A firmware extraction method based on electromagnetic injection
Through the firmware extraction method based on electromagnetic injection, the problems of inefficient and risky traditional firmware extraction are solved, and safe and efficient firmware data extraction and analysis are achieved.
Patent Information
- Application Number
- CN202411800072.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-12-09
AI Technical Summary
The traditional firmware extraction process relies on manual disassembly or access to special interfaces, resulting in inefficient extraction and risks of device damage, damage, and tampering.
Using a firmware extraction method based on electromagnetic injection, an extraction channel is established with the device to be extracted through detection operations, an electromagnetic injection operation is performed to obtain feedback information, and the feedback information is analyzed and processed to extract firmware data.
It avoids the risk of traditional physical evidence forensics, improves extraction efficiency, and can reflect the electromagnetic field characteristics of the target device during operation, supporting subsequent firmware analysis and vulnerability assessment.
Smart Images

Figure CN119718418B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the technical field of software testing, and in particular, relates to a firmware extraction method based on electromagnetic injection. Background Art
[0002] For smart hardware products, their intelligence is generally achieved through one or more programmable controllers. The code in the programmable controller is called firmware, which can control various hardware functions of the device, including startup, operation, data processing, etc. Compared with the operating system, firmware is usually more lightweight and occupies less space. It is mainly responsible for low-level control and management of hardware. Therefore, for some devices with limited resources and limited power consumption, it is more suitable to use firmware. For example, firmware can be embedded in various digital devices, such as mobile phones, routers, smart home devices, etc. The firmware used by different devices is different. The only common point is that they all need to be written, compiled, and burned into the device, and play a role when the device is running. Therefore, by extracting the firmware, it is possible to copy and clone the smart hardware, or reversely analyze whether it has backdoor vulnerabilities, protocol vulnerabilities, or even whether it has plaintext information such as keys, and then control or crack the entire system. Therefore, firmware extraction is the primary link in exploiting firmware vulnerabilities or cracking products or systems.
[0003] The traditional firmware provision process often requires manual disassembly of the device or access to a special interface (for example, when accessing a special interface, there is a risk that accidental operation or incorrect connection may cause damage to the device), which leads to low extraction efficiency. Summary of the invention
[0004] The embodiment of the present application provides a firmware extraction method based on electromagnetic injection, which can solve the problem that in the traditional firmware provision process, it is often necessary to rely on manual disassembly of the device or access to a special interface, which leads to low extraction efficiency.
[0005] In a first aspect, an embodiment of the present application provides a firmware extraction method based on electromagnetic injection, comprising:
[0006] Detecting a first operation; wherein the first operation is used to establish an extraction channel with a first device to be extracted; the first device to be extracted is a device from which a user actively initiates firmware extraction;
[0007] The firmware extraction device performs a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information; wherein the first firmware extraction operation is an operation of electromagnetic injection by the firmware extraction device to the first device to be extracted, and the feedback information is used to reflect the information of the timing characteristics of the firmware reading process in the first device to be extracted by the firmware extraction device;
[0008] The feedback information is analyzed and processed to extract the firmware data of the first device to be extracted; wherein the firmware data is used to reflect the code data or configuration data of the firmware in the first device to be extracted.
[0009] The above technical solutions in the embodiments of the present application have at least the following technical effects:
[0010] The firmware extraction method based on electromagnetic injection provided in the present application, first, detects the first operation for establishing an extraction channel with the first device to be extracted, and can establish an extraction channel with the first device to be extracted, thereby avoiding the risks of device destruction, damage, tampering, etc. caused by traditional physical forensics, which helps to improve the extraction efficiency. Then, the firmware extraction device performs the first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information, which can reflect the electromagnetic field characteristics of the target device to be extracted during actual operation. For example, this information may include the electromagnetic radiation pattern generated by the device in different operating modes, which helps to understand the operating status of the firmware in the device in the subsequent operation to ensure the extraction efficiency. For example, the feedback information obtained can provide data support for subsequent firmware analysis, such as identifying specific functional modules, algorithms or security vulnerabilities in the firmware by analyzing the feedback information, thereby helping security researchers to conduct in-depth firmware analysis and vulnerability assessment. Finally, by analyzing and processing the feedback information, the firmware data of the first device to be extracted can be extracted, which can avoid the defects and disadvantages of the traditional physical forensics method and help improve the extraction efficiency.
[0011] In a possible implementation manner of the first aspect, after detecting the first operation, the method further includes:
[0012] Determining whether a second firmware extraction activity is currently being performed with a second device to be extracted; wherein the second device to be extracted is a device for which firmware extraction is prearranged;
[0013] In the case of determining that the second firmware extraction activity is being performed with the second device to be extracted, determining whether the first device to be extracted is in an electromagnetic injection adaptation mode;
[0014] When the first device to be extracted is in the electromagnetic injection adaptation mode, in response to a first operation, a first firmware extraction operation is performed on the first device to be extracted based on the extraction channel, and a second firmware extraction activity with the second device to be extracted is suspended.
[0015] In a possible implementation manner of the first aspect, the method further includes:
[0016] Acquire software configuration information and a state to be extracted of the first device to be extracted; wherein the software configuration information is used to reflect whether parameter information corresponding to electromagnetic injection is configured in the first device to be extracted, and the state to be extracted is used to reflect whether the first device to be extracted is in an executable firmware extraction state;
[0017] When the software configuration information of the first device to be extracted reflects that parameter information corresponding to electromagnetic injection has been configured, and the state to be extracted reflects that the first device to be extracted is in an executable firmware extraction state, determining that the first device to be extracted is in the electromagnetic injection adaptation mode;
[0018] When the software configuration information of the first device to be extracted reflects that parameter information corresponding to electromagnetic injection is not configured and / or the state to be extracted reflects that the first device to be extracted is not in an executable firmware extraction state, it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode.
[0019] In a possible implementation manner of the first aspect, after determining whether the first device to be extracted is in an electromagnetic injection adaptation mode when it is determined that the second firmware extraction activity is performed with the second device to be extracted, the method further includes:
[0020] When it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode, the second firmware extraction activity between the second device to be extracted is maintained, and a first interface is displayed on the display device of the firmware extraction device; wherein the first interface is used to remind the user that the first device to be extracted is not in the electromagnetic injection adaptation mode.
[0021] In a possible implementation manner of the first aspect, the method further includes:
[0022] When it is determined that the current firmware version of the first device to be extracted does not need to be extracted, a user is prompted on a display device of the firmware extraction device that the current firmware version of the first device to be extracted is the latest version.
[0023] In a possible implementation manner of the first aspect, the method further includes:
[0024] During the process of extracting the firmware data, the operating status of the first device to be extracted is monitored, and the extraction operation is terminated when an abnormality is detected.
[0025] In a possible implementation manner of the first aspect, before the firmware extraction device performs a first firmware extraction operation on the first to-be-extracted device based on the extraction channel to obtain feedback information, the method further includes:
[0026] Acquire electromagnetic injection indication data of the first device to be extracted; wherein the electromagnetic injection indication data includes characteristic data of the first device to be extracted;
[0027] According to the characteristic data of the first device to be extracted, determining whether there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted;
[0028] When it is determined that there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted, the firmware extraction device maintains the transmission service of feedback information between the firmware extraction device and the first device to be extracted;
[0029] When it is determined that there is no electromagnetic injection activity between the firmware extraction device and the first device to be extracted, the firmware extraction device does not perform a transmission service of feedback information with the first device to be extracted based on the electromagnetic injection indication data.
[0030] In a possible implementation manner of the first aspect, when it is determined that there is no electromagnetic injection activity between the firmware extraction device and the first device to be extracted, after the firmware extraction device does not perform a transmission service of feedback information between the firmware extraction device and the first device to be extracted based on the electromagnetic injection indication data, the method further includes:
[0031] In response to a second operation, the firmware extraction device creates a task of establishing an extraction channel with the first device to be extracted; wherein the type of the extraction channel established by the second operation is different from that established by the first operation;
[0032] Based on the task of creating an extraction channel with the first device to be extracted, a first firmware extraction operation is performed on the first device to be extracted to obtain feedback information.
[0033] In a possible implementation manner of the first aspect, analyzing and processing the feedback information to extract the firmware data of the first device to be extracted includes:
[0034] Performing time domain analysis on the feedback information to obtain time domain characteristic parameters of the electromagnetic signal;
[0035] Performing frequency domain analysis on the feedback information to obtain frequency domain characteristic parameters of the electromagnetic signal;
[0036] The time domain characteristic parameters and the frequency domain characteristic parameters are compared and analyzed with a pre-established firmware feature library, and firmware data that is most similar to the time domain characteristic parameters and the frequency domain characteristic parameters is extracted from the firmware feature library as the firmware data of the first device to be extracted.
[0037] In a possible implementation manner of the first aspect, after analyzing and processing the feedback information to extract the firmware data of the first device to be extracted, the method further includes:
[0038] Creating a firmware backup file, and saving the extracted firmware data into the firmware backup file;
[0039] The firmware backup file is uploaded to a cloud storage server.
[0040] In a possible implementation manner of the first aspect, the method further includes:
[0041] A second interface is displayed on the display device of the firmware extraction device; wherein the second interface is used to prompt that the firmware data has been successfully extracted and stored in the cloud storage server.
[0042] In a second aspect, an embodiment of the present application provides a firmware extraction system based on electromagnetic injection, including:
[0043] A detection unit, configured to detect a first operation; wherein the first operation is used to establish an extraction channel with a first device to be extracted; the first device to be extracted is a device from which a user actively initiates firmware extraction;
[0044] an execution unit, configured for the firmware extraction device to perform a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information; wherein the feedback information is used to reflect the electromagnetic field characteristics of the firmware in the first device to be extracted;
[0045] The extraction unit is used to analyze and process the feedback information to extract the firmware data of the first device to be extracted; wherein the firmware data is used to reflect the code data or configuration data of the firmware in the first device to be extracted.
[0046] In a third aspect, an embodiment of the present application provides a firmware extraction device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the electromagnetic injection-based firmware extraction method described in any one of the first aspects above is implemented.
[0047] It can be understood that the beneficial effects of the second to third aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0049] Figure 1 It is a flowchart of a firmware extraction method based on electromagnetic injection provided by an embodiment of the present application;
[0050] Figure 2 It is a schematic diagram of the implementation process after step S100 in the firmware extraction method based on electromagnetic injection provided in one embodiment of the present application;
[0051] Figure 3 is a flowchart of a firmware extraction method based on electromagnetic injection provided by another embodiment of the present application;
[0052] Figure 4 It is a schematic diagram of the implementation flow before step S200 in the firmware extraction method based on electromagnetic injection provided in one embodiment of the present application;
[0053] Figure 5 It is a schematic diagram of the implementation process after step S240 in the firmware extraction method based on electromagnetic injection provided in one embodiment of the present application;
[0054] Figure 6 It is a schematic diagram of the implementation process of step S300 in the firmware extraction method based on electromagnetic injection provided in an embodiment of the present application;
[0055] Figure 7 It is a schematic diagram of the implementation flow after step S300 in the firmware extraction method based on electromagnetic injection provided in another embodiment of the present application;
[0056] Figure 8 It is a structural diagram of a firmware extraction system based on electromagnetic injection provided in an embodiment of the present application;
[0057] Fig. 9 It is a structural diagram of a firmware extraction device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0058] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0059] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0060] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0061] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting" depending on the context. Similarly, the phrase "if it is determined" or "if the described condition or event is detected" can be interpreted as meaning "uponce determined" or "in response to determining" or "uponce the described condition or event is detected" or "in response to detecting the described condition or event" depending on the context.
[0062] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0063] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0064] In the relevant technology, firmware refers to programmable software code embedded in a device, which can control various hardware functions of the device, including startup, operation, data processing, etc. Compared with the operating system, firmware is usually more lightweight and occupies less space. It is mainly responsible for low-level control and management of hardware. Therefore, for some devices with limited resources and limited power consumption, it is more suitable to use firmware. For example, firmware can be embedded in various digital devices, such as mobile phones, routers, smart home devices, etc. Different devices use different firmware. The only thing in common is that they all need to be written, compiled, and burned into the device, and play a role when the device is running.
[0065] The traditional firmware provision process often requires manual disassembly of the device or access to a special interface (for example, when accessing a special interface, there is a risk that accidental operation or incorrect connection may cause damage to the device), which leads to low extraction efficiency.
[0066] For example, in order to solve the problem that the traditional use of FIB invasive technology to extract the locked bit protection firmware of smart hardware requires destroying the chip and is costly, a method of losslessly extracting the locked bit protection firmware can be used by precise injection of nanosecond electromagnetic pulses, and a high-precision electromagnetic injection device can be built for the chip debugging interface. Breakthroughs can be made in the technology of accurately identifying and bypassing the firmware protection mechanism, greatly reducing the dependence of the extraction of locked bit protection firmware on high-cost invasive equipment, and lossless extraction can effectively reduce the dependence on the number of chips analyzed, thereby improving the extraction efficiency.
[0067] To solve the above problems, an embodiment of the present application provides a firmware extraction method based on electromagnetic injection.
[0068] In the method, first, a first operation for establishing an extraction channel with a first device to be extracted is detected, and an extraction channel can be established with the first device to be extracted, thereby avoiding the risks of device destruction, damage, tampering, etc. caused by traditional physical forensics, which helps to improve the extraction efficiency. Then, the firmware extraction device performs a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information, which can reflect the electromagnetic field characteristics of the target device to be extracted during actual operation. For example, this information may include the electromagnetic radiation pattern generated by the device in different operating modes, which helps to understand the operating status of the firmware in the device in the subsequent operation to ensure the extraction efficiency. For example, the obtained feedback information can provide data support for subsequent firmware analysis, such as identifying specific functional modules, algorithms or security vulnerabilities in the firmware by analyzing the feedback information, thereby helping security researchers to conduct in-depth firmware analysis and vulnerability assessment. Finally, the feedback information is analyzed and processed to extract the firmware data of the first device to be extracted, which can avoid the defects and disadvantages of traditional physical forensics methods and help improve the extraction efficiency.
[0069] The firmware extraction method based on electromagnetic injection provided in the embodiment of the present application can be applied to a firmware extraction device. In this case, the firmware extraction device is the execution subject of the firmware extraction method based on electromagnetic injection provided in the embodiment of the present application. The embodiment of the present application does not impose any restrictions on the specific type of the firmware extraction device.
[0070] For example, the firmware extraction device may include an electromagnetic probe, a signal generator, a data acquisition device, and an analysis algorithm installed in the firmware extraction device. The electromagnetic probe is used to generate and inject electromagnetic signals to stimulate the firmware in the device to be extracted. The signal generator can generate electromagnetic signals of the required frequency and intensity, which are then used to drive the electromagnetic probe. The data acquisition device is responsible for receiving, processing and recording the captured electromagnetic signals, converting the electromagnetic signals into digital data and transmitting them to the analysis algorithm. The analysis algorithm can process and analyze the digital signals to extract the required firmware data, such as code data or configuration data.
[0071] In order to better understand the firmware extraction method based on electromagnetic injection provided in the embodiment of the present application, the specific implementation process of the firmware extraction method based on electromagnetic injection provided in the embodiment of the present application is exemplarily introduced below.
[0072] Figure 1 A schematic flow chart of a firmware extraction method based on electromagnetic injection provided in an embodiment of the present application is shown. The firmware extraction method based on electromagnetic injection includes:
[0073] S100, detecting a first operation. The first operation is used to establish an extraction channel with a first device to be extracted. The first device to be extracted is a device from which a user actively initiates firmware extraction.
[0074] It can be understood that the electromagnetic signal generated and injected by the electromagnetic probe can be used to achieve communication with the first device to be extracted, that is, to establish an extraction channel with the first device to be extracted. A detector is set up to detect the first operation (such as clicking, touching or text input, etc.). The firmware extraction device can also display to the user that the first device to be extracted is detected, and request the user to confirm whether the firmware extraction operation needs to be performed on the first device to be extracted. This step ensures that the user actively initiates the firmware extraction of the first device to be extracted, and the user can confirm and authorize the extraction operation through an interactive interface (such as a button, a touch screen).
[0075] With such a configuration, by detecting the first operation, an extraction channel can be established with the first device to be extracted, thereby avoiding the risks of device destruction, damage, tampering, etc. caused by traditional physical evidence collection, and helping to improve extraction efficiency.
[0076] In one possible implementation, see Figure 2 In step S100, after detecting the first operation, the firmware extraction method based on electromagnetic injection further includes:
[0077] S110, determining whether a second firmware extraction activity is currently being performed with a second device to be extracted, wherein the second device to be extracted is a device for which firmware extraction is prearranged.
[0078] It can be understood that the timing of the second device to be extracted, which is pre-arranged for firmware extraction, can be obtained to determine whether the timing of the second device to be extracted is consistent with the current timing. If they are consistent, it is determined that the second firmware extraction activity is currently being performed with the second device to be extracted, such as the timing of the second device to be extracted is 8:00 to perform the second firmware extraction activity, and the current timing is 8:00; otherwise, it is determined that the second firmware extraction activity is not currently being performed with the second device to be extracted. It is also possible to check the task status or queue to confirm whether there are currently any tasks associated with the second device to be extracted in progress or queued for execution. It is also possible to check the description in the task list to confirm whether the information or identifier of the second device to be extracted is currently mentioned.
[0079] With such a configuration, it is determined whether the second firmware extraction activity is currently being performed with the second device to be extracted, and when the user actively adds or inserts the extraction task, it can avoid the extraction conflict with the second device to be extracted that is pre-arranged for firmware extraction, which helps to improve the extraction efficiency. It is also possible to identify and verify the device identity and the match with the pre-arranged firmware extraction device, which can avoid unauthorized devices or malicious attackers from performing firmware extraction, and ensure that the firmware extraction activity is carried out smoothly, reliably and safely, which helps to improve the extraction efficiency.
[0080] S120: When it is determined that the second firmware extraction activity is being performed with the second device to be extracted, determine whether the first device to be extracted is in an electromagnetic injection adaptation mode.
[0081] For example, the first device to be extracted will send out a 2.45GHz signal after entering the adaptation mode, or the first device to be extracted will send a data packet in a specific format in the adaptation mode, and its header information contains a special identifier, such as 0xABCD. The first device to be extracted will send out signals of other frequency bands, such as 900MHz, when it does not enter the adaptation mode, or the data packet header information sent by the first device to be extracted when it does not enter the adaptation mode is 0x1234, instead of 0xABCD in the electromagnetic injection adaptation mode, to indicate that the first device to be extracted is not in the electromagnetic injection adaptation mode.
[0082] It can be understood that, in the case of determining that the second firmware extraction activity is being performed with the second device to be extracted, it is possible to first determine whether the first device to be extracted on which the user actively initiates firmware extraction is in the electromagnetic injection adaptation mode, so as to analyze whether it is necessary to first perform the first firmware extraction activity on the first device to be extracted on which the user actively initiates firmware extraction. If the first device to be extracted is not in the electromagnetic injection adaptation mode, then it is meaningless to first perform the first firmware extraction activity on the first device to be extracted on which the user actively initiates firmware extraction, because when it is not in the electromagnetic injection adaptation mode, the firmware extraction activity may not be performed correctly or valid firmware data may not be obtained. Therefore, it is necessary to determine whether the first device to be extracted is in the electromagnetic injection adaptation mode.
[0083] With such a configuration, when it is determined that the second firmware extraction activity is being conducted with the second device to be extracted, determining whether the first device to be extracted is in the electromagnetic injection adaptation mode helps to ensure the effectiveness of the firmware extraction activity. If the first device to be extracted is not in the electromagnetic injection adaptation mode, it may be necessary to reconsider the strategy and steps of firmware extraction to ensure that valid firmware data can be successfully obtained, which helps to improve extraction efficiency.
[0084] S130 , when the first device to be extracted is in the electromagnetic injection adaptation mode, in response to the first operation, performing a first firmware extraction operation on the first device to be extracted based on the extraction channel, and suspending a second firmware extraction activity with the second device to be extracted.
[0085] It can be understood that, first, when it is determined that the first device to be extracted is in the electromagnetic injection adaptation mode, in response to the first operation, an extraction channel is established to ensure that the extraction channel is stable and has sufficient bandwidth and signal strength. The extraction channel can be a communication channel established between an electromagnetic injection device (such as an electromagnetic probe) and the first device to be extracted. In order to avoid interference, the second firmware extraction activity with the second device to be extracted is temporarily suspended. Then, the response data of the first device to be extracted is captured using a data acquisition device. Finally, after the first firmware extraction operation is completed, the second firmware extraction activity with the second device to be extracted is resumed.
[0086] With such a configuration, when the first device to be extracted is in the electromagnetic injection adaptation mode, in response to the first operation, the first firmware extraction operation is performed on the first device to be extracted based on the extraction channel, and the second firmware extraction activity with the second device to be extracted is suspended, thereby avoiding conflicts in resources or communications, ensuring the successful execution of the first operation, and helping to improve extraction efficiency.
[0087] In one possible implementation, see Figure 3 , the firmware extraction method based on electromagnetic injection also includes:
[0088] S111, obtaining software configuration information and a state to be extracted of the first device to be extracted, wherein the software configuration information is used to reflect whether parameter information corresponding to electromagnetic injection is configured in the first device to be extracted, and the state to be extracted is used to reflect whether the first device to be extracted is in a state where firmware extraction can be executed.
[0089] For example, the software configuration information can reflect whether the parameter information corresponding to the electromagnetic injection is configured in the first device to be extracted. Before performing the firmware extraction operation, it is necessary to check the software configuration information of the first device to be extracted to ensure that the parameters of the electromagnetic injection are coordinated with the internal device, so as to ensure the effectiveness of the firmware extraction. For example, if the corresponding electromagnetic injection parameters are not configured in the first device to be extracted, the firmware extraction operation may not be started or completed, resulting in the failure of the firmware extraction. For example, the parameter information corresponding to the electromagnetic injection can be the processor clock frequency. In the case of performing the firmware extraction operation, the processor clock frequency needs to be reduced to a specific range. This operation enables the electromagnetic injection device (such as an electromagnetic probe) to more easily break through the processor's protective layer. The parameter information corresponding to the electromagnetic injection can also be the power supply. In order to prevent problems such as current instability and power supply fluctuations during the firmware extraction operation, it is necessary to provide a more stable power supply for the device to be extracted, such as by an external battery.
[0090] For example, the state to be extracted can reflect whether the first device to be extracted is in a state where the firmware extraction can be executed. Before performing the firmware extraction operation, it is necessary to check the state to be extracted of the first device to be extracted to ensure that the first device to be extracted is already in a state where the firmware extraction can be executed. For example, if the first device to be extracted is in a dormant or abnormal operating state, the firmware extraction operation may not be started or completed, resulting in a firmware extraction failure.
[0091] It is understandable that the first device to be extracted can be communicated with wirelessly, and a query request can be sent to the first device to be extracted to obtain the software configuration information and the state to be extracted. When the first device to be extracted receives the query request, it will respond with corresponding data to send the software configuration information and the state to be extracted to the firmware extraction device.
[0092] Such a configuration helps to confirm the executability and security of the firmware extraction operation by obtaining the software configuration information and the state to be extracted of the first device to be extracted, thereby improving the extraction efficiency.
[0093] S112, when the software configuration information of the first device to be extracted reflects that parameter information corresponding to electromagnetic injection has been configured, and the state to be extracted reflects that the first device to be extracted is in an executable firmware extraction state, it is determined that the first device to be extracted is in an electromagnetic injection adaptation mode.
[0094] It can be understood that, first, it is confirmed whether the parameter information corresponding to the electromagnetic injection is configured inside the first device to be extracted, such as processor clock frequency adjustment, power supply configuration, etc. Then, it is confirmed whether the first device to be extracted is in an executable firmware extraction state, and whether it is in an executable state can be confirmed by checking the device status indicator of the first device to be extracted, or observing the running state of the device when it is started. Finally, when the software configuration information of the first device to be extracted reflects that the parameter information corresponding to the electromagnetic injection has been configured, and the state to be extracted reflects that the first device to be extracted is in an executable firmware extraction state, it is determined that the first device to be extracted is in the electromagnetic injection adaptation mode.
[0095] With such a configuration, the software configuration information of the first device to be extracted is reflected as parameter information that has been configured corresponding to the electromagnetic injection, and the state to be extracted reflects that the first device to be extracted is in an executable firmware extraction state. It is determined that the first device to be extracted is in the electromagnetic injection adaptation mode, which can ensure the effectiveness of the firmware extraction operation and avoid the acquisition of erroneous data due to firmware extraction activities when the first device to be extracted is not in the electromagnetic injection adaptation mode, thereby helping to improve the extraction efficiency.
[0096] S113, when the software configuration information of the first device to be extracted reflects that parameter information corresponding to electromagnetic injection is not configured and / or the state to be extracted reflects that the first device to be extracted is not in an executable firmware extraction state, it is determined that the first device to be extracted is not in an electromagnetic injection adaptation mode.
[0097] It can be understood that, first, it is confirmed whether the parameter information corresponding to electromagnetic injection is configured inside the first device to be extracted, such as processor clock frequency adjustment, power supply configuration, etc. Then, it is confirmed whether the first device to be extracted is in an executable firmware extraction state, and whether it is in an executable state can be confirmed by checking the device status indicator of the first device to be extracted, or observing the running state of the device when it is started. Finally, the software configuration information of the first device to be extracted reflects that the parameter information corresponding to electromagnetic injection is not configured and the state to be extracted reflects that the first device to be extracted is not in an executable firmware extraction state, and it is determined that the first device to be extracted is not in an electromagnetic injection adaptation mode; or, the software configuration information of the first device to be extracted reflects that the parameter information corresponding to electromagnetic injection is not configured and the state to be extracted reflects that the first device to be extracted is in an executable firmware extraction state, and it is determined that the first device to be extracted is not in an electromagnetic injection adaptation mode; or, the software configuration information of the first device to be extracted reflects that the parameter information corresponding to electromagnetic injection is configured and the state to be extracted reflects that the first device to be extracted is in an executable firmware extraction state, and it is determined that the first device to be extracted is not in an electromagnetic injection adaptation mode.
[0098] With such a configuration, when the software configuration information of the first device to be extracted reflects that parameter information corresponding to electromagnetic injection is not configured and / or the state to be extracted reflects that the first device to be extracted is not in an executable firmware extraction state, it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode. This ensures the validity of the firmware extraction operation, avoids the acquisition of erroneous data resulting from firmware extraction activities when the first device to be extracted is not in the electromagnetic injection adaptation mode, and helps to improve the extraction efficiency.
[0099] In a possible implementation, in step S120, after determining whether the first device to be extracted is in the electromagnetic injection adaptation mode when the second firmware extraction activity is performed with the second device to be extracted, the firmware extraction method based on electromagnetic injection further includes:
[0100] When it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode, the second firmware extraction activity with the second device to be extracted is maintained, and a first interface is displayed on the display device of the firmware extraction device, wherein the first interface is used to remind the user that the first device to be extracted is not in the electromagnetic injection adaptation mode.
[0101] It can be understood that before starting the firmware extraction activity, the electromagnetic injection adaptation mode of the first device to be extracted is first detected. When it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode, the second firmware extraction activity between the second device to be extracted is maintained. At the same time, on the display device (such as a display screen) of the firmware extraction device, a first interface is created and displayed to remind the user that the first device to be extracted is not in the electromagnetic injection adaptation mode. Easy-to-understand language and icons can be used so that the user can quickly understand, and some actionable prompts can also be provided, such as restarting the device to be extracted, adjusting parameters, or seeking help from professionals. In this way, when it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode, the firmware extraction activity of the device that pre-arranges the firmware extraction can be avoided.
[0102] With such a configuration, when it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode, the second firmware extraction activity with the second device to be extracted is maintained, and the first interface is displayed on the display device of the firmware extraction device. This can remind the user that the first device to be extracted is not ready for firmware extraction, reduce the occurrence of potential risks, and help improve extraction efficiency.
[0103] In a possible implementation, the firmware extraction method based on electromagnetic injection further includes:
[0104] When it is determined that the current firmware version of the first device to be extracted does not need to be extracted, the user is prompted on the display device of the firmware extraction device that the current firmware version of the first device to be extracted is the latest version.
[0105] It can be understood that the main purpose of firmware extraction is to obtain the currently used firmware code and configuration information from the device. This information can be used to analyze the operating status of the device and check whether there are any safety hazards or functional defects. When the current firmware version of the device is already the latest version, it means that the firmware is already the latest version released by the developer or supplier. In other words, the latest version of the firmware has been obtained and updated through other channels before, which means that the firmware data of the latest version of the firmware has been tested, verified and known. At this time, if the firmware extraction operation is performed again, the data obtained is actually the firmware data that has been obtained before. Therefore, if the firmware extraction is performed directly, the information obtained is completely consistent with the content that has been mastered before, which will waste time and resources and may also cause certain interference to the normal operation of the device.
[0106] For example, before performing the firmware extraction activity, it is first necessary to detect the current firmware version of the first device to be extracted, which can be achieved through communication between the firmware extraction device and the device to be extracted or other technical means, to determine whether the current firmware version of the first device to be extracted is already the latest version, and to compare it with the firmware management system or the online update server. If it is detected that the firmware version of the first device to be extracted is already the latest, the display device (such as a display screen) of the firmware extraction device should display a prompt message to inform the user that the current firmware version does not need to be extracted. This message should clearly indicate that the firmware is already the latest and no further operation is required.
[0107] With such a configuration, when it is determined that the current firmware version of the first device to be extracted does not need to be extracted, the user is prompted on the display device of the firmware extraction device that the current firmware version of the first device to be extracted is the latest version, which can save extraction time and resources and help improve extraction efficiency.
[0108] In a possible implementation, the firmware extraction method based on electromagnetic injection further includes:
[0109] During the process of extracting the firmware data, the operating status of the first device to be extracted is monitored, and the extraction operation is terminated when an abnormality is detected.
[0110] It is understandable that special monitoring software is used to monitor the operating status of the first device to be extracted, such as CPU usage, memory occupancy, disk read and write speed and other indicators. Set a threshold to determine whether there is an abnormality. If the indicator is higher or lower than the set threshold, it means that the first device to be extracted has an abnormality. If an abnormal operation of the device is detected, the firmware data extraction operation is immediately terminated to avoid unnecessary losses to the device. After the extraction operation is terminated, the user can be reminded to take corresponding actions, such as arranging equipment maintenance, replacing hardware, etc. If the status of the first device to be extracted is normal for a period of time, the firmware data extraction operation can be resumed.
[0111] With this arrangement, during the process of extracting firmware data, the operating status of the first device to be extracted is monitored, and the extraction operation is terminated when an abnormality is detected, which helps to ensure the stability and safety of the first device to be extracted during operation, thereby improving the extraction efficiency.
[0112] S200, the firmware extraction device performs a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information. The first firmware extraction operation is an operation in which the firmware extraction device performs electromagnetic injection on the first device to be extracted, and the feedback information is used to reflect the information of the timing characteristics of the firmware extraction device in the firmware reading process in the first device to be extracted.
[0113] It can be understood that according to the characteristics of the first device to be extracted, the parameters of the signal generator, such as frequency, amplitude and waveform, are set. The electromagnetic probe is precisely positioned at a key position of the first device to be extracted, such as near the firmware storage area or the processor. The signal generator is started, and a preset electromagnetic signal is injected into the first device to be extracted through the electromagnetic probe. The electromagnetic signal is used to stimulate the electromagnetic response of the device. The data acquisition device arranged around the first device to be extracted is activated to capture the electromagnetic response signal inside the first device to be extracted, that is, the electromagnetic field characteristics reflecting the firmware characteristics. The electromagnetic field characteristics may include frequency response, time domain waveform, amplitude change, etc., and the collected information is transmitted to the analysis algorithm in real time.
[0114] In this way, the firmware extraction device performs a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information, which can reflect the electromagnetic field characteristics of the target device to be extracted during actual operation. For example, this information may include the electromagnetic radiation pattern generated by the device in different operating modes, which is helpful for subsequent understanding of the operating status of the firmware in the device to ensure the extraction efficiency. For example, the obtained feedback information can provide data support for subsequent firmware analysis. For example, specific functional modules, algorithms or security vulnerabilities in the firmware can be identified by analyzing the feedback information, thereby helping security researchers to conduct in-depth firmware analysis and vulnerability assessment.
[0115] In one possible implementation, see Figure 4 In step S200, before the firmware extraction device performs a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information, the firmware extraction method based on electromagnetic injection further includes:
[0116] S210, obtaining electromagnetic injection indication data of a first device to be extracted, wherein the electromagnetic injection indication data includes characteristic data of the first device to be extracted.
[0117] It can be understood that the electromagnetic injection indication data can be the device number of the first device to be extracted, such as device 1, to distinguish which device needs to perform firmware extraction activities, or it can be the frequency, intensity, time domain waveform and other characteristics of the electromagnetic wave. Because the frequency or intensity of the electromagnetic wave required for each device to be extracted is different, these characteristic data can be used to distinguish and identify the device.
[0118] For example, the device number can be obtained through the device's own identification, user manual, device parameter setting interface, etc. Selecting suitable electromagnetic injection test equipment, including electromagnetic detectors, oscilloscopes, spectrum analyzers, etc., to perform electromagnetic injection testing can include setting test parameters, recording data, etc., to obtain electromagnetic radiation data of different devices to be extracted, including the frequency, intensity, time domain waveform and other characteristics of electromagnetic waves.
[0119] With such a configuration, by acquiring the electromagnetic injection indication data of the first device to be extracted, the device to be extracted can be distinguished and identified, so that subsequent extraction operations can be carried out in a targeted manner, which helps to improve the extraction efficiency.
[0120] S220: Determine, based on the characteristic data of the first device to be extracted, whether there is any electromagnetic injection activity between the firmware extraction device and the first device to be extracted.
[0121] It can be understood that the characteristic data of the first device to be extracted is analyzed to extract important features, such as representative changes in electromagnetic wave spectrum, time domain waveform changes, device labels or intensity changes, etc., and the characteristic data of the first device to be extracted and the characteristic data of the firmware extraction device are compared to find similarities, such as electromagnetic wave data with similar spectra, electromagnetic wave data with similar time domain waveforms, or device labels. For example, if electromagnetic wave data with similar characteristics to those of the first device to be extracted is found in the firmware extraction device, it means that the electromagnetic injection activity between the firmware extraction device and the first device to be extracted has not been completed or started, because the firmware extraction device will delete the device number of the device 1 to be extracted when completing the firmware extraction activity for the device 1 to be extracted, or the firmware extraction device will delete the electromagnetic wave data sent to the device 1 to be extracted when completing the firmware extraction activity for the device 1 to be extracted (because the frequency or intensity of the electromagnetic wave required for each device to be extracted is different, so when the firmware extraction activity for the device 1 to be extracted is completed, it can be deleted. Even if the firmware extraction activity for the device 1 to be extracted is performed again due to negligence, there is no electromagnetic wave data to rely on for the extraction activity) to indicate that the firmware extraction activity for the device 1 to be extracted is completed. This can avoid the situation where the firmware extraction activity for the device 1 to be extracted is performed again due to negligence after the firmware extraction activity for the device 1 to be extracted is completed.
[0122] For example, if electromagnetic wave data with similar characteristics to those of the first device to be extracted is found in the characteristic data of the firmware extraction device, then it can be determined that there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted; otherwise, it is determined that there is no electromagnetic injection activity between the firmware extraction device and the first device to be extracted.
[0123] With such a configuration, it is determined whether there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted based on the characteristic data of the first device to be extracted, thereby avoiding repeated extraction activities on the same device and helping to improve extraction efficiency.
[0124] S230: When it is determined that there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted, the firmware extraction device maintains the transmission service of feedback information between the firmware extraction device and the first device to be extracted.
[0125] It can be understood that determining that there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted indicates that the electromagnetic injection activity between the firmware extraction device and the first device to be extracted has not been completed or started, so it is necessary to maintain the transmission service of feedback information between the firmware extraction device and the first device to be extracted, that is, to complete the electromagnetic injection activity between the firmware extraction device and the first device to be extracted.
[0126] With such a configuration, when it is determined that there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted, the firmware extraction device maintains the transmission service of feedback information between the firmware extraction device and the first device to be extracted, which can avoid transmission service interruption caused by misjudgment and help improve extraction efficiency.
[0127] S240: When it is determined that there is no electromagnetic injection activity between the firmware extraction device and the first device to be extracted, the firmware extraction device does not perform a transmission service of feedback information between the firmware extraction device and the first device to be extracted based on the electromagnetic injection indication data.
[0128] It can be understood that determining that there is no electromagnetic injection activity between the firmware extraction device and the first device to be extracted indicates that the electromagnetic injection activity between the firmware extraction device and the first device to be extracted has been completed or ended. Therefore, it can be determined based on the electromagnetic injection indication data which device does not perform the transmission service of feedback information (for example, if there is no label of device 1 of the first device to be extracted, it is determined that the electromagnetic injection activity of device 1 of the first device to be extracted has been completed or ended), that is, the transmission service of feedback information between the firmware extraction device and the first device to be extracted is not performed.
[0129] With such a configuration, when it is determined that there is no electromagnetic injection activity in the firmware extraction device with the first device to be extracted, the firmware extraction device does not perform the transmission service of feedback information between the first device to be extracted based on the electromagnetic injection indication data, thereby avoiding repeated transmission services caused by misjudgment and helping to improve extraction efficiency.
[0130] In one possible implementation, see Figure 5 In step S240, after it is determined that there is no electromagnetic injection activity between the firmware extraction device and the first device to be extracted, the firmware extraction device does not perform the transmission service of feedback information between the first device to be extracted based on the electromagnetic injection indication data, the firmware extraction method based on electromagnetic injection further includes:
[0131] S241, in response to the second operation, the firmware extraction device creates a task of establishing an extraction channel with the first device to be extracted, wherein the types of the extraction channels established by the second operation and the first operation are different.
[0132] It can be understood that the second operation is an extraction channel established to obtain different feedback information. For example, the first operation can be used to establish a high-frequency electromagnetic channel (for example, a high-frequency signal can be obtained through a high-frequency electromagnetic channel, and the high-frequency signal can be used to obtain some high-level logical information, including the code, instructions and data executed by the system, and the operating status of the system, etc.), and the second operation can be used to establish a low-frequency electromagnetic channel (for example, a low-frequency signal can be obtained through a low-frequency electromagnetic channel, and the low-frequency signal can be used to obtain the underlying physical information, including the working status of the hardware device, the power on and off operation, fault information, etc.). The second operation can be a click, touch or text input, etc., to control the firmware extraction device to create a task to establish an extraction channel with the first device to be extracted.
[0133] In this way, in response to the second operation, the firmware extraction device creates a task of establishing an extraction channel with the first device to be extracted, which helps to more comprehensively obtain feedback information from the first device to be extracted, thereby more accurately analyzing and identifying the operating status and system structure of the first device to be extracted.
[0134] S242: Perform a first firmware extraction operation on the first device to be extracted based on the task of establishing an extraction channel with the first device to be extracted, to obtain feedback information.
[0135] It can be understood that before starting the first firmware extraction operation, it is necessary to confirm that an effective extraction channel has been established with the first device to be extracted, and that the quality and stability of the channel can meet the requirements for collecting feedback information. According to the content of the second operation, select the corresponding feedback information collection tool. For example, for the acquisition of high-frequency feedback information, you can select a high-speed digital acquisition card; for the acquisition of low-frequency feedback information, you can select a low-frequency induction coil and other equipment. Use the selected feedback information collection tool to collect the electromagnetic field of the first device to be extracted to obtain feedback information. During the collection process, it is necessary to ensure that the data collection parameters, such as the collection frequency, collection duration and other parameters, are set correctly to ensure that the collected data can accurately and comprehensively reflect the electromagnetic characteristics of the target device.
[0136] In this way, based on the task of creating an extraction channel with the first device to be extracted, a first firmware extraction operation is performed on the first device to be extracted to obtain feedback information, which helps to more comprehensively obtain the feedback information of the first device to be extracted, thereby more accurately analyzing and identifying the operating status and system structure of the first device to be extracted.
[0137] S300: Analyze and process the feedback information to extract the firmware data of the first device to be extracted, wherein the firmware data is used to reflect the code data or configuration data of the firmware in the first device to be extracted.
[0138] It can be understood that code data can be program codes stored in firmware, including operating systems, drivers, control programs, etc. These codes are the core functions of the device and are used to perform various tasks, such as controlling hardware devices, processing data, communicating with other devices, etc. Configuration data can be configuration files and parameters stored in firmware, including various settings of the device, network parameters, user accounts, access rights, etc. These configuration files and parameters determine the behavioral characteristics and security performance of the device, and directly affect the use effect and security of the device. First, the waveform characteristics of the electromagnetic signal in the feedback information are analyzed in the time domain, such as the amplitude, period, pulse width, etc. of the signal. Fourier transform is applied to convert the electromagnetic signal to the frequency domain, and the spectral characteristics of the signal, such as frequency components and harmonics, are extracted. Use methods such as short-time Fourier transform or wavelet transform to extract the time-frequency characteristics of the signal and understand the changes in the spectrum of the signal at different times. Then, the extracted electromagnetic signal features are matched with a pre-established firmware feature library (e.g., the firmware feature library may include feature patterns of known firmware codes or configuration data, and through comparison and analysis, feature patterns related to the firmware of the first device to be extracted are identified, and these patterns indicate that there are specific firmware data structures or identifiers in the signal) to identify feature patterns related to the target firmware. Finally, reverse engineering technology can be used to parse the feature patterns and restore the instruction sequence in the firmware, for example, by parsing binary data or encoding in a specific format and converting it into a readable instruction stream to extract firmware data. It is also possible to analyze the data patterns and structural features in the electromagnetic signal (e.g., some firmware uses a specific data structure to store data, such as a file system, configuration file, or database), and restore these data structures (e.g., using specialized software tools or self-written programs) and extract the valid information stored therein, i.e., firmware data, such as log data, event records, or user settings.
[0139] With such a configuration, the feedback information is analyzed and processed to extract the firmware data of the first device to be extracted, thereby avoiding the defects and disadvantages of the traditional physical evidence collection method and helping to improve the extraction efficiency.
[0140] In one possible implementation, see Figure 6 , S300, analyzing and processing the feedback information to extract the firmware data of the first device to be extracted, including:
[0141] S310, performing time domain analysis on the feedback information to obtain time domain characteristic parameters of the electromagnetic signal.
[0142] It can be understood that time domain characteristic parameters such as amplitude, amplitude, period, pulse width, pulse repetition interval, etc. are extracted from the electromagnetic signal. Each extracted characteristic parameter is analyzed to understand the characteristics of the electromagnetic signal in the time domain. According to the understanding of the time domain characteristics of the electromagnetic signal and the working principle of the device, the time domain characteristic parameters that conform to the state change of the device are selected. The time domain characteristic parameters of the electromagnetic signal may include: Amplitude is used to indicate the amplitude of the electromagnetic wave signal. Amplitude is used to indicate the number of vibrations in the electromagnetic wave signal. The period is used to indicate the time required for a complete vibration reciprocating motion in the electromagnetic wave signal.
[0143] With this arrangement, the feedback information is analyzed in the time domain to obtain the time domain characteristic parameters of the electromagnetic signal, so as to understand the working state and power characteristics of the first device to be extracted, thereby better performing firmware extraction and analysis, which helps to improve the extraction efficiency.
[0144] S320, performing frequency domain analysis on the feedback information to obtain frequency domain characteristic parameters of the electromagnetic signal.
[0145] It can be understood that the use of discrete Fourier transform can convert electromagnetic signals from the time domain to the frequency domain. The frequency domain signal obtained after the discrete Fourier transform is filtered, and the signal is subjected to power spectrum density analysis. The frequency domain characteristics of the signal are analyzed by calculating the power spectrum density, and the frequency domain characteristic parameters of the electromagnetic signal are analyzed from the frequency domain perspective. According to the frequency domain characteristics of the electromagnetic signal and the understanding of the working principle of the device, the frequency domain characteristic parameters that conform to the state change of the device are selected. The frequency domain characteristic parameters may include: The frequency is used to indicate the frequency of the number of vibrations in the electromagnetic wave signal. The peak frequency is used to indicate the frequency with the highest power spectrum density in the electromagnetic wave signal.
[0146] With this arrangement, the feedback information is analyzed in the frequency domain to obtain the frequency domain characteristic parameters of the electromagnetic signal, so as to understand the working state and power characteristics of the first device to be extracted, thereby better performing firmware extraction and analysis, which helps to improve the extraction efficiency.
[0147] S330, comparing and analyzing the time domain characteristic parameters and the frequency domain characteristic parameters with a pre-established firmware characteristic library, extracting firmware data most similar to the time domain characteristic parameters and the frequency domain characteristic parameters from the firmware characteristic library as firmware data of the first device to be extracted.
[0148] It can be understood that some normally operating devices are analyzed, firmware data is extracted, and stored in the form of firmware binary code. A feature library is established based on the code logic architecture, key functions, etc. The extracted time domain feature parameters and frequency domain feature parameters are sequentially constructed into a vector, which is the vector to be compared. The similarity between the vector to be compared and the firmware feature library vector can be calculated using a similarity measurement method (such as cosine similarity, Euclidean distance, Manhattan distance, etc.) to calculate the similarity between the vector to be compared and the firmware feature library vector, and the set of data with the highest similarity is found as the matching result. The matching result is compared with the known correct device features and verified. Once the matching result is correct, it indicates that the firmware of the device has the same or similar firmware as the device with similar features in the firmware library, and the firmware extraction tool can be used to extract the firmware. For example, taking the express automatic sorting system as an example, the time domain features and frequency domain features are extracted. Time domain features include pulse width, pulse repetition interval, oscillation period, etc.; frequency domain features include frequency, peak frequency, bandwidth, etc. The collected feature parameters are constructed into a vector to be compared, and the similarity is calculated with the vectors in the pre-established firmware feature library. The set of data with the highest similarity is the firmware version of the express automatic sorting system. Taking the security monitoring system as an example, time domain features and frequency domain features are extracted. Time domain features include amplitude, amplitude, rise time, etc.; frequency domain features include peak frequency, power spectral density, etc. Similarly, the collected feature parameters are constructed into a vector to be compared, and the similarity is calculated with the vectors in the pre-established firmware feature library. The set of data with the highest similarity is the firmware version of the security monitoring system.
[0149] In this way, the time domain characteristic parameters and frequency domain characteristic parameters are compared and analyzed with the pre-established firmware feature library, and the firmware data most similar to the time domain characteristic parameters and the frequency domain characteristic parameters are extracted from the firmware feature library as the firmware data of the first device to be extracted. This helps to quickly locate and match the device type or signal source, saving a lot of manual analysis time.
[0150] In one possible implementation, see Figure 7 In step S300, after analyzing and processing the feedback information and extracting the firmware data of the first device to be extracted, the firmware extraction method based on electromagnetic injection further includes:
[0151] S340, creating a firmware backup file, and saving the extracted firmware data into the firmware backup file.
[0152] It can be understood that the format of creating the firmware backup file is determined. The firmware backup file can be in the format of a binary file, a compressed file, etc. When selecting the format, the effectiveness of data preservation, the overall file size, and the convenience of subsequent processing should be considered. Use the corresponding file operation tool (such as a text editor) to create a new backup file. Write the extracted firmware data in binary form to the backup file, which can be done through file operation commands, scripts, or programs to ensure the integrity and accuracy of the data. According to the format of the firmware backup file, write the extracted firmware data byte by byte into the backup file, ensuring that the header of the data contains the necessary metadata information for subsequent identification and restoration.
[0153] With this setting, a firmware backup file is created and the extracted firmware data is saved in the firmware backup file, which can ensure that the firmware data is effectively backed up for subsequent analysis and processing.
[0154] S350, upload the firmware backup file to the cloud storage server.
[0155] As you can understand, select and register a cloud storage service provider, such as Amazon S3, Google CloudStorage, Microsoft Azure, etc., register an account and create a bucket to store files. In the management console of the cloud storage service provider, obtain access keys or credential information, including Access Key and Secret Key, etc., for authentication of upload operations. According to the selected cloud storage service provider, download the corresponding cloud storage SDK or use the provided command line tool to upload files. After the upload is completed, you can confirm whether the file has been successfully uploaded in the management console of the cloud storage service provider or through API query.
[0156] With this setup, uploading the firmware backup files to the cloud storage server can achieve secure storage and backup of the files, and also facilitate future retrieval, sharing, and management of the files.
[0157] In a possible implementation, the firmware extraction method based on electromagnetic injection further includes:
[0158] The second interface is displayed on the display device of the firmware extraction device, wherein the second interface is used to prompt that the firmware data has been successfully extracted and stored in the cloud storage server.
[0159] It is understandable that a display interface is designed to prompt that the firmware data has been successfully extracted and stored in the cloud storage server. The interface may include text information, icons or other visual elements to clearly display information to the user. Use relevant hardware controls to output the designed second interface display content to the display device. This may involve the device's graphical display interface, screen controller or other related hardware. After the firmware data has been successfully extracted and successfully uploaded to the cloud storage server, the designed second interface is displayed through the display device to prompt the user that the data has been successfully extracted and stored in the cloud storage server. Ensure that the information display is clear and easy to understand.
[0160] With such configuration, displaying the second interface on the display device of the firmware extraction device can effectively show the user the information that the data extraction is successful, thereby improving the user's experience.
[0161] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0162] Corresponding to the firmware extraction method based on electromagnetic injection described in the above embodiment, the embodiment of the present application further provides a firmware extraction system based on electromagnetic injection, and each unit of the system can implement each step of the firmware extraction method based on electromagnetic injection. Figure 8 A structural block diagram of a firmware extraction system based on electromagnetic injection provided in an embodiment of the present application is shown. For ease of explanation, only the parts related to the embodiment of the present application are shown.
[0163] Reference Figure 8 , the firmware extraction system based on electromagnetic injection includes:
[0164] The detection unit is used to detect a first operation. The first operation is used to establish an extraction channel with a first device to be extracted. The first device to be extracted is a device where a user actively initiates firmware extraction.
[0165] The execution unit is used for the firmware extraction device to perform a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information, wherein the feedback information is used to reflect the electromagnetic field characteristics of the firmware in the first device to be extracted.
[0166] The extraction unit is used to analyze and process the feedback information to extract the firmware data of the first device to be extracted, wherein the firmware data is used to reflect the code data or configuration data of the firmware in the first device to be extracted.
[0167] It should be noted that the information interaction, execution process, etc. between the above-mentioned systems / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0168] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the division of the above-mentioned functional units is used as an example for illustration. In practical applications, the above-mentioned functions can be assigned to different functional units as needed, that is, the internal structure of the system can be divided into different functional units to complete all or part of the functions described above. The functional units in the embodiment can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0169] The present application also provides a firmware extraction device. Fig. 9 This is a schematic diagram of the structure of a firmware extraction device provided in an embodiment of the present application. Fig. 9 As shown, the firmware extraction device 6 of this embodiment includes: at least one processor 60 ( Fig. 9 Only one is shown), at least one memory 61 ( Fig. 9 Only one is shown) and a computer program 62 stored in the at least one memory 61 and executable on the at least one processor 60. When the processor 60 executes the computer program 62, the firmware extraction device 6 implements the steps in any of the above-mentioned firmware extraction method embodiments based on electromagnetic injection, or implements the functions of the various units in the above-mentioned system embodiments.
[0170] Exemplarily, the computer program 62 may be divided into one or more units, which are stored in the memory 61 and executed by the processor 60 to complete the present application. The one or more units may be a series of computer program instruction segments capable of completing specific functions, which are used to describe the execution process of the computer program 62 in the firmware extraction device 6.
[0171] For example, the firmware extraction device 6 may include an electromagnetic probe, a signal generator, a data acquisition device, and an analysis algorithm installed in the firmware extraction device 6. The electromagnetic probe is used to generate and inject electromagnetic signals to stimulate the firmware in the device to be extracted. The signal generator can generate electromagnetic signals of the required frequency and intensity, which are then used to drive the electromagnetic probe. The data acquisition device is responsible for receiving, processing and recording the captured electromagnetic signals, converting the electromagnetic signals into digital data and transmitting them to the analysis algorithm. The analysis algorithm can process and parse the digital signals to extract the required firmware data, such as code data or configuration data. The firmware extraction device 6 may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art will understand that Fig. 9 It is only an example of the firmware extraction device 6 and does not constitute a limitation on the firmware extraction device 6. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components, for example, it may also include input and output devices, network access devices, buses, etc.
[0172] The processor 60 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0173] In some embodiments, the memory 61 may be an internal storage unit of the firmware extraction device 6, such as a hard disk or memory of the firmware extraction device 6. In other embodiments, the memory 61 may also be an external storage device of the firmware extraction device 6, such as a plug-in hard disk, a smart memory card (SmartMedia Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the firmware extraction device 6. Further, the memory 61 may also include both the internal storage unit of the firmware extraction device 6 and an external storage device. The memory 61 is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as the program code of the computer program, etc. The memory 61 may also be used to temporarily store data that has been output or is to be output.
[0174] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above method embodiments are implemented.
[0175] An embodiment of the present application provides a computer program product. When the computer program product is run on a firmware extraction device, the firmware extraction device implements the steps in any of the above method embodiments.
[0176] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the firmware extraction device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electric carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a disk or an optical disk.
[0177] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0178] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0179] In the embodiments provided in the present application, it should be understood that the disclosed firmware extraction device, the firmware extraction system based on electromagnetic injection, and the firmware extraction method based on electromagnetic injection can be implemented in other ways. For example, the firmware extraction device and the firmware extraction system based on electromagnetic injection described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0180] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0181] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A firmware extraction method based on electromagnetic injection, characterized in that: Applied to a firmware extraction device, the method comprises: Detecting a first operation; wherein the first operation is used to establish an extraction channel with a first device to be extracted; the first device to be extracted is a device from which a user actively initiates firmware extraction; The firmware extraction device performs a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information; wherein the first firmware extraction operation is an operation of electromagnetic injection by the firmware extraction device to the first device to be extracted, and the feedback information is used to reflect the information of the timing characteristics of the firmware reading process in the first device to be extracted by the firmware extraction device; The feedback information is analyzed and processed to extract the firmware data of the first device to be extracted; wherein the firmware data is used to reflect the code data or configuration data of the firmware in the first device to be extracted.
2. The firmware extraction method based on electromagnetic injection as claimed in claim 1, characterized in that: After detecting the first operation, the method further includes: Determining whether a second firmware extraction activity is currently being performed with a second device to be extracted; wherein the second device to be extracted is a device for which firmware extraction is prearranged; In the case of determining that the second firmware extraction activity is being performed with the second device to be extracted, determining whether the first device to be extracted is in an electromagnetic injection adaptation mode; When the first device to be extracted is in the electromagnetic injection adaptation mode, in response to a first operation, a first firmware extraction operation is performed on the first device to be extracted based on the extraction channel, and a second firmware extraction activity with the second device to be extracted is suspended.
3. The firmware extraction method based on electromagnetic injection as claimed in claim 2, characterized in that: The method further comprises: Acquire software configuration information and a state to be extracted of the first device to be extracted; wherein the software configuration information is used to reflect whether parameter information corresponding to electromagnetic injection is configured in the first device to be extracted, and the state to be extracted is used to reflect whether the first device to be extracted is in an executable firmware extraction state; When the software configuration information of the first device to be extracted reflects that parameter information corresponding to electromagnetic injection has been configured, and the state to be extracted reflects that the first device to be extracted is in an executable firmware extraction state, determining that the first device to be extracted is in the electromagnetic injection adaptation mode; When the software configuration information of the first device to be extracted reflects that parameter information corresponding to electromagnetic injection is not configured and / or the state to be extracted reflects that the first device to be extracted is not in an executable firmware extraction state, it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode.
4. The firmware extraction method based on electromagnetic injection as claimed in claim 3, characterized in that: After determining that the second firmware extraction activity is being performed with the second device to be extracted, and determining whether the first device to be extracted is in an electromagnetic injection adaptation mode, the method further includes: When it is determined that the first device to be extracted is not in the electromagnetic injection adaptation mode, the second firmware extraction activity between the second device to be extracted is maintained, and a first interface is displayed on the display device of the firmware extraction device; wherein the first interface is used to remind the user that the first device to be extracted is not in the electromagnetic injection adaptation mode.
5. The firmware extraction method based on electromagnetic injection according to any one of claims 1 to 4, characterized in that: The method further comprises: When it is determined that the current firmware version of the first device to be extracted does not need to be extracted, a user is prompted on a display device of the firmware extraction device that the current firmware version of the first device to be extracted is the latest version.
6. The firmware extraction method based on electromagnetic injection according to any one of claims 1 to 4, characterized in that: The method further comprises: During the process of extracting the firmware data, the operating status of the first device to be extracted is monitored, and the extraction operation is terminated when an abnormality is detected.
7. The firmware extraction method based on electromagnetic injection as claimed in claim 4, characterized in that: Before the firmware extraction device performs a first firmware extraction operation on the first device to be extracted based on the extraction channel to obtain feedback information, the method further includes: Acquire electromagnetic injection indication data of the first device to be extracted; wherein the electromagnetic injection indication data includes characteristic data of the first device to be extracted; According to the characteristic data of the first device to be extracted, determining whether there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted; When it is determined that there is electromagnetic injection activity between the firmware extraction device and the first device to be extracted, the firmware extraction device maintains the transmission service of feedback information between the firmware extraction device and the first device to be extracted; When it is determined that there is no electromagnetic injection activity between the firmware extraction device and the first device to be extracted, the firmware extraction device does not perform a transmission service of feedback information with the first device to be extracted based on the electromagnetic injection indication data.
8. The firmware extraction method based on electromagnetic injection as claimed in claim 7, characterized in that: In the case where it is determined that there is no electromagnetic injection activity between the firmware extraction device and the first device to be extracted, after the firmware extraction device does not perform a transmission service of feedback information between the firmware extraction device and the first device to be extracted based on the electromagnetic injection indication data, the method further includes: In response to a second operation, the firmware extraction device creates a task of establishing an extraction channel with the first device to be extracted; wherein the type of the extraction channel established by the second operation is different from that established by the first operation; Based on the task of creating an extraction channel with the first device to be extracted, a first firmware extraction operation is performed on the first device to be extracted to obtain feedback information.
9. The firmware extraction method based on electromagnetic injection as claimed in claim 7, characterized in that: The step of analyzing and processing the feedback information to extract the firmware data of the first device to be extracted includes: Performing time domain analysis on the feedback information to obtain time domain characteristic parameters of the electromagnetic signal; Performing frequency domain analysis on the feedback information to obtain frequency domain characteristic parameters of the electromagnetic signal; The time domain characteristic parameters and the frequency domain characteristic parameters are compared and analyzed with a pre-established firmware feature library, and firmware data that is most similar to the time domain characteristic parameters and the frequency domain characteristic parameters is extracted from the firmware feature library as the firmware data of the first device to be extracted.
10. The firmware extraction method based on electromagnetic injection as claimed in claim 9, characterized in that: After analyzing and processing the feedback information to extract the firmware data of the first device to be extracted, the method further includes: Creating a firmware backup file, and saving the extracted firmware data into the firmware backup file; Uploading the firmware backup file to a cloud storage server; Wherein, the method further comprises: A second interface is displayed on the display device of the firmware extraction device; wherein the second interface is used to prompt that the firmware data has been successfully extracted and stored in the cloud storage server.
Citation Information
Patent Citations
Embedded chip JTAG (Joint Test Action Group) interface side channel acquisition adapter and method
CN114461556A
Protective actions for memory devices based on detection of attacks
CN117149055A