Method, system and electronic device for processing key
By encrypting the HDCP key multiple times and performing encryption and decryption operations in a secure space, the problem of the key being cracked by the burning tool and intercepted during transmission is solved, the secure transmission and storage of the key is achieved, and the security and integrity of the key is ensured.
Patent Information
- Application Number
- CN202210661326.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-13
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2042-06-13
AI Technical Summary
In the prior art, HDCP keys are easily cracked when the burning tool is decompiled, and the keys may be intercepted as plain text during transmission, resulting in a high risk of key leakage.
The original key is encrypted multiple times through the burning tool to generate multiple encryption keys, and encryption and decryption operations are performed in the secure space of the target device. Finally, the key is stored in a secure memory and encrypted using the device-specific encryption and decryption seed to ensure the security of the key during transmission and storage.
The encryption of keys during transmission and the security of their storage are achieved, preventing them from being intercepted and cracked, and ensuring the security and integrity of the keys.
Smart Images

Figure CN115296789B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of key protection, and in particular to a method and system for processing keys, and an electronic device. Background Art
[0002] HDCP, a technology developed in collaboration between Hollywood and semiconductor giant Intel, protects uncompressed digital audio and video content. It's compatible with high-speed digital video interfaces (DisplayPort, HDMI, and DVI), using content scrambling for protection. Designed as the last link in the content consumption chain, from source device to display device, HDCP prohibits full content copying; the Copy Control Information (CCl) only states "copy-prohibited." For system updates, HDCP uses revocation lists to block stolen device private keys.
[0003] There are many keys in HDCP, each with its own scope and impact, and they all need to be protected. Leaking a key key (such as the HECP 1.X KEY) could result in significant damages, so no matter how rigorous the protection of a key key is, it's never too late. Summary of the Invention
[0004] The present application provides a method and system for processing keys, and an electronic device, which can ensure that the plaintext KEY will not be intercepted during the burning and transmission process of the protected KEY, and after the KEY is stored in the device memory, it will not be decrypted due to the tool encryption algorithm being cracked.
[0005] In a first aspect, a method for processing a key is provided. The method includes: encrypting an original key using a flashing tool to generate a first encryption key, and sending the first encryption key to a secure space of a target device; encrypting and decrypting the first encryption key in the secure space to generate a second encryption key, and sending the second encryption key to a memory of the target device; receiving the second encryption key in the secure space, and decrypting the second encryption key to generate a first decryption key; and storing the first decryption key in a memory in the secure space.
[0006] In some embodiments, encrypting the original key through a burning tool to generate a first encryption key includes: using the original encryption and decryption seed to encrypt the original key through a first encryption and decryption algorithm to generate an original encryption key, the original encryption key including the original encryption and decryption seed and the encryption key obtained by encrypting the original key using the original encryption and decryption seed; and using the first encryption and decryption seed to encrypt the original encryption key through a second encryption and decryption algorithm to generate the first encryption key.
[0007] In some embodiments, encrypting and decrypting the first encryption key in the secure space to generate a second encryption key includes: using the first encryption and decryption seed to decrypt the first encryption key through the second encryption and decryption algorithm to generate the original encryption key; and using the second encryption and decryption seed to encrypt the original encryption key through a third encryption and decryption algorithm to generate the second encryption key.
[0008] In some embodiments, the second encryption / decryption seed is unique to the target device.
[0009] In some embodiments, decrypting the second encryption key to generate a first decryption key includes: using the second encryption and decryption seed to decrypt the second encryption key through the third encryption and decryption algorithm to generate the first decryption key, wherein the first decryption key is the original encryption key.
[0010] In some embodiments, the method further comprises: sending the second encryption key from the memory to a multimedia interface of the target device; and sending the second encryption key from the multimedia interface to the secure space.
[0011] In some embodiments, the method further includes: using the original encryption and decryption seed to decrypt the first decryption key through the first encryption and decryption algorithm to generate the original key.
[0012] In some embodiments, the original key is a High-bandwidth Digital Content Protection (HDCP) key.
[0013] In a second aspect, a system for processing a key is provided. The system includes a burning tool and a target device; the burning tool is configured to encrypt an original key to generate a first encryption key and send the first encryption key to a secure space of the target device; the target device is configured to: encrypt and decrypt the first encryption key in the secure space to generate a second encryption key, send the second encryption key to a memory of the target device; receive the second encryption key in the secure space, decrypt the second encryption key to generate a first decryption key; and store the first decryption key in a memory in the secure space.
[0014] In some embodiments, the burning tool is configured to: use the original encryption and decryption seed to encrypt the original key through a first encryption and decryption algorithm to generate an original encryption key, wherein the original encryption key includes the original encryption and decryption seed and the original encryption key obtained by encrypting the original key using the original encryption and decryption seed; and use the first encryption and decryption seed to encrypt the original encryption key through a second encryption and decryption algorithm to generate the first encryption key.
[0015] In some embodiments, the target device is configured to: use the first encryption seed to decrypt the first encryption key through the second encryption algorithm to generate the original encryption key; and use the second encryption seed to encrypt the original encryption key through a third encryption algorithm to generate the second encryption key.
[0016] In some embodiments, the target device includes a one-time programmable memory configured to store the second encryption / decryption seed unique to the target device.
[0017] In some embodiments, the target device is configured to: use the second encryption seed to decrypt the second encryption key through the third encryption algorithm to generate the first decryption key, wherein the first decryption key is the original encryption key.
[0018] In some embodiments, the target device is further configured to: send the second encryption key from the memory to a multimedia interface of the target device; and send the second encryption key from the multimedia interface to the secure space.
[0019] In some embodiments, the target device is further configured to: use the original encryption and decryption seed to decrypt the first decryption key through the first encryption and decryption algorithm to generate the original key.
[0020] In a third aspect, an electronic device is provided, comprising: a memory configured to store an instruction set; and a processor configured to execute the instruction set to perform any step in the above-mentioned method for processing a key.
[0021] According to an embodiment of the present invention, an original key is encrypted using a burning tool to generate a first encryption key, which is then sent to a secure space on a target device. The original key is encrypted during the burning process, preventing the plaintext key from being intercepted. The first encryption key is then encrypted and decrypted in the secure space to generate a second encryption key, which is then sent to the target device's memory. The original key is encrypted and stored in the memory, ensuring it cannot be cracked. The second encryption key is then received in the secure space and decrypted to generate a first decryption key. The first decryption key is then stored in memory within the secure space. After the key is decrypted in the secure space, it is written to the secure space's memory. This register is a secure register that can only be written but not read, so the corresponding value cannot be retrieved after it is written, ensuring the security of the key. Furthermore, this write operation is performed within the secure space and is invisible to the user.
[0022] Furthermore, the first encryption key is encrypted and decrypted in the secure space to generate a second encryption key, and the second encryption key is sent to the memory of the target device; the original key is encrypted and stored in the memory, and the second encryption and decryption seeds used for encryption are different for each device, ensuring that the key cannot be cracked.
[0023] The above-mentioned records related to the content of the invention are only an overview of the technical solution of this application. In order to enable ordinary technicians in this field to understand the technical solution of this application more clearly, and then implement it according to the text of the specification and the contents recorded in the drawings, and to make the above-mentioned purposes and other purposes, features and advantages of this application easier to understand, the following is an explanation in combination with the specific implementation methods and drawings of this application. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The accompanying drawings are only used to illustrate the principles, implementation methods, applications, characteristics and effects of the specific embodiments of this application and other related contents, and are not to be considered as limiting this application.
[0025] Figure 1 is a flowchart illustrating a method for processing a key according to an embodiment of the present disclosure;
[0026] Figure 2 A flowchart illustrating a method for processing a key according to an embodiment of the present disclosure;
[0027] Figure 3 A schematic diagram illustrating a method for processing a key according to an embodiment of the present disclosure;
[0028] Figure 4A schematic diagram illustrating a module of a system for processing a key according to an embodiment of the present disclosure;
[0029] Figure 5 It is a schematic diagram showing modules of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0030] In order to explain in detail the possible application scenarios, technical principles, specific solutions that can be implemented, and the purpose and effects of this application, the following is a detailed description of the specific embodiments listed in conjunction with the accompanying drawings. The embodiments described herein are only used to more clearly illustrate the technical solutions of this application and are therefore only examples and are not intended to limit the scope of protection of this application.
[0031] References to "embodiments" herein mean that the specific features, structures, or characteristics described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the word "embodiment" in various places in the specification does not necessarily refer to the same embodiment, nor does it particularly limit its independence or relevance to other embodiments. In principle, in this application, as long as there are no technical contradictions or conflicts, the various technical features mentioned in the embodiments can be combined in any manner to form a corresponding implementable technical solution.
[0032] Unless otherwise defined, the technical terms used herein have the same meanings as those generally understood by those skilled in the art to which this application belongs; the use of relevant terms herein is only for describing specific embodiments and is not intended to limit this application.
[0033] In the description of this application, the term "and / or" is used to describe a logical relationship between objects, indicating that three relationships can exist. For example, A and / or B means: A exists, B exists, and both A and B exist. In addition, the character " / " in this document generally indicates that the objects before and after are in a logical "or" relationship.
[0034] In this application, terms such as "first" and "second" are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual quantity, priority or sequence relationship between these entities or operations.
[0035] Without further limitations, in this application, the words "include", "comprise", "have" or other similar expressions used in the sentences are intended to cover non-exclusive inclusion. These expressions do not exclude the presence of additional elements in the process, method or product including the elements, so that the process, method or product including a series of elements may include not only those defined elements, but also other elements not explicitly listed, or elements inherent to such process, method or product.
[0036] In this application, expressions such as "greater than," "less than," and "exceed" are understood to exclude the number itself; expressions such as "above," "below," and "within" are understood to include the number itself. In addition, in the description of the embodiments of this application, "multiple" means two or more (including two), and similar expressions related to "multiple" are also understood in this way, such as "multiple groups" and "multiple times," unless otherwise specifically limited.
[0037] As mentioned in the background technology, the HDCP1.x KEY is a very important key, owned by the DCP organization. Every manufacturer using HDCP technology must commit to protecting this key. The leakage of this key may result in huge compensation, so no matter how strict the protection measures are, they are never too strict.
[0038] Existing technologies for protecting critical keys often have the following two flaws: 1. If the KEY burning tool is decompiled and the encryption algorithm is cracked, the original KEY can be decrypted by simply reading the HDCP KEY in the device storage space; 2. If the KEY burning tool does not encrypt the KEY, the plaintext KEY will be intercepted during the KEY burning and transmission process.
[0039] Therefore, this application encrypts the original key during the burning and transmission process, so that the plaintext KEY cannot be intercepted during the key burning and transmission process. In addition, the original key is stored in memory after encryption, and the encryption seed used for encryption is different for each device. This ensures that even if the KEY burning tool is decompiled and the encryption algorithm is cracked, when reading the KEY stored in the device storage space, it still cannot decrypt the original key.
[0040] The following is an explanation of some of the terms involved in this article:
[0041] Secure space: refers to the security domain of the chip. The secure space and the normal space have memory isolation and are inaccessible to users. Users cannot see the read and write operations of the secure space.
[0042] Burning tool: refers to the Windows burning tool that burns the original key into the memory of the target device.
[0043] In some embodiments, the original key refers to a High-bandwidth Digital Content Protection HDCP key, such as HDCP1.xKEY.
[0044] Hereinafter, specific implementations according to embodiments of the present disclosure will be described in detail with reference to exemplary embodiments and in conjunction with the accompanying drawings.
[0045] Figure 1 FIG. 1 is a flow chart illustrating a key protection method 100 according to an embodiment of the present disclosure. Figure 1 As shown, the key protection method 100 includes steps S101 to S104.
[0046] In step S101, the original key is encrypted by a burning tool to generate a first encryption key, and the first encryption key is sent to the secure space of the target device. In this embodiment, the original key is encrypted and transmitted to the target device during the burning process. In some embodiments, the original key can be encrypted multiple times.
[0047] In step S102, the first encryption key is encrypted and decrypted in the secure space to generate a second encryption key, and the second encryption key is sent to the memory of the target device. In this embodiment, the first encryption key received from outside the target device is decrypted and re-encrypted in the secure space, so that the original key is stored in the memory outside the secure space in the form of the second encryption key, in association with the target device itself.
[0048] In step S103, the second encryption key is received in the secure space and decrypted to generate a first decryption key. In this embodiment, the second encryption key stored in the memory of the target device can be transmitted to the secure space via other components of the target device and decrypted in the secure space into a first decryption key corresponding to the original key.
[0049] In step S104, the first decryption key is stored in a memory in the secure space. In this embodiment, the first decryption key corresponding to the original key obtained by decryption in the secure space is then written to the memory in the secure space, which is a secure register. In some embodiments, the original key can be derived from the first decryption key.
[0050] Specifically, Figure 2 The specific operation of encrypting the original key by the burning tool to generate the first encryption key and the specific operation of encrypting and decrypting the first encryption key in the secure space to generate the second encryption key are shown.
[0051] In step S201, the original encryption key is encrypted using the original encryption seed through a first encryption algorithm to generate an original encryption key, where the original encryption key includes the original encryption seed and the original encryption key obtained by encrypting the original key using the original encryption seed.
[0052] In some embodiments, the original encryption and decryption seed is the encryption seed of HDCP1.4 KEY, 2 bytes. The original key is encrypted according to the first encryption and decryption algorithm provided by the IP, and the IP hardware decrypts the first decryption key in the memory using the original encryption and decryption seed.
[0053] In step S202, the original encryption key is encrypted using a second encryption algorithm using a first encryption seed to generate the first encryption key, and the first encryption key is sent to a secure space of a target device.
[0054] In step S203, the first encryption key is decrypted using the first encryption seed through the second encryption algorithm to generate the original encryption key.
[0055] In this embodiment, the first encryption and decryption seed may be a seed used for AES encryption and decryption, and is used when the burning tool encrypts the first decryption key. The first encryption and decryption seed is defined by the burning tool and has a fixed value.
[0056] In step S204, the original encryption key is encrypted using a third encryption algorithm using the second encryption seed to generate the second encryption key.
[0057] In this embodiment, the second encryption / decryption seed is unique to the target device.
[0058] In this embodiment, the second encryption seed is similar to the first encryption seed, both of which are used for AES encryption, but with different values. The second encryption seed is written to the one-time programmable memory (OTP) when the chip leaves the factory, and the second encryption seed is different for each chip.
[0059] In step S205 , the second encryption key is decrypted to generate the original encryption key, and the original encryption key is stored in the memory in the secure space.
[0060] In this embodiment, decrypting the second encryption key to generate the original encryption key includes: using the second encryption seed to decrypt the second encryption key using the third encryption algorithm to generate the original encryption key. Figure 1In this embodiment, the first decryption key is the original encryption key. It should be noted that the first decryption key (i.e., the original encryption key) includes the original encryption seed and the encryption key obtained by encrypting the original key using the original encryption seed. Therefore, after obtaining the first decryption key, the HDMI controller will decrypt the original encryption seed to obtain the final original key.
[0061] In some embodiments, the method 100 further includes: sending the second encryption key from the memory to the multimedia interface (such as an HDMI interface) of the target device; and sending the second encryption key from the multimedia interface to the secure space. In some embodiments, the kernel HDMI driver determines whether the HDCP1.X function needs to be enabled. If the HDCP1.X function is required, the HDMI driver obtains the encryption key from the memory and sends it to the secure space for decryption. The decryption of the encryption key needs to be performed in the secure space in order to prevent the decrypted key from being leaked. After the encryption key is decrypted in the secure space, the key is written to the HDCP KEY memory. This step is performed in the secure space to protect the key.
[0062] The above method encrypts the original key during the burning and transmission process, preventing the plaintext key from being intercepted. Furthermore, the original key is encrypted and stored in memory, using a different secondary encryption and decryption seed for each device, ensuring that the encrypted key cannot be cracked. After the key is decrypted in the secure space, it is written to the secure space's memory. This register is a secure register, write-only and not read-only, so the corresponding value cannot be retrieved after it is written, ensuring the security of the key. Furthermore, this write operation is performed in the secure space and is invisible to the user.
[0063] Hereinafter, another embodiment of the present disclosure is described by taking an example in which the original key is an HDCP key.
[0064] Figure 3 FIG2 shows a schematic diagram of a key protection method according to an embodiment of the present disclosure. Figure 3In the burning tool, the HDCP key is encrypted using the original encryption seed to generate the original encryption key. The original encryption key is encrypted using AES under the first encryption seed to generate the first encryption key. The first encryption key is sent to the secure space of the target device. In the secure space, the first encryption key is decrypted using AES under the first encryption seed to generate the first decryption key. The first decryption key is encrypted using AES under the second encryption seed to generate the second encryption key, where the second encryption seed comes from the OTP. The second encryption key is saved in the memory. The HDMI interface receives the second encryption key from the memory and sends the second encryption key to the secure space. Thereafter, the second encryption key is decrypted using AES in the secure space using the second encryption seed to obtain the first decryption key. The first decryption key is saved in the HDCP KEY memory.
[0065] Figure 4 FIG. 4 is a schematic diagram showing a module of a system 400 for processing a key according to an embodiment of the present disclosure. Figure 4 As shown, a system 400 for processing keys includes a burning tool 401 and a target device 402 .
[0066] The burning tool 401 is configured to encrypt the original key to generate a first encryption key, and send the first encryption key to the secure space of the target device 402 .
[0067] The target device 402 is configured to encrypt and decrypt the first encryption key in the secure space to generate a second encryption key, and send the second encryption key to a memory of the target device 402. The target device 402 is configured to receive the second encryption key in the secure space, decrypt the second encryption key to generate a first decryption key, and store the first decryption key in a memory in the secure space.
[0068] In this embodiment, the burning tool 401 is configured to use the original encryption seed to encrypt the original key using a first encryption algorithm to generate an original encryption key, wherein the original encryption key includes the original encryption seed and an encryption key obtained by encrypting the original key using the original encryption seed. The burning tool 401 is configured to use the first encryption seed to encrypt the original encryption key using a second encryption algorithm to generate the first encryption key.
[0069] In this embodiment, the target device 402 is configured to use the first encryption seed to decrypt the first encryption key using the second encryption algorithm to generate the original encryption key. The target device 402 is configured to use the second encryption seed to encrypt the original encryption key using a third encryption algorithm to generate the second encryption key.
[0070] In this embodiment, the target device 402 includes a one-time programmable memory, and the one-time programmable memory is configured to store the second encryption and decryption seed unique to the target device 402 .
[0071] In this embodiment, the target device 402 is configured to use the second encryption seed to decrypt the second encryption key through the third encryption algorithm to generate the first decryption key, where the first decryption key is the original encryption key.
[0072] In this embodiment, the target device 402 is further configured to send the second encryption key from the memory to the multimedia interface of the target device 402; and send the second encryption key from the multimedia interface to the secure space.
[0073] In this embodiment, the target device 402 is further configured to use the original encryption and decryption seed to decrypt the first decryption key through the first encryption and decryption algorithm to generate the original key.
[0074] In this embodiment, the original encryption and decryption seed is the encryption seed of HDCP1.4 KEY, 2 bytes. The original key is encrypted according to the first encryption and decryption algorithm provided by the IP, and the IP hardware decrypts the first decryption key in the memory using the original encryption and decryption seed.
[0075] In this embodiment, the first encryption and decryption seed may be a seed used for AES encryption and decryption, and is used when the burning tool 401 encrypts the first decryption key. The first encryption and decryption seed is defined by the burning tool 401 and has a fixed value.
[0076] The original key is encrypted during the burning and transmission process of the above system 400, preventing the plaintext KEY from being intercepted. The original key is encrypted and stored in memory. The secondary encryption and decryption seed used for encryption is unique to each device, ensuring that the encrypted key cannot be cracked. After the key is decrypted in the secure space, it is written to the secure space's memory. This register is a secure register that can only be written but not read. Therefore, after writing, the corresponding value cannot be retrieved, ensuring the security of the key. Furthermore, this writing operation is performed in the secure space and is invisible to the user.
[0077] Figure 5 FIG. 5 is a schematic diagram showing modules of an electronic device 500 according to an embodiment of the present disclosure.
[0078] The electronic device 500 includes: a memory 501 configured to store an instruction set; and a processor 502 configured to execute the instruction set to perform any step in the above-mentioned method 100 for processing a key.
[0079] The original key burning and transmission process of the electronic device 500 is encrypted, so the plaintext KEY cannot be intercepted. The original key is encrypted and stored in the memory. The second encryption and decryption seed used for encryption is different for each device, ensuring that the encrypted key cannot be cracked. After the key is decrypted in the secure space, it is written to the memory in the secure space. This register is a secure register that can only be written but not read. Therefore, the corresponding value cannot be obtained after it is written, ensuring the security of the key. Moreover, this writing operation is performed in the secure space, and the user cannot see the writing process.
[0080] Finally, it should be noted that although the above embodiments have been described in the specification and drawings of this application, this does not limit the scope of patent protection of this application. All technical solutions generated by replacing or modifying equivalent structures or equivalent processes based on the essential concepts of this application using the contents recorded in the specification and drawings of this application, as well as directly or indirectly implementing the technical solutions of the above embodiments in other related technical fields, are included in the scope of patent protection of this application.
Claims
1. A method for processing a key, characterized in that include: Encrypting the original key using a burning tool to generate a first encryption key, and sending the first encryption key to a secure space of a target device; encrypting and decrypting the first encryption key in the secure space to generate a second encryption key, and sending the second encryption key to a memory of the target device; receiving the second encryption key in the secure space, and performing a decryption process on the second encryption key to generate a first decryption key; as well as storing the first decryption key in a memory in the secure space, The encrypting of the original key by the burning tool to generate the first encryption key includes: encrypting the original key by a first encryption algorithm using an original encryption seed to generate an original encryption key, the original encryption key including the original encryption seed and an encryption key obtained by encrypting the original key by using the original encryption seed; and encrypting the original encryption key by a second encryption algorithm using the first encryption seed to generate the first encryption key. wherein encrypting and decrypting the first encryption key in the secure space to generate the second encryption key comprises: decrypting the first encryption key using the second encryption and decryption algorithm using the first encryption and decryption seed to generate the original encryption key; and encrypting the original encryption key using a third encryption and decryption algorithm using the second encryption and decryption seed to generate the second encryption key. Decrypting the second encryption key to generate the first decryption key includes: using the second encryption and decryption seed to decrypt the second encryption key through the third encryption and decryption algorithm to generate the first decryption key, wherein the first decryption key is the original encryption key.
2. The method according to claim 1, characterized in that The second encryption / decryption seed is unique to the target device.
3. The method according to claim 1, characterized in that Also includes: sending the second encryption key from the memory to a multimedia interface of the target device; as well as The second encryption key is sent from the multimedia interface to the secure space.
4. The method according to claim 1, wherein Also includes: The first decryption key is decrypted using the original encryption / decryption seed through the first encryption / decryption algorithm to generate the original key.
5. The method according to any one of claims 1 to 4, characterized in that The original key is a High-bandwidth Digital Content Protection HDCP key.
6. A system for processing keys, characterized in that Including burning tools and target devices; The burning tool is configured to encrypt the original key to generate a first encryption key, and send the first encryption key to the secure space of the target device; The target device is configured as: encrypting and decrypting the first encryption key in the secure space to generate a second encryption key, and sending the second encryption key to a memory of the target device; receiving the second encryption key in the secure space, and performing a decryption process on the second encryption key to generate a first decryption key; as well as storing the first decryption key in a memory in the secure space, The burning tool is configured to: encrypt the original key using the original encryption and decryption seed using a first encryption and decryption algorithm to generate an original encryption key, wherein the original encryption key includes the original encryption and decryption seed and an encryption key obtained by encrypting the original key using the original encryption and decryption seed; and encrypting the original encryption key using a second encryption / decryption algorithm using the first encryption / decryption seed to generate the first encryption key, The target device is configured to: use the first encryption seed to decrypt the first encryption key using the second encryption algorithm to generate the original encryption key; use the second encryption seed to encrypt the original encryption key using a third encryption algorithm to generate the second encryption key; And using the second encryption and decryption seed to decrypt the second encryption key through the third encryption and decryption algorithm to generate the first decryption key, wherein the first decryption key is the original encryption key.
7. The system according to claim 6, characterized in that The target device includes a one-time programmable memory configured to store the second encryption / decryption seed unique to the target device.
8. The system according to claim 6, wherein: The target device is further configured to: sending the second encryption key from the memory to the multimedia interface of the target device; and The second encryption key is sent from the multimedia interface to the secure space.
9. The system according to claim 6, wherein: The target device is further configured to: The first decryption key is decrypted using the original encryption / decryption seed through the first encryption / decryption algorithm to generate the original key.
10. An electronic device, characterized in that: include: a memory configured to store an instruction set; as well as A processor configured to execute the instruction set to perform the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Encryption chip and encryption method therefor
CN105631366A
Method, device and system of online writing application secret key into digital content equipment
CN106033503A
Recorder and secret key security programming method
CN114201183A