System version updating method, electronic equipment and storage medium

By adding the upgrade flag checksum HMAC algorithm to the system version update method of electronic equipment, the problem of unlocking the lock function after flashing back is solved, the system version's anti-back capability is improved, and the risk of information leakage and illegal use is reduced.

CN119939585AActive Publication Date: 2025-05-06HONOR DEVICE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202311418436.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-27
Publication Date
2025-05-06
Estimated Expiration
2043-10-27

AI Technical Summary

Technical Problem

In the prior art, after the electronic device returns the system version to the lower version by flashing the machine, the locking function may be unlocked, resulting in high risk of information leakage and the electronic device being used in violation of regulations.

Method used

By adding the verification step of the upgrade flag in the system version update method, and using the key hash message authentication code (HMAC) algorithm to process the version list when the system version is updated, it is ensured that only the version number that meets the criteria can pass the verification, and then upgrade or fall back the system version.

Benefits of technology

It significantly improves the anti-backback capability of the system version, reduces the risk of information leakage and electronic equipment being used in violation of regulations, and ensures the security and stability of the system version.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939585A_ABST
    Figure CN119939585A_ABST
Patent Text Reader

Abstract

The invention discloses a system version updating method, electronic equipment and a storage medium, and relates to the technical field of terminals. The method comprises the following steps: verifying an upgrade mark, wherein the upgrade mark is signed by adopting an encryption algorithm; when the verification is passed, the system version is allowed to be upgraded or returned; when verification is not passed, an HMAC algorithm is used for processing version numbers in a version list obtained during system version updating so as to obtain an HMAC set, the version list comprises the version number of an updated version and the version number of each early version of the updated version, and a secret key used by the HMAC algorithm is generated by the electronic equipment and uniquely corresponds to the electronic equipment; when the HMAC set comprises a first HMAC, the upgrade to the updated version is allowed, and the first HMAC is the HMAC corresponding to the version number of the current system version; otherwise, the system version is not allowed to be updated. According to the method, the anti-backspacing capability of the system version is improved, and the risks of information leakage and illegal use of the electronic equipment are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of terminal technology, and in particular to a system version updating method, electronic device and storage medium. Background Art

[0002] Flashing the device means changing or replacing some of the languages, images, ringtones, software and operating systems that originally existed in the electronic device through certain methods. Flashing the device can update or restore the system version of the electronic device. Locking the device means disabling the electronic device when it is lost, stolen or used illegally, thereby preventing information leakage and preventing the electronic device from being used illegally.

[0003] Currently, the system version of an electronic device can be rolled back by flashing the firmware, for example, rolling back from the second version to an earlier first version. Since the rolled-back first version may not support locking the device, the electronic device may no longer be locked after the flashing, which still leaves the electronic device at risk of information leakage and illegal use. Summary of the invention

[0004] In order to solve the above problems, the present application provides a system version update method, electronic device and storage medium, which improves the anti-rollback capability of the system version, thereby reducing the risk of information leakage and illegal use of electronic devices.

[0005] In the first aspect, the present application provides a method for updating a system version, which is applied to an electronic device and specifically includes: verifying an upgrade flag, wherein the upgrade flag is signed with an encryption algorithm; when the verification passes, allowing the system version to be upgraded or rolled back; when the verification fails, using a key-hash message authentication code HMAC algorithm to process each version number in a version list obtained when the system version is updated to obtain an HMAC set, wherein the version list includes the version number of the updated version and the version numbers of each earlier version of the updated version, and the key used by the HMAC algorithm is generated by the electronic device and uniquely corresponds to the electronic device; when it is determined that the HMAC set includes a first HMAC, allowing the system version to be upgraded to the updated version, wherein the first HMAC is the HMAC corresponding to the version number of the current system version stored on the electronic device; otherwise, updating the system version is not allowed.

[0006] Using the solution provided by the present application, when the system is updated by flashing the machine, due to the addition of a verification step for the upgrade flag, even if the first HMAC set stored on the electronic device is deleted, the electronic device will not directly allow the system version to be updated because of the misjudgment that this is the first system write. In this solution, the electronic device needs to first verify the upgrade flag when flashing the machine. The upgrade flag is signed with an encryption algorithm, and since the key used by the encryption algorithm has access rights, the tamper resistance is improved. When the user passes the verification of the upgrade flag, the user is allowed to upgrade or return the system version as required.

[0007] When the user fails to pass the verification of the upgrade flag, an HMAC verification is required. The HMAC verification needs to determine whether the HMAC set includes the first HMAC stored locally in the electronic device. Among them, the HMAC set includes the HMAC corresponding to the upgraded version of the electronic device, and the HMAC corresponding to each earlier version of the upgraded version; the first HMAC is the HMAC corresponding to the earlier version of the electronic device. When included, it is determined that the system update at this time is an upgrade update, and the system upgrade is allowed. When not included, it is determined that the system update at this time is a downgrade update, that is, the system version is rolled back, and the system upgrade is not allowed at this time. In this application, the HMAC corresponding to each version number is generated based on a hash algorithm using a key and a version number, and the key is generated by the electronic device. The key generated by each electronic device is different and cannot be obtained from the outside, so that the outside world cannot generate the HMAC corresponding to the correct version number. Therefore, it is impossible to pass the HMAC verification by replacing or modifying the first HMAC stored in the electronic device, and because the key is uniquely corresponding to the electronic device, the first HMAC transplanted from other electronic devices cannot pass the HMAC verification.

[0008] In summary, the solution provided by this application improves the anti-rollback capability of the system version, thereby reducing the risk of information leakage and illegal use of electronic devices.

[0009] In one possible implementation, the upgrade flag is signed using an RSA encryption algorithm, and the RSA encryption algorithm uses a first hash algorithm. The verification of the upgrade flag specifically includes: when the upgrade flag is obtained, decrypting the upgrade flag using a public key of the RSA encryption algorithm to obtain a first hash value; using the first hash algorithm to process the original upgrade flag to obtain a second hash value, and the original upgrade flag is not signed using the RSA encryption algorithm; when the first hash value is the same as the second hash value, determining that the upgrade flag verification has passed; otherwise, determining that the upgrade flag verification has failed.

[0010] In a possible implementation manner, it specifically includes: when the upgrade flag is not obtained, determining that the upgrade flag verification fails.

[0011] In one possible implementation, after the verification passes, the method further includes: upgrading or rolling back the system version to the first version, processing the version number of the first version using the HMAC algorithm to obtain the HMAC corresponding to the version number of the first version; and updating the first HMAC to the HMAC corresponding to the version number of the first version.

[0012] In a possible implementation, after updating the first HMAC to the HMAC corresponding to the version number of the first version, the method further includes: deleting the upgrade flag on the electronic device.

[0013] The electronic device deletes the upgrade mark, which, on the one hand, releases storage space and, on the other hand, prevents the upgrade mark from being obtained externally.

[0014] In one possible implementation, after determining that the HMAC set includes the first HMAC, the method also includes: upgrading the system version to a second version; processing the version number of the second version using the HMAC algorithm to obtain the HMAC corresponding to the version number of the second version; and updating the first HMAC to the HMAC corresponding to the version number of the second version.

[0015] In a possible implementation, when the current system version is a production test version, the first HMAC stored in the electronic device is empty data. When the verification passes, the method also includes: updating the system version to a third version; processing the version number of the third version using the HMAC algorithm to obtain the HMAC corresponding to the version number of the third version; and writing the HMAC corresponding to the version number of the third version to the data storage area as the first HMAC of the electronic device.

[0016] This implementation method realizes the first update of the system of the electronic device.

[0017] In a possible implementation, after writing the HMAC corresponding to the version number of the third version into the data storage area, the method further includes:

[0018] The upgrade mark is deleted on the electronic device.

[0019] In one possible implementation, the current system version is the fourth version. When the verification passes, or when it is determined that the HMAC set includes the first HMAC, the method further includes: updating the system version to the fourth version; processing the version number of the fourth version using the HMAC algorithm to obtain the HMAC corresponding to the version number of the fourth version; and updating the first HMAC to the HMAC corresponding to the version number of the fourth version.

[0020] In this implementation, no version upgrade or rollback is performed, but the current version of the system is reinstalled on the electronic device to repair or restore the system.

[0021] In a second aspect, the present application further provides an electronic device, which is used to run a program, and when the program is running, the system version updating method described in the first aspect and any one of the implementation methods of the first aspect is implemented.

[0022] The electronic device may be a mobile phone, a tablet computer, a computer with wireless transceiver function, an augmented reality (AR) terminal device, a virtual reality (VR) terminal device, a mixed reality (MR) terminal device, an extended reality (XR) terminal device, etc., and the embodiments of the present application are not specifically limited.

[0023] In a third aspect, the present application further provides a storage medium on which a computer program is stored, and when the program is executed by a processor, the system version updating method described in the above implementation manner is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 Schematic diagram of the scenario provided for this application;

[0025] Figure 2 A flowchart of a method for updating a system version provided in an embodiment of the present application;

[0026] Figure 3 A flowchart of another method for updating a system version provided in an embodiment of the present application;

[0027] Figure 4 A flowchart of another method for updating a system version provided in an embodiment of the present application;

[0028] Figure 5 A flowchart of another method for updating a system version provided in an embodiment of the present application;

[0029] Figure 6A flowchart of another method for updating a system version provided in an embodiment of the present application;

[0030] Figure 7 A schematic diagram of an electronic device provided in an embodiment of the present application;

[0031] Figure 8 A software architecture diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0032] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number or implicit order of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this embodiment, unless otherwise specified, "plurality" means two or more.

[0033] In the following description, “update” of the system version means that the system version loaded on the electronic device is different from the current earlier version of the electronic device; “upgrade” of the system version means that the system version loaded on the electronic device is an upgraded version of the current earlier version of the electronic device; and “downgrade” of the system version means that the system version loaded on the electronic device is a downgraded version of the current earlier version of the electronic device, that is, version rollback is achieved.

[0034] In order to enable persons skilled in the art to more clearly understand the solution of the present application, the application scenario of the technical solution of the present application is first described below.

[0035] See also Figure 1 , which is a schematic diagram of the scenario provided by this application.

[0036] In one possible application scenario, when a user purchases an electronic device in installments, the user generally pays a certain percentage of the amount as a down payment and the remaining amount is paid in installments. The electronic device has the ability to lock the device. Once the user defaults on the payment, the electronic device is locked, preventing the defaulting user from using other functions.

[0037] In another possible implementation, important information or data may be stored on the electronic device, and the electronic device can only be used by a user with permission. When it is found that the electronic device is held by a user without permission, the electronic device can be locked to prevent the user from using it illegally.

[0038] In another possible implementation, the electronic device may be lost or stolen, in which case the electronic device is locked by relying on the locking capability of the electronic device to avoid information leakage.

[0039] However, the current implementation of the lock function is affected by the system version of the electronic device. For example, a lower version system may not support lock, or a lower version system may have a system vulnerability that can unlock the device. After the user rolls back the system version of the electronic device to a lower version by flashing the device, the lock may be unlocked. Figure 1 As shown, when the system version is 3.0, the electronic device is locked. If the system version of the electronic device is rolled back to version 2.0 that does not support locking by flashing the device, the electronic device can be used normally.

[0040] In order to avoid the above situation, electronic devices need to have a higher system version anti-rollback capability. However, the system version anti-rollback capability of current electronic devices is relatively poor, and there is a high risk of information leakage and illegal use of electronic devices.

[0041] In order to solve the above technical problems, the present application provides a system version update method, electronic device and storage medium. In order to overcome the above loopholes, the present application is conceived to: on the one hand, by adding a verification step, it is impossible to directly update any version, but it is necessary to pass the verification first; on the other hand, the relevant algorithm for version number verification is improved, and integrity protection is provided, so that the correct data cannot be generated externally to replace the data in the data storage area.

[0042] Specifically, when updating the system by flashing the firmware, the upgrade flag needs to be verified first. The upgrade flag is signed with an encryption algorithm and bound to the electronic device, making it unique and tamper-proof. The key used by the encryption algorithm has access rights. When the user passes the upgrade flag verification, the user is allowed to update the system version as needed, such as upgrading or rolling back.

[0043] When the user fails to pass the verification of the upgrade flag, a version number verification is required. The version number verification of this application is a keyed-hash message authentication code (HMAC) verification. During the HMAC verification, an HMAC set is first generated. The HMAC set includes the HMAC corresponding to the upgraded version of the electronic device, and the HMACs corresponding to each earlier version of the upgraded version. The data storage area of ​​the electronic device includes a first HMAC, and the first HMAC is the HMAC corresponding to the version number of the earlier version of the electronic device. Then determine whether the first HMAC is included in the HMAC set. When included, it is determined that the system update at this time is an upgrade update, and the system upgrade is allowed. When not included, it is determined that the system update at this time is a downgrade update, that is, the system version is rolled back, and the system upgrade is not allowed at this time.

[0044] In this application, the HMAC corresponding to each version number is based on a hash algorithm and is generated using a key and a version number. The key is generated by an electronic device, and each electronic device generates a different key that cannot be obtained from the outside, so that the outside world cannot generate the correct HMAC corresponding to the version number. Therefore, it is impossible to pass the HMAC verification by replacing or modifying the first HMAC stored in the electronic device, and because the key is uniquely corresponding to the electronic device, directly transplanting the first HMAC of other electronic devices cannot pass the HMAC verification.

[0045] In summary, this solution can significantly improve the anti-rollback capability of the system version, thereby reducing the risk of information leakage and illegal use of electronic devices.

[0046] The following is a detailed description of the system version updating method provided by the present application in conjunction with the accompanying drawings.

[0047] See also Figure 2 , which is a flowchart of a system version updating method provided in an embodiment of the present application.

[0048] The method comprises the following steps:

[0049] S21: Start flashing the firmware.

[0050] Currently, commonly used flashing methods include secure digital (SD) card flashing, OTG (On-The-Go) flashing and Over-the-Air Technology (OTA) flashing.

[0051] When flashing the SD card, the flashing file is stored on the SD card, and after the SD card is inserted into the electronic device, the flashing process is triggered on the electronic device.

[0052] OTG technology allows data transmission between devices without a host, such as data transmission between an electronic device and a USB flash drive. When flashing a device using OTG, the flashing file is usually stored on a USB flash drive, and the USB flash drive is connected to the electronic device through an OTG adapter that supports OTG technology, triggering the flashing process on the electronic device.

[0053] OTA flashing can also be called OTA upgrading. It can be completed with the help of Wi-Fi wireless network or mobile network, which is equivalent to completing the upgrade with the help of air wireless network.

[0054] The embodiment of the present application does not limit the specific flashing method. The above two types of flashing methods are only examples and do not constitute a limitation on the technical solution of the present application.

[0055] S22: Determine whether the verification of the upgrade flag passes.

[0056] When an electronic device is flashing, the verification of the upgrade flag is triggered first.

[0057] In a possible implementation, when the electronic device is flashing, it can log in to the server through the network, obtain the upgrade flag from the server, and then verify the upgrade flag.

[0058] In another possible implementation, when the electronic device is flashing, it can also establish a connection with other external electronic devices, such as a personal computer (PC). The PC obtains an upgrade flag from a service area and writes the upgrade flag into the electronic device, so that the electronic device can verify the upgrade flag.

[0059] The upgrade mark in the embodiment of the present application is data uniquely corresponding to each electronic device and signed using an encryption algorithm. The encryption algorithm used by the upgrade mark can be a symmetric encryption algorithm or an asymmetric encryption algorithm.

[0060] In a possible implementation, the encryption algorithm is a symmetric encryption algorithm, in which case the encryption algorithm key can be stored on a server of the electronic device, external users have no access rights, and the signed upgrade mark cannot be tampered with. The symmetric encryption algorithm can be DES, 3DES, AES, DESX, Blowfish, RC4, RC5 or RC6, etc., and the embodiments of the present application do not specifically limit this.

[0061] In another possible implementation, the encryption algorithm may be an asymmetric encryption algorithm, such as RSA, DSA or ECC. When an asymmetric encryption algorithm is used, the private key is stored on the server of the electronic device, and external users have no access rights, and the signed upgrade mark cannot be tampered with.

[0062] For example, the manufacturer of electronic equipment uses an asymmetric encryption algorithm such as RSA to sign the original upgrade mark to obtain the upgrade mark.

[0063] The manufacturer first generates a pair of keys, namely a public key and a private key. The public key can be made public, while the private key is not public and can be stored on the manufacturer's server.

[0064] The following describes the key generation process of the RSA algorithm.

[0065] Determine a first prime number p and a second prime number q, where p and q are not equal. The first prime number p and the second prime number q cannot be too small, otherwise the key will be easily cracked.

[0066] Determine N: N=pq.

[0067] Determine L: L is the least common multiple of p-1 and q-1.

[0068] Determine E: E must satisfy two conditions: E is a number greater than 1 and less than L, and the greatest common divisor of E and L is 1.

[0069] Determine D: D satisfies 1 < D < L, and (DE) mod L = 1.

[0070] At this time, (N, E) is the public key and (N, D) is the private key.

[0071] When signing the original upgrade flag, first use the hash algorithm to process the original upgrade flag once to obtain a string hash value, and then encrypt the string hash value with the private key to obtain a signature.

[0072] The string hash value n can be encrypted to c through the following formula:

[0073] c = n E mod N (1)

[0074] The higher c in formula (1) is also the upgrade flag. When the manufacturer of the electronic device, or the R & D researchers authorized by the manufacturer, the device maintenance personnel authorized by the manufacturer, etc. perform flashing on the electronic device, the upgrade flag and the original upgrade flag will be transmitted to the electronic device together.

[0075] When the electronic device performs signature verification, first use the public key to decrypt the signature, and decrypt c to obtain the hash value a. See the following formula for details:

[0076] a = c D mod N (2)

[0077] Then the electronic device uses the same hash algorithm as the manufacturer to perform a hash process on the original upgrade flag once to obtain another hash value b. The electronic device compares whether a and b are the same. If they are the same, it can be determined that the object providing the upgrade flag and the original upgrade flag has passed the verification of the upgrade flag, and S24 is executed, that is, allowing the system of the electronic device to be updated to any version.

[0078] For users not authorized by the manufacturer, even if they obtain the original upgrade flag of the electronic device, due to lack of access rights to the private key, they cannot use the private key to sign the original upgrade flag, which makes it impossible for external users to forge a signed upgrade flag for the electronic device. When the electronic device performs upgrade flag verification, it is found that no valid upgrade flag is obtained at this time, that is, the upgrade flag is empty, resulting in the failure of the upgrade flag verification. At this time, S23 is executed.

[0079] In another possible implementation, although the user who performs the flashing is authorized by the manufacturer, a and b are inconsistent during the verification process, which may be caused by the user providing an incorrect upgrade mark and / or original upgrade mark. At this time, the electronic device determines that the verification of the upgrade mark has failed and executes S23. In addition, when the original upgrade mark is not obtained, the verification of the upgrade mark will also fail because the signature verification cannot be completed.

[0080] In the embodiment of the present application, the upgrade mark of each electronic device is unique, and the upgrade mark of other electronic devices cannot pass the upgrade mark verification. In a possible implementation, the upgrade mark may carry the serial number (SN) information of the electronic device.

[0081] S23: Determine whether the HMAC set includes the first HMAC.

[0082] In the embodiment of the present application, the version number of each version is converted into a keyed-hash message authentication code (HMAC). When performing HMAC operation on the version number, a hash algorithm is required, with the key and the version number as input to output the corresponding HMAC. The specific principle can be seen in the following formula:

[0083]

[0084] In formula (3), H is a cryptographic hash function; K is a key; m is a version number; K' is another secret key derived from the original key K (if K is shorter than the input block size of the hash function, it is padded to the right with zeros; if it is longer than the input block size, K is hashed); || represents concatenation; ⊕ represents exclusive OR (XOR); opad is external padding; and ipad is internal padding.

[0085] The specific process of using HMAC operation to process the version number is as follows:

[0086] 1. Add 0 after the key K or hash the key K to create a string with a word length of B. For example, if the word length of K is 20 bytes and B = 64 bytes, 44 zero bytes 0x00 will be added after K; if the word length of K is 120 bytes and B = 64 bytes, K will be hashed to produce a 64-byte string.

[0087] 2. Perform an XOR operation on the B-length string generated by 1 and the iPad to obtain the first result string.

[0088] 3. Fill the version number into the first result string to obtain the first data stream.

[0089] 4. Process the first data stream using a cryptographic hash function.

[0090] 5. Perform an XOR operation on the B-word length string generated by 1 and opad to obtain the second result string.

[0091] 6. Then fill the processing result of 4 into the second result character string obtained in 5 to obtain a second data stream.

[0092] 7. Use the cryptographic hash function to process the second data stream generated in 6 and output the final result.

[0093] Through the above HMAC algorithm, a version number can be converted into a corresponding HMAC.

[0094] The key K is required in the above HMAC processing. The key K in the embodiment of the present application is generated by the electronic device and cannot be obtained from the outside. The key K uniquely corresponds to the electronic device itself, and the key K generated by different electronic devices is different.

[0095] The data storage area of ​​the electronic device stores a first HMAC, and the first HMAC is an HMAC corresponding to the version number of the earlier version of the electronic device.

[0096] For example, if the current system version of the electronic device is the second version and the version number of the second version is the second version number, then the first HMAC stored in the electronic device is the HMAC corresponding to the second version number.

[0097] When verifying the version number, the external party needs to provide the flash version list corresponding to this flash. The flash version list can also be referred to as the version list. The flash version list includes the upgrade version number and the version number before the upgrade version number. Among them, the upgrade version number is the version number updated by the system on the electronic device through flashing. Taking the flashing to replace the system from the second version to the third version as an example, the upgrade version number is the version number of the third version, that is, the third version number. The version numbers before the third version number are the first version number and the second version number. Among them, the first version number is the version number of the first version, and the second version is the version number of the second version.

[0098] At this time, the flash version list includes the first version number, the second version number and the third version number.

[0099] In the embodiment of the present application, the HMAC set includes the HMAC corresponding to the upgraded version of the electronic device, and the HMACs corresponding to each earlier version of the upgraded version.

[0100] The electronic device performs an HMAC operation on each version number included in the flash version list to obtain an HMAC corresponding to the first version number, an HMAC corresponding to the second version number, and an HMAC corresponding to the third version number.

[0101] Then the electronic device determines whether the HMAC set includes the first HMAC. Since the HMAC set includes the first HMAC in the above example, it indicates that the flashing is for version upgrade, and the system is allowed to be updated through the flashing, and S24 is executed.

[0102] In another possible implementation, for example, if the upgraded version is the first version, then the flashing version list only includes the first version number, and the HMAC set only includes the HMAC corresponding to the first version number. At this time, the electronic device determines that the HMAC set does not include the HMAC corresponding to the second version number, and determines that the flashing is a version rollback. Then, system updating through flashing is not allowed, and S27 is executed.

[0103] It can be understood that in the embodiment of the present application, the HMAC corresponding to the upgraded version is also the first HMAC stored locally in the electronic device, indicating that there is no version upgrade or rollback at this time, but it is updated to the same version.

[0104] For example, flashing updates an electronic device from version 2 to version 2. This implementation is generally used to repair or restore the system of an electronic device. At this time, the HMAC set includes the HMAC corresponding to the first version number and the HMAC corresponding to the second version number. The first HMAC is the HMAC corresponding to the second version number, which meets the conditions for allowing flashing.

[0105] S24: Perform system update.

[0106] To update the system, you can perform the flashing steps normally and update the system version.

[0107] S25: The version number is upgraded after processing using the HMAC algorithm, and the processing result is stored in the data storage area.

[0108] The upgrade version number is processed using the HMAC algorithm to obtain the HMAC corresponding to the upgrade version number, and the HMAC corresponding to the upgrade version number is stored in the data storage area, that is, the first HMAC in the data storage area is updated in time so that the electronic device cannot perform version rollback later.

[0109] Continuing with the example of upgrading the electronic device from the second version to the third version, the electronic device uses the HMAC algorithm to process the third version number to obtain the HMAC corresponding to the third version number, and stores the HMAC in the data storage area. At this time, the first HMAC of the electronic device is updated from the HMAC corresponding to the second version number to the HMAC corresponding to the third version number.

[0110] S26: Delete the upgrade mark.

[0111] That is, the upgrade mark provided to the electronic device externally during the flashing is deleted, which releases storage space on the one hand and prevents the upgrade mark from being obtained externally on the other hand.

[0112] S27: System update is not allowed.

[0113] At this time, the electronic device does not allow system updates, making the subsequent flashing steps impossible to complete.

[0114] It is understandable that the division of the above steps is only for the convenience of explanation and does not constitute a limitation on the technical solution of the present application. In practical applications, the order of the above steps can be adjusted. For example, when the upgrade mark is not written to the electronic device during verification in S22, S26 may not be executed.

[0115] In summary, using the solution provided by the embodiment of the present application, the upgrade flag is first checked when flashing the machine, so that the data in the data storage area cannot be directly updated to any version. When the upgrade flag verification fails, check whether the first HMAC is included in the HMAC set. When it is included, it is determined that the system update at this time is an upgrade update, and the system upgrade is allowed. Since the key of HMAC is generated by the electronic device, the key generated by each electronic device is different and cannot be obtained from the outside, it is impossible for the outside to pass the HMAC verification by replacing or modifying the first HMAC stored in the electronic device, and since the key is uniquely corresponding to the electronic device, the first HMAC of other electronic devices cannot be directly transplanted. The HMAC verification cannot be passed. Therefore, the solution of the embodiment of the present application significantly improves the anti-rollback capability of the system version, thereby reducing the risk of information leakage and illegal use of electronic devices.

[0116] The following is an explanation based on specific application scenarios.

[0117] The following first introduces how to implement the first system update during the factory production process of electronic equipment.

[0118] See also Figure 3 , which is a flowchart of another system version updating method provided in an embodiment of the present application.

[0119] The system version currently running on the electronic device is a production test version, the upgraded version of the electronic device is a second version, and the version number of the second version is a second version number. The method includes the following steps:

[0120] S31: Start flashing the firmware.

[0121] The embodiment of the present application does not limit the specific flashing method. The above two types of flashing methods are only examples and do not constitute a limitation on the technical solution of the present application.

[0122] S32: The PC writes an upgrade flag to the electronic device.

[0123] In the embodiment of the present application, when the electronic device is flashing, the upgrade flag check is triggered, and the upgrade flag is written by the PC as an example. In this scenario, the PC user is the user of the device manufacturer or the authorized user of the manufacturer, and the PC can obtain the upgrade flag from the service area and write the upgrade flag into the electronic device.

[0124] In a possible implementation, the upgrade flag may be written as data into a designated file in the data storage area.

[0125] In another possible implementation, the upgrade flag is carried in a file and the file is stored in a data storage area.

[0126] When the electronic device is flashing, it can also log in to the server through the network, obtain the upgrade mark from the server, and then verify the upgrade mark.

[0127] S33: The upgrade flag bit is verified.

[0128] Since an upgrade flag encrypted with a correct private key is written into the electronic device in this scenario, the electronic device can pass the signature verification normally at this time.

[0129] S34: The electronic device performs a system update.

[0130] At this point, the electronic device can perform the flashing steps normally to update the system version.

[0131] S35: The electronic device processes the second version number using the HMAC algorithm and stores the processing result in the data storage area.

[0132] At this time, the electronic device processes the second version number using the HMAC algorithm, obtains the HMAC corresponding to the second version number, and updates the data storage area. The first HMAC stored in the data storage area before the update is empty data, and the first HMAC stored in the data storage area after the update is the HMAC corresponding to the second version number.

[0133] S36: The electronic device deletes the upgrade mark.

[0134] The electronic device deletes the upgrade mark, which, on the one hand, releases storage space and, on the other hand, prevents the upgrade mark from being obtained externally.

[0135] To sum up, by using the method provided in the embodiment of the present application, the first system update is performed on the electronic device. Since the person performing the system update at this time has the authority to access the upgrade flag and can write the correct upgrade flag to the electronic device, the electronic device can be updated to any version.

[0136] The following describes how to prevent the mobile phone version from rolling back when the upgrade verification fails.

[0137] See also Figure 4 , which is a flowchart of another system version updating method provided in an embodiment of the present application.

[0138] The system version currently running on the electronic device is the third version, and the version number of the third version is the third version number; the upgraded version of the electronic device is the second version, and the version number of the second version is the second version number. The method includes the following steps:

[0139] S41: Start flashing the firmware.

[0140] S42: Determine whether the current upgrade flag verification fails.

[0141] When the electronic device detects that the upgrade flag is not currently written, that is, when the upgrade flag is empty, it is determined that the current upgrade flag verification has failed; or when the electronic device performs signature verification on the upgrade flag and finds that there is a data error, it is determined that the current upgrade flag verification has failed, and an HMAC verification is performed at this time.

[0142] S43: Determine the HMAC set according to the second version of the flash version list.

[0143] The current upgrade version is the second version, and the second version's flash version list includes the first version number and the second version number. The first version number and the second version number are processed using the HMAC algorithm to obtain an HMAC set, which includes the HMAC corresponding to the first version number and the HMAC corresponding to the second version number.

[0144] S44: Determine that the HMAC set does not include the first HMAC stored in the electronic device at this time.

[0145] The version currently running on the electronic device is the third version, and at this time the first HMAC stored in the data storage area of ​​the electronic device is the HMAC corresponding to the third version number.

[0146] The HMAC set is compared with the first HMAC, and it is found that the first HMAC is not included in the HMAC set, which indicates that this flashing is for the purpose of returning the system version.

[0147] S45: System update is not allowed.

[0148] At this time, the electronic device does not allow system updates, making the subsequent flashing steps impossible to complete.

[0149] It can be understood that the division of the above steps is only for the convenience of explanation and does not constitute a limitation on the technical solution of the present application. In actual applications, the order of the above steps can be adjusted. For example, when an upgrade flag is written to the electronic device during verification in S42, although the verification of the upgrade flag fails, a step of deleting the upgrade flag can be added after S45.

[0150] In summary, by using the method provided in the embodiment of the present application, by performing HMAC verification, it is possible to identify that the upgraded version of the user's flashed device has been rolled back compared to the current running version of the electronic device, thereby preventing the system from being updated. In addition, the HMAC key is generated by the electronic device, and the key generated by each electronic device is different and cannot be obtained from the outside, so that the outside cannot pass the HMAC verification by replacing or modifying the first HMAC stored in the electronic device, and because the key is uniquely corresponding to the electronic device, the first HMAC directly transplanted from other electronic devices cannot pass the HMAC verification, so that the electronic device has the ability to prevent the system version from rolling back.

[0151] The following describes how to implement the method of allowing the mobile phone version to roll back when the upgrade verification passes.

[0152] See also Figure 5 , which is a flowchart of another system version updating method provided in an embodiment of the present application.

[0153] Taking the third version of the system version currently running on the electronic device, the version number of the third version is the third version number, and the upgraded version of the electronic device is the second version, the version number of the second version is the second version number as an example, the method includes the following steps:

[0154] S51: Start flashing the firmware.

[0155] S52: The PC writes an upgrade flag to the electronic device.

[0156] In the embodiment of the present application, when the electronic device is flashing, the upgrade flag check is triggered, and the upgrade flag is written by the PC as an example. In this scenario, the PC user is the user of the device manufacturer or the authorized user of the manufacturer, and the PC can obtain the upgrade flag from the service area and write the upgrade flag into the electronic device.

[0157] In a possible implementation, the upgrade flag may be written as data into a designated file in the data storage area.

[0158] In another possible implementation, the upgrade flag is carried in a file and the file is stored in a data storage area.

[0159] When the electronic device is flashing, it can also log in to the server through the network, obtain the upgrade mark from the server, and then verify the upgrade mark.

[0160] S53: The upgrade flag bit is verified to be passed.

[0161] Since an upgrade flag encrypted with a correct private key is written into the electronic device in this scenario, the electronic device can pass the signature verification normally at this time.

[0162] S54: The electronic device rolls back the system to the second version.

[0163] S55: Obtain the HMAC corresponding to the second version number and update the data storage area.

[0164] At this time, the electronic device processes the second version number using the HMAC algorithm, obtains the HMAC corresponding to the second version number, and updates the data storage area. The first HMAC stored in the data storage area before the update is the HMAC corresponding to the third version number, and the first HMAC stored in the data storage area after the update is the HMAC corresponding to the second version number.

[0165] S56: The electronic device deletes the upgrade mark.

[0166] The electronic device deletes the upgrade mark, which, on the one hand, releases storage space and, on the other hand, prevents the upgrade mark from being obtained externally.

[0167] In summary, the solution provided by the embodiment of the present application allows the electronic device to roll back the system version after the verification of the upgrade flag is passed. The electronic device can be repaired and restored through the version rollback. For example, when the compatibility of the electronic device with the new version is poor, resulting in a decline in the user experience, the electronic device can be restored to a system with better compatibility through version rollback. And the version rollback needs to pass the verification of the upgrade flag, which requires the current flashing processing personnel to have the processing authority for system rollback, generally the equipment manufacturer, or the R&D researcher authorized by the manufacturer, the equipment maintenance personnel authorized by the manufacturer and other compliance personnel, thereby avoiding information leakage and illegal use of electronic equipment.

[0168] The following describes how to upgrade the mobile phone version when the upgrade verification fails.

[0169] Taking the system version currently running on the electronic device as the second version, the version number of the second version as the second version number, and the upgraded version of the electronic device as the third version, the version number of the third version as the third version number as an example, the following steps are included:

[0170] See also Figure 6 , this figure is a flowchart of another system version updating method provided in an embodiment of the present application.

[0171] S61: Start flashing the firmware.

[0172] S62: Determine whether the current upgrade flag verification fails.

[0173] When the electronic device detects that the upgrade flag is not currently written, that is, when the upgrade flag is empty, it is determined that the current upgrade flag verification has failed; or when the electronic device performs signature verification on the upgrade flag and finds that there is a data error, it is determined that the current upgrade flag verification has failed, and an HMAC verification is performed at this time.

[0174] S63: Determine the HMAC set according to the third version of the flash version list.

[0175] The third version of the flash version list includes the first version number, the second version number and the third version number. The first version number, the second version number and the third version number are all processed using the HMAC algorithm to obtain an HMAC set, and the HMAC set includes the HMAC corresponding to the first version number, the HMAC corresponding to the second version number and the HMAC corresponding to the third version number.

[0176] S64: Determine that the HMAC set at this time includes the first HMAC stored in the electronic device.

[0177] The version currently running on the electronic device is the second version, and at this time the first HMAC stored in the data storage area of ​​the electronic device is the HMAC corresponding to the second version number.

[0178] The HMAC set is compared with the first HMAC, and it is found that the HMAC set includes the first HMAC, which indicates that the flashing is for upgrading the system version.

[0179] S65: Electronic equipment allows system updates.

[0180] At this time, the electronic device performs a system update and completes the subsequent flashing steps.

[0181] S66: The electronic device deletes the upgrade mark.

[0182] The electronic device deletes the upgrade mark, which, on the one hand, releases storage space and, on the other hand, prevents the upgrade mark from being obtained externally.

[0183] It is understandable that the division of the above steps is only for the convenience of explanation and does not constitute a limitation on the technical solution of the present application. In actual applications, the order of the above steps can be adjusted. For example, when the upgrade mark is not written to the electronic device during verification in S62, S66 may not be executed.

[0184] To sum up, the solution provided in the embodiment of the present application allows the electronic device to perform a normal system upgrade by performing an HMAC check when the check of the upgrade flag fails. Since the upgraded higher version is compatible with the locking capability of the lower version, the electronic device after the system is upgraded can be locked normally to avoid information leakage and illegal use of the electronic device.

[0185] Based on the system version updating method provided in the above embodiment, the embodiment of the present application further provides an electronic device, which is described in detail below with reference to the accompanying drawings.

[0186] See also Figure 7 , which is a schematic diagram of an electronic device provided in an embodiment of the present application.

[0187] The electronic device 70 may include a processor 701 , a memory 702 and a bus 703 .

[0188] The processor 701 and the memory 702 communicate with each other via the bus 703 .

[0189] The processor 701 may include one or more processing units, for example, the processor 701 may include an application processor (AP), a modem processor, a graphics processor (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated into one or more processors. A memory may also be provided in the processor 701 for storing instructions and data. In some embodiments, the memory in the processor 701 is a cache memory. The memory may store instructions or data that the processor 701 has just used or circulated. If the processor 701 needs to use the instruction or data again, it may be directly called from the memory. Repeated access is avoided, the waiting time of the processor 701 is reduced, and the efficiency of the system is improved.

[0190] The memory 702 may be used to store computer executable program codes, which include instructions. The memory 702 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application program required for at least one function, etc. The data storage area may store data created during the use of the electronic device, etc. The first HMAC in the embodiment of the present application is stored in the data storage area. The data storage area is also used to store an upgrade flag file or upgrade flag data written into the electronic device during upgrade flag verification.

[0191] In addition, the memory 702 may include a high-speed random access memory and may also include a non-volatile memory. The processor 701 executes the system version update method in the above embodiment by running instructions stored in the memory 702 and / or instructions stored in a memory disposed in the processor.

[0192] It is understandable that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on the electronic device 70. In other embodiments of the present application, the electronic device 70 may include more or fewer components than shown, or combine some components, or separate some components, or arrange the components differently.

[0193] The software architecture of the electronic device is described below.

[0194] See also Figure 8 , which is a software architecture diagram of the electronic device provided in an embodiment of the present application.

[0195] The environment in which mobile electronic devices run operating systems (OS) such as Android and IOS is called Rich Execution Environment (REE). Electronic devices also include Trusted Execution Environment (TEE). TEE is an independent execution environment that runs alongside REE, has its own execution space, and has a higher level of security. The operating systems running in the TEE environment are called TEE OS.

[0196] For operating systems running in REE environments, take the layered architecture Android system as an example. The layered architecture divides the software into several layers, and each layer has a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into the application layer, application framework layer, Android runtime and system library, hardware abstraction layer (HAL) and kernel layer from top to bottom.

[0197] The application layer may include a series of application packages, such as camera, gallery, calendar, etc. The application layer may also include a flashing APP, through which the user may start the flashing process for the electronic device, thereby triggering the verification of the upgrade flag.

[0198] The application framework layer provides an application programming interface (API) and a programming framework for the applications in the application layer. The application framework layer includes some predefined functions. The application framework layer may include a window manager, a content provider, a view system, a phone manager, a resource manager, a notification manager, etc.

[0199] Android Runtime includes core libraries and virtual machines. Android runtime is responsible for scheduling and management of the Android system.

[0200] The core library consists of two parts: one is the function that the Java language needs to call, and the other is the Android core library. The application layer and the application framework layer run in the virtual machine. The virtual machine executes the Java files of the application layer and the application framework layer as binary files. The virtual machine is used to perform object life cycle management, stack management, thread management, security and exception management, and garbage collection.

[0201] The system library may include multiple functional modules, such as surface manager, media library, 3D graphics processing library (such as OpenGL ES), 2D graphics engine (such as SGL), etc.

[0202] The hardware abstraction layer is a routine package of the software layer. It is an interface layer located between the operating system kernel and the hardware circuit. Its purpose is to abstract the hardware and simulate the details of a specific system platform so that the program can directly access the hardware resources.

[0203] In a possible implementation, the hardware abstraction layer is an Original Equipment Manufacturer (OEM) module included in the OEM module, and the HMAC corresponding to the earlier version number of the electronic device can be stored in the oeminfo storage file in the OEM module.

[0204] The kernel layer is the layer between hardware and software. The kernel layer contains at least display driver, camera driver, audio driver, and sensor driver.

[0205] In the embodiment of the present application, the TEE OS running in the TEE environment mainly includes a key derivation module, a secure storage module, an HMAC conversion module and an HMAC interface.

[0206] Among them, the key derivation module is used to generate the key K for HMAC operation. The key K uniquely corresponds to the electronic device itself, and different electronic devices generate different keys K.

[0207] The secure storage module is used to store the key K. Since the TEE environment has a high level of security, it can ensure that the key K generated locally by the electronic device cannot be obtained externally.

[0208] The HMAC conversion module user converts the version number into the corresponding HMAC.

[0209] The HMAC interface is used to output the HMAC obtained by the HMAC conversion module, that is, to output the HMAC to the REE environment.

[0210] Specifically, when performing HMAC verification, the external device needs to provide a list of flash versions corresponding to this flash, which includes the upgrade version number and the version number before the upgrade version number. The HMAC conversion module calls the key K in the secure storage module, and converts each version number included in the flash version list into a corresponding HMAC according to the HMAC algorithm, thereby obtaining an HMAC set. The HMAC interface outputs the HMAC set, and the REE environment compares the HMAC set with the first HMAC to determine whether the HMAC verification passes.

[0211] When the system update is completed, the HMAC conversion module calls the key K in the security storage module and processes the upgrade version number according to the HMAC algorithm to obtain the HMAC corresponding to the upgrade version number. The HMAC interface outputs the HMAC corresponding to the upgrade version number and updates the HMAC stored in the OEM module in the REE environment so that the first HMAC of the electronic device is updated to the HMAC corresponding to the upgrade version number.

[0212] For detailed description of the method for updating the system version, please refer to the above method embodiment, which will not be repeated here.

[0213] In summary, when the electronic device provided in the embodiment of the present application is flashed, the upgrade flag is first verified. The upgrade flag is signed with an encryption algorithm and bound to the electronic device, which is unique and tamper-proof. The key used by the encryption algorithm has access rights. When the user passes the verification of the upgrade flag, the user is allowed to update the system version as needed, such as upgrading or rolling back.

[0214] When the user fails to pass the verification of the upgrade flag, a version number verification is required. The version number verification of this application is an HMAC verification. During the HMAC verification, the key used is generated and saved in the TEE OS of the electronic device. The key generated by each electronic device is different and cannot be obtained from the outside, which has high security. And an HMAC set will be generated in the TEE OS, which includes the HMAC corresponding to the upgraded version of the electronic device and the HMAC corresponding to each earlier version of the upgraded version. The data storage area of ​​the electronic device includes a first HMAC, which is the HMAC corresponding to the version number of the earlier version of the electronic device. Then determine whether the first HMAC is included in the HMAC set. When included, it is determined that the system update at this time is an upgrade update, and the system upgrade is allowed. When not included, it is determined that the system update at this time is a downgrade update, that is, the system version is rolled back, and the system upgrade is not allowed at this time.

[0215] Since the key cannot be obtained from the outside, the HMAC corresponding to the correct version number cannot be generated, and the HMAC verification cannot be passed by replacing or modifying the first HMAC stored in the electronic device. Moreover, since the key uniquely corresponds to the electronic device, directly transplanting the first HMAC of other electronic devices will also fail the HMAC verification.

[0216] In summary, this solution can significantly improve the anti-rollback capability of the system version, thereby reducing the risk of information leakage and illegal use of electronic devices.

[0217] The embodiment of the present application also provides a storage medium on which a program is stored, and when the program is executed by a processor, the system version updating method is implemented.

[0218] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, parameter random access memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically-erasable programmable read-only memory (EEPROM), flash memory or other memory technologies.

[0219] It should be understood that in the present application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0220] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for updating a system version, characterized in that: Applied to electronic equipment, the method comprises: Verify the upgrade flag, which is signed using an encryption algorithm; When the verification passes, the system version is allowed to be upgraded or rolled back; When the verification fails, using a key-hash message authentication code HMAC algorithm to process each version number in a version list obtained when the system version is updated to obtain an HMAC set, wherein the version list includes the version number of the updated version and the version numbers of each earlier version of the updated version, and the key used by the HMAC algorithm is generated by the electronic device and uniquely corresponds to the electronic device; When it is determined that the HMAC set includes the first HMAC, the system version is allowed to be upgraded to the updated version, and the first HMAC is the HMAC corresponding to the version number of the current system version stored on the electronic device; otherwise, the system version is not allowed to be updated.

2. The method according to claim 1, characterized in that The upgrade mark is signed by using an RSA encryption algorithm, and the RSA encryption algorithm uses a first hash algorithm. The verification of the upgrade mark specifically includes: When the upgrade flag is obtained, the upgrade flag is decrypted using the public key of the RSA encryption algorithm to obtain a first hash value; Using the first hash algorithm to process an original upgrade flag to obtain a second hash value, the original upgrade flag is not signed by using the RSA encryption algorithm; When the first Hash value is the same as the second Hash value, it is determined that the upgrade flag check is passed; otherwise, it is determined that the upgrade flag check is not passed.

3. The method according to claim 2, characterized in that The checking of the upgrade flag specifically includes: When the upgrade flag is not obtained, it is determined that the upgrade flag check fails.

4. The method according to claim 2, characterized in that: When the verification is passed, the method further includes: Upgrade the system version or roll back to the first version. Processing the version number of the first version using the HMAC algorithm to obtain an HMAC corresponding to the version number of the first version; The first HMAC is updated to the HMAC corresponding to the version number of the first version.

5. The method according to claim 4, characterized in that After updating the first HMAC to the HMAC corresponding to the version number of the first version, the method further includes: The upgrade mark is deleted on the electronic device.

6. The method according to claim 2, characterized in that After determining that the HMAC set includes the first HMAC, the method further includes: Upgrade the system version to the second version; Processing the version number of the second version using the HMAC algorithm to obtain an HMAC corresponding to the version number of the second version; Update the first HMAC to the HMAC corresponding to the version number of the second version.

7. The method according to claim 2, characterized in that When the current system version is a production test version, the first HMAC stored in the electronic device is empty data, and when the verification passes, the method further includes: Update the system version to the third version; Processing the version number of the third version using the HMAC algorithm to obtain an HMAC corresponding to the version number of the third version; The HMAC corresponding to the version number of the third version is written into the data storage area as the first HMAC of the electronic device.

8. The method according to claim 7, characterized in that After writing the HMAC corresponding to the version number of the third version into the data storage area, the method further includes: The upgrade mark is deleted on the electronic device.

9. The method according to claim 1, characterized in that: The current system version is the fourth version. When the verification passes, or when it is determined that the HMAC set includes the first HMAC, the method further includes: Updating the system version to the fourth version; Processing the version number of the fourth version using the HMAC algorithm to obtain an HMAC corresponding to the version number of the fourth version; Update the first HMAC to the HMAC corresponding to the version number of the fourth version.

10. An electronic device, characterized in that: The electronic device is used to run a program, and when the program is running, the system version updating method described in any one of claims 1 to 9 is executed.

11. A storage medium, characterized in that: A computer program is stored thereon, and when the program is executed by a processor, the system version updating method described in any one of claims 1 to 9 is implemented.

Citation Information

Patent Citations

  • Version check method and device and terminal equipment

    CN106650460A

  • System version upgrade method and device

    CN107678762A

  • Content transmission protection method and related equipment thereof

    CN116134825A

  • Method and system for upgrading and rolling back versions

    US20030221189A1

  • Method and System for Deploying Advanced Cryptographic Algorithms

    US20080130895A1