A protection method for preventing malicious copying of single-chip microcomputer firmware

By burning the encryption software in the microcontroller FLASH and using hardware unique identifiers for MD5 encryption, combining custom array computing to generate encrypted data and compare, the problem of easy copying of microcontroller firmware is solved, and effective firmware protection is achieved to prevent malicious copying.

CN118427862BActive Publication Date: 2025-07-11YANGZHOU WANFANG ELECTRONICS TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410664459.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-27
Publication Date
2025-07-11
Estimated Expiration
2044-05-27

AI Technical Summary

Technical Problem

In the prior art, the firmware of microcontrollers is easily maliciously copied, resulting in damage to the intellectual property rights of the software developers and lack of effective protection methods.

Method used

By burning the encryption software in the microcontroller FLASH, the microcontroller's hardware unique identification is used for MD5 encryption, and the encrypted data is generated in combination with custom array operations, covering the encryption software storage area. The IPMC firmware compares the encrypted data during operation to determine whether it enters normal or safe mode.

Benefits of technology

It realizes the protection of firmware of microcontrollers that does not require additional hardware support and is difficult to crack, preventing malicious copying and ensuring that the intellectual property rights of software developers are not violated.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118427862B_ABST
    Figure CN118427862B_ABST
Patent Text Reader

Abstract

The present invention discloses a protection method for preventing malicious copying of single-chip microcomputer firmware, which relates to the field of single-chip microcomputer protection. The method includes the following steps: S1. Build the minimum working system for the periphery of the single-chip microcomputer; S2. Burn the encryption software into the FLASH of the single-chip microcomputer, obtain the unique identifier of the single-chip microcomputer hardware, encrypt the obtained unique identifier through an encryption function, and store the formed encrypted data in the FLASH of the single-chip microcomputer; S3. Burn the IPMC firmware into the FLASH of the single-chip microcomputer to overwrite the encryption software; S4. When the IPMC firmware is executed, obtain the unique identifier of the single-chip microcomputer hardware, calculate the obtained identifier according to the encryption function, and compare it with the stored encrypted data; S5. After the comparison is completed, if the comparison result is successful, enter the normal execution of the IPMC firmware, and if the comparison fails, enter the safe mode for execution. In the work of the present invention, the function of preventing malicious copying of the single-chip microcomputer firmware is realized by using the unique chip ID of each single-chip microcomputer for encryption operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of single-chip microcomputer software protection, and is a protection method for preventing malicious copying of single-chip microcomputer firmware. Background Art

[0002] A single-chip microcomputer is also known as a single-chip microcontroller. The single-chip microcomputer firmware can be burned and stored in the single-chip microcomputer FLASH through an ARM emulator. After the single-chip microcomputer is powered on, the initialization assembly code copies the firmware into the RAM of the single-chip microcomputer, sets up the stack, and calls the main function of the firmware program to start running the firmware.

[0003] The design of the peripheral hardware circuit of the single-chip microcomputer is relatively simple, and the relevant reference circuits are relatively common. Usually, the minimum system consists of a single-chip microcomputer chip, a crystal oscillator, a reset circuit, a power supply circuit, and an external expansion interface, etc. When in use, according to the functional requirements of the single-chip microcomputer, a corresponding peripheral circuit is added to form an IPMC (i.e., Intelligent Platform Management Controller) system. In the past use and debugging process, it was found that the development time was mainly concentrated on the development and debugging of the single-chip microcomputer software.

[0004] When the single-chip microcomputer software is debugged and solidified in the single-chip microcomputer FLASH, if the peripheral hardware circuit of the single-chip microcomputer is replicated and the firmware stored in the single-chip microcomputer FLASH is copied out through a burning tool, the same IPMC function can be obtained. The copying party only needs to bear very little cost, and the time and personnel costs of software development can be ignored, and only the corresponding hardware circuit needs to be built. The completion of the copying of the single-chip microcomputer's implemented function will cause great losses to the original software development party. Therefore, it is necessary to technically protect the single-chip microcomputer firmware to prevent the situation of malicious copying of the single-chip microcomputer firmware. Summary of the Invention

[0005] In view of the above problems, the present invention provides a method for preventing malicious copying of single-chip firmware without additional hardware support, which is not easy to crack and improves reliability.

[0006] The technical solution of the present invention is as follows: A protection method for preventing malicious copying of single-chip microcomputer firmware, comprising the following steps:

[0007] S1. Build the minimum working system of the single-chip microcomputer peripheral;

[0008] S2. Burn the encryption software in the single-chip microcomputer FLASH, obtain the unique identifier of the single-chip microcomputer hardware, encrypt the obtained unique identifier through an encryption function, and store the formed encrypted data in the single-chip microcomputer FLASH. The burning start address of the encryption software is designed after the encrypted data storage address;

[0009] S3. Burn the IPMC firmware into the single-chip microcomputer FLASH. The starting address for burning the IPMC firmware is the same as the starting address for running the encryption software, and it is used to overwrite the encryption software;

[0010] S4. When the IPMC firmware executes, obtain the unique hardware identifier of the single-chip microcomputer, calculate the obtained identifier according to the encryption function, and compare it with the stored encrypted data;

[0011] S5. After the comparison is completed, if the comparison result is successful, enter the normal execution of the IPMC firmware; if the comparison fails, enter the safe mode for execution.

[0012] In step S2, the encryption software uses the chip ID read from the single-chip microcomputer as the unique hardware identifier for encryption operations, and combines the MD5 encryption method, binary number operation encryption method, and custom array for encryption.

[0013] The encryption process of the encryption function is as follows:

[0014] Perform MD5 encryption operation on the obtained chip ID to generate 16-byte data;

[0015] Create an array with a storage space of 48 bytes, and store the data after the first MD5 encryption operation into the first 16 bytes of the array;

[0016] Perform exclusive OR operation on the data stored in the first 16 bytes of the array and the specified four-byte data, and store it into the 17 - 32 bytes of the array;

[0017] Perform OR operation on the first eight bytes of the data after the first MD5 encryption operation and the specified four-byte data, and store it into the 33 - 40 bytes of the array;

[0018] Perform AND operation on the last eight bytes of the data after the first MD5 encryption operation and the specified four-byte data, and store it into the 41 - 48 bytes of the array;

[0019] Perform MD5 encryption on the created array to generate 16-byte encrypted data.

[0020] In step S2, use an ARM emulator to connect to the single-chip microcomputer programming port to burn the encryption software.

[0021] The FLASH of the single-chip microcomputer includes an encrypted data storage area, an encryption software program storage area, and an IPMC firmware operation area.

[0022] The encrypted data storage area is used to store encrypted data, the encryption software program storage area is used to store the encryption software, and the IPMC firmware operation area is used to run the IPMC firmware.

[0023] In step S4,

[0024] When the IPMC firmware is executed,

[0025] The IPMC firmware first obtains the data in the corresponding FLASH storage area, then obtains the unique hardware identifier of the single-chip microcomputer, brings the obtained single-chip microcomputer hardware identifier into the encryption function for operation, generates 16-byte encrypted data, and thus compares it with the stored encrypted data.

[0026] In step S5, after the IPMC firmware enters the security mode, it prints an error prompt through the serial port for troubleshooting.

[0027] In step S3, use an ARM emulator to connect to the single-chip microcomputer programming port and program the IPMC firmware.

[0028] The specified four bytes are consecutive or non-consecutive letters, consecutive or non-consecutive numbers.

[0029] In the working process of the present invention, by using the unique chip ID of each single-chip microcomputer for encryption operation, the function of preventing malicious copying of the single-chip microcomputer firmware is realized. When this function is realized, it has the characteristics of simple software programming operation and convenient transplantation of the encryption function.

[0030] After the encrypted data is calculated and stored by programming the encryption software, the programmed IPMC firmware will avoid the storage area of the encrypted data, but will overwrite the storage area of the encryption software program to realize the protection of the encryption software. According to the comparison result of the encrypted data during the operation of the IPMC firmware, it enters different operation modes. If the firmware of the single-chip microcomputer FLASH is maliciously copied out, the firmware will enter the security mode due to the failure of the encrypted data comparison after running, realizing the anti-copy protection of the single-chip microcomputer firmware. Brief Description of the Drawings

[0031] Figure 1 is the working process of the encryption software,

[0032] Figure 2 is a schematic diagram of the storage locations of the encrypted data, the encryption software, and the IPMC firmware,

[0033] Figure 3 is the encryption process of the encrypted storage data,

[0034] Figure 4 is the flowchart of the judgment of the anti-malicious copying part in the IPMC firmware. Detailed Embodiment

[0035] A protection method for preventing malicious copying of single-chip microcomputer firmware in the present invention includes the following steps:

[0036] S1. Build the minimum working system of the single-chip microcomputer periphery. The minimum working system is a conventional technology;

[0037] S2. Burn the encrypted software into the single-chip microcomputer FLASH, obtain the unique identifier of the single-chip microcomputer hardware, encrypt the obtained unique identifier through the encryption function, and store the formed encrypted data in the single-chip microcomputer FLASH. The burning start address of the encrypted software is designed after the encrypted data storage address;

[0038] S3. Burn the IPMC firmware into the single-chip microcomputer FLASH. The burning start address of the IPMC firmware is the same as the running start address of the encrypted software, and it is used to overwrite the encrypted software;

[0039] S4. When the IPMC firmware is executed, obtain the unique identifier of the single-chip microcomputer hardware, calculate the obtained identifier according to the encryption function, and compare it with the stored encrypted data;

[0040] S5. After the comparison is completed, if the comparison result is successful, enter the normal execution of the IPMC firmware, and if the comparison fails, enter the safe mode for execution.

[0041] Specifically, as in the present invention Figure 1 shown, it is necessary to first burn the encrypted software into the single-chip microcomputer. When the encrypted software runs, it will read the chip ID number of the single-chip microcomputer, bring the obtained data into the encryption function, and realize the operation and storage of the encrypted data of the single-chip microcomputer.

[0042] As Figure 2 shown, the encrypted data occupies a total of 16 bytes and is stored starting from the address 0x8000000. The storage location of the encrypted data needs to be far away from the storage addresses of the encrypted software and the IPMC firmware. To avoid the situation where the encrypted data is overwritten and damaged, the storage addresses of the encrypted software and the IPMC firmware are set to 0x8001000. After the single-chip microcomputer is reset or powered on again, the program will start running from the set address 0x8001000. The writing ranges of the encrypted software and the IPMC firmware are uniformly set to 0x40000. After burning the encrypted software, then burn the IPMC firmware. Since the firmware storage area is the same as the set range of the encrypted software, the firmware will completely overwrite the encrypted software, avoiding the risk of encrypted software leakage.

[0043] By obtaining the chip ID of the single-chip microcomputer as the unique identifier number of the hardware, combining the MD5 encryption method with the custom encryption method, it is ensured that the encrypted data cannot be reversely restored, making the encrypted data unique.

[0044] The FLASH of the single-chip microcomputer includes an encrypted data storage area, an encrypted software program storage area, and an IPMC firmware operation area,

[0045] The encrypted data storage area is used to store encrypted data, the encrypted software program storage area is used to store encrypted software, and the IPMC firmware operation area is used to run the IPMC firmware.

[0046] As Figure 3 shown, the encryption process of the encrypted data involves the MD5 encryption method, the conventional binary number operation encryption method, and the custom array encryption method. By combining various encryption methods, a 48-byte encrypted array is generated, and finally the MD5 encryption method is used to calculate the encrypted array to generate 16-byte encrypted data, improving the security of the encryption algorithm.

[0047] The encryption process of the encryption function is as follows:

[0048] Perform MD5 encryption operation on the obtained chip ID to generate 16-byte data;

[0049] Create an array with a storage space of 48 bytes, and store the data after the initial MD5 encryption operation into the first 16 bytes of the array;

[0050] Perform an exclusive OR operation on the data stored in the first 16 bytes of the array and the specified four-byte data, and store it into the 17-32 bytes of the array;

[0051] Perform an OR operation on the first eight bytes of the data after the initial MD5 encryption operation and the specified four-byte data, and store it into the 33-40 bytes of the array;

[0052] Perform an AND operation on the last eight bytes of the data after the initial MD5 encryption operation and the specified four-byte data, and store it into the 41-48 bytes of the array;

[0053] Perform MD5 encryption on the created array to generate 16-byte encrypted data.

[0054] The specified four bytes in the present invention are consecutive or non-consecutive letters, consecutive or non-consecutive numbers. Consecutive letters such as abcd, etc.

[0055] MD5, also known as the Message Digest Algorithm, is a widely used cryptographic hash function that can produce a 128-bit (16-byte) encrypted value, and has the characteristics of fixed encrypted data size, simple encrypted data calculation, and extremely low encrypted data repetition rate.

[0056] Before the IPMC firmware is executed, the encryption function in the encryption software is used to perform encryption calculation on the chip ID of the single-chip microcomputer. The encrypted data stored in the FLASH is read out and compared with the data after the encryption calculation. If the comparison is successful, the normal IPMC function is executed. If the comparison fails, only some functions of the single-chip microcomputer are opened for subsequent fault troubleshooting.

[0057] The present invention is as Figure 4As shown, the comparison of encrypted data is implemented in the IPMC firmware. By using the encryption function encapsulated in the encryption software, the chip ID of the current microcontroller is encrypted and compared with the data stored in the corresponding encrypted data storage location. If the comparison is successful, the IPMC function is executed normally (i.e., the sub-card program runs normally). If the comparison fails, the initialization of the corresponding microcontroller pins is cancelled and the security mode is entered.

[0058] After the IPMC firmware enters the security mode, an error message is printed through the serial port for troubleshooting. The serial port input function is retained to be used as an information input channel for reactivating the IPMC function of the microcontroller on-site.

[0059] To activate the IPMC function of the microcontroller in the security mode, a pre-set activation key needs to be input through the serial port. After the IPMC firmware successfully recognizes it, the correct encrypted data is stored in the original encrypted data storage location through the encryption algorithm. After the data storage is completed, the microcontroller is reset, and the microcontroller firmware is re-executed to activate the IPMC function.

[0060] To ensure the security of the key, the key is formed by different combinations of numbers, special characters, uppercase and lowercase letters.

[0061] The present invention uses the unique chip ID of the microcontroller hardware when it leaves the factory. Through a custom encryption method, the encrypted data is stored in the FLASH memory of the microcontroller. Each time the IPMC firmware is executed, the microcontroller chip ID is obtained, and the encrypted data calculation is performed using the encryption algorithm in the encryption software. Then, the calculated value is compared with the data in the encrypted data storage address to determine whether the IPMC function is executed normally. If the firmware of the microcontroller FLASH is maliciously copied out, it will enter the security mode after the firmware runs because the comparison of the encrypted data fails, thus realizing the protection against malicious copying of the microcontroller firmware.

[0062] The technical means disclosed in the solution of the present invention are not limited to the technical means disclosed in the above embodiments, but also include technical solutions formed by any combination of the above technical features. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.

Claims

1. A protection method for preventing malicious copying of single-chip microcomputer firmware, characterized in that, It includes the following steps: S1. Build the minimum working system for the peripheral of the single-chip microcomputer; S2. Burn the encryption software into the FLASH of the single-chip microcomputer, obtain the unique identifier of the single-chip microcomputer hardware, encrypt the obtained unique identifier through the encryption function, and store the formed encrypted data in the FLASH of the single-chip microcomputer. The burning start address of the encryption software is designed after the encrypted data storage address; S3. Burn the IPMC firmware into the FLASH of the single-chip microcomputer. The burning start address of the IPMC firmware is the same as the running start address of the encryption software and is used to overwrite the encryption software; S4. When the IPMC firmware executes, obtain the unique identifier of the single-chip microcomputer hardware, calculate the obtained identifier according to the encryption function, and compare it with the stored encrypted data; S5. After the comparison is completed, if the comparison result is successful, enter the normal execution of the IPMC firmware. If the comparison fails, enter the safe mode for execution; In step S2, the encryption software uses the chip ID read from the single-chip microcomputer as the unique identifier of the hardware for encryption operation, and combines the MD5 encryption method, the binary number operation encryption method and the custom array for encryption; The encryption process of the encryption function is as follows: Perform MD5 encryption operation on the obtained chip ID to generate 16-byte data; Create an array with a storage space of 48 bytes, and store the data after the initial MD5 encryption operation into the first 16 bytes of the array; Perform an exclusive OR operation on the data stored in the first 16 bytes of the array and the specified four-byte data, and store it into the 17-32 bytes of the array; Perform an OR operation on the first eight bytes of the data after the initial MD5 encryption operation and the specified four-byte data, and store it into the 33-40 bytes of the array; Perform an AND operation on the last eight bytes of the data after the initial MD5 encryption operation and the specified four-byte data, and store it into the 41-48 bytes of the array; Perform MD5 encryption on the created array to generate 16-byte encrypted data.

2. A protection method for preventing malicious copying of the single-chip microcomputer firmware according to claim 1, characterized in that In step S2, use an ARM emulator to connect to the single-chip microcomputer burning port and burn the encryption software.

3. A protection method for preventing malicious copying of a single-chip microcomputer firmware according to claim 1, characterized in that, The FLASH of the single-chip microcomputer includes an encrypted data storage area, an encryption software program storage area, and an IPMC firmware operation area. The encrypted data storage area is used to store encrypted data, the encryption software program storage area is used to store encryption software, and the IPMC firmware operation area is used to run the IPMC firmware.

4. A protection method for preventing malicious copying of a single-chip microcomputer firmware according to claim 1, characterized in that, In step S4, When the IPMC firmware executes, The IPMC firmware first obtains the data in the corresponding FLASH storage area, then obtains the unique identifier of the single-chip microcomputer hardware, brings the obtained single-chip microcomputer identifier into the encryption function for operation to generate 16-byte encrypted data, and thus compares it with the stored encrypted data.

5. A protection method for preventing malicious copying of a single-chip microcomputer firmware according to claim 1, characterized in that In step S5, after the IPMC firmware enters the safe mode, it prints an error prompt through the serial port for troubleshooting.

6. A protection method for preventing malicious copying of a single-chip microcomputer firmware according to claim 1, characterized in that, In step S3, use an ARM emulator to connect to the single-chip microcomputer burning port and burn the IPMC firmware.

7. A protection method for preventing malicious copying of a single-chip microcomputer firmware according to claim 1, characterized in that, The specified four bytes are consecutive or non-consecutive letters, consecutive or non-consecutive numbers.

Citation Information

Patent Citations

  • Software authorization licensing system capable of preventing software piracy

    CN116383779A

  • EMS embedded software encryption algorithm

    CN117668883A