Security chip upgrade methods, devices, cloud platforms, terminal equipment, and security chips
By working in collaboration with the cloud platform and the microcontroller unit, the upgrade package for the security chip is acquired and sent in stages, solving the problems of cumbersome operation and high cost in the security chip upgrade process, and realizing remote upgrade of the security chip and an efficient and secure upgrade process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-24
- Publication Date
- 2026-04-03
AI Technical Summary
The existing security chip upgrade process is cumbersome and costly, especially in IoT terminals, where traditional methods require chip recycling or re-production of chips.
By working in tandem with the cloud platform and the microcontroller unit, the serial number of the target security chip is obtained and the corresponding upgrade package is determined. The microcontroller unit provides a temporary storage container, and the upgrade information is sent in stages. The security and efficiency of the upgrade package are ensured through digest calculation and encryption.
This enables remote upgrades of security chips, simplifying the operation process, reducing costs, and improving the security and efficiency of upgrades.
Smart Images

Figure CN115857980B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security chip technology, and in particular to a security chip upgrade method, apparatus, cloud platform, terminal equipment, and security chip. Background Technology
[0002] To reduce the cost of IoT terminals and meet the diverse and complex application environments of IoT, security chip hardware selection prioritizes low-cost hardware with limited resources. Software development employs methods that do not support dynamic downloading and deletion of applications. Installation utilizes a surface-mount connection method. A typical model for surface-mount security chips in IoT applications is as follows: Figure 1 As shown.
[0003] In practical applications, when the demand for security chips increases or unsuitable scenarios arise, two methods are generally used to assist businesses. Method 1: Recycle the terminal, remove the security chip, replace it with a new one, and destroy the old one. Method 2: Recycle the terminal, remove the security chip, perform a security update on the new chip on the production line, and then reinstall the updated chip on the terminal. Therefore, regardless of the method used to upgrade the security chip, the upgrade process is cumbersome and costly. Summary of the Invention
[0004] The purpose of this invention is to provide a security chip upgrade method, apparatus, cloud platform, terminal device, and security chip to solve the problems of cumbersome upgrade operations and high costs in the security chip upgrade process in related technologies.
[0005] To achieve the above objectives, embodiments of the present invention provide a security chip upgrade method applied to a cloud platform, comprising:
[0006] Once the upgrade request information of the target security chip is detected, an upgrade command is sent to the microcontroller unit;
[0007] Receive the serial number of the target security chip sent by the microcontroller unit according to the upgrade instruction;
[0008] Determine the upgrade package corresponding to the serial number;
[0009] The upgrade package is sent to the microcontroller unit.
[0010] Further, determining the upgrade package corresponding to the serial number includes:
[0011] Based on the serial number, the first upgrade package corresponding to the serial number is located;
[0012] The first upgrade package is processed to obtain a first instruction set, which includes multiple upgrade messages for the target security chip.
[0013] A first digest is obtained by performing a digest calculation on the first instruction set;
[0014] Based on the first instruction set and the first digest, the upgrade package corresponding to the serial number is obtained.
[0015] Further, obtaining the upgrade package corresponding to the serial number based on the first instruction set and the first digest includes:
[0016] Multiple upgrade information items are randomly selected from the first instruction set and encrypted to generate a second instruction set;
[0017] Generate first format data based on the second instruction set and the first instruction set;
[0018] The upgrade package is obtained based on the first format data and the first digest.
[0019] Embodiments of the present invention provide a security chip upgrade method, applied to a microcontroller unit, comprising:
[0020] After receiving the upgrade command from the cloud platform, obtain the serial number of the target security chip;
[0021] Send the serial number to the cloud platform;
[0022] Obtain the upgrade package corresponding to the serial number from the cloud platform;
[0023] The upgrade package is sent to the target security chip.
[0024] Further, sending the upgrade package to the target security chip includes:
[0025] Obtain the first instruction stream from the upgrade package, wherein the first instruction stream includes multiple upgrade information entries for the target security chip classified according to a preset standard;
[0026] The first instruction stream is sent to the target security chip in multiple parts.
[0027] Furthermore, the upgrade package includes: a first instruction set, a first digest, and first format data. The first instruction set includes multiple upgrade information entries for the target security chip. The first digest is obtained by performing a digest calculation on the first instruction set. The first format data is obtained based on the first instruction set and a second instruction set. The second instruction set is obtained by performing encryption calculation on multiple upgrade information entries randomly selected from the first instruction set.
[0028] The step of obtaining the first instruction stream in the upgrade package includes:
[0029] Perform a digest calculation on the first instruction set to obtain a second digest;
[0030] The second summary is verified based on the first summary;
[0031] After the second digest is verified, the first format data is parsed to obtain the first instruction stream.
[0032] Furthermore, the method also includes:
[0033] Receive upgrade status information sent by the target security chip, the upgrade status information being used to reflect whether the target security chip has been successfully upgraded;
[0034] If the upgrade of the target security chip fails, a reset command is generated and sent to the target security chip.
[0035] If the target security chip is successfully upgraded, upgrade completion information is generated and sent to the cloud platform.
[0036] Embodiments of the present invention provide a security chip upgrade method, applied to a security chip, comprising:
[0037] Once an upgrade is detected, an upgrade request is sent to the cloud platform.
[0038] Receive the upgrade package sent by the microcontroller unit and perform the upgrade according to the upgrade package.
[0039] Furthermore, it receives an upgrade package sent by the microcontroller unit, including:
[0040] Receive upgrade information for multiple target security chips corresponding to the upgrade package.
[0041] Furthermore, the method also includes:
[0042] The upgrade status information is sent to the microcontroller unit, and the upgrade status information is used to indicate whether the security chip has been successfully upgraded.
[0043] Embodiments of the present invention provide a security chip upgrade device applied to a cloud platform, comprising:
[0044] The first sending module is used to send an upgrade command to the microcontroller unit after detecting the upgrade requirement information of the target security chip;
[0045] The first receiving module is used to receive the serial number of the target security chip sent by the microcontroller unit according to the upgrade instruction;
[0046] The determination module is used to determine the upgrade package corresponding to the serial number;
[0047] The second sending module is used to send the upgrade package to the microcontroller unit.
[0048] Furthermore, the determining module includes:
[0049] The lookup unit is used to find the first upgrade package corresponding to the serial number based on the serial number;
[0050] The first processing unit is configured to process the first upgrade package to obtain a first instruction set, the first instruction set including multiple upgrade information of the target security chip;
[0051] A computing unit is used to perform a digest calculation on the first instruction set to obtain a first digest;
[0052] The second processing unit is used to obtain the upgrade package corresponding to the serial number based on the first instruction set and the first digest.
[0053] Furthermore, the second processing unit is also used for:
[0054] Multiple upgrade information items are randomly selected from the first instruction set and encrypted to generate a second instruction set;
[0055] Generate first format data based on the second instruction set and the first instruction set;
[0056] The upgrade package is obtained based on the first format data and the first digest.
[0057] Embodiments of the present invention provide a security chip upgrade device applied to a microcontroller unit, comprising:
[0058] The first acquisition module is used to acquire the serial number of the target security chip after receiving the upgrade instruction sent by the cloud platform;
[0059] The third sending module is used to send the serial number to the cloud platform;
[0060] The second acquisition module is used to acquire the upgrade package corresponding to the serial number fed back by the cloud platform;
[0061] The fourth sending module is used to send the upgrade package to the target security chip.
[0062] Furthermore, the fourth sending module includes:
[0063] The acquisition unit is used to acquire the first instruction stream in the upgrade package, wherein the first instruction stream includes multiple upgrade information of the target security chip classified according to a preset standard;
[0064] The sending unit is used to send the first instruction stream to the target security chip in multiple parts.
[0065] Furthermore, the upgrade package includes: a first instruction set, a first digest, and first format data. The first instruction set includes multiple upgrade information entries for the target security chip. The first digest is obtained by performing a digest calculation on the first instruction set. The first format data is obtained based on the first instruction set and a second instruction set. The second instruction set is obtained by performing encryption calculation on multiple upgrade information entries randomly selected from the first instruction set.
[0066] The acquisition unit is further configured to:
[0067] Perform a digest calculation on the first instruction set to obtain a second digest;
[0068] The second summary is verified based on the first summary;
[0069] After the second digest is verified, the first format data is parsed to obtain the first instruction stream.
[0070] Furthermore, the device also includes:
[0071] The second receiving module is used to receive upgrade status information sent by the target security chip, the upgrade status information being used to reflect whether the target security chip has been successfully upgraded;
[0072] The first generation module is used to generate a reset command and send the reset command to the target security chip if the upgrade of the target security chip fails.
[0073] The second generation module is used to generate upgrade completion information and send the upgrade completion information to the cloud platform when the target security chip is successfully upgraded.
[0074] Embodiments of the present invention provide a security chip upgrade device, applied to a security chip, comprising:
[0075] The fifth sending module is used to send upgrade request information to the cloud platform when an upgrade is detected.
[0076] The third receiving module is used to receive the upgrade package sent by the microcontroller unit and perform the upgrade according to the upgrade package.
[0077] Furthermore, the third receiving module is also used for:
[0078] Receive upgrade information for multiple target security chips corresponding to the upgrade package.
[0079] Furthermore, the device also includes:
[0080] The sixth sending module is used to send upgrade status information to the microcontroller unit, the upgrade status information being used to reflect whether the security chip has been successfully upgraded.
[0081] Embodiments of the present invention provide a cloud platform, including: a first transceiver and a first processor;
[0082] The first transceiver is used to send an upgrade command to the microcontroller unit after detecting an upgrade request for the target security chip;
[0083] Receive the serial number of the target security chip sent by the microcontroller unit according to the upgrade instruction;
[0084] The first processor is used to determine the upgrade package corresponding to the serial number;
[0085] The first transceiver is also used to send the upgrade package to the microcontroller unit.
[0086] Embodiments of the present invention provide a terminal device, including: a second transceiver;
[0087] The second transceiver is used to obtain the serial number of the target security chip after receiving the upgrade instruction sent by the cloud platform;
[0088] Send the serial number to the cloud platform;
[0089] Obtain the upgrade package corresponding to the serial number from the cloud platform;
[0090] The upgrade package is sent to the target security chip.
[0091] Embodiments of the present invention provide a security chip, comprising: a third transceiver and a second processor;
[0092] The third transceiver is used to send upgrade request information to the cloud platform when an upgrade is detected.
[0093] The second processor is used to receive the upgrade package sent by the microcontroller unit and perform the upgrade according to the upgrade package.
[0094] To achieve the above objectives, embodiments of the present invention provide a terminal, including a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; when the processor executes the program or instructions, it implements the security chip upgrade method described above.
[0095] To achieve the above objectives, embodiments of the present invention provide a readable storage medium having a program or instructions stored thereon, which, when executed by a processor, implement the steps in the security chip upgrade method described above.
[0096] The beneficial effects of the above-described technical solution of the present invention are as follows:
[0097] The security chip upgrade method of this invention obtains the serial number of the target security chip to be upgraded through a microcontroller unit (MCU), and after determining the upgrade package corresponding to the serial number, sends the upgrade package to the MCU. The MCU also provides a temporary storage container for the upgrade package of the target security chip. This invention provides a remote upgrade method for the target security chip, solving the problems of cumbersome upgrade operations and high costs in related technologies. Attached Figure Description
[0098] Figure 1 This is a schematic diagram of a surface-mount security chip in an Internet of Things (IoT) application.
[0099] Figure 2 This is a schematic diagram illustrating the connection between the security chip and external devices.
[0100] Figure 3 This is one of the schematic diagrams illustrating the steps of the security chip upgrade method according to an embodiment of the present invention;
[0101] Figure 4 This is a second schematic diagram illustrating the steps of the security chip upgrade method according to an embodiment of the present invention;
[0102] Figure 5 This is the third schematic diagram of the steps of the security chip upgrade method according to an embodiment of the present invention;
[0103] Figure 6 This is a schematic diagram illustrating the interaction process between the cloud platform, the microcontroller unit, and the target security chip in an embodiment of the present invention.
[0104] Figure 7 This is a timing diagram of the security chip upgrade method according to an embodiment of the present invention;
[0105] Figure 8 This is one of the schematic diagrams of a security chip upgrade device according to an embodiment of the present invention;
[0106] Figure 9 This is a second schematic diagram of the security chip upgrade device according to an embodiment of the present invention;
[0107] Figure 10 This is a third schematic diagram of the security chip upgrade device according to an embodiment of the present invention;
[0108] Figure 11This is a schematic diagram of the structure of a terminal according to another embodiment of the present invention. Detailed Implementation
[0109] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0110] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0111] In various embodiments of the present invention, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0112] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0113] In the embodiments provided in this application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0114] like Figure 1 As shown, both SIM chips and security chips belong to the category of security chips, but they are distinguished for different services. SIM chips are security chips that provide user identification and other functions specifically for cellular networks. Security chips mainly consist of two parts: software and hardware. They connect to external devices via a communication interface, such as... Figure 2 As shown.
[0115] like Figure 3 As shown, a security chip upgrade method according to an embodiment of the present invention is applied to a cloud platform, including:
[0116] Step 301: After detecting the upgrade request information of the target security chip, send an upgrade command to the microcontroller unit;
[0117] Step 302: Receive the serial number of the target security chip sent by the microcontroller unit according to the upgrade instruction;
[0118] Step 303: Determine the upgrade package corresponding to the serial number;
[0119] Step 304: Send the upgrade package to the microcontroller unit.
[0120] Optionally, there is business interaction between the microcontroller and the cloud platform. After the cloud platform detects the upgrade requirement information of the target security chip, it stops the business interaction with the microcontroller and performs the security chip upgrade first.
[0121] The security chip upgrade method of this invention obtains the serial number of the target security chip to be upgraded through a microcontroller unit (MCU), and after determining the upgrade package corresponding to the serial number, sends the upgrade package to the MCU. The MCU also provides a temporary storage container for the upgrade package of the target security chip. This invention provides a remote upgrade method for the target security chip, solving the problems of cumbersome upgrade operations and high costs in related technologies.
[0122] Optionally, determining the upgrade package corresponding to the serial number includes:
[0123] Based on the serial number, the first upgrade package corresponding to the serial number is located;
[0124] The first upgrade package is processed to obtain a first instruction set, which includes multiple upgrade messages for the target security chip.
[0125] A first digest is obtained by performing a digest calculation on the first instruction set;
[0126] Based on the first instruction set and the first digest, the upgrade package corresponding to the serial number is obtained.
[0127] In one embodiment of the present invention, the cloud platform pre-stores multiple upgrade packages, and the first upgrade package corresponding to the serial number is found through the serial number;
[0128] The first instruction set includes one upgrade message, or multiple upgrade messages and upgrade message packets.
[0129] The security chip upgrade method of this invention provides a verification method for the transmission of the first instruction set by calculating the first digest. This prevents malicious tampering during the transmission of the first instruction set to the microcontroller unit, thus preventing the microcontroller unit from receiving and sending the tampered first instruction to the target security chip, causing the target security chip to perform an incorrect upgrade based on the tampered first upgrade instruction. This ensures the security of the first upgrade instruction transmission and improves the efficiency of security chip upgrades.
[0130] Optionally, obtaining the upgrade package corresponding to the serial number based on the first instruction set and the first digest includes:
[0131] Multiple upgrade information items are randomly selected from the first instruction set and encrypted to generate a second instruction set;
[0132] Generate first format data based on the second instruction set and the first instruction set;
[0133] The upgrade package is obtained based on the first format data and the first digest.
[0134] In one embodiment of the present invention, only a portion of the first instruction set is encrypted, and the encrypted second instruction set is inserted into the first instruction set to obtain first format data; the first format data and the first digest are sent together as an upgrade package to the microcontroller unit.
[0135] It should be noted that the security chip has a small capacity and limited data processing capabilities. Therefore, encrypting only a portion of the first instruction set reduces the amount of data the security chip needs to decrypt. The security chip upgrade method of this invention, while ensuring the security of the upgrade package, alleviates the pressure on the security chip to decrypt the upgrade package.
[0136] like Figure 4 As shown, an embodiment of the present invention provides a security chip upgrade method applied to a microcontroller unit, comprising:
[0137] Step 401: After receiving the upgrade instruction sent by the cloud platform, obtain the serial number of the target security chip;
[0138] Step 402: Send the serial number to the cloud platform;
[0139] Step 403: Obtain the upgrade package corresponding to the serial number from the cloud platform;
[0140] Step 404: Send the upgrade package to the target security chip.
[0141] The security chip upgrade method of this invention obtains the serial number of the target security chip to be upgraded through a microcontroller unit, sends the serial number to a cloud platform, and then sends an upgrade package determined by the cloud platform based on the serial number to the target security chip, providing a temporary storage container for the upgrade package. This invention provides a remote upgrade method for target security chips, solving the problems of cumbersome upgrade operations and high costs in related technologies.
[0142] Optionally, sending the upgrade package to the target security chip includes:
[0143] Obtain the first instruction stream from the upgrade package, wherein the first instruction stream includes multiple upgrade information entries for the target security chip classified according to a preset standard;
[0144] The first instruction stream is sent to the target security chip in multiple parts.
[0145] Optionally, the preset criteria include the category of upgrade information and the required memory size. The classification of multiple upgrade messages for the target security chip according to the preset criteria includes: classifying them according to the category of upgrade information; or, splitting each upgrade message into individual upgrade messages, with the first instruction stream consisting of these individual upgrade messages.
[0146] In one embodiment of the present invention, by determining the first instruction stream corresponding to the upgrade package, the upgrade data in the upgrade package can be split into individual upgrade information, and the data of the upgrade package can be sent to the target security chip in multiple times. This allows the target security chip to process a smaller amount of data each time, alleviating the memory pressure on the target security chip and improving the firmware upgrade efficiency of the target security chip.
[0147] Optionally, the upgrade package includes: a first instruction set, a first digest, and first format data. The first instruction set includes multiple upgrade information entries for the target security chip. The first digest is obtained by performing a digest calculation on the first instruction set. The first format data is obtained based on the first instruction set and a second instruction set. The second instruction set is obtained by performing encryption calculation on multiple upgrade information entries randomly selected from the first instruction set.
[0148] The step of obtaining the first instruction stream in the upgrade package includes:
[0149] Perform a digest calculation on the first instruction set to obtain a second digest;
[0150] The second summary is verified based on the first summary;
[0151] After the second digest is verified, the first format data is parsed to obtain the first instruction stream.
[0152] Optionally, the second summary is compared with the first summary. If the second summary is the same as the first summary, then the second summary passes the verification.
[0153] Optionally, the first format data is parsed to obtain upgrade information.
[0154] In one embodiment of the present invention, digest calculations are performed on the first instruction set at both the cloud platform and the microcontroller unit. By comparing the first digest and the second digest obtained from the two calculations, it is determined whether there has been malicious tampering during the process of the cloud platform sending the first instruction set to the microcontroller unit. The solution of the present invention ensures the security of the target security chip upgrade by performing digest calculations on the first instruction set twice.
[0155] Optionally, the method further includes:
[0156] Receive upgrade status information sent by the target security chip, the upgrade status information being used to reflect whether the target security chip has been successfully upgraded;
[0157] If the upgrade of the target security chip fails, a reset command is generated and sent to the target security chip.
[0158] If the target security chip is successfully upgraded, upgrade completion information is generated and sent to the cloud platform.
[0159] Optionally, the upgrade status information can be a status code. For example, if the status code is 0x9000, the upgrade is successful; otherwise, the upgrade fails. The reset instruction cancels the current upgrade.
[0160] Optionally, the target security chip can be powered off after the microcontroller generates a reset command.
[0161] The target security chip upgrade method of this invention controls whether the target security chip needs to be powered off based on whether the upgrade is successful, thus ensuring the security of the target security chip.
[0162] like Figure 5 As shown, an embodiment of the present invention provides a security chip upgrade method, applied to a security chip, comprising:
[0163] Step 501: When an upgrade is detected, send upgrade request information to the cloud platform;
[0164] Step 502: Receive the upgrade package sent by the microcontroller unit and perform the upgrade according to the upgrade package.
[0165] The security chip upgrade method of this invention provides a temporary storage container for the upgrade package of the target security chip using a microcontroller unit, enabling firmware upgrades of the target security chip. This invention provides a remote upgrade method for the target security chip, solving the problems of cumbersome upgrade operations and high costs in related technologies.
[0166] Optionally, the upgrade package sent by the microcontroller unit includes:
[0167] Receive upgrade information for multiple target security chips corresponding to the upgrade package.
[0168] Optionally, after receiving the upgrade package sent by the microcontroller unit, it includes:
[0169] The upgrade package is verified using the key stored in the device.
[0170] Optionally, the upgrade information of multiple target security chips corresponding to the upgrade package can be received in multiple batches.
[0171] The target security chip upgrade method of this invention receives the upgrade information corresponding to the upgrade package multiple times, and then performs firmware upgrade in multiple steps according to the upgrade information, thereby alleviating the memory and data processing pressure of the target security chip and improving the firmware upgrade efficiency of the security chip.
[0172] Optionally, the method further includes:
[0173] The upgrade status information is sent to the microcontroller unit, and the upgrade status information is used to indicate whether the security chip has been successfully upgraded.
[0174] The target security chip upgrade method of this invention provides upgrade status information feedback. The microcontroller receives and forwards the upgrade status information, enabling the cloud platform to confirm whether the security chip has been successfully upgraded. For target security chips that have not been successfully upgraded, the platform performs a power-off process, thus ensuring the security of the security chip.
[0175] In this embodiment of the invention, the interaction process between the cloud platform, the microcontroller unit, and the target security chip is as follows: Figure 6 As shown.
[0176] A timing diagram of the security chip upgrade method according to an embodiment of the present invention is shown below. Figure 7 As shown.
[0177] There is business interaction between the microcontroller unit (MCU) and the cloud platform. When the cloud platform detects that the target security chip has an upgrade requirement, it obtains the serial number ID of the target security chip through the microcontroller unit.
[0178] The cloud platform determines the upgrade package corresponding to the serial number of the target security chip; processes the upgrade package to obtain a first instruction set; randomly selects multiple upgrade information from the first instruction set for encryption to generate a second instruction set, and inserts the second instruction set into the first instruction set to obtain first format data; performs digest calculation on the first instruction set to obtain a first digest; and sends the first instruction set, the first format data, and the first digest to the microcontroller unit.
[0179] After receiving the first instruction set, the first format data, and the first digest, the microcontroller first performs digest calculation on the first instruction set to obtain the second digest; it then compares the second digest with the first digest to verify the second digest; after the second digest has been verified, it parses the first format data to obtain upgrade information line by line; and sends the upgrade information to the target security chip in multiple batches.
[0180] Each time the target security chip receives an upgrade message, it performs a firmware upgrade based on the upgrade message and sends upgrade status information indicating whether the firmware upgrade was successful back to the microcontroller unit.
[0181] like Figure 8 As shown, an embodiment of the present invention provides a security chip upgrade device 800, applied to a cloud platform, comprising:
[0182] The first sending module 801 is used to send an upgrade command to the microcontroller unit after detecting the upgrade request information of the target security chip;
[0183] The first receiving module 802 is used to receive the serial number of the target security chip sent by the microcontroller unit according to the upgrade instruction;
[0184] The determination module 803 is used to determine the upgrade package corresponding to the serial number;
[0185] The second sending module 804 is used to send the upgrade package to the microcontroller unit.
[0186] The security chip upgrade device of this invention obtains the serial number of the target security chip to be upgraded through a microcontroller unit (MCU). After determining the upgrade package corresponding to the serial number, the device sends the upgrade package to the MCU and provides a temporary storage container for the upgrade package of the target security chip using the MCU. This invention provides a remote upgrade method for the target security chip, solving the problems of cumbersome upgrade operations and high costs in related technologies.
[0187] Optionally, the determining module includes:
[0188] The lookup unit is used to find the first upgrade package corresponding to the serial number based on the serial number;
[0189] The first processing unit is configured to process the first upgrade package to obtain a first instruction set, the first instruction set including multiple upgrade information of the target security chip;
[0190] A computing unit is used to perform a digest calculation on the first instruction set to obtain a first digest;
[0191] The second processing unit is used to obtain the upgrade package corresponding to the serial number based on the first instruction set and the first digest.
[0192] Optionally, the second processing unit is further configured to:
[0193] Multiple upgrade information items are randomly selected from the first instruction set and encrypted to generate a second instruction set;
[0194] Generate first format data based on the second instruction set and the first instruction set;
[0195] The upgrade package is obtained based on the first format data and the first digest.
[0196] like Figure 9 As shown, an embodiment of the present invention provides a security chip upgrade device 900, applied to a microcontroller unit, comprising:
[0197] The first acquisition module 901 is used to acquire the serial number of the target security chip after receiving the upgrade instruction sent by the cloud platform;
[0198] The third sending module 902 is used to send the serial number to the cloud platform;
[0199] The second acquisition module 903 is used to acquire the upgrade package corresponding to the serial number fed back by the cloud platform;
[0200] The fourth sending module 904 is used to send the upgrade package to the target security chip.
[0201] The security chip upgrade device of this invention obtains the serial number of the target security chip to be upgraded through a microcontroller unit, sends the serial number to a cloud platform, and obtains an upgrade package determined by the cloud platform based on the serial number, which is then sent to the target security chip. A temporary storage container is provided for the upgrade package of the target security chip. This invention provides a remote upgrade method for target security chips, solving the problems of cumbersome upgrade operations and high costs in related technologies.
[0202] Optionally, the fourth transmitting module includes:
[0203] The acquisition unit is used to acquire the first instruction stream in the upgrade package, wherein the first instruction stream includes multiple upgrade information of the target security chip classified according to a preset standard;
[0204] The sending unit is used to send the first instruction stream to the target security chip in multiple parts.
[0205] Optionally, the upgrade package includes: a first instruction set, a first digest, and first format data. The first instruction set includes multiple upgrade information entries for the target security chip. The first digest is obtained by performing a digest calculation on the first instruction set. The first format data is obtained based on the first instruction set and a second instruction set. The second instruction set is obtained by performing encryption calculation on multiple upgrade information entries randomly selected from the first instruction set.
[0206] The acquisition unit is further configured to:
[0207] Perform a digest calculation on the first instruction set to obtain a second digest;
[0208] The second summary is verified based on the first summary;
[0209] After the second digest is verified, the first format data is parsed to obtain the first instruction stream.
[0210] Optionally, the device further includes:
[0211] The second receiving module is used to receive upgrade status information sent by the target security chip, the upgrade status information being used to reflect whether the target security chip has been successfully upgraded;
[0212] The first generation module is used to generate a reset command and send the reset command to the target security chip if the upgrade of the target security chip fails.
[0213] The second generation module is used to generate upgrade completion information and send the upgrade completion information to the cloud platform when the target security chip is successfully upgraded.
[0214] like Figure 10 As shown, an embodiment of the present invention provides a security chip upgrade device 1000, applied to a security chip, comprising:
[0215] The fifth sending module 1001 is used to send upgrade request information to the cloud platform when an upgrade is detected.
[0216] The third receiving module 1002 is used to receive the upgrade package sent by the microcontroller unit and perform the upgrade according to the upgrade package.
[0217] The security chip upgrade device of this invention provides a temporary storage container for the upgrade package of the target security chip using a microcontroller unit, enabling firmware upgrades of the target security chip. This invention provides a remote upgrade method for the target security chip, solving the problems of cumbersome upgrade operations and high costs in related technologies.
[0218] Optionally, the third receiving module is further configured to:
[0219] Receive upgrade information for multiple target security chips corresponding to the upgrade package.
[0220] Optionally, the device further includes:
[0221] The sixth sending module is used to send upgrade status information to the microcontroller unit, the upgrade status information being used to reflect whether the security chip has been successfully upgraded.
[0222] Embodiments of the present invention provide a cloud platform, including: a first transceiver and a first processor;
[0223] The first transceiver is used to send an upgrade command to the microcontroller unit after detecting an upgrade request for the target security chip;
[0224] Receive the serial number of the target security chip sent by the microcontroller unit according to the upgrade instruction;
[0225] The first processor is used to determine the upgrade package corresponding to the serial number;
[0226] The first transceiver is also used to send the upgrade package to the microcontroller unit.
[0227] Optionally, the first processor is further configured to:
[0228] Based on the serial number, the first upgrade package corresponding to the serial number is located;
[0229] The first upgrade package is processed to obtain a first instruction set, which includes multiple upgrade messages for the target security chip.
[0230] A first digest is obtained by performing a digest calculation on the first instruction set;
[0231] Based on the first instruction set and the first digest, the upgrade package corresponding to the serial number is obtained.
[0232] Optionally, the first processor is further configured to:
[0233] Multiple upgrade information items are randomly selected from the first instruction set and encrypted to generate a second instruction set;
[0234] Generate first format data based on the second instruction set and the first instruction set;
[0235] The upgrade package is obtained based on the first format data and the first digest.
[0236] Embodiments of the present invention provide a terminal device, including: a second transceiver;
[0237] The second transceiver is used to obtain the serial number of the target security chip after receiving the upgrade instruction sent by the cloud platform;
[0238] Send the serial number to the cloud platform;
[0239] Obtain the upgrade package corresponding to the serial number from the cloud platform;
[0240] The upgrade package is sent to the target security chip.
[0241] Optionally, the second transceiver is further configured to:
[0242] Obtain the first instruction stream from the upgrade package, wherein the first instruction stream includes multiple upgrade information entries for the target security chip classified according to a preset standard;
[0243] The first instruction stream is sent to the target security chip in multiple parts.
[0244] Optionally, the second transceiver is further configured to:
[0245] Perform a digest calculation on the first instruction set to obtain a second digest;
[0246] The second summary is verified based on the first summary;
[0247] After the second digest is verified, the first format data is parsed to obtain the first instruction stream;
[0248] The upgrade package includes: a first instruction set, a first digest, and first format data. The first instruction set includes multiple upgrade information entries for the target security chip. The first digest is obtained by performing a digest calculation on the first instruction set. The first format data is obtained based on the first instruction set and a second instruction set. The second instruction set is obtained by performing encryption calculation on multiple randomly selected upgrade information entries from the first instruction set.
[0249] Optionally, the second transceiver is further configured to:
[0250] Receive upgrade status information sent by the target security chip, the upgrade status information being used to reflect whether the target security chip has been successfully upgraded;
[0251] If the upgrade of the target security chip fails, a reset command is generated and sent to the target security chip.
[0252] If the target security chip is successfully upgraded, upgrade completion information is generated and sent to the cloud platform.
[0253] Embodiments of the present invention provide a security chip, comprising: a third transceiver and a second processor;
[0254] The third transceiver is used to send upgrade request information to the cloud platform when an upgrade is detected.
[0255] The second processor is used to receive the upgrade package sent by the microcontroller unit and perform the upgrade according to the upgrade package.
[0256] Optionally, the third transceiver is further configured to:
[0257] Receive upgrade information for multiple target security chips corresponding to the upgrade package.
[0258] Optionally, the third transceiver is further configured to:
[0259] The upgrade status information is sent to the microcontroller unit, and the upgrade status information is used to indicate whether the security chip has been successfully upgraded.
[0260] Another embodiment of the present invention includes a terminal, such as Figure 11 As shown, it includes a transceiver 1110, a processor 1100, a memory 1120, and a program or instructions stored in the memory 1120 and executable on the processor 1100; when the processor 1100 executes the program or instructions, it implements the above-mentioned method for upgrading security chips.
[0261] The transceiver 1110 is used to receive and send data under the control of the processor 1100.
[0262] Among them, Figure 11 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1100 and memory represented by memory 1120 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 1110 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, user interface 1130 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0263] The processor 1100 is responsible for managing the bus architecture and general processing, and the memory 1120 can store the data used by the processor 1100 when performing operations.
[0264] An embodiment of the present invention provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the steps in the security chip upgrade method described above and achieve the same technical effect. To avoid repetition, the details will not be repeated here.
[0265] The processor mentioned above is the processor in the readable storage medium described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0266] It should be further noted that the terminals described in this specification include, but are not limited to, smartphones, tablets, etc., and many of the functional components described are referred to as modules in order to emphasize the independence of their implementation.
[0267] In this embodiment of the invention, the module can be implemented in software so that it can be executed by various types of processors. For example, an identified executable code module may include one or more physical or logical blocks of computer instructions, which may be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but may include different instructions stored in different bits, which, when logically combined, constitute the module and achieve the module's intended purpose.
[0268] In practice, an executable code module can be a single instruction or many instructions, and can even be distributed across multiple different code segments, different programs, and across multiple memory devices. Similarly, operational data can be identified within the module and can be implemented in any suitable form and organized within any suitable type of data structure. This operational data can be collected as a single dataset or distributed across different locations (including different storage devices), and can exist, at least in part, solely as electronic signals within the system or network.
[0269] When a module can be implemented using software, considering the current level of hardware technology, modules that can be implemented in software can be implemented using hardware circuits by those skilled in the art to achieve the corresponding functions, without considering cost. These hardware circuits include conventional very-large-scale integrated circuits (VLSI) or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules can also be implemented using programmable hardware devices, such as field-programmable gate arrays, programmable array logic, and programmable logic devices.
[0270] The exemplary embodiments described above are with reference to the accompanying drawings. Many different forms and embodiments are feasible without departing from the spirit and teachings of the invention. Therefore, the invention should not be construed as limiting the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided to make the invention complete and convey the scope of the invention to those skilled in the art. In these drawings, component dimensions and relative dimensions may be exaggerated for clarity. The terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. As used herein, unless clearly indicated otherwise, the singular forms “a,” “an,” and “the” are intended to include all such forms. It will be further understood that the terms “comprising” and / or “including”, when used in this specification, indicate the presence of the stated features, integers, steps, operations, components, and / or elements, but do not exclude the presence or addition of one or more other features, integers, steps, operations, components, and / or groups thereof. Unless otherwise indicated, when stated, a range of values includes the upper and lower limits of the range and any subranges in between.
[0271] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for upgrading a security chip, characterized in that, Applied to a cloud platform, the cloud platform and the microcontroller unit have business interactions, including: Upon detecting an upgrade request for the target security chip, an upgrade command is sent to the microcontroller unit; the target security chip is a SIM chip that provides user identification functionality only for cellular networks. Receive the serial number of the target security chip sent by the microcontroller unit according to the upgrade instruction; Determine the upgrade package corresponding to the serial number; The upgrade package is sent to the microcontroller unit, which stores the upgrade package as a temporary storage container. The step of determining the upgrade package corresponding to the serial number includes: Based on the serial number, the first upgrade package corresponding to the serial number is located; The first upgrade package is processed to obtain a first instruction set, which includes multiple upgrade messages for the target security chip. A first digest is obtained by performing a digest calculation on the first instruction set; Obtaining the upgrade package corresponding to the serial number based on the first instruction set and the first digest includes: randomly selecting multiple upgrade information entries from the first instruction set for encrypted calculation to generate a second instruction set; inserting the second instruction set into the first instruction set to generate first format data; and obtaining the upgrade package based on the first format data and the first digest.
2. A method for upgrading a security chip, characterized in that, Applied to microcontroller units, which have business interactions with the cloud platform, including: After receiving the upgrade instruction sent by the cloud platform, the serial number of the target security chip is obtained. The target security chip is a SIM chip that provides user identification function only for cellular networks. Send the serial number to the cloud platform; The microcontroller unit receives the upgrade package corresponding to the serial number from the cloud platform and stores the upgrade package as a temporary storage container. Send the upgrade package to the target security chip; Sending the upgrade package to the target security chip includes: Obtain the first instruction stream from the upgrade package, the first instruction stream including multiple upgrade information of the target security chip classified according to a preset standard; The first instruction stream is sent to the target security chip in multiple parts; The upgrade package includes: a first instruction set, a first digest, and first format data. The first instruction set is obtained by finding the first upgrade package corresponding to the serial number based on the serial number and processing the first upgrade package. The first instruction set includes multiple upgrade information entries for the target security chip. The first digest is obtained by performing digest calculation on the first instruction set. The first format data is obtained by inserting a second instruction set into the first instruction set. The second instruction set is obtained by performing encryption calculation on multiple randomly selected upgrade information entries from the first instruction set. The step of obtaining the first instruction stream in the upgrade package includes: Perform a digest calculation on the first instruction set to obtain a second digest; The second summary is verified based on the first summary; After the second digest is verified, the first format data is parsed to obtain the first instruction stream.
3. The security chip upgrade method according to claim 2, characterized in that, The method further includes: Receive upgrade status information sent by the target security chip, the upgrade status information being used to reflect whether the target security chip has been successfully upgraded; If the upgrade of the target security chip fails, a reset command is generated and sent to the target security chip. If the target security chip is successfully upgraded, upgrade completion information is generated and sent to the cloud platform.
4. A security chip upgrade device, characterized in that, Applied to a cloud platform, the cloud platform and the microcontroller unit have business interactions, including: The first sending module is used to send an upgrade command to the microcontroller unit after detecting the upgrade request information of the target security chip, wherein the target security chip is a SIM chip that only provides user identification function for cellular networks; The first receiving module is used to receive the serial number of the target security chip sent by the microcontroller unit according to the upgrade instruction; The determination module is used to determine the upgrade package corresponding to the serial number; The second sending module is used to send the upgrade package to the microcontroller unit, and the microcontroller unit stores the upgrade package as a temporary storage container; The determining module includes: The lookup unit is used to find the first upgrade package corresponding to the serial number based on the serial number; The first processing unit is configured to process the first upgrade package to obtain a first instruction set, the first instruction set including multiple upgrade information of the target security chip; A computing unit is used to perform a digest calculation on the first instruction set to obtain a first digest; The second processing unit is used to obtain the upgrade package corresponding to the serial number based on the first instruction set and the first digest; The second processing unit is further configured to: Multiple upgrade information items are randomly selected from the first instruction set and encrypted to generate a second instruction set; Insert the second instruction set into the first instruction set to generate data in the first format; The upgrade package is obtained based on the first format data and the first digest.
5. A security chip upgrade device, characterized in that, Applied to microcontroller units, which have business interactions with the cloud platform, including: The first acquisition module is used to acquire the serial number of the target security chip after receiving the upgrade instruction sent by the cloud platform. The target security chip is a SIM chip that only provides user identification function for cellular networks. The third sending module is used to send the serial number to the cloud platform; The second acquisition module is used to acquire the upgrade package corresponding to the serial number fed back by the cloud platform, and the microcontroller unit stores the upgrade package as a temporary storage container. The fourth sending module is used to send the upgrade package to the target security chip; The fourth sending module includes: The acquisition unit is used to acquire the first instruction stream in the upgrade package, wherein the first instruction stream includes multiple upgrade information of the target security chip classified according to a preset standard; A sending unit is used to send the first instruction stream to the target security chip in multiple parts; The upgrade package includes: a first instruction set, a first digest, and first format data. The first instruction set is obtained by finding the first upgrade package corresponding to the serial number based on the serial number and processing the first upgrade package. The first instruction set includes multiple upgrade information entries for the target security chip. The first digest is obtained by performing digest calculation on the first instruction set. The first format data is obtained by inserting a second instruction set into the first instruction set. The second instruction set is obtained by performing encryption calculation on multiple randomly selected upgrade information entries from the first instruction set. The acquisition unit is further configured to: Perform a digest calculation on the first instruction set to obtain a second digest; The second summary is verified based on the first summary; After the second digest is verified, the first format data is parsed to obtain the first instruction stream.
6. The security chip upgrade device according to claim 5, characterized in that, The device further includes: The second receiving module is used to receive upgrade status information sent by the target security chip, the upgrade status information being used to reflect whether the target security chip has been successfully upgraded; The first generation module is used to generate a reset command and send the reset command to the target security chip if the upgrade of the target security chip fails. The second generation module is used to generate upgrade completion information and send the upgrade completion information to the cloud platform when the target security chip is successfully upgraded.
7. A terminal, comprising: A transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the security chip upgrade method as described in any one of claims 1-3.
8. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the steps in the security chip upgrade method as described in any one of claims 1-3.
Citation Information
Patent Citations
Upgrading method and upgrading control method of Bluetooth device firmware program, and equipment
CN104915237A
Software upgrading method and device and electronic equipment
CN106886422A
POS upgrading method, apparatus and device based on OTA and storage medium
CN109165034A
Firmware protection method and device and terminal equipment
CN112100624A