Key management method and chip starting method

By using a hierarchical key management method, the target key is determined according to the product stage and the state is stored in a hardware fuse register, which solves the problem of low security startup of electronic device chips and achieves reasonable access control and enhanced information security.

CN119760696BActive Publication Date: 2026-01-13HONOR DEVICE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311283771.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-28
Publication Date
2026-01-13
Estimated Expiration
2043-09-28

AI Technical Summary

Technical Problem

In existing technologies, the secure boot capability of electronic device chips is low, and key permissions are not managed in a hierarchical manner, leading to frequent information security problems.

Method used

A hierarchical key management method is adopted, which determines the target key according to the product stage and stores the key status through a hardware fuse register to ensure that personnel at each stage use different keys to start the chip, including commercial keys, R&D prototype keys, and R&D mass production keys.

Benefits of technology

It improves the security of electronic devices, prevents unauthorized personnel from tampering with chips, ensures reasonable access control at each stage, and enhances information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119760696B_ABST
    Figure CN119760696B_ABST
Patent Text Reader

Abstract

The application relates to the terminal field, in particular to a key management method and a chip starting method. The key management method comprises the following steps: obtaining a product stage to which an electronic device belongs; determining a target key according to the product stage; and configuring a chip of the electronic device according to the target key, so that the chip is started according to the target key. According to the embodiment of the application, the keys used for starting the chip of the electronic device are classified and managed, and different keys are used by personnel involved in different product stages according to different permissions to start the chip of the electronic device, so that the security of the electronic device is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of terminals, and in particular to a key management method and a chip boot method. Background Technology

[0002] Secure boot, also known as secure boot, is a technique that verifies the boot image at each level to ensure trusted firmware loading. Without secure boot, if the boot image is maliciously replaced, the system will ultimately run tampered firmware, rendering all security mechanisms built on top of the operating system ineffective.

[0003] Currently, electronic devices rely on a single key for secure booting of chips, and all personnel involved at each stage of the product development process (manufacturing, R&D, and maintenance personnel, etc.) possess access to this key. In this scenario, a leak of this key can trigger a series of information security problems. These include, for example, tampering with the original operating system of commercial devices, maliciously installing applications on commercial devices, misusing demo units as commercial devices, and illegally unlocking electronic devices. Summary of the Invention

[0004] This application provides a key management method and a chip boot method, which solves the problem of low security in the chip boot of electronic devices in the prior art.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] Firstly, a key management method is provided, including:

[0007] Determine the product stage to which the electronic device belongs;

[0008] Determine the target key based on the product stage;

[0009] Configure the chip of the electronic device according to the target key so that the chip starts according to the target key.

[0010] In some embodiments, the product stages of electronic devices are divided into three types: trial production stage, mass production stage, and repair stage.

[0011] Through the embodiments of this application, the keys used to start the electronic device chip are subject to hierarchical control. Personnel involved in each product stage use different keys to start the electronic device chip according to different permissions, thereby improving the security of electronic device use.

[0012] In one implementation of the first aspect, determining the target key based on the product stage includes:

[0013] If the product stage is the trial production stage, the target key is the first key and the second key;

[0014] If the product stage is the mass production stage, the target key is the first key;

[0015] If the product stage is the maintenance stage, the target key is the first key and the third key;

[0016] The mass production stage is after the trial production stage, and the maintenance stage is after the mass production stage.

[0017] For example, the first key is a commercial key, the second key is a research and development prototype key, and the third key is a research and development mass production key. The production personnel have access to the commercial key, the research and development personnel have access to the research and development prototype key, and the maintenance personnel have access to the research and development mass production key.

[0018] During the prototyping phase, the commercial key and the R&D prototyping key are active (valid), while the R&D mass production key is inactive. During this phase, manufacturers can use the commercial key to power the electronic device's chip, and R&D personnel can use the R&D prototyping key to power the electronic device's chip.

[0019] During the mass production phase, the commercial key is active, the R&D prototype key is revoked (invalid), and the R&D mass production key is inactive. At this stage, manufacturers can use the commercial key to power the electronic device's chip, while R&D personnel cannot.

[0020] During the repair phase, the commercial key is activated, the R&D / prototype key is revoked, and the R&D / mass production key is inactive. When electronic devices require repair, relevant repair personnel can apply to activate the R&D / mass production key. Once activated, the repair personnel can use the R&D / mass production key to start the electronic device's chip, while the manufacturing personnel can use the commercial key to start the chip. After repair, the R&D / mass production key can be revoked. Once revoked, repair personnel will no longer be able to start the electronic device's chip.

[0021] By employing the above method, the keys used to start the electronic device chip are subject to hierarchical control. Personnel involved in each product stage use different keys according to their different permissions to start the electronic device chip, thereby improving the security of electronic device use.

[0022] In one implementation of the first aspect, configuring the chip of the electronic device according to the target key includes:

[0023] During the trial production phase, the system version corresponding to the first key or the system version corresponding to the second key is loaded into the chip;

[0024] The system version corresponding to the first key is generated based on the digital certificate and the first signature value, and the system version corresponding to the second key is generated based on the digital certificate and the second signature value. The first signature value is the signature value obtained by signing the root certificate in the digital certificate based on the first key, and the second signature value is the signature value obtained by signing the root certificate in the digital certificate based on the second key.

[0025] For example, the first, second, or third signature value can be appended to the digital certificate and loaded together into the chip's boot image.

[0026] In one implementation of the first aspect, configuring the chip of the electronic device according to the target key includes:

[0027] During the trial production phase, a first hash value is generated based on the first key, the second key, and the third key;

[0028] A first enable signal is sent to the first register of the chip according to the first hash value, so as to blow the first fuse bit of the first register.

[0029] When the first fuse bit is in the blown state, the signal value of the first register matches the first hash value.

[0030] In some implementations, the public keys corresponding to the first, second, and third keys can be stored in different memories. Compared to this approach, the storage method described above not only saves registers but also ensures the integrity of the public keys for all root certificates.

[0031] It should be noted that when manufacturing chips for electronic devices, the initial state of each pin of the first register in the chip is made to be in an unfused state by means of hardware fuses.

[0032] In one implementation of the first aspect, configuring the chip of the electronic device according to the target key includes:

[0033] During the trial production phase, a second enable signal is sent to the second register of the chip to blow the second fuse bit of the second register;

[0034] When the second fuse bit is in the blown state, the signal value of the second register indicates that the first key and the second key are activated, and the third key is not activated.

[0035] The activation state of the key is divided into two types: active and inactive, which can be represented by signal values ​​1 and 0, respectively. The activation states of the first key, the second key, and the third key can be represented by the signal values ​​(bits) of different pins of the second register.

[0036] During the trial production phase, if the commercial key and the R&D trial production key are activated, but the R&D mass production key is not activated, then the bits in the second register corresponding to the commercial key and the R&D trial production key will both be 1, while the bits in the second register corresponding to the R&D mass production key will be 0. For example, if the signal value of the second register is 110, then the "1" in the first bit indicates that the commercial key is activated, the "1" in the second bit indicates that the R&D trial production key is activated, and the "0" in the third bit indicates that the R&D mass production key is not activated.

[0037] It should be noted that when manufacturing chips for electronic devices, the initial state of each pin of the second register in the chip is made to be in an unfused state by means of hardware fuses.

[0038] In one implementation of the first aspect, during the trial production stage, the signal value of the third register of the chip indicates that the first key, the second key, and the third key have not been revoked.

[0039] The revocation status of the key is divided into two types: revoked and not revoked, which can be represented by signal values ​​1 and 0, respectively. The revocation status of the three sets of keys can be represented by the signal values ​​(bits) of different pins of the third register.

[0040] During the trial production phase, the commercial key and the R&D trial production key are activated (not revoked), while the R&D mass production key is not activated (not revoked). Therefore, the bits in the third register corresponding to the commercial key, R&D trial production key, and R&D mass production key are all 1. For example, the signal value of the third register is 000, where the first bit "0" indicates the commercial key is not revoked, the second bit "0" indicates the R&D trial production key is not revoked, and the third bit "0" indicates the R&D mass production key is not revoked.

[0041] In this embodiment, the first register, second register, and third register can be fuse registers. A fuse register is a register that uses fuse technology to store data; for example, a programmable read-only memory (PROM) is a type of fuse register. The data stored in this type of register is determined by the fuse state. For example, if a register pin is in an open state, the corresponding signal value is 0; if the fuse of that pin is blown, i.e., the pin is in a blown state, the corresponding signal value is 1. A fuse register can blow the fuse of a pin based on a received enable signal, but once the fuse blows, it cannot be restored to an open state. Therefore, rewriting the data in a fuse register is usually irreversible.

[0042] In one implementation of the first aspect, configuring the chip of the electronic device according to the target key includes:

[0043] During the mass production phase, a third enable signal is sent to the third register of the chip to blow the third fuse bit of the third register.

[0044] When the third fuse bit is in the blown state, the signal value of the third register indicates that the first key has not been revoked, the second key has been revoked, and the third key has not been revoked.

[0045] In one implementation of the first aspect, configuring the chip of the electronic device according to the target key includes:

[0046] During the mass production phase, the system version corresponding to the first key is loaded into the chip;

[0047] The system version corresponding to the first key is generated based on the digital certificate and the first signature value, where the first signature value is the signature value obtained by signing the root certificate in the digital certificate based on the first key.

[0048] In this embodiment, during the mass production stage, the R&D mass production key is revoked, and the manufactured electronic devices can only boot the chip using a commercial key. Since R&D personnel do not have access to the commercial key, this effectively prevents them from tampering with the commercial devices, thereby improving the security of chip booting in commercial devices.

[0049] In one implementation of the first aspect, configuring the chip of the electronic device according to the target key includes:

[0050] During the maintenance phase, request activation of the third key;

[0051] If the application is approved, a fourth enable signal is sent to the second register of the chip to blow the fourth fuse bit of the second register;

[0052] When the fourth fuse bit is in the blown state, the signal value of the second register indicates that the first key, the second key, and the third key are all activated.

[0053] In one implementation of the first aspect, the application to activate the third key includes:

[0054] Obtain a fourth signature value and a configuration image, wherein the fourth signature value is a signature value obtained by a preset server signing the hash value of the configuration image according to the first key, the configuration image includes the hardware information of the electronic device, and the preset server is used to generate a digital certificate;

[0055] The fourth signature value is verified based on the first key;

[0056] If the verification passes, the configuration image is compared with the hardware information of the electronic device;

[0057] If the comparison matches, the application is approved.

[0058] For example, the execution terminal sends the hardware information of the electronic device to the certificate server (preset server); accordingly, after receiving the hardware information, the certificate server uses the private key of the commercial key to sign the configuration image (including hardware information and configuration information for activating the R&D mass production key) to obtain the fourth signature value, and returns the fourth signature value and the configuration image.

[0059] The steps for verifying the fourth signature value include: verifying the fourth signature value using the public key of the first key to obtain the hash value of the configuration image; comparing the hash value of the configuration image with the hash value of the received configuration image, and if they match, the verification is successful.

[0060] In one implementation of the first aspect, configuring the chip of the electronic device according to the target key includes:

[0061] During the maintenance phase, the system version corresponding to the first key or the system version corresponding to the third key is loaded into the chip;

[0062] Wherein, the system version corresponding to the first key is generated based on the digital certificate and the first signature value, the system version corresponding to the third key is generated based on the digital certificate and the third signature value, the first signature value is the signature value obtained by signing the root certificate in the digital certificate based on the first key, and the third signature value is the signature value obtained by signing the root certificate in the digital certificate based on the third key.

[0063] In one implementation of the first aspect, after sending a fourth enable signal to the second register of the chip, the method further includes:

[0064] After the maintenance task is completed, a fifth enable signal is sent to the third register of the chip to blow the fifth fuse bit of the third register;

[0065] When the fifth fuse bit is in the blown state, the signal value of the third register indicates that the first key has not been revoked, and the second key and the third key have been revoked.

[0066] In one implementation, the step of revoking the third key can be performed by the execution terminal of any station after the maintenance station.

[0067] In this embodiment of the application, the R&D mass production key is revoked in a timely manner after the repair is completed. This can effectively prevent the leakage of the R&D mass production key and avoid repair personnel from tampering with electronic devices through the R&D mass production key. While ensuring repair privileges, it also ensures the security of the electronic device chip startup.

[0068] In one implementation of the first aspect, the method further includes:

[0069] Obtain a first signal value and a second signal value, wherein the first signal value is the current signal value of the second register of the chip, and the second signal value is the current signal value of the third register of the chip;

[0070] The current key state is determined based on the first signal value and the second signal value;

[0071] Determine if the current key status is appropriate for the current product stage;

[0072] If the conditions are met, the electronic device is deemed to have passed verification.

[0073] If it does not meet the requirements, the key status is adjusted to make it conform to the current product stage.

[0074] In this embodiment of the application, by setting up a foolproof interception, the key status of the electronic device leaving the factory is further ensured to be consistent with the product stage, thereby improving the security of the electronic device chip startup.

[0075] In one implementation of the first aspect, determining the current key state based on the first signal value and the second signal value includes:

[0076] A first calculated value is obtained by performing an AND operation on the first signal value and the second signal value;

[0077] The current key state is determined based on the first calculated value.

[0078] The step of determining whether the current key status is consistent with the current product stage may include: if the current product stage is the trial production stage, and the key status is that the commercial key and the R&D trial production key are valid, while the R&D mass production key is invalid, then the current key status is consistent with the current product stage; otherwise, it is not consistent.

[0079] If the current product stage is the mass production stage, and the key status is that the commercial key is valid, the R&D trial production key and the R&D mass production key are invalid, then the current key status is consistent with the current product stage; otherwise, it is not.

[0080] Since the R&D mass production key can be used during the repair process, but needs to be revoked before leaving the factory after repair, if the current product stage is the repair stage and the key status is that the commercial key is valid, while the R&D prototype key and the R&D mass production key are invalid, then the current key status is consistent with the current product stage; otherwise, it is not.

[0081] In one implementation of the first aspect, the root certificate in the digital certificate includes a first certificate, a second certificate, a third certificate, and a fourth certificate, wherein the first certificate is a root certificate generated based on the first key, the second certificate is a root certificate generated based on the second key, the third certificate is a root certificate generated based on the third key, and the fourth certificate is a root certificate generated based on a random key.

[0082] It should be noted that if N sets of keys are used to generate digital certificates, the number of root certificates in the digital certificate can be N+1. That is, an additional root certificate generated based on a random key is added to ensure the integrity of the N root certificates. Because an additional root public key (the public key of the random key) is added, the hash value of the public key string can further guarantee the integrity of the N root certificates, thereby improving the security of chip boot.

[0083] In a second aspect, a chip boot method is provided, applied to a chip, wherein the chip is a chip configured according to the key control method described in any one of the first aspects, the method comprising:

[0084] Obtain a third signal value and a fourth signal value, wherein the third signal value is the current signal value of the second register of the chip, and the fourth signal value is the current signal value of the third register of the chip;

[0085] The target key is obtained based on the third signal value and the fourth signal value;

[0086] The chip is activated based on the target key.

[0087] In this embodiment, before the chip starts, a target key is determined based on the signal values ​​of the second and third registers, and then the chip is started using the target key. This method effectively prevents the chip from being started with an unauthorized key, thereby improving the security of chip startup.

[0088] In one implementation of the second aspect, obtaining the target key based on the third signal value and the fourth signal value includes:

[0089] A second calculated value is obtained by performing a bitwise AND operation on the third signal value and the fourth signal value.

[0090] The target key is determined based on the second calculated value.

[0091] It should be noted that in the above implementation, the order of the keys corresponding to each bit in the third signal value is the same as the order of the keys corresponding to each bit in the fourth signal value. In some application scenarios, if the order of the keys corresponding to each bit in the third signal value is different from the order of the keys corresponding to each bit in the fourth signal value, such as the first bit in the third signal value corresponding to a commercial key while the first bit in the fourth signal value does not correspond to a commercial key, a bitwise AND operation can be performed, that is, the bits representing the same key in the third and fourth signal values ​​can be ANDed. Of course, other methods for determining the key status can also be used, and this application embodiment does not specifically limit this.

[0092] In one implementation of the second aspect, the step of activating the chip according to the target key includes:

[0093] Verify the digital certificate using the target key;

[0094] If the verification passes, the chip is activated.

[0095] In one implementation of the second aspect, the root certificate in the digital certificate includes a first certificate, a second certificate, a third certificate, and a fourth certificate, wherein the first certificate is a root certificate generated based on the first key, the second certificate is a root certificate generated based on the second key, the third certificate is a root certificate generated based on the third key, and the fourth certificate is a root certificate generated based on a random key.

[0096] It should be noted that if N sets of keys are used to generate digital certificates, the number of root certificates in the digital certificate can be N+1. That is, an additional root certificate generated based on a random key is added to ensure the integrity of the N root certificates. Because an additional root public key (the public key of the random key) is added, the hash value of the public key string can further guarantee the integrity of the N root certificates, thereby improving the security of chip boot.

[0097] In one implementation of the second aspect, verifying the digital certificate based on the target key includes:

[0098] A second hash value is generated based on the first key, the second key, and the third key;

[0099] Obtain the third hash value from the first register of the chip;

[0100] Compare the second hash value with the third hash value;

[0101] If the comparison matches, the target signature value corresponding to the target key is decrypted according to the target key to obtain the fourth hash value of the root certificate;

[0102] The fifth hash value of the root certificate is calculated using a hash algorithm;

[0103] The fourth hash value is compared with the fifth hash value;

[0104] If the comparison matches, then verification is performed based on the root certificate corresponding to the target key.

[0105] In one implementation of the second aspect, when the target key is a first key, the target signature value corresponding to the target key is a first signature value; the verification based on the root certificate corresponding to the target key includes: verification based on the first certificate;

[0106] When the target key is the second key, the target signature value corresponding to the target key is the second signature value; the verification based on the root certificate corresponding to the target key includes: verification based on the second certificate;

[0107] When the target key is a third key, the target signature value corresponding to the target key is a third signature value; the verification based on the root certificate corresponding to the target key includes: verification based on the third certificate.

[0108] Thirdly, a chip system is provided, the chip system including a processor coupled to a memory, the processor executing a computer program stored in the memory to implement the method as described in any of the second aspects.

[0109] Fourthly, an electronic device is provided, the electronic device including a processor for running a computer program stored in a memory, such that the electronic device implements the method as described in any of the first aspects, or implements the method as described in any of the second aspects.

[0110] Fifthly, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program that, when executed by one or more processors, implements the method as described in any of the first aspects, or implements the method as described in any of the second aspects. Attached Figure Description

[0111] Figure 1 This is a schematic diagram of a digital certificate provided in an embodiment of this application;

[0112] Figure 2 This is a schematic diagram of a digital certificate provided in an embodiment of this application;

[0113] Figure 3 This is a schematic diagram of a digital certificate provided in another embodiment of this application;

[0114] Figure 4 This is a flowchart illustrating the workstation operations during the trial production stage provided in an embodiment of this application;

[0115] Figure 5 This is a flowchart illustrating the workstation operations during the mass production stage provided in an embodiment of this application.

[0116] Figure 6 This is a flowchart illustrating the key control method during the maintenance phase provided in an embodiment of this application;

[0117] Figure 7 This is a flowchart illustrating the key management method provided in an embodiment of this application;

[0118] Figure 8 This is a schematic flowchart of the chip startup method provided in the embodiments of this application. Detailed Implementation

[0119] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limiting purposes, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details.

[0120] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0121] It should also be understood that in the embodiments of this application, "one or more" refers to one, two, or more; "and / or" describes the relationship between the associated objects, indicating that three relationships can exist; for example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.

[0122] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0123] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0124] In this embodiment, the electronic device includes a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and main memory. The operating system can be any one or more computer operating systems that implement business processing through processes, such as Linux, Unix, Android, iOS, or Windows. The application layer includes applications such as browsers, address books, word processing software, and instant messaging software.

[0125] The electronic devices in this application embodiment can also be referred to as terminal devices, terminals, user equipment (UE), or user terminals, etc. For example, electronic devices can be mobile phones, tablets, handheld computers, wearable devices (such as smartwatches, smart bracelets, etc.), laptops, PDAs, personal computers, smart home devices (such as televisions, etc.), smart screens, game consoles, mobile internet devices (MID), smart point-of-sale (POS) terminals, augmented reality (AR) devices, and virtual reality (VR) devices, etc. This application embodiment does not impose any special limitations on the specific form of the electronic devices.

[0126] This application does not specifically limit the structure of the execution subject of the method provided in this application embodiment. As long as the method provided in this application embodiment can be executed by running a program that records the code of the method provided in this application embodiment.

[0127] Secure boot, also known as secure boot, is a technique that enables trusted firmware loading by verifying the boot image at each level. For example, in the basic workflow of an embedded system, starting with the bootrom, the system boots the Linux operating system through a second program loader (SPL) and then the universal boot loader (U-Boot). Assuming that the SPL, U-Boot, and Linux images are all stored in flash memory, each bootloader at each level must load the next-level boot image from flash and verify it. For instance, the bootrom loads the SPL boot image from flash, the SPL loads the U-Boot boot image from flash, and U-Boot loads the Linux boot image from flash. If secure boot is not performed in this boot process, and the images in flash memory are maliciously replaced, the system will ultimately run tampered firmware, rendering all security mechanisms built on top of the operating system ineffective.

[0128] Verification of the boot image can be achieved using specific cryptographic algorithms, such as asymmetric algorithms. Specifically, the hash value of the boot image is signed using the private key, and the signature value and certificate chain are appended to the image file to achieve the signing of the boot image. During system startup, the hash value of the boot image signature is verified using the public key that matches the private key, thereby verifying the legitimacy of the boot image.

[0129] In some application scenarios, multi-level verification can be set up to improve security. For example, multi-level digital certificates can be used to verify the boot image. See also Figure 1 This is a schematic diagram of a digital certificate provided in an embodiment of this application. Figure 1 The image shows a Level 3 digital certificate. This digital certificate includes a root certificate, a Level 2 certificate, and a Level 3 certificate. The root certificate includes the root public key, the root certificate signature, and the hash value of the Level 2 public key; the Level 2 certificate includes the Level 2 public key, the Level 2 certificate signature, and the hash value of the Level 3 public key; the Level 3 certificate includes the Level 3 public key, the Level 3 certificate signature, and the hash value of the boot image.

[0130] The certificate server uses the Level 3 private key to sign the hash value of the boot image, obtaining the Level 3 certificate signature; it then generates the Level 3 certificate using the Level 3 public key, the Level 3 certificate signature, and the boot image's hash value. Next, the Level 2 private key is used to sign the hash value of the Level 3 public key, obtaining the Level 2 certificate signature; this is then combined with the Level 2 public key, the Level 2 certificate signature, and the Level 3 public key's hash value to generate the Level 2 certificate. Finally, the root key is used to sign the hash value of the Level 2 public key, obtaining the root certificate signature; this is combined with the root public key, the root certificate signature, and the Level 2 public key's hash value to generate the root certificate. All three keys—the Level 3 private key, the Level 2 private key, and the root key—are stored in the certificate server.

[0131] In this embodiment of the application, the certificate server may be a Public Key Infrastructure (PKI) server.

[0132] The digital certificate can be integrated into the boot image file. The hash value of the root public key can be recorded in the fuse register inside the chip via a physical fuse.

[0133] The verification process for digital certificates includes root certificate verification, secondary certificate verification, and tertiary certificate verification.

[0134] The root certificate verification process may include: obtaining the root public key from the root certificate, calculating the hash value of the root public key using a hash algorithm, and matching it with the hash value of the root public key recorded in the fuse register inside the chip. If the match is successful, the root public key verification is successful.

[0135] The process of verifying a secondary certificate may include: verifying the signature of the root certificate using the root public key to obtain the hash value of the secondary public key, and matching it with the hash value of the secondary public key recorded in the root certificate; if the match is successful, the secondary certificate verification is successful.

[0136] The process of verifying a Level 3 certificate may include: verifying the signature of the Level 2 certificate using the Level 2 public key to obtain the hash value of the Level 3 public key, and matching it with the hash value of the Level 3 public key recorded in the Level 2 certificate; if the match is successful, the Level 3 certificate verification is successful.

[0137] If the Level 3 certificate verification is successful, the Level 3 public key in the Level 3 certificate can be used to verify the Level 3 certificate signature, obtain the hash value of the boot image, and match it with the hash value of the boot image recorded in the Level 3 certificate. If the match is successful, the boot image verification is successful. After successful boot image verification, the boot image can be executed, thereby starting the chip.

[0138] In some application scenarios, the product development stages of electronic devices are divided into three phases: trial production, mass production, and maintenance. The trial production stage refers to the production of a small number of electronic devices (or prototypes) for R&D personnel to develop and debug. The mass production stage refers to the mass production of electronic devices (or commercial devices) for market release and user purchase or use. The maintenance stage refers to the return of commercial devices to the factory for repair by technicians after a malfunction. Currently, the secure startup of chips in electronic devices relies on a single key, and all personnel involved in each product stage (manufacturing personnel, R&D personnel, and maintenance personnel, etc.) possess access to this key. In this situation, if the key is leaked, it will trigger a series of information security problems. These include, for example, tampering with the original operating system of commercial devices, maliciously installing applications on commercial devices, tampering with demo prototypes to resemble commercial devices, and illegally unlocking electronic devices.

[0139] Based on this, embodiments of this application provide a key management method. The method in these embodiments enables hierarchical control of key permissions, allowing personnel at different product stages to use different keys to activate the electronic device's chip according to their respective permissions, thereby improving the security of electronic device use.

[0140] For ease of explanation, this application uses the three product stages mentioned above as examples to illustrate the key management method of this application.

[0141] In this embodiment, different keys are set for different product stages, i.e., three sets of keys are set. For example, the three sets of keys are a commercial key, a research and development prototype key, and a research and development mass production key. The manufacturing personnel have access to the commercial key, the research and development personnel have access to the research and development prototype key, and the maintenance personnel have access to the research and development mass production key. The keys corresponding to each product stage are shown in the table below:

[0142]

[0143] It should be noted that the above are merely examples of three sets of keys, and this application does not specifically limit the number or name of the control keys. For example, during the trial production stage, if different production personnel are involved, a separate set of keys can be assigned to each of them. Furthermore, a commercial key can also be called a general-purpose key or a level-one key, while a research and development trial production key can be called a mass production key or a level-two key, and a research and development mass production key can also be called a maintenance key or a level-three key.

[0144] During the prototyping phase, the commercial key and the R&D prototyping key are active (valid), while the R&D mass production key is inactive. During this phase, manufacturers can use the commercial key to power the electronic device's chip, and R&D personnel can use the R&D prototyping key to power the electronic device's chip.

[0145] During the mass production phase, the commercial key is active, the R&D prototype key is revoked (invalid), and the R&D mass production key is inactive. At this stage, manufacturers can use the commercial key to power the electronic device's chip, while R&D personnel cannot.

[0146] During the repair phase, the commercial key is activated, the R&D / prototype key is revoked, and the R&D / mass production key is inactive. When electronic devices require repair, relevant repair personnel can apply to activate the R&D / mass production key. Once activated, the repair personnel can use the R&D / mass production key to start the electronic device's chip, while the manufacturing personnel can use the commercial key to start the chip. After repair, the R&D / mass production key can be revoked. Once revoked, repair personnel will no longer be able to start the electronic device's chip.

[0147] By employing the above method, the keys used to start the electronic device chip are subject to hierarchical control. Personnel involved in each product stage use different keys according to their different permissions to start the electronic device chip, thereby improving the security of electronic device use.

[0148] Each key set includes a public key and a private key. That is, a commercial key includes a public key and a private key, a research and development prototype key includes a public key and a private key, and a research and development mass production key includes a private key and a public key.

[0149] In some embodiments, the certificate server can generate digital certificates based on three sets of keys. Correspondingly, the three sets of keys correspond to three root certificates. For example, see [link to example]. Figure 2 This is a schematic diagram of a digital certificate provided in an embodiment of this application. Figure 2 As shown, a digital certificate includes three root certificates (root0, root1, and root2), a secondary certificate, and a tertiary certificate. The process by which a certificate server generates tertiary and secondary certificates can be found in [link to documentation]. Figure 1The following is a description of the implementation example: After generating the secondary certificate, the certificate server signs the hash value of the secondary certificate using the private key from the commercial key to obtain the root certificate root0 signature value. The public key of root certificate root0, the root certificate root0 signature value, and the hash value of the secondary public key are then used to generate root certificate root0; the public key of root certificate root0 is the public key in the commercial key. The certificate server signs the hash value of the secondary certificate using the private key from the R&D prototype key to obtain the root certificate root1 signature value. The public key of root certificate root1, the root certificate root1 signature value, and the hash value of the secondary public key are then used to generate root certificate root1; the public key of root certificate root1 is the public key in the R&D prototype key. The certificate server signs the hash value of the secondary certificate using the private key from the R&D mass production key to obtain the root certificate root2 signature value. The public key of root certificate root2, the root certificate root2 signature value, and the hash value of the secondary public key are then used to generate root certificate root2; the public key of root certificate root2 is the public key in the R&D mass production key.

[0150] The private keys for the commercial key, the R&D prototype key, and the R&D mass production key are stored in a certificate server. The public keys for these three keys are concatenated into a public key string. A hash value for this public key string is calculated using a hash algorithm, and this hash value is recorded in a fuse register inside the chip via a physical fuse. Since any change to any public key will result in a change to the hash value of the public key string, this method effectively verifies whether the public key has been tampered with, thereby improving the security of the chip's boot process.

[0151] To enhance the security of digital certificates, in some embodiments, a root certificate may be added to the digital certificate. For example, see [link to example]. Figure 3 This is a schematic diagram of a digital certificate provided in another embodiment of this application. Figure 3 As shown, the digital certificate includes four root certificates (root0, root1, root2, and root3), a secondary certificate, and a tertiary certificate. Root3 is an additional root certificate. The certificate server can generate the root certificate root3 using a set of random keys. Specifically, after generating the secondary certificate, the certificate server uses the private key from the random key to sign the hash value of the secondary certificate, obtaining the root certificate root3 signature value. The public key of root certificate root3, the root certificate root3 signature value, and the hash value of the secondary public key are then used to generate root certificate root3; the public key of root certificate root3 is the public key from the random key.

[0152] The private keys for the commercial key, the R&D prototype key, the R&D mass production key, and the random key are stored in the certificate server. The public keys for these keys are concatenated into a public key string. A hash value for this public key string is calculated using a hash algorithm and recorded in the chip's internal fuse register via a physical fuse. The addition of a root public key (the public key of the random key) further ensures the integrity of the three root certificates (root0, root1, and root2), thereby improving the security of the chip's boot process.

[0153] It should be noted that the above is an example of using three sets of keys to generate a digital certificate. If N sets of keys are used to generate a digital certificate, the number of root certificates in the digital certificate can be N+1, that is, an additional root certificate generated based on a random key is added to ensure the integrity of the N root certificates.

[0154] It should be noted that different types of electronic devices use different sets of keys. For example, the commercial key for Model I mobile phone differs from that for Model II mobile phone; the commercial key for Model I mobile phone differs from the R&D / prototype key for Model II mobile phone; and the commercial key for Model I mobile phone also differs from the R&D / mass production key for Model II mobile phone. Furthermore, mobile phones and tablets produced by the same manufacturer may have different commercial keys, R&D / prototype keys, and R&D / mass production keys. Finally, electronic devices produced in different batches may have different commercial keys, R&D / prototype keys, and R&D / mass production keys.

[0155] In this embodiment, a fuse register is a register that uses fuse technology to store data, such as a programmable read-only memory (PROM). The data stored in this type of register is determined by the fuse state. For example, if a pin of the register is in an open state, the corresponding signal value is 0; if the fuse of the pin is blown, i.e., the pin is in a blown state, the corresponding signal value is 1. The fuse register can blow the fuse of a certain pin based on the received enable signal, but once the fuse blows, it cannot be restored to an open state. Therefore, rewriting the data in a fuse register is usually irreversible.

[0156] Based on the three product stages shown in the table above and the aforementioned digital certificates, the key management method of this application embodiment will be described in detail below.

[0157] Scenario 1: Trial Production Stage

[0158] The trial production stage may include the following steps:

[0159] 1-1. Generate three system versions based on the digital certificate, the first signature value, the second signature value, and the third signature value.

[0160] The certificate server calculates the root certificate (e.g., ...) in the digital certificate using a hash algorithm. Figure 3 As shown, the root certificate contains hash values ​​of root0, root1, root2, and root3. The hash values ​​of the root certificate are signed using the private key of the commercial key to obtain the first signature value; the hash values ​​of the root certificate are signed using the private key of the R&D prototype key to obtain the second signature value; the hash values ​​of the root certificate are signed using the private key of the R&D mass production key to obtain the third signature value; the first signature value, the second signature value, the third signature value, and the digital certificate are then sent to the execution terminal (e.g., ...). Figure 4 The execution terminal generates three system versions based on the digital certificate, the first signature value, the second signature value, and the third signature value. Specifically, a system version corresponding to the commercial key is generated based on the digital certificate and the first signature value, and this system version can be started by the commercial key; a system version corresponding to the R&D prototype key is generated based on the digital certificate and the second signature value, and this system version can be started by the R&D prototype key; a system version corresponding to the R&D mass production key is generated based on the digital certificate and the third signature value, and this system version can be started by the R&D mass production key.

[0161] 1-2. Load the system version corresponding to the trial production stage into the chip of the electronic device.

[0162] The execution terminal loads the system version into the chip of the electronic device, thereby refreshing the system. During the trial production phase, the chip can be started using a commercial key or a research and development trial key. In this case, the execution terminal can load the system version corresponding to the commercial key into the chip of the electronic device, or the system version corresponding to the research and development trial key into the chip of the electronic device.

[0163] In some implementations, a flag can be set, such as in the mirror frame header, to indicate which key is currently being used.

[0164] For example, the first, second, or third signature value can be appended to the digital certificate and loaded together into the chip's boot image.

[0165] 1-3. Record the hash value (first hash value) of the public key string of the root certificate of the digital certificate in the first register (fuse register) inside the chip through a physical fuse.

[0166] Of course, the public keys of the four root certificates can also be stored in different registers. Compared with this method, the storage method described in 1-3 not only saves registers but also ensures the integrity of the public keys of the four root certificates.

[0167] It should be noted that when manufacturing chips for electronic devices, the initial state of each pin of the first register in the chip is made to be in an unfuse state using hardware fuses. The specific process of executing steps 1-3 includes: executing the terminal (such as...) Figure 4 The execution terminal at workstation 1 sends a first enable signal to the first register of the chip based on the hash value of the public key string of the root certificate, so as to blow the first fuse bit of the first register; after the first fuse bit of the first register blows, the signal value of the first register matches the hash value of the public key string of the root certificate.

[0168] For example, the hash value of the public key string of the root certificate is 111000, and the initial signal value of the first register is 000000. The first enable signal can blow the first fuse bit (including the first three bits) of the first register. After the first fuse bit blows, the signal value of the first register is 111000.

[0169] 1-4. The activation status of each of the three sets of keys is recorded in the second register (fuse register) inside the chip by means of physical fuses.

[0170] The activation state of the key is divided into two types: active and inactive, which can be represented by signal values ​​1 and 0, respectively. The activation states of the three sets of keys can be represented by the signal values ​​(bits) of different pins of the second register.

[0171] As shown in the table above, during the trial production stage, the commercial key and the R&D trial production key are activated, while the R&D mass production key is not activated. Therefore, the bits in the second register corresponding to the commercial key and the R&D trial production key are both 1, and the bits in the second register corresponding to the R&D mass production key are 0. For example, the signal value of the second register is 110, where the "1" in the first bit indicates that the commercial key is activated, the "1" in the second bit indicates that the R&D trial production key is activated, and the "0" in the third bit indicates that the R&D mass production key is not activated. In this embodiment, the order of the pins of the second registers corresponding to the three sets of keys is not specifically limited.

[0172] It should be noted that when manufacturing chips for electronic devices, the initial state of each pin of the second register in the chip is made to be in an unfuse state using hardware fuses. The specific process of executing steps 1-4 includes: executing the terminal (such as...) Figure 4 After the execution terminal at workstation 1 sends the second enable signal to the second register, the second fuse bit (the bit corresponding to the R&D mass production key) of the second register is blown; when the second fuse bit is blown, the signal value of the second register indicates that the commercial key and the R&D trial production key are activated, and the R&D mass production key is not activated.

[0173] For example, the initial signal value of the second register is 000. The second enable signal can blow the second fuse bit of the second register (such as the first and second bits). After the second fuse bit blows, the signal value of the second register is 110, indicating that the commercial key and the R&D prototype key are activated, while the R&D mass production key is not activated.

[0174] 1-5. Record the revocation status of each of the three sets of keys in the third register (fuse register) inside the chip using physical fuses.

[0175] The revocation status of the key is divided into two types: revoked and not revoked, which can be represented by signal values ​​1 and 0, respectively. The revocation status of the three sets of keys can be represented by the signal values ​​(bits) of different pins of the third register.

[0176] As shown in the table above, during the trial production phase, the commercial key and the R&D trial production key are activated (not revoked), while the R&D mass production key is not activated (not revoked). Therefore, the bits of the third register corresponding to the commercial key, the R&D trial production key, and the R&D mass production key are all 0. For example, the signal value of the third register is 000, where the "0" in the first bit indicates that the commercial key is not revoked, the "0" in the second bit indicates that the R&D trial production key is not revoked, and the "0" in the third bit indicates that the R&D mass production key is not revoked. In this embodiment, the order of the pins of the third register corresponding to the three sets of keys is not specifically limited.

[0177] It should be noted that when manufacturing chips for electronic devices, the initial state of each pin of the third register in the chip is made unfrozen using hardware fuses. Since none of the three sets of keys were revoked during the trial production phase, the execution terminal (such as...) Figure 4 The execution terminal at workstation 1 does not need to send an enable signal to the third register. The signal value of the third register remains the initial value, such as 000, indicating that the commercial key, the R&D trial production key activation, and the R&D mass production key have not been revoked.

[0178] It should be noted that steps 1-3 to 1-5 above are not in any particular order and can be executed in parallel or sequentially.

[0179] In some application scenarios, the prototyping stage includes multiple production stations. The above steps can be performed by the execution terminal of the same station or by the execution terminals of different stations.

[0180] For example, see Figure 4 This is a flowchart illustrating the workstation operations during the trial production stage provided in an embodiment of this application. It is intended as an example and not a limitation. Figure 4As shown, the certificate server generates a digital certificate based on the certificate application and sends the digital certificate, the first signature value, the second signature value, and the third signature value to the execution terminal for creating the version. The execution terminal for creating the version executes step 1-1 above to generate three system versions. In the trial production stage 51, the execution terminal at workstation 1 (such as the high-dimensional board information inspection (BC) process) can perform the certificate loading and key activation steps. The certificate loading step can include steps 1-2 above, and the key activation step can include steps 1-3 to 1-5. After workstation 1, the personnel at workstation 2 (such as the board workstation) can use a commercial key or a research and development trial production key to start the chip of the electronic device.

[0181] Scenario 2: Mass Production Stage

[0182] The mass production stage may include the following steps:

[0183] 2-1. Send a third enable signal to the third register to blow the third fuse bit of the third register (the bit corresponding to the R&D trial production key); whereby, after the third fuse bit blows, the signal value of the third register indicates that the commercial key has not been revoked, the R&D trial production key has been revoked, and the R&D mass production key has not been revoked.

[0184] Continuing with the example in 1-5, the initial signal value of the third register is 000, indicating that the commercial key, R&D prototype key, and R&D mass production key have not been revoked. The execution terminal sends a third enable signal to the third register to blow the bit corresponding to the R&D mass production key (the third fuse bit). After the third fuse bit blows, the signal value of the third register changes to 010, indicating that the commercial key, R&D prototype key, and R&D mass production key have not been revoked.

[0185] For example, see Figure 5 This is a flowchart illustrating the workstation operations during the mass production stage, as provided in an embodiment of this application. It is intended as an example and not a limitation. Figure 5 As shown, after the trial production stage 51, the mass production stage 52 begins. In the mass production stage 52, the execution terminal at workstation 3 (such as the equipment downgrade workstation) performs the above steps 2-1 to revoke the R&D trial production key.

[0186] 2-2. Load the system version corresponding to the mass production stage into the chip of the electronic device.

[0187] During mass production, if a commercial key can boot the chip, the system version corresponding to the commercial key is loaded into the chip of the electronic device. In some application scenarios, if a commercial key is used to boot the chip during the trial production stage, there is no need to reload the version during mass production. If a research and development prototype key is used to boot the chip during the trial production stage, the version is refreshed during mass production, that is, the system version corresponding to the commercial key is loaded into the chip of the electronic device.

[0188] In this embodiment, during the mass production stage, the R&D prototype key is revoked, and the manufactured electronic devices can only boot the chip using a commercial key. Since R&D personnel do not have access to the commercial key, this effectively prevents them from tampering with the commercial devices, thereby improving the security of chip booting in commercial devices.

[0189] Scenario 3: Maintenance Phase

[0190] The maintenance phase may include the following steps:

[0191] 3-1. Send the hardware information of the electronic device to the certificate server to request a fourth signature value.

[0192] Accordingly, after receiving the hardware information, the certificate server uses the private key of the commercial key to sign the hash value of the configuration image (including hardware information and configuration information for activating the R&D mass production key) to obtain the fourth signature value, and returns the fourth signature value and the configuration image.

[0193] 3-2. After receiving the fourth signature value and configuration image, load the fourth signature value and configuration image into the chip of the electronic device.

[0194] 3-3. Verify the fourth signature value using the public key of the commercial key.

[0195] Specifically, the fourth signature value is verified using the public key of the commercial key to obtain the hash value of the configuration image; the hash value of the configuration image is compared with the hash value of the received configuration image, and if they match, the verification is successful.

[0196] 3-4. If the verification passes, the hardware information in the configuration image will be compared with the hardware information of the electronic device.

[0197] 3-5. If the comparison is consistent, a fourth enable signal is sent to the second register to blow the fourth fuse bit (the bit corresponding to the R&D mass production key) of the second register.

[0198] When the fourth fuse bit blows, the signal value of the second register indicates whether the commercial key is activated, the R&D trial production key is activated, or the R&D mass production key is activated.

[0199] Continuing with the example in steps 1-4, during the trial production and mass production stages, the signal value of the second register is 110, indicating that the commercial key and the R&D trial production key are activated, while the R&D mass production key is not activated. After sending the fourth enable signal to the second register, the fourth fuse bit (the third bit) blows, and the signal value of the second register changes to 111, indicating that the commercial key, the R&D trial production key, and the R&D mass production key are activated.

[0200] 3-6. Load the system version corresponding to the maintenance phase into the chip of the electronic device.

[0201] During the repair phase, both commercial keys and R&D / mass production keys can be used to boot the chip. In some application scenarios, if a commercial key is used to boot the chip during the repair phase, there is no need to reload the version. However, if an R&D / mass production key is used to boot the chip during the repair phase, the version needs to be refreshed, meaning the system version corresponding to the R&D / mass production key is loaded into the electronic device's chip.

[0202] In some application scenarios, steps 3-1 to 3-2 above can be executed by a separate server, and steps 3-3 to 3-5 can be executed by electronic devices.

[0203] For example, see Figure 6 This is a flowchart illustrating the key management method during the maintenance phase provided in an embodiment of this application. It is intended as an example and not a limitation. Figure 6 As shown, the IT server obtains the hardware information of the electronic device (which can be input by the user or obtained through interaction with the electronic device) and sends this hardware information to the certificate server. The certificate server generates a fourth signature value based on the hardware information and returns the fourth signature value and configuration image to the IT server. The IT server executes step 3-2, which loads the fourth signature value and configuration image into the chip of the electronic device. The electronic device performs signature verification (steps 3-3 and 3-4) and key activation (step 3-5). Then, the electronic device is returned to the factory for repair, and the system version is updated to the system version corresponding to the repair stage. During the factory repair process, repair personnel can activate the chip of the electronic device using the R&D mass production key.

[0204] Due to the different types of malfunctions in electronic equipment, returned electronic equipment may be sent to different workstations for repair. For example... Figure 6 As shown, in scenario ①, the device may be sent to workstation 1; in scenario ②, it may be sent to workstation 2; and in scenario ③, it may be sent to workstation 3. As described in the above embodiment, workstation 1 can be considered the first process, workstation 2 can be considered an intermediate process, and workstation 3 can be considered the final process. After the electronic device is repaired and shipped, if the R&D mass production key is still active, the repair personnel can use the R&D mass production key to tamper with the electronic device.

[0205] To prevent the above situation from occurring, in some embodiments, the R&D mass production key can be revoked before the electronic device leaves the factory for repair. Specifically, the step of revoking the R&D mass production key may include: sending a fifth enable signal to a third register to blow the fifth fuse bit of the third register; wherein, when the fifth fuse bit blows, the signal value of the third register indicates that the commercial key has not been revoked, the R&D prototype key has been revoked, and the R&D mass production key has been revoked.

[0206] Continuing with the example in 2-1, during the mass production stage, the signal value of the third register becomes 010, indicating that the commercial key, the R&D prototype key, and the R&D mass production key have not been revoked. Before leaving the factory for repair, a fifth enable signal is sent to the third register, causing the fifth fuse bit (the third bit) to blow. The signal value of the third register then becomes 011, indicating that the commercial key, the R&D prototype key, and the R&D mass production key have not been revoked.

[0207] In one implementation, the step of revoking the R&D mass production key can be performed by the execution terminal of any workstation after the repair workstation. For example, if the electronic device returns to workstation 1 (repair workstation), the R&D mass production key can be revoked by the execution terminal of workstation 1, workstation 2, or workstation 3 after the electronic device is repaired at workstation 1. If the electronic device returns to workstation 3, the R&D mass production key can be revoked by the execution terminal of workstation 3.

[0208] In this embodiment of the application, the R&D mass production key is revoked in a timely manner after the repair is completed. This can effectively prevent the leakage of the R&D mass production key and avoid repair personnel from tampering with electronic devices through the R&D mass production key. While ensuring repair privileges, it also ensures the security of the electronic device chip startup.

[0209] In some embodiments, a foolproof interception station can be set up before shipment. The execution terminal at this station performs the foolproof interception steps. Specifically, the foolproof interception steps may include: obtaining the current signal value (first signal value) of the second register and the current signal value (second signal value) of the third register; determining the current key state based on the first and second signal values; determining whether the current key state conforms to the current product stage; if it conforms, determining that the electronic device verification has passed; if it does not conform, adjusting the key state to conform to the current product stage.

[0210] In one implementation, the step of determining the current key state based on the first signal value and the second signal value may include: performing a bitwise AND operation on the first signal value and the second signal value to obtain a first calculated value; and determining the current key state based on the first calculated value.

[0211] For example, the first bit of both the first and second signal values ​​corresponds to the commercial key, the second bit corresponds to the R&D prototype key, and the third bit corresponds to the R&D mass production key. When the first signal value is 110 and the second signal value is 000, the first calculated value is 001, and the key status is that the commercial key and the R&D prototype key are valid, while the R&D mass production key is invalid. When the first signal value is 110, the second signal value is 010, and the first calculated value is 011, the key status is that the commercial key is valid, while the R&D prototype key and the R&D mass production key are invalid. When the first signal value is 111, the second signal value is 010, and the first calculated value is 010, the key status is that the commercial key is valid, the R&D prototype key is invalid, and the R&D mass production key is valid; when the first signal value is 111, the second signal value is 011, and the first calculated value is 011, the key status is that the commercial key is valid, while the R&D prototype key and the R&D mass production key are invalid.

[0212] If the current product stage is the trial production stage, and the key status is that the commercial key and the R&D trial production key are valid, while the R&D mass production key is invalid, then the current key status is consistent with the current product stage; otherwise, it is not.

[0213] If the current product stage is the mass production stage, and the key status is that the commercial key is valid, the R&D trial production key and the R&D mass production key are invalid, then the current key status is consistent with the current product stage; otherwise, it is not.

[0214] Since the R&D mass production key can be used during the repair process, but needs to be revoked before leaving the factory after repair, if the current product stage is the repair stage and the key status is that the commercial key is valid, while the R&D prototype key and the R&D mass production key are invalid, then the current key status is consistent with the current product stage; otherwise, it is not.

[0215] It should be noted that in the above implementation, the order of the keys corresponding to each bit in the first signal value is the same as the order of the keys corresponding to each bit in the second signal value. In some application scenarios, if the order of the keys corresponding to each bit in the first signal value is different from the order of the keys corresponding to each bit in the second signal value, such as the first bit in the first signal value corresponding to a commercial key while the first bit in the second signal value does not correspond to a commercial key, a bitwise AND operation can be performed, that is, the bits representing the same key in the first and second signal values ​​can be ANDed. Of course, other methods for determining the key status can also be used, and this application embodiment does not specifically limit this.

[0216] In some implementations, if the current key status does not match the current product stage, the key status can be adjusted by the execution terminal of the error prevention interception station, or by the execution terminal of the station before the error prevention interception station.

[0217] Specifically, the key state can be adjusted by sending an enable signal to the third register.

[0218] For example, see Figure 7 This is a flowchart illustrating the key management method provided in an embodiment of this application. Figure 7 As shown, a workstation 4 (such as the customer writer (CW) process) is added before shipment. The execution terminal at workstation 4 performs the aforementioned error-proofing interception steps. If the current key status matches the current product stage, the electronic device is deemed to have passed verification and can be shipped; if the current key status does not match the current product stage, the process returns to workstation 3, where the execution terminal adjusts the key status to match the current product stage.

[0219] In this embodiment of the application, by setting up a foolproof interception, the key status of the electronic device leaving the factory is further ensured to be consistent with the product stage, thereby improving the security of the electronic device chip startup.

[0220] Based on the above key management method, this application provides a chip boot method, which is applied to the chip of an electronic device. See also... Figure 8 This is a schematic flowchart of the chip startup method provided in an embodiment of this application. It is intended as an example and not a limitation. Figure 8 As shown, the chip startup method may include the following steps:

[0221] S801, obtain the third signal value and the fourth signal value.

[0222] The third signal value is the signal value of the second register of the current chip, and the fourth signal value is the signal value of the third register of the current chip.

[0223] S802, obtain the target key based on the third signal value and the fourth signal value.

[0224] In some implementations, step S802 may include:

[0225] Perform a bitwise AND operation on the third and fourth signal values ​​to obtain the second calculated value; determine the target key based on the second calculated value.

[0226] For example, the first bit of both the third and fourth signal values ​​corresponds to the commercial key, the second bit corresponds to the R&D prototype key, and the third bit corresponds to the R&D mass production key. When the third signal value is 110 and the fourth signal value is 000, the second calculated value is 001, indicating that the commercial key and the R&D prototype key are valid, while the R&D mass production key is invalid; therefore, the target key is the commercial key and the R&D prototype key. When the third signal value is 110, the fourth signal value is 010, and the second calculated value is 011, indicating that the commercial key is valid, while the R&D prototype key and the R&D mass production key are invalid; therefore, the target key is the commercial key. When the third signal value is 111, the fourth signal value is 010, and the second calculated value is 010, indicating that the commercial key is valid, the R&D prototype key is invalid, and the R&D mass production key is valid; therefore, the target key is the commercial key and the R&D mass production key.

[0227] It should be noted that in the above implementation, the order of the keys corresponding to each bit in the third signal value is the same as the order of the keys corresponding to each bit in the fourth signal value. In some application scenarios, if the order of the keys corresponding to each bit in the third signal value is different from the order of the keys corresponding to each bit in the fourth signal value, such as the first bit in the third signal value corresponding to a commercial key while the first bit in the fourth signal value does not correspond to a commercial key, a bitwise AND operation can be performed, that is, the bits representing the same key in the third and fourth signal values ​​can be ANDed. Of course, other methods for determining the key status can also be used, and this application embodiment does not specifically limit this.

[0228] S803, the chip is started according to the target key.

[0229] In one implementation, step S803 may include:

[0230] Verify the digital certificate using the target key; if the verification is successful, then activate the chip.

[0231] Specifically, the process of verifying a digital certificate based on the target key includes:

[0232] Generate a public key string based on the public key of the root certificate in the digital certificate; calculate the second hash value of the public key string using a hash algorithm; obtain the third hash value from the first register (e.g., ...). Figure 3 The hash values ​​of the public key strings of the four root certificates shown are used; the second hash value is compared with the third hash value; if they match, the target signature value corresponding to the target key is verified according to the target key to obtain the fourth hash value of the root certificate; the fifth hash value of the root certificate in the digital certificate is calculated by a hash algorithm; the fourth hash value is compared with the fifth hash value; if they match, the digital certificate is verified according to the root certificate.

[0233] Verifying digital certificates based on root certificates includes verifying secondary certificates based on root certificates, and verifying tertiary certificates based on secondary certificates. The specific verification steps are as follows: Figure 1 The principle is the same in the embodiments; for details, please refer to [link / reference]. Figure 1 The verification process for Level 2 and Level 3 certificates in the embodiments will not be described in detail here.

[0234] For example, as described in step 1-1, the commercial key corresponds to the first signature value, the R&D trial production key corresponds to the second signature value, and the R&D mass production key corresponds to the third signature value.

[0235] When the target key is a commercial key, a public key string is generated based on the public key of the root certificate in the digital certificate. A second hash value is calculated using a hash algorithm. A third hash value is retrieved from the first register. The second and third hash values ​​are compared. If they match, the first signature value is verified using the public key of the commercial key to obtain the fourth hash value of the root certificate. A fifth hash value of the root certificate in the digital certificate is calculated using a hash algorithm. The fourth and fifth hash values ​​are compared. If they match, the digital certificate is verified using the root certificate root0. root0 includes a signature value sign0 obtained by signing the secondary public key using the private key of the commercial key, and the hash value of the secondary public key. During verification, the signature value sign0 is decrypted using the public key of the commercial key to obtain the hash value of the secondary public key, and compared with the hash value of the secondary public key recorded in root0. If they match, the secondary certificate is successfully verified, and then the tertiary public key is verified using the secondary public key.

[0236] When the target key is a research and development trial key, a public key string is generated based on the public key of the root certificate in the digital certificate. A second hash value is calculated using a hash algorithm. A third hash value is retrieved from the first register. The second hash value is compared with the third hash value. If they match, the second signature value is verified using the public key of the research and development trial key to obtain the fourth hash value of the root certificate. A fifth hash value of the root certificate in the digital certificate is calculated using a hash algorithm. The fourth hash value is compared with the fifth hash value. If they match, the digital certificate is verified based on the root certificate root1. root1 includes a signature value sign1 obtained by signing the secondary public key using the private key of the research and development trial key, and the hash value of the secondary public key. During verification, the signature value sign1 is decrypted using the public key of the research and development trial key to obtain the hash value of the secondary public key, and compared with the hash value of the secondary public key recorded in root1. If they match, the secondary certificate verification is successful, and then the tertiary public key is verified based on the secondary public key.

[0237] When the target key is a production-ready key, a public key string is generated based on the public key of the root certificate in the digital certificate. A second hash value is calculated using a hash algorithm. A third hash value is retrieved from the first register. The second and third hash values ​​are compared. If they match, the third signature value is verified using the public key of the production-ready key to obtain the fourth hash value of the root certificate. A fifth hash value of the root certificate in the digital certificate is calculated using a hash algorithm. The fourth and fifth hash values ​​are compared. If they match, the digital certificate is verified using the root certificate root2. root2 includes a signature value sign2 obtained by signing the secondary public key using the private key of the production-ready key, and the hash value of the secondary public key. During verification, the signature value sign2 is decrypted using the public key of the production-ready key to obtain the hash value of the secondary public key, and compared with the hash value of the secondary public key recorded in root2. If they match, the secondary certificate verification is successful, and then the tertiary public key is verified using the secondary public key.

[0238] In this embodiment, before the chip starts, a target key is determined based on the signal values ​​of the second and third registers, and then the chip is started using the target key. This method effectively prevents the chip from being started with an unauthorized key, thereby improving the security of chip startup.

[0239] It should be noted that this embodiment uses three sets of keys as an example. In some application scenarios, the product can be divided into more or fewer stages according to actual needs, and correspondingly, more or fewer keys can be set. This embodiment does not specifically limit the number of product stages or the number of keys.

[0240] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0241] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement the steps in the above-described method embodiments.

[0242] This application also provides a computer program product that, when run on a first device, enables the first device to implement the steps described in the various method embodiments above.

[0243] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying the computer program code to the first device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.

[0244] This application also provides a chip system, which includes a processor coupled to a memory. The processor executes a computer program stored in the memory to implement the steps of the chip startup method embodiment of this application. The chip system can be a single chip or a chip module composed of multiple chips.

[0245] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0246] Those skilled in the art will recognize that the units and method steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application. Finally, it should be noted that the above descriptions are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A key management method, characterized by, The method comprises: acquiring a product stage to which an electronic device belongs; determining a target key according to the product stage; configuring a chip of the electronic device according to the target key, so that the chip is started according to the target key; after the chip of the electronic device is configured according to the target key, the method further comprises: if the product stage is a trial production stage, the target key is a first key and a second key, the first key and the second key are in an activated state, and a third key is in an unactivated state; if the product stage is a mass production stage, the target key is the first key, the first key is in the activated state, the second key is in a revoked state, and the third key is in the unactivated state; if the product stage is a maintenance stage, the target key is the first key and the third key, the first key is in the activated state, the second key is in the revoked state, and the third key is in the unactivated state and can be activated.

2. The method of claim 1, wherein, The configuration of the chip of the electronic device according to the target key comprises: in the trial production stage, a system version corresponding to the first key or a system version corresponding to the second key is loaded into the chip; wherein the system version corresponding to the first key is generated according to a digital certificate and a first signature value, the system version corresponding to the second key is generated according to the digital certificate and a second signature value, the first signature value is a signature value obtained by signing a root certificate in the digital certificate according to the first key, and the second signature value is a signature value obtained by signing the root certificate in the digital certificate according to the second key.

3. The method of claim 2, wherein, The configuration of the chip of the electronic device according to the target key comprises: in the trial production stage, a first hash value is generated according to the first key, the second key and the third key; a first enabling signal is sent to a first register of the chip according to the first hash value, so that a first fuse bit of the first register is fused; wherein when the first fuse bit is in a fused state, a signal value of the first register matches the first hash value.

4. The method of claim 2, wherein, The configuration of the chip of the electronic device according to the target key comprises: in the trial production stage, a second enabling signal is sent to a second register of the chip, so that a second fuse bit of the second register is fused; wherein when the second fuse bit is in a fused state, a signal value of the second register indicates that the first key and the second key are activated and the third key is not activated.

5. The method of claim 2, wherein, In the trial production stage, a signal value of a third register of the chip indicates that the first key, the second key and the third key are not revoked.

6. The method of claim 1, wherein, The configuration of the chip of the electronic device according to the target key comprises: in the mass production stage, a third enabling signal is sent to a third register of the chip, so that a third fuse bit of the third register is fused; wherein when the third fuse bit is in a fused state, a signal value of the third register indicates that the first key is not revoked, the second key is revoked, and the third key is not revoked.

7. The method of claim 6, wherein, The method comprises the following steps: In the mass production stage, a system version corresponding to the first key is loaded into the chip; The system version corresponding to the first key is generated according to a digital certificate and a first signature value, and the first signature value is a signature value obtained by signing a root certificate in the digital certificate according to the first key.

8. The method of claim 1, wherein, The method comprises the following steps: In the maintenance stage, the third key is applied to be activated; If the application is passed, a fourth enabling signal is sent to a second register of the chip to make a fourth fuse bit of the second register fuse; When the fourth fuse bit is in a fused state, the signal value of the second register indicates that the first key, the second key and the third key are all activated.

9. The method of claim 8, wherein, The method comprises the following steps: A fourth signature value and a configuration image are obtained, wherein the fourth signature value is a signature value obtained by signing a hash value of the configuration image according to the first key by a preset server, the configuration image comprises hardware information of the electronic device, and the preset server is used to generate a digital certificate; The fourth signature value is verified according to the first key; If the verification is passed, the configuration image is compared with the hardware information of the electronic device; If the comparison is consistent, the application is passed.

10. The method of claim 8, wherein, The method comprises the following steps: In the maintenance stage, a system version corresponding to the first key or a system version corresponding to the third key is loaded into the chip; The system version corresponding to the first key is generated according to a digital certificate and a first signature value, and the system version corresponding to the third key is generated according to a digital certificate and a third signature value, the first signature value is a signature value obtained by signing a root certificate in the digital certificate according to the first key, and the third signature value is a signature value obtained by signing the root certificate in the digital certificate according to the third key.

11. The method of claim 8, wherein, After the fourth enabling signal is sent to the second register of the chip, the method further comprises the following steps: After the maintenance task is completed, a fifth enabling signal is sent to a third register of the chip to make a fifth fuse bit of the third register fuse; When the fifth fuse bit is in a fused state, the signal value of the third register indicates that the first key is not revoked and the second key and the third key are revoked.

12. The method of claim 1, wherein, The method further comprises the following steps: A first signal value and a second signal value are obtained, wherein the first signal value is a current signal value of a second register of the chip, and the second signal value is a current signal value of a third register of the chip; A current key state is determined according to the first signal value and the second signal value; It is judged whether the current key state conforms to a current product stage; If it conforms, it is determined that the electronic device is verified; If it does not conform, the key state is adjusted so that the key state conforms to the current product stage.

13. The method of claim 12, wherein, The method further comprises the following steps: performing AND operation according to the first signal value and the second signal value to obtain a first calculation value; determining a current key state according to the first calculation value.

14. The method of claim 2, 7, or 10, wherein, The root certificate in the digital certificate includes a first certificate, a second certificate, a third certificate and a fourth certificate, wherein the first certificate is a root certificate generated according to the first key, the second certificate is a root certificate generated according to the second key, the third certificate is a root certificate generated according to the third key, and the fourth certificate is a root certificate generated according to a random key.

15. A chip enable method, characterized by, The chip is configured according to the key management method in any one of claims 1 to 14, and the method comprises: obtaining a third signal value and a fourth signal value, wherein the third signal value is a current signal value of a second register of the chip, and the fourth signal value is a current signal value of a third register of the chip; obtaining a target key according to the third signal value and the fourth signal value; starting the chip according to the target key.

16. The method of claim 15, wherein, The obtaining of the target key according to the third signal value and the fourth signal value comprises: performing AND operation according to the third signal value and the fourth signal value to obtain a second calculation value; determining a target key according to the second calculation value.

17. The method of claim 15, wherein, The starting of the chip according to the target key comprises: verifying a digital certificate according to the target key; if the verification is passed, starting the chip.

18. The method of claim 17, wherein, The root certificate in the digital certificate includes a first certificate, a second certificate, a third certificate and a fourth certificate, wherein the first certificate is a root certificate generated according to the first key, the second certificate is a root certificate generated according to the second key, the third certificate is a root certificate generated according to the third key, and the fourth certificate is a root certificate generated according to a random key.

19. The method of claim 18, wherein, The verification of the digital certificate according to the target key comprises: generating a second hash value according to the first key, the second key and the third key; obtaining a third hash value from a first register of the chip; comparing the second hash value with the third hash value; if the comparison is consistent, decrypting a target signature value corresponding to the target key according to the target key to obtain a fourth hash value of the root certificate; calculating a fifth hash value of the root certificate through a hash algorithm; comparing the fourth hash value with the fifth hash value; if the comparison is consistent, verifying according to a root certificate corresponding to the target key.

20. The method of claim 19, wherein, When the target key is the first key, the target signature value corresponding to the target key is a first signature value; The verification according to the root certificate corresponding to the target key comprises verifying according to the first certificate; When the target key is the second key, the target signature value corresponding to the target key is a second signature value; the verification according to the root certificate corresponding to the target key comprises verifying according to the second certificate; When the target key is the third key, the target signature value corresponding to the target key is a third signature value; the verification according to the root certificate corresponding to the target key comprises verifying according to the third certificate.

21. A chip system, characterized by The chip system comprises a processor coupled to a memory, the processor executing a computer program stored in the memory to implement the method of any one of claims 15 to 20.

22. An electronic device, comprising: The electronic device comprises a processor configured to execute a computer program stored in a memory to cause the electronic device to implement the method of any one of claims 1 to 14, or to implement the method of any one of claims 15 to 20.

23. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program which, when executed by one or more processors, implements the method of any one of claims 1 to 14, or implements the method of any one of claims 15 to 20.

Citation Information

Patent Citations

  • Method and apparatus for safely starting chip

    CN108021812A