Firmware upgrading method, electronic device, and computer readable storage medium
By verifying the encrypted firmware data digest and performing MAC verification between the terminal device and the server, the security issues in the firmware upgrade process are resolved, ensuring the integrity and security of the firmware upgrade process.
Patent Information
- Application Number
- CN202211295981.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-21
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2042-10-21
AI Technical Summary
During the firmware upgrade process, there is a risk that the firmware may be attacked or tampered with, which may compromise the security of the terminal device after the upgrade.
By employing digest verification and MAC verification of encrypted firmware data between terminal devices and servers, the integrity and security of firmware data are ensured. This includes using terminal keys to encrypt and decrypt server keys, ensuring the security of the firmware upgrade process.
It improves the security of firmware upgrades, ensuring the integrity and security of firmware data during transmission and upgrades, and preventing tampering.
Smart Images

Figure CN115686565B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of firmware upgrade, in particular to a firmware upgrade method, an electronic device and a computer readable storage medium. BACKGROUND
[0002] The firmware upgrade of the terminal device can be performed in a wired data transmission mode or a wireless data transmission mode.
[0003] The present application inventors have found in long-term research that, in the firmware upgrade process, there is a risk that the firmware is attacked or tampered with, and thus the security of the terminal device cannot be guaranteed after the upgrade. SUMMARY
[0004] The present application provides a firmware upgrade method, an electronic device and a computer readable storage medium, which can improve the security of firmware upgrade.
[0005] To solve the above technical problems, one technical solution adopted by the present application is to provide a firmware upgrade method, which comprises: a terminal device sends a firmware upgrade request to a server; receives encrypted firmware data sent by the server; the encrypted firmware data comprises encrypted firmware and a firmware description file; performs digest verification on the encrypted firmware according to the firmware description file; after the digest verification passes, performs MAC verification on the encrypted firmware according to the firmware description file; after the MAC verification passes, decrypts the encrypted firmware, and performs firmware upgrade on the terminal device by using the decrypted encrypted firmware.
[0006] The firmware description file comprises a first digest value, a second digest value and firmware basic data; the first digest value is obtained from a terminal key; the second digest value is obtained based on the firmware basic data and unencrypted firmware data; the digest verification on the encrypted firmware according to the firmware description file comprises: obtaining a server key according to the first digest value; decrypting the encrypted firmware by using the server key to obtain firmware plaintext; obtaining a third digest value by using the firmware plaintext and the firmware basic data; performing digest verification on the encrypted firmware according to the third digest value and the second digest value.
[0007] The firmware description file comprises key ciphertext, which is obtained by encrypting the server key by using the terminal key; obtaining the server key according to the first digest value comprises: determining the terminal key according to the first digest value; decrypting the key ciphertext by using the terminal key to obtain the server key.
[0008] The firmware description file comprises a first firmware MAC value; the MAC verification on the encrypted firmware according to the firmware description file comprises: obtaining a second firmware MAC value by using the terminal key and the third digest value; performing MAC verification on the encrypted firmware according to the first firmware MAC value and the second firmware MAC value.
[0009] The encrypted firmware is decrypted, and the terminal device is upgraded with the decrypted encrypted firmware, including: decrypting the encrypted firmware, storing the decrypted firmware plaintext into the non-volatile memory, and replacing the original firmware in the non-volatile memory.
[0010] To solve the above technical problems, another technical solution adopted by the present application is to provide a firmware upgrade method, which includes: receiving a firmware upgrade request sent by a first terminal device; sending encrypted firmware data to the first terminal device; the encrypted firmware data includes encrypted firmware and a firmware description file; so that the first terminal device performs digest verification on the encrypted firmware according to the firmware description file; and after the digest verification passes, performs MAC verification on the encrypted firmware according to the firmware description file; and after the MAC verification passes, decrypts the encrypted firmware, and upgrades the terminal device with the decrypted encrypted firmware.
[0011] Before receiving the firmware upgrade request sent by the terminal device, it includes: receiving firmware data and terminal keys sent by a second terminal device; obtaining encrypted firmware and a firmware description file by using the terminal keys and the firmware data.
[0012] The firmware description file includes a first digest value, a second digest value, a key ciphertext, firmware basic data, and a first firmware MAC value; obtaining the encrypted firmware and the firmware description file by using the terminal keys and the firmware data includes: obtaining the encrypted firmware and the firmware description file by using the terminal keys and the firmware data, including: obtaining the first digest value by using the terminal keys; obtaining the second digest value by using the firmware basic data and the firmware data; obtaining the key ciphertext by encrypting the server key with the terminal keys; and obtaining the first firmware MAC value by using the terminal keys and the second digest value.
[0013] To solve the above technical problems, another technical solution adopted by the present application is to provide an electronic device, which includes a processor, a memory coupled with the processor, and a communication module; wherein the memory is used to store a computer program, and the processor is used to execute the computer program to implement the method provided in any of the above technical solutions.
[0014] To solve the above technical problems, another technical solution adopted by the present application is to provide a computer readable storage medium, which stores a computer program, and the computer program, when executed by a processor, implements the method provided in any of the above technical solutions.
[0015] Differing from the prior art, the firmware upgrading method provided in the application, after the terminal device acquires the encrypted firmware data, the integrity and security of the firmware data are determined by performing digest verification and MAC verification on the encrypted firmware, and then after the MAC verification passes, the encrypted firmware is decrypted, and the terminal device is upgraded by using the decrypted encrypted firmware, so that the security of the firmware upgrading can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor. Among them:
[0017] Figure 1 is a structural schematic diagram of an embodiment of the encrypted firmware data provided by the present application;
[0018] Figure 2 is a flowchart of an embodiment of the firmware upgrading method provided by the present application;
[0019] Figure 3 is a flowchart of another embodiment of the firmware upgrading method provided by the present application;
[0020] Figure 4 is a flowchart of an embodiment of step 33 provided by the present application;
[0021] Figure 5 is a flowchart of another embodiment of the firmware upgrading method provided by the present application;
[0022] Figure 6 is a schematic diagram of an application scenario of the firmware upgrading method provided by the present application;
[0023] Figure 7 is a structural schematic diagram of an embodiment of the electronic device provided by the present application;
[0024] Figure 8 is a structural schematic diagram of an embodiment of the computer readable storage medium provided by the present application. DETAILED DESCRIPTION
[0025] With reference to the drawings, the technical solutions in the embodiments of the present application will be clearly and completely described below. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application. In addition, it should be noted that, in order to facilitate description, only the parts related to the present application are shown in the drawings, rather than all the structures. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of the present application.
[0026] Reference herein to“an embodiment” means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily mutually exclusive of one another. It is expressly understood that the embodiments described herein are merely examples from among a great variety of embodiments that can be claimed as falling within the scope of the present application.
[0027] Firmware is a program written into memory. That is, firmware refers to a device "driver" saved in a terminal device. Through the firmware, the operating system of the terminal device can implement the running action of a specific machine according to the standard device driver, such as an optical drive, a CD recorder, etc. all have internal firmware. Firmware is a software that performs the most basic and lowest level work of a system.
[0028] The user can develop different functions of the firmware, and then burn the developed firmware to the terminal device to complete the firmware upgrade of the terminal device, so that the terminal device implements the function of the new firmware.
[0029] With the development of science and technology, cloud upgrade technology is more and more widely used, and the security problem brought by the upgrade process follows. Based on this, the present application proposes any of the following embodiments to solve the security problem involved in firmware upgrade.
[0030] When the developer develops a new firmware or a new version of firmware on a terminal device with firmware development function, the firmware is sent to the server for processing. At the same time, when the firmware is sent to the server, the terminal key is also sent to the server. The server can be a FOTA (Firmware Over-The-Air, mobile terminal software upgrade over the air) platform.
[0031] The server processes the firmware after receiving the firmware and the terminal key. For example, the firmware basic data, the first digest value, the second digest value, the key ciphertext, and the first firmware MAC value are determined.
[0032] The firmware basic data can be the upload time of the firmware, the firmware size, the firmware version, and the like.
[0033] The first digest value is obtained by the terminal key. The terminal key can be calculated by a digest algorithm. For example, the MD5 algorithm can be used to calculate the terminal key. The first digest value can be used in subsequent verification.
[0034] The second digest value is obtained based on the firmware basic data and the unencrypted firmware. The firmware basic data and the unencrypted firmware can be calculated by a digest algorithm, such as the MD5 algorithm. The first digest value can be used in subsequent verification.
[0035] The key ciphertext is obtained by encrypting the server key with the terminal key. The server key is randomly generated. For example, the server randomly generates a server key according to a preset period, and then uses the server key to perform corresponding operations on the firmware data received within the preset period. The server key is encrypted with the terminal key to obtain the key ciphertext. The server key generated within the preset period is deleted at the end of the preset period, effectively preventing the server key from being maliciously obtained. For another example, the server randomly generates a server key when receiving firmware data, and then uses the server key to perform corresponding operations on the firmware data. The server key is encrypted with the terminal key to obtain the key ciphertext. Then the server key is deleted, effectively preventing the server key from being maliciously obtained. That is, the server can use different server keys to encrypt firmware data of different versions.
[0036] The first firmware MAC value is obtained by MAC operation of the terminal key and the second digest value.
[0037] Then the firmware is encrypted with the server key to obtain the encrypted firmware.
[0038] That is, the firmware data processed by the server includes the content as shown in Figure 1 .
[0039] When the terminal device needs to be upgraded, the following technical solutions can be used.
[0040] Referring to Figure 2 , Figure 2 is a flowchart of an embodiment of the firmware upgrade method provided by the present application. The method is applied to a terminal device, and includes the following steps.
[0041] Step 21: The terminal device sends a firmware upgrade request to the server.
[0042] In some embodiments, the terminal device initiates a firmware version query to the server, and then the corresponding firmware upgrade download link can be obtained. In this case, the terminal device sends the current firmware version to the server, so that the server detects whether there is a firmware higher than the firmware version, and if so, sends the terminal device a download link of the corresponding firmware. It can be understood that different versions of firmware have different storage locations in the server, and therefore there are corresponding download links.
[0043] The terminal device downloads the corresponding encrypted firmware data according to the download link.
[0044] Step 22: receiving the encrypted firmware data sent by the server; the encrypted firmware data includes encrypted firmware and a firmware description file.
[0045] The terminal device can download the encrypted firmware data from the server according to the download link.
[0046] Step 23: performing digest verification on the encrypted firmware according to the firmware description file.
[0047] In some embodiments, the firmware description file includes the relevant processing data of the server on the encrypted firmware data that is not encrypted. For example, the first digest value, the second digest value, and the firmware basic data.
[0048] The first digest value can be used to obtain the terminal key pre-stored in the terminal device. Specifically, the first digest value is unique, so the same digest algorithm can be used to calculate the corresponding terminal digest value of the terminal key pre-stored in the terminal device, and then the first digest value and the terminal digest value are compared to determine whether they are the same. If so, the terminal key can be used to decrypt the key ciphertext to obtain the corresponding server key.
[0049] Then the server key is used to decrypt the encrypted firmware to obtain the firmware plaintext, and the firmware plaintext and the firmware basic data are used to obtain the third digest value.
[0050] The second digest value and the third digest value are subjected to digest verification.
[0051] Step 24: after the digest verification passes, performing MAC verification on the encrypted firmware according to the firmware description file.
[0052] MAC algorithm (Message Authentication Codes) is a Hash function with a secret key, and the hash value of the message is controlled by the secret key known only to the communication parties. At this time, the Hash value is called the MAC value.
[0053] The firmware description file includes the first firmware MAC value. After the digest verification passes, only the security of the server in sending the encrypted firmware can be ensured, and whether the encrypted firmware in the server is modified before the server sends cannot be ensured, so the terminal device also needs to perform MAC verification on the encrypted firmware.
[0054] Since the first firmware MAC value is obtained by performing MAC operation on the terminal key and the second digest value on the server, the second firmware MAC value can be obtained by performing MAC operation on the terminal key and the third digest value on the terminal device. The first firmware MAC value and the second firmware MAC value are subjected to MAC verification to determine whether the firmware data is modified.
[0055] In the embodiment, the secret key is the terminal key.
[0056] Step 25: After the MAC verification passes, the encrypted firmware is decrypted, and the terminal device is subjected to firmware upgrade by using the decrypted encrypted firmware.
[0057] In the embodiment, after the terminal device obtains the encrypted firmware data, the integrity and security of the firmware data are determined by performing digest verification and MAC verification on the encrypted firmware. Then, after the MAC verification passes, the encrypted firmware is decrypted, and the terminal device is subjected to firmware upgrade by using the decrypted encrypted firmware, so that the security of the firmware upgrade can be improved.
[0058] Referring to Figure 3 , Figure 3 is a flowchart of another embodiment of the firmware upgrade method provided in the application. The method includes the following steps:
[0059] Step 31: The terminal device sends a firmware upgrade request to the server.
[0060] Step 32: The encrypted firmware data sent by the server is received; the encrypted firmware data includes the encrypted firmware and the firmware description file.
[0061] The firmware description file includes the first digest value, the second digest value and the firmware basic data; the first digest value is obtained by the terminal key; and the second digest value is obtained based on the firmware basic data and the unencrypted firmware data.
[0062] Step 33: The server key is obtained according to the first digest value.
[0063] The firmware description file includes the key ciphertext, and the key ciphertext is obtained by encrypting the server key by using the terminal key.
[0064] In some embodiments, referring to Figure 4 , step 33 can be the following flow:
[0065] Step 41: Determine the terminal key according to the first digest value.
[0066] The first digest value can be used to obtain the terminal key pre-stored in the terminal device. Specifically, the first digest value is unique, so the same digest algorithm can be used to calculate the corresponding terminal digest value for the terminal key pre-stored in the terminal device. Then, the first digest value and the terminal digest value are compared to determine whether they are the same. If they are the same, the terminal key can be used to perform step 42.
[0067] Step 42: Decrypt the key ciphertext using the terminal key to obtain the server key.
[0068] Therefore, the key ciphertext is encrypted on the server using the terminal key for the server key, so the terminal key can be used on the terminal device to decrypt the key ciphertext to obtain the server key.
[0069] Step 34: Decrypt the encrypted firmware using the server key to obtain the firmware plaintext.
[0070] In some embodiments, the way step 34 decrypts the encrypted firmware using the server key is implemented in the running memory, so the encrypted firmware is not completely decrypted, and only the corresponding hash data is obtained. It can be understood that these hash data can also be used as firmware plaintext.
[0071] Step 35: Obtain a third digest value using the firmware plaintext and the firmware basic data.
[0072] The same digest algorithm as used to calculate the second digest value is used to obtain the third digest value for the firmware plaintext and the firmware basic data.
[0073] Step 36: Perform digest verification on the encrypted firmware according to the third digest value and the second digest value.
[0074] The digest verification method can refer to any of the above embodiments, which will not be described here.
[0075] When the verification fails, delete the obtained encrypted firmware data and do not perform firmware upgrade.
[0076] When the verification passes, perform step 37.
[0077] Step 37: After the digest verification passes, obtain a second firmware MAC value using the terminal key and the third digest value.
[0078] Since the second digest value described above is obtained from the firmware plaintext and the firmware basic data, it cannot guarantee that the encrypted firmware data in the server has not been modified, such as modifying the firmware basic data in the server to obtain the second digest value and modifying the firmware.
[0079] Then, when the third digest value is calculated in the terminal device, the modified firmware basic data and the firmware are still used to calculate, at this time, the digest check can also be passed, but the firmware data is actually modified, that is, the safety of the firmware data cannot be completely guaranteed by the digest check, and thus the MAC check needs to be performed again.
[0080] Since the first firmware MAC value is obtained by the MAC operation of the terminal key and the second digest value in the server, the second firmware MAC value can be obtained by the terminal key and the third digest value in the terminal device.
[0081] Step 38: performing the MAC check on the encrypted firmware according to the first firmware MAC value and the second firmware MAC value.
[0082] Since the terminal key is unique, the MAC check on the encrypted firmware can be performed according to the first firmware MAC value and the second firmware MAC value, when the check is passed, it can be determined that the firmware data is safe, and step 39 is performed. When the check is not passed, the obtained encrypted firmware data is deleted, and the firmware upgrade is not performed.
[0083] Step 39: after the MAC check is passed, the encrypted firmware is decrypted, and the terminal device is upgraded by using the decrypted encrypted firmware.
[0084] The encrypted firmware is decrypted, and the decrypted firmware plaintext is stored in the non-volatile memory to replace the original firmware in the non-volatile memory.
[0085] In the embodiment, the corresponding firmware description file is obtained by processing the firmware in the server, so that after the terminal device obtains the encrypted firmware data, the integrity and safety of the firmware data are determined by performing the digest check and the MAC check on the encrypted firmware, and then the encrypted firmware is decrypted after the MAC check is passed, and the terminal device is upgraded by using the decrypted encrypted firmware, which can improve the safety of the firmware upgrade.
[0086] Referring to Figure 5 , Figure 5 is a flowchart of another embodiment of the firmware upgrade method provided in the application. The method is applied to a server, and the method comprises the following steps:
[0087] Step 51: receiving the firmware upgrade request sent by the terminal device.
[0088] In some embodiments, before step 51, the following steps can be performed: receiving the firmware data and the terminal key sent by the terminal device for developing the firmware; obtaining the encrypted firmware and the firmware description file by using the terminal key and the firmware data.
[0089] The firmware description file includes the first digest value, the second digest value, the key ciphertext, firmware basic data and the first firmware MAC value; the encrypted firmware and the firmware description file are obtained by using the terminal key and the firmware data, including: the first digest value is obtained by using the terminal key; the second digest value is obtained by using the firmware basic data and the firmware data; the key ciphertext is obtained by encrypting the server key by using the terminal key; and the first firmware MAC value is obtained by using the terminal key and the second digest value.
[0090] Step 52: sending the encrypted firmware data to the terminal device; the encrypted firmware data includes the encrypted firmware and the firmware description file.
[0091] The terminal device performs digest verification on the encrypted firmware according to the firmware description file; and after the digest verification passes, performs MAC verification on the encrypted firmware according to the firmware description file; and after the MAC verification passes, decrypts the encrypted firmware and performs firmware upgrade on the terminal device by using the decrypted encrypted firmware.
[0092] In other embodiments, the terminal device can perform firmware upgrade in the manner of any of the above embodiments.
[0093] It can be understood that the implementation processes of any of the above embodiments can be reasonably integrated to form a complete firmware upgrade manner. In this embodiment, the corresponding firmware description file is obtained by processing the firmware in the server, so that after the terminal device obtains the encrypted firmware data, the integrity and security of the firmware data are determined by performing digest verification and MAC verification on the encrypted firmware, and then after the MAC verification passes, the encrypted firmware is decrypted and firmware upgrade is performed on the terminal device by using the decrypted encrypted firmware, which can improve the security of firmware upgrade.
[0094] Referring to Figure 6 , Figure 6 is a schematic diagram of an application scenario of the firmware upgrade method provided in the present application.
[0095] The firmware development end uploads the developed new version of firmware and the corresponding terminal key to the server, and sends the terminal key to the corresponding terminal device.
[0096] The server processes the uploaded new version of firmware by using the terminal key. First, the firmware description file corresponding to the new version of firmware is calculated.
[0097] For example, the firmware basic data, the first digest value, the second digest value, the key ciphertext and the first firmware MAC value are determined.
[0098] The firmware basic data can be upload time of the firmware, firmware size, firmware version and the like.
[0099] The first digest value is obtained by the terminal key. The first digest value can be calculated by using a relevant digest algorithm on the terminal key. For example, the MD5 message digest algorithm can be used. The first digest value can be used in subsequent verification. The first digest value is subsequently used to find the corresponding preset terminal key in the terminal device.
[0100] The second digest value is obtained based on the firmware basic data and the unencrypted firmware. The second digest value can be calculated by using a relevant digest algorithm on the firmware basic data and the unencrypted firmware, such as the MD5 message digest algorithm. The second digest value can be used in subsequent verification. The second digest value contains both the firmware basic data and the unencrypted firmware, which ensures that the firmware basic data and the unencrypted firmware cannot be tampered with maliciously.
[0101] The key ciphertext is obtained by encrypting the server key using the terminal key. The server key is used to encrypt the firmware uploaded by the firmware development end.
[0102] The first firmware MAC value is obtained by performing MAC operation on the terminal key and the second digest value.
[0103] Then, when the terminal device performs firmware upgrade, it initiates a version query to the server, obtains a firmware upgrade download link, and downloads the encrypted firmware carrying authentication information processed by the server to the terminal device. Specifically, the encrypted firmware is downloaded to the corresponding region of the non-volatile memory of the terminal device.
[0104] Then, the terminal device performs firmware verification to check the integrity, authenticity, and confidentiality of the firmware.
[0105] First, the digest verification is performed. Specifically, the terminal device first finds the terminal key matching the first digest value in the memory according to the first digest value, decrypts the key ciphertext using the terminal key to obtain the server key, decrypts the encrypted firmware using the server key to obtain the firmware plaintext, and then calculates the third digest value based on the firmware plaintext and the firmware basic data. The third digest value is checked to see if it is consistent with the second digest value. If they are consistent, the integrity is proved, and further MAC verification is performed. If they are not consistent, the upgrade process is ended, and the upgrade firmware is erased. The firmware ciphertext is decrypted to obtain the firmware plaintext only for calculating the digest, and the plaintext will not be written into the memory.
[0106] Then, the digest verification and the MAC verification are performed. Specifically, the terminal device performs MAC operation based on the third digest value calculated after decryption and the terminal key to obtain the second firmware MAC value. The second firmware MAC value is compared with the first firmware MAC value. If they are consistent, the verification is passed. If they are not consistent, the upgrade process is ended, and the upgrade firmware is erased.
[0107] Because the key used in the MAC operation is derived from the terminal key, the consistency of the MAC value can prove the authenticity of the firmware.
[0108] Then, the firmware decryption is performed. Specifically, after the digest check and the MAC check are passed, the integrity, authenticity and confidentiality of the upgraded firmware can be proved, the firmware ciphertext is decrypted, the execution area of the original firmware in the memory is erased, the execution area is written with the plaintext of the upgraded firmware, and finally the upgrade flag is erased, and the device is restarted to jump to use the new firmware.
[0109] In any of the above embodiments, the terminal key and the server key described above can be symmetric keys, and the terminal device can be an embedded device in the Internet of Things. Because the hardware of the embedded device is relatively imperfect and the resources are limited, the MAC authentication based on the pure symmetric algorithm requires only the pre-setting of the terminal key, and the required computing power and memory occupation are less, and the calculation speed is faster.
[0110] Referring to Figure 7 , Figure 7 is a structural schematic diagram of an embodiment of an electronic device provided by the present application. The electronic device 70 includes a processor 71, a memory 72 coupled to the processor 71, and a communication module 73; wherein the memory 72 is used to store a computer program, and the processor 71 is used to execute the computer program to implement the following method:
[0111] The terminal device sends a firmware upgrade request to the server; receives the encrypted firmware data sent by the server; the encrypted firmware data includes encrypted firmware and a firmware description file; performs a digest check on the encrypted firmware according to the firmware description file; after the digest check is passed, performs a MAC check on the encrypted firmware according to the firmware description file; after the MAC check is passed, decrypts the encrypted firmware, and upgrades the firmware of the terminal device by using the decrypted encrypted firmware;
[0112] Or, receiving a firmware upgrade request sent by a first terminal device; sending encrypted firmware data to the first terminal device; the encrypted firmware data includes encrypted firmware and a firmware description file; so that the first terminal device performs a digest check on the encrypted firmware according to the firmware description file; and after the digest check is passed, performs a MAC check on the encrypted firmware according to the firmware description file; and after the MAC check is passed, decrypts the encrypted firmware, and upgrades the firmware of the terminal device by using the decrypted encrypted firmware.
[0113] It can be understood that the processor 71 is also used to execute the computer program to implement the method of any of the above embodiments.
[0114] Referring to Figure 8 , Figure 8is a structural schematic diagram of an embodiment of the computer readable storage medium provided in the present application. The computer readable storage medium 80 stores a computer program 81, and the computer program 81, when executed by a processor, implements the following method:
[0115] The terminal device sends a firmware upgrade request to the server; receives encrypted firmware data sent by the server; the encrypted firmware data comprises encrypted firmware and a firmware description file; performs digest verification on the encrypted firmware according to the firmware description file; after the digest verification passes, performs MAC verification on the encrypted firmware according to the firmware description file; after the MAC verification passes, decrypts the encrypted firmware, and upgrades the firmware of the terminal device by using the decrypted encrypted firmware;
[0116] Or, receives a firmware upgrade request sent by a first terminal device; sends encrypted firmware data to the first terminal device; the encrypted firmware data comprises encrypted firmware and a firmware description file; so that the first terminal device performs digest verification on the encrypted firmware according to the firmware description file; and after the digest verification passes, performs MAC verification on the encrypted firmware according to the firmware description file; and after the MAC verification passes, decrypts the encrypted firmware, and upgrades the firmware of the terminal device by using the decrypted encrypted firmware.
[0117] It can be understood that the computer program 81, when executed by the processor, is also used to implement the method of any of the above embodiments.
[0118] In several embodiments provided in the present application, it should be understood that the disclosed method and device can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed.
[0119] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment scheme.
[0120] In addition, each functional unit in each embodiment of the present application can be integrated into one processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0121] The integrated units in the above other embodiments, if implemented in the form of software function units and sold or used as independent products, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application, essentially or in other words, the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0122] The above is only the embodiment of the present application, and does not limit the patent scope of the present application. Any equivalent structural transformation according to the content of the specification and drawings, or direct or indirect application in other related technical fields, is also included in the patent protection scope of the present application.
Claims
1. A firmware upgrade method characterized by comprising: The method comprises: The terminal device sends a firmware upgrade request to the server; Receiving the encrypted firmware data sent by the server; the encrypted firmware data comprises encrypted firmware and a firmware description file; the firmware description file comprises a first digest value, a second digest value and firmware basic data; wherein the first digest value is derived from a terminal key; the second digest value is derived based on the firmware basic data and unencrypted firmware data; Deriving a server key according to the first digest value; Decrypting the encrypted firmware using the server key to obtain firmware plaintext; Obtaining a third digest value using the firmware plaintext and the firmware basic data; Performing digest verification on the encrypted firmware according to the third digest value and the second digest value; After the digest verification passes, performing MAC verification on the encrypted firmware according to the firmware description file; After the MAC verification passes, decrypting the encrypted firmware and using the decrypted encrypted firmware to perform firmware upgrade on the terminal device.
2. The method of claim 1, wherein, The firmware description file comprises key ciphertext, which is encrypted using a terminal key on a server key; deriving the server key according to the first digest value comprises: Determining the terminal key according to the first digest value; Decrypting the key ciphertext using the terminal key to obtain the server key.
3. The method of claim 1, wherein, The firmware description file comprises a first firmware MAC value; Performing MAC verification on the encrypted firmware according to the firmware description file comprises: Obtaining a second firmware MAC value using the terminal key and the third digest value; Performing MAC verification on the encrypted firmware according to the first firmware MAC value and the second firmware MAC value.
4. The method of claim 1, wherein, Decrypting the encrypted firmware and using the decrypted encrypted firmware to perform firmware upgrade on the terminal device comprises: Decrypting the encrypted firmware, storing the decrypted firmware plaintext into a non-volatile memory, and replacing the original firmware in the non-volatile memory.
5. A firmware upgrade method characterized by, The method comprises: Receiving a firmware upgrade request sent by a first terminal device; Sending encrypted firmware data to the first terminal device; the encrypted firmware data comprises encrypted firmware and a firmware description file; the firmware description file comprises a first digest value, a second digest value and firmware basic data; wherein the first digest value is derived from a terminal key; the second digest value is derived based on the firmware basic data and unencrypted firmware data; so that the first terminal device derives a server key according to the first digest value; decrypts the encrypted firmware using the server key to obtain firmware plaintext; obtains a third digest value using the firmware plaintext and the firmware basic data; performs digest verification on the encrypted firmware according to the third digest value and the second digest value; and after the digest verification passes, performs MAC verification on the encrypted firmware according to the firmware description file; and after the MAC verification passes, decrypts the encrypted firmware and uses the decrypted encrypted firmware to perform firmware upgrade on the terminal device.
6. The method of claim 5, wherein, The receiving the firmware upgrade request sent by the first terminal device comprises: receiving firmware data and a terminal key sent by a second terminal device; obtaining the encrypted firmware and the firmware description file by using the terminal key and the firmware data.
7. The method of claim 6, wherein, The firmware description file further comprises a key ciphertext and a first firmware MAC value; The obtaining the encrypted firmware and the firmware description file by using the terminal key and the firmware data comprises: obtaining the first digest value by using the terminal key; obtaining the second digest value by using the firmware basic data and the firmware data; obtaining the key ciphertext by encrypting a server key by using the terminal key; obtaining the first firmware MAC value by using the terminal key and the second digest value.
8. An electronic device, comprising: The electronic device comprises a processor, a memory and a communication module coupled with the processor; The memory is configured to store a computer program, and the processor is configured to execute the computer program to implement the method according to any one of claims 1-7.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program, when executed by a processor, implements the method according to any one of claims 1-7.
Citation Information
Patent Citations
Equipment, firmware upgrading device thereof and firmware upgrading method thereof
CN108196867A
Safe firmware updating method, device and equipment and storage medium
CN112433742A