Firmware Monitoring and Protection Method and System Based on PFR and SPI Bus

By adopting a monitoring and protection method based on PFR and SPI bus in the firmware system, using the whitelist mechanism and command monitoring unit, the problem of difficulty in monitoring and protection of the firmware is solved, and effective monitoring and protection of the firmware is achieved.

CN119739595BActive Publication Date: 2025-05-27HUNAN BOSHENGXIN MICROELECTRONICS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510253251.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-27
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

The prior art is difficult to effectively monitor and protect the firmware from malicious attacks, and the security defects of the firmware are highly concealed, difficult to detect, difficult to remove, and strong destructive.

Method used

The firmware monitoring and protection method based on PFR and SPI buses is adopted. By configuring the host to obtain custom commands and store them in a whitelist, the command monitoring unit monitors the chip select signal of the access host, parses and determines whether the access command is in the whitelist, and if it is inconsistent, communication between the access host and memory is blocked.

Benefits of technology

It realizes monitoring and protection of firmware in memory, avoids malicious attacks on the firmware, and ensures the security and reliability of the firmware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119739595B_ABST
    Figure CN119739595B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of computer firmware, and particularly relates to a firmware monitoring and protection method and system based on PFR and SPI buses; first, a configuration host obtains a custom command, and stores the custom command in a whitelist through the AHB bus; during the normal operation of the system, a command monitoring unit monitors the chip select signal of the access host to obtain a first data input signal sent by the access host to the memory through the SPI bus, parses the first data input signal to obtain a corresponding first access command, and determines whether the first access command is consistent with any custom command in the whitelist; if not, it proves that the operation that the access host wants to perform on the memory belongs to a risk operation. To ensure the security of the firmware in the memory, the command operation unit immediately blocks the communication connection between the access host and the memory, thereby monitoring and protecting the firmware in the memory.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer firmware, and in particular to a firmware monitoring and protection method and system based on PFR and SPI bus. Background Art

[0002] With the rapid development of electronic information technology, computer systems are subject to more and more security attacks: Firmware refers to the programs written into erasable programmable read-only memory (such as Flash, an electronically erasable programmable read-only memory); firmware is responsible for the most basic and lowest-level work of a computer system, so there are more and more security attacks on firmware.

[0003] Firmware security flaws are highly concealed, difficult to detect, difficult to eliminate, and highly destructive. At present, there are implementation standards for fixed security protection on the market, such as the Platform Firmware Resiliency (PFR) standard. PFR aims to strengthen the prevention of unauthorized instructions from intrusion and modification of firmware, and ensure the legitimacy and legality of the firmware; the main functions of PFR are Protection, Detection, and Recovery. Therefore, there is an urgent need for a technical solution that can monitor and protect firmware to prevent it from being attacked maliciously. Summary of the invention

[0004] The main purpose of the present invention is to provide a firmware monitoring and protection method and system based on PFR and SPI bus, aiming to solve the problem that a technical solution capable of monitoring and protecting firmware is urgently needed to prevent the firmware from being subjected to malicious attacks.

[0005] The technical solution proposed by the present invention is:

[0006] A firmware monitoring and protection method based on PFR and SPI bus is applied to a firmware monitoring and protection system based on PFR and SPI bus; the system comprises a filtering monitoring module, a configuration host, an access host and a memory; the configuration host is connected to the filtering monitoring module via AHB bus communication; the memory and the filtering monitoring module are connected to the access host via SPI bus communication; the filtering monitoring module comprises a command monitoring unit and a command operation unit; the memory stores firmware; the method comprises:

[0007] The host is configured to obtain a custom command, and the custom command is stored in a white list through an AHB bus, wherein the custom command is an operation command allowed to be performed on the firmware in the memory, and the number of the custom command is multiple;

[0008] The command monitoring unit monitors the chip select signal of the access host to obtain a first data input signal sent by the access host to the memory through the SPI bus, and analyzes the first data input signal to obtain a corresponding first access command;

[0009] The command monitoring unit determines whether the first access command is consistent with any custom command in the whitelist;

[0010] If they are inconsistent, the command operation unit pulls up the chip select signal of the memory to prevent the communication connection between the access host and the memory.

[0011] Preferably, the filtering monitoring module further includes a slave unit; the slave unit includes a whitelist register and an interrupt control register; the configuration host obtains the custom command and stores the custom command in the whitelist through the AHB bus, including:

[0012] Configure the host to obtain custom commands and send the custom commands to the whitelist register through the AHB bus;

[0013] The whitelist register stores the custom commands in the whitelist;

[0014] If the communication connection between the host and the memory is inconsistent, the command operation unit is commanded to pull up the chip select signal of the memory to prevent access to the communication connection between the host and the memory, including:

[0015] If they are inconsistent, the command operation unit generates an interrupt control signal through the interrupt control register;

[0016] The command operation unit pulls up a chip selection signal of the memory based on the interrupt control signal to prevent access to a communication connection between the host and the memory.

[0017] Preferably, the system further comprises a simulation test platform; the simulation test platform comprises a simulation filtering module, a simulation configuration host, a simulation access host and a simulation memory; the simulation configuration host is communicatively connected to the simulation filtering module; the simulation memory and the simulation filtering module are both communicatively connected to the simulation access host; the method further comprises:

[0018] The simulation configuration host obtains the custom command and stores the custom command in the simulation filtering module;

[0019] The simulated access host obtains a preset access command input, wherein the preset access command is multiple in number and the preset access command includes multiple commands that are different from the custom command;

[0020] The simulated access host marks commands in the preset access commands that are different from the custom commands as illegal commands, and marks the number of the illegal commands as an illegal number;

[0021] The emulated access host generates a data input signal corresponding to each preset access command and marks it as a second data input signal;

[0022] Every first preset time period, the simulation access host sends each second data input signal to the simulation memory in sequence;

[0023] The simulation filtering module obtains a second data input signal sent by the simulation access host to the simulation memory, and parses the second data input signal to obtain a corresponding second access command;

[0024] The simulation filtering module determines in turn whether each second access command is consistent with any custom command in the simulation filtering module;

[0025] If they are inconsistent, the simulation filtering module marks the second access command as an abnormal command;

[0026] The simulation filtering module determines whether the number of abnormal commands is consistent with the illegal number;

[0027] If so, the simulation filtering module generates first feedback information for indicating that the simulation verification has passed;

[0028] If not, the simulation filtering module generates second feedback information for indicating that the simulation verification has not passed.

[0029] Preferably, the system further comprises a management terminal capable of communicating with the configuration host; the method further comprises:

[0030] The management terminal generates update verification information, wherein the update verification information includes an allowed update time period, and the start time of the allowed update time period is later than the current time;

[0031] The management terminal sends the update verification information to the configuration host;

[0032] The configuration host generates an update command based on the update verification information, and obtains the start time and end time of the update time period;

[0033] If the interval between the current time and the start time of the update time period is less than the second preset time period, the configuration host stores the update command to the whitelist via the AHB bus;

[0034] If the current time is consistent with the end time of the update time period, the filter monitoring module deletes the update command from the whitelist;

[0035] The command monitoring unit pulls down the chip select signal of the access host to obtain a first data input signal sent by the access host to the memory through the SPI bus, and parses the first data input signal to obtain a corresponding first access command, and then further includes:

[0036] The command monitoring unit determines whether the first access command is an update command;

[0037] If so, the command monitoring unit determines whether there is an update command in the whitelist;

[0038] If there is an update instruction, the command operation unit allows the access host to update the firmware in the memory;

[0039] If there is no update instruction, the command operation unit prohibits the access host from updating the firmware in the memory.

[0040] Preferably, the update verification information further includes an allowed update source address, and the number of allowed update source addresses is multiple; the management terminal sends the update verification information to the configuration host, and then further includes:

[0041] The configuration host sends the allowed update source address in the update verification information to the filtering monitoring module;

[0042] The command monitoring unit determines whether there is an update command in the white list, and then further includes:

[0043] If there is an update instruction, the command monitoring unit obtains the IP address of the access host corresponding to the first access command;

[0044] The command monitoring unit determines whether the IP address of the access host corresponding to the first access command is consistent with any allowed update source address;

[0045] If they are consistent, the command operation unit allows the access host to update the firmware in the memory.

[0046] Preferably, it also includes:

[0047] After the memory is newly added or updated with firmware, the filtering monitoring module performs a hash operation on the newly added or updated firmware to obtain a first hash value corresponding to the newly added or updated firmware;

[0048] The host is configured to perform an operation risk check on the storage once every third preset time period to obtain an operation risk value corresponding to the storage, wherein the operation risk value is used to express the operation risk of the storage, and the greater the operation risk value, the higher the risk of the storage being attacked by the network;

[0049] When the operation risk value is greater than the first preset value, the filtering monitoring module performs a hash operation on the current firmware in the memory to obtain a second hash value corresponding to the current firmware in the memory;

[0050] The filtering monitoring module determines whether the first hash value is consistent with the second hash value;

[0051] If so, the filtering monitoring module assigns the operation risk value corresponding to the memory to a second preset value, wherein the second preset value is less than the first preset value;

[0052] If not, the filtering monitoring module generates early warning feedback information.

[0053] Preferably, the external device is connected to the access host through the Internet; if there is inconsistency, the command operation unit pulls up the chip select signal of the memory to prevent the communication connection between the access host and the memory, and then includes:

[0054] The command operation unit marks the first access command as a risk command, and sends the risk command to the configuration host and the access host;

[0055] The access host determines the source device corresponding to the risk command and obtains the IP address of the source device, wherein the source device is an external device that sends the risk command to the access host;

[0056] The access host sends the IP address of the source device corresponding to the risky command to the configuration host;

[0057] The configuration host performs an operation risk check on the memory every third preset time period to obtain an operation risk value corresponding to the memory, including:

[0058] The configuration host performs an operation risk check on the storage device every third preset time period based on the risk command and the IP address of the source device corresponding to the risk command to obtain an operation risk value corresponding to the storage device.

[0059] Preferably, the configuration host performs an operation risk check on the memory once every third preset time period based on the risk command and the IP address of the source device corresponding to the risk command to obtain an operation risk value corresponding to the memory, including:

[0060] The configuration host obtains the number of risk commands received from the command operation unit within a third preset time period in the past, and marks the number as an abnormal number;

[0061] The configuration host obtains the IP address of the source device corresponding to the risky command received from the access host within the third preset time period in the past, and marks it as an abnormal address;

[0062] The host is configured to obtain an input risk address set, wherein the risk address set includes at least one IP address of an external device that has been subjected to a network security attack in the past fourth preset time period;

[0063] When an abnormal address falls into the risk address set, the host is configured to mark the abnormal address as a target address;

[0064] The configuration host calculates an operation risk value corresponding to the memory based on the number of exceptions, the number of exception addresses, and the number of target addresses.

[0065] Preferably, the configuration host calculates the operation risk value corresponding to the memory based on the number of exceptions, the number of exception addresses, and the number of target addresses using the following calculation formula:

[0066]

[0067] In the formula, is the operation risk value corresponding to the memory, and the maximum value is 2; is an abnormal number; is the standard quantity, which is a positive integer; is the number of target addresses; is the number of exception addresses.

[0068] The present invention also proposes a firmware monitoring and protection system based on PFR and SPI bus, and applies a firmware monitoring and protection method based on PFR and SPI bus; the system includes a filtering monitoring module, a configuration host, an access host and a memory; the configuration host is connected to the filtering monitoring module via AHB bus communication; the memory and the filtering monitoring module are connected to the access host via SPI bus communication; the filtering monitoring module includes a command monitoring unit and a command operation unit; and the firmware is stored in the memory.

[0069] Through the above technical solution, the following beneficial effects can be achieved:

[0070] The firmware monitoring and protection method based on PFR and SPI bus proposed in the present invention can monitor and protect the firmware in the memory to prevent the firmware from being subjected to malicious attacks; firstly, a custom command is obtained by configuring the host, and the custom command is stored in a white list through the AHB bus; during the normal operation of the system, the command monitoring unit will pull down the chip select signal of the access host, thereby establishing communication between the command monitoring unit and the access host, so as to obtain the first data input signal sent by the access host to the memory through the SPI bus, and parse the first data input signal to obtain the corresponding first access command, and determine whether the first access command is consistent with any custom command in the white list; if not, it proves that the operation that the access host wants to perform on the memory is not in the white list, which is a risky operation. In order to ensure the security of the firmware in the memory, the command operation unit immediately pulls up the chip select signal of the memory to prevent the communication connection between the access host and the memory, thereby monitoring and protecting the firmware in the memory. BRIEF DESCRIPTION OF THE DRAWINGS

[0071] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying creative work.

[0072] Figure 1 A flowchart of the steps of a first embodiment of a firmware monitoring and protection method based on PFR and SPI bus proposed by the present invention;

[0073] Figure 2 This is a schematic diagram of the structure of a filtering monitoring module in a second embodiment of a firmware monitoring protection method based on PFR and SPI bus proposed by the present invention. DETAILED DESCRIPTION

[0074] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0075] The present invention provides a firmware monitoring and protection method and system based on PFR and SPI bus.

[0076] As attached Figure 1 As shown, in a first embodiment of a firmware monitoring and protection method based on PFR and SPI bus proposed by the present invention, the method is applied to a firmware monitoring and protection system based on PFR and SPI bus; the system includes a filtering monitoring module, a configuration host, an access host and a memory; the configuration host is connected to the filtering monitoring module through AHB bus communication; the memory and the filtering monitoring module are connected to the access host through SPI bus communication; the filtering monitoring module includes a command monitoring unit and a command operation unit; the memory stores firmware; in this embodiment, the filtering monitoring module is mounted on an FPGA chip (such as Xilinx's zynq series development board); the memory is a flash memory (Flash), specifically a GigaDevice domestic chip; the access host is a BMC chip (BMC is a baseboard management controller, Baseboard Management Controller, a microcontroller specifically used for server management); this embodiment includes the following steps:

[0077] Step S110: configuring the host to obtain a custom command, and storing the custom command in a white list through the AHB bus, wherein the custom command is an operation command allowed to be performed on the firmware in the memory, and the number of the custom command is multiple.

[0078] Specifically, the custom command here is an operation command determined by the administrator to operate the firmware in the memory, such as a read command, a copy command, etc. The white list here is set in the filtering monitoring module.

[0079] In addition, the above-mentioned AHB (Advanced High-performance Bus) bus is a high-performance on-chip bus, which is mainly used to connect high-performance system modules.

[0080] Step S120: the command monitoring unit monitors the chip select signal of the access host to obtain a first data input signal sent by the access host to the memory through the SPI bus (Serial Peripheral Interface), and analyzes the first data input signal to obtain a corresponding first access command.

[0081] Specifically, the chip select signal (CS) is a control signal used in a digital circuit system with multiple chips. The chip select signal is used to select a specific chip so that the chip can communicate with other devices in the system. When the chip select signal is valid (low level in this embodiment), the corresponding chip is "selected" so that it can receive or send data, address and other information; when the chip select signal is invalid (high level in this embodiment), the chip is inactive, that is, it cannot receive signals from other devices.

[0082] In this embodiment, the chip select signal of the access host is pulled low (so that the command monitoring unit can communicate with the access host), thereby obtaining the first data input signal sent by the access host to the memory through the SPI bus.

[0083] Specifically, the SPI bus is a high-speed, full-duplex, synchronous communication bus; the first data input signal here is a signal transmitted on the MOSI (Master Out Slave In) signal line on the SPI bus: MOSI is the signal line for the access host to send data to other slave devices.

[0084] Step S130: The command monitoring unit determines whether the first access command is consistent with any custom command in the whitelist.

[0085] Step S140: If not consistent, the command operation unit pulls up the chip select signal of the memory to prevent access to the communication connection between the host and the memory.

[0086] Specifically, if there is any inconsistency, it proves that the operation that the access host wants to perform on the memory is not in the whitelist and is a risky operation. In order to ensure the security of the firmware in the memory, the command operation unit pulls up the chip select signal of the memory (making the memory inactive and unable to receive data information from other chips (access host)) to block the communication connection between the access host and the memory.

[0087] The firmware monitoring and protection method based on PFR and SPI bus proposed in the present invention can monitor and protect the firmware in the memory to prevent the firmware from being subjected to malicious attacks; firstly, a custom command is obtained by configuring the host, and the custom command is stored in a white list through the AHB bus; during the normal operation of the system, the command monitoring unit will pull down the chip select signal of the access host, thereby establishing communication between the command monitoring unit and the access host, so as to obtain the first data input signal sent by the access host to the memory through the SPI bus, and parse the first data input signal to obtain the corresponding first access command, and determine whether the first access command is consistent with any custom command in the white list; if not, it proves that the operation that the access host wants to perform on the memory is not in the white list, which is a risky operation. In order to ensure the security of the firmware in the memory, the command operation unit immediately pulls up the chip select signal of the memory to prevent the communication connection between the access host and the memory, thereby monitoring and protecting the firmware in the memory.

[0088] In a second embodiment of a firmware monitoring protection method based on PFR and SPI bus proposed by the present invention, based on the first embodiment, as shown in the attached Figure 2 As shown, the filtering monitoring module also includes a slave unit; the slave unit includes a whitelist register and an interrupt control register; step S110 includes the following steps:

[0089] Step S210: configure the host to obtain the custom command, and send the custom command to the whitelist register through the AHB bus.

[0090] Step S220: the whitelist register stores the custom command in the whitelist.

[0091] Step S140: If the information is inconsistent, the command operation unit pulls up the chip select signal of the memory to prevent the access host from communicating with the memory, including:

[0092] Step S230: If they are inconsistent, the command operation unit generates an interrupt control signal through the interrupt control register.

[0093] Step S240: the command operation unit pulls up the chip select signal of the memory based on the interrupt control signal to prevent access to the communication connection between the host and the memory.

[0094] Specifically, this embodiment provides a specific solution of how the filtering monitoring module stores the custom commands from the configured host in the whitelist based on the whitelist register, and how to block access to the communication connection between the host and the memory based on the interrupt control register.

[0095] Furthermore, the slave unit here is mainly used to implement the register configuration function. The slave unit also includes a control register (Ctrl_reg), a status register (Status_reg), an interrupt enable register (Int_enable) and an interrupt status register (Int_status_reg). These registers are used to configure to implement the required functions, states and interrupts.

[0096] Specifically, the whitelist in this embodiment is composed of 10 32-bit whitelist registers, each whitelist register can store 4 custom commands, and each custom command is one byte.

[0097] In a third embodiment of a firmware monitoring protection method based on PFR and SPI bus proposed by the present invention, based on the first embodiment, the system further includes a simulation test platform; the simulation test platform includes a simulation filtering module, a simulation configuration host, a simulation access host and a simulation memory; the simulation configuration host is communicatively connected to the simulation filtering module; the simulation memory and the simulation filtering module are both communicatively connected to the simulation access host; in this embodiment, the simulation test platform is built using Modelsim (ModelSim is a hardware description language simulation tool widely used in the field of electronic design automation); the method further includes the following steps:

[0098] Step S310: The simulation configuration host obtains the custom command and stores the custom command in the simulation filtering module.

[0099] Step S320: simulating access to the host to obtain input preset access commands, wherein there are multiple preset access commands, and the preset access commands include multiple commands that are different from the custom commands.

[0100] Specifically, the preset access commands here include both commands that are the same as the custom commands and commands that are different from the custom commands, so that in the subsequent verification simulation filtering module, the command that is different from the custom command can be identified and prevented from performing corresponding operations on the firmware in the memory.

[0101] Step S330: the simulated access host marks the commands in the preset access commands that are different from the custom commands as illegal commands, and marks the number of the illegal commands as an illegal number.

[0102] Specifically, the illegal command here is a command that is different from the custom command.

[0103] Step S340: The simulated access host generates a data input signal corresponding to each preset access command and marks it as a second data input signal.

[0104] Step S350: every first preset time period (eg, 5 seconds), the simulation access host sends each second data input signal to the simulation memory in sequence.

[0105] Step S360: the simulation filtering module obtains a second data input signal sent by the simulation access host to the simulation memory, and parses the second data input signal to obtain a corresponding second access command.

[0106] Step S370: The simulation filtering module determines in turn whether each second access command is consistent with any custom command in the simulation filtering module.

[0107] Step S380: If they are inconsistent, the simulation filtering module marks the second access command as an abnormal command.

[0108] Step S390: The simulation filtering module determines whether the number of abnormal commands is consistent with the illegal number.

[0109] Specifically, the abnormal command here is the illegal command recognized by the simulation filtering module.

[0110] If so, execute step S391: the simulation filtering module generates first feedback information for indicating that the simulation verification has passed.

[0111] If not, execute step S392: the simulation filtering module generates second feedback information for indicating that the simulation verification has not passed.

[0112] Specifically, if the number of abnormal commands is consistent with the number of illegal commands, it means that the simulation filtering module has successfully identified all illegal commands, thereby proving that the technical solution proposed in the present invention can intercept illegal commands.

[0113] In a fourth embodiment of a firmware monitoring and protection method based on PFR and SPI bus proposed by the present invention, based on the first embodiment, the system further includes a management terminal (i.e., a terminal operated by a management personnel) capable of communicating with the configuration host; this embodiment further includes the following steps:

[0114] Step S410: the management terminal generates update verification information, wherein the update verification information includes an allowed update time period, and the start time of the allowed update time period is later than the current time.

[0115] Step S420: The management terminal sends the update verification information to the configuration host.

[0116] Step S430: The configuration host generates an update command based on the update verification information, and obtains the start time and end time of the update time period.

[0117] Step S440: If the interval between the current time and the start time of the update time period is less than a second preset time period (eg, 10 seconds), the configuration host stores the update command to the whitelist via the AHB bus.

[0118] Step S450: If the current time is consistent with the end time of the update time period, the filtering monitoring module deletes the update command from the whitelist.

[0119] Step S130 further includes the following steps:

[0120] Step S460: The command monitoring unit determines whether the first access command is an update command.

[0121] If yes, execute step S470: the command monitoring unit determines whether there is an update command in the whitelist.

[0122] Step S480: If there is an update instruction, the command operation unit allows the access host to update the firmware in the memory.

[0123] Step S490: If there is no update instruction, the command operation unit prohibits the host from updating the firmware in the memory.

[0124] Specifically, the update command is stored in the whitelist only when the update time period is approaching, and if the current time exceeds the update time period, the update command is deleted from the whitelist; this ensures that the access host can only execute the update command on the memory within the specified update time period, thereby improving security and reducing the risk of malicious modification and update of the firmware in the memory.

[0125] In a fifth embodiment of a firmware monitoring protection method based on PFR and SPI bus proposed by the present invention, based on the fourth embodiment, the update verification information also includes an allowed update source address, and the number of allowed update source addresses is multiple; step S420, and then further includes the following steps:

[0126] Step S510: The configuration host sends the allowed update source address in the update verification information to the filtering monitoring module.

[0127] Specifically, the running update source address here is the IP address of the access host that is allowed to perform firmware update on the memory.

[0128] Step S470 further includes the following steps:

[0129] Step S520: If there is an update instruction, the command monitoring unit obtains the IP address of the access host corresponding to the first access command.

[0130] Step S530: The command monitoring unit determines whether the IP address of the access host corresponding to the first access command is consistent with any allowed update source address.

[0131] Step S540: If they are consistent, the command operation unit allows the host to update the firmware in the memory.

[0132] Specifically, this embodiment locks the whitelist of access hosts that can perform firmware update on the memory, thereby prohibiting other access hosts that do not belong to the update source address from performing firmware update on the memory, thereby further ensuring data security of the firmware in the memory.

[0133] In a sixth embodiment of a firmware monitoring and protection method based on PFR and SPI bus proposed by the present invention, based on the first embodiment, this embodiment further includes the following steps:

[0134] Step S610: After the memory is newly added or updated with firmware, the filtering monitoring module performs a hash operation on the newly added or updated firmware to obtain a first hash value corresponding to the newly added or updated firmware.

[0135] Specifically, hashing, also known as hashing, is a process of converting data of any length into a fixed-length output (hash value) through a specific hash function. Through hashing, the integrity of the data can be verified.

[0136] Step S620: configure the host to perform an operation risk check on the memory every third preset time period (for example, 1 day) to obtain an operation risk value corresponding to the memory, where the operation risk value is used to express the operation risk of the memory. The larger the operation risk value, the higher the risk of the memory being attacked by the network.

[0137] Step S630: When the operation risk value is greater than the first preset value, the filtering monitoring module performs a hash operation on the current firmware in the memory to obtain a second hash value corresponding to the current firmware in the memory.

[0138] Step S640: The filtering monitoring module determines whether the first Hash value is consistent with the second Hash value.

[0139] If so, execute step S650: the filtering monitoring module assigns the operation risk value corresponding to the memory to a second preset value, wherein the second preset value is smaller than the first preset value, and when the operation risk value corresponding to the memory is the second preset value, it indicates that the risk of the memory being attacked by a network is low.

[0140] Specifically, if the first hash value and the second hash value are consistent, it means that the firmware in the memory has not been tampered with, and the operation risk value corresponding to the memory is directly assigned to the second preset value.

[0141] If not, execute step S660: the filtering monitoring module generates early warning feedback information.

[0142] Specifically, if the first hash value and the second hash value are inconsistent, it means that the firmware in the memory has been tampered with, and then early warning feedback information is directly generated.

[0143] In the seventh embodiment of the firmware monitoring protection method based on PFR and SPI bus proposed by the present invention, based on the sixth embodiment, the external device is connected to the access host through the Internet; step S140, and then further includes the following steps:

[0144] Step S710: The command operation unit marks the first access command as a risky command, and sends the risky command to the configuration host and the access host.

[0145] Step S72: The access host determines the source device corresponding to the risk command and obtains the IP address of the source device, wherein the source device is an external device that sends the risk command to the access host.

[0146] Step S730: The access host sends the IP address of the source device corresponding to the risk command to the configuration host.

[0147] Step S620 includes the following steps:

[0148] Step S740: The configuration host performs an operation risk check on the memory every third preset time period based on the risk command and the IP address of the source device corresponding to the risk command to obtain an operation risk value corresponding to the memory.

[0149] Specifically, the risky command here is the first access command intercepted by the filtering monitoring module. The more risky commands there are, the higher the security risk of the memory. Similarly, the higher the risk of the source device corresponding to the risky command, the higher the firmware risk of the corresponding memory.

[0150] In an eighth embodiment of a firmware monitoring and protection method based on PFR and SPI bus proposed by the present invention, based on the seventh embodiment, step S740 includes the following steps:

[0151] Step S810: The configuration host obtains the number of risk commands received from the command operation unit within the past third preset time period, and marks it as an abnormal number.

[0152] Step S820: The configuration host obtains the IP address of the source device corresponding to the risk command received from the access host within the third preset time period in the past, and marks it as an abnormal address.

[0153] Step S830: The configuration host obtains an input risk address set, wherein the risk address set includes at least one IP address of an external device that has been subject to network security attack behavior within a fourth preset period of time (eg, 10 days).

[0154] Specifically, the external devices corresponding to the IP addresses in the risk address set are high-risk external devices. If the abnormal address falls into the risk address set, it means that the risk of the storage being attacked by the network is higher.

[0155] Step S840: When the abnormal address falls into the risk address set, the configuration host marks the abnormal address as a target address.

[0156] Step S850: The configuration host calculates the operation risk value corresponding to the memory based on the number of exceptions, the number of exception addresses, and the number of target addresses.

[0157] Specifically, the operation risk value corresponding to the memory can be defined and calculated according to the number of exceptions, the number of exception addresses, and the number of target addresses.

[0158] In a ninth embodiment of a firmware monitoring protection method based on PFR and SPI bus proposed by the present invention, based on the eighth embodiment, the configuration host calculates the operation risk value corresponding to the memory based on the number of exceptions, the number of exception addresses, and the number of target addresses. The calculation formula is:

[0159]

[0160] In the formula, is the operation risk value corresponding to the memory, and the maximum value is 2; is an abnormal number; is the standard quantity, which is a positive integer (10 in this embodiment); is the number of target addresses; is the number of exception addresses.

[0161] Specifically, this embodiment proposes a specific calculation formula for calculating the operation risk value, and the operation risk value is proportional to the number of exceptions and to the ratio of the target address to the exception address; from the above formula, it can be seen that the maximum value of the operation risk value corresponding to the memory is 2, and the larger the operation risk value, the higher the risk of the memory being attacked by the network; in this embodiment, the first preset value is set to 1, and the second preset value is set to 0.

[0162] The present invention also proposes a firmware monitoring and protection system based on PFR and SPI bus, and applies a firmware monitoring and protection method based on PFR and SPI bus; the system includes a filtering monitoring module, a configuration host, an access host and a memory; the configuration host is connected to the filtering monitoring module via AHB bus communication; the memory and the filtering monitoring module are connected to the access host via SPI bus communication; the filtering monitoring module includes a command monitoring unit and a command operation unit; and the firmware is stored in the memory.

[0163] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0164] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation modes, which are merely illustrative rather than restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the present invention and the claims, all of which are within the protection of the present invention.

Claims

1. A firmware monitoring and protection method based on PFR and SPI bus, characterized in that: Applicable to a firmware monitoring and protection system based on PFR and SPI bus; the system includes a filtering monitoring module, a configuration host, an access host and a memory; The configuration host is connected to the filter monitoring module via AHB bus communication; The memory and the filter monitoring module are connected to the access host through SPI bus communication; the filter monitoring module includes a command monitoring unit and a command operation unit; The memory stores firmware; the system also includes a simulation test platform; The simulation test platform includes a simulation filtering module, a simulation configuration host, a simulation access host and a simulation memory; The simulation configuration host is communicatively connected to the simulation filtering module; The simulation memory and the simulation filtering module are both communicatively connected to the simulation access host; the method comprises: The host is configured to obtain a custom command, and the custom command is stored in a white list through an AHB bus, wherein the custom command is an operation command allowed to be performed on the firmware in the memory, and the number of the custom command is multiple; The command monitoring unit monitors the chip select signal of the access host to obtain a first data input signal sent by the access host to the memory through the SPI bus, and analyzes the first data input signal to obtain a corresponding first access command; The command monitoring unit determines whether the first access command is consistent with any custom command in the whitelist; If they are inconsistent, the command operation unit pulls up the chip select signal of the memory to prevent the communication connection between the access host and the memory; The simulation configuration host obtains the custom command and stores the custom command in the simulation filtering module; The simulated access host obtains a preset access command input, wherein the preset access command is multiple in number and the preset access command includes multiple commands that are different from the custom command; The simulated access host marks commands in the preset access commands that are different from the custom commands as illegal commands, and marks the number of the illegal commands as an illegal number; The emulated access host generates a data input signal corresponding to each preset access command and marks it as a second data input signal; Every first preset time period, the simulation access host sends each second data input signal to the simulation memory in sequence; The simulation filtering module obtains a second data input signal sent by the simulation access host to the simulation memory, and parses the second data input signal to obtain a corresponding second access command; The simulation filtering module determines in turn whether each second access command is consistent with any custom command in the simulation filtering module; If they are inconsistent, the simulation filtering module marks the second access command as an abnormal command; The simulation filtering module determines whether the number of abnormal commands is consistent with the illegal number; If so, the simulation filtering module generates first feedback information for indicating that the simulation verification has passed; If not, the simulation filtering module generates second feedback information for indicating that the simulation verification has not passed.

2. A firmware monitoring and protection method based on PFR and SPI bus according to claim 1, characterized in that: The filter monitoring module also includes a slave unit; the slave unit includes a whitelist register and an interrupt control register; The configuration host obtains the custom command and stores the custom command in the white list through the AHB bus, including: Configure the host to obtain custom commands and send the custom commands to the whitelist register through the AHB bus; The whitelist register stores the custom commands in the whitelist; If the communication connection between the host and the memory is inconsistent, the command operation unit is commanded to pull up the chip select signal of the memory to prevent access to the communication connection between the host and the memory, including: If they are inconsistent, the command operation unit generates an interrupt control signal through the interrupt control register; The command operation unit pulls up a chip selection signal of the memory based on the interrupt control signal to prevent access to a communication connection between the host and the memory.

3. The firmware monitoring and protection method based on PFR and SPI bus according to claim 1, characterized in that: The system also includes a management terminal capable of communicating with the configuration host; the method also includes: The management terminal generates update verification information, wherein the update verification information includes an allowed update time period, and the start time of the allowed update time period is later than the current time; The management terminal sends the update verification information to the configuration host; The configuration host generates an update command based on the update verification information, and obtains the start time and end time of the update time period; If the interval between the current time and the start time of the update time period is less than the second preset time period, the configuration host stores the update command to the whitelist via the AHB bus; If the current time is consistent with the end time of the update time period, the filter monitoring module deletes the update command from the whitelist; The command monitoring unit pulls down the chip select signal of the access host to obtain a first data input signal sent by the access host to the memory through the SPI bus, and parses the first data input signal to obtain a corresponding first access command, and then further includes: The command monitoring unit determines whether the first access command is an update command; If so, the command monitoring unit determines whether there is an update command in the whitelist; If there is an update instruction, the command operation unit allows the access host to update the firmware in the memory; If there is no update instruction, the command operation unit prohibits the access host from updating the firmware in the memory.

4. The firmware monitoring and protection method based on PFR and SPI bus according to claim 3 is characterized in that: The update verification information also includes an allowed update source address, and the number of allowed update source addresses is multiple; the management terminal sends the update verification information to the configuration host, and then also includes: The configuration host sends the allowed update source address in the update verification information to the filtering monitoring module; The command monitoring unit determines whether there is an update command in the white list, and then further includes: If there is an update instruction, the command monitoring unit obtains the IP address of the access host corresponding to the first access command; The command monitoring unit determines whether the IP address of the access host corresponding to the first access command is consistent with any allowed update source address; If they are consistent, the command operation unit allows the access host to update the firmware in the memory.

5. The firmware monitoring and protection method based on PFR and SPI bus according to claim 1, characterized in that: Also includes: After the memory is newly added or updated with firmware, the filtering monitoring module performs a hash operation on the newly added or updated firmware to obtain a first hash value corresponding to the newly added or updated firmware; The host is configured to perform an operation risk check on the storage once every third preset time period to obtain an operation risk value corresponding to the storage, wherein the operation risk value is used to express the operation risk of the storage, and the greater the operation risk value, the higher the risk of the storage being attacked by the network; When the operation risk value is greater than the first preset value, the filtering monitoring module performs a hash operation on the current firmware in the memory to obtain a second hash value corresponding to the current firmware in the memory; The filtering monitoring module determines whether the first hash value is consistent with the second hash value; If so, the filtering monitoring module assigns the operation risk value corresponding to the memory to a second preset value, wherein the second preset value is less than the first preset value; If not, the filtering monitoring module generates early warning feedback information.

6. The firmware monitoring and protection method based on PFR and SPI bus according to claim 5, characterized in that: The external device is connected to the access host through the Internet; if the two are inconsistent, the command operation unit pulls up the chip select signal of the memory to prevent the communication connection between the access host and the memory, and then includes: The command operation unit marks the first access command as a risk command, and sends the risk command to the configuration host and the access host; The access host determines the source device corresponding to the risk command and obtains the IP address of the source device, wherein the source device is an external device that sends the risk command to the access host; The access host sends the IP address of the source device corresponding to the risky command to the configuration host; The configuration host performs an operation risk check on the memory every third preset time period to obtain an operation risk value corresponding to the memory, including: The configuration host performs an operation risk check on the storage device every third preset time period based on the risk command and the IP address of the source device corresponding to the risk command to obtain an operation risk value corresponding to the storage device.

7. The firmware monitoring and protection method based on PFR and SPI bus according to claim 6 is characterized in that: The configuration host performs an operation risk check on the memory once every third preset time period based on the risk command and the IP address of the source device corresponding to the risk command to obtain an operation risk value corresponding to the memory, including: The configuration host obtains the number of risk commands received from the command operation unit within a third preset time period in the past, and marks the number as an abnormal number; The configuration host obtains the IP address of the source device corresponding to the risky command received from the access host within the third preset time period in the past, and marks it as an abnormal address; The host is configured to obtain an input risk address set, wherein the risk address set includes at least one IP address of an external device that has been subjected to a network security attack in the past fourth preset time period; When an abnormal address falls into the risk address set, the host is configured to mark the abnormal address as a target address; The configuration host calculates an operation risk value corresponding to the memory based on the number of exceptions, the number of exception addresses, and the number of target addresses.

8. The firmware monitoring and protection method based on PFR and SPI bus according to claim 7, characterized in that: The configuration host calculates the operation risk value corresponding to the memory based on the number of exceptions, the number of exception addresses, and the number of target addresses using the following calculation formula: In the formula, is the operation risk value corresponding to the memory, and the maximum value is 2; is an abnormal number; is the standard quantity, which is a positive integer; is the number of target addresses; is the number of exception addresses.

9. A firmware monitoring and protection system based on PFR and SPI bus, characterized in that: The firmware monitoring and protection method based on PFR and SPI bus as described in any one of claims 1 to 8 is applied; the system includes a filtering monitoring module, a configuration host, an access host and a memory; The configuration host is connected to the filter monitoring module via AHB bus communication; The memory and the filter monitoring module are connected to the access host through SPI bus communication; the filter monitoring module includes a command monitoring unit and a command operation unit; The memory stores firmware.

Citation Information

Patent Citations

  • Device for monitoring data access to internal storage device and internal storage device

    CN106295381A

  • Read controller based on bus interface

    CN114036096A