An Encryption Distribution Method and System for Upgrade Packages
By generating encrypted upgrade packages in the upgrade package production factory and using their attribute information for obfuscating encryption of key files, the problems of tampering and leaking during the upgrade package distribution process are solved, and the secure and complete distribution of upgrade packages is achieved.
Patent Information
- Application Number
- CN202510353770.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-25
AI Technical Summary
The prior art is difficult to ensure its integrity and correctness during the distribution of upgrade packages, and is prone to tampering and leaking by intermediaries.
The upgrade package production factory is used to generate the encrypted upgrade package, and the attribute information of the encrypted upgrade package is used as the password to obfuscate the secret key and signature information to obtain the secret key file. The encrypted upgrade package and key file are distributed through different channels respectively. The client decrypts the key file through attribute information to decrypt the upgrade package.
The security and integrity of the upgrade package in the distribution stage is realized, the risks of tampering and leaking are avoided, and the secure distribution of software or system upgrade packages is ensured.
Smart Images

Figure CN119892496B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to software upgrade technology, and particularly to an encrypted distribution method and system for upgrade packages. Background Art
[0002] With the continuous development of Internet technology, software applications have been widely used in all walks of life. Different software systems have brought great convenience to people's lives, and at the same time have promoted the iterative upgrade of production, greatly releasing productivity and providing great benefits for social development. With the continuous iterative development of technology, the running systems also need to be updated and evolved, and the upgrade of software and systems becomes particularly important. As an important material in the upgrade process, the security of the distribution of upgrade packages is very important.
[0003] Generally, the upgrade methods of software or systems can be divided into online upgrade and offline upgrade, and the overall process is as follows:
[0004] 1. Upgrade package generation: Generate the software package or system package required for upgrade to provide the original materials for upgrade.
[0005] 2. Upgrade package distribution: Generally, it is divided into online upgrade distributed through the Internet and offline upgrade distributed through offline channels (such as optical discs, USB flash drives and other removable storage media) according to the upgrade package distribution method.
[0006] 3. Upgrade package installation: Install the provided upgrade package on the client that needs to be upgraded to complete the upgrade of the software or system.
[0007] However, whether it is an online upgrade package distributed through the Internet or an offline upgrade package distributed through removable storage media, it is very difficult to ensure its integrity and correctness during the upgrade package installation stage. During the distribution process of the upgrade package, it is also extremely easy to be illegally tampered with and intercepted and monitored by a man-in-the-middle. Summary of the Invention
[0008] The technical problem to be solved by the present invention is: aiming at the technical problems existing in the prior art, the present invention provides an encrypted distribution method and system for upgrade packages, which solves the problems that the upgrade package may be tampered with, intercepted and monitored during the distribution stage, so that the software or system upgrade package can be safely and completely distributed to the upgraded client.
[0009] To solve the above technical problems, the technical solution proposed by the present invention is:
[0010] An encrypted distribution method for upgrade packages, including the steps of upgrade package distribution by an upgrade package production factory, including:
[0011] Generate an upgrade package, sign the upgrade package, and encrypt the upgrade package to obtain an encrypted upgrade package;
[0012] Extract the attribute information of the encrypted upgrade package as the password to perform confusion encryption on the secret key and signature information of the encrypted upgrade package, and obtain the secret key file;
[0013] Distribute the encrypted upgrade package and the secret key file through different channels respectively.
[0014] Furthermore, the attribute information of the encrypted upgrade package includes the hash value and file size value of the encrypted upgrade package. When extracting the attribute information of the encrypted upgrade package as the password to perform confusion encryption on the symmetric encryption secret key and the signature information, it includes:
[0015] Take the hash value of the encrypted upgrade package as the symmetric encryption secret key 1, and take the file size value of the encrypted upgrade package as the symmetric encryption secret key 2;
[0016] Perform an exclusive OR calculation on the symmetric encryption secret key 1 and the symmetric encryption secret key 2 to obtain the encryption secret key 3;
[0017] Use the encryption secret key 1 to perform an exclusive OR calculation on the secret key and signature information of the encrypted upgrade package to obtain the corresponding binary data;
[0018] Use the encryption secret key 3 as the key KEY and the symmetric encryption secret key 2 as the initialization vector IV to perform symmetric encryption on the binary data to obtain the ciphertext data as the secret key file.
[0019] Furthermore, after distributing the encrypted upgrade package and the secret key file through different channels respectively, it also includes the steps for the client to be upgraded to obtain the encrypted upgrade package and decrypt it, including:
[0020] Obtain the encrypted upgrade package and the secret key file through different channels, extract the attribute information of the encrypted upgrade package as the password to decrypt the secret key file to obtain the secret key and signature information of the encrypted upgrade package, verify the signature information, and after passing the verification, use the secret key to decrypt the encrypted upgrade package to obtain the plaintext upgrade package and install it.
[0021] Furthermore, when extracting the attribute information of the encrypted upgrade package as the password to decrypt the secret key file to obtain the secret key and signature information of the encrypted upgrade package, it specifically includes:
[0022] Calculate the hash value of the encrypted upgrade package to obtain the symmetric encryption secret key 1, calculate the file size of the encrypted upgrade package to obtain the symmetric encryption secret key 2;
[0023] Perform an exclusive OR calculation on the symmetric encryption secret key 1 and the symmetric encryption secret key 2 to obtain the encryption secret key 3;
[0024] Use the encryption secret key 3 as the key KEY and the symmetric encryption secret key 2 as the initialization vector IV to decrypt the content of the secret key file to obtain the plaintext binary data;
[0025] Perform an exclusive OR calculation on the binary data and the symmetric encryption key 1 to obtain the key and signature information of the encrypted upgrade package;
[0026] Use the key of the encrypted upgrade package to decrypt the encrypted upgrade package to obtain the plaintext upgrade package.
[0027] Further, when signing the upgrade package, specifically use the private key to encrypt the upgrade package description information of the upgrade package to obtain the signature information; when verifying the signature information and decrypting the encrypted upgrade package with the key to obtain the plaintext upgrade package and install it, it specifically includes:
[0028] Extract the upgrade package description information from the plaintext upgrade package, and use the public key to decrypt the signature information to obtain the first upgrade package description information;
[0029] Compare the extracted upgrade package description information with the first upgrade package description information. If the extracted upgrade package description information is consistent with the first upgrade package description information, install the upgrade package; otherwise, discard the upgrade package.
[0030] Further, when encrypting the upgrade package, specifically generate a one-time key KEY and an initialization vector IV as the symmetric encryption key, and encrypt the upgrade package according to the key.
[0031] Further, when distributing the encrypted upgrade package and the key file through different channels, it includes the distribution steps during online upgrade, including:
[0032] Distribute the key file through the channel of the update management platform, and distribute the encrypted upgrade package through the channel of the data platform. The update management platform is a platform with a higher security level and a weaker data throughput capacity, and the data platform is a platform with a lower security level and a stronger data throughput capacity.
[0033] Further, when distributing the encrypted upgrade package and the key file through different channels, it includes the distribution steps during offline upgrade, including:
[0034] Distribute the encrypted upgrade package through the upgrade package distribution storage medium, and distribute the key file through the key distribution storage medium. The upgrade package distribution storage medium is a storage medium with a lower security level and a stronger data throughput capacity, and the key distribution storage medium is a storage medium with a higher security level and a weaker data throughput capacity.
[0035] The present invention also proposes an upgrade package encryption and distribution system, which is used to execute the steps of the upgrade package encryption and distribution method. The upgrade package encryption and distribution system includes:
[0036] An upgrade package production factory is used to generate an upgrade package, sign the upgrade package, and encrypt the upgrade package to obtain an encrypted upgrade package; extract the attribute information of the encrypted upgrade package as a password to perform confusion encryption on the secret key and signature information of the encrypted upgrade package to obtain a secret key file; finally, distribute the encrypted upgrade package and the secret key file through different channels respectively;
[0037] A client is used to obtain the encrypted upgrade package and the secret key file through different channels, extract the attribute information of the encrypted upgrade package as a password to decrypt the secret key file to obtain the secret key and signature information of the encrypted upgrade package, verify the signature information, and after passing the verification, use the secret key to decrypt the encrypted upgrade package to obtain a plaintext upgrade package and install it.
[0038] Further, it further includes:
[0039] An update management platform is used to distribute the secret key file, and the update management platform is a platform with a relatively high security level and a relatively weak data throughput capacity;
[0040] A data platform is used to distribute the encrypted upgrade package, and the data platform is a platform with a relatively low security level and a relatively strong data throughput capacity.
[0041] Compared with the prior art, the advantages of the present invention are:
[0042] The present invention uses the attribute information, which is the implicit information of the encrypted upgrade package itself, as the secret key and uses a private encryption algorithm to encrypt the secret key of the encrypted upgrade package, realizing that no additional information needs to be transmitted. As long as the privacy of the encryption algorithm is ensured, double protection of the upgrade package and the secret key can be achieved, solving the problem that the leakage of the secret key file during online or offline transmission leads to the failure of the encrypted file protection.
[0043] The present invention uses different channels to distribute the encrypted upgrade package and the secret key file respectively, ensuring data security while also taking into account economic benefits, and effectively balancing security and cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a flowchart of the method according to an embodiment of the present invention.
[0045] Figure 2 It is a schematic diagram of the detailed process of upgrade distribution according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] The following further describes the present invention in conjunction with the drawings of the specification and specific preferred embodiments, but does not limit the protection scope of the present invention thereby.
[0047] Embodiment 1
[0048] From the analysis of the security protection boundary, the upgrade package should be secure when it is generated. At this time, the operating environment and conditions should meet the security standards and not be hijacked. That is, the environment is considered to be secure and reliable during the production of the upgrade package. The factory that produces the upgrade package is a secure environment, and means such as network isolation, physical isolation, and social engineering protection should be relied on to ensure its security. Here, it is considered that the production factory is a secure environment that is under independent control.
[0049] If we want to ensure the security of the upgrade package during the distribution and installation phases, first, we need to ensure that the receiving end, that is, the client, gets the correct upgrade package. At the same time, a method for the client to verify the source of the package should also be provided. Upgrade packages from illegal sources cannot be disguised, nor can they tamper with the correct upgrade package. For this reason, the client needs to verify the upgrade package. Taking the PKI system of the current mainstream security authentication means as the technical means, the private key is used to sign the upgrade package in the production factory, and the public key that can be distributed on the Internet is used for signature verification in the upgrade client. This technology can ensure the legality of the source of the installation package.
[0050] During the distribution process of the upgrade package, due to the need for different ways of data transmission, whether it is network distribution or distribution via mobile transmission media, there are risks such as data being hijacked, and man-in-the-middle attacks on the upgrade package for tampering, forgery, and stealing secrets. The data signature in the factory is difficult to effectively resist the tampering and forgery of the upgrade package by the man-in-the-middle. The existing technical solutions use symmetric encryption to encrypt the upgrade package and use an asymmetric encryption algorithm to distribute the symmetric key, but its key distribution mechanism is relatively complex, and it also cannot meet the symmetric key distribution scenario for offline installation. This upgrade method obviously does not meet the security, reliability, and stability requirements for software or system upgrades.
[0051] To address the risk of data leakage, this embodiment adopts an encryption protection strategy for the upgrade package. When the factory produces the upgrade package, a corresponding key is generated to encrypt the upgrade package. At the same time, the key is encrypted using a private algorithm, and the encryption keys all come from the attributes of the encrypted upgrade package, thus forming a mutually dependent decryption chain. Under the condition of ensuring the security of the private encryption algorithm, the encrypted upgrade package and the encrypted key can be directly distributed. The private encryption algorithm is used for decryption at the client, thus realizing a simple and secure distribution of the upgrade package.
[0052] Based on the above concept, this embodiment proposes an upgrade package encryption and distribution method. The upgrade package is signed using an asymmetric algorithm, symmetrically encrypted based on the symmetric encryption algorithm, and at the same time, the symmetric encryption key and the upgrade package signature information are encrypted using a private encryption algorithm to ensure the security of the upgrade package and the key, enabling the software or system upgrade package to be securely and completely distributed to the upgrade client.
[0053] As Figure 1As shown in the figure, the method of this embodiment includes:
[0054] S1) The upgrade package production factory distributes the upgrade package, specifically including:
[0055] S101) Generate an upgrade package, sign the upgrade package, and encrypt the upgrade package to obtain an encrypted upgrade package;
[0056] S102) Extract the attribute information of the encrypted upgrade package as a password to perform confusion encryption on the secret key and signature information of the encrypted upgrade package to obtain a secret key file;
[0057] S103) Distribute the encrypted upgrade package and the secret key file through different channels respectively.
[0058] S2) The client to be upgraded obtains the encrypted upgrade package and decrypts it, specifically including:
[0059] S201) Obtain the encrypted upgrade package and the secret key file through different channels;
[0060] S202) Extract the attribute information of the encrypted upgrade package as a password to decrypt the secret key file to obtain the secret key and signature information of the encrypted upgrade package;
[0061] S203) Verify the signature information, and after passing the verification, use the secret key to decrypt the encrypted upgrade package to obtain the plaintext upgrade package and install it.
[0062] The following specifically describes each step.
[0063] In this embodiment, the upgrade package is signed and encrypted through step S101. When signing the upgrade package, specifically, the private key of the upgrade package production factory is used to encrypt the upgrade package description information of the upgrade package to obtain the signature information. In the environment where the encrypted package is generated, generally, the factory environment is considered secure. At this time, the environment is a secure and reliable private environment, and the private key can be used to sign the upgrade package when the upgrade package is generated. The upgrade package description information is a document or metadata used to explain important information such as the content, function, and applicable scope of the upgrade package to users or systems. In this embodiment, it includes, but is not limited to: information such as version information, installation information, and metadata.
[0064] Since the signed upgrade package cannot cope with the risk of data leakage during transmission, in order to ensure data security, in step S101, the upgrade package is further encrypted. Specifically, a one-time key (KEY) and initialization vector (IV) are generated after the upgrade package is signed as the secret key for symmetric encryption, and the upgrade package is symmetrically encrypted according to the generated one-time secret key.
[0065] In this embodiment, the key is encrypted through step S102. The KEY and IV for symmetric encryption of the upgrade package are data information with stronger privacy. However, these data are essential when decrypting the encrypted package on the client side, so they must also be distributed to the client. Clearly, it is inappropriate to distribute them in plain text here. Therefore, in step S102 of this embodiment, the implicit information of the attribute information of the encrypted upgrade package is used as the password to perform confusion encryption on the key and signature information. Specifically, the attribute information of the encrypted upgrade package includes the hash value and file size value of the encrypted upgrade package. When extracting the attribute information of the encrypted upgrade package as the password to perform confusion encryption on the symmetric encryption key and the signature information, it includes:
[0066] Taking the hash value (MD5) of the encrypted upgrade package as the symmetric encryption key 1, and taking the file size value of the encrypted upgrade package as the symmetric encryption key 2;
[0067] Performing an exclusive OR calculation on the symmetric encryption key 1 and the symmetric encryption key 2 to obtain the encrypted key 3;
[0068] Performing an exclusive OR calculation on the key and signature information of the encrypted upgrade package using the encrypted key 1 to obtain the corresponding binary data;
[0069] Using the encrypted key 3 as the key (KEY) and the symmetric encryption key 2 as the initialization vector (IV) to perform symmetric encryption on the binary data to obtain the ciphertext data as the key file.
[0070] In the foregoing calculation process, for the case where the length is insufficient, padding with 0 is used for extension. At this time, if any one of the encrypted package or the key file is tampered with, the content of the upgrade package cannot be correctly parsed. And the key information for key decryption all comes from the correct encrypted upgrade package. Since the calculation process is a private calculation process and is not publicly disclosed, even if the encrypted upgrade package and the key file are illegally obtained at the same time, the private key encryption protocol ensures the security of the data.
[0071] This embodiment distributes the encrypted upgrade package and the key file through step S103. Considering the actual situation, as Figure 2 shown, it includes the following two cases:
[0072] 1. During online upgrade, the key file is distributed through the channel of the update management platform, and the encrypted upgrade package is distributed through the channel of the data platform. The update management platform is a platform with a relatively high security level and a relatively weak data throughput capacity. After requiring the client to authenticate its identity, it can use an encrypted channel to transmit the key file containing the key and signature information (such as the signed upgrade package metadata file) and the download address of the encrypted upgrade package file. The data platform is a platform with a relatively low security level and a relatively strong data throughput capacity. The client can directly download the encrypted ciphertext upgrade package from this platform through the download address obtained from the update management platform.
[0073] 2. During offline upgrade, the encrypted upgrade package is distributed through the upgrade package distribution storage medium, and the key file is distributed through the key distribution storage medium. The upgrade package distribution storage medium is a storage medium with a relatively low security level and a relatively strong data throughput capacity, such as a common USB flash drive, a solid-state drive, or a common optical disc. These media have fast read and write speeds and are suitable for fast distribution. The key distribution storage medium is a storage medium with a relatively high security level and a relatively weak data throughput capacity, such as an SD card with a write protection function, a MicroSD card, a USB flash drive, an M-Disc optical disc, or an LTO tape. These media have high security and anti-tampering capabilities.
[0074] In step S201 of this embodiment, after the client obtains the encrypted upgrade package and the key file through the channels of different platforms in the online upgrade scenario or different distribution storage media in the offline upgrade scenario, it transfers the obtained encrypted upgrade package and key file to a specified directory or folder and then loads the key file and the encrypted upgrade package for decryption to ensure the security of the data during the transmission process.
[0075] This embodiment realizes the decryption of the client after obtaining the correct encrypted upgrade package and key file through steps S202 and S203. Specifically:
[0076] In step S202, when extracting the attribute information of the encrypted upgrade package as the password to decrypt the key file to obtain the key and signature information of the encrypted upgrade package, it specifically includes:
[0077] Calculate the hash value of the encrypted upgrade package to obtain the symmetric encryption key 1, and calculate the file size of the encrypted upgrade package to obtain the symmetric encryption key 2;
[0078] Perform an exclusive OR calculation on the symmetric encryption key 1 and the symmetric encryption key 2 to obtain the encryption key 3;
[0079] Use the encryption key 3 as the key KEY and the symmetric encryption key 2 as the initialization vector IV to decrypt the content of the key file to obtain the plaintext binary data;
[0080] Perform an exclusive OR calculation on the binary data and the symmetric encryption key 1 to obtain the key and signature information of the encrypted upgrade package;
[0081] Use the key of the encrypted upgrade package to decrypt the encrypted upgrade package to obtain the plaintext upgrade package.
[0082] In step S203, when verifying the signature information and, after passing the verification, decrypting the encrypted upgrade package with the key to obtain the plaintext upgrade package and installing it, it specifically includes:
[0083] Extract the upgrade package description information from the plaintext upgrade package, and use the public key to decrypt the signature information to obtain the first upgrade package description information;
[0084] Compare the extracted upgrade package description information with the first upgrade package description information. If the extracted upgrade package description information is consistent with the first upgrade package description information, install the upgrade package; otherwise, discard the upgrade package.
[0085] Embodiment 2
[0086] This embodiment proposes an upgrade package encryption and distribution system to execute the steps of the upgrade package encryption and distribution method of Embodiment 1. The upgrade package encryption and distribution system includes:
[0087] An upgrade package production factory, which is used to generate an upgrade package, sign the upgrade package, and encrypt the upgrade package to obtain an encrypted upgrade package; extract the attribute information of the encrypted upgrade package as a password to perform confusion encryption on the key and signature information of the encrypted upgrade package to obtain a key file; finally, distribute the encrypted upgrade package and the key file through different channels;
[0088] A client, which is used to obtain the encrypted upgrade package and the key file through different channels, extract the attribute information of the encrypted upgrade package as a password to decrypt the key file to obtain the key and signature information of the encrypted upgrade package, verify the signature information and, after passing the verification, decrypt the encrypted upgrade package with the key to obtain the plaintext upgrade package and install it;
[0089] An update management platform, which is used to distribute the key file. The update management platform is a platform with a relatively high security level and a relatively weak data throughput capacity;
[0090] A data platform, which is used to distribute the encrypted upgrade package. The data platform is a platform with a relatively low security level and a relatively strong data throughput capacity.
[0091] In actual business, usually the upgrade management platform, as the management center, is often deployed on a platform with a higher security level and provides a more complex authentication mechanism. To control costs, its throughput is generally relatively small. However, the data platform, as the data center, can often carry a larger throughput. Therefore, in this embodiment, the dual-channel distribution method effectively balances security and cost.
[0092] In summary, the present invention proposes an upgrade package encryption and distribution method and designs a corresponding upgrade package encryption and distribution system. The present invention uses the implicit information of the upgrade package as the secret key, combines a private encryption algorithm to encrypt the secret key file of the encrypted upgrade package, and does not need to transmit additional information. As long as the privacy of the encryption algorithm is ensured, double protection of the upgrade package and the secret key can be achieved, which well solves the problem that the protection of the encrypted file fails due to the leakage of the secret key file. The present invention uses the idea of multi-channel transmission, transmits a small amount of secret keys and description information through a highly secure channel, and the massive upgrade data transmission channel adopts a more economical open environment, ensuring security while also taking into account economic benefits. The present invention solves the following key problems:
[0093] 1. Source authentication:
[0094] Sign the upgrade package and ensure the reliability of the package source through the signature verification mechanism of the PKI system. That is, sign the upgrade package with the private key and verify the signature of the upgrade package with the public key on the client side to ensure the legitimacy of the package source.
[0095] 2. Tamper prevention:
[0096] The signed and verified installation package indicates that the message has not been tampered with during the transmission process.
[0097] 3. Leakage prevention:
[0098] Adopt symmetric encryption for the upgrade package to prevent leakage caused by being eavesdropped by a man-in-the-middle during the transmission process.
[0099] The above is only a preferred embodiment of the present invention and does not impose any form of limitation on the present invention. Although the present invention has been disclosed above with a preferred embodiment, it is not intended to limit the present invention. Therefore, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention without departing from the technical solution of the present invention shall fall within the scope of protection of the technical solution of the present invention.
Claims
1. A method for encrypting and distributing an upgrade package, characterized in that: The steps for the upgrade package production factory to distribute the upgrade package include: Generate an upgrade package, sign the upgrade package, and encrypt the upgrade package to obtain an encrypted upgrade package; Extracting the attribute information of the encrypted upgrade package as a password to encrypt the key and signature information of the encrypted upgrade package, and obtaining a key file. The attribute information of the encrypted upgrade package includes a hash value and a file size value of the encrypted upgrade package. Extracting the attribute information of the encrypted upgrade package as a password to encrypt the key and signature information of the encrypted upgrade package includes: The hash value of the encrypted upgrade package is used as symmetric encryption key 1, and the file size of the encrypted upgrade package is used as symmetric encryption key 2; XOR the symmetric encryption key 1 and the symmetric encryption key 2 to obtain the encryption key 3; Use encryption key 1 to perform XOR calculation on the encryption upgrade package's key and signature information to obtain the corresponding binary data; Use encryption key 3 as key KEY and symmetric encryption key 2 as initialization vector IV to symmetric encrypt the binary data and obtain the ciphertext data as the key file; Distribute the encrypted upgrade package and key file through different channels.
2. The upgrade package encryption distribution method according to claim 1, characterized in that: After the encrypted upgrade package and the key file are distributed through different channels, the client to be upgraded obtains the encrypted upgrade package and decrypts it, including: Obtain the encrypted upgrade package and secret key file through different channels, extract the attribute information of the encrypted upgrade package as the password to decrypt the secret key file to obtain the secret key and signature information of the encrypted upgrade package, verify the signature information and after passing the verification, use the secret key to decrypt the encrypted upgrade package to obtain the plaintext upgrade package and install it.
3. The upgrade package encryption distribution method according to claim 2, characterized in that: When extracting the attribute information of the encrypted upgrade package as the password to decrypt the key file to obtain the key and signature information of the encrypted upgrade package, it specifically includes: Calculate the hash value of the encrypted upgrade package to obtain symmetric encryption key 1, calculate the file size of the encrypted upgrade package to obtain symmetric encryption key 2; XOR the symmetric encryption key 1 and the symmetric encryption key 2 to obtain the encryption key 3; Use encryption key 3 as key KEY and symmetric encryption key 2 as initialization vector IV to decrypt the key file content and obtain the plaintext binary data; Perform XOR calculation on the binary data and the symmetric encryption key 1 to obtain the key and signature information of the encrypted upgrade package; Use the secret key of the encrypted upgrade package to decrypt the encrypted upgrade package to obtain the plaintext upgrade package.
4. The upgrade package encryption distribution method according to claim 3, characterized in that: When signing the upgrade package, specifically, the upgrade package description information of the upgrade package is encrypted using the private key to obtain the signature information; after verifying the signature information and passing the verification, the encrypted upgrade package is decrypted using the secret key to obtain the plaintext upgrade package and install it, specifically including: Extracting upgrade package description information from the plaintext upgrade package, and using the public key to decrypt the signature information to obtain first upgrade package description information; The extracted upgrade package description information is compared with the first upgrade package description information. If the extracted upgrade package description information is consistent with the first upgrade package description information, the upgrade package is installed; otherwise, the upgrade package is discarded.
5. The upgrade package encryption distribution method according to claim 1, characterized in that: When the upgrade package is encrypted, a one-time key KEY and an initialization vector IV are specifically generated as a secret key for symmetric encryption, and the upgrade package is encrypted according to the secret key.
6. The upgrade package encryption distribution method according to claim 1, characterized in that: When distributing the encrypted upgrade package and key file through different channels, including the distribution steps during online upgrade, include: The key file is distributed through the channel of the update management platform, and the encrypted upgrade package is distributed through the channel of the data platform. The update management platform is a platform with a higher security level and weaker data throughput capacity, and the data platform is a platform with a lower security level and stronger data throughput capacity.
7. The upgrade package encryption distribution method according to claim 1, characterized in that: When distributing the encrypted upgrade package and key file through different channels, including the distribution steps for offline upgrades, include: The encrypted upgrade package is distributed through the upgrade package distribution storage medium, and the secret key file is distributed through the secret key distribution storage medium. The upgrade package distribution storage medium is a storage medium with a lower security level and a higher data throughput capacity, and the secret key distribution storage medium is a storage medium with a higher security level and a lower data throughput capacity.
8. An upgrade package encryption distribution system, characterized in that: The upgrade package encryption distribution system is used to execute the steps of the upgrade package encryption distribution method according to any one of claims 1 to 7, and the upgrade package encryption distribution system includes: The upgrade package production factory is used to generate the upgrade package, sign the upgrade package, and encrypt the upgrade package to obtain an encrypted upgrade package; extract the attribute information of the encrypted upgrade package as a password to encrypt the secret key and signature information of the encrypted upgrade package to obtain a secret key file; finally, distribute the encrypted upgrade package and the secret key file through different channels respectively; The client is used to obtain the encrypted upgrade package and key file through different channels, extract the attribute information of the encrypted upgrade package as the password to decrypt the key file to obtain the key and signature information of the encrypted upgrade package, verify the signature information and after verification, use the key to decrypt the encrypted upgrade package to obtain the plaintext upgrade package and install it.
9. The upgrade package encryption distribution system according to claim 8, characterized in that: Also includes: An update management platform, used to distribute key files, wherein the update management platform is a platform with a high security level and a low data throughput capacity; The data platform is used to distribute the encrypted upgrade package, and the data platform is a platform with a lower security level and a higher data throughput capacity.
Citation Information
Patent Citations
Data security control method, device and system and storage medium
CN116707783A
Vehicle software management system using ota
WO2023101401A1