OTA security upgrading method

By setting up specific storage area division and encryption iteration solutions in the storage area of ​​the MCU, the challenge of OTA security upgrade in low-speed IoT products is solved, and the security and success rate of upgrades are improved.

CN120145394APending Publication Date: 2025-06-13E-SMARTCHIPS (JIANGSU) ELECTRONIC TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510220805.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

In low-rate IoT products with MCU as the control core, how to ensure OTA security upgrade is a challenge, mainly due to the problems of fully automatic upgrade, low MCU main frequency, few storage resources, high communication delay and easy tampering of upgrade source files.

Method used

By dividing the MCU storage area into 5 parts, the built-in key is run in the Bootloader program, and it is burned online, and by setting the A1 area and B1 area to take turns to each other as the pre-encrypted data and the encrypted data, the encrypted data is iterated every time it is upgraded, improving the security of the upgrade.

Benefits of technology

The security and success rate of OTA upgrades have been improved. Even if there is an error in the upgrade source file or the OTA upgrade is unsuccessful, the original version can be saved to avoid product abnormalities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145394A_ABST
    Figure CN120145394A_ABST
Patent Text Reader

Abstract

The invention discloses an OTA security upgrading method. The method comprises the following steps: S1) dividing a storage area of an MCU into a Bootloader program starting area, an application program A area, an application program B area, a secret key A1 area and a secret key B1 area; s2) during first running, writing is completed through online burning of a Bootloader program containing a built-in secret key, and an application program and a 16-byte random number are written into an application program A area and a secret key A1 area respectively; s3), preparing a compiled Bin file; s4) carrying out OTA upgrading request by using the compiled Bin file; s5) comparing and verifying, and judging whether updating is carried out or not; s6, the working area and the idle area are alternated, and follow-up OTA upgrading starts from S3. The built-in key runs in a Bootloader program and is written in through online burning, and no leakage risk exists in the encryption process; meanwhile, the A1 area and the B1 area are set to serve as the data before encryption and the data after encryption in turn, so that iteration is performed once every time the encrypted data is upgraded, and the upgrading safety is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of OTA upgrades, and particularly relates to an OTA security upgrade method. Background Art

[0002] OTA (Over-the-Air) is a technology for remotely updating device software, firmware, or configurations via a wireless network (such as Wi-Fi, cellular network, etc.). It is widely used in fields such as consumer electronics, automotive, and the Internet of Things, enabling users to achieve system upgrades, function optimizations, or vulnerability repairs without physically connecting the device (such as plugging in a cable or manual operation).

[0003] In fields such as consumer electronics, automotive, and the Internet of Things, due to reasons such as product function optimization or vulnerability repair, OTA is often used for system upgrades. There are mature solutions for OTA upgrade technology in the application of consumer electronics or automotive fields with Android or Linux platforms to prevent upgrade failures or have upgrade anomaly repair solutions.

[0004] However, in the low-rate Internet of Things product solutions with an MCU as the control core, how to ensure OTA security upgrade remains a major challenge. The reasons are as follows: 1. The upgrades of these Internet of Things products are fully automatic upgrades, generally without the need for and no way to have human participation; 2. The control core of these Internet of Things products is an MCU, with a low main frequency and little storage resources, and a too complex upgrade process cannot be designed; 3. Due to cost and power consumption requirements, these Internet of Things products generally adopt low-rate communication technologies such as 2G, NB-IoT, cat1, BLE, etc., with high communication latency and relatively low success rates; 4. The upgrade source files generally use Bin files. If the source files are accidentally or deliberately modified by someone, it is easy to cause irrecoverable upgrade errors.

[0005] Therefore, there is an urgent need to design a new OTA upgrade solution for low-rate Internet of Things products with an MCU as the control core to solve the above problems. Summary of the Invention

[0006] Object of the Invention: To overcome the above deficiencies, the object of the present invention is to provide an OTA security upgrade method, which runs with a built-in key in the Bootloader program, is written through in-circuit programming, and there is no interaction with the outside world during the subsequent encryption process, without the risk of leakage; at the same time, by setting Area A1 and Area B1 to alternately serve as pre-encrypted data and encrypted data, the encrypted data is iterated each time an upgrade is performed, greatly improving the security of the upgrade.

[0007] Technical solution: To achieve the above object, the present invention provides an OTA security upgrade method, which includes the following steps: S1): Divide the storage area of the MCU into 5 parts, namely the Bootloader program startup area, application program area A, application program area B, key area A1, and key area B1; S2): When running for the first time, complete the writing by online programming the Bootloader program containing the built-in key, and write the application program and a 16-byte random number into the application program area A and the key area A1 respectively; At this time, the application program area A is the program working area, the key area A1 is the key working area, the application program area B is the program idle area, and the key area B1 is the key idle area; S3): Prepare the compiled Bin file; the Bin file is a secondary processed file, not the original compiled Bin file, to prevent tampering; S301): The compiled Bin file is obtained by connecting encrypted data to the Bin file generated by compiling the new application program; the encrypted data is calculated from the data in the key working area and the built-in key; combining the encrypted data with the Bin file makes the file structure clearer, facilitating management and updating; at the same time, this structure also supports the tracking and management of versions; S4): Use the compiled Bin file to make an OTA upgrade request; S5): The program to be upgraded calls the built-in key and the data in the key working area for encryption calculation to obtain an encryption result, and compares and verifies it with the encrypted data at the end of the Bin file; if they are consistent, write the encrypted data and the upgrade program into the key idle area and the program idle area respectively, and at the same time update the application address pointer to the program idle area, and this upgrade is successful; if they are inconsistent, reject this upgrade and jump to S3) to wait for the next OTA upgrade request; by setting the A1 area and the B1 area to alternately serve as the data before encryption and the data after encryption, the encrypted data is iterated every time an upgrade is made, greatly improving the security of the upgrade; S6): Alternate between the program working area and the program idle area, and alternate between the key working area and the key idle area; subsequent OTA upgrades start from S3). This method can maximize the success rate of product upgrades. Even if there are errors in the upgrade source file or this OTA upgrade is not successful, the original version can still work and the product will not malfunction.

[0008] Further, the S5) specifically includes: S501): The program to be upgraded extracts the encrypted data at the end of the Bin file as the encryption result X16; S502): The program to be upgraded uses the data in the key workspace as the original data and calls the built-in key to encrypt it to obtain the encrypted result Y16. Encrypting using the data in the key workspace and the built-in key ensures the security of the key and prevents the key from being leaked or tampered with. S503): Compare whether the encrypted result X16 and the encrypted result Y16 are exactly the same. If they are the same, write the encrypted result Y16 and the upgrade program into the key free area and the program free area respectively, update the application address pointer to the program free area, and the current upgrade is successful. If they are not the same, reject the current upgrade and jump to S3) to wait for the next OTA upgrade request. By comparing the encrypted result X16 and the encrypted result Y16, unauthorized firmware can be effectively prevented from being loaded. At the same time, if the comparison fails, the system will reject the current upgrade and wait for the next OTA upgrade request to avoid the device being unable to start normally due to a failed upgrade.

[0009] Further, the specific operation of updating the application address pointer in S503) is as follows: Run the Bootloader program. The Bootloader program initializes the program and calls a pointer address, which is used to indicate whether to jump to Area A of the application program or Area B of the application program to work after the Bootloader program finishes running. The Bootloader program jumps according to the pointer address and normally starts the application program, and the product works normally. The Bootloader can flexibly switch to Area A or Area B to run according to the pointer address, realizing seamless upgrade. At the same time, the Bootloader can clearly distinguish the currently running firmware and the firmware to be updated, which is convenient for version management and troubleshooting.

[0010] Further, S4) includes that when the application program receives an OTA upgrade request, it first accepts and verifies the data according to the conventional upgrade process and upgrade protocol, and then executes S5) to perform the verification and write operation into the program free area. The conventional upgrade process and upgrade protocol provide basic security guarantees for the OTA upgrade of this solution, reduce the risk of upgrade failure, and improve the stability and availability of the device.

[0011] Further, the specific judgment of the first run in S2) is as follows: After the MCU runs the Bootloader program, it reads the content of Area A1 and the content of Area B1 respectively. When it is found that the content of these two areas is either 0x00 or 0XFF, it is determined that the program is running for the first time, and the FLASH write function is called to complete the writing of the data in the first key Area A1. Otherwise, it is determined that the program is not running for the first time, and no writing work is done for the key in Area A1. During the first run, the Bootloader completes the initialization work related to secure startup, such as generating a secure startup key and setting Flash encryption, providing a basic guarantee for the secure operation of the device.

[0012] Further, the built-in key in S2) is written once through program online burning, cannot be changed, and does not interact with the outside world. The built-in key runs in the Bootloader program, is written through online burning, and the subsequent encryption process also does not interact with the outside world, without the risk of leakage.

[0013] Further, the space sizes of the key A1 area and the key B1 area in S1) are equal, both being the minimum allowable erasure block size of the current MCU. Using the minimum erasure block as a unit can reduce the error risk caused by improper operation and improve the reliability of the system; at the same time, when the system has an exception, the smaller erasure block size can complete the recovery operation faster and reduce the system downtime.

[0014] From the above technical solutions, it can be seen that the present invention has the following beneficial effects: 1. For the OTA security upgrade method of the present invention, the built-in key runs in the Bootloader program, is written through online burning, and the subsequent encryption process also does not interact with the outside world, without the risk of leakage; 2. For the OTA security upgrade method of the present invention, even if someone obtains the previous OTA upgrade files, due to the absence of the built-in key, they cannot calculate the encrypted data of the next OTA upgrade package, with high security; 3. For the OTA security upgrade method of the present invention, the Bin file is a secondary processed file, not the original compiled Bin file, preventing tampering; 4. For the OTA security upgrade method of the present invention, by setting the A1 area and the B1 area to alternately serve as the data before encryption and the data after encryption, the encrypted data is iterated every time an upgrade is made, greatly improving the security of the upgrade. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a step diagram of an OTA security upgrade method described in the present invention; Figure 2 It is a flowchart of an OTA security upgrade method described in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are intended to explain the present invention, and should not be construed as limiting the present invention. Embodiment

[0017] In this embodiment, as Figure 1 and Figure 2, the present invention discloses an OTA security upgrade method, including the following steps: S1): Divide the storage area of the MCU into 5 parts, namely the Bootloader program startup area, application program area A, application program area B, key area A1, and key area B1; S2): When running for the first time, complete the writing by online programming the Bootloader program containing the built-in key, and write the application program and a 16-byte random number into the application program area A and the key area A1 respectively; At this time, the application program area A is the program working area, the key area A1 is the key working area, the application program area B is the program idle area, and the key area B1 is the key idle area; S3): Prepare the compiled Bin file; S301): The compiled Bin file is obtained by connecting the encrypted data to the Bin file generated by compiling the new application program; the encrypted data is calculated from the data in the key working area and the built-in key; S4): Use the compiled Bin file to make an OTA upgrade request; S5): The program to be upgraded calls the built-in key and the data in the key working area to perform encryption calculation to obtain the encryption result, and compares and verifies it with the encrypted data at the end of the Bin file; if they are consistent, write the encrypted data and the upgrade program into the key idle area and the program idle area respectively, and at the same time update the application address pointer to the program idle area, and this upgrade is successful; if they are inconsistent, reject this upgrade and jump to S3) to wait for the next OTA upgrade request; S6): Alternate between the program working area and the program idle area, and alternate between the key working area and the key idle area; subsequent OTA upgrades start from S3).

[0018] Specifically, when the program has never been OTA upgraded, the key area A1 stores the random number confirmed by the developer during the first program initialization, and the key area B1 is empty; When the program has been OTA upgraded once, the key area A1 stores the random number confirmed by the developer during the first program initialization, and the key area B1 stores the data encrypted by the built-in key from the random number in the key area A1; When the program has been OTA upgraded 2 times or more: (a) When the application program area A is running, the key area A1 stores the data encrypted by the built-in key from the 16-byte key area B1 data, and the key area B1 stores the data before encryption of the current key area A1 data, and is also the data encrypted from the previous key area A1 data; (b)When the application B area is running, the key B1 area stores the data of the 16-byte key A1 area encrypted by the built-in key. The key A1 area stores the data before encryption of the current key B1 area, and is also the data encrypted by the previous key B1 area.

[0019] In this embodiment, as Figure 2 , the step S5) specifically includes: S501): The program to be upgraded extracts the encrypted data at the end of the Bin file as the encryption result X16; S502): The program to be upgraded uses the data in the key working area as the original data and calls the built-in key for encryption to obtain the encryption result Y16; S503): Compare whether the encryption result X16 and the encryption result Y16 are exactly the same. If they are the same, write the encryption result Y16 and the upgrade program into the key free area and the program free area respectively, update the application address pointer to the program free area, and the current upgrade is successful; if they are not the same, reject the current upgrade and jump to S3) to wait for the next OTA upgrade request.

[0020] Specifically, if the current program free area for OTA preparation is the application B area, after the product to be OTA receives the Bin file, the application program first extracts the encrypted data at the end of the Bin file as the encryption result X16, and then uses the 16-byte content of the key A1 area as the original data, and calls the built-in key to perform AES128 encryption to obtain 16-byte encrypted data Y16; compare whether the 16-byte X16 and Y16 are exactly the same. If they are the same, write the X16 data into the key B1 area, update the application address pointer to the application B area, and the current update is successful; if they are not the same, the X16 data will not be written into the key B1 area, the application address pointer is not updated, and the current update is unsuccessful. If the current free area for OTA preparation is the application A area, the opposite is true.

[0021] In this embodiment, the update of the application address pointer in the step S503) is specifically as follows: Run the Bootloader program. The Bootloader program initializes the program and calls a pointer address, which is used to indicate whether to jump to the application A area or the application B area to work after the Bootloader program runs to the end; the Bootloader program jumps according to the pointer address and normally starts the application program, and the product works normally.

[0022] Specifically, the built-in key is loaded into the RAM in the Bootloader program, and the key information data in the RAM is ensured not to be lost after the program jumps through the embedded code language.

[0023] In this embodiment, step S4) includes that after the application receives an OTA upgrade request, it first accepts data and verifies the data according to the conventional upgrade process and upgrade protocol, and then executes step S5) to perform the operations of verification and writing to the program idle area.

[0024] Specifically, accepting data means receiving upgrade data from the OTA server according to a preset communication protocol (such as MQTT, HTTPS, etc.); verifying data means calculating the digest of the received upgrade data (such as MD5, SHA256) and comparing it with the signature value provided in the upgrade package.

[0025] In this embodiment, the first run in step S2) is specifically determined as follows: After the MCU runs the Bootloader program, it reads the content of area A1 and the content of area B1 respectively. When it is found that the content of both areas is 0x00 or 0XFF, it is determined that the program is running for the first time, and the FLASH write function is called to complete the writing of the data in the first key area A1; otherwise, it is determined that the program is not running for the first time, and no writing work is done for the key area A1.

[0026] Specifically, after it is determined that the program is running for the first time, first, the Flash erase function is called to erase area A1; then, the Flash write function is called to write the predefined data into area A1; finally, after the key writing is completed, the Bootloader continues to execute the subsequent process.

[0027] In this embodiment, the built-in key in step S2) is written once through program in-circuit programming, cannot be changed, and does not interact with the outside world.

[0028] Specifically, tools supporting in-circuit programming, such as PowerWriter or e2studio, are used to achieve the programming and signature writing of the key.

[0029] In this embodiment, the space sizes of the key area A1 and the key area B1 in step S1) are equal, and both are the minimum allowable erase block size of the current MCU.

[0030] Specifically, in this embodiment, 4K bytes is selected as a preference for the minimum allowable erase block size of the MCU.

[0031] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements can be made, and these improvements should also be regarded as the protection scope of the present invention.

Claims

1. An OTA security upgrade method, characterized by: The steps include: S1): Divide the storage area of ​​MCU into 5 parts, namely Bootloader program startup area, application A area, application B area, key A1 area and key B1 area; S2): When running for the first time, the bootloader program containing the built-in key is burned online to complete the writing, and the application and 16-byte random number are written in the application area A and the key area A1 respectively; At this time, the application area A is the program working area, the key area A1 is the key working area, the application area B is the program idle area, and the key area B1 is the key idle area; S3): Prepare the compiled Bin file; S301): the compiled Bin file is obtained by connecting the Bin file generated by compiling the new application to the encrypted data; the encrypted data is calculated by the data in the key working area and the built-in key; S4): Use the compiled Bin file to make an OTA upgrade request; S5): The program to be upgraded calls the built-in key and the data in the key workspace to perform encryption calculations, obtains the encryption result, and compares and verifies it with the encrypted data at the end of the Bin file; If they are consistent, the encrypted data and the upgrade program are written into the key free area and the program free area respectively, and the application address pointer is updated to the program free area, and the upgrade is successful; if they are inconsistent, the upgrade is rejected and the process jumps to S3) to wait for the next OTA upgrade request; S6): The program working area and the program idle area alternate, and the key working area and the key idle area alternate; subsequent OTA upgrades start from S3).

2. The OTA security upgrade method according to claim 1, characterized in that: The S5) specifically includes: S501): The program to be upgraded extracts the encrypted data at the end of the Bin file as the encryption result X16; S502): The program to be upgraded uses the data in the key work area as the original data and calls the built-in key to encrypt the data to obtain the encryption result Y16; S503): Compare the encryption result X16 and the encryption result Y16 to see if they are exactly the same. If they are the same, write the encryption result Y16 and the upgrade program into the key free area and the program free area respectively, update the application address pointer to the program free area, and the upgrade is successful. If they are not the same, reject the upgrade and jump to S3) to wait for the next OTA upgrade request.

3. The OTA security upgrade method according to claim 2, characterized in that: The specific updating of the application address pointer in S503) is: Run the Bootloader program, the Bootloader program initializes the program and calls a pointer address. The pointer address is used to indicate whether to jump to application area A or application area B after the Bootloader program ends. The Bootloader program jumps according to the pointer address and starts the application normally, and the product works normally.

4. The OTA security upgrade method according to claim 1, characterized in that: The S4) includes that when the application receives the OTA upgrade request, it first accepts the data and verifies the data according to the conventional upgrade process and upgrade protocol, and then executes S5) to verify and write the program free area operation.

5. The OTA security upgrade method according to claim 1, characterized in that: The specific judgment of the first operation in S2) is: After the MCU runs the Bootloader program, it reads the contents of area A1 and area B1 respectively. When it finds that the contents of these two areas are both 0x00 or 0XFF, it determines that the program is running for the first time and calls the FLASH write function to complete the first key A1 area data write; Otherwise, it is determined that the program is not being run for the first time, and the key A1 area is not written.

6. The OTA security upgrade method according to claim 1, characterized in that: The built-in key in S2) is written once online through a program, cannot be changed, and does not interact with the outside world.

7. The OTA security upgrade method according to claim 1, characterized in that: The space sizes of the key A1 area and the key B1 area in S1) are equal, and both are the minimum allowed erase block sizes of the current MCU.

Citation Information

Cited By

  • Safe OTA upgrading method for escalator software

    CN121598384A