Set-top box upgrading method and apparatus, set-top box, and storage medium

By performing three-level signature encryption on the set-top box upgrade package, the problem of signatures being easily cracked in the existing technology is solved, and a safer and more efficient upgrade process is achieved.

CN115640614BActive Publication Date: 2025-10-10HUNAN GOKE MICROELECTRONICS CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211305076.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-24
Publication Date
2025-10-10
Estimated Expiration
2042-10-24

AI Technical Summary

Technical Problem

The existing set-top box upgrade method has the problem of insufficient security. The signature of the upgrade package can be easily cracked, which poses a security risk.

Method used

The upgrade package is encrypted using a three-level signature method, including performing the first signature operation on the target partition file, generating a signature partition file, and replacing the target partition file in the native upgrade package with it. The second and third signature operations are then performed to finally generate a three-level signature upgrade package. The set-top box is upgraded after performing the three-level signature verification.

Benefits of technology

This improves the security of the set-top box upgrade process, reduces packaging time, saves computing resources, and enhances the security of the upgrade process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115640614B_ABST
    Figure CN115640614B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a set-top box upgrading method and device, a set-top box and a storage medium. The embodiments of the present application adopt a three-level signature mode to sign and pack an original upgrade package, and then the set-top box verifies the original upgrade package. The set-top box upgrades only when the three-level signature verification is passed, thereby better ensuring the security of the set-top box upgrading process. In the first-level signature encryption, only important partition files are signed, thereby reducing the time consumption of packing and saving computing resources. The set-top box provided by the embodiments improves the security of the set-top box upgrading process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a set-top box upgrading method, device, set-top box and storage medium. Background Art

[0002] To protect set-top boxes from system attacks and data theft, they require secure boot and upgrades. Existing Android-based set-top boxes typically package the partition files to be upgraded using an upgrade package, sign them with a release_key, and perform RSA verification on the upgrade package during a recovery upgrade. While this upgrade method ensures the integrity of the upgrade package, it carries a certain risk of signature cracking, posing a security risk. Summary of the Invention

[0003] In order to solve the above technical problems, the embodiments of the present invention provide a set-top box upgrade method, device, set-top box and storage medium, which can encrypt the upgrade package multiple times to protect the information security of the upgrade package.

[0004] The embodiments of the present invention can be implemented as follows:

[0005] In a first aspect, an embodiment of the present invention provides a set-top box upgrade method, which is applied to a set-top box upgrade system host, and the method includes:

[0006] Get the target partition file in the native upgrade package of the set-top box;

[0007] Performing a first signature operation on the target partition file to obtain a signature partition file;

[0008] Replacing the target partition file in the native upgrade package with the signature partition file to obtain a first signature upgrade package;

[0009] Performing a second signature operation on the first signed upgrade package to obtain a second signed upgrade package;

[0010] Performing the first signature operation on the second signed upgrade package to obtain a third signed upgrade package;

[0011] Verifying the third signed upgrade package and obtaining a verification result;

[0012] If the verification result is passed, the set-top box is upgraded based on the third signed upgrade package.

[0013] In some embodiments, the step of performing a first signature operation on the target partition file includes:

[0014] Performing a first signature operation on the target partition file to obtain the first signature operation information;

[0015] Adding a first signature calculation data header area to the target partition file;

[0016] The first signature operation information is stored in the first signature operation data header area to obtain a signature partition file.

[0017] In some embodiments, the step of performing a second signature operation on the first signed upgrade package to obtain a second signed upgrade package includes:

[0018] Performing a second signature operation on the first signature upgrade package to obtain second signature operation information;

[0019] The second signature calculation information is stored in the central directory record tail area of ​​the first signature upgrade package to obtain the second signature upgrade package.

[0020] In some embodiments, the step of performing a third signature operation on the second signed upgrade package to obtain a third signed upgrade package includes:

[0021] Adding a second signature calculation data header area to the second signature upgrade package;

[0022] Obtaining the central directory record tail area of ​​the second signature upgrade package;

[0023] performing a third signature operation on the tail area of ​​the central directory record to obtain third signature operation information;

[0024] The third signature operation information is stored in the second signature operation data header area to obtain the third signature upgrade package.

[0025] In some embodiments, the step of obtaining the central directory record tail area of ​​the second signature upgrade package includes:

[0026] Obtain a central directory end identifier, and search for the central directory record tail area according to the central directory end identifier.

[0027] In a second aspect, an embodiment of the present application provides a set-top box upgrade method, which is applied to a set-top box, and the method includes:

[0028] receiving a third-signed upgrade package, and performing third-signature verification on the third-signed upgrade package;

[0029] If the third signature verification passes, obtain the second signature upgrade package based on the third signature upgrade package to perform the second signature verification;

[0030] If the second signature verification passes, obtain the first signature upgrade package based on the second signature upgrade package to perform the first signature verification;

[0031] If the first signature verification passes, a signature partition file is obtained, where the signature partition file includes first signature calculation information, where the first signature calculation information is signature information obtained by performing the first signature calculation on the target partition file;

[0032] A target upgrade file is obtained according to the signature partition file, and the upgrade is performed according to the target upgrade file, wherein the target upgrade file includes the target partition file.

[0033] In some embodiments, performing third signature verification on the third signature upgrade package includes:

[0034] Determining whether the third signed upgrade package contains a central directory end identifier;

[0035] If the third signature upgrade package includes the central directory end identifier, obtaining the central directory record tail area of ​​the third signature upgrade package;

[0036] A third signature verification is performed on the central directory record trailer area.

[0037] In some embodiments, obtaining a second signed upgrade package based on the third signed upgrade package and performing second signature verification includes:

[0038] Obtaining second signature calculation information of the tail area of ​​the central directory record;

[0039] Perform a second signature verification on the second signature upgrade package according to the second signature operation information.

[0040] In some embodiments, performing a first signature verification on the first signed upgrade package includes:

[0041] Performing a first signature operation verification on all signature partition files in the first signature upgrade package;

[0042] If all the signature partition files pass verification, it is determined that the first signature verification passes.

[0043] In a third aspect, an embodiment of the present application provides a set-top box upgrade device, which is applied to a set-top box upgrade system host, and the device includes:

[0044] An acquisition module is used to obtain the target partition file in the native upgrade package of the set-top box;

[0045] A first operation module is configured to perform a first signature operation on the target partition file to obtain a signature partition file, wherein the signature partition file includes first signature operation information;

[0046] a replacement module, configured to replace the target partition file in the native upgrade package with the signature partition file to obtain a first signature upgrade package;

[0047] A second operation module is used to perform a second signature operation on the first signed upgrade package to obtain a second signed upgrade package;

[0048] The third operation module is used to perform a third signature operation on the second signature upgrade package to obtain a third signature upgrade package, and the third signature upgrade package is used to upgrade the set-top box.

[0049] In a fourth aspect, an embodiment of the present application provides a set-top box, comprising a memory and a processor, wherein the memory is used to store a computer program, and when the computer program is run by the processor, the set-top box upgrade method provided in the second aspect is executed.

[0050] The set-top box upgrade method provided by this application uses a three-level signature method to sign and package the original upgrade package, which is then verified by the set-top box. The set-top box upgrade is performed only after the three-level signature verification is passed, which effectively ensures the security of the set-top box upgrade process. In the first-level signature encryption, only important partition files are signed, which reduces the time spent on packaging and saves computing resources. The set-top box upgrade method provided by this embodiment improves the security of the set-top box upgrade process. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solution of this application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of this application and should not be regarded as limiting the scope of protection of this application. In each of the drawings, similar components are numbered similarly.

[0052] Figure 1 A schematic diagram of a flow chart of a set-top box upgrade method provided in an embodiment of the present application is shown;

[0053] Figure 2 A schematic diagram of the structure of the native upgrade package provided in an embodiment of the present application is shown;

[0054] Figure 3 A schematic diagram of the structure of the third signature upgrade package provided in an embodiment of the present application is shown;

[0055] Figure 4 Another flowchart of the set-top box upgrade method provided by an embodiment of the present application is shown;

[0056] Figure 5 A structural schematic diagram of a set-top box upgrading device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0057] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments.

[0058] The components of the embodiments of the present application generally described and illustrated in the drawings herein may be arranged and designed in a variety of different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed application, but rather merely represents selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative effort are within the scope of protection of the present application.

[0059] Hereinafter, the terms "including", "having" and their cognates, which may be used in various embodiments of the present application, are intended only to indicate specific features, numbers, steps, operations, elements, components or combinations of the foregoing items, and should not be understood as first excluding the existence of one or more other features, numbers, steps, operations, elements, components or combinations of the foregoing items or the possibility of adding one or more features, numbers, steps, operations, elements, components or combinations of the foregoing items.

[0060] Furthermore, the terms “first,” “second,” “third,” etc., are merely used for distinguishing descriptions and are not to be understood as indicating or implying relative importance.

[0061] Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by those skilled in the art to which the various embodiments of the present application belong. The terms (such as those defined in generally used dictionaries) will be interpreted as having the same meaning as in the context of the relevant technical field and will not be interpreted as having an idealized meaning or an overly formal meaning unless clearly defined in the various embodiments of the present application.

[0062] Example 1

[0063] An embodiment of the present disclosure provides a set-top box upgrading method.

[0064] The conventional upgrade method for existing Android set-top boxes involves using the native Android upgrade package (update.zip), packaging the partition files to be upgraded, and signing the packaged files with the release_key. This upgrade process typically relies on the Recovery system, which performs RSA verification on the packaged and signed upgrade package. This approach, however, is insecure in current applications.

[0065] Based on this, seeFigure 1 An embodiment of the present invention provides a set-top box upgrade method, which is applied to a set-top box upgrade system host. The method includes:

[0066] Step S110: Obtain the target partition file in the native upgrade package of the set-top box.

[0067] In actual application, the target partition files are all the partition files included in the native upgrade package of the set-top box. Because the partition files in the native upgrade package are the most important, the target partition files are obtained first to perform the first signature operation.

[0068] Step S120: Perform a first signature operation on the target partition file to obtain a signature partition file, where the signature partition file includes first signature operation information.

[0069] After obtaining the target partition file, a first signature operation is performed on the target partition file to obtain first signature information. A signed partition file is generated based on the first signature information and the target partition file, so that the signed partition file includes the first signature information, thereby implementing a first-level encrypted signature. The first signature operation can be performed using the SM2 algorithm or the RSA algorithm. The specific signature operation method is not limited here. In this embodiment, the signature operation information can specifically be the encrypted result of the signature operation.

[0070] In some embodiments, the step of performing a first signature operation on the target partition file to obtain a signature partition file includes: performing a first signature operation on the target partition file to obtain first signature operation information; adding a first signature operation data header area to the target partition file; and storing the first signature operation information in the first signature operation data header area to obtain a signature partition file.

[0071] Specifically, a first signature calculation data header area is added to the original data structure of the target partition file. After performing the first signature calculation on the target partition file, the first signature calculation information is stored in the first signature calculation data header area to obtain a signed partition file. This facilitates the subsequent replacement of the target partition file in the native upgrade package with the signed partition file to obtain the first signed upgrade package. The length of the first signature calculation data header area can be a preset first length.

[0072] Step S130: Replace the target partition file in the native upgrade package with the signature partition file to obtain a first signature upgrade package.

[0073] Step S140: Perform a second signature operation on the first signed upgrade package to obtain a second signed upgrade package.

[0074] After obtaining the first signature upgrade package, a second signature operation is performed on the first signature upgrade package to obtain second signature information, and the second signature information is stored in the first upgrade package to obtain a second signature upgrade package, so that the second signature upgrade package includes second signature operation information, and the second signature operation can be in an RSA signature mode.

[0075] Referring to Figure 2 , Figure 2 FIG. 1 is a structural diagram of a native upgrade package of an Android system, which includes a data area, a central directory record area, and a central directory record tail area. To store the second signature information in the first upgrade package, any part of the native upgrade package can be selected to store the second signature information, or a data header area can be added to store the second signature information.

[0076] In some embodiments, the step of performing a second signature operation on the first signature upgrade package to obtain a second signature upgrade package includes: performing a second signature operation on the first signature upgrade package to obtain second signature operation information; and storing the second signature operation information in a central directory record tail area of the first signature upgrade package to obtain the second signature upgrade package.

[0077] Specifically, a second signature operation is first performed on the first signature upgrade package to obtain second signature operation information, and then the second signature operation information is stored in a central directory record tail area of the first signature upgrade package to obtain a second signature upgrade package, so that the central directory record tail area of the second signature upgrade package includes the second signature operation information, thereby realizing a second-level encryption signature.

[0078] At step S150, a third signature operation is performed on the second signature upgrade package to obtain a third signature upgrade package.

[0079] After obtaining the second signature upgrade package, a third signature operation is performed on the second signature upgrade package to obtain third signature operation information, and a third signature upgrade package is obtained according to the third signature operation information and the second signature upgrade package. The third signature operation can be in an SM2 signature algorithm, or can be selected according to actual conditions, which is not limited herein. Finally, the third signature upgrade package is a three-level encryption signature upgrade package with good security.

[0080] To reduce the size of the signature upgrade package and the subsequent set-top box signature verification process, only a portion of the data in the second signature upgrade package is selected for signature calculation. For example, because the central directory record tail area of ​​the second signature upgrade package includes the second signature information, the central directory record tail area of ​​the second signature upgrade package is selected for signature calculation. In some embodiments, the step of performing a third signature calculation on the second signature upgrade package includes: adding a second signature calculation data header area to the second signature upgrade package; obtaining the central directory record tail area of ​​the second signature upgrade package; performing a third signature calculation on the central directory record tail area to obtain third signature calculation information; and storing the third signature calculation information in the second signature calculation data header area to obtain the third signature upgrade package. The length of the second signature calculation data header area is a preset second length, which can be the same as or different from the preset first length.

[0081] In some embodiments, the step of obtaining the central directory record tail area of ​​the second signature upgrade package includes: obtaining a central directory end identifier, and searching for the central directory record tail area according to the central directory end identifier.

[0082] See also Figure 2 In the structural diagram of the native upgrade package for the Android system, the central directory record area includes the central directory file header identifier, and the communication protocol uses (0x50, 0x4b, 0x01, 0x02); the central directory record trailer area includes the central directory end identifier, and the communication protocol uses (0x50, 0x4b, 0x05, 0x06). Therefore, the central directory end identifier can be used to find the central directory record trailer area.

[0083] See Figure 3 , Figure 3 This is a data structure diagram of the third signature upgrade package. Compared with the second upgrade package, the third signature upgrade package adds a second signature operation data header area, and the second signature operation data header area includes the third signature operation information.

[0084] Step S160: The set-top box is upgraded based on the third signed upgrade package.

[0085] After obtaining the final third signature upgrade package, the set-top box can be upgraded based on the third signature upgrade package. Specifically, the set-top box system host can send the third signature upgrade package to the set-top box, so that the set-top box is upgraded based on the third signature upgrade package.

[0086] To improve security, before the set-top box system host sends the third signature upgrade package to the set-top box, it may first perform encryption on the third signature upgrade package and send the third signature upgrade package to the set-top box in ciphertext.

[0087] The set-top box upgrade method provided in this application uses a three-level signature method to sign and package the original upgrade package, which is then verified by the set-top box. The set-top box upgrade is performed only after the three-level signature verification is passed, which effectively ensures the security of the set-top box upgrade process. In the first-level signature encryption, only important partition files are signed, which reduces the time spent on packaging and saves computing resources. The set-top box upgrade method provided in this embodiment improves the security of the set-top box upgrade process.

[0088] Example 2

[0089] In actual application, after receiving the third signature upgrade package, the set-top box needs to first verify the signature of the third signature upgrade package, and obtain the target upgrade file for upgrade after the verification is passed. Therefore, this application also provides a set-top box upgrade method applied to the set-top box.

[0090] See Figure 4 , is a flow chart of a set-top box upgrade method provided in an embodiment of the present application. The upgrade method is applied to a set-top box, and the method includes:

[0091] receiving a third-signed upgrade package, and performing third-signature verification on the third-signed upgrade package;

[0092] If the third signature verification passes, obtain the second signature upgrade package based on the third signature upgrade package to perform the second signature verification;

[0093] If the second signature verification passes, obtain the first signature upgrade package based on the second signature upgrade package to perform the first signature verification;

[0094] If the first signature verification passes, a signature partition file is obtained, where the signature partition file includes first signature calculation information, where the first signature calculation information is signature information obtained by performing the first signature calculation on the target partition file;

[0095] A target upgrade file is obtained according to the signature partition file, and the upgrade is performed according to the target upgrade file, wherein the target upgrade file includes the target partition file.

[0096] Because the third signed upgrade package received by the set-top box is an upgrade package obtained by performing three-level encryption on the native upgrade package during the corresponding upgrade package packaging process, when the set-top box receives the third signed upgrade package for upgrading, it is necessary to first perform the corresponding three-level step-by-step verification on the third signed upgrade package. After obtaining the target upgrade file, the upgrade is performed according to the target upgrade file. Specifically, the set-top box upgrade system host obtains the target partition file in the native upgrade package of the set-top box, performs a first signature operation on the target partition file to obtain a signed partition file, replaces the target partition file in the native upgrade package with the signed partition file to obtain a first signed upgrade package, performs a second signature operation on the first signed upgrade package to obtain a second signed upgrade package, and performs a third signature operation on the second signed upgrade package to obtain an upgrade package. The specific upgrade package signature packaging process can be referred to the steps described in Example 1 and will not be repeated here.

[0097] In some embodiments, the step of performing a third signature verification on the third signature upgrade package includes: determining whether the third signature upgrade package contains a central directory end identifier; if the third signature upgrade package contains the central directory end identifier, obtaining the central directory record tail area of ​​the third signature upgrade package; and performing a third signature verification on the central directory record tail area.

[0098] Specifically, verification can be performed in the Recovery system. First, the third-signed upgrade package must contain the end-of-central-directory marker, which indicates the package is complete. If the end-of-central-directory marker is present, the third-signed upgrade package can be preliminarily determined to be complete, allowing for further verification.

[0099] Because the third signature calculation is performed on the tail area of ​​the central directory record during the packaging process, the third signature verification only needs to be performed on the tail area of ​​the central directory record during verification. Usually, the encrypted upgrade package is large in size, and verification takes a long time. For example, if the size of the encrypted upgrade package is greater than 300M, the subsequent signature verification will take more than 10 seconds, which is about 40% longer than the upgrade method using the native upgrade package. In this embodiment, even if the length of the tail area of ​​the central directory record takes the maximum value of 22+65535, the maximum data volume is about 64K, and the verification time is about 0.3 seconds, which is negligible for the entire upgrade process, greatly improving the verification efficiency.

[0100] In some embodiments, obtaining a second signature upgrade package based on the third signature upgrade package and performing a second signature verification includes: obtaining second signature operation information of the tail area of ​​the central directory record; and performing a second signature verification on the second signature upgrade package based on the second signature operation information.

[0101] Specifically, when the third signature verification is passed, the second upgrade package can be obtained based on the third signature upgrade package, and the second signature operation information of the tail area of ​​the central directory record is obtained, and the second signature verification is performed on the second signature upgrade package based on the second signature operation information.

[0102] In some embodiments, the step of performing a first signature verification on the first signature upgrade package includes: performing a first signature operation verification on all signature partition files in the first signature upgrade package; if all the signature partition files pass the verification, it is determined that the first signature verification passes.

[0103] Specifically, at this time, it is necessary to traverse all the signature partition files in the first signature upgrade package and perform the first signature operation verification on each signature partition file; if all the signature partition files pass the verification, it is determined that the verification of the first signature upgrade package passes.

[0104] If any verification step fails during the verification process, the upgrade will fail. For example, if the third signature upgrade package does not contain the end-of-central-directory marker, or if the first signature calculation verification of the central-directory record tail area fails, or if the second signature calculation verification of the second signature upgrade package fails, or if the first signature calculation verification of any signed partition file in the first signature upgrade package fails, the upgrade will fail.

[0105] If all verifications are passed, the set-top box can enter the upgrade state. In some embodiments, an upgrade script stored in the third signature upgrade package can be searched and executed to enable the set-top box to perform the upgrade operation.

[0106] The set-top box upgrade method provided by this embodiment uses a three-level signature method to sign and package the original upgrade package, which is then verified by the set-top box. The set-top box upgrade is performed only after the three-level signature verification is passed, which effectively ensures the security of the set-top box upgrade process. In the first-level signature encryption, only important partition files are signed, which reduces the time spent on packaging and saves computing resources. The set-top box upgrade method provided by this embodiment improves the security of the set-top box upgrade process.

[0107] Example 3

[0108] In addition, an embodiment of the present disclosure provides a set-top box upgrade device, which is applied to a set-top box upgrade system host.

[0109] Specifically, such as Figure 5 As shown, the set-top box upgrading device 500 includes:

[0110] An acquisition module 510 is configured to acquire a target partition file in a native upgrade package of a set-top box;

[0111] A first operation module 520 is configured to perform a first signature operation on the target partition file to obtain a signature partition file, wherein the signature partition file includes first signature operation information;

[0112] A replacement module 530 is configured to replace the target partition file in the native upgrade package with the signature partition file to obtain a first signed upgrade package;

[0113] A second operation module 540 is configured to perform a second signature operation on the first signed upgrade package to obtain a second signed upgrade package;

[0114] The third operation module 550 is configured to perform a third signature operation on the second signature upgrade package to obtain a third signature upgrade package, where the third signature upgrade package is used to upgrade the set-top box.

[0115] The set-top box upgrading apparatus 500 provided in this embodiment can implement the set-top box upgrading method provided in Example 1, and will not be described again here to avoid repetition.

[0116] The set-top box upgrade device provided by this embodiment uses a three-level signature method to sign and package the original upgrade package, which is then verified by the set-top box. The set-top box upgrade is only carried out after the three-level signature verification is passed, which effectively ensures the security of the set-top box upgrade process. In the first-level signature encryption, only important partition files are signed, which reduces the time spent on packaging and saves computing resources. The set-top box upgrade device provided by this embodiment improves the security of the set-top box upgrade process.

[0117] Example 4

[0118] In addition, an embodiment of the present disclosure provides a set-top box, including a memory and a processor, wherein the memory stores a computer program, and when the computer program runs on the processor, the set-top box upgrade method provided in embodiment 1 is executed.

[0119] The set-top box provided in the embodiment of the present invention can implement the set-top box upgrade method provided in Example 2, which will not be described again here to avoid repetition.

[0120] The set-top box provided in this embodiment uses a three-level signature method to sign and package the original upgrade package, which is then verified by the set-top box. The set-top box upgrade is only carried out after the three-level signature verification is passed, which effectively ensures the security of the set-top box upgrade process. In the first-level signature encryption, only important partition files are signed, which reduces the packaging time and saves computing resources. The set-top box provided in this embodiment improves the security of the set-top box upgrade process.

[0121] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or terminal comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or terminal comprising the element.

[0122] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0123] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A set-top box upgrade method, applied to a set-top box upgrade system host, characterized in that: The method comprises: Get the target partition file in the native upgrade package of the set-top box; Performing a first signature operation on the target partition file to obtain a signature partition file, wherein the signature partition file includes first signature operation information; Replacing the target partition file in the native upgrade package with the signature partition file to obtain a first signature upgrade package; Performing a second signature operation on the first signature upgrade package to obtain second signature operation information, and storing the second signature operation information in the tail area of ​​the central directory record of the first signature upgrade package to obtain a second signature upgrade package; Performing a third signature operation on the second-signed upgrade package to obtain a third-signed upgrade package; The set-top box is upgraded based on the third signature upgrade package; The performing of the third signature operation on the second signature upgrade package to obtain the third signature upgrade package includes: adding a second signature operation data header area to the second signature upgrade package; obtaining a central directory record tail area of ​​the second signature upgrade package; performing the third signature operation on the central directory record tail area to obtain third signature operation information; and storing the third signature operation information in the second signature operation data header area to obtain the third signature upgrade package.

2. The set-top box upgrading method according to claim 1, characterized in that: The performing a first signature operation on the target partition file to obtain a signed partition file includes: Performing a first signature operation on the target partition file to obtain the first signature operation information; Adding a first signature calculation data header area to the target partition file; The first signature operation information is stored in the first signature operation data header area to obtain a signature partition file.

3. The set-top box upgrading method according to claim 1, characterized in that: The step of obtaining the tail area of ​​the central directory record of the second signature upgrade package includes: Obtain a central directory end identifier, and search for the central directory record tail area according to the central directory end identifier.

4. A set-top box upgrade method, applied to a set-top box, characterized in that: The method comprises: receiving a third-signed upgrade package, and performing third-signature verification on the third-signed upgrade package; If the third signature verification passes, obtain the second signature upgrade package based on the third signature upgrade package to perform the second signature verification; If the second signature verification passes, obtain the first signature upgrade package based on the second signature upgrade package to perform the first signature verification; If the first signature verification passes, a signature partition file is obtained, where the signature partition file includes first signature calculation information, where the first signature calculation information is signature information obtained by performing the first signature calculation on the target partition file; Obtain a target upgrade file according to the signature partition file, and perform an upgrade according to the target upgrade file, wherein the target upgrade file includes the target partition file; Among them, the third signature upgrade package is an upgrade package obtained by storing the third signature operation information in the second signature operation data header area added to the second signature upgrade package, and the third signature operation information is obtained by performing a third signature operation on the tail area of ​​the central directory record of the second signature upgrade package; the second signature upgrade package is an upgrade package obtained by performing a second signature operation on the first signature upgrade package to obtain the second signature operation information, and storing the second signature operation information in the tail area of ​​the central directory record of the first signature upgrade package.

5. The set-top box upgrading method according to claim 4, characterized in that: The performing third signature verification on the third signature upgrade package includes: Determining whether the third signed upgrade package contains a central directory end identifier; If the third signature upgrade package includes the central directory end identifier, obtaining the central directory record tail area of ​​the third signature upgrade package; A third signature verification is performed on the central directory record trailer area.

6. The set-top box upgrading method according to claim 4, characterized in that: Obtaining a second signed upgrade package according to the third signed upgrade package and performing second signature verification includes: Obtaining second signature calculation information of the tail area of ​​the central directory record; Perform a second signature verification on the second signature upgrade package according to the second signature operation information.

7. The set-top box upgrading method according to claim 4, characterized in that: The performing a first signature verification on the first signed upgrade package includes: Performing a first signature operation verification on all signature partition files in the first signature upgrade package; If all the signature partition files pass verification, it is determined that the first signature verification passes.

8. A set-top box upgrade device, applied to a set-top box upgrade system host, characterized in that: The device comprises: An acquisition module is used to obtain the target partition file in the native upgrade package of the set-top box; A first operation module is configured to perform a first signature operation on the target partition file to obtain a signature partition file, wherein the signature partition file includes first signature operation information; a replacement module, configured to replace the target partition file in the native upgrade package with the signature partition file to obtain a first signature upgrade package; a second operation module, configured to perform a second signature operation on the first signature upgrade package to obtain second signature operation information, and store the second signature operation information in a tail area of ​​a central directory record of the first signature upgrade package to obtain a second signature upgrade package; a third operation module, configured to perform a third signature operation on the second signature upgrade package to obtain a third signature upgrade package, where the third signature upgrade package is used to upgrade the set-top box; The third operation module performs a third signature operation on the second signature upgrade package. The process of obtaining the third signature upgrade package includes: adding a second signature operation data header area to the second signature upgrade package; obtaining a central directory record tail area of ​​the second signature upgrade package; performing a third signature operation on the central directory record tail area to obtain third signature operation information; and storing the third signature operation information in the second signature operation data header area to obtain the third signature upgrade package.

9. A set-top box, characterized in that: The device comprises a memory and a processor, wherein the memory stores a computer program, and when the computer program is run by the processor, the set-top box upgrading method according to any one of claims 4 to 7 is executed.

Citation Information

Patent Citations

  • IPTV upgrade package structure, upgrading method and startup calibration method

    CN102572595A

  • Data processing method, set top box upgrade method, terminal and set top box

    CN108055585A

  • Signature and signature verification method of upgrade package, and storage medium

    CN111274552A