Lib library permission management system and management method

By encrypting the Lib library with an encryption chip and a burning tool, and combining it with cloud platform verification, the problem of insufficient security of the Lib library is solved, and a high level of security access control is achieved.

CN115114673BActive Publication Date: 2026-01-30NORTH VALLEY ELECTRONICS CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210726734.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-23
Publication Date
2026-01-30
Estimated Expiration
2042-06-23

AI Technical Summary

Technical Problem

Existing libraries lack security restrictions, allowing any individual or product to call their internal functions, resulting in a high risk of security function leakage.

Method used

The Lib library is encrypted using an encryption chip and a burning tool. The security of the Lib library is ensured by verifying the legitimacy of the software through chip permission certificates and random number signatures, combined with verification by the cloud platform.

Benefits of technology

It effectively prevents unauthorized calls to the library, ensures the library's security, prevents the leakage of security features, and improves the library's security level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115114673B_ABST
    Figure CN115114673B_ABST
Patent Text Reader

Abstract

This invention provides a permission control system and method for a library, comprising: an encryption chip for sending a chip permission certificate and an encryption chip ID to the library, and for obtaining a random number sent by the library and returning a random number signature; each encryption chip has an encryption chip ID, a chip permission certificate, and a private key; and a cloud platform for obtaining the encryption chip ID and the random number from the library to determine whether the encryption chip ID is duplicated or valid. The library, functional software, and encryption chip are integrated into the same product. The library considers the verification between the encryption chip and the library successful after verifying the permission certificate and the random number signature. The encryption chip of this invention encrypts the library. Before the functional software accesses the library, the library needs to verify the encryption chip. Only after successful verification can the functional software access the library, thus ensuring the security of the library.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to a permission control system and method for a library. Background Technology

[0002] Functional software can provide users with a wide variety of features. To implement these features, the software needs to call functions. If there are too many functions, a database is needed for storage. For example, for security reasons, a library (static link library) can be used. Libraries can effectively prevent the leakage of technical secrets.

[0003] However, in current technology, libraries lack security restrictions. Any product or individual with access to a library can call its internal functions. Therefore, the leakage of some libraries involving security features could lead to major security incidents and irreparable consequences. Summary of the Invention

[0004] The purpose of this invention is to provide a permission control system and method for Lib libraries, which can ensure the security of Lib libraries.

[0005] To achieve the above objectives, this invention provides a library access control system for encrypting and verifying the libraries included in a product. Upon successful verification, the functional software included in the product gains the right to access the libraries. The system includes:

[0006] An encryption chip is used to send a chip permission certificate and an encryption chip ID to the Lib library. It is also used to obtain a random number sent by the Lib library and return a random number signature to the Lib library. Each encryption chip has an encryption chip ID, a chip permission certificate and a private key.

[0007] A programming tool is used to read the public key and the encryption chip ID from the encryption chip and return the chip authorization certificate, wherein one public key corresponds to one private key; and

[0008] The Lib library, functional software, and encryption chip are integrated into the same product. After the Lib library verifies that the permission certificate and the random number signature are both valid, it is considered that the verification of the encryption chip and the Lib library has passed.

[0009] Optionally, the control system further includes a cloud platform, used to obtain the encryption chip ID and random number from the Lib library to determine whether the encryption chip ID is duplicated or valid, and also used to return a platform certificate and a signature of the encryption chip ID and random number to the Lib library.

[0010] Optionally, in the aforementioned control system, the Lib library includes a root certificate used to verify the legality of the chip permission certificate and platform certificate.

[0011] Optionally, in the aforementioned control system, the encryption chip is also used to store the chip's authorization certificate and private key.

[0012] Optionally, in the aforementioned control system, the Lib library includes a random number generation module for generating random numbers.

[0013] Optionally, in the aforementioned control system, the encryption chip includes a signature module for signing the random number.

[0014] Accordingly, the present invention also provides a method for permission control of a library, including:

[0015] The programming tool reads the public key and the encryption chip ID from the encryption chip and generates a chip access certificate, and then programs the chip access certificate into the encryption chip.

[0016] The Lib library sends a random number to the encryption chip and obtains the chip authorization certificate and random number signature from the encryption chip;

[0017] Verify the validity of the chip permission certificate and random number signature. If they are invalid, the functional software loses the right to call the Lib library; if they are valid, the functional software gains the right to call the Lib library.

[0018] Optionally, the control method further includes:

[0019] The library sends the encryption chip ID and a random number to the cloud platform;

[0020] The cloud platform determines whether the encryption chip ID is duplicated or valid on the cloud platform. If it is duplicated or invalid, it considers that the private key of the encryption chip has been leaked and issues an alarm.

[0021] The cloud platform sends the platform certificate, the encryption chip ID, and the signature of the random number to the Lib library;

[0022] The Lib library determines whether the platform certificate, the encryption chip ID, and the signature of the random number are valid;

[0023] If the access is valid, the cloud platform gains the right to access and manage the Lib library; if the access is invalid, the cloud platform loses the right to access and manage the Lib library.

[0024] Optionally, in the aforementioned control method, the method by which the library verifies the validity of the permission certificate includes:

[0025] The library verifies the validity of the permission certificate based on its built-in root certificate.

[0026] Optionally, in the aforementioned control method, the method by which the library verifies the legitimacy of the platform certificate includes:

[0027] The library verifies the legitimacy of the platform certificate based on its built-in root certificate.

[0028] In the access control system and method for the Lib library provided by this invention, the encryption chip encrypts the Lib library. The Lib library, the encryption chip, and the functional software are located on the same product. Before the functional software accesses the Lib library, the Lib library needs to verify the encryption chip. Only after the verification is successful can the functional software access the Lib library, thereby ensuring the security of the Lib library. Attached Figure Description

[0029] Figure 1 This is a schematic diagram of the permission control system of the Lib library according to an embodiment of the present invention;

[0030] Figure 2 This is a flowchart of the permission control method for the Lib library according to an embodiment of the present invention;

[0031] In the diagram: 110 - Product, 111 - Library, 112 - Functional Software, 113 - Encryption Chip, 120 - Burning Tool, 130 - Cloud Platform. Detailed Implementation

[0032] The specific embodiments of the present invention will now be described in more detail with reference to the accompanying drawings. The advantages and features of the present invention will become clearer from the following description. It should be noted that the drawings are all in a very simplified form and use non-precise proportions, and are only used to facilitate and clarify the illustration of the embodiments of the present invention.

[0033] In the following text, the terms “first,” “second,” etc., are used to distinguish between similar elements and are not necessarily used to describe a specific order or chronological sequence. It should be understood that these terms, as used herein, may be replaced where appropriate. Similarly, if the methods described herein comprise a series of steps, and the order of these steps presented herein is not necessarily the only possible order in which they can be performed, and some described steps may be omitted and / or other steps not described herein may be added to the method.

[0034] Please refer to Figure 1This invention provides a permission control system and method for a library, used to encrypt a library 111 included in product 110 and verify it against the library 111. After successful verification, the functional software 112 included in product 110 is granted the right to call the library 111, including:

[0035] Encryption chip 113 is used to send chip permission certificate and encryption chip ID to Lib library 111. It is also used to obtain random numbers sent by Lib library 111 and return random number signatures to Lib library 111. An encryption chip 113 has an encryption chip ID, a chip permission certificate and a private key.

[0036] The programming tool 120 is used to read the public key and encryption chip ID from the encryption chip 113 and return the chip authorization certificate; one public key corresponds to one private key.

[0037] Among them, the Lib library 111, the functional software 112 and the encryption chip 113 are integrated on the same product 110. After the Lib library 111 verifies that the permission certificate and the random number signature are both valid, it is considered that the verification of the encryption chip 113 and the Lib library 111 is successful.

[0038] Furthermore, the access control system also includes a cloud platform 130, used to obtain the encryption chip ID and random number from the Lib library 111 to determine whether the encryption chip ID is duplicated or valid. If it is duplicated or invalid, it indicates that the encryption chip ID has been leaked, and the Lib library 111 is in an insecure environment. Simultaneously, the cloud platform 130 is also used to return the platform certificate and the signature of the encryption chip ID and random number to the Lib library 111. By determining whether the encryption chip ID is duplicated, it verifies whether the encryption chip's private key has been leaked. After the platform certificate and the signature of the encryption chip ID and random number are verified, the cloud platform 130 is also used to access and manage the Lib library. The cloud platform and the Lib library are transmitted over a network, such as 2G, 3G, 4G, or Wi-Fi. Both the cloud platform and the Lib library belong to the same owner. If the access control system does not have a cloud platform, access to the Lib library can be obtained only after verification of the encryption chip. If a cloud platform is present, access to the Lib library requires verification of both the encryption chip and the cloud platform.

[0039] Furthermore, the Lib library 111 includes a root certificate used to verify the legitimacy of the chip authorization certificate and platform certificate. The encryption chip 113 also stores the chip authorization certificate and private key; the private key cannot be read outside the encryption chip in any way. The platform certificate, the programming tool 120, and the chip authorization certificate are all generated by signing with the private key and can be verified by the root certificate.

[0040] Furthermore, the Lib library 111 includes a random number generation module for generating random numbers. The encryption chip 113 includes a signature module for signing the random numbers.

[0041] Please refer to Figure 2 The present invention also provides a method for permission control of a library, including:

[0042] S1: The programming tool reads the public key and the encryption chip ID from the encryption chip and generates a chip access certificate, and then programs the chip access certificate into the encryption chip;

[0043] S2: The Lib library sends a random number to the encryption chip, which serves as a request to obtain the chip authorization certificate, and obtains the chip authorization certificate and the random number signature from the encryption chip;

[0044] S3: Verify the validity of the chip authorization certificate and random number signature. If they are invalid, the functional software loses the right to call the Lib library. If they are valid, the functional software gains the right to call the Lib library.

[0045] Furthermore, the access control methods for libraries also include:

[0046] The Lib library sends the encryption chip ID and a random number to the cloud platform as a request to obtain the platform certificate;

[0047] The cloud platform determines whether the encryption chip ID is duplicated or valid on the cloud platform. If it is duplicated or invalid, it assumes that the encryption chip's private key has been leaked and triggers an alarm.

[0048] The cloud platform sends the platform certificate, along with the encryption chip ID and a random number signature, to the Lib library.

[0049] The Lib library determines whether the platform certificate, encryption chip ID, and random number signature are valid;

[0050] If it is legal, the cloud platform gains access to and management of the Lib library; if it is illegal, the cloud platform loses access to and management of the Lib library.

[0051] In this embodiment of the invention, the programming tool writes the chip authorization certificate into the encryption chip. Specifically, the programming tool issues and programs the chip authorization certificate to the encryption chip on the product that will use the Lib library. Each encryption chip has a unique certificate, i.e., one chip, one certificate. This process is only performed once during the production stage of the product that will use the Lib library and will not occur during subsequent normal use of the product. Once programming is successful, the private key formed by the product's public key, the encryption chip ID, and the authorization certificate are all unique. Therefore, the Lib library can verify whether the product's functional software calls the Lib library by using these unique private keys, encryption chip IDs, and authorization certificates, thereby completing the encryption and verification of the Lib library.

[0052] Preferably, the encryption chip and library are verified multiple times. The cloud platform and library are also verified multiple times. Both the verification of the encryption chip and library, and the verification of the cloud platform and library, occur during product use. The more frequent the verification of either the encryption chip and library, or the cloud platform and library, the more secure the library will be.

[0053] In this embodiment of the invention, one encryption chip ID corresponds to one private key. If the private key is leaked, other users can copy the encryption chip to pass the verification of the library and thus obtain the library's functions and methods, leading to a security breach in the library. Since the private key also corresponds to a unique encryption chip ID, if the private key is leaked, it means that the thief is using the encryption chip ID to access the library. The library transmits the encryption chip ID to the cloud platform, so whether the encryption chip ID obtained by the cloud platform is duplicated can be used to determine if the private key has been leaked. If a leak is detected, an alarm is triggered, prompting the library owner to take action.

[0054] In this embodiment of the invention, the method for the Lib library to verify the validity of the authorization certificate includes: the Lib library verifies the validity of the authorization certificate based on its built-in root certificate. More specifically, the Lib library generates a random number and sends it to the encryption chip. The encryption chip sends its chip authorization certificate and the random number signature together to the Lib library. The Lib library uses its root certificate to verify the validity of the authorization certificate and the random number signature. If valid, the verification passes, and the functional software gains the right to call the Lib library; otherwise, the verification fails, and the functional software loses the right to call the Lib library. The Lib library's verification of the encryption chip can be performed when the product is powered on, or periodically during the usage period after power-on.

[0055] In this embodiment of the invention, the method for the Lib library to verify the legitimacy of the platform certificate includes: the Lib library verifies the legitimacy of the platform certificate based on its own root certificate. More specifically, the Lib library generates a random number and transmits the random number and the encryption chip ID to the cloud platform. The cloud platform sends a signature of the platform certificate + (encryption chip ID + random number) to the Lib library. The Lib library uses the root certificate to verify its legitimacy; if it is legitimate, it passes; otherwise, it fails. The cloud platform records and saves the encryption chip ID reported by the Lib library. The platform can verify the legitimacy of the encryption chip ID. If the encryption chip ID is legitimate, it is considered that the functional chip can call the Lib library; if it is illegitimate, it is considered that the functional chip cannot call the Lib library. In other words, the cloud platform can be used as a tool to further verify the legitimacy of the encryption chip, further improving the security of the Lib library. At the same time, the cloud platform can also determine whether the uploaded encryption chip ID is duplicated. If it is duplicated with the encryption chip ID stored on the platform, it is considered that the private key of the encryption chip has been leaked. The leakage of the private key may affect the uniqueness of the root certificate, which may lead to other products that steal the private key passing the verification of the Lib library's root certificate, seriously affecting the security of the Lib library. Therefore, when the private key of the encryption chip is leaked, an alarm can be triggered to alert the user. In this embodiment of the invention, if there is no cloud platform or the cloud platform and the library cannot be connected, verification relying solely on the library and the encryption chip is also possible.

[0056] This invention can be applied to access control of the library in automotive electronic (mobile mechanical equipment) intelligent control devices. By adding a security chip to the hardware and improving the software interaction, access control of the library can be implemented at a very high security level, making it extremely difficult to crack. This method effectively controls access to the library; even if the library is leaked to unauthorized users, it cannot be executed normally, thus preventing unauthorized access from using the library.

[0057] In summary, in the permission control system and method for the Lib library provided in this embodiment of the invention, the encryption chip encrypts the Lib library. The Lib library, the encryption chip, and the functional software are located on the same product. Before the functional software accesses the Lib library, the Lib library needs to verify the encryption chip. Only after the verification is passed can the functional software access the Lib library, thereby ensuring the security of the Lib library.

[0058] The above are merely preferred embodiments of the present invention and do not constitute any limitation on the present invention. Any equivalent substitutions or modifications made by those skilled in the art to the technical solutions and content disclosed in the present invention without departing from the scope of the present invention shall be deemed to have remained within the protection scope of the present invention.

Claims

1. A library access control system, used to encrypt the library contained in a product and verify it. Upon successful verification, the functional software contained in the product is granted the right to access the library, characterized in that... The application comprises: an encryption chip for sending a chip permission certificate and an encryption chip ID to the Lib library, and for obtaining a random number sent by the Lib library and returning a random number signature to the Lib library, one encryption chip having one encryption chip ID, one chip permission certificate and one private key; a burning tool for reading a public key and the encryption chip ID from the encryption chip and returning a chip permission certificate, one public key corresponding to one private key; and wherein the Lib library, the functional software and the encryption chip are integrated on the same product, and the Lib library considers that the encryption chip and the Lib library pass the verification after verifying that the permission certificate and the random number signature are both legal; The application further comprises a cloud platform for obtaining the encryption chip ID and the random number from the Lib library to determine whether the encryption chip ID is repeated or legal, and for returning a platform certificate and the signature of the encryption chip ID and the random number to the Lib library. The Lib library comprises a root certificate for verifying whether the chip permission certificate and the platform certificate are legal.

2. The management system of claim 1, wherein, The encryption chip is further configured to store the chip permission certificate and the private key.

3. The management system of claim 1, wherein, The Lib library comprises a random number generation module for generating a random number.

4. The management system of claim 1, wherein, The encryption chip comprises a signature module for signing the random number.

5. The management system of claim 1, wherein, The application comprises:

6. A method of managing rights of a Lib library of a rights management system using the Lib library according to any one of claims 1 to 5, characterized by, the burning tool reads a public key, an encryption chip ID from the encryption chip and generates a chip permission certificate, and then burns the chip permission certificate to the encryption chip; the Lib library sends a random number to the encryption chip and obtains a chip permission certificate and a random number signature from the encryption chip; the chip permission certificate and the random number signature are verified to be legal or not, if not, the functional software loses the qualification to call the Lib library, and if yes, the functional software obtains the qualification to call the Lib library; The application further comprises: the Lib library sends the encryption chip ID and the random number to the cloud platform; the cloud platform determines whether the encryption chip ID is repeated or legal on the cloud platform, if repeated or illegal, it is considered that the private key of the encryption chip has been leaked and an alarm is given; the cloud platform sends a platform certificate and the signature of the encryption chip ID and the random number to the Lib library; the Lib library determines whether the platform certificate and the signature of the encryption chip ID and the random number are legal; if yes, the cloud platform obtains the qualification to access and manage the Lib library, and if not, the cloud platform loses the qualification to access and manage the Lib library. The method for the Lib library to verify whether the permission certificate is legal comprises:

7. The method of claim 6, wherein, the Lib library verifies whether the permission certificate is legal according to the self-provided root certificate. The method for the Lib library to verify whether the platform certificate is legal comprises:

8. The method of claim 7, wherein, the Lib library verifies whether the platform certificate is legal according to the self-provided root certificate. ​

Citation Information

Patent Citations

  • Security authentication method, and device, equipment, and storage medium

    CN110798475A

  • Library file encryption method, decryption method and encryption device

    CN114398598A