Application upgrading method and device in secure element, equipment and storage medium
By introducing upgrade management applications into the security components and using upgrade files to generate upgrade management instruction sets, offline and batch upgrades of security components are achieved, solving the problems of low upgrade efficiency and complexity in the existing technology, and improving the automation and stability of upgrades.
Patent Information
- Application Number
- CN202411841230.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-13
AI Technical Summary
The prior art cannot realize offline upgrades and batch upgrades of security components, and the upgrade efficiency is low, and it cannot be upgraded without communicating with the server. The upgrade process is complicated, with many participants, and the efficiency is low.
By obtaining the upgrade file of the security component in the target device and sending it to the upgrade management application, generating an upgrade management instruction set based on the upgrade file, adopting an online or offline upgrade strategy, including including the upgrade files of the new and old versions of the application before the upgrade is successful, and automatically upgrading the new version of the application to ensure automation and unmanned mechanism of the upgrade process.
Offline upgrades and batch upgrades of security components are realized, reducing upgrade participants and complexity, improving upgrade efficiency, ensuring system stability and security, and avoiding service interruptions caused by upgrade failure.
Smart Images

Figure CN119987804A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of software upgrade, and in particular to an application upgrade method, device, equipment and storage medium in a security element. Background Art
[0002] In today's era of rapid technological development, electronic information and embedded technology are increasingly used in various fields, among which security technology is particularly important. As a key technology for protecting data security and achieving security authentication, security elements appear in various industries in the form of embedded security modules (eSE), SIM / UICC smart cards, eUICC chips, and Bank of Communications smart cards, playing a vital role. These security elements play a core role in many fields such as Internet of Vehicles, Internet of Things, mobile payment, smart cards and identity authentication, industrial Internet, smart home and building automation, and health care. They provide secure storage, processing, and transmission of data while preventing various forms of network attacks and data leaks.
[0003] As technology develops and threats continue to evolve, security systems need to be regularly updated to address new security threats. By upgrading applications in secure elements, known security vulnerabilities can be fixed, security protection measures can be enhanced, and system security can be continuously strengthened. In addition, secure element application upgrades can introduce new features and improvements to improve the performance and efficiency of secure elements. At the same time, as regulations and standards are updated, secure elements also need to be upgraded to meet new compliance requirements.
[0004] In the prior art, one solution involves real-time connection with the server to establish a secure channel, and the server generates secure element management instructions (such as deletion, downloading, and installation) in a point-to-point manner to upgrade the application. However, this solution requires online interaction with the server and requires the device to be connected to the Internet, which affects efficiency and cannot achieve batch upgrades; during the deletion process of the application, the running data cannot be saved, and secondary personalization and other operations are required, which increases the number of participants and complexity of the upgrade. Summary of the invention
[0005] The embodiments of the present application provide a method, apparatus, device and storage medium for upgrading an application in a security element, so as to at least solve the technical problems in the related art of being unable to perform offline upgrading, batch upgrading and low upgrading efficiency.
[0006] According to one aspect of an embodiment of the present application, a method for upgrading an application in a security element is provided, comprising:
[0007] The target device obtains an upgrade file of the security element, and sends the upgrade file to an upgrade management application in the security element;
[0008] The upgrade management application obtains an upgrade management instruction set based on the upgrade file;
[0009] The upgrade management application performs online or offline upgrade of the security element based on the upgrade management instructions and upgrade strategy in the upgrade management instruction set. The upgrade strategy includes that before the upgrade is successful, the upgrade management application contains both the new and old version application upgrade files.
[0010] In one embodiment, the upgrade management application performs online or offline upgrade of the security element based on the upgrade management instructions and upgrade strategy in the upgrade management instruction set, and the upgrade strategy process includes:
[0011] Receive an upgrade start instruction, record the upgrade file information of the new and old versions of the application, the identifiers of the upgrade files of the new and old versions of the application are different, and obtain automatic upgrade flag information;
[0012] Receive application download instructions and save application download data until a complete application executable file is received;
[0013] After the download is completed, the new version application is automatically upgraded based on the automatic upgrade mark in the automatic upgrade flag information.
[0014] In one embodiment, after the application is successfully installed and upgraded, the method further includes:
[0015] Delete old versions of applications, backup information, and upgrade management information;
[0016] Change the identity of the new version of the app to the same identity as the old version of the app.
[0017] In one implementation, after the application upgrade fails, the method further includes:
[0018] Delete installed new version applications, backup information, and upgrade management information;
[0019] Perform application upgrade and restore based on the old version of the application already in the system.
[0020] In one implementation, after the download is completed, based on the automatic upgrade identifier in the automatic upgrade flag information, the new version application is automatically upgraded, including:
[0021] Receive the notification of successful execution of the last instruction of the application download, install the new version of the application based on the automatic upgrade flag in the automatic upgrade flag information; call the upgrade backup API of the old version of the application to complete the backup of the application data;
[0022] Call the upgrade recovery API of the new version of the application to complete the recovery of application data.
[0023] In one implementation, before the target device obtains the upgrade file of the security element, the method further includes:
[0024] Upgrade the server to generate a new version of the application executable file;
[0025] The upgrade server generates an upgrade management instruction set using the application executable file;
[0026] The upgrade server generates a one-time public-private key pair for key negotiation; and negotiates a symmetric key through a key negotiation algorithm;
[0027] The upgrade server uses the symmetric key to perform security processing on the upgrade management instruction set to generate a ciphertext upgrade management instruction set, and the upgrade server uses the one-time public key and the ciphertext upgrade management instruction set to generate an upgrade file for the security element.
[0028] In one implementation, the upgrade management application obtains an upgrade management instruction set based on the upgrade file, including:
[0029] The upgrade management application uses the key negotiation algorithm to negotiate the same symmetric key as the server;
[0030] The upgrade file is verified and decrypted based on the symmetric key to obtain the decrypted upgrade management instruction set.
[0031] According to another aspect of an embodiment of the present application, there is provided an application upgrade device in a security element, comprising:
[0032] A target device, used to obtain an upgrade file of a secure element and send the upgrade file to an upgrade management application in the secure element;
[0033] An upgrade management application module is used to obtain an upgrade management instruction set based on the upgrade file; based on the upgrade management instructions and upgrade strategy in the upgrade management instruction set, perform online or offline upgrade of the security element, and the upgrade strategy includes that before the upgrade is successful, the upgrade management application contains both the new and old version application upgrade files.
[0034] According to another aspect of an embodiment of the present application, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the application upgrade method in the security element through the computer program.
[0035] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the application upgrade method in the above-mentioned security element when running.
[0036] The technical solution provided by the embodiments of the present application may have the following beneficial effects:
[0037] In the scheme of the embodiment of the present application, during the offline upgrade process of the security element application (the device cannot communicate with the server), the offline upgrade package of the security element is stored in the terminal device, and the device sends the upgrade data to the security element through the upgrade instruction to complete the upgrade process. There is no need to communicate with the server throughout the process, and offline upgrades and batch upgrades can be achieved, which reduces the number of upgrade participants, reduces the upgrade complexity, and improves the efficiency of application upgrades.
[0038] Furthermore, this application will not delete the old version of the application before the upgrade is successful, and the old and new versions will coexist. When dealing with upgrade failures, exceptions, and other problems encountered during the offline upgrade process, it can ensure that the security application will not be in an unavailable state due to abnormal problems, thereby ensuring the normal operation of the security element and the smooth progress of security services. The upgrade process does not require intervention from users, terminal devices, or servers, and the upgrade process is completed automatically; if the upgrade fails, the application to be upgraded will be kept in the state before the upgrade, which will not affect the available state of the application to be upgraded. It can ensure that the application to be upgraded is in the two states of upgrade completion or non-upgrade, and the security service will not be interrupted due to upgrade failure. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0040] Figure 1 is a flow chart of an application upgrade method in a security element according to an embodiment of the present application;
[0041] Figure 2 is a flow chart of an upgrade file installation method according to an embodiment of the present application;
[0042] Figure 3 is a schematic diagram of an application upgrade device in a security element according to an embodiment of the present application;
[0043] Figure 4 It is a schematic diagram of the structure of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0044] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0045] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0046] During the offline upgrade process of the secure element application (the device cannot communicate with the server), the secure element offline upgrade package is stored in the terminal device, and the device sends the upgrade data to the secure element through the upgrade command to complete the upgrade process. In this process, the following problems may further occur:
[0047] 1. The communication between the terminal device and the security element is unstable, causing the upgrade process to be interrupted;
[0048] 2. An error occurs during the security element upgrade process, causing the upgrade process to be interrupted;
[0049] General processing logic of terminal equipment:
[0050] 1. If the upgrade is interrupted due to communication interruption, the device uses breakpoint resume or restarts the upgrade process;
[0051] 2. The terminal device stores two sets of upgrade file data, new and old. When the device determines that the upgrade of the new version upgrade file fails, it uses the old upgrade file to restore to the state before the upgrade.
[0052] However, in actual use, many devices do not have the ability to complete the above processing logic:
[0053] 1. For offline upgrades, the terminal device cannot communicate with the server and cannot resolve upgrade failure issues by interacting with the server;
[0054] 2. The device processing capacity is limited and cannot complete breakpoint resumption. Automatically complete the upgrade according to the abnormal upgrade status and use the old upgrade file to restore the status before the upgrade.
[0055] This will eventually cause the upgrade process to fail, the security application data or code to be damaged, resulting in the security application being unable to work properly, the security element being unable to provide security services to the business, causing serious problems such as device malfunction and business function interruption.
[0056] This application can ensure that the security application will not be in an unavailable state due to abnormal problems, thereby ensuring the normal operation of the security element and the smooth progress of the security business.
[0057] The following is combined with Figure 1-2 The application upgrade method in the security element of the embodiment of the present application is described in detail. Figure 1 As shown, the method mainly includes the following steps:
[0058] S101: The target device obtains an upgrade file of the secure element and sends the upgrade file to an upgrade management application in the secure element.
[0059] The target device is a device that needs to upgrade the secure element, such as vehicles, industrial automation equipment, smart home devices, etc. If the upgrade scenario is an offline upgrade, the device cannot communicate with the server, and the upgrade file of the secure element generated by the server can be obtained through a USB flash drive or other means. Then the upgrade file is sent to the upgrade management application in the secure element.
[0060] Before the target device obtains the upgrade file of the security element, the method also includes: the upgrade server generates a new version application executable file; the upgrade server uses the application executable file to generate an upgrade management instruction set.
[0061] Furthermore, the upgrade server generates a one-time public-private key pair for key negotiation; a symmetric key is negotiated through a key negotiation algorithm; the upgrade server uses the symmetric key to securely process the upgrade management instruction set to generate a ciphertext upgrade management instruction set, and the upgrade server uses the one-time public key and the ciphertext upgrade management instruction set to generate an upgrade file for the security element.
[0062] Specifically, first, the upgrade server needs to generate a new version of the application executable file, and then the upgrade server uses the new version of the application executable file to generate an upgrade management instruction set, which includes upgrade management instructions and application download instructions. The upgrade server generates a one-time public-private key pair for key negotiation, and negotiates a symmetric key through a key negotiation algorithm, which includes an encryption key (K_ENC) and a message authentication code key (K_MAC).
[0063] The upgrade server uses the negotiated symmetric key to securely process the upgrade management instruction set and generate a ciphertext upgrade management instruction set. The securely processed upgrade instruction includes an instruction header, ciphertext data, and a first message authentication code (MAC). Finally, the upgrade server uses the one-time public key and the ciphertext upgrade management instruction set to generate an upgrade file for the security element.
[0064] This process ensures the security and integrity of the upgrade file. Through key negotiation and symmetric encryption technology, it protects data security during the upgrade process and prevents unauthorized access and tampering.
[0065] S102: The upgrade management application obtains an upgrade management instruction set based on the upgrade file.
[0066] In one embodiment, the upgrade management application obtains an upgrade management instruction set based on the upgrade file, including: the upgrade management application negotiates a symmetric key that is the same as the server using a key negotiation algorithm; and verifies and decrypts the upgrade file based on the symmetric key to obtain a decrypted upgrade management instruction set.
[0067] The upgrade management application uses the server's public key (ePK_SERVER_KA) and its own private key (SK_MANAGE_APP_KA) to negotiate a symmetric key consistent with the server through a key negotiation algorithm. This symmetric key includes an encryption key (K_ENC) and a message authentication code key (K_MAC).
[0068] The upgrade management application uses the negotiated K_MAC to verify the MAC in the upgrade file. This step is to ensure the integrity and authenticity of the upgrade file and prevent the file from being tampered with during transmission.
[0069] Decryption using K_ENC: Once the MAC verification is passed, the upgrade management application uses K_ENC to decrypt the ciphertext upgrade management instruction set in the upgrade file. This step converts the ciphertext back to plaintext and restores the original upgrade management instruction set.
[0070] S103 The upgrade management application performs online or offline upgrade of the security element based on the upgrade management instructions and upgrade strategy in the upgrade management instruction set. The upgrade strategy includes that before the upgrade is successful, the upgrade management application includes both the new and old version application upgrade files.
[0071] The upgrade strategy of the security element of the present application can be applied in online upgrade scenarios and offline upgrade scenarios. Preferably, it is applied in offline upgrades to solve upgrade exception problems that may occur in offline upgrades and ensure the availability of the security element.
[0072] In one embodiment, the upgrade management application performs online or offline upgrade of the security element based on the upgrade management instructions and upgrade policies in the upgrade management instruction set. The upgrade policy process includes:
[0073] Receive the start upgrade instruction, record the new and old version application upgrade file information, the new and old version application upgrade file identifiers are different, and obtain the automatic upgrade flag information.
[0074] Specifically, after receiving the upgrade management start instruction: the upgrade management information in the record instruction includes relevant information of the new and old application upgrade files. In order for the new and old application files to coexist, the AID identifiers of the two cannot be the same.
[0075] The solution of this application does not delete the old version application and data immediately after receiving the upgrade start instruction. Instead, the new and old application files coexist. At this time, the new and old version application identifiers are different.
[0076] The upgrade management information also includes an automatic upgrade option, which is used to indicate that after the new version file is downloaded, the subsequent upgrade process is automatically completed. It can be set in advance in the upgrade management start instruction. For example, the automatic upgrade flag can be set. If the flag is set to 1 in advance, the automatic upgrade is performed subsequently without issuing other upgrade management instructions, reducing instruction interactions and improving automation.
[0077] Further, an application download instruction is received, and the application download data is saved until a complete application executable file is received.
[0078] Furthermore, after the download is completed, the new version application is automatically upgraded based on the automatic upgrade mark in the automatic upgrade flag information.
[0079] The solution of the present application receives a notification of successful execution of the last instruction of the application download, and installs the new version of the application based on the automatic upgrade identifier in the automatic upgrade flag information; calls the upgrade backup API of the old version of the application to complete the backup of the application data; and calls the upgrade recovery API of the new version of the application to complete the recovery of the application data.
[0080] It can be seen that the solution of this application does not need to receive the upgrade management "restore" instruction again. After the application downloads the last instruction and executes it successfully, it immediately makes an API call to implement the subsequent upgrade process.
[0081] In one implementation, after the application is successfully installed and upgraded, the old version of the application, the backup information, and the upgrade management information are deleted; and the identifier of the new version of the application is changed to the same identifier as that of the old version of the application.
[0082] In one implementation, after the application upgrade fails, the installed new version application, backup information, and upgrade management information are deleted; the application upgrade is restored based on the old version application already in the system. The old version application of this application is still in the security management application, and can be rolled back based on the old version. However, the solution of the prior art needs to contact the device and server to manually re-issue the old version application because the old version has been deleted.
[0083] It can be seen that in the solution of this application, if an error occurs in any instruction before the last download instruction is executed, the system will not continue the upgrade process and will not delete the old version data. This ensures the stability of the system and prevents data loss due to upgrade errors. The old version of the data will only be deleted after all instructions, including backup and restore operations, have been successfully completed. This ensures that the user's data and system status can be protected when any step fails during the upgrade process.
[0084] The design of the entire upgrade process reduces the risk of system failure due to upgrade errors, and improves system reliability and user trust.
[0085] In order to facilitate understanding of the installation method of the upgrade file in the embodiment of the present application, the following Figure 2 Further description.
[0086] like Figure 2 As shown, first, the system receives the instruction to start upgrading and records the upgrade file information of the new and old versions of the application. This information includes the identification of the new and old versions, as well as the automatic upgrade flag information. Next, the system receives the application download instruction and starts saving the application download data. This process continues until the system receives the complete application executable file.
[0087] Execute upgrade: After receiving the last instruction of the application download and executing it successfully, the system will install the new version of the application according to the automatic upgrade flag in the automatic upgrade flag information; call the upgrade backup API of the old version of the application to complete the backup of the application data. Subsequently, call the upgrade recovery API of the new version of the application to complete the recovery of the application data.
[0088] Determine whether the upgrade is successful: After completing the above steps, the system will determine whether the upgrade is successful. If the upgrade fails, the system will delete the installed new version of the application, backup information, and upgrade management information, and perform application upgrade restoration based on the old version of the application already in the system.
[0089] Upgrade success processing: If the upgrade is successful, the system will delete the old version application, backup information and upgrade management information. Finally, complete the conversion of the new version application to the old version application identity to ensure the normal operation of the system.
[0090] The application upgrade method of the security element provided in the embodiment of the present application does not require breakpoint resumption, and the upgrade process is designed so that the breakpoint resumption function is not required at the critical stage. This means that even if the upgrade process is interrupted, the device can resend the upgrade instruction from the beginning and execute it normally. The entire upgrade process does not require the intervention of the user, terminal device or server and can be completed automatically. The upgrade operation is simplified, the possibility of human error is reduced, and the convenience and efficiency of the upgrade are improved. If the upgrade fails, the system will keep the application to be upgraded in the state before the upgrade, which will not affect the available state of the application and will not interrupt related services. The continuity of the business is guaranteed and service interruptions caused by upgrade failures are avoided.
[0091] The upgrade process is designed as an atomic operation, that is, the upgrade is either completely successful or completely rolled back to the state before the upgrade. This ensures the stability of the system and prevents security issues caused by incomplete states during the upgrade process.
[0092] A batch processing upgrade method is provided to upgrade multiple applications at the same time, which improves the efficiency of the upgrade and reduces the impact on users and system resources.
[0093] The automatic backup and recovery mechanism ensures data integrity during the upgrade process.
[0094] The upgrade method of the present application has broad application prospects in the industry, especially in scenarios requiring offline upgrades, which can significantly improve the reliability and security of upgrades and reduce risks during the upgrade process.
[0095] According to another aspect of the embodiments of the present application, there is also provided an application upgrade device in a secure element for implementing the application upgrade method in the secure element. Figure 3 As shown, the apparatus includes: a device 200, a security element 201, and an upgrade management application 202 in the security element.
[0096] The target device is used to obtain the upgrade file of the secure element and send the upgrade file to the upgrade management application in the secure element;
[0097] The upgrade management application module is used to obtain an upgrade management instruction set based on the upgrade file; based on the upgrade management instructions and upgrade strategy in the upgrade management instruction set, the security element is upgraded online or offline, and the upgrade strategy includes that before the upgrade is successful, the upgrade management application contains both the old and new version application upgrade files.
[0098] It should be noted that the application upgrade device in the security element provided in the above embodiment only uses the division of the above functional modules as an example when executing the application upgrade method in the security element. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the application upgrade device in the security element provided in the above embodiment and the application upgrade method embodiment in the security element belong to the same concept, and the implementation process thereof is detailed in the method embodiment, which will not be repeated here.
[0099] According to another aspect of an embodiment of the present application, an electronic device corresponding to the application upgrade method in a security element provided in the aforementioned embodiment is also provided to execute the application upgrade method in the aforementioned security element.
[0100] Please refer to Figure 4 , which shows a schematic diagram of an electronic device provided by some embodiments of the present application. Figure 4 As shown, the electronic device includes: a processor 300, a memory 301, a bus 302 and a communication interface 303, and the processor 300, the communication interface 303 and the memory 301 are connected via the bus 302; the memory 301 stores a computer program that can be run on the processor 300, and when the processor 300 runs the computer program, the application upgrade method in the security element provided in any of the aforementioned embodiments of the present application is executed.
[0101] The memory 301 may include a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk memory. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 303 (which may be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. may be used.
[0102] The bus 302 may be an ISA bus, a PCI bus, or an EISA bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. Among them, the memory 301 is used to store programs, and the processor 300 executes the program after receiving the execution instruction. The application upgrade method in the security element disclosed in any implementation of the embodiment of the present application may be applied to the processor 300, or implemented by the processor 300.
[0103] The processor 300 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 300. The above processor 300 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a readily available programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application can be directly embodied as a hardware decoding processor to be executed, or the hardware and software modules in the decoding processor can be executed. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 301, and the processor 300 reads the information in the memory 301 and completes the steps of the above method in combination with its hardware.
[0104] The electronic device provided in the embodiment of the present application and the application upgrade method in the security element provided in the embodiment of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented therein.
[0105] According to another aspect of the embodiments of the present application, a computer-readable storage medium corresponding to the application upgrade method in the security element provided in the aforementioned embodiments is also provided, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it will execute the application upgrade method in the security element provided in any of the aforementioned embodiments.
[0106] It should be noted that examples of computer-readable storage media may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical or magnetic storage media, which are not listed here one by one.
[0107] The computer-readable storage medium provided in the above-mentioned embodiments of the present application and the application upgrade method in the security element provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the method adopted, run or implemented by the application program stored therein.
[0108] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0109] The above embodiments only express several implementation methods of the present invention, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present invention. It should be pointed out that, for a person of ordinary skill in the art, several modifications and improvements can be made without departing from the concept of the present invention, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the attached claims.
Claims
1. A method for upgrading an application in a security element, characterized in that: include: The target device obtains an upgrade file of the security element, and sends the upgrade file to an upgrade management application in the security element; The upgrade management application obtains an upgrade management instruction set based on the upgrade file; The upgrade management application performs online or offline upgrade of the security element based on the upgrade management instructions and upgrade strategy in the upgrade management instruction set. The upgrade strategy includes that before the upgrade is successful, the upgrade management application contains both the new and old version application upgrade files.
2. The method according to claim 1, characterized in that: The upgrade management application performs online or offline upgrade of the security element based on the upgrade management instructions and upgrade strategy in the upgrade management instruction set. The upgrade strategy process includes: Receive an upgrade start instruction, record the upgrade file information of the new and old versions of the application, the identifiers of the upgrade files of the new and old versions of the application are different, and obtain automatic upgrade flag information; Receive application download instructions and save application download data until a complete application executable file is received; After the download is completed, the new version application is automatically upgraded based on the automatic upgrade mark in the automatic upgrade flag information.
3. The method according to claim 2, characterized in that After the application is successfully installed and upgraded, it also includes: Delete old versions of applications, backup information, and upgrade management information; Change the identity of the new version of the app to the same identity as the old version of the app.
4. The method according to claim 2, characterized in that: After an application upgrade fails, it also includes: Delete installed new version applications, backup information, and upgrade management information; Perform application upgrade and restore based on the old version of the application already in the system.
5. The method according to claim 2, characterized in that: After the download is completed, the new version application is automatically upgraded based on the automatic upgrade mark in the automatic upgrade flag information, including: Receive the notification of successful execution of the last instruction of the application download, install the new version of the application based on the automatic upgrade flag in the automatic upgrade flag information; call the upgrade backup API of the old version of the application to complete the backup of the application data; Call the upgrade recovery API of the new version of the application to complete the recovery of application data.
6. The method according to claim 1, characterized in that Before the target device obtains the upgrade file of the secure element, it also includes: Upgrade the server to generate a new version of the application executable file; The upgrade server generates an upgrade management instruction set using the application executable file; The upgrade server generates a one-time public-private key pair for key negotiation; and negotiates a symmetric key through a key negotiation algorithm; The upgrade server uses the symmetric key to perform security processing on the upgrade management instruction set to generate a ciphertext upgrade management instruction set, and the upgrade server uses the one-time public key and the ciphertext upgrade management instruction set to generate an upgrade file for the security element.
7. The method according to claim 1, characterized in that The upgrade management application obtains an upgrade management instruction set based on the upgrade file, including: The upgrade management application uses the key negotiation algorithm to negotiate the same symmetric key as the server; The upgrade file is verified and decrypted based on the symmetric key to obtain the decrypted upgrade management instruction set.
8. An application upgrade device in a security element, characterized in that: include: A target device, used to obtain an upgrade file of a secure element and send the upgrade file to an upgrade management application in the secure element; An upgrade management application module, used to obtain an upgrade management instruction set based on the upgrade file; Based on the upgrade management instructions and upgrade strategies in the upgrade management instruction set, the security element is upgraded online or offline. The upgrade strategy includes that before the upgrade is successful, the upgrade management application includes both the new and old version application upgrade files.
9. An electronic device, characterized in that: The invention comprises a processor and a memory storing program instructions, wherein the processor is configured to execute the application upgrade method in the security element according to any one of claims 1 to 7 when executing the program instructions.
10. A computer-readable medium, characterized in that Computer-readable instructions are stored thereon, and the computer-readable instructions are executed by a processor to implement an application upgrade method in a security element as claimed in any one of claims 1 to 7.