the data receiving device, and sequentially splice the CPU ID with the second key value to obtain the initial boot password;
[0125] S6: Encrypt the initial boot password using the shA256 encryption algorithm to obtain the secondary boot password;
[0126] S7: Screen out the lower 8-bit data and the upper 8-bit data from the secondary boot password respectively, and splice the lower 8-bit data and the upper 8-bit data to obtain the final boot password;
[0127] S8: Write the final boot password into the MCU register of the data receiving device.
[0128] Further, after the step of writing the final boot password into the MCU register of the data receiving device, it includes:
[0129] S9: When the data receiving device is powered on, collect the third key value input by the user;
[0130] S10: Sequentially splice the CPU ID with the third key value to obtain the initial input password;
[0131] S11: Encrypt the initial input password using the shA256 encryption algorithm to obtain the final input password;
[0132] S12: Determine whether the final input password is consistent with the final boot password;
[0133] S13: If the final input password is not consistent with the final boot password, control the data receiving device to restart the system.
[0134] Further, after the step of writing the functional data into the data receiving device, it also includes:
[0135] S14: Obtain the initial write count of the data storage device;
[0136] S15: Update the initial write count to obtain the current write count.
[0137] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, a data writing verification method is implemented. The data writing verification method is specifically as follows:
[0138] S1: Monitor whether the data writing function is triggered;
[0139] S2: If the data writing function is triggered, verify whether the data storage device is a genuine device. The data storage device is a device for storing functional data;
[0140] S3: If the data storage device is a genuine device, verify whether the data storage device meets the functional conditions;
[0141] S4: If the data storage device meets the functional conditions, write the functional data to the data receiving device.
[0142] Further, the step of verifying whether the data storage device is a genuine device includes:
[0143] S201: The data receiving device generates an initial verification command and sends the initial verification command to the data storage device;
[0144] S202: The data receiving device receives a feedback verification command, and the feedback verification instruction is feedback information generated by the data storage device according to the initial verification command;
[0145] S203: Identify whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command;
[0146] S204: If the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device, determine that the data storage device is a genuine device.
[0147] Further, the length of the feedback verification command is 25 bits. The step of identifying whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command includes:
[0148] S20401: Encrypt the first 23 bits of the first data of the feedback verification command to obtain second data;
[0149] S20402: Select the data ranked first and second in the second data as the third data, and select the data ranked third and fourth in the second data as the fourth data;
[0150] S20403: Determine whether the third data is the same as the 24th bit data of the feedback verification command, and determine whether the fourth data is the same as the 25th bit data of the feedback verification command;
[0151] S20404: If the third data is the same as the 24th bit data of the feedback verification command, and the fourth data is the same as the 25th bit data of the feedback verification command, it is determined that the first encryption logic is consistent with the second encryption logic.
[0152] Further, the length of the feedback verification command is 25 bits. The feedback verification command sequentially includes 5-bit fixed header data and 12-bit Ethernet MAC address. The step of verifying whether the data storage device meets the functional conditions includes:
[0153] S301: Concatenate the Ethernet MAC address and the first key value to obtain a secondary verification command;
[0154] S302: Encrypt the secondary verification command to obtain a tertiary verification command;
[0155] S303: Select 16-bit data from the 6th bit to the 21st bit of the feedback verification command as verification data, and determine whether the verification data is the same as the tertiary verification command;
[0156] S304: If the verification data is the same as the tertiary verification command, it is determined that the data storage device meets the functional conditions.
[0157] Further, after the step of writing the functional data into the data receiving device, it includes:
[0158] S5: Obtain the CPU ID of the data receiving device, and sequentially concatenate the CPU ID with the second key value to obtain an initial startup password;
[0159] S6: Encrypt the initial startup password using the shA256 encryption algorithm to obtain a secondary startup password;
[0160] S7: Select the lower 8-bit data and the higher 8-bit data from the secondary startup password respectively, and concatenate the lower 8-bit data and the higher 8-bit data to obtain a final startup password;
[0161] S8: Write the final startup password into the MCU register of the data receiving device.
[0162] Further, after the step of writing the final startup password into the MCU register of the data receiving device, it includes:
[0163] S9: When the data receiving device is powered on, collect the third key value input by the user;
[0164] S10: Sequentially splice the CPU ID and the third key value to obtain an initial input password;
[0165] S11: Use the shA256 encryption algorithm to encrypt the initial input password to obtain a final input password;
[0166] S12: Determine whether the final input password is the same as the final power-on password;
[0167] S13: If the final input password is not the same as the final power-on password, control the data receiving device to restart the system.
[0168] Further, after the step of writing the function data into the data receiving device, the following steps are further included:
[0169] S14: Obtain the initial write count of the data storage device;
[0170] S15: Update the initial write count to obtain the current write count.
[0171] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium provided in the present application and used in the embodiments can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0172] It should be noted that in this text, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, first object or method comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, apparatus, first object or method. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, apparatus, first object or method comprising such element.
[0173] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall similarly be included within the patent protection scope of the present application.
Claims
1. A method for verifying data writing, characterized in that, Including: Monitoring whether the data writing function is triggered; If the data writing function is triggered, verifying whether the data storage device is a genuine device, where the data storage device is a device for storing functional data and stores functional data; If the data storage device is a genuine device, verifying whether the data storage device meets the functional conditions; If the data storage device meets the functional conditions, writing the functional data to the data receiving device; The step of verifying whether the data storage device is a genuine device includes: The data receiving device generates an initial verification command and sends the initial verification command to the data storage device; The data receiving device receives a feedback verification command, where the feedback verification command is feedback information generated by the data storage device according to the initial verification command; Identifying whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command; If the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device, determining that the data storage device is a genuine device; The length of the feedback verification command is 25 bits. The step of verifying whether the data storage device meets the functional conditions includes: Concatenating the Ethernet MAC address and the first key value to obtain a secondary verification command; the first key value is associated with the function, and different functions correspond to different first key values; Encrypting the secondary verification command to obtain a tertiary verification command; Filtering 16-bit data from the 6th to 21st bits of the feedback verification command as verification data, and determining whether the verification data is the same as the tertiary verification command; If the verification data is the same as the tertiary verification command, determining that the data storage device meets the functional conditions; The length of the feedback verification command is 25 bits. The step of identifying whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command includes: Encrypting the first 23-bit first data of the feedback verification command to obtain second data; Filtering the data ranked first and second in the second data as third data, and using the data ranked third and fourth in the second data as fourth data; Determining whether the third data is the same as the 24th bit data of the feedback verification command, and determining whether the fourth data is the same as the 25th bit data of the feedback verification command; If the third data is the same as the 24th bit data of the feedback verification command, and the fourth data is the same as the 25th bit data of the feedback verification command, determining that the first encryption logic is consistent with the second encryption logic.
2. The data writing verification method according to claim 1, characterized in that, After the step of writing the functional data to the data receiving device, including: Obtain the CPU ID of the data receiving device, and sequentially splice the CPU ID with the second key value to obtain the initial boot password; the second key value is customized by the manufacturer; Use the shA256 encryption algorithm to encrypt the initial boot password to obtain the secondary boot password; Respectively screen out the lower 8-bit data and the higher 8-bit data from the secondary boot password, and splice the lower 8-bit data and the higher 8-bit data to obtain the final boot password; Write the final boot password into the MCU register of the data receiving device.
3. The data writing verification method according to claim 2, characterized in that, After the step of writing the final boot password into the MCU register of the data receiving device, it includes: When the data receiving device is powered on, collect the third key value input by the user; the third key value is the boot password; Sequentially splice the CPU ID with the third key value to obtain the initial input password; Use the shA256 encryption algorithm to encrypt the initial input password to obtain the final input password; Judge whether the final input password is consistent with the final boot password; If the final input password is not consistent with the final boot password, control the data receiving device to restart the system.
4. The data writing verification method according to claim 1, characterized in that, After the step of writing the function data into the data receiving device, it further includes: Obtain the initial write count of the data storage device; Update the initial write count to obtain the current write count.
5. A verification device for data writing, characterized in that, It includes: A monitoring module for monitoring whether the data writing function is triggered; A first verification module for verifying whether the data storage device is a genuine device if the data writing function is triggered. The data storage device is a device for storing function data, and the data storage device stores function data; A second verification module for verifying whether the data storage device meets the function conditions if the data storage device is a genuine device; A writing module for writing the function data into the data receiving device if the data storage device meets the function conditions; The first verification module includes: A generating unit for generating an initial verification command and sending the initial verification command to the data storage device; A receiving unit for receiving a feedback verification command, where the feedback verification command is feedback information generated by the data storage device according to the initial verification command; An identifying unit for identifying whether the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device according to the feedback verification command; A first determination unit for determining that the data storage device is a genuine device if the first encryption logic of the data storage device is consistent with the second encryption logic of the data receiving device; The length of the feedback verification command is 25 bits, and the feedback verification command sequentially includes 5-bit fixed header data and 12-bit Ethernet MAC address. The second verification module includes: A splicing unit for splicing the Ethernet MAC address and the first key value to obtain a secondary verification command; the first key value is associated with the function, and different functions correspond to different first key values; An encryption unit, configured to encrypt the secondary verification command to obtain a tertiary verification command; A judgment unit, configured to screen out 16-bit data from the 6th bit to the 21st bit in the feedback verification command as verification data, and judge whether the verification data is the same as the tertiary verification command; A second determination unit, configured to determine that the data storage device meets the functional conditions if the verification data is the same as the tertiary verification command; The length of the feedback verification command is 25 bits, and the identification unit includes: An encryption subunit, configured to encrypt the first 23-bit data of the feedback verification command to obtain second data; A screening subunit, configured to screen out the data ranked first and second in the second data as third data, and use the data ranked third and fourth in the second data as fourth data; A judgment subunit, configured to judge whether the third data is the same as the 24th bit data of the feedback verification command, and judge whether the fourth data is the same as the 25th bit data of the feedback verification command; A determination subunit, configured to determine that the first encryption logic is consistent with the second encryption logic if the third data is the same as the 24th bit data of the feedback verification command and the fourth data is the same as the 25th bit data of the feedback verification command; 6. A computer device, comprising a memory and a processor, wherein a computer program is stored in the memory, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Data protection method for chip rewriting equipment, electronic equipment and storage medium
CN107451494A
Authority verification method, storage medium and electronic equipment
CN112398824A