Embedded system burning starting method and device and embedded SoC
By using the hash value and signature verification mechanisms of the master key pair and the working key pair in an embedded system, the security of the burn-in startup of the embedded system is solved, and the problem of low security in the existing technology is achieved, and efficient security mirror burn-in and startup is achieved.
Patent Information
- Application Number
- CN202510130039.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-05
- Publication Date
- 2025-06-20
AI Technical Summary
The existing embedded system burn-in startup method has low security problems, which may lead to illegal mirroring participating in burn-in and loading, reducing the security of the entire system.
Ensure the legitimacy and security of the image by obtaining the SPL packaged image from the server and verifying the hash value and signature of the master key pair and the work key pair. If the verification is successful, the image is written to the target storage medium and a chain security verification is performed when the system is started to ensure that only legal images are involved in burning and loading.
It improves the security of embedded system burning and startup, prevents illegal images from participating in burning and loading, and enhances the security of the entire system.
Smart Images

Figure CN120180423A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of embedded systems, and in particular to an embedded system burning startup method, device and embedded SoC. Background Art
[0002] Generally, an embedded SoC (System on Chip) is first burned and then started.
[0003] At present, the embedded SoC chip image burning process is roughly as follows: the SoC chip is powered on and started, and the BootRom (Boot Read-Only Memory) code (used to initialize hardware and load and start the operating system or boot loader) solidified inside the chip starts running, and enters the burning state by reading the Boot pin state. The BootRom code communicates with the burning software on the PC (Personal Computer) to burn the image to the specified storage medium. After the burning is completed, the embedded SoC is powered on again, the BootRom code is run, the image is loaded from the specified storage medium by reading the Boot pin state, and the DDR (Double Data Rate SDRAM) is initialized, the subsequent image is loaded into the DDR, and then the image is executed in the DDR to complete the system initialization, and the system enters the running state. The above method will cause illegal images to participate in burning and loading, reduce the security of the embedded system burning startup, and thus reduce the security of the entire system.
[0004] In summary, how to improve the security of embedded system burning and starting is a technical problem that needs to be solved urgently by those skilled in the art. Summary of the invention
[0005] In view of this, the purpose of the present application is to provide an embedded system burning and starting method, device and embedded SoC, which are used to improve the security of embedded system burning and starting.
[0006] In order to achieve the above objectives, this application provides the following technical solutions:
[0007] An embedded system burning startup method, applied to embedded SoC, comprising:
[0008] Obtain an SPL packaged image from the server, and calculate a first hash value for the master key pair public key therein; the SPL packaged image includes the master key pair public key, the SPL image and its signature;
[0009] If the first hash value is the same as the second hash value stored in the one-time programmable memory in the embedded SoC, verify the signature of the SPL image against the public key using the working key corresponding to the SPL image; the second hash value is generated from the legitimate master key and the public key.
[0010] If the signature verification is successful, the SPL runs and initializes the DDR, obtains the SPL packaged image from the server to the DDR, verifies the signature of the SPL image against the public key using the corresponding working key, and after successful signature verification, writes the SPL packaged image from the DDR to the target storage medium.
[0011] Obtain the next image with the corresponding signature from the server to the DDR, verify the signature of the image against the public key using the working key corresponding to the image, and if the signature verification is successful, write the image from the DDR to the target storage medium until the last image is written to the target storage medium, power on again and load each image from the target storage medium to start.
[0012] Optionally, loading each image from the target storage medium to start includes:
[0013] Obtain the SPL packaged image from the target storage medium, calculate the first hash value for the master key and the public key therein, and determine whether the first hash value is the same as the second hash value stored in the one-time programmable memory.
[0014] If they are the same, verify the signature of the SPL image against the public key using the working key corresponding to the SPL image, and if the signature verification is successful, the SPL runs and initializes the DDR.
[0015] Obtain the next image with the corresponding signature from the target storage medium to the DDR, verify the signature of the image against the public key using the working key corresponding to the image, and if the signature verification is successful, execute the step of obtaining the next image with the corresponding signature from the target storage medium to the DDR until the signature verification of the Uboot image is successful, then jump to execute Uboot, load the Linux image from the target storage medium to the DDR using Uboot, and verify the signature of the Linux image against the public key using the working key corresponding to the Linux image, and if the signature verification is successful, jump to execute Linux.
[0016] Optionally, writing the SPL packaged image from the DDR to the target storage medium includes:
[0017] Writing the SPL packaged image from the DDR into the data register of the controller corresponding to the target storage medium in the embedded SoC, encrypting the SPL packaged image using the controller, and writing the encrypted SPL packaged image into the target storage medium;
[0018] Writing the image from the DDR into the target storage medium includes:
[0019] Writing the image from the DDR into the data register, encrypting the image using the controller, and writing the encrypted image into the target storage medium;
[0020] Obtaining the SPL packaged image from the target storage medium includes:
[0021] Obtaining the encrypted SPL packaged image from the target storage medium into the data register, and decrypting it using the controller to obtain the SPL packaged image;
[0022] Obtaining the next image from the target storage medium into the DDR includes:
[0023] Obtaining the encrypted image from the target storage medium into the data register, decrypting it using the controller to obtain the corresponding image, and loading the image into the DDR.
[0024] Optionally, the SPL packaged image further includes multiple working key pairs of public keys and mirror key configuration information, and the mirror key configuration information includes the mirror name and the working key pairs of public keys corresponding to the corresponding mirror;
[0025] Before verifying the signature of the SPL image using the working key pair of public keys corresponding to the SPL image, it further includes:
[0026] Obtaining the working key pair of public keys corresponding to the SPL image from the SPL packaged image according to the mirror key configuration information;
[0027] Before verifying the signature of the image using the working key pair of public keys corresponding to the image, it further includes:
[0028] Obtaining the working key pair of public keys corresponding to the image from the SPL packaged image according to the mirror key configuration information.
[0029] Optionally, obtaining the next image from the server into the DDR includes:
[0030] Obtaining images from the server into the DDR in the order of Sloader image, SecureOS image, Uboot image, and Linux image;
[0031] Fetch the next image from the target storage medium to the DDR, including:
[0032] Fetch images from the target storage medium to the DDR in the order of Sloader image, SecureOS image, Uboot image, and Linux image.
[0033] Optionally, the master key pair is different from each working key pair, and each working key pair is different from each other, and the master key pair and the working key pairs are all RSA2048 key pairs.
[0034] Optionally, it further includes:
[0035] If the first hash value is different from the second hash value or the signature verification fails, terminate the process and issue a prompt that the process has not been successfully carried out.
[0036] An embedded system flashing and starting device, applied to an embedded SoC, includes:
[0037] A first calculation module, configured to obtain an SPL packaged image from a server and calculate a first hash value for the public key of the master key pair therein; the SPL packaged image includes the public key of the master key pair, the SPL image, and its signature;
[0038] A first signature verification module, configured to, if the first hash value is the same as the second hash value stored in the one-time programmable memory of the embedded SoC, verify the signature of the SPL image using the public key of the working key pair corresponding to the SPL image; the second hash value is generated based on the legal public key of the master key pair;
[0039] A second signature verification module, configured to, if the signature verification is successful, run the SPL and initialize the DDR, obtain the SPL packaged image from the server to the DDR, verify the signature of the SPL image using the public key of the corresponding working key pair, and after the signature verification is successful, write the SPL packaged image from the DDR to the target storage medium;
[0040] A third signature verification module, configured to obtain the next image with the corresponding signature from the server to the DDR, verify the signature of the image using the public key of the working key pair corresponding to the image, and if the signature verification is successful, write the image from the DDR to the target storage medium until the last image is written to the target storage medium, power on again and load each image to start.
[0041] Optionally, the third signature verification module includes:
[0042] A second calculation module, configured to obtain the SPL packaged image from the target storage medium, calculate a first hash value for the public key of the master key therein, and determine whether the first hash value is the same as a second hash value stored in the one-time programmable memory;
[0043] A fourth signature verification module, configured to, if they are the same, verify the signature of the SPL image using the public key of the working key corresponding to the SPL image, and if the verification is successful, the SPL runs and initializes the DDR;
[0044] A fifth signature verification module, configured to obtain the next image with a corresponding signature from the target storage medium to the DDR, verify the signature of the image using the public key of the working key corresponding to the image, and if the verification is successful, execute the step of obtaining the next image with a corresponding signature from the target storage medium to the DDR, until the Uboot image verification is successful, then jump to execute Uboot, load the Linux image to the DDR using the Uboot, and verify the signature of the Linux image using the public key of the working key corresponding to the Linux image, and if the verification is successful, jump to execute Linux.
[0045] An embedded SoC, comprising:
[0046] A memory, configured to store a computer program;
[0047] A processor, configured to implement the steps of the embedded system flashing and starting method as described in any one of the above when executing the computer program.
[0048] The present application provides an embedded system flashing and starting method, device and embedded SoC. Among them, the method is applied to an embedded SoC and includes: obtaining an SPL packaged image from a server, and calculating a first hash value for the public key of the master key therein; the SPL packaged image includes the public key of the master key, the SPL image and its signature; if the first hash value is the same as a second hash value stored in the one-time programmable memory of the embedded SoC, verifying the signature of the SPL image using the public key of the working key corresponding to the SPL image; the second hash value is generated according to a legal public key of the master key; if the verification is successful, the SPL runs and initializes the DDR, obtains the SPL packaged image from the server to the DDR, verifies the signature of the SPL image using the corresponding working key public key, and after the verification is successful, writes the SPL packaged image from the DDR to the target storage medium; obtains the next image with a corresponding signature from the server to the DDR, verifies the signature of the image using the public key of the working key corresponding to the image, and if the verification is successful, writes the image from the DDR to the target storage medium, until the last image is written to the target storage medium, powers on again and loads each image from the target storage medium to start.
[0049] In the above technical solution disclosed in this application, first obtain a SPL packaged image containing the public key of the master key, the SPL image and its signature from the server. Then, calculate the first hash value for the public key of the master key among them. If the first hash value is the same as the second hash value generated based on the legal public key of the master key stored in the one-time programmable memory of the embedded SoC, it indicates that the SPL packaged image has not been tampered with, etc., that is, it indicates that the SPL packaged image is legal and secure. Then, verify the signature of the SPL image using the public key of the working key corresponding to the SPL image. If the signature verification is successful, it indicates that the SPL image is legal, secure, and has not been tampered with. At this time, the corresponding SPL runs and initializes the DDR. After that, obtain the SPL packaged image from the server to the DDR, verify the signature of the SPL image using the public key of the working key corresponding to the SPL image. Only when the signature verification is successful, obtain the next image from the server to the DDR, and verify the signature of the image using the public key of the working key corresponding to the image. If the signature verification is successful, it indicates that the image is secure, legal, and has not been tampered with. Then, the image can be written from the DDR to the target storage medium, and repeat the above steps of obtaining the next image from the server to the DDR until the last image is written to the target storage medium. Then, the embedded SoC can be powered on again and load and start each burned image from the target storage medium. Through the above process, it is ensured that only legal, secure, and untampered images are burned to the target storage medium and each image is loaded and started from the target storage medium, avoiding illegal, insecure, and tampered images from participating in the burning and starting process, thereby improving the security of image burning and starting, and further improving the security of the entire system.
[0050] Additional aspects and advantages of this application will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of this application. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is a flowchart of a method for burning and starting an embedded system provided by an embodiment of this application;
[0052] Figure 2 It is a schematic diagram of the composition of the SPL packaged image provided by an embodiment of this application;
[0053] Figure 3 It is a schematic diagram of the composition of other images provided by an embodiment of this application;
[0054] Figure 4 It is a flowchart of the image transfer process during the image burning process provided by an embodiment of this application;
[0055] Figure 5 It is a flowchart of the image transfer process during the startup process provided by an embodiment of this application;
[0056] Figure 6 A flowchart of an embedded system programming method provided in an embodiment of the present application;
[0057] Figure 7 A flowchart of an embedded system startup method provided in an embodiment of the present application;
[0058] Figure 8 A schematic diagram of the structure of an embedded system burning startup device provided in an embodiment of the present application;
[0059] Figure 9 A schematic diagram of the structure of an embedded SoC provided in an embodiment of the present application. DETAILED DESCRIPTION
[0060] The general process of burning the image of an embedded SoC chip is that the SoC chip is powered on and started, and the BootRom code solidified inside the chip starts running, and enters the burning state by reading the Boot pin status. The BootRoom code communicates with the burning software on the PC to burn the image to the specified storage medium. After the embedded SoC is burned, it is powered on again, runs the BootRom code, loads the image from the specified storage medium by reading the Boot pin and initializes the DDR, loads the subsequent image into the DDR, and then jumps to the DDR to execute the subsequent image. After the system is initialized, the system enters the normal operating state. The above method will cause illegal images to participate in burning and loading, reduce the security of the embedded system burning startup, and thus reduce the security of the entire system.
[0061] To this end, the present application provides an embedded system burning and starting method, device and embedded SoC, which are used to improve the security of embedded system burning and starting.
[0062] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.
[0063] See also Figures 1 to 3 ,in, Figure 1 A flowchart of an embedded system programming startup method provided by an embodiment of the present application is shown. Figure 2 The figure shows a schematic diagram of the composition of the SPL packaged image provided by the embodiment of the present application. Figure 3 The composition diagram of other images provided by the embodiment of the present application is shown. An embedded system burning startup method provided by the embodiment of the present application is applied to an embedded SoC and may include:
[0064] S11: Obtain the SPL packaged image from the server, and calculate the first hash value for the public key of the master key in it; the SPL packaged image includes the public key of the master key, the SPL image and its signature.
[0065] First, on the server side, the hash calculation can be performed separately on the SPL (Second Program Loader) image to be burned into the embedded system and each other image (for each image, specifically, the hash operation is performed on the entire program part of the image), obtaining the hash value corresponding to each image. Then, use the private key in the corresponding working key pair pre-set for each image (all private keys are not sent out and not made public) to sign the hash value corresponding to the corresponding image, obtaining the signature corresponding to each image, and the signature corresponding to each image can be placed in the corresponding image, for example, at the end of the corresponding image. That is, each image can include image header information (information specifying the size, loading address, etc. of the image), a program part (i.e., the corresponding program logic part, taking the SPL image as an example, the program part therein is the program logic part of the SPL), and a signature, where the image header information and the program part belong to the original data of the image, and the signature belongs to the newly added data in the image.
[0066] Considering that the SPL image is the first burned image and also serves as the first image for startup during startup, in order to improve the burning and startup efficiency, the SPL image, the signature of the SPL image, and the pre-set public key of the main key pair (i.e., the public key included in the main key pair, used to verify the legality of the SPL packaged image) can be packaged together to form an SPL packaged image (i.e., the SPL.pak image). And the second hash value can be calculated using the pre-set legal public key of the main key pair, and the calculated second hash value can be written into the one-time programmable memory inside the embedded SoC to facilitate verifying the legality and security of the SPL packaged image based on the second hash value stored in the one-time programmable memory inside the embedded SoC. The one-time programmable memory only allows programming once. Once programmed, the data is permanently valid, that is, it can only go from 0 to 1 and cannot go from 1 to 0. Therefore, using the one-time programmable memory to store the key can play a role in protecting the key. Among them, in order to save the storage space of the one-time programmable memory and reduce the storage cost of the embedded SoC, etc., the second hash value can be obtained by performing a hash calculation on the legal public key of the main key pair first and storing the second hash value in the one-time programmable memory. Of course, the legal public key of the main key pair can also be directly stored in the one-time programmable memory, and later when comparing, it can be directly compared whether the public key of the main key pair in the SPL packaged image is the same as the public key of the main key pair in the one-time programmable memory. It should be noted that the one-time programmable memory mentioned here can be, for example, an efuse (electronic fuse) (not limited to efuse, and can also be other one-time programmable memories), and its characteristic is that it can only go from 0 to 1 and cannot go from 1 to 0.
[0067] By packaging the SPL image, the signature of the SPL image, and the pre-set public key of the main key pair together to form an SPL packaged image, the SPL packaged image can be used as the first burned image during the secure burning process, and can be used to initialize the burning environment and burn other images, and also serves as the first-level image for startup during secure startup.
[0068] Specifically, when image burning is needed, the embedded SoC is powered on, and the BootRom code solidified in the embedded SoC starts running, and communicates with the burning software on the server through the USB (Universal Serial Bus) interface, so as to improve the burning efficiency and burning convenience. Load the SPL packaged image from the server through the USB interface (judged by the external pin whether to enter the USB download mode, if so, load the SPL packaged image) to the internal SRAM (Static Random-Access Memory, static random access memory), the BootRom code calculates the master key in the SPL packaged image to the public key to obtain the first hash value, and compares the first hash value with the second hash value stored in the one-time programmable memory in the embedded SoC to determine whether the two are the same. Wherein, the second hash value is generated in advance according to the legal master key to the public key.
[0069] S12: If the first hash value is the same as the second hash value stored in the one-time programmable memory in the embedded SoC, the signature of the SPL image is verified using the working key pair public key corresponding to the SPL image; the second hash value is generated based on the legitimate master key pair public key.
[0070] If the first hash value is different from the second hash value stored in the one-time programmable memory in the embedded SoC, it indicates that the SPL package image obtained from the server is illegal and insecure. At this time, the download process is terminated. If the first hash value is the same as the second hash value stored in the one-time programmable memory in the embedded SoC, it indicates that the SPL package image obtained from the server is legal and secure. At this time, the public key of the working key pair corresponding to the SPL image included in the SPL package image (i.e., the public key included in the working key pair) can be obtained. For example, the public key of the working key pair corresponding to the SPL image can be obtained from the server in advance, or the public key of the working key pair corresponding to the SPL image can be obtained from the SPL package image, etc. Then, the signature of the SPL image can be verified using the public key of the working key pair corresponding to the SPL image. Specifically, the signature of the SPL image is decrypted using the public key of the working key pair corresponding to the SPL image. If the decryption fails, the signature verification fails, indicating that the SPL image included in the SPL package image obtained from the server is illegal; if the decryption is successful, the hash value of the SPL image included in the SPL package image is calculated and compared with the hash value obtained by decrypting the signature of the SPL image using the public key of the working key pair corresponding to the SPL image. If the calculated hash value is inconsistent with the decrypted hash value, it indicates that the SPL image in the SPL package image is illegal or tampered with, and the signature verification fails; if the calculated hash value is consistent with the decrypted hash value, it indicates that the SPL image in the SPL package image is legal, secure and not tampered with, and the signature verification is successful.
[0071] S13: If the signature verification is successful, the SPL runs and initializes the DDR, obtains the SPL package image from the server to the DDR, verifies the signature of the SPL image using the corresponding public key of the working key pair, and writes the SPL package image from the DDR to the target storage medium after the signature verification is successful.
[0072] When using the working key corresponding to the SPL image to verify the signature of the public key for the SPL image, if the signature verification fails, the download process is terminated. If the signature verification is successful, the SPL is run (i.e., the SPL is started), the DDR is initialized using the SPL, and then a connection to the root server is established again. Specifically, a USB communication connection can be established to improve the burning efficiency and convenience. Then, the embedded SoC (specifically, the SPL running in the embedded SoC) obtains the SPL packaged image from the server to the DDR through the USB connection, and uses the working key corresponding to the SPL image to verify the signature of the public key for the SPL image. The specific process is the same as the process of using the working key corresponding to the SPL image to verify the signature of the public key for the SPL image in step S12, which will not be elaborated here. If the signature verification fails, the download process is terminated. If the signature verification is successful, it indicates that the SPL image is legal, secure, and unmodified. At this time, the SPL packaged image is written from the DDR to the target storage medium. Specifically, reference can be made to Figure 4 , which shows the mirror transfer flow chart in the mirror burning process provided by the embodiment of the present application. ① represents that the mirror is written from the server side to the DDR through the embedded SoC via the USB interface. ② represents that after the signature verification of the mirror is successful, the embedded SoC writes the mirror in the DDR to the external target storage medium. Among them, the target storage medium is connected to the embedded SoC, and can be, for example, Emmc (Embedded multi media card), NandFlash (flash memory), etc.
[0073] Of course, after obtaining the SPL packaged image from the server to the DDR, before using the corresponding working key to verify the signature of the public key for the SPL image, the first hash value can also be calculated for the public key of the master key in the SPL packaged image, and it is judged whether the first hash value is the same as the second hash value stored in the one-time programmable memory in the embedded SoC. If they are the same, the step of using the corresponding working key to verify the signature of the public key for the SPL image is executed. If they are not the same, the step of using the corresponding working key to verify the signature of the public key for the SPL image and subsequent steps are refused to be executed, that is, the download process is terminated.
[0074] S14: Obtain the next mirror containing the corresponding signature from the server to the DDR, use the working key corresponding to the mirror to verify the signature of the public key for the mirror. If the signature verification is successful, write the mirror from the DDR to the target storage medium until the last mirror is written to the target storage medium, power on again and load and start each mirror from the target storage medium.
[0075] In step S13, when verifying the signature of the public key pair of the SPL image using the corresponding working key of the SPL image, if the verification is successful, the embedded SoC (specifically, the SPL running in the embedded SoC) obtains the next image (which contains the corresponding signature) from the server to the DDR. Then, obtain the public key of the working key pair corresponding to this image. Specifically, the public key of the working key pair corresponding to this image can be obtained from the server in advance, or the public key of the working key pair corresponding to the corresponding image can be obtained from the SPL package image, etc. Verify the signature of the image using the public key of the working key pair corresponding to the image. Specifically, decrypt the signature of the image using the public key of the working key pair corresponding to the image. If the decryption fails, the verification fails, indicating that the image obtained from the server is illegal and insecure; if the decryption is successful, calculate the hash value of the image and compare it with the hash value obtained by decrypting the signature of the image using the public key of the working key pair corresponding to the image. If the two do not match, it indicates that the image is illegal or tampered with, and the verification fails. If the two match, it indicates that the image is legal, secure, and not tampered with, and the verification is successful. At this time, write this image from the DDR to the target storage medium, and return to execute the step of obtaining the next image containing the corresponding signature from the server to the DDR and subsequent related steps. During this period, if the verification fails, the process is terminated. Only when the verification is successful will the next process be carried out until the last image is written to the target storage medium. Then, the embedded SoC is powered on again and loads each image from the target storage medium to start up.
[0076] Through the above process, a security verification mechanism is implemented in the image burning stage of the embedded SoC chip, ensuring that only legal and secure images can be burned into the system during the image burning stage, and a chained security verification method is adopted during the burning process to ensure the legality of the image burning. Only when the current image verification is successful will the burning process continue. If the current image verification fails, the burning process ends, ensuring the legality and security of each burned image, and then loading each burned image from the target storage medium to start up to ensure the security of the system startup. Moreover, from the above process, it can be seen that the embodiment of the present application uses two levels of key pairs, the master key pair and the working key pair, to manage secure burning and secure startup (wherein, all private keys are not sent externally and are not publicly disclosed).
[0077] In the above technical solution disclosed in the embodiments of the present application, first, an SPL packaged image containing the public key of the master key, the SPL image, and its signature is obtained from the server. Then, a first hash value is calculated for the public key of the master key therein. If the first hash value is the same as the second hash value generated based on the legal public key of the master key stored in the one-time programmable memory of the embedded SoC, it indicates that the SPL packaged image has not been tampered with, that is, it indicates that the SPL packaged image is legal and secure. Then, the signature of the SPL image is verified using the public key of the working key corresponding to the SPL image. If the verification is successful, it indicates that the SPL image is legal, secure, and has not been tampered with. At this time, the corresponding SPL runs and initializes the DDR. After that, the SPL packaged image is obtained from the server to the DDR, and the signature of the SPL image is verified using the public key of the working key corresponding to the SPL image. Only when the verification is successful, the next image is obtained from the server to the DDR, and the signature of the image is verified using the public key of the working key corresponding to the image. If the verification is successful, it indicates that the image is secure, legal, and has not been tampered with. Then, the image can be written from the DDR to the target storage medium, and the above steps of obtaining the next image from the server to the DDR are repeated until the last image is written to the target storage medium. Then, the embedded SoC can be powered on again and the burned images can be loaded from the target storage medium to start. Through the above process, it is ensured that only legal, secure, and untampered images are burned to the target storage medium and the burned images are loaded from the target storage medium to start, avoiding illegal, insecure, and tampered images from participating in the burning and starting process, thereby improving the security of image burning and starting, and further improving the security of the entire system.
[0078] An embedded system burning and starting method provided by an embodiment of the present application, which can include loading each image from a target storage medium to start:
[0079] Obtain an SPL packaged image from the target storage medium, calculate a first hash value for the public key of the master key therein, and determine whether the first hash value is the same as the second hash value stored in the one-time programmable memory;
[0080] If they are the same, verify the signature of the SPL image using the public key of the working key corresponding to the SPL image. If the verification is successful, the SPL runs and initializes the DDR;
[0081] Fetch the next image with the corresponding signature from the target storage medium to the DDR, verify the signature of the image using the public key with the working key corresponding to the image. If the signature verification is successful, execute the step of fetching the next image with the corresponding signature from the target storage medium to the DDR until the signature verification of the Uboot image is successful, then jump to execute Uboot, load the Linux image to the DDR using Uboot, and verify the signature of the Linux image using the public key with the working key corresponding to the Linux image. If the signature verification is successful, then jump to execute Linux.
[0082] In the embodiment of the present application, in order to ensure the security of the startup of the embedded SoC, a chained security verification method can be adopted to verify the startup process of the embedded SoC. The specific implementation process is as follows:
[0083] Step 21: The embedded SoC is powered on again, and the BootRom code starts to run, fetching the SPL packaged image from the target storage medium to the on-chip SRAM. The embedded SoC (specifically, the BootRom code in the embedded SoC) calculates the first hash value for the public key of the main key in the SPL packaged image, and judges the first hash value and the second hash value stored in the one-time programmable memory in the embedded SoC (pre-generated according to the legal main key public key).
[0084] Step 22: If the first hash value is different from the second hash value, it indicates that the SPL packaged image fetched from the target storage medium is illegal and insecure. At this time, the startup process is terminated. If the first hash value is the same as the second hash value, it indicates that the SPL packaged image fetched from the target storage medium is legal and secure. At this time, the public key of the working key corresponding to the SPL image included in the SPL packaged image can be obtained (for example, the public key of the working key corresponding to the SPL image can be obtained from the server in advance, or the public key of the working key corresponding to the SPL image can be obtained from the SPL packaged image, etc.), and the signature of the SPL image is verified using the public key of the working key corresponding to the SPL image. Specifically, the signature of the SPL image is decrypted using the public key of the working key corresponding to the SPL image. If the decryption fails, the signature verification fails, indicating that the SPL image included in the SPL packaged image fetched from the target storage medium is illegal; if the decryption is successful, calculate the hash value of the SPL image included in the SPL packaged image, and compare it with the hash value obtained by decrypting the signature of the SPL image using the public key of the working key corresponding to the SPL image. If the calculated hash value is inconsistent with the decrypted hash, it indicates that the SPL image is illegal or tampered with, the signature verification fails, and the startup process is terminated; if the calculated hash value is consistent with the decrypted hash, it indicates that the SPL image is legal, secure and not tampered with, the signature verification is successful, and the SPL starts to run and initializes the DDR to prepare for image loading.
[0085] Step 23: After initializing the DDR, the embedded SoC (specifically, the SPL running in the embedded SoC) fetches the next image with the corresponding signature from the target storage medium to the DDR. Then, obtain the public key of the working key pair corresponding to this image (for example, the public key of the working key pair corresponding to this image can be obtained from the server in advance, or the public key of the working key pair corresponding to the corresponding image can be obtained from the SPL packaged image, etc.), and use the public key of the working key pair corresponding to this image to verify the signature of this image. The signature verification process is similar to the above signature verification process and will not be elaborated here. If the signature verification fails, the startup process is terminated; if the signature verification is successful, it indicates that this image is legal, secure, and not tampered with. At this time, the step of fetching the next image with the corresponding signature from the target storage medium to the DDR can be executed until the Uboot (embedded system boot loader) image is fetched from the target storage medium to the DDR and the signature verification of the Uboot (Universal Boot Loader) image is successful. For details, please refer to Figure 5 , which shows the flowchart of image transfer during startup provided by the embodiment of the present application. ③ represents that the embedded SoC loads the image from the target storage medium to the specified address in the DDR and jumps to execute after passing the signature verification.
[0086] If the signature verification of the Uboot image is successful, jump to execute Uboot. Then, use Uboot to load the Linux (Linux, a computer operating system) image to the DDR. Obtain the public key of the working key pair corresponding to the Linux image (for example, the public key of the working key pair corresponding to the Linux image can be obtained from the server in advance, or the public key of the working key pair corresponding to the Linux image can be obtained from the SPL packaged image, etc.), and use the public key of the working key pair corresponding to the Linux image to verify the signature of the Linux image. The signature verification process is similar to the above signature verification process and will not be elaborated here. If the signature verification fails, the startup process is terminated; if the signature verification is successful, it indicates that the Linux image is legal, secure, and not tampered with. At this time, it can jump to execute Linux to successfully start the embedded SoC.
[0087] Through the above process, a security verification mechanism is added during the startup phase of the embedded SoC chip, and the chain security verification method is adopted to ensure the legality of the startup image. Only legal images can be started normally, ensuring the security of the startup process.
[0088] An embedded system burning and startup method provided by an embodiment of the present application for writing the SPL packaged image from the DDR to the target storage medium may include:
[0089] Write the SPL packaged image from the DDR into the data register included in the controller corresponding to the target storage medium in the embedded SoC, encrypt the SPL packaged image using the data register, and write the encrypted SPL packaged image into the target storage medium;
[0090] Writing the image from the DDR into the target storage medium may include:
[0091] Write the image from the DDR into the data register, encrypt the image using the data register, and write the encrypted image into the target storage medium;
[0092] Obtaining the SPL packaged image from the target storage medium may include:
[0093] Obtain the encrypted SPL packaged image from the target storage medium to the data register, and decrypt it using the data register to obtain the SPL packaged image;
[0094] Obtaining the next image from the target storage medium to the DDR may include:
[0095] Obtain the encrypted image from the target storage medium to the data register, decrypt it using the data register to obtain the corresponding image, and load the image into the DDR.
[0096] In the embodiments of the present application, considering that there may be a risk of leakage when the image of the embedded SoC is stored in an external storage medium, in order to improve the security of image transmission and storage, the IP (Internet Protocol) of the controller corresponding to the external storage medium can be designed and improved specifically during the chip design stage of the embedded SoC to ensure security at the hardware level. The main idea is to encrypt the data register of the IP such as the target storage medium. When the embedded SoC needs to save data to the target storage medium, the embedded SoC needs to write the data into the data register included in the controller. After writing is completed, the data is encrypted before data transmission, and after encryption is completed, it is transmitted to the target storage medium. When the embedded SoC needs to read data from the target storage medium, the embedded SoC needs to send a read command to the controller. After the controller reads the data from the target storage medium into the data register, the data is decrypted. Through the above methods, the security of data transmission and storage is ensured at the lowest hardware level of the embedded SoC.
[0097] Specifically, when the embedded SoC writes the SPL packaged image from the DDR to the target storage medium, it can first write the SPL packaged image from the DDR to the data register included in the controller corresponding to the target storage medium in the embedded SoC. Use the controller corresponding to the target storage medium to encrypt the SPL packaged image, and then write the encrypted SPL packaged image to the target storage medium to ensure the security of the transmission and storage of the SPL packaged image. Moreover, when the embedded SoC writes the image from the DDR to the target storage medium, it can first write the image from the DDR to the data register included in the controller corresponding to the target storage medium, use the controller corresponding to the target storage medium to encrypt the image, and then write the encrypted image to the target storage medium to ensure the security of the transmission and storage of other images.
[0098] Correspondingly, when the embedded SoC obtains the SPL packaged image from the target storage medium, it can first obtain the encrypted SPL packaged image from the target storage medium to the data register included in the controller corresponding to the target storage medium in the embedded SoC, and use the controller corresponding to the target storage medium to decrypt the encrypted SPL packaged image to obtain the SPL packaged image. Moreover, when the embedded SoC obtains the next image from the target storage medium to the DDR, specifically, it can obtain the encrypted image from the target storage medium to the data register included in the controller corresponding to the target storage medium in the embedded SoC, use the controller corresponding to the target storage medium to decrypt the encrypted image to obtain the corresponding image, and then load the decrypted corresponding image into the DDR.
[0099] Through the above process, the probability of the program logic outside the mirror during the burning and startup process can be reduced, and the security of the mirror transmission and storage can be improved.
[0100] In an embedded system burning and startup method provided by an embodiment of the present application, the SPL packaged image may further include multiple working key public keys and mirror key configuration information, and the mirror key configuration information may include the mirror name and the working key public keys corresponding to the corresponding mirror;
[0101] Before verifying the signature of the SPL image using the working key public key pair corresponding to the SPL image, it may further include:
[0102] Obtain the working key public key pair corresponding to the SPL image from the SPL packaged image according to the mirror key configuration information;
[0103] Before verifying the signature of the image using the working key public key pair corresponding to the image, it may further include:
[0104] Obtain the working key public key pair corresponding to the image from the SPL packaged image according to the mirror key configuration information.
[0105] In an embodiment of the present application, the SPL image, the signature of the SPL image, the public key of the pre-set master key pair, the public key of the working key pair corresponding to each image, and the image key configuration information can be packaged together to form an SPL packaged image. That is, the SPL packaged image can not only include the SPL image, the signature of the SPL image, and the public key of the pre-set master key pair, but also include multiple public keys of the working key pairs and the image key configuration information. The image key configuration information includes the working key pair configuration information of each image for secure burning and secure booting, and may include the image name and the public key of the working key pair corresponding to the corresponding image (for example, which public key in the working key pair is used by the corresponding image). Among them, there is only one master key pair, and the number of working key pairs can be multiple.
[0106] On this basis, before verifying the signature of the SPL image using the public key of the working key pair corresponding to the SPL image, the public key of the working key pair corresponding to the SPL image can be obtained from the multiple public keys of the working key pairs included in the SPL packaged image according to the image key configuration information included in the SPL packaged image, and then the signature of the SPL image is verified using the public key of the working key pair corresponding to the SPL image. For other images, similar to the SPL image, before verifying the signature of the image using the public key of the working key pair corresponding to the image, the public key of the working key pair corresponding to the corresponding image can be obtained from the multiple public keys of the working key pairs included in the SPL packaged image according to the image key configuration information included in the SPL packaged image, and then the signature of the corresponding image is verified using the public key of the working key pair corresponding to the corresponding image.
[0107] Through the above process, the number of interactions can be reduced, and the security, efficiency, and convenience of burning and booting can be improved.
[0108] See Figure 6 and Figure 7 wherein, Figure 6 shows a flowchart of an embedded system burning method provided by an embodiment of the present application, Figure 7 shows a flowchart of an embedded system booting method provided by an embodiment of the present application. An embedded system burning and booting method provided by an embodiment of the present application for obtaining the next image from the server to the DDR may include:
[0109] Obtain images from the server to the DDR in the order of Sloader image, SecureOS image, Uboot image, and Linux image;
[0110] Obtaining the next image from the target storage medium to the DDR includes:
[0111] Obtain the images from the target storage medium to the DDR in the order of Sloader image, SecureOS image, Uboot image, and Linux image.
[0112] In the embodiments of the present application, the images corresponding to the embedded SoC specifically include the SPL image, the Sloader (an ELF (Executable and Linkable Format) loader) image, the SecureOS (Secure Operating System) image, the Uboot image, and the Linux image.
[0113] On this basis, during the flashing process, after the signature verification of the SPL image is successful and the SPL packaged image is written from the DDR to the target storage medium, when obtaining the next image from the server to the DDR, obtain the images from the server to the DDR in the order of Sloader image, SecureOS image, Uboot image, and Linux image. Specifically, during the flashing process, after the signature verification of the SPL image is successful and the SPL packaged image is written from the DDR to the target storage medium, first obtain the Sloader image from the server to the DDR, verify the signature of the Sloader image using the public key with the working key corresponding to the Sloader image. If the verification fails, terminate the download process; if the verification is successful, write the Sloader image from the DDR to the target storage medium. Then, obtain the SecureOS image from the server to the DDR, verify the signature of the SecureOS image using the public key with the working key corresponding to the SecureOS image. If the verification fails, terminate the download process; if the verification is successful, write the SecureOS image from the DDR to the target storage medium. After that, obtain the Uboot image from the server to the DDR, verify the signature of the Uboot image using the public key with the working key corresponding to the Uboot image. If the verification fails, terminate the download process; if the verification is successful, write the Uboot image from the DDR to the target storage medium. Finally, obtain the Linux image from the server to the DDR, verify the signature of the Linux image using the public key with the working key corresponding to the Linux image. If the verification fails, terminate the download process; if the verification is successful, write the Linux image from the DDR to the target storage medium.
[0114] At startup, after the SPL runs and initializes the DDR, when fetching the next image from the target storage medium to the DDR, the images are fetched from the target storage medium to the DDR in the order of Sloader image, SecureOS image, Uboot image, and Linux image. Specifically, at startup, after the SPL runs and initializes the DDR, the SPL loads the Sloader image from the target storage medium into the DDR, and verifies the signature of the Sloader image's public key using the working key corresponding to the Sloader image. If the signature verification fails, the startup process is terminated. If the signature verification is successful, the SPL loads the SecureOS image from the target storage medium into the DDR, and verifies the signature of the SecureOS image's public key using the working key corresponding to the SecureOS image. If the signature verification fails, the startup process is terminated. If the signature verification is successful, the SPL loads the Uboot image from the target storage medium into the DDR, and verifies the signature of the Uboot image's public key using the working key corresponding to the Uboot image. If the signature verification fails, the startup process is terminated. If the signature verification is successful, it jumps to execute Uboot, and Uboot loads the Linux image into the DDR. Then, it verifies the signature of the Linux image's public key using the working key corresponding to the Linux image. If the signature verification fails, the startup process is terminated. If the signature verification is successful, it jumps to execute Linux.
[0115] Through the above process, the images are burned and loaded in sequence according to the arrangement order of the images, improving the orderliness and efficiency of the embedded system burning and startup.
[0116] An embedded system burning and startup method provided by an embodiment of this application, the main key pair is different from each working key pair, and each working key pair is different from each other, and both the main key pair and the working key pairs are RSA2048 key pairs.
[0117] In the embodiment of this application, the main key pair is different from each working key pair and each working key pair is different from each other, so as to further improve the security of burning and startup. It should be noted that the number of working key pairs can be determined according to the number of images, for example, it can be equal to or greater than the number of images. Exemplarily, 8 pairs of working key pairs can be owned.
[0118] Among them, both the main key pair and the working key pair can be RSA (Rivest-Shamir-Adleman) 2048 key pairs. Among them, RSA can resist most of the known cryptographic attacks so far. RSA2048 has 617 decimal digits, a total of 2048 bits, which is the largest RSA number currently. Using the RSA2048 key pair as the main key pair and the working key pair can greatly improve the security of the embedded system flashing and startup. Of course, other RSA key pairs or other types of key pairs can also be used as the main key pair and the working key pair.
[0119] An embedded system flashing and startup method provided by an embodiment of the present application may further include:
[0120] If the first hash value is different from the second hash value or the signature verification fails, the process is terminated and a prompt indicating that the process has not been successfully carried out is issued.
[0121] In an embodiment of the present application, during the flashing or startup process, if the first hash value is different from the second hash value or the signature verification fails when verifying the signature of a certain image, the corresponding process can be terminated to ensure the security of the corresponding process. And, a prompt indicating that the process has not been successfully carried out can also be issued, so that relevant personnel can take corresponding measures in a timely manner according to the prompt.
[0122] An embodiment of the present application also provides an embedded system flashing and startup device, which is applied to an embedded SoC. Refer to Figure 8 , which shows a schematic structural diagram of an embedded system flashing and startup device provided by an embodiment of the present application, and may include:
[0123] The first calculation module 81 is used to obtain the SPL packaged image from the server and calculate the first hash value for the public key of the main key pair therein; the SPL packaged image includes the public key of the main key pair, the SPL image and its signature;
[0124] The first signature verification module 82 is used to, if the first hash value is the same as the second hash value stored in the one-time programmable memory in the embedded SoC, verify the signature of the SPL image using the public key of the working key pair corresponding to the SPL image; the second hash value is generated according to the legal public key of the main key pair;
[0125] The second signature verification module 83 is used to, if the signature verification is successful, run the SPL and initialize the DDR, obtain the SPL packaged image from the server to the DDR, verify the signature of the SPL image using the public key of the corresponding working key pair, and write the SPL packaged image from the DDR to the target storage medium after the signature verification is successful;
[0126] The third signature verification module 84 is used to obtain the next image with the corresponding signature from the server to the DDR, verify the signature of the image with the public key using the working key corresponding to the image. If the signature verification is successful, the image is written from the DDR to the target storage medium until the last image is written to the target storage medium, and then the power is reset and each image is loaded to start.
[0127] An embedded system burning and starting device provided by an embodiment of the present application, the third signature verification module 84 may include:
[0128] A second calculation module is used to obtain the SPL packaged image from the target storage medium, calculate the first hash value for the public key of the master key therein, and determine whether the first hash value is the same as the second hash value stored in the one-time programmable memory;
[0129] A fourth signature verification module is used to, if they are the same, verify the signature of the SPL image with the public key using the working key corresponding to the SPL image. If the signature verification is successful, the SPL runs and initializes the DDR;
[0130] A fifth signature verification module is used to obtain the next image with the corresponding signature from the target storage medium to the DDR, verify the signature of the image with the public key using the working key corresponding to the image. If the signature verification is successful, execute the step of obtaining the next image with the corresponding signature from the target storage medium to the DDR until the signature verification of the Uboot image is successful, then jump to execute Uboot, load the Linux image to the DDR using Uboot, and verify the signature of the Linux image with the public key using the working key corresponding to the Linux image. If the signature verification is successful, jump to execute Linux.
[0131] An embedded system burning and starting device provided by an embodiment of the present application, the second signature verification module 83 may include:
[0132] A first writing unit is used to write the SPL packaged image from the DDR to the data register included in the controller corresponding to the target storage medium in the embedded SoC, encrypt the SPL packaged image using the data register, and write the encrypted SPL packaged image to the target storage medium;
[0133] The third signature verification module 84 may include:
[0134] A second writing unit is used to write the image from the DDR to the data register, encrypt the image using the data register, and write the encrypted image to the target storage medium;
[0135] The second calculation module may include:
[0136] A first obtaining unit is used to obtain the encrypted SPL packaged image from the target storage medium to the data register, decrypt it using the data register to obtain the SPL packaged image;
[0137] The fifth signature verification module may include:
[0138] A second acquisition unit, configured to acquire the encrypted image to a data register from a target storage medium, decrypt the encrypted image by using the data register to obtain the corresponding image, and load the image into the DDR.
[0139] In an embedded system flashing and starting device provided by an embodiment of the present application, the SPL packaged image may further include multiple public keys of working key pairs and image key configuration information. The image key configuration information may include an image name and the public keys of the working key pairs corresponding to the corresponding image;
[0140] It may further include:
[0141] A first acquisition module, configured to acquire the public keys of the working key pairs corresponding to the SPL image from the SPL packaged image according to the image key configuration information before verifying the signature of the SPL image by using the public keys of the working key pairs corresponding to the SPL image;
[0142] A second acquisition module, configured to acquire the public keys of the working key pairs corresponding to the image from the SPL packaged image according to the image key configuration information before verifying the signature of the image by using the public keys of the working key pairs corresponding to the image.
[0143] In an embedded system flashing and starting device provided by an embodiment of the present application, the third signature verification module 84 may include:
[0144] A first acquisition unit, configured to acquire images to the DDR from a server in the order of Sloader image, SecureOS image, Uboot image, and Linux image;
[0145] The fifth signature verification module may include:
[0146] A second acquisition unit, configured to acquire images to the DDR from the target storage medium in the order of Sloader image, SecureOS image, Uboot image, and Linux image.
[0147] In an embedded system flashing and starting device provided by an embodiment of the present application, the main key pair is different from each working key pair, and each working key pair is different from each other, and the main key pair and the working key pairs are all RSA2048 key pairs.
[0148] An embedded system flashing and starting device provided by an embodiment of the present application may further include:
[0149] A termination module, configured to terminate the process and issue a prompt that the process has not been successfully performed if the first hash value is different from the second hash value or the signature verification fails.
[0150] The embodiment of the present application also provides an embedded SoC. Refer to Figure 9 , which shows a schematic structural diagram of an embedded SoC provided by the embodiment of the present application. It may include:
[0151] A memory 91 for storing computer programs;
[0152] A processor 92, when executing the computer program stored in the memory 91, can implement the following steps:
[0153] Obtain the SPL package image from the server and calculate the first hash value for the public key of the master key in it; the SPL package image includes the public key of the master key, the SPL image and its signature; if the first hash value is the same as the second hash value stored in the one-time programmable memory in the embedded SoC, then verify the signature of the SPL image using the public key of the working key corresponding to the SPL image; the second hash value is generated based on the legal public key of the master key; if the signature verification is successful, then the SPL runs and initializes the DDR, obtains the SPL package image from the server to the DDR, verifies the signature of the SPL image using the public key of the corresponding working key, and after the signature verification is successful, writes the SPL package image from the DDR to the target storage medium; obtains the next image with the corresponding signature from the server to the DDR, verifies the signature of the image using the public key of the working key corresponding to the image, and if the signature verification is successful, writes the image from the DDR to the target storage medium until the last image is written to the target storage medium, then powers on again and loads each image from the target storage medium to start.
[0154] For the description of the relevant parts of an embedded system burning and starting device and an embedded SoC provided by the embodiment of the present application, reference can be made to the detailed description of the corresponding parts in an embedded system burning and starting method provided by the embodiment of the present application, which will not be elaborated here.
[0155] It should be noted that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in combination with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in combination with an instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection portion having one or more wirings (electronic device), a portable computer diskette case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or otherwise processing as appropriate, and then stored in a computer memory.
[0156] It should be understood that the various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0157] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0158] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In the description of this application, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.
[0159] In this application, unless otherwise clearly specified and defined, terms such as "installed", "connected", "linked", "fixed", etc. shall be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or integrated; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two elements or the interaction relationship between two elements, unless otherwise clearly defined. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0160] Although the embodiments of this application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting this application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.
Claims
1. A method for burning and starting an embedded system, characterized in that: Applied to embedded system-level SoC, including: Obtain a secondary program loader SPL packaged image from the server, and calculate a first hash value for the master key pair public key therein; the SPL packaged image includes the master key pair public key, the SPL image and its signature; If the first hash value is the same as the second hash value stored in the one-time programmable memory in the embedded SoC, the signature of the SPL image is verified using the working key pair public key corresponding to the SPL image; the second hash value is generated according to the legitimate master key pair public key; If the signature verification succeeds, the SPL runs and initializes the double-rate synchronous dynamic random access memory DDR, obtains the SPL package image from the server to the DDR, uses the corresponding working key to verify the signature of the SPL image with the public key, and writes the SPL package image from the DDR to the target storage medium after the signature verification succeeds; Obtain the next image containing the corresponding signature from the server to the DDR, and use the working key pair public key corresponding to the image to verify the signature of the image. If the verification is successful, write the image from the DDR to the target storage medium until the last image is written to the target storage medium, then power on again and load each image from the target storage medium to start.
2. The embedded system burning startup method according to claim 1, characterized in that: Loading each image from the target storage medium to start, including: Obtain the SPL packaged image from the target storage medium, calculate a first hash value for the master key pair public key therein, and determine whether the first hash value is the same as a second hash value stored in the one-time programmable memory; If they are the same, the signature of the SPL image is verified using the working key pair public key corresponding to the SPL image. If the verification succeeds, the SPL runs and initializes the DDR; Obtain the next image containing the corresponding signature from the target storage medium to the DDR, and use the working key pair public key corresponding to the image to verify the signature of the image. If the verification is successful, execute the step of obtaining the next image containing the corresponding signature from the target storage medium to the DDR, until the universal boot loader Uboot image is successfully verified, jump to execute Uboot, use the Uboot to load the Linus Linux image to the DDR, and use the working key pair public key corresponding to the Linux image to verify the signature of the Linux image. If the verification is successful, jump to execute Linux.
3. The embedded system burning startup method according to claim 2, characterized in that: Writing the SPL packaged image from the DDR to a target storage medium includes: Writing the SPL packaged image from the DDR into a data register included in a controller in the embedded SoC corresponding to the target storage medium, encrypting the SPL packaged image using the controller, and writing the encrypted SPL packaged image into the target storage medium; Writing the image from the DDR to the target storage medium includes: Writing the image from the DDR into the data register, encrypting the image using the controller, and writing the encrypted image into the target storage medium; Acquiring the SPL packaged image from the target storage medium includes: Obtain the encrypted SPL package image from the target storage medium to the data register, and decrypt it using the controller to obtain the SPL package image; Acquiring a next image from the target storage medium to the DDR includes: The encrypted image is obtained from the target storage medium to the data register, and is decrypted by the controller to obtain the corresponding image, and the image is loaded into the DDR.
4. The embedded system burning and starting method according to any one of claims 1 to 3, characterized in that: The SPL packaged image also includes multiple working key pair public keys and image key configuration information, and the image key configuration information includes the image name and the working key pair public key corresponding to the corresponding image; Before verifying the signature of the SPL image using the working key pair public key corresponding to the SPL image, the method further includes: Obtaining a public key of a working key pair corresponding to the SPL image from the SPL packaged image according to the image key configuration information; Before verifying the signature of the image using the working key pair public key corresponding to the image, the method further includes: According to the image key configuration information, obtain the public key of the working key pair corresponding to the image from the SPL packaged image.
5. The embedded system burning startup method according to claim 4, characterized in that: Obtaining the next image from the server to the DDR includes: Obtain the image from the server to the DDR according to the order of the executable and linkable format loader Sloader image, the secure operating system SecureOS image, the Uboot image, and the Linux image; Acquiring a next image from the target storage medium to the DDR includes: According to the arrangement order of Sloader image, SecureOS image, Uboot image and Linux image, the image is obtained from the target storage medium to the DDR.
6. The embedded system burning startup method according to claim 4, characterized in that: The master key pair is different from each working key pair, and each working key pair is different from each other, and both the master key pair and the working key pair are Rivest-Summer-Adleman RSA2048 key pairs.
7. The embedded system burning and starting method according to claim 4, characterized in that: Also includes: If the first hash value is different from the second hash value or the signature verification fails, the process is terminated and a prompt is issued indicating that the process has not been successfully completed.
8. An embedded system burning startup device, characterized in that: Applications in embedded SoCs, including: A first calculation module is used to obtain an SPL packaged image from a server and calculate a first hash value for a master key pair public key therein; the SPL packaged image includes a master key pair public key, an SPL image and its signature; A first signature verification module, configured to verify the signature of the SPL image using the working key pair public key corresponding to the SPL image if the first hash value is the same as the second hash value stored in the one-time programmable memory in the embedded SoC; the second hash value is generated according to the legitimate master key pair public key; The second signature verification module is used to run the SPL and initialize the DDR if the signature verification succeeds, obtain the SPL packaged image from the server to the DDR, use the corresponding working key to verify the signature of the SPL image with the public key, and write the SPL packaged image from the DDR to the target storage medium after the signature verification succeeds; The third signature verification module is used to obtain the next image containing the corresponding signature from the server to the DDR, and use the working key pair public key corresponding to the image to verify the signature of the image. If the signature verification is successful, the image is written from the DDR to the target storage medium until the last image is written to the target storage medium, and then power is turned on again and each image is loaded to start.
9. The embedded system burning and starting device according to claim 8, characterized in that: The third signature verification module includes: A second calculation module is used to obtain the SPL packaged image from the target storage medium, calculate a first hash value for the master key pair public key therein, and determine whether the first hash value is the same as a second hash value stored in the one-time programmable memory; The fourth signature verification module is used to verify the signature of the SPL image using the working key pair public key corresponding to the SPL image if they are the same. If the verification succeeds, the SPL runs and initializes the DDR; The fifth signature verification module is used to obtain the next image containing the corresponding signature from the target storage medium to the DDR, and use the working key pair public key corresponding to the image to verify the signature of the image. If the verification is successful, the step of obtaining the next image containing the corresponding signature from the target storage medium to the DDR is executed until the Uboot image is successfully verified, and then jump to execute Uboot, use the Uboot to load the Linux image to the DDR, and use the working key pair public key corresponding to the Linux image to verify the signature of the Linux image. If the verification is successful, jump to execute Linux.
10. An embedded SoC, characterized in that: include: Memory for storing computer programs; A processor is used to implement the steps of the embedded system burning and starting method as described in any one of claims 1 to 7 when executing the computer program.