Software anti-shoveling method and electronic product

By binding the software to PUF chips and electronic devices, using the non-cloneable characteristics of the PUF chips to generate a unique encryption key, the problem of software copying is solved, and the software is high security and anti-counterfeiting ability is achieved.

CN120068025APending Publication Date: 2025-05-30北京普安信科技有限公司 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311618659.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the prior art, software is easy to copy boards, which is difficult to eliminate or reduce the probability of copying boards.

Method used

By binding the software to the PUF chip and electronic devices, using the non-cloneable physical function characteristics of the PUF chip, a unique encryption key is generated to realize the software's anti-copy board.

Benefits of technology

It effectively prevents software board copying, ensures that the relationship between the software and the supporting electronic equipment is unique, increases the product's anti-counterfeiting ability, and greatly improves the security of software use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068025A_ABST
    Figure CN120068025A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a software anti-shoveling method and an electronic product, and relates to the field of digital integrated circuit design and software security anti-counterfeiting. The software anti-copying method comprises the following steps: an authorization stage: initiating a challenge to a PUF chip built in matched electronic equipment based on a preset initial value to obtain a first response value, and carrying out cryptographic operation on the first response value and a first to-be-signed character string to obtain a message authentication code; in the verification stage, in the process of performing initialization loading on the software in the current electronic equipment, according to verification steps set by the software, executing the steps of initiating challenge to a PUF chip built in the current electronic equipment based on a preset initial value to obtain a second response value and performing cryptographic operation on the second response value and a second character string to be signed to obtain an execution result; and determining whether the software continues to be loaded or not based on the execution result and the message identification code. And when the product lacks a matched PUF chip or has other PUF chips, the software cannot work normally, so that the purpose of the software anti-shoveling plate is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of digital integrated circuit design and software security anti-counterfeiting, and particularly relates to a method for preventing software from being reverse-engineered and an electronic product. Background Art

[0002] Board copying, also known as cloning or imitation, is the reverse technical research on designed software. For enterprises and research institutions, the most troublesome thing is that the circuits and software they painstakingly designed are copied by others and enter the market at a low cost through imitation, affecting the enterprise's revenue.

[0003] In the process of implementing the present invention, the applicant found that there are at least the following problems in the prior art:

[0004] Software security mainly relies on cryptographic techniques. The cryptographic algorithms are public, and the core of cryptographic techniques is the security of the secret key. Various insecure storage forms of the secret key will bring the risk of physical attacks, resulting in the leakage of the secret key information. After stealing the secret key, illegal elements can generate the same calculation result through the same cryptographic calculation with the same original text, and pass the trusted verification check logic and run the program normally to achieve the purpose of copying. Summary of the Invention

[0005] The embodiments of the present invention provide a method for preventing software from being reverse-engineered and an electronic product, which solve the problems in the prior art that software is easily reverse-engineered and it is difficult to prevent or reduce the probability of reverse-engineering.

[0006] To achieve the above object, on the one hand, the embodiments of the present invention provide a method for preventing software from being reverse-engineered. The software is integrated into a supporting electronic device, and the method for preventing software from being reverse-engineered includes:

[0007] Authorization stage: When the software is authorized after being integrated into the supporting electronic device, a challenge is sent to the PUF chip built in the supporting electronic device based on a preset initial value in the software to obtain a first response value. The first response value is used as an encryption secret key, and the encryption secret key is subjected to a cryptographic operation with a first signature string to obtain a message authentication code, and the message authentication code is saved in a non-volatile memory; wherein, the PUF chip has the characteristic of an unclonable physical function, and when the same challenge value is sent to different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different;

[0008] Verification stage: When the software is initialized and loaded in the current electronic device, according to the verification steps set by the software, the steps of sending a challenge to the PUF chip built in the current electronic device based on the preset initial value to obtain a second response value and performing a cryptographic operation on the second response value with a second signature string are executed, and the execution result is obtained after completion;

[0009] Determine whether the software continues to load based on the execution result and the message authentication code.

[0010] On the other hand, an embodiment of the present invention provides an electronic product, including a supporting electronic device, a PUF chip built in the supporting electronic device, software integrated into the supporting electronic device, and a non-volatile memory; wherein:

[0011] When the software is authorized during integration into the supporting electronic device, a challenge is sent to the PUF chip based on a preset initial value in the software, the first response value returned by the PUF chip is used as an encryption key, and a password operation is performed on the encryption key and a first signature string to obtain a message authentication code;

[0012] When the software is authorized during integration into the supporting electronic device, the PUF chip obtains a first response value corresponding to the preset initial value based on the challenge of the preset initial value; wherein, the PUF chip has the characteristic of an unclonable physical function, and when the same challenge value is sent to different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different;

[0013] The non-volatile memory stores the message authentication code;

[0014] When the software is initialized and loaded in the supporting electronic device, in accordance with the verification steps set by the software, the step of sending a challenge to the PUF chip based on the preset initial value is executed; the second response value returned by the PUF chip is received, and a password operation is performed on the second response value and a second signature string to obtain a comparison code;

[0015] When the software is initialized and loaded in the supporting electronic device, the PUF chip responds to the challenge based on the preset initial value to obtain a second response value;

[0016] The software compares the comparison code with the message authentication code; if the comparison code is consistent with the message authentication code, the software continues to load; if the comparison code is inconsistent with the message authentication code, the software terminates loading and automatically exits.

[0017] The above technical solution has the following beneficial effects: The software, PUF chip, and electronic device are bound together and locked in the supporting electronic device. Utilizing the physical unclonable characteristic of the PUF chip, replacing the PUF chip cannot obtain the same secret key, ensuring the uniqueness of the encryption secret key and making the relationship between the software and the supporting electronic device unique. Even if the software is copied and the copied board of the software is installed on other electronic devices, when it is loaded and run, according to the verification steps set by the software, that is, the trusted root verification check mechanism, a challenge is initiated to the PUF chip built into the current electronic device based on the preset initial value. Because the PUF chip has the unclonable characteristic, it utilizes some tiny differences in the manufacturing process of each chip that cannot be artificially intervened to form the unique chip fingerprint of each chip. Since the chip fingerprints of each chip are different and have uniqueness, randomness, unpredictability, non-tamperability, and cannot be cloned by mathematical modeling or physical modeling, lawbreakers cannot manufacture the same PUF chip. Therefore, the obtained second response value is also different from the first response value obtained during the supporting electronic authorization stage when the software itself is integrated, and cannot pass the verification. Then, the copied board will stop loading and cannot run. It is ensured that the software cannot work properly when the product lacks a matching PUF chip or there is another PUF chip. That is, lacking a PUF chip, replacing the PUF chip, lacking an authorization file, or replacing and tampering with the authorization file cannot pass the trusted verification in the program initialization stage. The anti-counterfeiting ability of the product is increased, and the investment in copying the board and cracking the software is not proportional to its value, thus achieving the purpose of preventing copying of the board and greatly enhancing the security of software use. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0019] Figure 1 is a flowchart of a method for preventing software copying in an embodiment of the present invention;

[0020] Figure 2 is a logic structure diagram of an electronic product in an embodiment of the present invention;

[0021] Figure 3 is a flowchart of the authorization stage in the method for preventing software copying in an embodiment of the present invention;

[0022] Figure 4 is a flowchart of the verification stage in the method for preventing software copying in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0024] As Figure 1 shown, in combination with the embodiments of the present invention, a method for preventing software piracy is provided. The software is integrated into a supporting electronic device, and the method for preventing software piracy includes:

[0025] S101: Authorization stage: When the software is integrated into the supporting electronic device for authorization, a challenge is sent to the PUF chip built into the supporting electronic device based on a preset initial value in the software to obtain a first response value. The first response value is used as an encryption key, and the encryption key is subjected to a cryptographic operation with a first signature string to obtain a message authentication code, which is stored in a non-volatile memory. Among them, the PUF chip has the characteristic of an unclonable physical function. When the same challenge value is sent to different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different.

[0026] S102: Verification stage: When the software is initialized and loaded in the current electronic device, according to the verification steps set by the software, execute the step of sending a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, and perform a cryptographic operation on the second response value and a second signature string. After execution, an execution result is obtained.

[0027] Based on the execution result and the message authentication code, it is determined whether the software continues to be loaded.

[0028] The software, PUF chip and electronic device are bound together and locked in the supporting electronic device, taking advantage of the physical unclonable characteristics of the PUF chip. Replacing the PUF chip cannot obtain the same secret key, ensuring the uniqueness of the encryption secret key and making the relationship between the software and the supporting electronic device unique. Even if the software is copied and the copied board of the software is installed on other electronic devices, when it is loaded and run, according to the verification steps set by the software, that is, the trusted root verification check mechanism, a challenge is initiated to the PUF chip built into the current electronic device based on the preset initial value. Because the PUF chip has unclonable characteristics, it uses some tiny differences in the manufacturing process of each chip that cannot be artificially intervened to form a unique chip fingerprint for each chip. Since the chip fingerprints of each chip are different and have uniqueness, randomness, unpredictability, non-tamperability, and cannot be cloned by mathematical modeling or physical modeling, lawbreakers cannot manufacture the same PUF chip. Therefore, the obtained second response value is also different from the first response value obtained during the supporting electronic authorization stage when the software itself is integrated, and cannot pass the verification. Then the copied board will stop loading and cannot run. It is ensured that the software cannot work properly when the product lacks a matching PUF chip or there is another PUF chip. Lacking a PUF chip, replacing the PUF chip, lacking an authorization file or replacing and tampering with the authorization file cannot pass the trusted verification in the program initialization stage. It increases the anti-counterfeiting ability of the product, thus achieving the purpose of preventing copying of the board and greatly enhancing the security of software use.

[0029] Preferably, in the authorization stage: when the software is integrated into the supporting electronic device for authorization, authorization parameter information is collected, and each of the authorization parameter information is spliced to form a first signature string to be signed; the types of the authorization parameter information include: PUF chip identifier, and parameter information of the supporting electronic device including at least one of the following: main board identifier, hard disk identifier, CPU identifier, and MAC address, and at least one of the following: software identifier and software version number; the authorization parameter information further includes: reserved custom information; the information of the PUF chip, the information of the supporting electronic device, and the information of the software are collected to realize the binding of the software, PUF chip, and supporting electronic device. The reserved custom information is some specific strings defined by the user himself; an additional HMAC original text component is added, increasing the complexity of the HMAC original text. The reserved custom information is an optional item.

[0030] Verification phase: During the process of initializing and loading the software in the current electronic device, according to the verification steps set by the software, perform the steps of collecting verification parameter information and splicing each piece of verification parameter information in the splicing order of each piece of authorization parameter information to form a second signature string to be signed; among them, the types of the verification parameter information are the same as those of the authorization parameter information collected in the authorization phase. If it runs on the authorized supporting electronic device, the collected verification parameter information is the same as the authorization parameter information, and the second signature string to be signed can be the same as the first signature string to be signed; therefore, the comparison code will be consistent with the message authentication code.

[0031] Preferably, in the authorization phase, initiate a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, and perform a cryptographic operation on the second response value and the second signature string to be signed. After the execution is completed, the execution result is obtained, specifically including:

[0032] If a PUF chip is built into the current electronic device, perform the step of initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, perform a cryptographic operation on the second response value and the second signature string to be signed to obtain a comparison code, and use the comparison code as the execution result;

[0033] If there is no PUF chip in the current electronic device, an error will be reported when initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value, and the error will be used as the execution result.

[0034] It is necessary to judge whether the current electronic device is an authorized supporting electronic device through the normal execution of the verification steps. If it is not a supporting electronic device, the software stops loading and cannot be used, avoiding software piracy.

[0035] Preferably, in the verification phase, initiate a challenge to the PUF chip built into the supporting electronic device based on the preset initial value in the software to obtain a first response value, specifically including:

[0036] When it is determined that a PUF chip is provided in the current electronic device, use the preset initial value in the software as the challenge value to initiate a challenge to the PUF chip built into the supporting electronic device. The PUF chip of the supporting electronic device responds to obtain a first intermediate value, and cycle a preset number of times to use the first intermediate value as the challenge value to initiate a challenge to the PUF chip of the supporting electronic device to obtain a first response value; multiple cycles can increase the complexity of the first response value.

[0037] In the verification phase, initiate a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, specifically including:

[0038] When it is determined that the PUF chip is provided in the current electronic device, use the preset initial value as the challenge value to initiate a challenge to the PUF chip built into the current electronic device to obtain a second intermediate value. Repeat the preset number of times to use the second intermediate value as the challenge value to initiate a challenge to the PUF chip of the current electronic device. The PUF chip of the current electronic device responds to obtain a second response value. The number of repetitions is the same as the number of repetitions for obtaining the first response value. The purpose is that if the software runs on the authorized supporting electronic device, then the second response value is the same as the first response value, so the comparison code will be consistent with the message authentication code.

[0039] Preferably, the performing a cryptographic operation on the encryption key and the first string to be signed to obtain a message authentication code specifically includes:

[0040] Performing HMAC calculation on the encryption key and the first string to be signed to obtain a message authentication code;

[0041] The performing a cryptographic operation on the second response value and the second string to be signed to obtain a comparison code specifically includes:

[0042] Performing HMAC calculation on the second response value and the second string to be signed to obtain a comparison code.

[0043] Preferably, in the verification stage:

[0044] When the execution result is the comparison code, compare the comparison code with the message authentication code; if the comparison code is consistent with the message authentication code, it indicates that the current electronic device is the supporting electronic device, and the software continues to be loaded; if the comparison code is inconsistent with the message authentication code, it indicates that the current electronic device is not the supporting electronic device, and the software terminates the loading;

[0045] When the execution result is the error message, it indicates that the current electronic device is not the supporting electronic device, and the software terminates the loading and automatically exits.

[0046] As Figure 2 shown, in combination with the embodiments of the present invention, there is provided an electronic product, including a supporting electronic device, a PUF chip built into the supporting electronic device, software integrated into the supporting electronic device, and a non-volatile memory; wherein:

[0047] When the software is authorized and integrated into the supporting electronic device, based on the preset initial value in the software, a challenge is initiated to the PUF chip, the first response value returned by the PUF chip is used as the encryption key, and a cryptographic operation is performed on the encryption key and the first string to be signed to obtain a message authentication code;

[0048] When the PUF chip is authorized when the software is integrated into the supporting electronic device, a first response value corresponding to the preset initial value is obtained based on the challenge of the preset initial value; wherein, the PUF chip has the characteristic of an unclonable physical function, and when the same challenge value is used to challenge different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different;

[0049] The non-volatile memory stores the message authentication code;

[0050] When the software is initialized and loaded in the supporting electronic device, according to the verification steps set by this software, the step of challenging the PUF chip based on the preset initial value is executed; the second response value returned by the PUF chip is received, and the second response value is subjected to a cryptographic operation with the second signature string to obtain a comparison code;

[0051] The PUF chip responds to the challenge based on the preset initial value during the process of initializing and loading the software in the supporting electronic device to obtain a second response value;

[0052] The software compares the comparison code with the message authentication code; if the comparison code is consistent with the message authentication code, this software continues to be loaded; if the comparison code is inconsistent with the message authentication code, this software terminates the loading and automatically exits.

[0053] Preferably, the software: when integrated into the supporting electronic device for authorization, collects authorization parameter information, and splices each piece of authorization parameter information to form a first signature string; the types of the authorization parameter information include: PUF chip identifier, and at least one of the following: motherboard identifier, hard disk identifier, CPU identifier, and MAC address, and at least one of the following: software identifier and software version number; the authorization parameter information further includes: reserved custom information;

[0054] When in the process of initializing and loading in the supporting electronic device, according to the verification steps set by this software, the steps of collecting verification parameter information and splicing each piece of verification parameter information in the splicing order of each piece of authorization parameter information to form a second signature string are executed; wherein, the types of the verification parameter information are the same as those of the authorization parameter information collected during the authorization phase.

[0055] Preferably, the software is specifically used for:

[0056] When this software is integrated into the supporting electronic device for authorization, perform HMAC calculation on the encryption key and the first signature string to obtain a message authentication code;

[0057] When the software is initialized and loaded in the current electronic device, calculate the HMAC of the second response value and the second signature string to be signed to obtain a comparison code.

[0058] Preferably, the PUF chip is specifically configured to:

[0059] When the software is integrated into the supporting electronic device for authorization, respond to the preset initial value as a challenge value to obtain a first intermediate value, and loop a preset number of times to respond based on the first intermediate value as a challenge value to obtain a first response value;

[0060] When the software is initialized and loaded in the supporting electronic device, respond to the preset initial value as a challenge value to obtain a second intermediate value, and loop a preset number of times to respond based on the second intermediate value as a challenge value to obtain a second response value.

[0061] The above technical solutions of the embodiments of the present invention will be described in detail below in combination with specific application examples. For technical details not introduced during the implementation process, reference can be made to the relevant descriptions above.

[0062] A method for preventing software from being reverse-engineered according to an embodiment of the present invention, the software is integrated into a supporting electronic device, and the method for preventing software from being reverse-engineered includes:

[0063] Authorization stage: When the software is integrated (referring to the initial installation) into the supporting electronic device for authorization, initiate a challenge to the PUF chip built into the supporting electronic device based on the preset initial value in the software to obtain a first response value, use the first response value as an encryption key, perform a cryptographic operation on the encryption key and the first signature string to be signed to obtain a message authentication code, and save the message authentication code in a non-volatile memory; wherein, the PUF chip has the characteristic of an unclonable physical function, and when the same challenge value is initiated to different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different;

[0064] Verification stage: When the software is initialized and loaded in the current electronic device, according to the verification steps set by the software, execute the step of initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value, obtain a second response value after execution, and execute the step of performing a cryptographic operation on the second response value and the second signature string to be signed, and obtain an execution result after completion;

[0065] Determine whether the software continues to be loaded based on the execution result and the message authentication code.

[0066] When lawbreakers copy this software to form a cloned board and install the cloned board of this software on the current electronic device, before the current electronic device is loaded and used, the cloned board of this software needs to enter the verification stage: during the process of initializing and loading the software in the current electronic device, according to the verification steps set by the software, execute the step of initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value, and after execution, obtain a second response value, and perform a cryptographic operation on the second response value and the second signature string to be signed.

[0067] In the embodiments of the present invention, the software is bound to the PUF chip and the electronic device and locked in the supporting electronic device. Utilizing the physical unclonable characteristic of the PUF chip, the same secret key cannot be obtained by replacing the PUF chip, ensuring the uniqueness of the encryption secret key and making the relationship between the software and the supporting electronic device unique. Even if the software is copied and the cloned board of the software is installed on other electronic devices, during the loading and running process, according to the verification steps set by the software, that is, the trusted root verification check mechanism, a challenge is initiated to the PUF chip built into the current electronic device based on the preset initial value. Because the PUF chip has the unclonable characteristic, it utilizes some tiny differences that cannot be artificially intervened during the manufacturing process of each chip to form a unique chip fingerprint for each chip. Since the chip fingerprints of each chip are different and have uniqueness, randomness, unpredictability, and non-tamperability, and cannot be cloned by mathematical modeling or physical modeling, lawbreakers cannot manufacture the same PUF chip. Therefore, the obtained second response value is also different from the first response value obtained during the supporting electronic authorization stage when the software itself is integrated, and cannot pass the verification. Then the cloned board will stop loading and cannot run. It is ensured that when the product lacks a matching PUF chip or there is another PUF chip, the software cannot work properly. And the lack of a message authentication code or the replacement and tampering of the message authentication code cannot pass the trusted verification in the initialization stage. That is: 1. Only the software is copied, lacking the PUF chip; 2. Only the software is copied, lacking the preset message authentication code; 3. Only the software is copied, replacing the new PUF chip, and the generated keys are inconsistent. This increases the anti-counterfeiting ability of the product, and the investment in cloning the board and cracking the software is not proportional to its value, thus achieving the purpose of preventing board cloning and greatly enhancing the security of software use. It enables the product to have the ability of anti-counterfeiting certification, preventing product replication and plagiarism, and protecting the intellectual property rights of the product.

[0068] Thus, it solves the problem that the root key of electronic products is insecurely stored and the secret key has been obtained and cracked by lawbreakers. It also solves the problem that the hardware identification is insecurely stored and the hardware is easily forged and imitated, making the hardware identification of the electronic product supporting the software random and unique, ensuring that each hardware identification is unique, random, and non-repeating.

[0069] Specifically, the entire process of the software anti-piracy method is divided into two stages: the authorization stage and the verification stage. The specific operations are as follows.

[0070] As Figure 3 shown, in the authorization stage: when the software is integrated into the supporting electronic device for authorization, a challenge is sent to the PUF chip built into the supporting electronic device based on a preset initial value in the software to obtain a first response value. The first response value is used as an encryption key, and the encryption key is subjected to a cryptographic operation with a first string to be signed to obtain a message authentication code, which is saved in a non-volatile memory; wherein, the PUF chip has the characteristic of an unclonable physical function, and when the same challenge value is sent to different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different.

[0071] Among them, sending a challenge to the PUF chip built into the supporting electronic device based on a preset initial value in the software to obtain a first response value specifically includes: using the preset initial value in the software as a challenge value to send a challenge to the PUF chip built into the supporting electronic device to obtain a first intermediate value, and looping a preset number of times to use the first intermediate value as a challenge value to send a challenge to the PUF chip of the supporting electronic device to obtain a first response value; that is, using each response value as a challenge value to send a challenge to the PUF chip of the supporting electronic device, and after looping a preset number of times in this way, the obtained response value is used as the first response value.

[0072] The formation method of the first string to be signed (also known as the HMAC original text) is: collecting authorization parameter information, and splicing each piece of authorization parameter information to form the first string to be signed (the original text for HMAC calculation); the types of the authorization parameter information include: the PUF chip identifier, and at least one of the following: the motherboard identifier, the hard disk identifier, the CPU identifier, and the MAC address, and at least one of the following: the software identifier and the software version number; the authorization parameter information also includes: reserved custom information; the reserved custom information is some specific strings defined by the user himself; an additional element of the HMAC original text is added, increasing the complexity of the HMAC original text, and the reserved custom information is an optional item. It can be seen from the authorization parameter information that the authorization method in the embodiment of the present invention binds the software, the PUF chip, and the hardware of the electronic device, making the relationship between the software entity, the PUF chip entity, and the electronic device entity of a set of electronic products unique.

[0073] Perform a cryptographic operation on the encryption key and the first signature string to be signed to obtain a message authentication code, specifically including: performing HMAC calculation on the encryption key and the first signature string to obtain a message authentication code (or authorization code AC), and storing it in the non-volatile memory of the electronic product. Herein, HMAC is the abbreviation of Hash-based Message Authentication Code, which is a key-related hash operation message authentication code.

[0074] As Figure 4 shown, in the verification stage, when the software is initialized and loaded in the current electronic device, according to the verification steps set by the software, perform the step of initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, and perform a cryptographic operation on the second response value and the second signature string to be signed. After execution, obtain an execution result;

[0075] Among them, the formation method of the second signature string to be signed is: according to the verification steps set by the software, perform the steps of collecting verification parameter information and splicing each piece of verification parameter information in the splicing order of each piece of authorization parameter information to form the second signature string to be signed; among them, the types of the verification parameter information are the same as those of the authorization parameter information collected in the authorization stage.

[0076] Perform a cryptographic operation on the second response value and the second signature string to be signed to obtain a comparison code, specifically including: performing HMAC calculation on the second response value and the second signature string to be signed to obtain a comparison code.

[0077] When the software is initialized and loaded in the current electronic device, according to the verification steps set by the software, perform the step of initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, and perform a cryptographic operation on the second response value and the second signature string to be signed. After execution, obtain an execution result, specifically including: if a PUF chip is built into the current electronic device, perform the step of initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, perform a cryptographic operation on the second response value and the second signature string to be signed to obtain a comparison code, and use the comparison code as the execution result; when an error occurs when initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value, use the error as the execution result.

[0078] Initiating a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, which specifically includes: when it is determined that the PUF chip is built into the current electronic device, using the preset initial value as a challenge value to initiate a challenge to the PUF chip built into the current electronic device to obtain a second intermediate value, and looping a preset number of times to use the second intermediate value as a challenge value to initiate a challenge to the PUF chip of the current electronic device to obtain a second response value.

[0079] When the execution result is the comparison code, comparing the comparison code with the message authentication code; if the comparison code is consistent with the message authentication code, it indicates that the current electronic device is the supporting electronic device, and the software continues to be loaded; if the comparison code is inconsistent with the message authentication code, it indicates that the current electronic device is not the supporting electronic device, and the software terminates the loading.

[0080] When the execution result is the error message, it indicates that the current electronic device is not the supporting electronic device, and the software terminates the loading and automatically exits.

[0081] An embodiment of the present invention further includes an electronic product, including a supporting electronic device, a PUF chip built into the supporting electronic device, software integrated into the supporting electronic device, and a non-volatile memory. The software uses a software anti-copying method for authorization and verification during the design process; wherein:

[0082] When the software is integrated into the supporting electronic device for authorization, it initiates a challenge to the PUF chip based on a preset initial value in the software, uses the first response value returned by the PUF chip as an encryption key, and performs a cryptographic operation on the encryption key and the first signature string to obtain a message authentication code;

[0083] When the PUF chip is integrated into the supporting electronic device for authorization, it obtains a first response value corresponding to the preset initial value based on the challenge of the preset initial value; wherein, the PUF chip has the characteristic of an unclonable physical function, and when the same challenge value is used to initiate a challenge to different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different;

[0084] The non-volatile memory stores the message authentication code;

[0085] When the software is initialized and loaded in the supporting electronic device, in accordance with the verification steps set by the software, it executes the step of initiating a challenge to the PUF chip based on the preset initial value; receives the second response value returned by the PUF chip, and performs an encryption calculation on the second response value and the second signature string to obtain a comparison code;

[0086] During the process of initializing and loading the software in the supporting electronic device, the PUF chip responds to the challenge based on the preset initial value to obtain a second response value.

[0087] The software compares the comparison code with the message authentication code. If the comparison code is consistent with the message authentication code, the software continues to load. If the comparison code is inconsistent with the message authentication code, the software terminates the continued loading. In the electronic product of the embodiment of the present invention, the software is bound to the PUF chip and locked in the supporting electronic device. Utilizing the physical unclonable characteristic of the PUF chip, replacing the PUF chip cannot obtain the same secret key, ensuring the uniqueness of the encryption secret key and making the relationship between the software and the supporting electronic device unique. Even if the software is copied and the copied board of the software is installed on other electronic devices, during the loading and running process, according to the verification steps set by the software, that is, the trusted root verification check mechanism, a challenge is initiated to the PUF chip built into the current electronic device based on the preset initial value. Due to the unclonable characteristic of the PUF chip, the chip fingerprint of each chip is different, with uniqueness, randomness, unpredictability, non-tamperability, and cannot be cloned by mathematical modeling and physical modeling methods. Lawbreakers cannot manufacture the same PUF chip, so the obtained second response value is also different from the first response value obtained during the supporting electronic authorization stage when the software is integrated. As a result, the comparison code is different from the message authentication code generated during the authorization stage, and then the software will stop loading and cannot run. It is ensured that when the product lacks a matching PUF chip or there is another PUF chip, the software cannot work properly. The anti-counterfeiting ability of the product is increased, and the investment in copying the board and cracking the software is not proportional to its value, thus achieving the purpose of preventing board copying and greatly enhancing the security of software use. The product has the ability of anti-counterfeiting authentication, preventing product replication and plagiarism, and protecting the intellectual property rights of the product.

[0088] Thus, the problem that the secret key is obtained and cracked by lawbreakers due to the insecure storage of the root key of electronic products is solved. It also solves the problem that the hardware is easily forged and imitated due to the insecure storage of the hardware identifier, making the hardware identifier of the electronic product supporting the software random and unique, ensuring that each hardware identifier is unique, random, and non-repeating.

[0089] In summary, for electronic products, the security level of the system depends on the weakest link in system security. The weakest link in chip security is the insecure key storage. Regardless of the complexity of the key design itself, insecure storage will immediately endanger the security of the entire system. Information security is mainly verified through the privacy of the key, that is, it claims the identity that you are who you claim to be. After the key is stolen or leaked, the identity becomes untrustworthy and is easily forged.

[0090] The most crucial aspect of chip security is the uniqueness of the root key or hardware identifier, which is the foundation of trust and the starting point of the trust chain for the entire system and related services. The root is the starting point of the trust chain. Only when the root is trustworthy can the system built on this basis be more secure.

[0091] The anti-copying board software and electronic products based on PUF chips in the embodiments of the present invention utilize the physical unclonable characteristic of PUF as the trusted root of the hardware. The PUF chip is integrated into the electronic device, and the software is locked in the electronic device, realizing the binding of the software, PUF chip, and electronic device. Due to the unclonable characteristic of the PUF chip, the chip fingerprints of each chip are different, with uniqueness, randomness, unpredictability, non-tamperability, and a cloning method that cannot be mathematically or physically modeled. Lawbreakers cannot manufacture the same PUF chip, ensuring that the program cannot work properly when the product lacks a matching PUF chip. The problem of easy replication, forgery, and tampering of electronic products is solved through the trusted root verification and inspection mechanism. Thus, the purpose of preventing copying and protecting intellectual property rights is achieved. In addition, the key management process is also simplified.

[0092] It should be understood that the specific order or hierarchy of steps in the disclosed process is an example of an exemplary method. Based on design preferences, it should be understood that the specific order or hierarchy of steps in the process can be rearranged without departing from the protection scope of the present disclosure. The appended method claims present the elements of various steps in an exemplary order and are not intended to be limited to the specific order or hierarchy described.

[0093] In the above detailed description, various features are combined in a single embodiment to simplify the present disclosure. This method of disclosure should not be interpreted as reflecting the intention that the embodiments of the claimed subject matter require more features than those clearly stated in each claim. On the contrary, as reflected in the appended claims, the present invention is in a state with fewer features than all the features of the disclosed single embodiment. Therefore, the appended claims are hereby clearly incorporated into the detailed description, where each claim stands alone as a separate preferred embodiment of the present invention.

[0094] To enable any person skilled in the art to implement or use the present invention, the above-described disclosed embodiments have been described. For those skilled in the art, various modification methods of these embodiments are obvious, and the general principles defined herein can also be applied to other embodiments without departing from the spirit and protection scope of the present disclosure. Therefore, the present disclosure is not limited to the embodiments given herein, but is consistent with the broadest scope of the principles and novel features disclosed in this application.

[0095] The foregoing description includes examples of one or more embodiments. Of course, it is not possible to describe all possible combinations of components or methods for the purpose of describing the above embodiments, but those of ordinary skill in the art should recognize that the various embodiments can be further combined and arranged. Therefore, the embodiments described herein are intended to cover all such changes, modifications, and variations that fall within the scope of the appended claims. In addition, with respect to the term "comprising" used in the specification or claims, this term is inclusive in a manner similar to the term "including", as is explained when "including" is used as a transitional word in a claim. In addition, any use of the term "or" in the specification or claims is intended to mean "non-exclusive or".

[0096] Those skilled in the art will also appreciate that the various illustrative logical blocks, units, and steps listed in the embodiments of the present invention can be implemented by electronic hardware, computer software, or a combination of both. To clearly show the interchangeability of hardware and software, the above various illustrative components, units, and steps have been generally described in terms of their functions. Whether such functions are implemented by hardware or software depends on the specific application and the design requirements of the overall system. Those skilled in the art can use various methods to implement the described functions for each specific application, but such implementation should not be construed as exceeding the scope of protection of the embodiments of the present invention.

[0097] The various illustrative logical blocks or units described in the embodiments of the present invention can be implemented or operated to perform the described functions by a general-purpose processor, a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination of the above designs. The general-purpose processor can be a microprocessor, and optionally, the general-purpose processor can also be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented by a combination of computing devices, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a digital signal processor core, or any other similar configuration.

[0098] In the embodiments of the present invention, the steps of the methods or algorithms described may be directly implemented in hardware, software modules executed by a processor, or a combination of the two. The software modules may be stored in a RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium may be connected to the processor so that the processor can read information from the storage medium and write information to the storage medium. Optionally, the storage medium may also be integrated into the processor. The processor and the storage medium may be provided in an ASIC, and the ASIC may be provided in a user terminal. Optionally, the processor and the storage medium may also be provided in different components of the user terminal.

[0099] In one or more exemplary designs, the above-described functions in the embodiments of the present invention may be implemented in hardware, software, firmware, or any combination of the three. If implemented in software, these functions may be stored on a computer-readable medium or transmitted on a computer-readable medium in the form of one or more instructions or codes. A computer-readable medium includes a computer storage medium and a communication medium that facilitates the transfer of a computer program from one place to another. The storage medium may be any available medium accessible by a general or special computer. For example, such a computer-readable medium may include, but is not limited to, RAM, ROM, EEPROM, CD-ROM, or other optical disk storage, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to carry or store program code in the form of instructions or data structures and other forms readable by a general or special computer, or a general or special processor. In addition, any connection may be appropriately defined as a computer-readable medium. For example, if software is transmitted from a website, server, or other remote resource via a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless means such as infrared, wireless, and microwave, it is also included in the defined computer-readable medium. The disks (disk) and discs (disc) include compact disks, laser disks, optical discs, DVDs, floppy disks, and Blu-ray discs. Disks typically reproduce data magnetically, while discs typically reproduce data optically by laser. The above combinations may also be included in the computer-readable medium.

[0100] The above-described specific embodiments further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for preventing software piracy, where the software is integrated into a supporting electronic device. Characterized in that: The method for preventing software piracy includes: Authorization stage: When the software is integrated into the supporting electronic device for authorization, a challenge is sent to the PUF chip built into the supporting electronic device based on a preset initial value in the software to obtain a first response value. The first response value is used as an encryption key, and the encryption key is subjected to a cryptographic operation with a first signature string to obtain a message authentication code, which is saved in a non-volatile memory. Among them, the PUF chip has the characteristic of an unclonable physical function. When the same challenge value is sent to different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different. Verification stage: When the software is initialized and loaded in the current electronic device, according to the verification steps set by the software, perform the steps of sending a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, and performing a cryptographic operation on the second response value and a second signature string. After completion, obtain an execution result. Determine whether the software continues to be loaded based on the execution result and the message authentication code.

2. The method for preventing software piracy according to claim 1. Characterized in that: In the authorization stage: When the software is integrated into the supporting electronic device for authorization, authorization parameter information is collected, and each piece of authorization parameter information is concatenated to form a first signature string. The types of the authorization parameter information include: PUF chip identifier, and at least one of the following: motherboard identifier, hard disk identifier, CPU identifier, and MAC address, and at least one of the following: software identifier and software version number. The authorization parameter information also includes: reserved custom information. In the verification stage: When the software is initialized and loaded in the current electronic device, according to the verification steps set by the software, perform the steps of collecting verification parameter information and concatenating each piece of verification parameter information in the same concatenation order as the authorization parameter information in the authorization stage to form a second signature string. Among them, the types of the verification parameter information are the same as those of the authorization parameter information collected in the authorization stage.

3. The method for preventing software piracy according to claim 1. Characterized in that: In the authorization stage, the steps of sending a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, and performing a cryptographic operation on the second response value and a second signature string, after completion, obtain an execution result, specifically including: If a PUF chip is built into the current electronic device, perform the step of sending a challenge to the PUF chip built into the current electronic device based on the preset initial value to obtain a second response value, perform a cryptographic operation on the second response value and a second signature string to obtain a comparison code, and use the comparison code as the execution result. If there is no PUF chip in the current electronic device, report an error when sending a challenge to the PUF chip built into the current electronic device based on the preset initial value, and use the error as the execution result.

4. The method for software anti-piracy board according to claim 1, characterized in that, in the authorization stage, challenging the PUF chip built in the supporting electronic device based on the preset initial value in the software to obtain a first response value, specifically including: using the preset initial value in the software as a challenge value to challenge the PUF chip built in the supporting electronic device, the PUF chip of the supporting electronic device responds to obtain a first intermediate value, and using the first intermediate value as a challenge value to challenge the PUF chip of the supporting electronic device for a preset number of times to obtain a first response value; in the verification stage, challenging the PUF chip built in the current electronic device based on the preset initial value to obtain a second response value, specifically including: when it is determined that the current electronic device is equipped with a PUF chip, using the preset initial value as a challenge value to challenge the PUF chip built in the current electronic device, the PUF chip of the current electronic device responds to obtain a second intermediate value, and using the second intermediate value as a challenge value to challenge the PUF chip of the current electronic device for a preset number of times to obtain a second response value.

5. The method for software anti-piracy board according to claim 1 or 2, characterized in that, in the authorization stage, performing a cryptographic operation on the encryption key and the first signature string to obtain a message authentication code, specifically including: performing HMAC calculation on the encryption key and the first signature string to obtain a message authentication code; in the verification stage, performing a cryptographic operation on the second response value and the second signature string to obtain a comparison code, specifically including: performing HMAC calculation on the second response value and the second signature string to obtain a comparison code.

6. The method for software anti-piracy board according to claim 3, characterized in that, the verification stage: when the execution result is the comparison code, comparing the comparison code with the message authentication code; if the comparison code is consistent with the message authentication code, it indicates that the current electronic device is the supporting electronic device, and the software continues to load; if the comparison code is inconsistent with the message authentication code, it indicates that the current electronic device is not the supporting electronic device, and the software terminates loading; when the execution result is the error message, it indicates that the current electronic device is not the supporting electronic device, and the software terminates loading and automatically exits.

7. An electronic product, characterized in that, including a supporting electronic device, a PUF chip built in the supporting electronic device, software integrated into the supporting electronic device, and a non-volatile memory; wherein: when the software is integrated into the supporting electronic device for authorization, challenging the PUF chip based on the preset initial value in the software, using the first response value returned by the PUF chip as an encryption key, and performing a cryptographic operation on the encryption key and the first signature string to obtain a message authentication code; When the PUF chip is authorized when the software is integrated into the supporting electronic device, a first response value corresponding to the preset initial value is obtained based on the challenge of the preset initial value; wherein, the PUF chip has the characteristics of an unclonable physical function, and when the same challenge value is used to challenge different PUF chips, the response values obtained by each PUF chip in response to the challenge are all different; The non-volatile memory stores the message authentication code; When the software is initialized and loaded in the supporting electronic device, according to the verification steps set by this software, the step of challenging the PUF chip based on the preset initial value is executed; the second response value returned by the PUF chip is received, and the second response value and the second signature string to be signed are subjected to a cryptographic operation to obtain a comparison code; When the software is initialized and loaded in the supporting electronic device, the PUF chip responds to the challenge based on the preset initial value to obtain a second response value; The software compares the comparison code with the message authentication code; if the comparison code is consistent with the message authentication code, this software continues to be loaded; if the comparison code is inconsistent with the message authentication code, this software terminates the loading and automatically exits.

8. The electronic product according to claim 7, wherein, The software: when integrated into the supporting electronic device for authorization, collects authorization parameter information, and splices the authorization parameter information to form a first signature string to be signed; the types of the authorization parameter information include: PUF chip identifier, and at least one of the following: motherboard identifier, hard disk identifier, CPU identifier, and MAC address, and at least one of the following: software identifier and software version number; the authorization parameter information further includes: reserved custom information; When in the process of initializing and loading in the supporting electronic device, according to the verification steps set by this software, the steps of collecting verification parameter information and splicing the verification parameter information in the splicing order of the authorization parameter information to form a second signature string to be signed are executed; wherein, the types of the verification parameter information are the same as those of the authorization parameter information collected during the authorization phase.

9. The electronic product according to claim 8, wherein, The software is specifically used for: When the software is integrated into the supporting electronic device for authorization, perform HMAC calculation on the encryption key and the first signature string to be signed to obtain a message authentication code; When the software is initialized and loaded in the current electronic device, perform HMAC calculation on the second response value and the second signature string to be signed to obtain a comparison code.

10. The electronic product according to claim 7, wherein, The PUF chip is specifically used for: When the software is integrated into the supporting electronic device for authorization, respond to the preset initial value as a challenge value to obtain a first intermediate value, and loop a preset number of times to respond based on the first intermediate value as a challenge value to obtain a first response value; During the process of initializing and loading the software in the supporting electronic device, a second intermediate value is obtained by responding to the preset initial value as a challenge value, and the second response value is obtained by responding based on the second intermediate value as a challenge value for a preset number of times in a loop.