A Software Upgrade Package Signing Method and Device
By dividing the software upgrade package into small pieces of data and encrypting and signing on the server, the problems of incomplete structure and high communication pressure during the verification process of the software upgrade package are solved, and a safer and more efficient data transmission is achieved.
Patent Information
- Application Number
- CN202211485193.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-24
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-11-24
AI Technical Summary
When verifying the software upgrade package in the prior art, the software upgrade package is prone to problems such as incomplete structure and high communication pressure for transmission.
By dividing the software upgrade package to be signed into the first divided data and the second divided data, and sending these divided data to the server for encryption and signature, the communication pressure of data transmission and the computing pressure of the server are reduced.
It reduces the possibility of data incompleteness during transmission due to too large data, and improves security during data transmission.
Smart Images

Figure CN115843022B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology. Specifically, it relates to a software upgrade package signature method and device. Background Art
[0002] With the development of the Internet of Things, the interconnection of all things is the future development trend. As a means of transportation for our daily travel, the intelligent and networked development of automobiles is even more rapid. Among them, with the development of automobile intelligence and networking, in-vehicle software emerges in an endless stream.
[0003] In the prior art, generally, the Over-the-air Technology (OTA) is used to download and upgrade the software upgrade package of in-vehicle software. In addition, generally, the method of signature verification of the software upgrade package is used to improve the security of the software upgrade package download and upgrade. However, in the process of verifying the software upgrade package by the above method, problems such as the incomplete structure of the software upgrade package and the relatively large communication pressure during transmission are likely to occur. Summary of the Invention
[0004] The purpose of the embodiments of this application is to provide a software upgrade package signature method and device, so as to solve the technical problems in the prior art that in the process of verifying the software upgrade package, the structure of the software upgrade package is likely to be incomplete and the communication pressure during transmission is relatively large.
[0005] In a first aspect, the embodiments of this application provide a software upgrade package signature method, which is applied to a client and includes: splitting the software upgrade package to be signed into first split data and second split data; sending the first split data and / or the second split data to a server so that the server encrypts the first split data and / or the second split data to obtain corresponding encrypted data; receiving the encrypted data, and signing the software upgrade package to be signed according to the encrypted data, the first split data, and the second split data.
[0006] In the above solution, the client splits the software upgrade package to be signed, so as to obtain the first split data and the second split data with smaller sizes. In this way, in the process of sending the first split data and / or the second split data to the server, the possibility of incomplete data during transmission caused by too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0007] In an alternative embodiment, sending the first split data and / or the second split data to the server to enable the server to encrypt the first split data and / or the second split data to obtain corresponding encrypted data includes: sending the first split data to the server to enable the server to encrypt the first split data to obtain corresponding encrypted data; signing the software upgrade package to be signed according to the encrypted data, the first split data, and the second split data includes: combining the encrypted data with the second split data to obtain combined data; signing the software upgrade package to be signed according to the combined data. In the above solution, only the first split data can be sent to the server for encryption; since the size of the first split data is smaller than the size of the software upgrade package to be signed, the possibility of data incompleteness during transmission caused by too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0008] In an alternative embodiment, sending the first split data and / or the second split data to the server to enable the server to encrypt the first split data and / or the second split data to obtain corresponding encrypted data includes: sending the first split data to the server to enable the server to encrypt the first split data, and sending the second split data to the server to enable the server to encrypt the second split data to obtain corresponding encrypted data; wherein the encrypted data includes first encrypted data corresponding to the first split data and second encrypted data corresponding to the second split data; signing the software upgrade package to be signed according to the encrypted data, the first split data, and the second split data includes: combining the first encrypted data with the second encrypted data to obtain combined data; signing the software upgrade package to be signed according to the combined data. In the above solution, the first split data and the second split data can be sent to the server for encryption respectively; since the sizes of the first split data and the second split data are both smaller than the size of the software upgrade package to be signed, the possibility of data incompleteness during transmission caused by too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0009] In an alternative embodiment, signing the software upgrade package to be signed according to the combined data includes: calculating a hash value of the combined data; sending the hash value to the server so that the server generates signature data according to the hash value; receiving the signature data, and storing a signature file corresponding to the signature data. In the above solution, the software upgrade package to be signed can be signed by calculating the hash value of the combined data. Since the hash value corresponding to the combined data is unique, the accuracy of the signature can be guaranteed.
[0010] In an alternative embodiment, before splitting the software upgrade package to be signed into first split data and second split data, the method further includes: obtaining the software upgrade package to be signed; determining whether the size of the software upgrade package to be signed is greater than a preset size; if the size of the software upgrade package to be signed is greater than the preset size, then perform the step of splitting the software upgrade package to be signed into first split data and second split data. In the above solution, when the software upgrade package to be signed is relatively large, in order to reduce the possibility of incomplete data during transmission due to the large amount of data, and at the same time reduce the communication pressure of data transmission and the computing pressure on the server, the software upgrade package to be signed can be split.
[0011] In an alternative embodiment, the size of the first split data is less than or equal to the preset size. In the above solution, the software upgrade package to be signed can be split into first split data and second split data whose sizes are less than or equal to the preset size. In this way, during the transmission of the first split data, the possibility of incomplete data during transmission due to the large amount of data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure on the server can be reduced.
[0012] In a second aspect, an embodiment of the present application provides a software upgrade package signature device, which is applied to a client and includes: a splitting module, configured to split a software upgrade package to be signed into first split data and second split data; a sending module, configured to send the first split data and / or the second split data to a server so that the server encrypts the first split data and / or the second split data to obtain corresponding encrypted data; a signature module, configured to receive the encrypted data, and sign the software upgrade package to be signed according to the encrypted data, the first split data, and the second split data.
[0013] In the above solution, the client divides the software upgrade package to be signed, so as to obtain the first divided data and the second divided data with smaller sizes. In this way, during the process of sending the first divided data and / or the second divided data to the server, the possibility of incomplete data during transmission caused by too large data can be reduced, and at the same time, the communication pressure during data transmission and the computing pressure on the server can be reduced. In addition, since only a part of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0014] In an alternative embodiment, the sending module is specifically configured to: send the first divided data to the server, so that the server encrypts the first divided data to obtain corresponding encrypted data; the signing module is specifically configured to: combine the encrypted data with the second divided data to obtain combined data; and sign the software upgrade package to be signed according to the combined data. In the above solution, only the first divided data can be sent to the server for encryption. Since the size of the first divided data is smaller than the size of the software upgrade package to be signed, the possibility of incomplete data during transmission caused by too large data can be reduced, and at the same time, the communication pressure during data transmission and the computing pressure on the server can be reduced. In addition, since only a part of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0015] In an alternative embodiment, the sending module is specifically configured to: send the first divided data to the server, so that the server encrypts the first divided data, and send the second divided data to the server, so that the server encrypts the second divided data to obtain corresponding encrypted data; wherein, the encrypted data includes the first encrypted data corresponding to the first divided data and the second encrypted data corresponding to the second divided data; the signing module is specifically configured to: combine the first encrypted data with the second encrypted data to obtain combined data; and sign the software upgrade package to be signed according to the combined data. In the above solution, the first divided data and the second divided data can be sent to the server for encryption respectively. Since the sizes of the first divided data and the second divided data are both smaller than the size of the software upgrade package to be signed, the possibility of incomplete data during transmission caused by too large data can be reduced, and at the same time, the communication pressure during data transmission and the computing pressure on the server can be reduced. In addition, since only a part of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0016] In an alternative embodiment, the signature module is further configured to: calculate a hash value of the combined data; send the hash value to the server so that the server generates signature data based on the hash value; receive the signature data, and store a signature file corresponding to the signature data. In the above solution, the software upgrade package to be signed can be signed by calculating the hash value of the combined data. Since the hash value corresponding to the combined data is unique, the accuracy of the signature can be guaranteed.
[0017] In an alternative embodiment, the software upgrade package signature device further includes: an acquisition module, configured to acquire the software upgrade package to be signed; a judgment module, configured to judge whether the size of the software upgrade package to be signed is greater than a preset size; if the size of the software upgrade package to be signed is greater than the preset size, the splitting module executes the step of splitting the software upgrade package to be signed into first split data and second split data. In the above solution, when the software upgrade package to be signed is relatively large, in order to reduce the possibility of incomplete data during transmission due to the large data size, and at the same time reduce the communication pressure of data transmission and the computing pressure of the server, the software upgrade package to be signed can be split.
[0018] In an alternative embodiment, the size of the first split data is less than or equal to the preset size. In the above solution, the software upgrade package to be signed can be split into first split data and second split data with sizes less than or equal to the preset size. In this way, during the transmission of the first split data, the possibility of incomplete data during transmission due to the large data size can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced.
[0019] In a third aspect, an embodiment of the present application provides a computer program product, including computer program instructions, which when read and run by a processor, execute the software upgrade package signature method as described in the first aspect.
[0020] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a processor, a memory, and a bus; the processor and the memory communicate with each other through the bus; the memory stores computer program instructions executable by the processor, and the processor can execute the software upgrade package signature method as described in the first aspect by invoking the computer program instructions.
[0021] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores computer program instructions, and when the computer program instructions are run by a computer, the computer is enabled to execute the software upgrade package signature method as described in the first aspect.
[0022] To make the above objects, features, and advantages of the present application more obvious and understandable, specific embodiments of the present application are hereinafter given, and in conjunction with the accompanying drawings, the following detailed description is provided. Description of the Drawings
[0023] To more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as a limitation of the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0024] Figure 1 A flowchart of a software upgrade package signature method provided for an embodiment of the present application;
[0025] Figure 2 An interaction diagram of a software upgrade package signature method provided for an embodiment of the present application;
[0026] Figure 3 A structural block diagram of a software upgrade package signature device provided for an embodiment of the present application;
[0027] Figure 4 A structural block diagram of an electronic device provided for an embodiment of the present application. Detailed Embodiments
[0028] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0029] The embodiments of the present application provide a software upgrade package signature system, wherein the software upgrade package signature system includes a client and a server.
[0030] Specifically, a user can register and activate a corresponding account in advance on the server; in this way, the user logs in to the client using the above account and establishes a secure connection with the server. Among them, as an implementation method, the user can log in to the client only in a feasible environment, thereby improving the security of data transmission.
[0031] In addition, the user can select to sign a certain software upgrade package on the client, and the server can perform corresponding signature operations on the software upgrade package.
[0032] It should be noted that, based on the above embodiments, the software upgrade package signature system provided by the embodiments of the present application may further include a signature verification tool for verifying the signed software upgrade package, so as to install and upgrade the software upgrade package that passes the verification.
[0033] Based on the above software upgrade package signature system, an embodiment of the present application further provides a software upgrade package signature method. Next, a software upgrade package signature method applied to the client will be introduced in detail.
[0034] Please refer to Figure 1 , Figure 1 which is a flowchart of a software upgrade package signature method provided by an embodiment of the present application. This software upgrade package signature method can be applied to, and specifically may include the following steps:
[0035] Step S101: Split the software upgrade package to be signed into first split data and second split data.
[0036] Step S102: Send the first split data and / or the second split data to the server so that the server encrypts the first split data and / or the second split data to obtain corresponding encrypted data.
[0037] Step S103: Receive the encrypted data, and sign the software upgrade package to be signed according to the encrypted data, the first split data, and the second split data.
[0038] Specifically, in the above step S101, the software upgrade package to be signed is a software upgrade package selected by the user through the client that needs to be signed. It should be noted that the specific implementation manner of obtaining the software upgrade package to be signed in the embodiment of the present application is not specifically limited, and those skilled in the art can make appropriate adjustments according to the actual situation. For example, the client can read the software upgrade package to be signed stored in the cloud or locally; or, the client can receive the software upgrade package to be signed sent by other devices.
[0039] The client can split the software upgrade package to be signed, thereby splitting the software upgrade package to be signed into two parts. Among them, for the convenience of description, the two parts obtained by the above splitting can be named first split data and second split data respectively.
[0040] It should be noted that the specific implementation manner of splitting the software upgrade package to be signed in the embodiment of the present application is not specifically limited, and those skilled in the art can make appropriate adjustments according to the actual situation. For example, the software upgrade package to be signed can be split into two parts of the same size; or, according to a preset size set in advance, the software upgrade package to be signed can be split into first split data and second split data whose sizes are equal to the preset size, etc.
[0041] In the above step S102, there are the following three implementation manners:
[0042] The first implementation manner: The client only sends the first split data to the server, and the server encrypts the first split data to obtain encrypted data corresponding to the first split data.
[0043] In the second implementation, the client only sends the second split data to the server, and the server encrypts the second split data to obtain the encrypted data corresponding to the second split data.
[0044] In the third implementation, the client sends the first split data and the second split data to the server respectively, and the server encrypts the first split data and the second split data respectively to obtain the first encrypted data corresponding to the first split data and the second encrypted data corresponding to the second split data; wherein, the encrypted data includes the above-mentioned first encrypted data and second encrypted data.
[0045] The client can send the first split data and / or the second split data to the server; after receiving the above data sent by the client, the server can calculate the data encryption key according to the data encryption rule and the user's personal certificate, and use the data encryption key to encrypt the first split data and / or the second split data to obtain the corresponding encrypted data; the server returns the above encrypted data to the client.
[0046] As an implementation, the normal communication method can be adopted between the client and the server; as another implementation, the encrypted transmission method can be adopted between the client and the server.
[0047] For the above-mentioned encrypted transmission implementation, the communication between the server and the client can be encrypted; the client and the server can pre-agree on a special communication encryption rule, calculate the communication secret key based on the above communication encryption rule, and then encrypt the communication data according to the communication secret key; for example, the above encryption method can adopt the Advanced Encryption Standard (AES) encryption method.
[0048] In this implementation, the client can encrypt the first split data and / or the second split data with the communication key and send it to the server; when the server receives the above encrypted data sent by the client, it can decrypt it with the communication key to obtain the corresponding first split data and / or second split data; the server then calculates the data encryption key according to the data encryption rule and the user's personal certificate, and uses the data encryption key to encrypt the first split data and / or the second split data to obtain the corresponding encrypted data; the server sends the above encrypted data to the client.
[0049] In the above step S103, after receiving the encrypted data returned by the server, the client can sign the software upgrade package to be signed according to the above encrypted data, the first split data, and the second split data. Among them, the dimer implementation manner of signing the software upgrade package to be signed will be introduced in detail in the subsequent embodiments and will not be described here for the time being.
[0050] In the above solution, the client splits the software upgrade package to be signed, thereby obtaining the first split data and the second split data with smaller sizes. In this way, during the process of sending the above first split data and / or second split data to the server, the possibility of incomplete data during transmission caused by too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0051] Further, on the basis of the above embodiments, in the above step S102, only the first split data can be sent to the server. At this time, the software upgrade package signing method provided by the embodiments of the present application may include the following steps:
[0052] Step 1), split the software upgrade package to be signed into the first split data and the second split data.
[0053] Step 2), send the first split data to the server so that the server encrypts the first split data to obtain the corresponding encrypted data.
[0054] Step 3), receive the encrypted data, and combine the encrypted data with the second split data to obtain combined data.
[0055] Step 4), sign the software upgrade package to be signed according to the combined data.
[0056] Specifically, in the above step 3), after receiving the encrypted data corresponding to the first split data, the client can combine the encrypted data with the second split data to obtain a new data packet, named combined data; using this combined data, the software upgrade package to be signed can be signed.
[0057] In the above solution, only the first split data can be sent to the server for encryption; since the size of the first split data is smaller than the size of the software upgrade package to be signed, the possibility of incomplete data during transmission caused by too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0058] Further, based on the above embodiments, in the above step S102, only the second split data may be sent to the server. At this time, the software upgrade package signature method provided by the embodiments of the present application may include the following steps:
[0059] Step 1), split the software upgrade package to be signed into first split data and second split data.
[0060] Step 2), send the second split data to the server so that the server encrypts the second split data to obtain the corresponding encrypted data.
[0061] Step 3), receive the encrypted data, and combine the encrypted data with the first split data to obtain combined data.
[0062] Step 4), sign the software upgrade package to be signed according to the combined data.
[0063] Specifically, in the above step 3), after the client receives the encrypted data corresponding to the second split data, the encrypted data may be combined with the first split data to obtain a new data packet, named combined data; using the combined data, the software upgrade package to be signed can be signed.
[0064] In the above solution, only the second split data may be sent to the server for encryption; since the size of the second split data is smaller than the size of the software upgrade package to be signed, the possibility of incomplete data during transmission due to too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0065] Further, based on the above embodiments, in the above step S102, the first split data and the second split data may be sent to the server respectively. At this time, the software upgrade package signature method provided by the embodiments of the present application may include the following steps:
[0066] Step 1), split the software upgrade package to be signed into first split data and second split data.
[0067] Step 2), send the first split data to the server so that the server encrypts the first split data, and send the second split data to the server so that the server encrypts the second split data to obtain the corresponding encrypted data; wherein, the encrypted data includes first encrypted data corresponding to the first split data and second encrypted data corresponding to the second split data.
[0068] Step 3), receive the encrypted data, and combine the first encrypted data and the second encrypted data to obtain combined data.
[0069] Step 4), sign the software upgrade package to be signed according to the combined data.
[0070] Specifically, in the above step 3), after the client receives the first encrypted data corresponding to the first split data and the second encrypted data corresponding to the second split data, the first encrypted data and the second encrypted data can be combined to obtain a new data packet, named combined data; using the combined data, the software upgrade package to be signed can be signed.
[0071] In the above solution, the first split data and the second split data can be separately sent to the server for encryption; since the sizes of the first split data and the second split data are both smaller than the size of the software upgrade package to be signed, the possibility of incomplete data during transmission due to too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0072] Further, on the basis of the above embodiments, the specific implementation manner of signing the software upgrade package to be signed according to the combined data is introduced below. The steps of signing the software upgrade package to be signed according to the combined data can specifically include the following steps:
[0073] Step 1), calculate the hash value of the combined data.
[0074] Step 2), send the hash value to the server so that the server generates signature data according to the hash value.
[0075] Step 3), receive the signature data and store the signature file corresponding to the signature data.
[0076] Specifically, in the above step 1), the client can calculate the hash value of the combined data by using a hash algorithm. Among them, since this step is executed on the client, the computing pressure on the server can be reduced.
[0077] In the above step 2), the client sends the calculated hash value to the server; after receiving the hash value, the server can generate corresponding signature data according to the hash value; the server can send the signature data to the client.
[0078] In the above step 3), after receiving the signature data, the client can write the signature data into a file to generate a signature file and store the signature file.
[0079] In the above solution, the software upgrade package to be signed can be signed by calculating the hash value of the combined data. Since the hash value corresponding to the combined data is unique, the accuracy of the signature can be guaranteed.
[0080] Further, on the basis of the above embodiment, before the above step S101, the software upgrade package signing method provided by the embodiments of the present application may further include the following steps:
[0081] Step 1), obtain the software upgrade package to be signed.
[0082] Step 2), determine whether the size of the software upgrade package to be signed is greater than a preset size.
[0083] Step 3), if the size of the software upgrade package to be signed is greater than the preset size, then execute the step of splitting the software upgrade package to be signed into first split data and second split data.
[0084] Specifically, the preset size can be the data packet size value set by the user in advance. When the size of the software upgrade package to be signed is greater than the above preset size, it can be considered that the size of the software upgrade package to be signed is relatively large. In order to ensure data integrity and reduce communication pressure, the software upgrade package to be signed can be split.
[0085] In the above solution, when the software upgrade package to be signed is relatively large, in order to reduce the possibility of data incompleteness during the transmission due to too large data, and at the same time reduce the communication pressure of data transmission and the computing pressure of the server, the software upgrade package to be signed can be split.
[0086] Further, on the basis of the above embodiment, the size of the first split data is less than or equal to the preset size.
[0087] In the above solution, the software upgrade package to be signed can be split into first split data and second split data with sizes less than or equal to the preset size. In this way, during the transmission of the first split data, the possibility of data incompleteness during the transmission due to too large data can be reduced, and at the same time the communication pressure of data transmission and the computing pressure of the server can be reduced.
[0088] Further, on the basis of the above embodiment, after the above step S103, the software upgrade package signing method provided by the embodiments of the present application may further include the following steps:
[0089] Step 1), the verification tool verifies the combined data according to the signature file.
[0090] Step 2), if the verification passes, then use the software upgrade package to be signed for software upgrade and installation; if the verification fails, then do not perform upgrade and installation.
[0091] Specifically, the signature verification tool can verify the combined data according to the pre-determined decryption rule and signature verification rule; if the verification passes and the encrypted data can be restored, and if successful, it means the verification passes, and then the upgrade can be performed.
[0092] It can be understood that the embodiments of the present application comprehensively implement security measures such as digital signature, shared secret key, dynamic encryption and decryption to achieve the security, integrity, authenticity and confidentiality of software upgrade package download and upgrade; each time a user logs in to the client, a new communication secret key will be generated as the secret key for communication encryption to ensure the uniqueness and security of each session. Each user corresponds to a unique signature certificate, and different users will generate different encrypted data when signing the same software upgrade package, realizing the confidentiality and independence of task data.
[0093] Please refer to Figure 2 , Figure 2 FIG. is an interaction diagram of a software upgrade package signature method provided by an embodiment of the present application. The software upgrade package signature method can be applied to a software upgrade package signature system, and specifically may include the following steps:
[0094] Step S201: The client divides the software upgrade package to be signed into first divided data and second divided data.
[0095] Step S202: The client sends the first divided data to the server.
[0096] Step S203: The server encrypts the first divided data to obtain corresponding encrypted data.
[0097] Step S204: The server sends the encrypted data to the client.
[0098] Step S205: The client combines the encrypted data with the second divided data to obtain combined data.
[0099] Step S206: The client calculates the hash value of the combined data.
[0100] Step S207: The client sends the hash value to the server.
[0101] Step S208: The server generates signature data according to the hash value.
[0102] Step S209: The server sends the signature data to the client.
[0103] Step S210: The client stores the signature file corresponding to the signature data.
[0104] Please refer to Figure 3 , Figure 3The following is a structural block diagram of a software upgrade package signature device provided by an embodiment of the present application. The software upgrade package signature device 300 can be applied to a client, and specifically may include: a splitting module 301, configured to split a software upgrade package to be signed into first split data and second split data; a sending module 302, configured to send the first split data and / or the second split data to a server, so that the server encrypts the first split data and / or the second split data to obtain corresponding encrypted data; a signature module 303, configured to receive the encrypted data, and sign the software upgrade package to be signed according to the encrypted data, the first split data, and the second split data.
[0105] In the above solution, the client splits the software upgrade package to be signed, so as to obtain the first split data and the second split data with smaller sizes. In this way, during the process of sending the first split data and / or the second split data to the server, the possibility of incomplete data during transmission caused by too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during the data transmission process can also be improved.
[0106] Further, on the basis of the above embodiment, the sending module 302 is specifically configured to: send the first split data to the server, so that the server encrypts the first split data to obtain corresponding encrypted data; the signature module 303 is specifically configured to: combine the encrypted data with the second split data to obtain combined data; and sign the software upgrade package to be signed according to the combined data.
[0107] In the above solution, only the first split data can be sent to the server for encryption. Since the size of the first split data is smaller than the size of the software upgrade package to be signed, the possibility of incomplete data during transmission caused by too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the data of the software upgrade package to be signed is transmitted at the same time, the security during the data transmission process can also be improved.
[0108] Further, based on the above embodiments, the sending module 302 is specifically configured to: send the first split data to the server so that the server encrypts the first split data, and send the second split data to the server so that the server encrypts the second split data to obtain corresponding encrypted data; wherein, the encrypted data includes first encrypted data corresponding to the first split data and second encrypted data corresponding to the second split data; the signature module 303 is specifically configured to: combine the first encrypted data and the second encrypted data to obtain combined data; sign the software upgrade package to be signed according to the combined data.
[0109] In the above solution, the first split data and the second split data can be separately sent to the server for encryption; since the sizes of the first split data and the second split data are both smaller than the size of the software upgrade package to be signed, the possibility of data incompleteness during transmission caused by too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced. In addition, since only a part of the software upgrade package to be signed is transmitted at the same time, the security during data transmission can also be improved.
[0110] Further, based on the above embodiments, the signature module 303 is further configured to: calculate the hash value of the combined data; send the hash value to the server so that the server generates signature data according to the hash value; receive the signature data and store the signature file corresponding to the signature data.
[0111] In the above solution, signing the software upgrade package to be signed can be achieved by calculating the hash value of the combined data. Since the hash value corresponding to the combined data is unique, the accuracy of the signature can be guaranteed.
[0112] Further, based on the above embodiments, the software upgrade package signature device 300 further includes: an acquisition module, configured to acquire the software upgrade package to be signed; a judgment module, configured to judge whether the size of the software upgrade package to be signed is greater than a preset size; if the size of the software upgrade package to be signed is greater than the preset size, the splitting module executes the step of splitting the software upgrade package to be signed into first split data and second split data.
[0113] In the above solution, when the software upgrade package to be signed is relatively large, in order to reduce the possibility of data incompleteness during transmission caused by too large data, and at the same time reduce the communication pressure of data transmission and the computing pressure of the server, the software upgrade package to be signed can be split.
[0114] Further, on the basis of the above embodiments, the size of the first split data is less than or equal to the preset size.
[0115] In the above solution, the software upgrade package to be signed can be split into first split data and second split data with sizes less than or equal to the preset size. In this way, during the transmission of the first split data, the possibility of incomplete data during transmission due to too large data can be reduced, and at the same time, the communication pressure of data transmission and the computing pressure of the server can be reduced.
[0116] Please refer to Figure 4 , Figure 4 , which is a structural block diagram of an electronic device provided by an embodiment of the present application. The electronic device 400 includes: at least one processor 401, at least one communication interface 402, at least one memory 403, and at least one communication bus 404. Among them, the communication bus 404 is used to realize the direct connection and communication of these components. The communication interface 402 is used to communicate with other node devices for signaling or data. The memory 403 stores machine-readable instructions executable by the processor 401. When the electronic device 400 runs, the processor 401 communicates with the memory 403 through the communication bus 404. When the machine-readable instructions are called by the processor 401, the above software upgrade package signing method is executed.
[0117] For example, the processor 401 of the embodiment of the present application can read a computer program from the memory 403 through the communication bus 404 and execute the computer program to implement the following method: Step S101: Split the software upgrade package to be signed into first split data and second split data. Step S102: Send the first split data and / or the second split data to the server so that the server encrypts the first split data and / or the second split data to obtain corresponding encrypted data. Step S103: Receive the encrypted data, and sign the software upgrade package to be signed according to the encrypted data, the first split data, and the second split data.
[0118] Among them, the processor 401 includes one or more, which may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor 401 may be a general-purpose processor, including a central processing unit (CPU), a microcontroller unit (MCU), a network processor (NP), or other conventional processors; it may also be a dedicated processor, including a neural-network processing unit (NPU), a graphics processing unit (GPU), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. Moreover, when there are multiple processor 401s, a part of them may be general-purpose processors, and another part may be dedicated processors.
[0119] The memory 403 includes one or more, which may be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc.
[0120] It can be understood that Figure 4 The structure shown is only for illustration, and the electronic device 400 may also include more or fewer components than those Figure 4 shown in, or have a different configuration from that Figure 4 shown. Figure 4Each component shown in the figure may be implemented by hardware, software, or a combination thereof. In the embodiments of the present application, the electronic device 400 may be, but is not limited to, physical devices such as a desktop computer, a laptop computer, a smart phone, a smart wearable device, a vehicle-mounted device, etc., or may also be a virtual device such as a virtual machine. In addition, the electronic device 400 does not necessarily have to be a single device, but may also be a combination of multiple devices, such as a server cluster, and so on.
[0121] The embodiments of the present application also provide a computer program product, including a computer program stored on a computer-readable storage medium. The computer program includes computer program instructions. When the computer program instructions are executed by a computer, the computer can execute the steps of the software upgrade package signature method in the foregoing embodiments, for example, including: splitting the software upgrade package to be signed into first split data and second split data; sending the first split data and / or the second split data to a server so that the server encrypts the first split data and / or the second split data to obtain corresponding encrypted data; receiving the encrypted data, and signing the software upgrade package to be signed according to the encrypted data, the first split data, and the second split data.
[0122] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium stores computer program instructions. When the computer program instructions are run by a computer, the computer executes the software upgrade package signature method described in the foregoing method embodiments.
[0123] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods may be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other may be through some communication interfaces. The indirect coupling or communication connection of the devices or units may be in an electrical, mechanical, or other form.
[0124] In addition, the units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0125] Furthermore, in each embodiment of the present application, each functional module may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.
[0126] It should be noted that if a function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0127] In this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.
[0128] The above description is only for the embodiments of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A software upgrade package signature method, characterized in that, Applied to a client, including: Splitting a software upgrade package to be signed into first split data and second split data; Sending the first split data and / or the second split data to a server so that the server encrypts the first split data and / or the second split data to obtain corresponding encrypted data; Receiving the encrypted data and determining combined data; wherein, if the first split data is sent to the server, the combined data is obtained by combining the encrypted data and the second split data; if the second split data is sent to the server, the combined data is obtained by combining the encrypted data and the first split data; if the first split data and the second split data are sent to the server, the encrypted data includes first encrypted data corresponding to the first split data and second encrypted data corresponding to the second split data, and the combined data is obtained by combining the first encrypted data and the second encrypted data; Calculating a hash value of the combined data; Sending the hash value to the server so that the server generates signature data according to the hash value; Receiving the signature data and storing a signature file corresponding to the signature data.
2. The software upgrade package signature method according to claim 1, wherein Before splitting the software upgrade package to be signed into first split data and second split data, the method further includes: Obtaining the software upgrade package to be signed; Judging whether the size of the software upgrade package to be signed is greater than a preset size; If the size of the software upgrade package to be signed is greater than the preset size, performing the step of splitting the software upgrade package to be signed into first split data and second split data.
3. The software upgrade package signature method according to claim 2, characterized in that, The size of the first split data is less than or equal to the preset size.
4. A software upgrade package signature device, characterized in that, Applied to a client, including: A splitting module, configured to split a software upgrade package to be signed into first split data and second split data; A sending module, configured to send the first split data and / or the second split data to a server so that the server encrypts the first split data and / or the second split data to obtain corresponding encrypted data; A signature module, configured to: Receive the encrypted data and determine combined data; wherein, if the first split data is sent to the server, the combined data is obtained by combining the encrypted data and the second split data; if the second split data is sent to the server, the combined data is obtained by combining the encrypted data and the first split data; if the first split data and the second split data are sent to the server, the encrypted data includes first encrypted data corresponding to the first split data and second encrypted data corresponding to the second split data, and the combined data is obtained by combining the first encrypted data and the second encrypted data; Calculate a hash value of the combined data; Send the hash value to the server so that the server generates signature data according to the hash value; Receive the signature data and store a signature file corresponding to the signature data.
5. A computer program product, characterized in that, It includes computer program instructions which, when read and executed by a processor, perform the software upgrade package signature method according to any one of claims 1 - 3.
6. An electronic device, characterized in that, It includes: a processor, a memory, and a bus; the processor and the memory complete communication with each other through the bus; the memory stores computer program instructions executable by the processor, and the processor can execute the software upgrade package signature method according to any one of claims 1 - 3 by invoking the computer program instructions.
7. A computer-readable storage medium, characterized in that, The computer - readable storage medium stores computer program instructions which, when run on a computer, cause the computer to execute the software upgrade package signature method according to any one of claims 1 - 3.
Citation Information
Patent Citations
Cloud data integrity detection method and system based on block chain
CN109194466A
Vehicle upgrade package processing method and device
CN112799706A