MCU burning method and system based on authorization protection

By using encryption keys in the MCU burning system to encrypt the firmware and decrypt and verify in real time in the verification circuit board, the problem of risk of leaking the firmware during the verification process is solved, achieving higher security and authorization control.

CN120010869APending Publication Date: 2025-05-16SHANGHAI CHANGYUAN WAYON MICROELECTRONICS
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510103069.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

During firmware development, unencrypted firmware has a risk of leaks during verification, especially when external units are developing firmware.

Method used

By introducing a verification end and verification circuit board in the MCU burning system, the firmware to be burned is encrypted using an encryption key, and real-time decryption and verification are performed in the verification circuit board, so that the firmware remains encrypted during the verification phase.

Benefits of technology

It effectively avoids the risk of leaks in the firmware during the verification stage, improves the security of the firmware, and ensures that only authorized devices can perform burning operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120010869A_ABST
    Figure CN120010869A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of single-chip microcomputer firmware burning, in particular to an MCU burning method and system based on authorization protection, and the method comprises the steps: encrypting to-be-burnt firmware by adopting an encryption key to obtain encrypted firmware; writing the encrypted firmware into a verification circuit board, and verifying the encrypted firmware in the verification circuit board by adopting a verification end; and after the verification is passed, inputting the encryption key and the encryption firmware into a burner for burning. In order to solve the problem that in the prior art, in the process of verifying firmware to be burnt, the firmware is prone to leakage, the verification end and the verification circuit board are arranged, encrypted firmware is written into the verification circuit board in the verification process of a manufacturer, and the verification end is adopted to decrypt and verify corresponding partitions of the encrypted firmware in a memory in real time, so that the verification efficiency is improved. According to the method and the device, the encrypted firmware is always kept in an encrypted state in the flash memory in the verification stage, and the running data in the memory can be automatically erased after power failure, so that the problem of secret leakage caused by sending out unencrypted firmware in the verification stage is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of single-chip microcomputer firmware burning, and in particular to an MCU burning method and system based on authorization protection. Background Art

[0002] A microcontroller (MCU) is a small computer that integrates a processor, memory, and input and output interfaces. In order to store computer programs after power failure, and read and run them after power is on, microcontrollers are usually integrated with flash memory or reprogrammable read-only memory (EEPROM). Chip burning is the process of transferring code to the chip through a specific communication protocol, such as SPI, I2C, UART, etc., for the processor to execute. This process usually involves two links: on the one hand, programming the internal storage unit of the chip, and on the other hand, verifying the chip function. Burning is not just about writing code into the chip, but more importantly, ensuring that the burned program can run reliably, which requires the use of special burning tools and techniques. Since microcontrollers are widely used in industry, banking, transportation, electricity and other fields, in order to avoid firmware leakage and cracking, causing losses to related production activities, it is usually necessary to control the burning process.

[0003] For example, Chinese patent CN202411157040.7 discloses a chip burning method, a host computer and a chip burning system, which relate to the field of chip burning. This application uses a key to encrypt key information such as burning data, device identification, firmware effective time, etc. to ensure the security of data transmission and storage, and prevent unauthorized access and tampering. By generating a self-checking feature code and a mirror hash value, and performing an integrity check before burning, the accuracy and integrity of the burned data are ensured to prevent data from being damaged during transmission or storage. Allowing solution providers to set the firmware effective time and limit the number of burning times to achieve flexible control of the burning process, ensuring that only qualified devices can perform burning operations within a specific time, and preventing illegal copying and abuse.

[0004] Based on the above prior art, it can be seen that most of the burning boxes on the market are in unencrypted mode. After the customer imports his own burning file into the burner, the burning number of times is configured through software. This method is to transfer the burning file to the burning factory operator, and the burning personnel will store the burning file in the burning device. Or there is a remote operation function, the customer configures the burning file and configuration information locally, the burning factory opens the remote service, and remotely transfers the burning file to the burning device, thereby completing the file transfer.

[0005] However, in some cases, especially when the firmware development process is outsourced to an external organization, manufacturers usually also need to locally verify whether the firmware can execute the corresponding functions. If the firmware is directly verified through the above-mentioned unencrypted process, there is still a risk of leakage. Summary of the invention

[0006] In view of the above problems existing in the prior art, a MCU burning method based on authorization protection is now provided;

[0007] On the other hand, an MCU burning system for implementing the MCU burning method is also provided.

[0008] The specific technical solutions are as follows:

[0009] An MCU burning method based on authorization protection includes:

[0010] Step S1: Encrypt the firmware to be burned using an encryption key to obtain encrypted firmware;

[0011] Step S2: writing the encrypted firmware into a verification circuit board, and using a verification terminal to verify the encrypted firmware in the verification circuit board;

[0012] Step S3: After the verification is passed, the encryption key and the encrypted firmware are input into the burner for burning.

[0013] On the other hand, the step S1 comprises:

[0014] Step S11: compile the original code to obtain a binary file as the firmware to be burned;

[0015] Step S12: configuring burning information for the firmware to be burned;

[0016] The burning information includes the number of times the encrypted firmware can be used.

[0017] Step S13: generating the encryption key according to the burning information;

[0018] Step S14: using the encryption key to encrypt the firmware to be burned to obtain the encrypted firmware.

[0019] On the other hand, the step S2 comprises:

[0020] Step S21: inputting the encryption key into the verification terminal;

[0021] Step S22: flashing the encrypted firmware to the verification circuit board through the verification terminal;

[0022] Step S23: In the verification circuit board, the verification terminal is used to verify the encrypted firmware.

[0023] On the other hand, the step S23 comprises:

[0024] Step S231: performing integrity check on the encrypted firmware;

[0025] Step S232: After the integrity check passes, the encrypted firmware is tested using a test case.

[0026] On the other hand, the step S3 comprises:

[0027] Step S31: storing the encrypted firmware in the burning box and configuring the device to be flashed;

[0028] Step S32: Sending the encryption key to the burning box;

[0029] Step S33: the burning box decrypts the encrypted firmware according to the encryption key and writes it into the device to be flashed;

[0030] During the execution of step S33, the programming box compares the programming information with the actual programming times to control the programming process.

[0031] An MCU burning system based on authorization protection, used to implement the above burning method;

[0032] The MCU burning system includes:

[0033] A firmware encryption module, wherein the firmware encryption module encrypts the firmware to be burned using an encryption key to obtain encrypted firmware;

[0034] A firmware verification module, the firmware verification module is connected to the firmware encryption module, the firmware verification module writes the encrypted firmware into a verification circuit board, and uses a verification terminal to verify the encrypted firmware in the verification circuit board;

[0035] A firmware burning module, the firmware burning module is connected to the firmware encryption module;

[0036] When the verification is passed, the firmware burning module inputs the encryption key and the encrypted firmware into the burner for burning.

[0037] On the other hand, the firmware encryption module includes:

[0038] A compiling module, wherein the compiling module compiles the original code to obtain a binary file as the firmware to be burned;

[0039] A parameter configuration module, wherein the parameter configuration module is connected to the compilation module;

[0040] The parameter configuration module configures the burning information for the firmware to be burned;

[0041] The burning information includes the number of times the encrypted firmware can be used.

[0042] A key generation module, the key generation module is connected to the parameter configuration module;

[0043] The key generation module generates the encryption key according to the burning information;

[0044] An encryption module, the encryption module is connected to the key generation module;

[0045] The encryption module uses the encryption key to encrypt the firmware to be burned to obtain the encrypted firmware.

[0046] On the other hand, the firmware verification module includes:

[0047] A key configuration module, wherein the key configuration module inputs the encryption key into the verification terminal;

[0048] A verification circuit flashing module, the verification circuit flashing module is connected to the key configuration module;

[0049] The verification circuit flashing module flashes the encrypted firmware to the verification circuit board through the verification terminal;

[0050] A firmware verification module, the firmware verification module is connected to the verification circuit flashing module;

[0051] The firmware verification module is in the verification circuit board, and uses the verification terminal to verify the encrypted firmware.

[0052] On the other hand, the firmware verification module includes:

[0053] A first verification module, wherein the first verification module performs integrity verification on the encrypted firmware;

[0054] A second verification module, wherein the second verification module is connected to the first verification module;

[0055] When the integrity check passes, the second verification module tests the encrypted firmware using a test case.

[0056] On the other hand, the firmware burning module includes:

[0057] A burning box configuration module, wherein the burning box configuration module stores the encrypted firmware in the burning box and configures the device to be flashed;

[0058] A key issuing module, the key issuing module is connected to the burning box configuration module;

[0059] The key issuing module issues the encryption key to the burning box;

[0060] A decryption and burning module, the decryption and burning module is connected to the key issuing module;

[0061] The decryption and burning module controls the burning box to decrypt the encrypted firmware according to the encryption key and write it into the device to be flashed;

[0062] The decryption and burning module also controls the burning box to compare the burning information with the actual number of burning times to control the burning process.

[0063] The above technical solution has the following advantages or beneficial effects:

[0064] In view of the problem that the firmware is easily leaked during the verification process of the burned firmware in the prior art, in this solution, a verification terminal and a verification circuit board are set up. During the manufacturer's verification process, the encrypted firmware is written into the verification circuit board, and the verification terminal is used to decrypt and verify the corresponding partition of the encrypted firmware in the memory in real time. In this way, the encrypted firmware always remains encrypted in the flash memory during the verification phase, and the running data in the memory is automatically erased after power failure, thereby avoiding the leakage problem caused by the outgoing unencrypted firmware during the verification phase. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] The embodiments of the present invention will be described more fully with reference to the attached drawings, which are provided for illustration and description only and are not intended to limit the scope of the present invention.

[0066] Figure 1 is an overall schematic diagram of an embodiment of the present invention;

[0067] Figure 2 This is a schematic diagram of step S1 in an embodiment of the present invention;

[0068] Figure 3 This is a schematic diagram of step S2 in an embodiment of the present invention;

[0069] Figure 4 This is a schematic diagram of step S23 in an embodiment of the present invention;

[0070] Figure 5 This is a schematic diagram of step S3 in an embodiment of the present invention;

[0071] Figure 6 A schematic diagram of a system in an embodiment of the present invention;

[0072] Figure 7This is a schematic diagram of a firmware encryption module in an embodiment of the present invention;

[0073] Figure 8 This is a schematic diagram of a firmware verification module in an embodiment of the present invention;

[0074] Fig. 9 This is a schematic diagram of a firmware verification module in an embodiment of the present invention;

[0075] Fig.10 Schematic diagram of a firmware burning module in an embodiment of the present invention. DETAILED DESCRIPTION

[0076] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0077] Some of the blocks shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0078] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other.

[0079] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, but they are not intended to limit the present invention.

[0080] The present invention comprises:

[0081] A MCU burning method based on authorization protection, such as Figure 1 As shown, including:

[0082] Step S1: Encrypt the firmware to be burned using an encryption key to obtain encrypted firmware;

[0083] Step S2: writing the encrypted firmware into the verification circuit board, and using the verification end to verify the encrypted firmware in the verification circuit board;

[0084] Step S3: After the verification is passed, the encryption key and the encrypted firmware are input into the burner for burning.

[0085] Specifically, in order to solve the problem that the firmware is easily leaked during the verification process of the burned firmware in the prior art, in this solution, a verification terminal and a verification circuit board are set up. During the manufacturer's verification process, the encrypted firmware is written into the verification circuit board, and the verification terminal is used to decrypt and verify the corresponding partition of the encrypted firmware in the memory in real time. In this way, the encrypted firmware always remains encrypted in the flash memory during the verification stage, and the running data in the memory is automatically erased after power failure, thereby avoiding the leakage problem caused by the outgoing unencrypted firmware during the verification stage.

[0086] Specifically, after the firmware development is completed, a compiled binary target file *.bin can be obtained as the firmware to be burned. The burned firmware is encrypted with the encryption key test.db to obtain the encrypted firmware.

[0087] The encrypted firmware needs to be decrypted before it can be run. However, the decrypted unencrypted firmware has the risk of leakage.

[0088] To address this problem, a set of verification circuit boards and corresponding verification terminals are provided.

[0089] The verification circuit board is a development circuit board with the same hardware architecture and configuration as the target device, and has flash memory, a processor, etc. After obtaining the encrypted firmware, the flash memory of the verification circuit board can be burned to write relevant data.

[0090] Accordingly, in order to make the verification circuit board run, a verification terminal is also configured. When the encryption key is input into the verification terminal, the firmware to be burned is started through the verification terminal. The verification terminal reads the data according to the specific partition, and in the process of loading into the memory, the data is decrypted and input into the memory for the processor to execute. When the verification process is completed, the verification circuit board is powered off so that the data in the memory is cleared, and the firmware to be burned that is retained in the flash memory is still in an encrypted state, thereby improving security.

[0091] When the verification is passed, a specific burning box is used to decrypt and burn the program.

[0092] The burning box hardware uses WY32F4375 as the main control MCU chip. This chip is a high-performance MCU ARMv8-M architecture, providing 512KB Flash space and 96KB SRAM, with rich peripheral resources.

[0093] In order to further enhance the functionality and flexibility of the programmer, a W25Q128 is used as an external memory to store user-programmed firmware and key system information. A 2.4-inch LCD screen is also used to provide an intuitive interface for user interaction.

[0094] In order to improve the recognition during the download process, a buzzer and a two-color LED are used. Three buttons are reserved for system configuration and interactive operation. Based on portability considerations, USB power supply is used, and 3.3 and 5V power supply can be provided externally. 30 groups of IO interface information are reserved to facilitate multi-channel target MCU burning.

[0095] In one embodiment, Figure 2 As shown, step S1 includes:

[0096] Step S11: compile the original code to obtain a binary file as the firmware to be burned;

[0097] Step S12: configuring burning information for the firmware to be burned;

[0098] The burning information includes the number of times the encrypted firmware can be used;

[0099] Step S13: Generate an encryption key according to the burning information;

[0100] Step S14: using an encryption key to encrypt the firmware to be burned to obtain encrypted firmware.

[0101] Specifically, in order to achieve effective control of the firmware, in this embodiment, after the R&D end completes the encoding and generates the binary file *.bin, it is used as the firmware to be burned. Then, the product manager configures the burning information in the PC configuration software PRJ-Manage.exe, and generates the encrypted burning file test.twy and the secret key test.db, which are used as the firmware to be burned and the encryption key respectively.

[0102] The burning information mainly includes the number of times the encrypted firmware can be used. In other embodiments, the number of verification and decryption times, the valid time period for verification and decryption, and the valid time period for actual burning can also be configured as needed. By arbitrarily selecting the above parameters, the burning process can be precisely controlled to avoid the risk of leakage caused by decryption at unexpected times.

[0103] Finally, the encryption key is used to encrypt the firmware to be burned to obtain the encrypted firmware.

[0104] In one embodiment, Figure 3 As shown, step S2 includes:

[0105] Step S21: input the encryption key into the verification terminal;

[0106] Step S22: flashing the encrypted firmware to the verification circuit board through the verification terminal;

[0107] Step S23: In the verification circuit board, the encrypted firmware is verified by using a verification terminal.

[0108] Specifically, in order to realize effective verification of the encrypted firmware, a verification terminal and a verification circuit board are introduced in this embodiment.

[0109] The verification circuit board is a development circuit board with the same hardware architecture and configuration as the target device, and has flash memory, a processor, etc. After obtaining the encrypted firmware, the flash memory of the verification circuit board can be burned to write relevant data.

[0110] The verification end is an ISP / ICP tool configured in the host computer, which can interact with the verification circuit board through a specific communication protocol. The ICP tool has a built-in decryption function, but it cannot obtain the original data, which is convenient for users or testers to perform functional verification.

[0111] When the customer receives the encryption key and encryption firmware, he / she inputs the encryption key into the verification terminal, and then the verification terminal flashes the encryption firmware to the verification circuit board.

[0112] Subsequently, the encrypted firmware is verified by the verification end. The verification process usually includes starting the verification circuit board, which performs a self-test and then reads the encrypted firmware in the flash memory. During the reading process, the verification end intercepts the data read into the memory according to the partition, decrypts it with the encryption key, and enters the memory.

[0113] Subsequently, the processor verifies the decrypted data in the memory, and clears the decrypted data in the memory after each stage of verification passes. When the verification is completed, the verification circuit board is powered off to clear all the data in the memory, and the firmware to be burned in the flash memory is still encrypted, thereby improving security.

[0114] In one embodiment, Figure 4 As shown, step S23 includes:

[0115] Step S231: Perform integrity check on the encrypted firmware;

[0116] Step S232: After the integrity check passes, the encrypted firmware is tested using a test case.

[0117] Specifically, in order to achieve effective verification of the encrypted firmware, in this embodiment, the following verification steps are set, including:

[0118] First, the integrity of the encrypted firmware is checked. The integrity check process includes verification of the digital signature and CRC cyclic check. The integrity of the firmware is determined by the above two check methods.

[0119] When the integrity check passes, the encrypted firmware is tested using test cases, including inputting specific test signals through the signal interface to determine whether the firmware has executed specific outputs and whether the output content meets expectations, etc.

[0120] Only when both of the above two verifications are passed can the encrypted firmware be verified.

[0121] In one embodiment, Figure 5 As shown, step S3 includes:

[0122] Step S31: storing the encrypted firmware in the burning box and configuring the device to be flashed;

[0123] Step S32: Sending an encryption key to the burning box;

[0124] Step S33: the burning box decrypts the encrypted firmware according to the encryption key and writes it into the device to be flashed;

[0125] During the execution of step S33, the programming box compares the programming information with the actual programming times to control the programming process.

[0126] Specifically, in order to achieve a better burning control process, a specific burning box is introduced in this embodiment.

[0127] After the verification is passed, the encrypted firmware is first stored in the burning box, and the device to be flashed is configured for connection, and then the encryption key is sent to the burning box. The burning box decrypts the encrypted firmware according to the encryption key and writes it to the device to be flashed.

[0128] During the flashing process, according to the configured burning information, the burning box will start the corresponding counter to record the current burning times. When the corresponding burning times are reached, the burning box will automatically clear the key to avoid leakage;

[0129] Accordingly, under the working condition that the program can be flashed at a specific time, the burning box will start the timer or obtain the current time through the external network and compare it with the burning information. When the timer duration is reached or the external time reaches a specific date, the burning box will automatically clear the key to avoid leakage.

[0130] An MCU burning system based on authorization protection, used to implement the above burning method;

[0131] like Figure 6 As shown, the MCU burning system includes:

[0132] The firmware encryption module 1 encrypts the firmware to be burned using an encryption key to obtain the encrypted firmware;

[0133] Firmware verification module 2, firmware verification module 2 is connected to firmware encryption module 1, firmware verification module 2 writes the encrypted firmware into the verification circuit board, and uses the verification end to verify the encrypted firmware in the verification circuit board;

[0134] Firmware burning module 3, firmware burning module 3 is connected to firmware encryption module 2;

[0135] When the verification is passed, the firmware burning module 3 inputs the encryption key and the encrypted firmware into the burner for burning.

[0136] Specifically, in view of the problem that the firmware is easily leaked during the verification process of the firmware to be burned in the prior art, in this solution, after the firmware development is completed, a compiled binary target file *.bin can be obtained as the firmware to be burned. For the burned firmware, the firmware encryption module 1 encrypts it through the encryption key test.db to obtain the encrypted firmware.

[0137] The encrypted firmware needs to be decrypted before it can be run. However, the decrypted unencrypted firmware has the risk of leakage.

[0138] To address this problem, a set of verification circuit boards and corresponding verification terminals are provided.

[0139] The verification circuit board is a development circuit board with the same hardware architecture and configuration as the target device, and has flash memory, a processor, etc. After obtaining the encrypted firmware, the flash memory of the verification circuit board can be burned to write relevant data.

[0140] Accordingly, in order to enable the verification circuit board to operate, a verification terminal is also configured. When the encryption key is input into the verification terminal, the firmware verification module 2 starts the firmware to be burned through the verification terminal. The verification terminal reads the data according to the specific partition, and in the process of loading into the memory, the data is decrypted and input into the memory for the processor to execute. When the verification process is completed, the verification circuit board is powered off so that the data in the memory is cleared, and the firmware to be burned that is retained in the flash memory is still in an encrypted state, thereby improving security.

[0141] When the verification is passed, the firmware burning module 3 uses a specific burning box to decrypt and burn.

[0142] In one embodiment, Figure 7 As shown, the firmware encryption module 1 includes:

[0143] A compiling module 11, the compiling module 11 compiles the original code to obtain a binary file as the firmware to be burned;

[0144] A parameter configuration module 12, the parameter configuration module 12 is connected to the compilation module 11;

[0145] The parameter configuration module 12 configures the burning information for the firmware to be burned;

[0146] The flashing information includes the number of times the encrypted firmware can be used.

[0147] A key generation module 13, the key generation module 13 is connected to the parameter configuration module 12;

[0148] The key generation module generates an encryption key according to the burning information;

[0149] An encryption module 14, the encryption module 14 is connected to the key generation module 13;

[0150] The encryption module 14 uses the encryption key to encrypt the firmware to be burned to obtain the encrypted firmware.

[0151] Specifically, in order to achieve effective control of the firmware, in this embodiment, after the compilation module 11 completes the encoding and generates the binary file *.bin, it is used as the firmware to be burned. Then, the parameter configuration module 12 and the key generation module 13 configure the burning information through the PC configuration software PRJ-Manage.exe, and generate the encrypted burning file test.twy and the secret key test.db, which are used as the firmware to be burned and the encryption key respectively.

[0152] The burning information mainly includes the number of times the encrypted firmware can be used. In other embodiments, the number of verification and decryption times, the valid time period for verification and decryption, and the valid time period for actual burning can also be configured as needed. By arbitrarily selecting the above parameters, the burning process can be precisely controlled to avoid the risk of leakage caused by decryption at unexpected times.

[0153] Finally, the encryption module 14 uses the encryption key to encrypt the firmware to be burned to obtain the encrypted firmware.

[0154] In one embodiment, Figure 8 As shown, the firmware verification module 2 includes:

[0155] The key configuration module 21 inputs the encryption key into the verification terminal;

[0156] A verification circuit flashing module 22, the verification circuit flashing module 22 is connected to the key configuration module 21;

[0157] The verification circuit flashing module 22 flashes the encrypted firmware to the verification circuit board through the verification end;

[0158] A firmware verification module 23, the firmware verification module 23 is connected to the verification circuit flashing module 22;

[0159] The firmware verification module 23 is in the verification circuit board and uses a verification terminal to verify the encrypted firmware.

[0160] Specifically, in order to realize effective verification of the encrypted firmware, a verification terminal and a verification circuit board are introduced in this embodiment.

[0161] The verification circuit board is a development circuit board with the same hardware architecture and configuration as the target device, and has flash memory, a processor, etc. After obtaining the encrypted firmware, the flash memory of the verification circuit board can be burned to write relevant data.

[0162] The verification end is an ISP / ICP tool configured in the host computer, which can interact with the verification circuit board through a specific communication protocol. The ICP tool has a built-in decryption function, but it cannot obtain the original data, which is convenient for users or testers to perform functional verification.

[0163] When the customer receives the encryption key and the encryption firmware, the key configuration module 21 inputs the encryption key into the verification end, and then the verification circuit flashing module 22 flashes the encryption firmware to the verification circuit board through the verification end.

[0164] Subsequently, the firmware verification module 23 uses the verification end to verify the encrypted firmware. The verification process generally includes starting the verification circuit board, which performs a self-check and then reads the encrypted firmware in the flash memory. During the reading process, the verification end intercepts the data read into the memory according to the partition, decrypts it with the encryption key, and then enters the memory.

[0165] Subsequently, the processor verifies the decrypted data in the memory, and clears the decrypted data in the memory after each stage of verification passes. When the verification is completed, the verification circuit board is powered off to clear all the data in the memory, and the firmware to be burned in the flash memory is still encrypted, thereby improving security.

[0166] In one embodiment, Fig. 9 As shown, the firmware verification module 23 includes:

[0167] A first verification module 231, the first verification module 231 performs integrity verification on the encrypted firmware;

[0168] A second verification module 232, the second verification module 232 is connected to the first verification module 231;

[0169] When the integrity check passes, the second check module 232 tests the encrypted firmware using a test case.

[0170] Specifically, in order to achieve effective verification of the encrypted firmware, in this embodiment, the following verification steps are set, including:

[0171] First, the first verification module 231 performs integrity verification on the encrypted firmware. The integrity verification process includes verification of the digital signature and CRC cyclic verification. The integrity of the firmware is determined by the above two verification methods.

[0172] When the integrity check passes, the second check module 232 tests the encrypted firmware using test cases, including inputting specific test signals through the signal interface to determine whether the firmware has executed specific outputs and whether the output content meets expectations, etc.

[0173] Only when both of the above two verifications are passed can the encrypted firmware be verified.

[0174] In one embodiment, Fig.10 As shown, the firmware burning module 3 includes:

[0175] The burning box configuration module 31 stores the encrypted firmware in the burning box and configures the device to be flashed;

[0176] The key issuing module 32 is connected to the burning box configuration module 31;

[0177] The key issuing module 32 issues an encryption key to the burning box;

[0178] A decryption and burning module 33, the decryption and burning module 33 is connected to the key issuing module 32;

[0179] The decryption and burning module 33 controls the burning box to decrypt the encrypted firmware according to the encryption key and write it into the device to be flashed;

[0180] The decryption and burning module 33 also controls the burning box to compare the burning information with the actual number of burning times to control the burning process.

[0181] Specifically, in order to achieve a better burning control process, a specific burning box is introduced in this embodiment.

[0182] After the verification is passed, the burning box configuration module 31 first stores the encrypted firmware in the burning box and configures the device to be flashed for connection. Then the key issuing module 32 issues the encryption key to the burning box, and the decryption burning module 33 decrypts the encrypted firmware according to the encryption key and writes it to the device to be flashed.

[0183] During the flashing process, according to the configured burning information, the burning box will start the corresponding counter to record the current burning times. When the corresponding burning times are reached, the burning box will automatically clear the key to avoid leakage;

[0184] Accordingly, under the working condition that the program can be flashed at a specific time, the burning box will start the timer or obtain the current time through the external network and compare it with the burning information. When the timer duration is reached or the external time reaches a specific date, the burning box will automatically clear the key to avoid leakage.

[0185] Those skilled in the art will appreciate that various aspects of the present invention, or possible implementations of various aspects, may be specifically implemented as systems, methods, or computer program products. Therefore, various aspects of the present invention, or possible implementations of various aspects, may take the form of complete hardware embodiments, complete software embodiments (including firmware, resident software, etc.), or embodiments of combined software and hardware aspects, all collectively referred to herein as "circuits," "modules," or "systems." In addition, various aspects of the present invention, or possible implementations of various aspects, may take the form of computer program products, which refer to computer instructions stored in a memory.

[0186] The memory may be a computer-readable signal medium or a computer-readable storage medium. Computer-readable storage media include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or apparatuses, or any suitable combination of the foregoing, such as random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable read-only memory (CD-ROM).

[0187] The processor in the computer reads the computer instructions stored in the memory, so that the processor can execute the functional actions specified in each step or the combination of steps in the flowchart; and generate a device for implementing the functional actions specified in each block or the combination of blocks in the block diagram.

[0188] It should be understood that the processor in the computer can be understood as one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components implemented to execute the aforementioned computer instructions.

[0189] Computer instructions can be executed completely on the user's local computer, partially on the user's local computer, as a separate software package, partially on the user's local computer and partially on a remote computer, or completely on a remote computer or server. It should also be noted that in some alternative embodiments, the functions noted in each step in the flow chart or each block in the block diagram may not occur in the order noted in the figure. For example, depending on the functions involved, two steps or two blocks shown in succession may actually be executed roughly simultaneously, or these blocks may sometimes be executed in reverse order.

[0190] Of course, in actual application, the various components in the computer system are coupled together through the bus system. It can be understood that the bus system is used to realize the connection and communication between these components. In addition to the data bus, the bus system also includes a power bus, a control bus and a status signal bus.

[0191] The above are only preferred embodiments of the present invention, and are not intended to limit the implementation methods and protection scope of the present invention. Those skilled in the art should be aware that all solutions obtained by equivalent substitutions and obvious changes made using the description and illustrations of the present invention should be included in the protection scope of the present invention.

Claims

1. A MCU burning method based on authorization protection, characterized in that: include: Step S1: Encrypt the firmware to be burned using an encryption key to obtain encrypted firmware; Step S2: writing the encrypted firmware into a verification circuit board, and using a verification terminal to verify the encrypted firmware in the verification circuit board; Step S3: After the verification is passed, the encryption key and the encrypted firmware are input into the burner for burning.

2. The MCU burning method according to claim 1, characterized in that: The step S1 comprises: Step S11: compile the original code to obtain a binary file as the firmware to be burned; Step S12: configuring burning information for the firmware to be burned; The burning information includes the number of times the encrypted firmware can be used; Step S13: generating the encryption key according to the burning information; Step S14: using the encryption key to encrypt the firmware to be burned to obtain the encrypted firmware.

3. The MCU burning method according to claim 1, characterized in that: The step S2 comprises: Step S21: inputting the encryption key into the verification terminal; Step S22: flashing the encrypted firmware to the verification circuit board through the verification terminal; Step S23: In the verification circuit board, the verification terminal is used to verify the encrypted firmware.

4. The MCU burning method according to claim 3, characterized in that: The step S23 comprises: Step S231: performing integrity check on the encrypted firmware; Step S232: After the integrity check passes, the encrypted firmware is tested using a test case.

5. The MCU burning method according to claim 2, characterized in that: The step S3 comprises: Step S31: storing the encrypted firmware in the burning box and configuring the device to be flashed; Step S32: Sending the encryption key to the burning box; Step S33: the burning box decrypts the encrypted firmware according to the encryption key and writes it into the device to be flashed; During the execution of step S33, the programming box compares the programming information with the actual programming times to control the programming process.

6. An MCU burning system based on authorization protection, characterized in that: Used to implement the burning method according to any one of claims 1 to 5; The MCU burning system includes: A firmware encryption module, wherein the firmware encryption module encrypts the firmware to be burned using an encryption key to obtain encrypted firmware; A firmware verification module, the firmware verification module is connected to the firmware encryption module, the firmware verification module writes the encrypted firmware into a verification circuit board, and uses a verification terminal to verify the encrypted firmware in the verification circuit board; A firmware burning module, the firmware burning module is connected to the firmware encryption module; When the verification is passed, the firmware burning module inputs the encryption key and the encrypted firmware into the burner for burning.

7. The MCU burning system according to claim 6, characterized in that: The firmware encryption module includes: A compiling module, wherein the compiling module compiles the original code to obtain a binary file as the firmware to be burned; A parameter configuration module, wherein the parameter configuration module is connected to the compilation module; The parameter configuration module configures the burning information for the firmware to be burned; The burning information includes the number of times the encrypted firmware can be used. A key generation module, the key generation module is connected to the parameter configuration module; The key generation module generates the encryption key according to the burning information; An encryption module, the encryption module is connected to the key generation module; The encryption module uses the encryption key to encrypt the firmware to be burned to obtain the encrypted firmware.

8. The MCU burning system according to claim 6, characterized in that: The firmware verification module includes: A key configuration module, wherein the key configuration module inputs the encryption key into the verification terminal; A verification circuit flashing module, the verification circuit flashing module is connected to the key configuration module; The verification circuit flashing module flashes the encrypted firmware to the verification circuit board through the verification terminal; A firmware verification module, the firmware verification module is connected to the verification circuit flashing module; The firmware verification module is in the verification circuit board, and uses the verification terminal to verify the encrypted firmware.

9. The MCU burning system according to claim 8, characterized in that: The firmware verification module includes: A first verification module, wherein the first verification module performs integrity verification on the encrypted firmware; A second verification module, wherein the second verification module is connected to the first verification module; When the integrity check passes, the second verification module tests the encrypted firmware using a test case.

10. The MCU burning system according to claim 7, characterized in that: The firmware burning module includes: A burning box configuration module, wherein the burning box configuration module stores the encrypted firmware in the burning box and configures the device to be flashed; A key issuing module, the key issuing module is connected to the burning box configuration module; The key issuing module issues the encryption key to the burning box; A decryption and burning module, the decryption and burning module is connected to the key issuing module; The decryption and burning module controls the burning box to decrypt the encrypted firmware according to the encryption key and write it into the device to be flashed; The decryption and burning module also controls the burning box to compare the burning information with the actual number of burning times to control the burning process.

Citation Information

Patent Citations

  • Chip programming methods, host computer, and chip programming system

    CN118690377B