A method for implementing firmware upgrade, a permission management device, and a chip
Through the permission management device and the two-way authentication and key negotiation of the chip to be upgraded, a temporary key encryption firmware file is generated, which solves the security and life cycle management problems during the firmware download process of embedded chips and improves the security of firmware upgrades.
Patent Information
- Application Number
- CN202210708664.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-21
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-06-21
AI Technical Summary
Existing embedded chips are vulnerable to man-in-the-middle attacks during firmware downloading, resulting in leaks in firmware files and unable to effectively manage the life cycle of the firmware.
Through the permission management device, two-way authentication and key negotiation are carried out with the chip to be upgraded, a temporary key is generated to encrypt the firmware file, forming the firmware ciphertext data, and sending it to the chip to be upgraded for firmware upgrade.
Improves the security of firmware upgrades, avoids firmware file leakage caused by man-in-the-middle attacks, and realizes effective management of the firmware life cycle.
Smart Images

Figure CN115016819B_ABST
Abstract
Description
Technical Field
[0001] This document relates to, but is not limited to, embedded chip technology, and particularly to a method for implementing firmware upgrade, a permission management device, and a chip. Background Art
[0002] Most of the embedded chips on the market currently do not support encrypted download. Attackers can easily recover the firmware of the chip by collecting and organizing the data during the transmission process, stealing the achievements of the firmware developers and infringing on the legitimate rights and interests of the developers.
[0003] With the development of embedded chip technology, the design and production processes of embedded products have also been segmented; chip application design manufacturers conduct application design, and the final products are produced by manufacturers. Chip application design manufacturers hope to control the entire life cycle of embedded products; mainly including online or offline download methods based on whether the embedded chip supports secure firmware upgrade. Figure 1 and Figure 2 For the schematic diagram of firmware download in related technologies, see Figure 1 and Figure 2 For an embedded chip that cannot support secure firmware download and upgrade, the non-securely downloaded embedded chip realizes firmware download through connection with a download device; some embedded chips provide a firmware download method. Before downloading, key negotiation is first performed through the Elliptic Curve Diffie-Hellman (ECDH) method, but the ECDH method cannot protect against the leakage of firmware code by the "man-in-the-middle attack" method; at this time, there is a risk of firmware code leakage when chip application design manufacturers perform online upgrade or offline upgrade. Before downloading the firmware, the securely downloaded embedded chip conducts communication authentication with the download device and then performs firmware download; the embedded chip with the secure download function can protect the integrity and privacy of the embedded chip firmware during the transmission process, but when entrusting a third party for production, the firmware code needs to be provided to the third party, increasing the risk of firmware code leakage, and the life cycle of firmware download cannot be effectively managed by controlling the number of firmware downloads.
[0004] In summary, how to achieve secure download of firmware and manage the life cycle of firmware has become a problem to be solved. Summary of the Invention
[0005] The following is an overview of the subject matter described in detail in this document. This overview is not intended to limit the scope of protection of the claims.
[0006] Embodiments of the present invention provide a method for implementing firmware upgrade, a permission management device, and a chip, which can achieve secure download of firmware.
[0007] Embodiments of the present invention provide a method for implementing firmware upgrade, including:
[0008] The privilege management device pre-storing the firmware file performs two-way authentication with the chip to be upgraded;
[0009] When the two-way authentication is passed, the privilege management device and the chip to be upgraded perform key negotiation to obtain a temporary key for encrypting the firmware file;
[0010] The privilege management device encrypts the firmware file stored in itself with the obtained temporary key to obtain firmware ciphertext data;
[0011] The privilege management device sends the encrypted firmware ciphertext data to the chip to be upgraded, so that the chip to be upgraded performs firmware upgrade according to the firmware ciphertext data.
[0012] On the other hand, an embodiment of the present invention further provides a method for implementing firmware upgrade, including:
[0013] The chip to be upgraded performs two-way authentication with the privilege management device pre-storing the firmware file;
[0014] When the two-way authentication is passed, the chip to be upgraded and the privilege management device perform key negotiation to obtain a temporary key for encrypting the firmware file;
[0015] The chip to be upgraded receives the firmware ciphertext data from the privilege management device and performs firmware upgrade according to the received firmware ciphertext data;
[0016] Wherein, the firmware ciphertext data is: the data obtained by the privilege management device encrypting the firmware file with the temporary key.
[0017] On yet another aspect, an embodiment of the present invention further provides a privilege management device storing a firmware file for firmware upgrade of a chip to be upgraded, including: a first two-way authentication unit, a first key negotiation unit, a first encryption unit, and a sending unit; wherein,
[0018] The first two-way authentication unit is configured to: perform two-way authentication with the chip to be upgraded;
[0019] The first key negotiation unit is configured to: when the first two-way authentication unit and the chip to be upgraded pass the two-way authentication, perform key negotiation with the chip to be upgraded to obtain a temporary key for encrypting the firmware file;
[0020] The first encryption unit is configured to: encrypt the firmware file with the obtained temporary key to obtain firmware ciphertext data;
[0021] The sending unit is configured to: send the encrypted firmware ciphertext data to the chip to be upgraded, so that the chip to be upgraded performs firmware upgrade according to the firmware ciphertext data.
[0022] On the other hand, an embodiment of the present invention further provides a chip, including: a second two-way authentication unit, a second key negotiation unit, and an upgrade unit; wherein,
[0023] The second two-way authentication unit is configured to perform two-way authentication with a permission management device that pre-stores firmware files;
[0024] The second key negotiation unit is configured to: when the second two-way authentication unit passes the two-way authentication, the chip to be upgraded negotiates a key with the permission management device to obtain a temporary key for encrypting the firmware file;
[0025] The upgrade unit is configured to: receive firmware ciphertext data from the permission management device and perform firmware upgrade according to the received firmware ciphertext data;
[0026] Wherein, the firmware ciphertext data is: data obtained by the permission management device encrypting the firmware file according to the temporary key.
[0027] The technical solution of this application includes: a permission management device that pre-stores firmware files performs two-way authentication with the chip to be upgraded; when passing the two-way authentication, the permission management device and the chip to be upgraded negotiate a key to obtain a temporary key for encrypting the firmware file; the permission management device encrypts the firmware file stored in itself through the obtained temporary key to obtain firmware ciphertext data; the permission management device sends the encrypted firmware ciphertext data to the chip to be upgraded so that the chip to be upgraded performs firmware upgrade according to the firmware ciphertext data. By adding a permission management device to perform two-way authentication and key negotiation with the chip to be upgraded, the embodiment of the present invention avoids the leakage of firmware files caused by man-in-the-middle attacks when only using key negotiation, and improves the security of firmware upgrade.
[0028] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained through the structures specifically pointed out in the specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The drawings are used to provide a further understanding of the technical solution of the present invention, and constitute a part of the specification. Together with the embodiments of this application, they are used to explain the technical solution of the present invention and do not constitute a limitation to the technical solution of the present invention.
[0030] Figure 1 Schematic diagram for firmware download in related technologies;
[0031] Figure 2 Schematic diagram for another firmware download in related technologies;
[0032] Figure 3 It is a flowchart of the method for implementing firmware upgrade in an embodiment of the present invention;
[0033] Figure 4 It is a schematic diagram of the composition of the permission management device in an embodiment of the present invention;
[0034] Figure 5 It is an interactive schematic diagram of two-way authentication and key negotiation in an embodiment of the present invention;
[0035] Figure 6 It is a schematic diagram of the firmware upgrade system in an embodiment of the present invention;
[0036] Figure 7 It is a flowchart of another method for implementing firmware upgrade in an embodiment of the present invention;
[0037] Figure 8 It is a schematic diagram of firmware upgrade in an embodiment of the present invention;
[0038] Figure 9 It is a block diagram of the composition of the permission management device in an embodiment of the present invention;
[0039] Figure 10 It is a block diagram of the composition of the chip in an embodiment of the present invention. Detailed implementation manners
[0040] To make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be noted that, without conflict, the embodiments and features in the embodiments of the present application can be combined with each other arbitrarily.
[0041] The steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions. And, although the logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in a different order.
[0042] Figure 3 It is a flowchart of the method for implementing firmware upgrade in an embodiment of the present invention, as Figure 3 shown, including:
[0043] Step 301, perform two-way authentication between the permission management device pre-storing the firmware file and the chip to be upgraded;
[0044] Step 302, when the two-way authentication is passed, perform key negotiation between the permission management device and the chip to be upgraded to obtain a temporary key for encrypting the firmware file;
[0045] Step 303, the permission management device encrypts the firmware file stored in itself with the obtained temporary key to obtain firmware ciphertext data;
[0046] Step 304: The permission management device sends the encrypted firmware ciphertext data to the chip to be upgraded, so that the chip to be upgraded performs firmware upgrade according to the firmware ciphertext data.
[0047] In an exemplary instance, the chip to be upgraded in the embodiment of the present invention includes: an embedded chip to be upgraded.
[0048] In the embodiment of the present invention, the permission management device is used as a secure carrier for firmware file download. It can be used as the key (KEY) of the online download server during online download and as an offline download device during offline download. Through the newly added permission management device, two-way authentication and key negotiation are carried out with the chip to be upgraded, avoiding the leakage of firmware files caused by "man-in-the-middle attack" when only key negotiation is adopted, and improving the security of firmware upgrade.
[0049] In an exemplary instance, the two-way authentication between the permission management device and the chip to be upgraded in the embodiment of the present invention includes:
[0050] The permission management device performs two-way authentication with the chip to be upgraded through a symmetric algorithm.
[0051] Based on the firmware upgrade process of the chip to be upgraded, the embodiment of the present invention uses a symmetric algorithm for two-way authentication, and improves the security of firmware upgrade through a high-speed and simple two-way authentication process. In an exemplary instance, the embodiment of the present invention can perform two-way authentication based on an asymmetric algorithm.
[0052] In an exemplary instance, the permission management device in the embodiment of the present invention may be composed of a storage chip and a security chip. Figure 4 For the schematic diagram of the composition of the permission management device in the embodiment of the present invention, as Figure 4 shown, the storage chip is used to store firmware files, and the security chip is used to perform two-way authentication and key negotiation. The security chip internally supports functions such as asymmetric algorithms (error correction code (ECC), elliptic curve public key cryptography algorithm (SM2), and RSA (RSA is an algorithm proposed by Ronald Rivest, Adi Shamir, and Leonard Adleman)), symmetric algorithms (Advanced Encryption Standard (AES), Data Encryption Standard (DES), Triple Data Encryption Algorithm (3DES), and Block Cipher Algorithm (SM4)), digest algorithms (Hash and Cryptographic Hash Algorithm (SM3)), random numbers, etc.
[0053] In an exemplary instance, the permission management device in the embodiment of the present invention is composed of Figure 4It consists of the storage chip and the security chip shown, and the life cycle management function can be run by the security chip. In an exemplary instance, the relevant data of life cycle management can be stored by the security chip, and storing through the security chip ensures the security of critical data.
[0054] In an exemplary instance, the method of the embodiment of the present invention further includes:
[0055] The permission management device encrypts the stored firmware file with a pre-configured storage key; decrypts the firmware file with the storage key before encrypting the firmware file with a temporary key, and the encryption process with the storage key improves the storage security of the firmware file.
[0056] In an exemplary instance, the embodiment of the present invention can perform key negotiation based on the result of mutual authentication.
[0057] In an exemplary instance, the method of the embodiment of the present invention further includes:
[0058] The permission management device performs life cycle management on the stored firmware file.
[0059] In an exemplary instance, the permission management device of the embodiment of the present invention performs mutual authentication with the chip to be upgraded through a symmetric algorithm, including:
[0060] The permission management device reads the first data (EKr1(R1 + SN)) encrypted according to the first root key (Kr1) from the chip to be upgraded, and decrypts the first data (EKr1(R1 + SN)) with the second root key (Kr2) to obtain the first random number (R1) and the chip unique identifier (SN); wherein, the first root key and the second root key are the same pre-set root keys; the second root key is stored in the permission management device, and the first root key is stored in the chip to be upgraded; the first data is the data (EKr1(R1 + SN)) obtained by encrypting the first random number and the chip unique identifier with the first root key;
[0061] When the permission management device determines that the decrypted chip unique identifier is valid according to the pre-stored chip unique identifier of the chip to be upgraded, it generates a second random number (R2);
[0062] The permission management device encrypts the first random number (R1) and the generated second random number (R2) with the decrypted first random number (R1) to generate the first encrypted data ER1(R1 + R2); and sends the generated first encrypted data (ER1(R1 + R2)) to the chip to be upgraded;
[0063] The permission management device receives the second encrypted data ER2(R2) from the chip to be upgraded, decrypts the received second encrypted data ER2(R2) according to the generated second random number, obtains the second random number in the second encrypted data ER2(R2), and determines that the two-way authentication is passed when the second random number obtained by decrypting the second encrypted data ER2(R2) is the same as the second random number generated by itself;
[0064] Among them, the second encrypted data is: the chip to be upgraded decrypts the first encrypted data through its own first random number, and when its own first random number is the same as the first random number obtained by decryption, the data obtained by encrypting the second random number (R2) according to the second random number obtained by decryption.
[0065] In an exemplary instance, the permission management device of the embodiment of the present invention negotiates keys with the chip to be upgraded, including:
[0066] The permission management device and the chip to be upgraded perform cross-positioning processing on the first random number and the second random number to obtain a third random number;
[0067] Calculate the third random number according to a preset calculation rule to obtain a temporary key.
[0068] In an exemplary instance, the embodiment of the present invention performs a hash calculation on the third random number to obtain a temporary key. Figure 5 For the interactive schematic diagram of two-way authentication and key negotiation in the embodiment of the present invention, as Figure 5 shown, the permission management device and the chip to be upgraded in the embodiment of the present invention perform two-way authentication through the first key, the second key, the first random number, the second random number, and the chip unique identifier.
[0069] In an exemplary instance, the method of the embodiment of the present invention further includes:
[0070] The permission management device sends the interaction information between itself and the chip to be upgraded to a preset terminal, so that the preset terminal transparently transmits the received interaction information;
[0071] Among them, the interaction information includes: communication information for two-way authentication, and / or transmission instruction information for sending firmware ciphertext data to the chip to be upgraded.
[0072] The embodiment of the present invention visually displays the progress of firmware upgrade by sending interaction information to a preset terminal and performing transparent transmission.
[0073] The firmware upgrade system of the embodiment of the present invention includes a terminal for transparently transmitting interaction information, a chip to be upgraded, and a permission management device; when performing firmware upgrade, the above system is handed over to a third-party manufacturer.
[0074] Figure 6Schematic diagram of the firmware upgrade system according to an embodiment of the present invention, as Figure 6 shown, the terminal for transparent transmission of interaction information is connected between the permission management device and the chip to be upgraded; in an exemplary instance, the terminal for transparent transmission of interaction information is connected to the permission management device through a multi-bus communication interface; the terminal for transparent transmission of interaction information is connected to the chip to be upgraded through an interface supporting firmware download.
[0075] In an exemplary instance, the permission management device in the embodiment of the present invention provides a variety of bus interfaces, including but not limited to: Inter-Integrated Circuit (IIC), Serial Peripheral Interface (SPI), Asynchronous Serial Interface (UART), Universal Serial Bus (USB), etc. for communication reception.
[0076] The firmware file in the embodiment of the present invention can be stored after being encrypted by the security chip in the permission management device to protect the security of the firmware file. The permission management device can support online and offline firmware downloads, so it can adapt to a variety of usage scenarios; through the control of the firmware download life cycle and transmission control, the leakage of the firmware file is avoided, and the security of the firmware file during the firmware upgrade process is improved.
[0077] Figure 7 Flowchart of another method for implementing firmware upgrade according to an embodiment of the present invention, as Figure 7 shown, includes:
[0078] Step 701, the chip to be upgraded performs two-way authentication with the permission management device that pre-stores the firmware file;
[0079] Step 702, when passing the two-way authentication, the chip to be upgraded and the permission management device perform key negotiation to obtain a temporary key for encrypting the firmware file;
[0080] Step 703, the chip to be upgraded receives the firmware ciphertext data from the permission management device and performs firmware upgrade according to the received firmware ciphertext data;
[0081] Among them, the firmware ciphertext data is: the data obtained by the permission management device encrypting the firmware file according to the temporary key.
[0082] In the embodiment of the present invention, through the newly added permission management device, two-way authentication and key negotiation are performed with the chip to be upgraded, avoiding the leakage of the firmware file caused by the "man-in-the-middle attack" when only using key negotiation, and improving the security of the firmware upgrade.
[0083] Figure 8 Schematic diagram of firmware upgrade according to an embodiment of the present invention, as Figure 8 shown, for the chip to be upgraded with the function of secure ciphertext download, the firmware upgrade in the embodiment of the present invention includes:
[0084] Step 801: The chip to be upgraded performs mutual authentication and key negotiation with the permission management device to determine a temporary key.
[0085] Step 802: The security chip in the permission management device reads the firmware file from the storage chip and decrypts the firmware file using the storage key.
[0086] Step 803: The permission management device encrypts the decrypted firmware file using the temporary key to obtain firmware ciphertext data.
[0087] Step 804: The chip to be upgraded downloads the firmware ciphertext data and performs integrity detection after downloading the firmware ciphertext data; in an exemplary instance, the embodiment of the present invention can perform integrity verification through a digest algorithm; including but not limited to: performing integrity verification according to the digest value of the firmware ciphertext data.
[0088] Step 805: After the chip to be upgraded completes the integrity detection of the firmware ciphertext data, it upgrades the firmware using the firmware ciphertext data after integrity detection.
[0089] In an exemplary instance, before the chip to be upgraded performs mutual authentication with the permission management device that pre-stores the firmware file, the method of the embodiment of the present invention further includes:
[0090] When the chip to be upgraded is a chip for non-secure download, a preset secondary startup Boot file is loaded in the chip to be upgraded, so that the chip to be upgraded has one or any combination of the following functions: mutual authentication, key negotiation, and downloading of firmware ciphertext data.
[0091] It should be noted that the embodiment of the present invention can design and implement the secondary Boot file according to the security requirements of firmware download and the chip characteristics; how to implement ciphertext download and integrity detection can be designed and implemented with reference to related technologies.
[0092] In an exemplary instance, a preset secondary startup Boot file is loaded in the chip to be upgraded in the embodiment of the present invention, and the chip to be upgraded has the function of integrity detection of the firmware.
[0093] In an exemplary instance, when the chip to be upgraded in the embodiment of the present invention is a chip that supports secure download, the native Boot file in the chip to be upgraded enables the chip to be upgraded to have one or any combination of the following functions: mutual authentication, key negotiation, firmware ciphertext download, and integrity detection of the firmware.
[0094] In an exemplary instance, after the chip to be upgraded negotiates keys with the permission management device, the method of the embodiment of the present invention further includes:
[0095] After receiving the first encrypted data from the permission management device, the chip to be upgraded decrypts the first encrypted data ER1(R1+R2) with its own first random number (R1).
[0096] When it is compared that its own first random number is the same as the first random number obtained by decryption, the second random number (R2) in the decrypted data is read.
[0097] The second random number (R2) is encrypted according to the second random number (R2) obtained by decryption to obtain the second encrypted data ER2(R2), and the obtained second encrypted data ER2(R2) is sent to the permission management device.
[0098] In an exemplary instance, when the chip to be upgraded is a chip that does not support secure download, the method of the embodiment of the present invention further includes:
[0099] According to the unique serial number (SN) of the chip to be upgraded and the dispersion factor in the secondary boot, the first random number is calculated.
[0100] In an exemplary instance, the first random number is obtained by hash calculation of the SN and the dispersion factor.
[0101] The chip that does not support secure download in the embodiment of the present invention obtains the first random number by calculation, providing data support for realizing two-way authentication.
[0102] Figure 9 This is the block diagram of the permission management device in the embodiment of the present invention, which stores the firmware file for firmware upgrade of the chip to be upgraded, including: a first two-way authentication unit, a first key negotiation unit, a first encryption unit and a sending unit; wherein,
[0103] The first two-way authentication unit is set to: perform two-way authentication with the chip to be upgraded;
[0104] The first key negotiation unit is set to: when the first two-way authentication unit and the chip to be upgraded pass two-way authentication, perform key negotiation with the chip to be upgraded to obtain a temporary key for encrypting the firmware file;
[0105] The first encryption unit is set to: encrypt the firmware file with the obtained temporary key to obtain the firmware ciphertext data;
[0106] The sending unit is set to: send the encrypted firmware ciphertext data to the chip to be upgraded, so that the chip to be upgraded performs firmware upgrade according to the firmware ciphertext data.
[0107] In an exemplary instance, the permission management device of the embodiment of the present invention further includes a lifecycle management unit, which is set to:
[0108] Perform lifecycle management on the stored firmware file.
[0109] In an exemplary instance, the first two-way authentication unit of the embodiment of the present invention is configured as follows: the permission management device performs two-way authentication with the chip to be upgraded through a symmetric algorithm.
[0110] In an exemplary instance, the first two-way authentication unit of the embodiment of the present invention is configured as follows:
[0111] The permission management device reads the first data encrypted according to the first root key from the chip to be upgraded, and decrypts the first data through the second root key to obtain the first random number and the unique chip identifier;
[0112] When the permission management device determines that the unique chip identifier obtained by decryption is valid according to the unique chip identifier of the chip to be upgraded stored in advance, it generates a second random number;
[0113] The permission management device encrypts the first random number obtained by decryption and the generated second random number through the first random number obtained by decryption to generate the first encrypted data; and sends the generated first encrypted data to the chip to be upgraded;
[0114] The permission management device receives the second encrypted data from the chip to be upgraded, and decrypts the received second encrypted data according to the generated second random number to obtain the second random number in the second encrypted data. When the second random number obtained by decrypting the second encrypted data is the same as the second random number generated by itself, it determines that the two-way authentication is passed;
[0115] Wherein, the first root key and the second root key are the same preset root keys; the second root key is stored in the permission management device; the first data is the data obtained by encrypting the first random number and the unique chip identifier with the first root key; the second encrypted data is: when the chip to be upgraded decrypts the first encrypted data through its own first random number and its own first random number is the same as the first random number obtained by decryption, the data obtained by encrypting the second random number with the second random number obtained by decryption.
[0116] In an exemplary instance, the first key negotiation unit of the embodiment of the present invention is configured as follows:
[0117] The permission management device and the chip to be upgraded perform a cross-positioning process on the first random number and the second random number to obtain a third random number;
[0118] The third random number is calculated according to a preset calculation rule to obtain a temporary key.
[0119] Figure 10 It is a block diagram of the chip of the embodiment of the present invention, including: a second two-way authentication unit, a second key negotiation unit and an upgrade unit; wherein,
[0120] The second two-way authentication unit is configured to perform two-way authentication with a privilege management device that pre-stores a firmware file;
[0121] The second key negotiation unit is configured to: when the second two-way authentication unit passes the two-way authentication, the chip to be upgraded negotiates a key with the privilege management device to obtain a temporary key for encrypting the firmware file;
[0122] The upgrade unit is configured to: receive firmware ciphertext data from the privilege management device and perform firmware upgrade according to the received firmware ciphertext data;
[0123] Wherein, the firmware ciphertext data is data obtained by the privilege management device encrypting the firmware file according to the temporary key.
[0124] In an exemplary instance, the chip to be upgraded in the embodiment of the present invention further includes a loading unit, configured to:
[0125] Load a preset secondary startup Boot file so that the chip to be upgraded itself has one or any combination of the following functions: two-way authentication, key negotiation, and firmware ciphertext data download.
[0126] In an exemplary instance, the chip to be upgraded in the embodiment of the present invention further includes a second encryption unit, configured to:
[0127] After receiving the first encrypted data from the privilege management device, decrypt the first encrypted data with its own first random number; when it is compared that its own first random number is the same as the first random number obtained by decryption, read the second random number in the data obtained by decryption; encrypt the second random number according to the second random number obtained by decryption to obtain second encrypted data, and send the obtained second encrypted data to the privilege management device.
[0128] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof. In the hardware implementation, the division of the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, one physical component may have multiple functions, or one function or step may be executed by several physical components in cooperation. Some or all of the components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application specific integrated circuit. Such software can be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and may include any information delivery medium.
Claims
1. A method for implementing firmware upgrade, comprising: Performing two-way authentication between a privilege management device pre-storing a firmware file and a chip to be upgraded; When passing the two-way authentication, performing key negotiation between the privilege management device and the chip to be upgraded to obtain a temporary key for encrypting the firmware file; The privilege management device encrypts the firmware file stored in itself with the obtained temporary key to obtain firmware ciphertext data; The privilege management device sends the encrypted firmware ciphertext data to the chip to be upgraded, so that the chip to be upgraded performs firmware upgrade according to the firmware ciphertext data; Wherein, the two-way authentication between the privilege management device and the chip to be upgraded includes: the privilege management device reads first data encrypted according to a first root key from the chip to be upgraded, and decrypts the first data with a second root key to obtain a first random number and a unique chip identifier; when the privilege management device determines that the unique chip identifier obtained by decryption is valid according to the pre-stored unique chip identifier of the chip to be upgraded, generating a second random number; the privilege management device encrypts the first random number obtained by decryption and the generated second random number with the first random number obtained by decryption to generate first encrypted data; sending the generated first encrypted data to the chip to be upgraded; the privilege management device receives second encrypted data from the chip to be upgraded, and decrypts the received second encrypted data according to the generated second random number to obtain the second random number in the second encrypted data, and when the second random number obtained by decrypting the second encrypted data is the same as the second random number generated by itself, determining that the two-way authentication passes; wherein, the first root key and the second root key are the same pre-set root keys; the second root key is stored in the privilege management device; the first data is data obtained by encrypting the first random number and the unique chip identifier with the first root key; the second encrypted data is: when the chip to be upgraded decrypts the first encrypted data with its own first random number and its own first random number is the same as the first random number obtained by decryption, data obtained by encrypting the second random number with the second random number obtained by decryption.
2. The method according to claim 1, characterized in that, The method further includes: The privilege management device performs lifecycle management on the stored firmware file.
3. The method according to claim 1 or 2, characterized in that, The key negotiation between the privilege management device and the chip to be upgraded includes: The privilege management device and the chip to be upgraded perform cross-positioning processing on the first random number and the second random number to obtain a third random number; Calculating the third random number according to a pre-designed calculation rule to obtain the temporary key.
4. A method for implementing firmware upgrade, comprising: Performing two-way authentication between a chip to be upgraded and a privilege management device pre-storing a firmware file; When passing the two-way authentication, performing key negotiation between the chip to be upgraded and the privilege management device to obtain a temporary key for encrypting the firmware file; The chip to be upgraded receives firmware ciphertext data from the privilege management device and performs firmware upgrade according to the received firmware ciphertext data; Among them, the firmware ciphertext data is the data obtained by the permission management device encrypting the firmware file according to the temporary key; the two-way authentication between the chip to be upgraded and the permission management device pre-storing the firmware file includes: the chip to be upgraded receives the first encrypted data from the permission management device, and the first encrypted data is obtained by the permission management device through the following processing: the permission management device reads the first data encrypted according to the first root key from the chip to be upgraded, and decrypts the first data through the second root key to obtain the first random number and the unique chip identifier; when the permission management device determines that the unique chip identifier obtained by decryption is valid according to the unique chip identifier of the chip to be upgraded pre-stored, it generates a second random number; the permission management device encrypts the first random number obtained by decryption and the generated second random number through the first random number obtained by decryption to generate the first encrypted data; the chip to be upgraded decrypts the first encrypted data through its own first random number, and when its own first random number is the same as the first random number obtained by decryption, it encrypts the second random number according to the second random number obtained by decryption to obtain the second encrypted data; the chip to be upgraded sends the second encrypted data to the permission management device, so that the permission management device decrypts the received second encrypted data according to the generated second random number to obtain the second random number in the second encrypted data, and when the second random number obtained by decrypting the second encrypted data is the same as the second random number generated by itself, it determines that the two-way authentication is passed; among them, the first root key and the second root key are the same preset root keys; the second root key is stored in the permission management device; the first data is the data obtained by encrypting the first random number and the unique chip identifier through the first root key.
5. The method according to claim 4, characterized in that, Before the two-way authentication between the chip to be upgraded and the permission management device pre-storing the firmware file, the method further includes: When the chip to be upgraded is a non-secure download chip, a preset secondary startup Boot file is loaded in the chip to be upgraded, so that the chip to be upgraded has one or any combination of the following functions: two-way authentication, key negotiation, and firmware ciphertext data download.
6. The method according to claim 4 or 5, characterized in that After the key negotiation between the chip to be upgraded and the permission management device, the method further includes: After the chip to be upgraded receives the first encrypted data from the permission management device, it decrypts the first encrypted data with its own first random number; When it is compared that its own first random number is the same as the first random number obtained by decryption, it reads the second random number in the decrypted data; It encrypts the second random number according to the second random number obtained by decryption to obtain the second encrypted data, and sends the obtained second encrypted data to the permission management device.
7. A permission management device that stores firmware files for firmware upgrade of a chip to be upgraded, including: The first two-way authentication unit, the first key negotiation unit, the first encryption unit, and the sending unit; among them, The first two-way authentication unit is configured to perform two-way authentication with the chip to be upgraded. Among them, performing two-way authentication with the chip to be upgraded includes: reading the first data encrypted according to the first root key from the chip to be upgraded, and decrypting the first data with the second root key to obtain the first random number and the unique chip identifier; generating a second random number when it is determined that the unique chip identifier obtained by decryption is valid according to the pre-stored unique chip identifier of the chip to be upgraded; encrypting the first random number obtained by decryption and the generated second random number with the first random number obtained by decryption to generate the first encrypted data; sending the generated first encrypted data to the chip to be upgraded; receiving the second encrypted data from the chip to be upgraded, and decrypting the received second encrypted data with the generated second random number to obtain the second random number in the second encrypted data. When the second random number obtained by decrypting the second encrypted data is the same as the second random number generated by itself, it is determined that the two-way authentication is passed; among them, the first root key and the second root key are the same pre-set root keys; the second root key is stored in the permission management device; the first data is the data obtained by encrypting the first random number and the unique chip identifier with the first root key; the second encrypted data is: when the chip to be upgraded decrypts the first encrypted data with its own first random number and its own first random number is the same as the first random number obtained by decryption, the data obtained by encrypting the second random number with the second random number obtained by decryption. The first key negotiation unit is configured to: when the first two-way authentication unit and the chip to be upgraded pass the two-way authentication, negotiate a key with the chip to be upgraded to obtain a temporary key for encrypting the firmware file. The first encryption unit is configured to: encrypt the firmware file with the obtained temporary key to obtain the firmware ciphertext data. The sending unit is configured to: send the encrypted firmware ciphertext data to the chip to be upgraded so that the chip to be upgraded performs firmware upgrade according to the firmware ciphertext data.
8. A chip, comprising: The second two-way authentication unit, the second key negotiation unit and the upgrade unit; among them, The second two-way authentication unit is configured to perform two-way authentication with a privilege management device that pre-stores a firmware file. Among them, performing two-way authentication with a privilege management device that pre-stores a firmware file includes: receiving first encrypted data from the privilege management device; decrypting the first encrypted data with its own first random number, and when the first random number of itself is the same as the first random number obtained by decryption, encrypting the second random number with the second random number obtained by decryption to obtain second encrypted data; sending the second encrypted data to the privilege management device, so that the privilege management device decrypts the received second encrypted data according to the generated second random number to obtain the second random number in the second encrypted data, and when the second random number obtained by decrypting the second encrypted data is the same as the second random number generated by itself, it is determined that the two-way authentication is passed; among them, the first root key and the second root key are the same pre-set root keys; the second root key is stored in the privilege management device; the first data is data obtained by encrypting the first random number and the chip unique identifier with the first root key; the first encrypted data is obtained by the privilege management device through the following processing: reading the first data encrypted according to the first root key from the chip, and decrypting the first data with the second root key to obtain the first random number and the chip unique identifier; when it is determined that the chip unique identifier obtained by decryption is valid according to the pre-stored chip unique identifier of the chip to be upgraded, generating a second random number; encrypting the first random number obtained by decryption and the generated second random number with the first random number obtained by decryption to generate the first encrypted data; The second key negotiation unit is configured to: when the second two-way authentication unit passes the two-way authentication, the chip to be upgraded negotiates a key with the privilege management device to obtain a temporary key for encrypting the firmware file; The upgrade unit is configured to: receive firmware ciphertext data from the privilege management device and perform firmware upgrade according to the received firmware ciphertext data; Among them, the firmware ciphertext data is: data obtained by the privilege management device encrypting the firmware file with the temporary key.
Citation Information
Patent Citations
Method and server for identifying risk application
CN107480519A
TEE-based firmware upgrading method and device
CN113849210A
Bluetooth security communication method, device and equipment for bank peripherals and medium
CN113905359A