Encryption burning method, device and equipment and computer readable storage medium
An encryption-based firmware flashing method for Android devices ensures secure firmware updates by verifying a unique authentication tag before data transmission, thereby preventing unauthorized access and data breaches.
Patent Information
- Application Number
- CN202510008395.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-05-27
AI Technical Summary
Existing methods for firmware flashing in Android devices are vulnerable to unauthorized data breaches, as public protocols like QsaharaServer and Firehose can be exploited for unauthorized firmware downloads.
Implementing an encryption-based firmware flashing method that involves establishing a secure connection with a target device, sending a unique authentication tag, and verifying it before transmitting encrypted data to ensure only authorized devices can perform firmware updates.
Enhances the security of firmware flashing by preventing unauthorized access and reducing the risk of data leakage.
Smart Images

Figure CN120045194A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of computer technologies, including but not limited to an encryption burning method, apparatus, device, and computer-readable storage medium. Background Art
[0002] With the rapid development of science and technology, more and more electronic products have been widely popularized, such as smart watches, smart phones, and various Internet of Things devices. Moreover, generally, these electronic products need to be processed such as firmware burning to ensure that these electronic products can work properly after leaving the factory.
[0003] In the related art, for Android devices, relevant technicians often perform downloading and burning based on corresponding communication protocols. For example, the public version of QsaharaServer (Sahara service) can be used to enable the burning device to communicate with the device to be written, and the public version of the transmission protocol can be used to enable the device to be written to handshake and verify with the burning device, and at the same time, the Fh_loader command tool is used to download and flash the firmware program into the device to be written.
[0004] However, this solution has the problem that other people can directly use the leaked or stolen image data for burning and downloading. Summary of the Invention
[0005] In view of this, the encryption burning method, apparatus, device, and computer-readable storage medium provided by the embodiments of the present application can achieve encryption burning, thereby reducing the risk of leakage of the data to be burned. The encryption burning method, apparatus, device, and computer-readable storage medium provided by the embodiments of the present application are implemented as follows:
[0006] On the one hand, an embodiment of the present application provides an encryption burning method, which is applied to a data burning device, and the data burning device is used to connect to a terminal device to be burned; the method includes:
[0007] Establish a communication connection with the terminal device, and send target authentication information to the terminal device, where the target authentication information includes an authentication label for uniquely identifying the burning permission;
[0008] Perform a verification operation on the target authentication information, and in the case of passing the verification, send the data to be burned to the terminal device.
[0009] Optionally, a communication tool and a data processing tool are deployed in the data burning device;
[0010] The establishing a communication connection with the terminal device and sending target authentication information to the terminal device includes:
[0011] Establish a communication connection with the terminal device through the communication tool, and send the target authentication information to the terminal device through the communication tool and the communication connection;
[0012] Sending the data to be burned to the terminal device includes:
[0013] Send the data to be burned to the terminal device through the data processing tool.
[0014] Optionally, establishing a communication connection with the terminal device through the communication tool and sending the target authentication information to the terminal device through the communication tool and the communication connection includes:
[0015] Encrypt the interface of the communication tool through a preset encryption algorithm, and establish a communication connection with the terminal device through the encrypted communication tool;
[0016] Decrypt the initially downloaded initial authentication information through the communication tool based on a preset decryption algorithm to obtain the target authentication information. The preset decryption algorithm corresponds to the preset encryption algorithm, and the initial authentication information is the information encrypted through the preset encryption algorithm;
[0017] Call the download port of the terminal device through the communication tool, and send the target authentication information to the terminal device through the communication connection and the download port.
[0018] Optionally, the method further includes:
[0019] Erase the target authentication information in case of power-off or after the burning is completed.
[0020] Optionally, establishing a communication connection with the terminal device through the communication tool and sending the target authentication information to the terminal device through the data processing tool and the communication connection includes:
[0021] Establish a communication connection with the terminal device through the unencrypted communication tool;
[0022] Call the download port of the terminal device through the communication tool, and send the initially downloaded initial authentication information to the terminal device through the communication connection and the download port. The initial authentication information is the target authentication information, and the initial authentication information is the information encrypted through the preset encryption algorithm.
[0023] Optionally, performing a verification operation on the target authentication information includes:
[0024] During the process of sending the target authentication information, obtain the device parameters corresponding to the target authentication information, where the device parameters include at least one of the following: Internet Protocol address, Media Access Control address, serial number, and account information;
[0025] Verify the device parameters, and determine that the verification is passed when the device parameters meet the preset conditions.
[0026] Optionally, the method further includes:
[0027] Encrypt the preset authentication information based on a preset encryption algorithm to obtain the initial authentication information, and store the initial authentication information in the data burning device or a server connected to the data burning device.
[0028] Optionally, the method further includes:
[0029] Compile and process the preset data to obtain the data to be burned, where the data to be burned includes signature information.
[0030] On the other hand, an embodiment of the present application further provides an encryption and burning method, which is applied to a terminal device, and the terminal device is used to connect to a data burning device; the method includes:
[0031] Establish a communication connection with the data burning device;
[0032] Receive the authentication information sent by the data burning device, where the authentication information includes an authentication label for uniquely identifying the burning permission;
[0033] Receive the data to be burned sent by the data burning device, and the data to be burned is sent by the data burning device when the authentication information is verified and passed by the data burning device.
[0034] Optionally, the receiving the authentication information sent by the data burning device includes:
[0035] Receive the decrypted authentication information, and store the decrypted authentication information in the first memory of the terminal device, where the first memory is configured to erase all stored data in the case of power-off or after burning is completed;
[0036] The receiving the data to be burned sent by the terminal device includes:
[0037] Receive the data to be burned based on the authentication information, and write the data to be burned into the second memory.
[0038] Optionally, the method further includes:
[0039] Stop the programming when the verification fails, output a prompt message, and erase the decrypted authentication information received.
[0040] On the other hand, an embodiment of the present application further provides an encrypted programming device, which is applied to a data programming device for connecting a terminal device to be programmed; the device includes:
[0041] A first communication module, configured to establish a communication connection with the terminal device and send target authentication information to the terminal device, where the target authentication information includes an authentication tag for uniquely identifying the programming permission.
[0042] A verification module, configured to perform a verification operation on the target authentication information, and send the data to be programmed to the terminal device when the verification is passed.
[0043] On the other hand, an embodiment of the present application further provides an encrypted programming device, which is applied to a terminal device for connecting a data programming device; the device includes:
[0044] A second communication module, configured to establish a communication connection with the data programming device;
[0045] A first receiving device, configured to receive the authentication information sent by the data programming device, where the authentication information includes an authentication tag for uniquely identifying the programming permission;
[0046] A second receiving device, configured to receive the data to be programmed sent by the data programming device, where the data to be programmed is sent by the data programming device when the verification of the authentication information is passed.
[0047] The computer device provided by the embodiment of the present application includes a memory and a processor, where the memory stores a computer program that can run on the processor, and the processor implements the method described in the embodiment of the present application when executing the program.
[0048] The computer-readable storage medium provided by the embodiment of the present application stores a computer program, and when the computer program is executed by a processor, the method provided by the embodiment of the present application is implemented.
[0049] The encrypted programming method, device, equipment, and computer-readable storage medium provided by the embodiment of the present application establish a communication connection with the terminal device, send target authentication information to the terminal device, perform a verification operation on the target authentication information, and send the data to be programmed to the terminal device when the verification is passed.
[0050] Among them, the target authentication information includes an authentication tag for uniquely identifying the programming permission.
[0051] That is to say, the target authentication information sent by the data burning device to the terminal device includes an authentication label, and the authentication label is used to uniquely identify the burning permission. Moreover, only when the target authentication information is verified and the verification is passed, the data to be burned will be written into the terminal device. However, since the authentication label does not exist in other authentication information (such as the initial burning authentication protocol or the public Firehose protocol), it can be recognized that the device or user using other authentication information for burning does not have the burning permission, and thus cannot send other authentication information to the terminal device. Even if other authentication information is sent, it will cause the terminal device to fail to recognize or authenticate, and further prevent operations such as writing, reading, and erasing data on the terminal device. In this way, the security of burning the terminal device can be improved as much as possible.
[0052] In this way, encrypted burning can be achieved, and further the effect of reducing the risk of leakage of the data to be burned can be achieved, so as to solve the technical problems proposed in the background art. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0054] Figure 1 Schematic diagram of the application scenario provided by the embodiment of the present application;
[0055] Figure 2 Flowchart of the first encrypted burning method provided by the embodiment of the present application;
[0056] Figure 3 Flowchart of the second encrypted burning method provided by the embodiment of the present application;
[0057] Figure 4 Flowchart of the third encrypted burning method provided by the embodiment of the present application;
[0058] Figure 5 Flowchart of the fourth encrypted burning method provided by the embodiment of the present application;
[0059] Figure 6 Flowchart of the fifth encrypted burning method provided by the embodiment of the present application;
[0060] Figure 7 Flowchart of the sixth encrypted burning method provided by the embodiment of the present application;
[0061] Figure 8Schematic diagram of the first encryption programming device provided by the embodiment of the present application;
[0062] Figure 9 Schematic diagram of the second encryption programming device provided by the embodiment of the present application;
[0063] Figure 10 Schematic diagram of a computer device provided by the embodiment of the present application. Detailed implementation manners
[0064] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will further describe the specific technical solutions of the present application in detail with reference to the accompanying drawings in the embodiments of the present application. The following embodiments are used to illustrate the present application but are not intended to limit the scope of the present application.
[0065] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0066] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments and can be combined with each other without conflict.
[0067] It should be noted that the terms "first / second / third" involved in the embodiments of the present application are used to distinguish similar or different objects and do not represent a specific order for the objects. It can be understood that "first / second / third" can be interchanged with a specific order or sequence when allowed, so that the embodiments of the present application described here can be implemented in an order other than that illustrated or described here.
[0068] In the related art, for Android devices, relevant technicians often perform downloading and programming based on corresponding communication protocols. For example, the public version of QsaharaServer can be used to enable the programming device to communicate with the device to be written, and the public version of the transmission protocol can be used to enable the device to be written to handshake and verify with the programming device. At the same time, the Fh_loader command tool is used to download and flash the firmware program into the device to be written.
[0069] However, this solution has the problem that other people can directly use the leaked or stolen image data for programming and downloading.
[0070] To this end, the embodiments of the present application provide an encryption programming method, which establishes a communication connection with the terminal device and sends target authentication information to the terminal device; performs a verification operation on the target authentication information, and in the case of successful verification, sends the data to be programmed to the terminal device. Among them, the target authentication information includes an authentication label for uniquely identifying the programming permission. In this way, encryption programming can be achieved, thereby reducing the risk of leakage of the data to be programmed.
[0071] The embodiments of the present application are described by taking the encryption programming method applied in a data programming device and / or a terminal device as an example. However, it does not mean that the embodiments of the present application can only be applied to the data programming device and / or the terminal device for encryption programming.
[0072] Hereinafter, the application scenarios of the encryption programming method provided in the embodiments of the present application will be briefly introduced first.
[0073] Figure 1 For a schematic diagram of an application scenario provided in the embodiments of the present application, please refer to Figure 1 In this scenario, it may include a data programming device A and a terminal device B, and the data programming device A and the terminal device B are connected to each other.
[0074] Among them, the data programming device A may include, for example, but not limited to, a PC (Personal Computer), a programmer, etc., and the terminal device B may include, for example, but not limited to, a mobile phone, a wearable device (such as a smart watch, a smart bracelet, smart glasses, etc.), a tablet computer, a notebook computer, a vehicle-mounted terminal, etc. The functions implemented by this method can be realized by a processor in the data programming device A and / or the terminal device B calling program code. Of course, the program code can be stored in a computer storage medium. It can be seen that both the data programming device A and the terminal device B at least include a processor and a storage medium.
[0075] For example, the data programming device A may include a PC, which is connected to the terminal device B through a USB or other interface. Corresponding programming software can be deployed in the PC, and corresponding programming parameters can be set, program code or firmware can be transmitted to the terminal device B, and corresponding programming result verification can be performed. For example, the QFIL (Qualcomm Flash ImageLoader) tool can be used to enable the PC to have the function of programming data into the terminal device B. Specifically, the PC can select appropriate download methods, communication interfaces, baud rates and other parameters, and then the programming purpose can be achieved through the programming software.
[0076] For another example, the data burning device A may include a PC and a burner. The PC is connected to the burner, and the burner is used to connect to the terminal device B. Generally, the PC can be used as a host computer, and the burner can be used to receive the program code or firmware data transmitted by the PC and write it into the memory of the terminal device B. It can also be used for data verification to ensure that the data has been correctly written into the terminal device B and return the verification result to the PC. The embodiments of the present application do not limit this.
[0077] In addition, the function of offline burning can also be implemented only by using the burner. The encryption burning method provided by the embodiments of the present application can be applied to the data burning device A with a PC or other host computer, so the embodiments of the present application will not elaborate on this.
[0078] The encryption burning method provided by the embodiments of the present application will be explained in detail below.
[0079] Figure 2 It is a schematic flowchart of an encryption burning method provided by the present application. This method can be applied to the above-mentioned data burning device A, and the data burning device may include any processor with functions such as processing, control, identification, and operation. See Figure 2 The embodiments of the present application provide an encryption burning method, which includes:
[0080] Step 101: Establish a communication connection with the terminal device and send the target authentication information to the terminal device.
[0081] Among them, the terminal device may be the above-mentioned terminal device B. When the data burning device is connected to the terminal device through a hardware interface, the data burning device can perform any possible operations such as handshaking with the terminal device to establish a communication connection with the terminal device. Moreover, when the data burning device and the terminal device establish a communication connection, the data burning device can perform any possible operations such as data interaction, signature authentication, and / or protocol authentication with the terminal device. The embodiments of the present application do not limit this.
[0082] Optionally, the target authentication information may be a string for identity verification, and specifically, the target authentication information may be a burning authentication protocol.
[0083] For example, the target authentication information can specify the format and transmission method of the data packets transmitted between the data burning device and the terminal device to ensure that the data can be accurately transmitted to the terminal device during the burning process. For another example, through the target authentication information and / or the burning authentication protocol, the occurrence of errors and failures during the optimized burning process can be reduced.
[0084] Specifically, the target authentication information includes an authentication label for uniquely identifying the burning permission.
[0085] In this embodiment, the authentication label can be used to determine the one currently being programmed.
[0086] Specifically, the authentication label can be a customized or personalized label set by relevant technical personnel according to actual needs. The authentication label can be in any possible form such as a digital signature, and the authentication label can include an ODM signature for characterizing the original design manufacturer.
[0087] For example, the authentication label can be a special code set at the beginning, middle, or end of the code of the initial programming authentication protocol, or a special logic interface for authentication and data exchange set for the initial programming authentication protocol. The authentication label can also be formed in any other possible way for identifying the programming permission. The embodiments of the present application do not make any limitation in this regard.
[0088] Among them, the initial programming authentication protocol can refer to an off-the-shelf protocol without any modification. For example, if the terminal device is a device programmed based on a download port such as port 9008, then the initial programming authentication protocol can be the off-the-shelf Firehose protocol. In this case, the target authentication information can be an authentication protocol obtained by customizing the off-the-shelf Firehose protocol and having this authentication label. The embodiments of the present application do not make any limitation in this regard.
[0089] Exemplarily, when sending the target authentication information to the terminal device, specifically, the PC in the data programming device can send the target authentication information to the terminal device through interfaces such as USB. Specifically, the encrypted target authentication information can be sent, or the unencrypted target authentication information can be sent, which can be adjusted according to actual needs in practical applications. Moreover, the data programming device can send any possible data to the terminal device through a data processing tool deployed in the data programming device.
[0090] For example, if the target authentication information is obtained by customizing the Firehose protocol, then the data processing tool can be the Fh_loader command tool, and thus the data programming device and the terminal device can establish a communication connection through the Fh_loader command tool.
[0091] In addition, the data programming device can establish a communication connection with the terminal device through a communication tool deployed in the data programming device. The embodiments of the present application do not make any limitation in this regard.
[0092] For another example, if the target authentication information is customized based on the Firehose protocol, then the communication tool can be QsaharaServer, and then the data burning device can establish a communication connection with the terminal device through the QsaharaServer.
[0093] It should be noted that the above is only an example based on a possible application scenario of the encryption burning method, and it does not mean that the target authentication information provided by the embodiments of the present application can only be customized based on the Firehose protocol, nor does it mean that only the Fh_loader command tool and / or QsaharaServer can be deployed in the data burning device provided by the embodiments of the present application. In actual application scenarios, the target authentication information and the tools deployed in the data burning device can be adjusted arbitrarily according to actual needs. The embodiments of the present application do not make any limitations in this regard.
[0094] It should be noted that after the data burning device establishes a communication connection with the terminal device, the data burning device can perform data interaction with the terminal device, so as to subsequently send the target authentication information and / or any other possible data to the terminal device, and / or read and erase data from the terminal device.
[0095] Correspondingly, when the terminal device receives the target authentication information, the terminal device can feedback a corresponding signal to the data burning device to enable the data burning device to determine that the burning operation can start currently; moreover, during the process of burning data, the terminal device can also feedback a corresponding signal to the data burning device based on the format and transmission method of the data packet specified by the target authentication information after successfully receiving each data packet, so that the data burning device can determine that the terminal device has successfully received the currently sent data packet and continue to send a new data packet.
[0096] In this way, it is convenient for the data burning device to reliably burn data to the terminal device subsequently.
[0097] Step 102: Perform a verification operation on the target authentication information, and if the verification passes, send the data to be burned to the terminal device.
[0098] Optionally, the verification operation can be any possible operation. For example, it can perform a verification operation on network parameters, user information, and any other possible parameters generated in the burning environment when sending the target authentication information, or perform a verification operation on the authentication label of the target authentication information. The embodiments of the present application do not make any limitations in this regard.
[0099] It can be understood that if the verification passes, it indicates that the data burning tool and / or the current burning environment have the burning permission, and the data can be burned to the terminal device. If the verification fails, it can indicate that the current data burning device and / or the current burning environment do not have the burning permission, and the burning can be stopped, and the communication connection between the terminal device and the data burning tool can be disconnected.
[0100] In this embodiment, the data to be burned can be program code or firmware data that needs to be burned into the terminal device. The data to be burned can also be data obtained after compilation processing. Generally, the data to be burned can be binary files in formats such as ".bin" or ".hex". In this way, it can be ensured that the terminal device can correctly identify, process, and execute the data to be burned.
[0101] Moreover, the data to be burned can generally be image data, that is, the data to be burned can be the image file of any software or application program.
[0102] It is worth noting that if the verification passes, it can be determined that the current burning environment, the data burning device, and / or the target authentication information are all legal and valid, and the risk of data leakage is relatively low. Therefore, the data to be burned can be sent to the terminal device.
[0103] It can be seen that in the embodiment of the present application, the target authentication information sent by the data burning device to the terminal device includes an authentication tag, and the authentication tag is used to uniquely identify the burning permission. Moreover, only when the verification operation on the target authentication information is passed, the data to be burned will be written into the terminal device. However, since the authentication tag does not exist in other authentication information (such as the above-mentioned initial burning authentication protocol or the public Firehose protocol), it can be recognized that the device or user using other authentication information does not have the burning permission, and other authentication information cannot be sent to the terminal device. Even if other authentication information is sent, it will cause the terminal device to fail to recognize or authenticate, and thus the operations of writing, reading, and erasing data on the terminal device cannot be performed. In this way, the security of burning the terminal device can be improved as much as possible, and the risk of leakage of the data to be burned can be reduced.
[0104] Another possible way is that when sending the data to be burned to the terminal device, it can be specifically sent based on the target authentication information, and corresponding adjustments can also be made to the data to be burned sent to the terminal device. For example, the read-back condition of the data to be burned can be specified in the target authentication information. The read-back condition can be that the data volume is less than or equal to a preset threshold, and the preset threshold can be any possible value such as 512 KB or 256 KB. Generally, the preset threshold needs to be less than the minimum data volume for any application to run properly in the terminal device, and the embodiments of the present application do not limit this. In this way, the terminal device can be prohibited from performing a read-back operation exceeding the preset threshold, preventing others from cracking the terminal device to obtain the complete data to be burned, which can further improve the security and reliability of encrypted burning and reduce the risk of data leakage.
[0105] In the embodiments of the present application, a communication connection is established with the terminal device, the target authentication information is sent to the terminal device, a verification operation is performed on the target authentication information, and when the verification is passed, the data to be burned is sent to the terminal device.
[0106] Among them, the target authentication information includes an authentication label for uniquely identifying the burning permission.
[0107] That is to say, the target authentication information sent by the data burning device to the terminal device includes an authentication label, and the authentication label is used to uniquely identify the burning permission. Moreover, only when the verification operation is performed on the target authentication information and the verification is passed, the data to be burned will be written into the terminal device. However, since the authentication label does not exist in other authentication information (such as the initial burning authentication protocol or the public Firehose protocol), it can be recognized that devices or users using other authentication information do not have the burning permission, and thus cannot send other authentication information to the terminal device. Even if other authentication information is sent, it will cause the terminal device to fail to recognize or authenticate, and further prevent operations such as writing, reading, and erasing data to the terminal device. In this way, the security of burning the terminal device can be improved as much as possible.
[0108] In this way, encrypted burning can be achieved, and the effect of reducing the risk of leakage of the data to be burned can be achieved.
[0109] Hereinafter, each possible step in the burning process will be explained in detail.
[0110] Some communication tools and data processing tools can be deployed in the data burning device. For example, the communication tool deployed in the device for burning the terminal device of the Android system can be QsaharaServer, and the data processing tool deployed can be Fh_loader. Therefore, in a possible implementation, refer to Figure 3 , establish a communication connection with the terminal device, and send the target authentication information to the terminal device, including:
[0111] Step 1011: Establish a communication connection with the terminal device through the communication tool, and send the target authentication information to the terminal device through the communication tool and the communication connection.
[0112] Optionally, the communication tool can be QsaharaServer or any other possible communication tool, and the embodiments of the present application do not limit this.
[0113] Specifically, the operation of sending the target authentication information to the terminal device through the data processing tool and the communication connection may refer to: when the data burning tool and the terminal device successfully establish a communication connection through the communication tool, call the download port of the terminal device through the communication tool, and then send the target authentication information to the terminal device through the download port.
[0114] Exemplarily, the download port can be a port set on the processor in the terminal device. The download port has read and write functions and can specifically be used to enable other devices to write data to the terminal device and / or the processor. If the target authentication information is customized from the Firehose protocol, then the download port can be port 9008. The embodiments of the present application do not limit this.
[0115] In addition, sending the data to be burned to the terminal device includes:
[0116] Send the data to be burned to the terminal device through the data processing tool.
[0117] Optionally, the data processing tool can be Fh_loader or any other possible communication tool, and the embodiments of the present application do not limit this.
[0118] Specifically, the operation of sending the data to be burned to the terminal device through the data processing tool may refer to: calling the download port of the terminal device through the data processing tool, and then sending the data to be burned to the terminal device through the download port.
[0119] It should be noted that deploying the communication tool and the data processing tool in the data burning device can enable the data burning device to accurately call the download port of the terminal device to write the target authentication information and / or the data to be burned into the terminal device, thereby ensuring the normal progress of the burning process.
[0120] In a possible implementation, refer to Figure 4 , establish a communication connection with the terminal device through the communication tool, and send the target authentication information to the terminal device through the communication tool and the communication connection, including:
[0121] Step 1012: Encrypt the interface of the communication tool through a preset encryption algorithm, and establish a communication connection with the terminal device through the encrypted communication tool.
[0122] Optionally, the preset encryption algorithm can be any possible encryption algorithm, such as the AES encryption algorithm or other symmetric encryption algorithms, and the embodiments of the present application do not limit this.
[0123] Optionally, the interface of the communication tool may refer to the code or command line called by the processor of the PC or other programs when using the communication tool.
[0124] In this embodiment, the operation of encrypting the interface of the communication tool may refer to encrypting the command line or code corresponding to the interface of the communication tool based on the preset encryption algorithm.
[0125] It can be understood that by encrypting the interface of the communication tool, it can be regarded that the communication tool has also been customized, and thus the communication tool can be made incompatible with the off-the-shelf communication tool. Then, it can be ensured that others cannot use the target authentication information through the off-the-shelf communication tool and / or burn the terminal device through the off-the-shelf communication tool. In this way, the security of the burning process can be improved.
[0126] Step 1013: Decrypt the initially downloaded initial authentication information through the communication tool based on a preset decryption algorithm to obtain the target authentication information.
[0127] Optionally, the preset decryption algorithm corresponds to the preset encryption algorithm. If the preset encryption algorithm is the AES encryption algorithm, then the preset decryption algorithm is the AES decryption algorithm.
[0128] Optionally, the initial authentication information may refer to the above-mentioned initial burning authentication protocol, that is, the off-the-shelf protocol without any modification. The initial authentication information is the information encrypted through a preset encryption algorithm.
[0129] Moreover, the initial authentication information can be stored in any other device that can be connected to the data burning device, such as a server. In this way, when the data burning device needs to use the initial authentication information and / or the target authentication information, it can be downloaded from other devices, which can prevent others from directly obtaining the initial authentication information or the target authentication information in case the data burning device is cracked. In this way, the security of burning can be improved to a certain extent.
[0130] It should be noted that since the target authentication information is obtained after decrypting the initial authentication information, in this case, the target authentication information is unencrypted.
[0131] Step 1014: Invoke the download port of the terminal device through the communication tool, and send the target authentication information to the terminal device through the communication connection and the download port.
[0132] Optionally, sending the target authentication information to the terminal device through the communication connection and the download port may mean that, when the communication connection between the data burning tool and the terminal device is successfully established through the communication tool, the target authentication information is sent to the terminal device through the download port.
[0133] It should be noted that since the interface of the communication tool is also encrypted, that is, in this embodiment, the communication tool is also customized to make it incompatible with the off-the-shelf communication tool. Moreover, since the initial authentication information is encrypted based on a preset encryption algorithm, generally only the customized communication tool can decrypt the initial authentication information to obtain the target authentication information. In this way, it can be ensured that others cannot use the target authentication information through the off-the-shelf communication tool and / or burn the terminal device through the off-the-shelf communication tool. Furthermore, the security of the burning process can be improved.
[0134] In addition, since the target authentication information sent by the data burning device to the terminal device is unencrypted in this embodiment, in order to further prevent others from stealing the target authentication information, the embodiment of the present application also provides a possible implementation manner, and the method further includes:
[0135] Erase the target authentication information in case of power-off or after burning is completed.
[0136] Optionally, the operation of erasing the target authentication information can be actively performed by the data burning device or passively performed.
[0137] For example, the target authentication information can be stored in the random access memory (RAM) of the data burning device, and the target authentication information can be automatically erased when the data burning device is powered off; alternatively, when the burning is completed, the processor of the data burning device can actively control the RAM of the data burning device to erase the target authentication information. Or, the target authentication information can be stored in the read-only memory (ROM) of the data burning device, and when the burning is completed, the processor of the data burning device can actively control the RAM of the data burning device to erase the target authentication information.
[0138] In this way, it can be prevented that the target authentication information is still stored in the data burning device when the burning is completed or the power is off, which may cause others to steal or crack the target authentication information from the data burning device. Furthermore, the reliability and security of the encrypted burning method can be improved.
[0139] In a possible implementation, refer to Figure 5 , establish a communication connection with the terminal device through the communication tool, and send the target authentication information to the terminal device through the communication tool and the communication connection, including:
[0140] Step 1015: Establish a communication connection with the terminal device through the unencrypted communication tool.
[0141] Optionally, the unencrypted communication tool may refer to a public communication tool. Generally, the unencrypted communication tool only has conventional communication functions.
[0142] Step 1016: Call the download port of the terminal device through the communication tool, and send the initially downloaded initial authentication information to the terminal device through the communication connection and the download port.
[0143] Optionally, the initial authentication information is the target authentication information, and the initial authentication information is information encrypted by a preset encryption algorithm. That is, in this embodiment, the target authentication information is encrypted.
[0144] It should be noted that since in this embodiment, the communication tool can be a public communication tool, the communication tool does not need to perform decryption operations on the initial authentication information and / or the target authentication information. Then, only encrypted authentication information will exist in the data burning device, and there will be no decrypted or unencrypted authentication information.
[0145] It can be seen that since the initial authentication information and / or the target authentication information is encrypted based on the preset encryption algorithm, even if others crack the data burning device and obtain the initial authentication information and / or the target authentication information, they cannot decrypt the initial authentication information and / or the target authentication information, nor can they obtain the decrypted authentication information. In this way, it is possible to prevent, as much as possible, the problem that others may steal or crack the unencrypted authentication information from the data burning device.
[0146] It can be understood that after the initial authentication information is sent to the terminal device, the terminal device can decrypt the initial authentication information based on a preset decryption algorithm. In addition, since the terminal device needs to perform decryption, the preset decryption algorithm can also be stored in the terminal device in advance at the time of factory or before burning. And after the decryption is completed, the terminal device can delete the preset decryption algorithm; or, after the burning is completed, the terminal device can delete the preset decryption algorithm, the initial authentication information, and the decrypted authentication information. In this way, it is possible to prevent, as much as possible, the problem that the unencrypted authentication information or the decrypted authentication information is leaked due to others cracking the terminal device.
[0147] Therefore, the method of using a public communication tool to send the initial authentication information and / or the target authentication information provided in this embodiment is particularly applicable to the scenario of burning a terminal device that only needs to be burned once.
[0148] In a possible implementation manner, performing a verification operation on the target authentication information includes:
[0149] During the process of sending the target authentication information, obtaining the device parameters corresponding to the target authentication information.
[0150] Optionally, the device parameters include at least one of the following: Internet Protocol address (IP address), Media Access Control address (MAC address), serial number (such as CPU serial number), and account information.
[0151] Specifically, the device parameters may be the parameters of the data burning device.
[0152] Verifying the device parameters, and determining that the verification is passed when the device parameters meet the preset conditions.
[0153] Exemplarily, specifically, the device parameters can be verified in the following way:
[0154] Judging whether the current network IP is a legal IP and whether the user in the account information is a legal user.
[0155] When the network IP is a legal IP and the user is a legal user, it is determined that the device parameters meet the preset conditions, and the burning continues.
[0156] When the network IP is illegal and / or the user is an illegal user, the current data burning device's IP address, MAC address, CPU serial number, account information and other device parameters will be reported to the server.
[0157] The server determines whether the reported data is legally authorized. If it is legal, it determines that the device parameters meet the preset conditions and continues to burn.
[0158] If it is illegal, the reported data will be saved in the server, the relevant technical personnel will be notified that there is abnormal burning behavior, and the burning will be exited.
[0159] It is worth noting that step 1021 and step 1022 can be specifically performed before executing the step of sending the data to be burned to the terminal device, thereby improving the security of sending the data to be burned to the terminal device through the above-mentioned data processing tool, and thus making the data processing tool only able to be used in a legal environment, thereby avoiding security issues caused by the theft of the data processing tool as much as possible.
[0160] For a possible implementation, see Figure 6 , the method further comprises:
[0161] Step 103: Encrypt the preset authentication information based on a preset encryption algorithm to obtain initial authentication information, and store the initial authentication information in the data burning device or a server connected to the data burning device.
[0162] Optionally, the preset authentication information may refer to public authentication information, such as a public Firehose protocol.
[0163] Specifically, encrypting the preset authentication information based on the preset encryption algorithm may include:
[0164] Perform binary analysis on the preset authentication information.
[0165] The binary parsing of the preset authentication information may parse the preset authentication information into a binary character string.
[0166] In this embodiment, the preset authentication information also includes the above-mentioned authentication tag.
[0167] The preset encryption algorithm is used to encrypt the value of each bit in the preset authentication information to complete the encryption of the preset authentication information.
[0168] It should be noted that the value of each bit in the preset authentication information refers to each character of the binary string obtained by parsing the preset authentication information. For example, if the parsed binary string is 10101010, then the value of each bit in the preset authentication information is respectively "1", "0", "1", "0", "1", "0", "1", "0". By encrypting the values of each bit, even if others steal the initial authentication information, they cannot obtain the plaintext code of the initial authentication information, which can prevent the risk that others may modify the string of the initial authentication information to delete the authentication label in the initial authentication information. In this way, the security and reliability of the encryption and burning method can be improved.
[0169] In a possible implementation manner, continue to refer to Figure 6 , the method further includes:
[0170] Step 104: Compile and process the preset data to obtain the data to be burned.
[0171] Optionally, the preset data may be the source program of the firmware or software. The data to be burned includes signature information, and the signature information may include the above-mentioned ODM signature.
[0172] Among them, compiling and processing the preset data means translating the preset data written in a high-level language into a binary program recognizable by a computer. In this way, it can be ensured that the data burning device and the terminal device can correctly recognize and process the data to be burned.
[0173] It should be noted that after downloading the above target authentication information and the data to be burned to the terminal device, since generally the server of the chip manufacturer of the terminal device will default to verifying the signature information of the target authentication information and the data to be burned, when the signature information of the data to be burned is all the electronic signature of the manufacturer, the terminal device can normally load the data to be burned. Even if others obtain the firmware data in the terminal device, when burning the firmware data into the devices of other manufacturers, the signature of the firmware data cannot pass the verification of the server of the chip manufacturer, so that the devices of other manufacturers cannot normally load when flashing or burning the firmware data. In this way, it can prevent the situation that other people use the data to be burned encrypted into the terminal device by this encryption and burning method for other devices.
[0174] It should be noted that the execution order of step 103 and step 104 is not fixed, that is, step 103 may be executed before step 104, step 103 may also be executed after step 104, and step 103 may also be executed simultaneously with step 104. The embodiments of the present application do not make any limitations in this regard.
[0175] Figure 7 A schematic flowchart of another encryption burning method provided for this application. This method can be applied to terminal device B, and any processor with functions such as processing, control, recognition, and operation can be included in this terminal device. Refer to Figure 7 An embodiment of this application provides an encryption burning method, and this method includes:
[0176] Step 201: Establish a communication connection with the data burning device.
[0177] Specifically, a communication connection can be established between the data burning device and the terminal device based on the communication tool in the data burning device.
[0178] Step 202: Receive the authentication information sent by the data burning device.
[0179] Optionally, the authentication information includes an authentication label for uniquely identifying the burning permission. This authentication information is the target authentication information in step 101 above.
[0180] Step 203: Receive the data to be burned sent by the data burning device.
[0181] Optionally, the data to be burned is sent by the data burning device when the authentication information passes the verification by the data burning device.
[0182] In the embodiment of this application, a communication connection is established with the data burning device, the authentication information sent by the data burning device is received, and the data to be burned sent by the data burning device is received. Among them, the authentication information includes an authentication label for uniquely identifying the burning permission, and the data to be burned is sent by the data burning device when the authentication information passes the verification by the data burning device.
[0183] That is to say, the received authentication information by the terminal device includes an authentication label, and this authentication label is used to uniquely identify the burning permission. Moreover, it can be ensured that only when the authentication information is verified and the verification is passed, the terminal device will receive the data to be burned sent by the data burning device. Furthermore, it can be ensured that only the data burning device with the burning permission can perform operations such as writing, reading, and erasing data on the terminal device. In this way, the security of burning the terminal device can be improved as much as possible.
[0184] In this way, encryption burning can be realized, and further the effect of reducing the risk of leakage of the data to be burned can be achieved.
[0185] In a possible implementation manner, this method further includes:
[0186] When the reception is completed, send a confirmation information to the data burning device based on the authentication information.
[0187] In this embodiment, receiving completion means that the terminal device has received a complete data packet. For example, if the data to be burned includes multiple data packets, then when each data packet is received, a confirmation message can be sent to the data burning device for the authentication information.
[0188] Optionally, the confirmation message is used to indicate that the terminal device has received the current data packet, and the data burning device can continue to send the next data packet.
[0189] In this way, the data burning device can timely and accurately understand the progress of the terminal device receiving the data to be burned, so as to better implement data burning.
[0190] In a possible implementation, receiving the authentication information sent by the data burning device includes:
[0191] Receiving the decrypted authentication information and storing the decrypted authentication information in the first memory of the terminal device.
[0192] Optionally, the first memory is configured to erase all stored data in the case of power-off or burn completion.
[0193] For example, the first memory can be the RAM in the terminal device.
[0194] It should be noted that since the decrypted authentication information is an unencrypted and plaintext string, in order to avoid the problem that the decrypted authentication information stored in the terminal device is stolen or cracked by others, the decrypted authentication information is stored in the first memory, and the RAM can automatically erase all stored data when the power is off, or can actively erase all data stored in the RAM in the case of burn completion.
[0195] In a possible way, receiving the data to be burned sent by the terminal device includes:
[0196] Receiving the data to be burned based on the authentication information and writing the data to be burned into the second memory.
[0197] Optionally, the second memory is configured not to actively erase the stored data. For example, the second memory can be the ROM in the terminal device.
[0198] In this way, it can be ensured that the terminal device does not easily lose the received data to be burned, so as to ensure the normal operation of the firmware of the terminal device.
[0199] In a possible implementation, the method further includes:
[0200] Stop the programming when the verification fails, output a prompt message, and erase the decrypted authentication information received.
[0201] Optionally, the situation where the verification fails may refer to the failure of verifying the above device parameters corresponding to the target authentication information, or the failure of authenticating information such as the manufacturer's signature of the target authentication information, or any other possible situation. The embodiments of the present application do not limit this.
[0202] Optionally, the prompt message may be output by the terminal device to the server of the manufacturer corresponding to the ODM signature, so that relevant technical personnel can timely learn about the information leakage of the data.
[0203] It should be noted that erasing the decrypted authentication information received can prevent the decrypted authentication information from being stored in the terminal device when the verification fails, resulting in the problem of leakage of unencrypted and plaintext authentication information. It can improve the security and reliability of encrypted programming and reduce the risk of data leakage.
[0204] It should be noted that the encrypted programming method applied to the above data programming device and the encrypted programming method applied to the above terminal device are corresponding, that is, the encrypted programming method applied to the data programming device and the encrypted programming method applied to the terminal device belong to the same inventive concept. Therefore, the encrypted programming method applied to the terminal device may further include any other steps corresponding to each step in the encrypted programming method applied to the terminal device. The embodiments of the present application do not limit this.
[0205] It should be understood that although each step in the above flowcharts is shown sequentially according to the indication of the arrow, these steps are not necessarily executed sequentially according to the order indicated by the arrow. Unless there is a clear description in this article, the execution of these steps does not have a strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the above flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.
[0206] Based on the foregoing embodiments, the embodiments of the present application provide an encrypted programming device. The device includes each module included and each unit included in each module, and can be implemented by a processor; of course, it can also be implemented by specific logic circuits; in the implementation process, the processor can be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.
[0207] Figure 8 is a schematic structural diagram of an encryption burning device provided by an embodiment of the present application. Refer to Figure 8 , this device is applied to the above data burning device, and this data burning device is used to connect the terminal device to be burned; this device includes:
[0208] A first communication module 301, configured to establish a communication connection with the terminal device and send target authentication information to the terminal device, where the target authentication information includes an authentication label for uniquely identifying the burning permission;
[0209] A verification module 302, configured to perform a verification operation on the target authentication information, and in the case of successful verification, send the data to be burned to the terminal device.
[0210] Figure 9 is a schematic structural diagram of another encryption burning device provided by an embodiment of the present application. Refer to Figure 9 , and is applied to the above terminal device. This device includes:
[0211] A second communication module 401, configured to establish a communication connection with the data burning device;
[0212] A first receiving device 402, configured to receive the authentication information sent by the data burning device, where the authentication information includes an authentication label for uniquely identifying the burning permission;
[0213] A second receiving device 403, configured to receive the data to be burned sent by the data burning device, and the data to be burned is sent by the data burning device when the data burning device passes the verification of the authentication information.
[0214] The description of the above device embodiments is similar to the description of the above method embodiments, and has beneficial effects similar to those of the method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0215] It should be noted that in the embodiments of the present application Figure 8 or Figure 9 The division of the encryption burning device into modules shown is schematic, and is only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present application, each functional unit may be integrated in a processing unit, may exist alone physically, or two or more units may be integrated in one unit. The above integrated units may be implemented in the form of hardware, or may be implemented in the form of software functional units. It may also be implemented in the form of a combination of software and hardware.
[0216] It should be noted that in the embodiments of the present application, if the above method is implemented in the form of software function modules and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application, in essence or the part that contributes to the related technology, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to enable an electronic device to execute all or part of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), magnetic disks, or optical discs that can store program codes. In this way, the embodiments of the present application are not limited to any specific combination of hardware and software.
[0217] The embodiments of the present application provide a computer device, which may include the above data burning device and / or the above terminal device. Its internal structural diagram may be as Figure 10 shown. The computer device includes a processor 502, a memory, and a network interface 503 connected through a system bus 501. Among them, the processor 502 of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium 504 and an internal memory 505. The non-volatile storage medium 504 stores an operating system, a computer program, and a database. The internal memory 505 provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium 504. The database of the computer device is used to store data. The network interface 503 of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the above method is implemented.
[0218] The embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the method provided in the above embodiments are implemented.
[0219] The embodiments of the present application provide a computer program product containing instructions. When it runs on a computer, it enables the computer to execute the steps in the method provided in the above method embodiments.
[0220] Those skilled in the art can understand that Figure 10 the structure shown in
[0221] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements. In one embodiment, the encryption burning device provided by the present application can be implemented in the form of a computer program, and the computer program can be inFigure 10 It runs on the computer device shown. Each program module that makes up the above device can be stored in the memory of the computer device. The computer program composed of each program module enables the processor to execute the steps in the methods of the various embodiments of the present application described in this specification.
[0222] It should be noted here that the descriptions of the above storage medium and device embodiments are similar to the descriptions of the above method embodiments and have beneficial effects similar to those of the method embodiments. For the technical details not disclosed in the storage medium, storage medium and device embodiments of the present application, please refer to the descriptions of the method embodiments of the present application for understanding.
[0223] It should be understood that the "one embodiment" or "an embodiment" or "some embodiments" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the "in one embodiment" or "in an embodiment" or "in some embodiments" that appear throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in the various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution, and the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments. The descriptions of the above embodiments tend to emphasize the differences between the embodiments, and their similarities or similarities can be referred to each other. For the sake of brevity, they will not be repeated here.
[0224] The term "and / or" in this article is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, object A and / or object B can represent three situations: object A exists alone, object A and object B exist simultaneously, and object B exists alone.
[0225] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, the element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0226] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation. For example, multiple modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed with each other can be through some interfaces, and the indirect coupling or communication connection of devices or modules can be electrical, mechanical, or other forms.
[0227] The modules described above as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules; they can be located in one place or distributed to multiple network units; some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0228] In addition, each functional module in the embodiments of the present application can be all integrated in a processing unit, or each module can be separately used as a unit, or two or more modules can be integrated in a unit; the above integrated modules can be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0229] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes: removable storage devices, read-only memory (ROM), magnetic disks, or optical disks and other various media that can store program codes.
[0230] Alternatively, if the above integrated unit of the present application is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application essentially or the part that contributes to the related technology can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to enable an electronic device to execute all or part of the methods described in the various embodiments of the present application. And the foregoing storage medium includes: removable storage devices, ROM, magnetic disks, or optical disks and other various media that can store program codes.
[0231] The methods disclosed in several method embodiments provided by the present application can be arbitrarily combined without conflict to obtain new method embodiments.
[0232] The features disclosed in several product embodiments provided by this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0233] The features disclosed in several method or device embodiments provided by this application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.
[0234] As mentioned above, it is only the implementation mode of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claimed rights.
[0235] The above is only the preferred embodiment of this application and is not used to limit this application. For those skilled in the art, this application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall be included within the protection scope of this application.
Claims
1. An encryption burning method, characterized in that: Applied to a data burning device, the data burning device is used to connect to a terminal device to be burned; the method comprises: Establishing a communication connection with the terminal device and sending target authentication information to the terminal device, the target authentication information including an authentication tag for uniquely identifying the burning authority; The target authentication information is verified, and if the verification passes, the data to be burned is sent to the terminal device.
2. The encryption burning method as claimed in claim 1, characterized in that: The data burning device is equipped with communication tools and data processing tools; The establishing a communication connection with the terminal device and sending the target authentication information to the terminal device includes: Establishing a communication connection with the terminal device through the communication tool, and sending the target authentication information to the terminal device through the communication tool and the communication connection; The step of sending the data to be burned to the terminal device comprises: The data to be burned is sent to the terminal device through the data processing tool.
3. The encryption burning method as claimed in claim 2, characterized in that: The establishing a communication connection with the terminal device through the communication tool, and sending the target authentication information to the terminal device through the communication tool and the communication connection, comprises: Encrypting the interface of the communication tool by using a preset encryption algorithm, and establishing a communication connection with the terminal device through the encrypted communication tool; decrypting the pre-downloaded initial authentication information by the communication tool based on a preset decryption algorithm to obtain the target authentication information, wherein the preset decryption algorithm corresponds to the preset encryption algorithm, and the initial authentication information is information encrypted by the preset encryption algorithm; The download port of the terminal device is called through the communication tool, and the target authentication information is sent to the terminal device through the communication connection and the download port.
4. The encryption burning method as claimed in claim 3, characterized in that: The method further comprises: The target authentication information is erased when power is off or burning is completed.
5. The encryption burning method as claimed in claim 2, characterized in that: The establishing a communication connection with the terminal device through the communication tool, and sending the target authentication information to the terminal device through the communication tool and the communication connection, comprises: Establishing a communication connection with the terminal device through the unencrypted communication tool; The download port of the terminal device is called by the communication tool, and the pre-downloaded initial authentication information is sent to the terminal device through the communication connection and the download port, wherein the initial authentication information is the target authentication information and is information encrypted by a preset encryption algorithm.
6. The encryption burning method as claimed in claim 1, characterized in that: The verifying operation on the target authentication information includes: In the process of sending the target authentication information, obtaining device parameters corresponding to the target authentication information, the device parameters including at least one of the following: an Internet Protocol address, a media access control address, a serial number, and account information; The device parameters are verified, and if the device parameters meet preset conditions, it is determined that the verification is passed.
7. The encryption burning method according to any one of claims 1 to 6, characterized in that: The method further comprises: The preset authentication information is encrypted based on a preset encryption algorithm to obtain initial authentication information, and the initial authentication information is stored in the data burning device or a server connected to the data burning device.
8. The encryption burning method according to any one of claims 1 to 6, characterized in that: The method further comprises: The preset data is compiled to obtain the data to be burned, wherein the data to be burned includes signature information.
9. An encryption burning method, characterized in that: Applied to a terminal device, the terminal device is used to connect to a data burning device; the method comprises: Establishing a communication connection with the data burning device; Receiving authentication information sent by the data burning device, the authentication information including an authentication tag for uniquely identifying the burning authority; The data to be burned is received from the data burning device. The data to be burned is sent by the data burning device when the data burning device verifies the authentication information successfully.
10. The encryption burning method according to claim 9, characterized in that: The receiving of authentication information sent by the data burning device includes: Receiving the decrypted authentication information, and storing the decrypted authentication information in a first memory of the terminal device, wherein the first memory is configured to erase all stored data when power is off or burning is completed; The receiving the data to be burned sent by the terminal device includes: The data to be burned is received based on the authentication information, and the data to be burned is written into the second memory.
11. The encryption burning method as claimed in claim 9, characterized in that: The method further comprises: If the verification fails, the burning is stopped, a prompt message is output, and the received decrypted authentication information is erased.
12. A computer device comprising a memory and a processor, wherein the memory stores a computer program executable on the processor, wherein: When the processor executes the program, the method described in any one of claims 1 to 8 and / or the method described in any one of claims 9 to 11 is implemented.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 and / or the method according to any one of claims 9 to 11 is implemented.