A Firmware Rollback Protection Method and System Based on Trusted Credentials
Through a trusted credential-based method, the attack risk in device firmware rollback protection is solved, the controllability and security of device firmware updates are realized, and the after-audience audit capability is provided.
Patent Information
- Application Number
- CN202410783147.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-18
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-06-18
AI Technical Summary
In the prior art, an attacker can use security flaws to attack the device by burning old version of firmware to the device and restarting it, lacking effective rollback protection measures.
By extracting and verifying the latest trusted credentials based on trusted credentials, ensuring that firmware updates and restart versions meet security requirements, including timestamps, serial numbers and signature verification, building a trust chain to achieve firmware rollback protection.
Improve the controllability and security of device firmware updates, prevent illegal firmware flushing, and provide after-audience audit capabilities.
Smart Images

Figure CN118779863B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of firmware update protection, and more specifically, to a method and system for firmware rollback protection based on trusted credentials. Background Art
[0002] Even if the update process is completely secure and trustworthy, an attacker can burn an old version of the firmware with security vulnerabilities into the device, then restart and enter the old version, and use the security vulnerabilities to attack the device. The protection measure against such attacks is called "rollback protection"; "rollback protection" is usually achieved in the following way: using a tamper-proof storage space to record the latest firmware version, and refusing to start when the firmware version is lower than the recorded version; the tamper-proof storage space usually includes OTP / EFuse, TPM / TCM, etc. In the present invention, the OTP / EFuse generally refers to a one-time programmable space, which has good tamper-proof characteristics, but the space for recording data is limited; the TPM / TCM in the present invention generally refers to a trusted module, which usually has secure storage and trusted computing capabilities. The TPM / TCM with software tamper-proof design has good tamper-proof characteristics. Summary of the Invention
[0003] In view of the above problems, the purpose of the present invention is to provide a method and system for firmware rollback protection based on trusted credentials, which can improve the controllability and security of device firmware updates.
[0004] The first aspect of the present invention provides a method for firmware rollback protection based on trusted credentials, including:
[0005] Extracting a set of trusted credentials based on a preset time period;
[0006] Comparing and analyzing the trusted credentials in the set of trusted credentials to obtain the latest trusted credential;
[0007] Extracting the required firmware package based on the latest trusted credential;
[0008] Based on a preset rule for verifying trusted credentials, verifying the latest trusted credential. If the latest trusted credential passes the verification, firmware update is allowed; if the latest trusted credential fails the verification, firmware update is not allowed;
[0009] Updating the firmware based on the firmware package to obtain an updated firmware, and restarting the updated firmware;
[0010] Based on a rollback protection verification rule, verifying the version number of the restarted firmware. If the restart verification is passed, the updated firmware starts normally and the firmware update is successful; if the restart verification is not passed, the firmware update fails.
[0011] In this solution, the step of comparing and analyzing the trusted credentials in the trusted credential set to obtain the latest trusted credential specifically includes:
[0012] Extract the expiration date and timestamp in the latest trusted credential;
[0013] Extract the current timestamp;
[0014] Subtract the timestamp in the latest trusted credential from the current timestamp to obtain a time difference;
[0015] If the time difference is less than or equal to the expiration date in the latest trusted credential, the current latest trusted credential is valid;
[0016] If the time difference is greater than the expiration date in the latest trusted credential, the current latest trusted credential is invalid.
[0017] In this solution, after obtaining the latest trusted credential, it further includes:
[0018] Extract the expiration date and the current timestamp in the latest trusted credential;
[0019] If the current timestamp is within the expiration date of the corresponding latest trusted credential, the current latest trusted credential is valid;
[0020] If the current timestamp is not within the expiration date of the corresponding latest trusted credential, the current latest trusted credential is invalid.
[0021] This solution further includes:
[0022] Extract the product serial number set and device serial number set in the latest trusted credential;
[0023] Extract the product serial number and device serial number of the device;
[0024] Match the product serial number of the device with the product serial numbers in the product serial number set in the latest trusted credential one by one. If they are all different, the trusted credential is invalid for this device;
[0025] Match the device serial number of the device with the device serial numbers in the device serial number set in the latest trusted credential one by one. If they are all different, the trusted credential is invalid for this device.
[0026] In this solution, the step of verifying the latest trusted credential specifically includes:
[0027] Extract the trusted signature in the latest trusted credential;
[0028] Based on the preset trusted signature verification rule, verify the trusted signature. If the trusted signature verification is passed, extract the elements in the latest trusted credential; if the trusted signature verification fails, the verification of the latest trusted credential fails.
[0029] Based on the preset element verification rules, verify the elements in the latest trusted credential. If the element verification is passed, the latest trusted credential passes the verification; if the element verification fails, the latest trusted credential fails the verification.
[0030] In this solution, the steps for verifying the trusted signature specifically include:
[0031] Obtain the public key in the trusted environment of the device;
[0032] Decrypt the trusted signature according to the public key in the trusted environment of the device to obtain the trusted credential digest value 1;
[0033] Extract the content of the latest trusted credential;
[0034] Send the content of the latest trusted credential to the trusted environment of the device for calculation to obtain the trusted credential digest value 2;
[0035] Compare and analyze the trusted credential digest value 1 and the trusted credential digest value 2. If they are consistent, the trusted signature passes the verification; if they are inconsistent, the trusted signature fails the verification.
[0036] In this solution, the steps for verifying the elements in the latest trusted credential specifically include:
[0037] Extract the elements in the latest trusted credential;
[0038] Extract the trusted credential corresponding to the current firmware, set it as the existing trusted credential, and extract the elements in the existing trusted credential;
[0039] Compare and analyze the elements in the latest trusted credential and the elements in the existing trusted credential. If the elements in the latest trusted credential are not lower than the elements in the existing trusted credential, the element verification is passed; if there is one or more elements in the latest trusted credential that are lower than the elements in the existing trusted credential, the element verification fails.
[0040] In this solution, when updating the firmware based on the firmware package, it also includes:
[0041] When updating the firmware with the latest trusted credential, the software version number of the firmware to be updated can be less than the software version number of the current firmware of the device;
[0042] When updating the firmware without carrying the latest trusted credential, the software version number of the firmware to be updated cannot be less than the software version number of the current firmware of the device.
[0043] In this solution, the steps for verifying the version number of the restarted firmware specifically include:
[0044] Extract the version number of the restart firmware and the preset firmware version number stored in the device trusted environment;
[0045] If the version numbers of the restart firmware are all greater than or equal to the preset firmware version number stored in the device trusted environment, the restart verification is passed;
[0046] The version number includes a security version number and a software version number.
[0047] The second aspect of the present invention provides a firmware rollback protection system based on trusted credentials, including a trusted memory and a processor. The trusted memory stores a program of a firmware rollback protection method according to any one of the above.
[0048] The present invention provides a firmware rollback protection method and system. The present invention constructs a trust chain between the cloud trusted update server and the device trusted environment, and transmits the trust relationship through trusted credentials, realizing the device firmware rollback protection ability; compared with the prior art, under the premise of ensuring security, the present invention can flexibly perform device firmware version update and rollback configuration through the dual-version number authentication mechanism of trusted credentials; relying on the update strategy of the trusted credentials of the present invention, even if the firmware package pushed within a limited range leaks, devices outside the push range cannot flash the leaked firmware package, greatly enhancing the controllability and security of device firmware update; in addition, each issued viable credential is recorded in the cloud viable update server, providing a complete post-audit ability. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 Shows a flowchart of a firmware rollback protection method according to the present invention;
[0050] Figure 2 Shows a schematic diagram of the rollback protection verification process of the present invention;
[0051] Figure 3 Shows an example diagram of the trusted credentials of the present invention;
[0052] Figure 4 Shows a firmware rollback protection framework diagram of the present invention;
[0053] Figure 5 Shows a block diagram of a firmware rollback protection system based on trusted credentials according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] In order to more clearly understand the above objects, features and advantages of the present invention, the present invention will be further described in detail below with reference to the drawings and specific embodiments. It should be noted that, without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.
[0055] In the following description, many specific details are set forth in order to provide a thorough understanding of the present invention. However, the present invention may be implemented in other ways different from those described herein. Therefore, the scope of protection of the present invention is not limited by the specific embodiments disclosed below.
[0056] Figure 1 The flowchart of a firmware rollback protection method based on trusted credentials according to the present invention is shown.
[0057] As Figure 1 shown, the present invention discloses a firmware rollback protection method based on trusted credentials, including:
[0058] S101, extracting a set of trusted credentials based on a preset time period;
[0059] S102, comparing and analyzing the trusted credentials in the set of trusted credentials to obtain the latest trusted credential;
[0060] S103, extracting the required firmware package based on the latest trusted credential;
[0061] S104, verifying the latest trusted credential based on a preset verification trusted credential rule. If the latest trusted credential verification passes, firmware update is allowed; if the latest trusted credential verification fails, firmware update is not allowed;
[0062] S105, updating the firmware based on the firmware package to obtain an updated firmware, and restarting the updated firmware;
[0063] S106, verifying the version number of the restarted firmware based on a rollback protection verification rule. If the restart verification passes, the firmware is successfully started after the update, and the firmware update is successful; if the restart verification fails, the firmware update fails.
[0064] According to an embodiment of the present invention, the firmware update service periodically checks for firmware updates, requests firmware updates with the latest trusted credentials, determines the firmware to be updated. If there is no firmware to be updated, the periodic check of the current firmware update ends; if there is firmware to be updated, the firmware package and the corresponding latest trusted credential are sent, and the latest trusted credential is verified. If the latest trusted credential verification passes, the firmware is updated based on the sent firmware package to obtain an updated firmware. When the updated firmware is restarted, if the restart verification passes, the device update is successful; if the restart verification fails, the device update fails.
[0065] According to an embodiment of the present invention, the step of comparing and analyzing the trusted credentials in the set of trusted credentials to obtain the latest trusted credential specifically includes:
[0066] extracting the timestamp in the trusted credential and extracting the current time;
[0067] Sort the timestamps in the trusted credentials in chronological order to obtain the trusted credential with the largest timestamp.
[0068] When the largest timestamp is less than or equal to the current time, set the trusted credential with the largest timestamp as the latest trusted credential.
[0069] When the largest timestamp is greater than the current time, delete the trusted credential with the largest timestamp and re - sort the trusted credentials in the trusted credential set.
[0070] It should be noted that the timestamp in the trusted credential is the total number of seconds from 00:00:00 on January 1, 1970, Greenwich Mean Time to the time when the trusted credential is issued, and the current time is the total number of seconds from 00:00:00 on January 1, 1970, Greenwich Mean Time to the current time. When the largest timestamp is greater than the current time, it indicates that there is an error in the issuance time of the corresponding trusted credential. Therefore, delete the corresponding trusted credential.
[0071] According to the embodiment of the present invention, after obtaining the latest trusted credential, it further includes:
[0072] Extract the validity period and timestamp from the latest trusted credential;
[0073] Extract the current timestamp;
[0074] Subtract the timestamp in the latest trusted credential from the current timestamp to obtain a time difference;
[0075] If the time difference is less than or equal to the validity period in the latest trusted credential, the current latest trusted credential is valid;
[0076] If the time difference is greater than the validity period in the latest trusted credential, the current latest trusted credential is invalid.
[0077] It should be noted that the validity period is calculated from the issued timestamp and indicates how long the trusted credential is valid, with the unit being seconds.
[0078] According to the embodiment of the present invention, it further includes:
[0079] Extract the product serial number set and device serial number set from the latest trusted credential;
[0080] Extract the product serial number and device serial number of the device;
[0081] Match the product serial number of the device and the product serial numbers in the product serial number set in the latest trusted credential one by one. If they are all different, the trusted credential is invalid for this device;
[0082] Match the device serial number of the device with the device serial numbers in the latest trusted credential one by one. If they are all different, the trusted credential is invalid for this device.
[0083] It should be noted that the trusted credential contains one or more product serial numbers and one or more device serial numbers. The trusted credential is only valid for the marked products and the marked devices. When the product serial number and the device serial number of the device are both in the trusted credential, the firmware update on the corresponding device can be supported by this trusted credential.
[0084] According to an embodiment of the present invention, the step of verifying the latest trusted credential specifically includes:
[0085] Extract the trusted signature from the latest trusted credential;
[0086] Based on a preset trusted signature verification rule, verify the trusted signature. If the trusted signature verification is passed, extract the elements from the latest trusted credential; if the trusted signature verification fails, the verification of the latest trusted credential fails.
[0087] Based on a preset element verification rule, verify the elements in the latest trusted credential. If the element verification is passed, the verification of the latest trusted credential passes; if the element verification fails, the verification of the latest trusted credential fails.
[0088] It should be noted that the step of verifying the latest trusted credential includes the verification of the trusted signature and the verification of the elements. Only when both the trusted signature verification and the element verification are passed, the corresponding latest trusted credential passes the verification.
[0089] According to an embodiment of the present invention, the step of verifying the trusted signature specifically includes:
[0090] Obtain the public key in the device trusted environment;
[0091] Decrypt the trusted signature according to the public key in the device trusted environment to obtain the trusted credential digest value 1;
[0092] Extract the content of the latest trusted credential;
[0093] Send the content of the latest trusted credential to the device trusted environment for calculation to obtain the trusted credential digest value 2;
[0094] Compare and analyze the trusted credential digest value 1 and the trusted credential digest value 2. If they are the same, the trusted signature passes the verification; if they are different, the trusted signature fails the verification.
[0095] It should be noted that the public key and the private key are generated by the RSA algorithm. The public key is stored in the trusted environment of the device and can be made public; the private key is stored in the trusted update server and set as a confidential file, which cannot be made public. The trusted update server signs the trusted credential with the private key to obtain a trusted signature, and then sends the trusted signature to the trusted environment of the device. The trusted signature is decrypted by the public key stored in the trusted environment of the device to obtain the trusted credential digest value 1. The trusted credential digest value 2 is calculated through the content of the latest trusted credential. The trusted credential digest value 1 and the trusted credential digest value 2 are compared. If they are consistent, the signature verification passes.
[0096] According to the embodiment of the present invention, the step of verifying the elements in the latest trusted credential specifically includes:
[0097] Extract the elements in the latest trusted credential;
[0098] Extract the trusted credential corresponding to the current firmware, set it as the current trusted credential, and extract the elements in the current trusted credential;
[0099] Compare and analyze the elements in the latest trusted credential and the elements in the current trusted credential. If the elements in the latest trusted credential are not lower than the elements in the current trusted credential, the element verification passes; if there is one or more elements in the latest trusted credential that are lower than the elements in the current trusted credential, the element verification fails.
[0100] It should be noted that the elements in the latest trusted credential include the new credential version, the new timestamp, and the new firmware security version number, and the elements in the current trusted credential include the current credential version, the current timestamp, and the current firmware security version number. Among them, when the new credential version is greater than or equal to the current credential version, the new timestamp is greater than or equal to the current timestamp, and the new firmware security version number is greater than or equal to the current firmware security version number occur simultaneously, the corresponding element verification passes.
[0101] According to the embodiment of the present invention, when updating the firmware based on the firmware package, it further includes:
[0102] When updating the firmware with the latest trusted credential, the software version number of the firmware to be updated can be less than the software version number of the current firmware of the device;
[0103] When updating the firmware without carrying the latest trusted credential, the software version number of the firmware to be updated cannot be less than the software version number of the current firmware of the device.
[0104] It should be noted that by carrying the latest trusted credential, the software version number of the firmware to be updated can be rolled back and updated; the security version number of the firmware to be updated cannot be less than the security version number of the current device firmware. Static rollback and update are prohibited. When the security version number of the starting firmware is less than the security version number stored in the trusted environment, the device will not be able to start.
[0105] Figure 2 The figure shows a schematic diagram of the rollback protection verification process of the present invention;
[0106] As Figure 2 shown, according to an embodiment of the present invention, the step of verifying the version number of the restart firmware specifically includes:
[0107] Extract the version number of the restart firmware and the preset firmware version number stored in the device trusted environment;
[0108] If the version numbers of the restart firmware are all greater than or equal to the preset firmware version number stored in the device trusted environment, the restart verification is passed;
[0109] The version number includes a security version number and a software version number.
[0110] It should be noted that after the firmware update is completed, during the startup process, the firmware verification service compares the version number of the firmware to be started with the preset firmware version number stored in the device trusted environment. Only when the comparison passes according to the rules can the system start normally. The firmware to be started is the updated firmware.
[0111] Figure 3 The figure shows an example diagram of the trusted credential of the present invention.
[0112] As Figure 3 shown, the trusted credential contains a credential version, a credential serial number, a timestamp, a validity period, a flag bit, an authorized product, a product serial number, etc. For example, the credential version is the version information of the trusted credential, and the content of different credential versions may be different; the credential serial number is the serial number of the trusted credential, generated by the trusted update server for post-event audit retrieval; the flag bit can identify various capabilities, such as the effective range and the number of valid times, etc.; one firmware corresponds to one security version number and one software version number.
[0113] Figure 4 The figure shows the firmware rollback protection framework diagram of the present invention.
[0114] As Figure 4 shown, the firmware rollback protection framework diagram of the present invention is composed of a trusted update server, a device general operating system, and a device trusted environment. The trusted update server includes a trusted credential issuing center and a firmware release center. The trusted credential issuing center issues trusted credentials, and the firmware release center publishes information such as firmware update notifications. The device general operating system mainly includes a firmware update service, a firmware verification service, device restart, and a startup verification service; the device trusted environment includes a trusted credential management service and a secure storage service.
[0115] Figure 5 The figure shows a block diagram of a firmware rollback protection system based on trusted credentials of the present invention.
[0116] As shown Figure 5 in FIG. 5, a firmware rollback protection system 5 based on trusted credentials according to a second aspect of the present invention includes a trusted memory 51 and a processor 52, and a program of a firmware rollback protection method based on trusted credentials as described in any one of the above is stored in the trusted memory.
[0117] The present invention provides a firmware rollback protection method and system based on trusted credentials. The present invention constructs a trust chain between a cloud trusted update server and a device trusted environment, and transmits trust relationships through trusted credentials, thereby realizing the ability of device firmware rollback protection; compared with the prior art, the present invention can flexibly perform device firmware version update and rollback configuration through a dual version number authentication mechanism of trusted credentials while ensuring security; relying on the update strategy of trusted credentials of the present invention, even if the leaked firmware package is pushed within a limited range, devices not within the push range cannot flash the leaked firmware package, greatly enhancing the controllability and security of device firmware update; in addition, each issued viable credential is recorded in the cloud viable update server, providing a complete post-audit ability.
[0118] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed with each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical, or other forms.
[0119] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units; they can be located in one place or distributed to multiple network units; some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0120] In addition, each functional unit in the embodiments of the present invention can be all integrated in a processing unit, or each unit can be separately used as a unit, or two or more units can be integrated in a unit; the above integrated unit can be implemented in the form of hardware, or in the form of a hardware plus software functional unit.
[0121] Those of ordinary skill in the art will understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including those of the above method embodiments. The aforementioned storage medium includes various media that can store program codes, such as removable storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0122] Alternatively, if the above integrated units of the present invention are implemented in the form of software function modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solutions of the embodiments of the present invention, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media that can store program codes, such as removable storage devices, ROM, RAM, magnetic disks, or optical discs.
Claims
1. A firmware rollback protection method based on trusted credentials, characterized in that, Including: Extract a set of trusted credentials based on a preset time period; Conduct a comparative analysis of the trusted credentials in the set of trusted credentials to obtain the latest trusted credentials; Extract the required firmware package based on the latest trusted credentials; Based on a preset rule for verifying trusted credentials, verify the latest trusted credentials. If the latest trusted credentials pass the verification, allow firmware update; If the latest trusted credentials do not pass the verification, do not allow firmware update; Update the firmware based on the firmware package to obtain the updated firmware and restart the updated firmware; Based on a rollback protection verification rule, verify the version number of the restarted firmware. If the restart verification is passed, the updated firmware starts normally and the firmware update is successful; If the restart verification is not passed, the firmware update fails; The step of conducting a comparative analysis of the trusted credentials in the set of trusted credentials to obtain the latest trusted credentials specifically includes: Extract the timestamps in the trusted credentials and extract the current time; Sort the timestamps in the trusted credentials in chronological order to obtain the trusted credentials with the maximum timestamp; When the maximum timestamp is less than or equal to the current time, set the trusted credentials with the maximum timestamp as the latest trusted credentials; When the maximum timestamp is greater than the current time, delete the trusted credentials with the maximum timestamp and re-sort the trusted credentials in the set of trusted credentials; The step of verifying the latest trusted credentials specifically includes: Extract the trusted signature in the latest trusted credentials; Based on a preset trusted signature verification rule, verify the trusted signature. If the trusted signature passes the verification, extract the elements in the latest trusted credentials; if the trusted signature does not pass the verification, the verification of the latest trusted credentials fails; Based on a preset element verification rule, verify the elements in the latest trusted credentials. If the element verification is passed, the verification of the latest trusted credentials is passed; if the element verification is not passed, the verification of the latest trusted credentials fails; The step of verifying the trusted signature specifically includes: Obtain the public key in the trusted environment of the device; Decrypt the trusted signature according to the public key in the trusted environment of the device to obtain the trusted credential digest value 1; Extract the content of the latest trusted credentials; Send the content of the latest trusted credentials to the trusted environment of the device for calculation to obtain the trusted credential digest value 2; Conduct a comparative analysis of the trusted credential digest value 1 and the trusted credential digest value 2. If they are consistent, the trusted signature passes the verification; if they are inconsistent, the trusted signature does not pass the verification; The step of verifying the elements in the latest trusted credentials specifically includes: Extract the elements in the latest trusted credentials; Extract the trusted credentials corresponding to the current firmware and set them as the current trusted credentials, and extract the elements in the current trusted credentials; Conduct a comparative analysis of the elements in the latest trusted credentials and the elements in the current trusted credentials. If the elements in the latest trusted credentials are not lower than the elements in the current trusted credentials, the element verification is passed; if there is one or more elements in the latest trusted credentials that are lower than the elements in the current trusted credentials, the element verification fails.
2. The firmware rollback protection method based on trusted credentials according to claim 1, wherein After obtaining the latest trusted credentials, it further includes: Extract the validity period and timestamp in the latest trusted credentials; Extract the current timestamp; Subtract the timestamp in the latest trusted credentials from the current timestamp to obtain the time difference; If the time difference is less than or equal to the validity period in the latest trusted credential, the current latest trusted credential is valid; If the time difference is greater than the validity period in the latest trusted credential, the current latest trusted credential is invalid.
3. The method for firmware rollback protection based on trusted credentials according to claim 1, wherein, It further includes: Extract the product serial number set and device serial number set in the latest trusted credential; Extract the product serial number and device serial number of the device; Match the product serial number of the device and the product serial numbers in the product serial number set in the latest trusted credential one by one. If they are all different, the trusted credential is invalid for this device; Match the device serial number of the device and the device serial numbers in the device serial number set in the latest trusted credential one by one. If they are all different, the trusted credential is invalid for this device.
4. A firmware rollback protection method based on a trusted credential according to claim 1, characterized in that, When updating the firmware based on the firmware package, it further includes: When updating the firmware with the latest trusted credential, the software version number of the firmware to be updated can be less than the software version number of the current firmware of the device; When updating the firmware without the latest trusted credential, the software version number of the firmware to be updated cannot be less than the software version number of the current firmware of the device.
5. The method for protecting firmware rollback based on trusted credentials according to claim 1, characterized in that The step of verifying the version number of the restart firmware specifically includes: Extract the version number of the restart firmware and the preset firmware version number stored in the trusted environment of the device; If the version number of the restart firmware is greater than or equal to the preset firmware version number stored in the trusted environment of the device, the restart verification is passed; The version number includes a security version number and a software version number.
6. A firmware rollback protection system based on trusted credentials, characterized in that, It includes a trusted memory and a processor, and the trusted memory stores a program of a firmware rollback protection method based on a trusted credential as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Method and equipment for preventing hardware update from failing
CN103455354A
System and method for updating firmware in wireless charger
CN110489137A
Secure starting method and system based on RISC-V
CN113486360A