Mirror image file encapsulation method, decapsulation method, encryption device and communication terminal

By using certificate private key encryption and symmetric encryption algorithms for dual encryption during image file transfer, and splitting the image file into sub-files for splicing, the problem of easy tampering during image file transfer is solved, and high-security data transmission is achieved.

CN119892519BActive Publication Date: 2025-05-27CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510379319.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-05-27
Estimated Expiration
2045-03-28

AI Technical Summary

Technical Problem

In the prior art, mirror files are susceptible to malicious tampering during transmission, making it difficult to ensure the security of data transmission, and the existing encryption methods are relatively low in security, making it difficult to meet the growing security needs.

Method used

The target image file is encrypted once by the private key of the certificate of the vehicle communication terminal T-box to obtain the signature data; then the symmetric encryption algorithm is used to encrypt the first mirror head data, signature data and T-box certificate data to obtain the ciphertext; the target image file is split into the first sub-file and the second sub-file based on the stored information of the random number, and the ciphertext, sub-file and random number are spliced ​​to form the encapsulated mirror file.

Benefits of technology

By double encryption and splitting the image file, the security of the data is significantly improved, preventing the data from being tampered with during transmission. Even if the decryption key is leaked, the contents of the upgraded image file cannot be obtained, ensuring communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892519B_ABST
    Figure CN119892519B_ABST
Patent Text Reader

Abstract

The present application relates to the field of communication security technology, and specifically, to a method for encapsulating and unsealing a mirror file, an encryption device, and a communication terminal. The encapsulation method includes using the private key of the certificate of the vehicle-mounted communication terminal T‑box to encrypt the unencapsulated target mirror file once to obtain signature data; using a symmetric encryption algorithm to perform secondary encryption on the first mirror header data, the signature data, and the certificate data of the T‑box to obtain a ciphertext. According to the storage information of the random number, the target mirror file is split into a first sub-file and a second sub-file; the size of the ciphertext, the ciphertext, the first sub-file, the random number, and the second sub-file are spliced ​​to form an encapsulated mirror file. The present application can improve the communication security of the mirror file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication security technology, and to a mirror file encapsulation method, decapsulation method, encryption device and communication terminal. Background Art

[0002] Image files play a vital role in upgrading the vehicle's Microcontroller Unit (MCU). They are data files containing firmware or software updates, which are used to update the functions of the vehicle's MCU, fix vulnerabilities, or improve performance.

[0003] Image files are very susceptible to malicious tampering during the upgrade process, making it difficult to ensure the security of data transmission. To solve this problem, image files can be encapsulated to effectively prevent them from being intercepted during transmission, thereby ensuring data security.

[0004] However, the encryption methods used in existing solutions have low security and cannot meet the growing security needs. Summary of the invention

[0005] In order to improve the security of image files, the present application provides an image file packaging method, an unpacking method, an encryption device and a communication terminal.

[0006] In a first aspect, the present application provides a method for packaging an image file, comprising:

[0007] The private key of the certificate of the vehicle communication terminal T-box is used to encrypt the unpackaged target image file once to obtain the signature data;

[0008] A symmetric encryption algorithm is used to perform secondary encryption on the first image header data, the signature data and the certificate data of the T-box to obtain a ciphertext; wherein the first image header data includes storage information of the certificate, storage information of the random number and storage information of the signature data;

[0009] Splitting the target image file into a first sub-file and a second sub-file according to the storage information of the random number;

[0010] The size of the ciphertext, the ciphertext, the first sub-file, the random number, and the second sub-file are concatenated to form a packaged image file.

[0011] In a second aspect, the present application provides a method for unpacking an image file. The encapsulated image file is obtained according to the above method. The unpacking method includes:

[0012] Obtain the size of the ciphertext, the ciphertext and the remaining data from the encapsulated image file;

[0013] Decrypt the ciphertext once using a symmetric encryption algorithm to obtain first image header data, signature data and certificate data; wherein the first image header data includes: storage information of the certificate of the vehicle-mounted communication terminal T-box, storage information of the random number and storage information of the signature data;

[0014] According to the storage information of the random number, the random number is removed from the remaining data to obtain the image file to be verified;

[0015] Decrypting the signature data twice using the public key of the certificate to obtain reference data;

[0016] If the data of the image file to be verified is consistent with the reference data, the image file to be verified is determined as the target image file.

[0017] In a third aspect, the present application provides an encryption device, comprising:

[0018] at least one processor, and a memory communicatively coupled to at least one of the processors;

[0019] The memory stores instructions that can be executed by at least one of the processors, and the instructions are executed by at least one of the processors so that at least one of the processors can execute the above-mentioned image file packaging method.

[0020] In a fourth aspect, the present application provides a vehicle-mounted communication terminal, including:

[0021] at least one processor, and a memory communicatively coupled to at least one of the processors;

[0022] The memory stores instructions that can be executed by at least one of the processors, and the instructions are executed by at least one of the processors so that at least one of the processors can execute the above-mentioned method for decapsulating the image file.

[0023] This application includes at least the following beneficial effects:

[0024] This application first uses the certificate private key to encrypt the target image file once, which can ensure the integrity and authenticity of the data and prevent the data from being tampered with during transmission; then a symmetric encryption algorithm is used to encrypt the first image header data, signature data and certificate data twice, further improving the security of the data. By splitting the target image file into a first sub-file and a second sub-file according to the storage information of the random number, the target image file is prevented from being intercepted and the communication security is improved; even if the decryption key is leaked, the content of the upgraded image file cannot be obtained. The final encapsulated image file includes an initialization vector, the size of the ciphertext, the ciphertext, the first sub-file, the random number and the second sub-file. This structural design can effectively organize and manage the target image file and certificate data, and improve the security of the data. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the specific implementation methods of the present application or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0026] Figure 1 It is a flowchart of a method for packaging an image file provided in an embodiment of the present application;

[0027] Figure 2 It is a flowchart of a method for decompressing an image file provided in an embodiment of the present application;

[0028] Figure 3 It is a schematic diagram of the structure of the encryption device provided in the embodiment of the present application. DETAILED DESCRIPTION

[0029] The following is a description of exemplary embodiments of the present application in conjunction with the accompanying drawings, including various details of the embodiments of the present application to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present application. Similarly, for the sake of clarity and conciseness, the description of well-known functions and structures is omitted in the following description.

[0030] An embodiment of the present application provides a method for packaging an image file. The method is applicable to the case of packaging an image file. The image file may be a file for upgrading a vehicle-mounted MCU or other files.

[0031] This embodiment is executed by an encryption device. The encryption device encapsulates the unencapsulated target image file to obtain an encapsulated image file. The encapsulated image file is transmitted to a vehicle-mounted communication terminal (Telematics BOX, T-box), and the T-box then decrypts the received image file to obtain the target image file, which is provided to the vehicle-mounted MCU for upgrading.

[0032] See Figure 1 , this application provides a method for encapsulating an image file, including:

[0033] S110. Use the private key of the certificate of the vehicle-mounted communication terminal T-box to encrypt the unencapsulated target image file once to obtain signature data.

[0034] The target image file is the file to be encapsulated, which includes the file for upgrading the MCU. Any encryption algorithm can be used to encrypt the target image file once with the private key to obtain signature data.

[0035] S120. Use a symmetric encryption algorithm to encrypt the first image header data, the signature data, and the certificate data of the T-box twice to obtain ciphertext.

[0036] In the image file, the image header is a key data structure located at the beginning of the image file. It contains metadata that describes the content and attributes of the image file and is used to guide the system on how to correctly parse and process the image file. In this embodiment, the image header of the target image file is called the first image header. Optionally, the certificate (i.e., the secondary certificate of the T-box) data (Cert data) and the signature data (RSA value) are concatenated in sequence behind the first image header. The storage information of the certificate data (Cert data) and the signature data (RSA value) is written into the first image header. In addition, a random number and its storage information are randomly generated, and the storage information of the random number is also written into the first image header. Then, the first image header data includes the storage information of the certificate (i.e., the secondary certificate of the T-box), the storage information of the random number, and the storage information of the signature data (RSA value). The storage information is used to indicate the storage location and occupied space of the data. For example, it can be represented by the data size and the offset address. Table 1 shows the field name, number of bytes, and meaning in the first image header.

[0037] Table 1 Structure of the first image header

[0038]

[0039] In this embodiment, the first image header data, the signature data, and the certificate data are encrypted twice as a whole.

[0040] Then, the first image header data, signature data and T-box certificate data are taken as a data block, and the data block is encrypted twice using a symmetric encryption algorithm to obtain a ciphertext (ED), and the size of the ciphertext (ES) is calculated.

[0041] S130. Split the target image file into a first sub-file and a second sub-file according to the storage information of the random number.

[0042] If the random number is stored in the middle of the target image file, the part of the target image file before the first random number is split into a first sub-file, and the remaining part of the target image file is used as a second sub-file. The first sub-file, the random number, and the second sub-file are sequentially spliced.

[0043] S140: Concatenate the size of the ciphertext, the ciphertext, the first sub-file, the random number, and the second sub-file to form a packaged image file.

[0044] This embodiment does not limit the size of the ciphertext, the ciphertext, the first sub-file, the random number, and the splicing order of the second sub-file. In order to quickly read the data when unpacking, the size of the ciphertext (ES), the ciphertext (ED), the first sub-file (SW.TBOX.x.xx.xx.xxxx.zip1), the random number (Random data), and the second sub-file (SW.TBOX.x.xx.xx.xxxx.zip2) are sequentially spliced ​​to form a packaged image file (SW.TBOX.x.xx.xx.xxxx.bin).

[0045] The embodiment of the present application first uses the certificate private key to encrypt the target image file once, which can ensure the integrity and authenticity of the data and prevent the data from being tampered with during transmission; then a symmetric encryption algorithm is used to encrypt the first image header data, signature data and certificate data twice, further improving the security of the data. By splitting the target image file into a first sub-file and a second sub-file according to the storage information of the random number, the target image file is prevented from being intercepted and the communication security is improved; even if the decryption key is leaked, the content of the upgraded image file cannot be obtained. The final encapsulated image file includes an initialization vector, the size of the ciphertext, the ciphertext, the first sub-file, the random number and the second sub-file. This structural design can effectively organize and manage the target image file and certificate data and improve the security of the data.

[0046] Optionally, in this embodiment, when the private key of the certificate of the vehicle-mounted communication terminal T-box is used to encrypt the unpackaged target image file once, the following method is specifically adopted:

[0047] First, calculate the first hash value of the target image file. For example, if the image file is SW.TBOX.x.xx.xx.xxxx.zip, calculate the SHA256 (Secure Hash Algorithm 256-bit) value of this image file. SHA256 is a cryptographic hash function. For the convenience of description and distinction, the obtained hash value is called the first hash value.

[0048] Then, adopt an asymmetric encryption algorithm and use the private key of the T-box certificate to encrypt the first hash value to obtain signature data. The asymmetric encryption algorithm uses a pair of keys: the public key and the private key. The public key is used to encrypt data or verify signatures, and the private key is used to decrypt data or generate signatures. The private key of the T-box certificate (such as a secondary certificate) is adopted. Optionally, in this embodiment, the RSA (Rivest-Shamir-Adleman) encryption algorithm is adopted to obtain RSA2048 signature data (RSA value). This embodiment uses public key encryption and private key decryption, without sharing the private key, reducing the risk of key leakage and being beneficial to improving the security of the target image file.

[0049] Optionally, in this embodiment, when using a symmetric encryption algorithm to perform secondary encryption on the first image header data, the signature data, and the T-box certificate data to obtain ciphertext, the symmetric encryption algorithm adopts the Advanced Encryption Standard with 128-bit key and CipherBlock Chaining (AES128 CBC) mode.

[0050] The AES128 CBC (AES-128 Cipher Block Chaining) mode is a symmetric encryption algorithm that requires a 128-bit key as input; the data to be encrypted is divided into blocks of a fixed size (128 bits for AES), and each block is XORed with the previous ciphertext block before encryption. When encrypting the first block, a randomly generated initialization vector IV is used to ensure that different ciphertexts are generated after encrypting the same plaintext.

[0051] First, calculate the second hash value of the public key in the certificate of the T-box (such as the root certificate). For example, convert the public key into data in DER (Distinguished Encoding Rules) format (DERD), and calculate the MD5 (Message Digest Algorithm 5) value of the DERD. This MD5 value serves as the second hash value. Then, use the second hash value as the key for the AES128 CBC mode. Perform secondary encryption on the first mirror header data, signature data, and certificate data of the T-box according to the key and the initialization vector IV of the AES128 CBC mode to obtain the ciphertext. During the secondary encryption process, the first mirror header data, signature data, and certificate data need to be divided into blocks of a fixed size. If the data length is not an integer multiple of the block size, the Public Key Cryptography Standard #7 (PKCS#7) padding algorithm needs to be used for padding.

[0052] In view of the fact that the AES128 CBC mode is used for secondary encryption in this embodiment, when forming the encapsulated mirror file, the initialization vector of the AES128 CBC mode also needs to be added. For example, concatenate the initialization vector IV, the size of the ciphertext, the ciphertext, the first sub-file, the random number, and the second sub-file in sequence to form the encapsulated mirror file.

[0053] Optionally, before encrypting the unencapsulated target mirror file with the private key of the certificate, this embodiment also includes the process of generating the target mirror file (SW.TBOX.x.xx.xx.xxxx.zip).

[0054] First, obtain the original application program APP file (2-TBOX-App-A01.srec) for upgrading the MCU. Then, generate the second mirror header data according to the data size and checksum of the App in the original APP file. For example, perform CRC32 (Cyclic Redundancy Check) verification calculation on the data of the original APP to obtain a 32-bit checksum. In addition to the data size and checksum, the second mirror header also includes the MCU mirror header identifier, version number, timestamp for generating the second mirror header data, and the MCU program entry. The following table shows the field names and meanings in the second mirror header.

[0055] Table 2 Structure of the Second Mirror Header

[0056]

[0057] Then, insert the second mirror header data into the original APP file. For example, if the offset address of the second mirror header data in the original APP file is predefined as 0x800, then insert the second mirror header data at the offset address 0x800 of the original APP file. After formatting conversion and compression of the file inserted with the second mirror header data, the target mirror file (SW.TBOX.x.xx.xx.xxxx.zip) is obtained.

[0058] The following uses a specific embodiment to detail the generation process of the target mirror file (SW.TBOX.x.xx.xx.xxxx.zip). A script (McuPack.sh) can be run to execute this generation process:

[0059] 1) Initialize the production environment of the second mirror header and delete the MCU Flash mirror file that might be left over last time.

[0060] 2) Initialize the second mirror header structure and write the version number and timestamp.

[0061] 3) Convert the original APP file (2-TBOX-App-A01.srec) into a Bin format file (2-TBOX-App-A01.bin).

[0062] 4) Calculate the size of the original APP file data in 2-TBOX-App-A01.bin and write it to the corresponding position of the second mirror header.

[0063] 5) Calculate the CRC32 checksum of the original APP file data in 2-TBOX-App-A01.bin and write it to the corresponding position of the second mirror header.

[0064] 6) Insert the data of the second mirror header at the offset address 0x800 of the 2-TBOX-App-A01.bin file.

[0065] 7) Use the SRecord tool command to convert the 2-TBOX-App-A01.bin inserted with the second mirror header data into 2-TBOX-App-A01.s19 to complete the format conversion. The main function of the SRecord tool is to operate the Erasable Programmable Read-Only Memory (EPROM) loading file and support the conversion and processing of multiple file formats.

[0066] Optionally, before the second mirror header, there also includes an interrupt vector table and the configuration of the operating environment, forming the following MCU Flash file (i.e., 2-TBOX-App-A01.s19). The structure of the Flash file is shown in the following table:

[0067] Table 3 Structure of Flash File

[0068]

[0069] Among them, the Interrupt Vector Table (IVT) is used to store the addresses of Interrupt Service Routines (ISRs). When the MCU receives an interrupt signal, it will jump to the corresponding address in the interrupt vector table according to the interrupt type, so as to execute the corresponding interrupt service routine.

[0070] 8) Compress 2-TBOX-App-A01.s19, Flash Driver (1-TBOX-Drv-D01.s19) and the NAD original upgrade package (Nad.zip) to form the target image file (SW.TBOX.x.xx.xx.xxxx.zip). Among them, FlashDriver is a key component for managing and operating Flash files (i.e., 2-TBOX-App-A01.s19), responsible for implementing functions such as reading, writing, erasing, bad block management, wear leveling, etc. The NAD (Network Access Device) original upgrade package refers to the firmware file used to update the NAD module. The NAD module is the core component of the vehicle communication system, responsible for the communication between the vehicle and external networks (such as 4G / 5G, GPS, Bluetooth, etc.). Upgrading the firmware of the NAD module can fix problems, optimize performance or add new functions.

[0071] The file directory after decompressing SW.TBOX.x.xx.xx.xxxx.zip is as follows:

[0072] ├── MCU

[0073] │├── 1-TBOX-Drv-D01.s19

[0074] │└── 2-TBOX-App-A01.s19

[0075] └──Nad.zip

[0076] In this embodiment, the generation process of SW.TBOX.x.xx.xx.xxxx.zip is mainly a packaging process of Flash files. By packaging Flash files, the security of the target image file during transmission has been greatly improved. Even if the target image file is intercepted during transmission, the attacker cannot obtain the content of the target image file, thus avoiding the problem of malicious upgrade.

[0077] The following uses a specific embodiment to detail the encapsulation process of the target image file (SW.TBOX.x.xx.xx.xxxx.zip). This encapsulation process can be executed by running a script (TBoxPack.sh):

[0078] 1) Initialize the first image header, and write a random 16-byte initialization vector IV, version number, and timestamp.

[0079] 2) Calculate the data size (SWS) of SW.TBOX.x.xx.xx.xxxx.zip.

[0080] 3) Calculate the first hash value of SW.TBOX.x.xx.xx.xxxx.zip, such as the SHA256 value (shaValue), and encrypt the calculated shaValue using the private key of the T-box secondary certificate (Cert) to obtain the signature data (RSA value).

[0081] 4) Calculate the size of the Cert data and the size of the RSA value, and write them into the header.

[0082] 5) Concatenate the Cert data and the RSA value in order after the header, and write the offset addresses of the Cert data and the RSA value relative to the target image file into the header.

[0083] 6) Randomly generate a number within the range (0, SWS) as the offset address (RO) of the random data (Random data).

[0084] 7) Randomly generate a number within the range (0, SWS - RO) as the size (Random size) of the Random data, and write the RO and the Random size into the header.

[0085] 8) Split SW.TBOX.x.xx.xx.xxxx.zip into two parts according to the Random data and the Random size, namely the first sub-file (SW.TBOX.x.xx.xx.xxxx.zip1) and the second sub-file (SW.TBOX.x.xx.xx.xxxx.zip2).

[0086] 9) Read the public key in the T-Box root certificate and convert it into DER format data (DERD). Calculate the MD5 value of DERD, and use the MD5 value as the input key for AES128 CBC NoPadding (no padding). Then, use the IV as the initialization vector for the AES CBC mode and perform data padding using the PKCS#7 padding algorithm. Calculate the ciphertext (ED) of header + Cert + RSA value. Calculate the size (ES) of ED.

[0087] 10) Concatenate in sequence: IV + ES + ED + SW.TBOX.x.xx.xx.xxxx.zip1 + Random data + SW.TBOX.x.xx.xx.xxxx.zip2 to generate the encapsulated image file SW.TBOX.x.xx.xx.xxxx.bin.

[0088] The directory structure of the encapsulated target image file is as follows. After encapsulation, send the bin file to the T-box.

[0089] ├── TBox

[0090] │ ├── SW.TBOX.x.xx.xx.xxxx.zip

[0091] │ └── version

[0092] ├── PKI

[0093] │├── root.pem

[0094] │ ├── cert.pem

[0095] │ └── private.key

[0096] ├── SW.TBOX.x.xx.xx.xxxx.bin

[0097] └── TBoxPack.sh

[0098] Among them, version: T-box version number, its content will be written into the version field of the header after running TBoxPack.sh. PKI (Public Key Infrastructure) is a security framework based on public key cryptography. root.pem: T-box root certificate. cert.pem: Secondary certificate for signature verification (issued by T-box root certificate). private.key: Private key for signing. SW.TBOX.x.xx.xx.xxxx.bin: The packaged image file obtained after running the script TBoxPack.sh.

[0099] See also Figure 2 The present application provides a method for decapsulating an image file, which aims to decapsulate an encapsulated image file to obtain a target image file. The method can be executed by a vehicle-mounted communication terminal T-box. Figure 2 The methods shown include:

[0100] S210. Obtain the size of the ciphertext, the ciphertext, and the remaining data from the encapsulated image file.

[0101] The size of the ciphertext is represented by a fixed-length byte, which can be read out according to the byte length in the encapsulated image file (SW.TBOX.x.xx.xx.xxxx.bin). According to the size of the ciphertext, the bytes that match the size length are read as the ciphertext. The remaining data includes the first sub-file, the random number, and the second sub-file. Currently, it is not possible to determine which of the remaining data is the first sub-file and which is the second sub-file.

[0102] S220. Decrypt the ciphertext once using a symmetric encryption algorithm to obtain first image header data, signature data, and certificate data.

[0103] The first image header data includes: storage information of the certificate of the vehicle-mounted communication terminal T-box, storage information of the random number and storage information of the signature data, and the storage information is represented by data size and offset address.

[0104] When the symmetric encryption algorithm is used for decryption, the same key as that used for encryption is required, and the first image header data, signature data and certificate data are obtained after decryption.

[0105] S230. According to the storage information of the random number, the random number is removed from the remaining data to obtain the image file to be verified.

[0106] The storage information of the random number represents the storage location of the random number in the target image file. The remaining data is generated by inserting the random number into the target image file. Therefore, the image file can be obtained by removing the random number from the remaining data, which is called the image file to be verified.

[0107] S240. Use the public key of the certificate to decrypt the signature data a second time to obtain the reference data.

[0108] If the signature data is encrypted using the private key of the secondary certificate for the target image file, then use the public key of the secondary certificate to decrypt the signature data. Since the target image file has been encrypted twice and has high security, the data (such as the hash value or digest, etc.) of the target image file obtained by the second decryption in this step is called the reference data.

[0109] S250. If the data of the image file to be verified is consistent with the reference data, then determine the image file to be verified as the target image file.

[0110] For example, if the hash value of the image file to be verified is consistent with the reference data, it is considered that the image file has not been tampered with during the transmission process, and the real target image file is obtained.

[0111] This embodiment has the following technical effects: By decrypting the encapsulated image file a second time and verifying the image file, the security of the image file during the transmission process is greatly improved. Even if the upgraded image file is intercepted during the transmission process, the attacker cannot obtain the content of the upgraded image file, thus avoiding the problem of malicious upgrade and enhancing the storage security of the data at the same time. This application encrypts the image file, greatly improving the security of the image file during the storage process. This application can effectively prevent the image file from being tampered with during the transmission or storage process through the signature data, thus ensuring the integrity of the upgraded image file. The encapsulation and parsing scheme of this application makes the transmission and storage of the upgraded image file more convenient, thus optimizing the upgrade process and improving the upgrade efficiency.

[0112] Optionally, when this embodiment uses the symmetric encryption algorithm to decrypt the ciphertext for the first time to obtain the first image header data, signature data, and certificate data, the symmetric encryption algorithm is the AES128 CBC mode. When decrypting using the AES128 CBC mode, the encryption key and initialization vector IV are required. The ciphertext is grouped into multiple ciphertext blocks according to 16 bytes. For each ciphertext block, the AES128 algorithm is used to decrypt to obtain the plaintext block. Finally, each plaintext block is concatenated in order to obtain the first image header data, signature data, and certificate data.

[0113] First, calculate the second hash value of the public key in the certificate of the T-box. For the convenience of description and distinction, the hash value of the public key is called the second hash value. Use the second hash value as the key for the AES128 CBC mode; decrypt the ciphertext once according to the key and the initialization vector IV of the AES128 CBC mode to obtain the first mirror header data; obtain the certificate data according to the storage information of the certificate in the first mirror header data, and obtain the signature data according to the storage information of the signature data in the first mirror header data.

[0114] Optionally, in this embodiment, when excluding the random number from the remaining data according to the storage information of the random number to obtain the mirror file to be verified, the following scheme is adopted:

[0115] According to the storage information of the random number, determine the data segment of the random number from the remaining data, that is, the xx bytes to yy bytes belong to the random number. Since the random number divides the target mirror header file into a first sub-file and a second sub-file, the data before and after the data segment are sequentially spliced to obtain the mirror file to be verified. Since only the target mirror file is split and spliced with the random number during packaging, there is a certain security risk, so the spliced mirror file needs to be verified at this time, which is called the mirror file to be verified.

[0116] Optionally, after determining the mirror file to be verified as the target mirror file, it is necessary to parse the original APP file and the second mirror header data therein from the target mirror file. First, decompress and convert the format of the target mirror file to obtain the file to be parsed; then, according to the storage information of the second mirror header data, read the second mirror header data and the original APP file from the file to be parsed; access the second mirror header data to obtain the final parsing information.

[0117] The following shows a specific implementation to illustrate the process of parsing the original APP file and the second mirror header data from the target mirror file.

[0118] 1) Decompress the target mirror file and read 2-TBOX-App-A01.s19 from it, and convert 2-TBOX-App-A01.s19 to a Bin format file (2-TBOX-App-A01.bin).

[0119] 2) Load 2-TBOX-App-A01.bin. Since the storage location of the second mirror header (McuImageHeader_st) is the offset address 0x800 and it occupies 1 byte, read 1 byte of data from the offset address 0x800 at the beginning of the binary stream of the 2-TBOX-App-A01.bin file and store it in the variable (mcuImageHeader). If the data of the second mirror header is not read, an error is prompted.

[0120] Remove the second image header data from 2-TBOX-App-A01.bin to obtain the original APP data in Bin format, and then perform format conversion to obtain 2-TBOX-App-A01.srec.

[0121] 3) The second image header data can be obtained by accessing the members in mcuImageHeader. If the aforementioned members are not accessed, an error will be prompted.

[0122] The following directory is formed after unpacking:

[0123] ├── MCU

[0124] │├── 2-TBOX-App-A01.srec

[0125] │└── version

[0126] └── McuPack.sh

[0127] The following is a specific implementation method to detail the process of parsing the target image file from the packaged image file:

[0128] 1) Obtain the packaged image file, including the following fields:

[0129] Table 4 Structure of the Packaged Image File

[0130]

[0131] 2) Read the IV data (IV), encrypted data size (ES), encrypted data (ED) and remaining data in the image header.

[0132] 3) Read the public key in the T-box root certificate and convert it into DER format data (DERD).

[0133] 4) Use the IV as the initialization vector for the CBC mode, encrypt the MD5 value of DERD as the input key for AES128, and decrypt ED to obtain the plaintext (DE).

[0134] 5) Parse DE according to the second image header data structure to obtain the offset address and size of the secondary certificate data (Cert data), the offset address and size of the signature data (RSA value), and the offset address and size of the random number (Random data). Read Cert data and RSA value according to the aforementioned offset addresses and sizes.

[0135] 6) Verify Cert data using the T-box root certificate. If the verification fails, the program ends.

[0136] 7) If the verification passes, Randomdata is removed from the remaining data according to the offset address and size of Random data to obtain the SW.TBOX.x.xx.xx.xxxx.zip to be verified, and the SHA256 value (shaValue) of the SW.TBOX.x.xx.xx.xxxx.zip to be verified is calculated.

[0137] 8) Use Cert data to verify and calculate RSA value to obtain decodeValue (i.e. the SHA256 value of the real target image file).

[0138] 9) Compare shaValue and decodeValue. If they are different, the program ends. If they are the same, SW.TBOX.x.xx.xx.xxxx.zip is extracted.

[0139] like Figure 3 As shown, the present application provides an encryption device, comprising:

[0140] at least one processor; and a memory in communication with the at least one processor; wherein,

[0141] The memory stores instructions that can be executed by at least one processor, and the instructions are executed by at least one processor so that at least one processor can execute the above-mentioned image file packaging method. At least one processor in the encryption device can execute the above-mentioned image file packaging method, and thus has at least the same advantages as the above-mentioned image file packaging method.

[0142] The encryption device also includes interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses and can be installed on a common mainboard or installed in other ways as needed. The processor can process instructions executed in the terminal, including instructions stored in or on a memory to display graphical information of a GUI (Graphical User Interface) on an external input / output device (such as a display device coupled to an interface). In other embodiments, if necessary, multiple processors can be used together with multiple memories, and / or multiple buses can be used together with multiple memories. Similarly, multiple electronic devices can be connected (for example, as a server array, a group of blade servers, or a multi-processor system), and each device provides some necessary operations. Figure 3 A processor 301 is taken as an example.

[0143] The memory 302, being a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the mirror file encapsulation method in the embodiments of the present application. The processor 301 executes various functional applications and data processing of the encryption device by running the software programs, instructions, and modules stored in the memory 302, that is, implements the above-mentioned mirror file encapsulation method.

[0144] The memory 302 may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory 302 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some examples, the memory 302 may further include a memory remotely set relative to the processor 301, and these remote memories can be connected to the encryption device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0145] As Figure 3 shown, the encryption device may further include: an input device 303 and an output device 304. The processor 301, the memory 302, the input device 303, and the output device 304 can be connected through a bus or other means, Figure 3 taking the connection through the bus as an example.

[0146] The input device 303 can receive input digital or character information, and the output device 304 may include a display device, an auxiliary lighting device (for example, an LED), a tactile feedback device (for example, a vibration motor), etc. The display device may include but is not limited to a liquid crystal display (LCD), a light-emitting diode (LED) display, and a plasma display. In some embodiments, the display device may be a touch screen.

[0147] The embodiments of the present application further provide a communication terminal, which can be mounted on a vehicle for vehicle communication. Refer to Figure 3 , the communication terminal includes: at least one processor, and a memory communicatively connected to at least one of the processors; the memory stores instructions executable by at least one of the processors, and the instructions are executed by at least one of the processors so that at least one of the processors can execute the mirror file decapsulation method. The communication terminal further includes an input device and an output device, for details, refer to the above description, and will not be elaborated here.

[0148] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired results of the technical solutions disclosed in this application can be achieved, and no limitations are imposed herein.

[0149] The above specific embodiments do not constitute a limitation on the protection scope of this application. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the protection scope of this application.

Claims

1. A method for packaging an image file, characterized in that: include: The private key of the certificate of the vehicle communication terminal T-box is used to encrypt the unpackaged target image file once to obtain the signature data; A symmetric encryption algorithm is used to perform secondary encryption on the first image header data, the signature data and the certificate data of the T-box to obtain a ciphertext; wherein the first image header data includes storage information of the certificate, storage information of the random number and storage information of the signature data; Splitting the target image file into a first sub-file and a second sub-file according to the storage information of the random number; The size of the ciphertext, the ciphertext, the first sub-file, the random number, and the second sub-file are concatenated to form a packaged image file.

2. The method according to claim 1, characterized in that The private key of the certificate of the vehicle communication terminal T-box is used to encrypt the unpackaged target image file once to obtain the signature data, including: Calculate a first hash value of the target image file; An asymmetric encryption algorithm is adopted to encrypt the first hash value using the private key of the T-box certificate to obtain signature data.

3. The method according to claim 1, characterized in that The first image header data, the signature data and the certificate data of the T-box are encrypted twice using a symmetric encryption algorithm to obtain a ciphertext, including: Calculate a second hash value of the public key in the certificate of the T-box, and use the second hash value as a key for the Advanced Encryption Standard 128-bit cipher block chaining AES128 CBC mode; The first image header data, the signature data and the certificate data of the T-box are encrypted twice according to the key and the initialization vector IV of the AES128 CBC mode to obtain a ciphertext; The size of the ciphertext, the ciphertext, the first sub-file, the random number, and the second sub-file are concatenated to form a packaged image file, including: The initialization vector IV, the size of the ciphertext, the ciphertext, the first sub-file, the random number and the second sub-file are sequentially concatenated to form a packaged image file.

4. The method according to claim 1, characterized in that: The private key of the certificate of the vehicle communication terminal T-box is used to encrypt the unpackaged target image file once. Before obtaining the signature data, it also includes: Get the original application APP file; Generate the second image header data according to the data size and checksum of the App in the original App file; The second image header data is inserted into the original APP file, and the target image file is obtained after format conversion and compression.

5. The method for unpacking an image file is characterized in that: The encapsulated image file is obtained according to the method according to any one of claims 1 to 4; the method for decapsulating the image file comprises: Obtain the size of the ciphertext, the ciphertext and the remaining data from the encapsulated image file; Decrypt the ciphertext once using a symmetric encryption algorithm to obtain first image header data, signature data and certificate data; wherein the first image header data includes: storage information of the certificate of the vehicle-mounted communication terminal T-box, storage information of the random number and storage information of the signature data; According to the storage information of the random number, the random number is removed from the remaining data to obtain the image file to be verified; Decrypting the signature data twice using the public key of the certificate to obtain reference data; If the data of the image file to be verified is consistent with the reference data, the image file to be verified is determined as the target image file.

6. The method according to claim 5, characterized in that The symmetric encryption algorithm is used to decrypt the ciphertext once to obtain the first image header data, signature data and certificate data, including: Calculate a second hash value of the public key in the certificate of the T-box, and use the second hash value as a key for the Advanced Encryption Standard 128-bit cipher block chaining AES128 CBC mode; Decrypt the ciphertext once according to the key and the initialization vector IV of the AES128 CBC mode to obtain the first image header data; The certificate data is obtained according to the storage information of the certificate in the first image header data, and the signature data is obtained according to the storage information of the signature data in the first image header data.

7. The method according to claim 6, characterized in that According to the storage information of the random number, the random number is removed from the remaining data to obtain the image file to be verified, including: Determining a data segment of the random number from the remaining data according to the storage information of the random number; The data before and after the data segment are sequentially spliced ​​together to obtain the image file to be verified.

8. The method according to claim 6, characterized in that After the image file to be verified is determined as the target image file, the following steps are also included: Decompressing and formatting the target image file to obtain a file to be parsed; According to the storage information of the second image header data, read the second image header data and the original APP file from the file to be parsed; The second image header data is accessed to obtain final parsing information.

9. An encryption device, characterized in that include: at least one processor, and a memory communicatively coupled to at least one of the processors; The memory stores instructions executable by at least one of the processors, and the instructions are executed by at least one of the processors so that at least one of the processors can execute the image file packaging method described in any one of claims 1 to 4.

10. A communication terminal, characterized in that: include: at least one processor, and a memory communicatively coupled to at least one of the processors; The memory stores instructions that can be executed by at least one of the processors, and the instructions are executed by at least one of the processors so that at least one of the processors can execute the image file decapsulation method described in any one of claims 5-8.

Citation Information

Patent Citations

  • A method and system for protecting digital content

    CN102279908A

  • Safety secrecy method and system for data transmission

    CN113572614A