Protection method and system for upgrade data, electronic equipment and storage medium
By encrypting and digital digest signatures of upgraded data and packaging them, the problem of low security in the existing technology is solved, and a higher data protection effect is achieved.
Patent Information
- Application Number
- CN202510186617.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-06-27
AI Technical Summary
In the prior art, upgrade data is usually protected by a single password encryption, which is easily tampered with low security.
By encrypting the upgrade data with a preset encryption password, obtaining and signing the digital digest, and finally packaging the encrypted upgrade data, the preset encryption password and the signed digital digest to form safe upgrade data.
Significantly improves the security of upgraded data, preventing tampering and unauthorized access.
Smart Images

Figure CN120217403A_ABST
Abstract
Description
Background Art
[0002] Currently, upgraded data is often protected by a single password encryption method, which is easy to be tampered with and has low security. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide a method, system, electronic device and storage medium for protecting upgraded data in view of the deficiencies of the prior art, as follows:
[0004] 1) In the first aspect, the present invention provides a method for protecting upgraded data, and the specific technical solution is as follows:
[0005] Use a preset encryption password to encrypt the upgraded data to obtain encrypted upgraded data;
[0006] Obtain the digital digest of the upgraded data and sign the digital digest;
[0007] Package the encrypted upgraded data, the preset encryption password and the signed digital digest to obtain secure upgraded data.
[0008] The beneficial effects of the method for protecting upgraded data provided by the present invention are as follows:
[0009] By encrypting the upgraded data and signing the digital digest of the upgraded data, the security of the upgraded data can be greatly guaranteed.
[0010] On the basis of the above solution, the method for protecting upgraded data of the present invention can also be improved as follows.
[0011] Further, using a preset encryption password to encrypt the upgraded data to obtain encrypted upgraded data includes:
[0012] Use the preset encryption password to perform symmetric encryption on the upgraded data to obtain encrypted upgraded data.
[0013] Further, it also includes:
[0014] Perform asymmetric encryption on the preset encryption password to obtain a protected password.
[0015] The beneficial effect of adopting the above further solution is that the security of the upgraded data can be further guaranteed.
[0016] Further, packaging the encrypted upgraded data, the preset encryption password and the signed digital digest to obtain secure upgraded data includes:
[0017] Package the encrypted upgraded data, the protected password and the signed digital digest to obtain secure upgraded data.
[0018] The beneficial effects of adopting the above further solution are: It can further ensure the security of the upgrade data.
[0019] 2) In the second aspect, the present invention also provides a protection system for upgrade data, and the specific technical solution is as follows:
[0020] It includes: a first encryption module, a signature module, and a packaging module;
[0021] The first encryption module is used for: encrypting the upgrade data with a preset encryption password to obtain encrypted upgrade data;
[0022] The signature module is used for: obtaining the digital digest of the upgrade data and signing the digital digest;
[0023] The packaging module is used for: packaging the encrypted upgrade data, the preset encryption password, and the signed digital digest to obtain secure upgrade data.
[0024] Based on the above solution, a protection system for upgrade data of the present invention can also be improved as follows.
[0025] Further, the first encryption module is specifically used for: symmetrically encrypting the upgrade data with a preset encryption password to obtain encrypted upgrade data.
[0026] Further, it further includes a second encryption module, and the second encryption module is used for: asymmetrically encrypting the preset encryption password to obtain a protected password.
[0027] Further, the packaging module is specifically used for:
[0028] Packaging the encrypted upgrade data, the protected password, and the signed digital digest to obtain secure upgrade data.
[0029] 3) In the third aspect, the present invention also provides an electronic device. The electronic device includes a processor, the processor is coupled with a memory, and at least one computer program is stored in the memory. The at least one computer program is loaded and executed by the processor so that the electronic device implements any one of the above protection methods for upgrade data.
[0030] 4) In the fourth aspect, the present invention also provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, it implements any one of the above protection methods for upgrade data.
[0031] It should be noted that for the beneficial effects obtained by the technical solutions and corresponding possible implementation manners of the second to fourth aspects of the present invention, reference can be made to the technical effects of the first aspect and its corresponding possible implementation manners above, which will not be elaborated here. Description of the Drawings
[0032] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the accompanying drawings required for the description of the embodiments of the present invention:
[0033] Figure 1 It is a schematic flowchart of a method for protecting upgraded data according to an embodiment of the present invention;
[0034] Figure 2 It is a schematic structural diagram of a system for protecting upgraded data according to an embodiment of the present invention;
[0035] Figure 3 It is a schematic structural diagram of an electronic device according to an embodiment of the present invention. Detailed implementation manners
[0036] The principles and features of the present invention are described below, and the examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0037] The following uses specific embodiments to elaborate in detail on the technical solutions of the present invention and how the technical solutions of the present invention solve the above technical problems. These several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present invention will be described below in conjunction with the accompanying drawings.
[0038] As Figure 1 shown, a method for protecting upgraded data according to an embodiment of the present invention includes the following steps:
[0039] S1. Use a preset encryption password to encrypt the upgraded data to obtain encrypted upgraded data;
[0040] Among them, the upgraded data is for the upgraded firmware, and the upgraded firmware can be a computer, a router, etc.
[0041] Among them, the preset encryption password can be set according to the actual situation, and the preset encryption algorithm can be a randomly generated password or a fixed password.
[0042] S2. Obtain the digital digest of the upgraded data and sign the digital digest.
[0043] Among them, the digital digest of the upgraded data can be obtained through the following method. Specifically:
[0044] 1) The first method for obtaining the digital digest:
[0045] ① According to the requirements of the hash function, preprocess the upgraded data, such as padding (padding the insufficient part with 0), grouping, etc., and group the preprocessed upgraded data according to the grouping length of the hash function (the grouping length can be 512 bits and can be set according to the actual situation);
[0046] ②Operate on the data in each group according to the corresponding operation sequence respectively. The operation sequence corresponding to each group includes: cyclic shift, AND, OR, NOT and other bitwise operations arranged in sequence. The sorting order of the bitwise operations in the operation sequence corresponding to each group can be set according to the actual situation.
[0047] ③In the order of grouping the preprocessed upgrade data, merge the operation results of each group, calculate the merged data using a hash function to obtain a hash calculation result, and use this hash calculation result as the digital digest of the upgrade data.
[0048] 2) The second way to obtain the digital digest:
[0049] ①Determine multiple key data segments from the upgrade data and randomly assign weights. Among them, the key data segment refers to: in the upgrade data, data that appears more than a preset number threshold. The preset number threshold can be set according to the actual situation. For example, the preset number threshold is 3 times or 5 times, etc.
[0050] ②Calculate the hash calculation result of each key data segment using a hash function, calculate the product of the hash calculation result of each key data segment and the corresponding weight, merge the products corresponding to each key data segment in the order in which each key data segment appears in the upgrade data, calculate the merged data using a hash function to obtain the final hash calculation result, and use this final hash calculation result as the digital digest of the upgrade data.
[0051] Currently, although the hash function is designed to minimize the possibility of collisions, in the case of a limited hash value space, it is still possible that different input data produce the same hash calculation result. In the present invention, multiple key data segments are isolated from the upgrade data, randomly assigned weights, the hash calculation result of each key data segment is calculated using a hash function, the product of the hash calculation result of each key data segment and the corresponding weight is calculated, the products corresponding to each key data segment are merged in the order in which each key data segment appears in the upgrade data, and the merged data is calculated using a hash function, which can effectively magnify the difference degree of the finally obtained digital digest, is more convenient for accurate verification, and improves the security of the upgrade data.
[0052] Optionally, in the above technical solution, the present invention proposes the following method to reduce the hash collision probability. Specifically:
[0053] 1) The first method:
[0054] Before performing calculations using a hash function, a string (salt value) is randomly generated and added to the data to be hashed (the data to be hashed can be upgrade data, merged data, etc.). In this way, even if the data to be hashed is the same, due to the different salt values, the final hash calculation results will be different. Ensure that each piece of data to be hashed uses a different salt value, which can greatly reduce the probability of collisions.
[0055] 2) The second method:
[0056] Use two hash functions. The first hash function determines the initial position, and the second hash function is used to calculate a new index position when a collision occurs. This method can reduce the collisions that may occur with a single hash function.
[0057] 3) The third method:
[0058] Divide the data to be hashed into multiple segments, and continue to perform hash operations on the hash calculation results of each segment, using the hash calculation result of the previous segment as the input for the next segment. This method can improve the collision resistance of the hash function.
[0059] 4) The fourth method:
[0060] Control the load factor of the hash table, that is, the ratio of the filled slots to the total slots in the hash table. By adjusting the load factor, the collision rate can be reduced while ensuring performance. When the filling degree of the hash table reaches a certain level, perform dynamic expansion to increase the number of slots in the hash table, thereby reducing the probability of collisions.
[0061] Optionally, in the above technical solution, it further includes: determining the hash function through a hash function selection strategy, and the hash function selection strategy is as follows:
[0062] ① Define the hash function as h(k) = k mod m (the hash function can specifically be other hash functions such as folding hash, mid-square hash, etc.), where k represents the input data, m should be selected as a prime number and not too close to powers of 2 or 10 to avoid conflicts caused by a certain distribution pattern of the low bits of the key values, and mod represents the calculation process between k and m.
[0063] ② Let m = 2 r , then define the hash function as: h(k) = k mod m = (A × k mod 2 w )>>(w - r), where A is an odd number within the range of (2 w-1 , 2 w ), and r and w are both intermediate variables.
[0064] The advantage of the multiplication hashing method is that the hash value is actually related to each bit of the k value, so it can distribute the hash calculation results more evenly.
[0065] ③Evaluate the performance of the hash function through experiments or simulations, including the distribution of hash values, the probability of collisions, etc. Different input data sets can be used to test the stability and uniformity of the hash function.
[0066] ④According to the evaluation results, adjust the parameters of the hash function (such as the value of m and the value of A, etc.) to optimize the performance of the hash function. Specifically:
[0067] a. Statistically analyze the distribution of hash values, check for obvious clustering or sparse regions, and calculate the collision rate of hash values, that is, the proportion of different inputs that produce the same hash value.
[0068] b. Perform lookup operations using a hash table, record the average time complexity of successful and failed lookups, and analyze the relationship between lookup efficiency and the distribution of hash values.
[0069] c. If the collision rate is high, it indicates that the hash function is uneven when mapping input data to the hash value space. Adjust the parameters of the hash function to reduce the collision rate and improve the lookup efficiency of the hash table. If the distribution of hash values is uneven, it may cause the hash table to be overcrowded in some areas and relatively sparse in other areas. Optimize the distribution of hash values by adjusting the parameters of the hash function to make it more uniform.
[0070] d. For specific hash functions, such as the divisor m in the division hashing method, the multiplier A, r, and w in the multiplication hashing method, etc., make fine-tuning according to the evaluation results. Test the impact of different parameter combinations on the performance of the hash function through experiments and simulations, and select the optimal parameter combination.
[0071] e. If the performance of the adjusted hash function still does not meet the expected goal, continue the iterative optimization process. Further adjust the parameters or design of the hash function according to the new evaluation results.
[0072] Among them, the process of signing the digital digest is as follows:
[0073] Encrypt the digital digest using the private key to generate a digital signature. Specifically, take the digital digest as input, and through the processing of the private key encryption algorithm, output an encrypted digital signature, and this encrypted digital signature is the signed digital digest.
[0074] S3. Package the encrypted upgrade data, the preset encryption password, and the signed digital digest to obtain the secure upgrade data.
[0075] Optionally, in S1, use the preset encryption password to encrypt the upgrade data to obtain the encrypted upgrade data, including: use the preset encryption password to perform symmetric encryption on the upgrade data to obtain the encrypted upgrade data.
[0076] Optionally, in the above technical solution, it further includes: asymmetrically encrypting a preset encryption password to obtain a protected password.
[0077] Optionally, packing the encrypted upgrade data, the preset encryption password, and the signed digital digest to obtain secure upgrade data, including: packing the encrypted upgrade data, the protected password, and the signed digital digest to obtain secure upgrade data.
[0078] Optionally, it further includes: setting an operation process for obtaining upgrade data from the secure upgrade data, and the operation process is: decrypting the protected password, verifying the signed digital digest, and decrypting the encrypted upgrade data. In each adjacent two steps of the operation process, if the previous step operation is not completed or fails, the next step operation is prohibited.
[0079] Optionally, in the above technical solution, it further includes: sending the secure upgrade data to a receiving end, and the receiving end processes the secure upgrade data according to the operation process to obtain upgrade data. Specifically:
[0080] S101. The receiving end uses the public key and private key used for asymmetrically encrypting the preset encryption password to decrypt the protected password to obtain the preset encryption password, and then executes S102; when the decryption fails, the receiving end is prohibited from executing S102;
[0081] Among them, the receiving end can specifically be a controller of a device, and can specifically be a computer or the like.
[0082] S102. The receiving end verifies the signed digital digest. Specifically:
[0083] The receiving end uses the public key decryption algorithm corresponding to the private key encryption algorithm to decrypt the signed digital digest to obtain the digital digest, and compares the decrypted digital digest with the previously received digital digest (sending the digital digest of the upgrade data to the receiving end through other communication links, and other communication links refer to: communication links other than the communication link for sending the secure upgrade data). If they are consistent, it means that the secure upgrade data has not been tampered with during the transmission process, and S102 is continued to be executed. If they are inconsistent, the secure upgrade data may have been tampered with. When the decryption of the signed digital digest fails, or when the secure upgrade data may have been tampered with, the receiving end is prohibited from executing S103.
[0084] S103. Using the decryption key used for symmetrically encrypting the upgrade data to decrypt the encrypted upgrade data to obtain the upgrade data, and then the receiving end uses the decrypted upgrade data to upgrade the corresponding upgrade firmware (such as a computer or a router, etc.).
[0085] Optionally, in the above technical solution, before the receiving end uses the upgraded data obtained by decryption to upgrade the corresponding upgraded firmware (such as a computer or a router, etc.), it further includes: verifying whether the upgraded data obtained by decryption is complete. Specifically:
[0086] Determine multiple key data segments from the upgraded data obtained by decryption, calculate the hash calculation results of each key data segment obtained from the upgraded data obtained by decryption using a hash function, and perform a consistency comparison with the hash calculation results of each key data segment received (previously sending the "hash calculation results of each key data segment obtained by calculating using the hash function" to the receiving end). If they are consistent, it is determined that the upgraded data obtained by decryption is complete; if they are inconsistent, it is determined that the upgraded data obtained by decryption is incomplete. This verification process is implemented based on the specific data in the upgraded data and is more accurate than the existing verification method based on CRC check values. Because the data packet corresponding to the CRC check value may be tampered with, but as long as the CRC check value remains unchanged, it cannot be detected that it has been tampered with. Moreover, by comparing the hash calculation results, it can also effectively prevent data leakage and further ensure data security.
[0087] In the above embodiments, although the steps are numbered S1, S2, etc., these are only specific embodiments given by the present invention. Those skilled in the art can adjust the execution order of S1, S2, etc. according to the actual situation, and this is also within the protection scope of the present invention. It can be understood that in some embodiments, it may include some or all of the above embodiments.
[0088] As Figure 2 shown, a protection system 200 for upgraded data according to an embodiment of the present invention includes: a first encryption module 201, a signature module 202, and a packaging module 203;
[0089] The first encryption module 201 is configured to: encrypt the upgraded data using a preset encryption password to obtain encrypted upgraded data;
[0090] The signature module 202 is configured to: obtain the digital digest of the upgraded data and sign the digital digest;
[0091] The packaging module 203 is configured to: package the encrypted upgraded data, the preset encryption password, and the signed digital digest to obtain secure upgraded data.
[0092] Optionally, in the above technical solution, the first encryption module 201 is specifically configured to: perform symmetric encryption on the upgraded data using a preset encryption password to obtain encrypted upgraded data.
[0093] Optionally, in the above technical solution, it further includes a second encryption module, and the second encryption module is configured to: perform asymmetric encryption on the preset encryption password to obtain a protected password.
[0094] Optionally, in the above technical solution, the packaging module 202 is specifically configured to:
[0095] Package the encrypted upgrade data, the protection password, and the signed digital digest to obtain secure upgrade data.
[0096] It should be noted that the beneficial effects of the protection system 200 for upgrade data provided in the above embodiments are the same as those of the protection method for upgrade data described above, and will not be elaborated here. In addition, when the system provided in the above embodiments implements its functions, only the division of the above function modules is used as an example for illustration. In practical applications, the above functions can be allocated to different function modules according to needs, that is, the system can be divided into different function modules according to the actual situation to complete all or part of the functions described above. In addition, the system provided in the above embodiments and the method embodiments belong to the same concept, and the specific implementation process can be seen in the method embodiments, which will not be elaborated here.
[0097] Among them, the protection system for upgrade data of the present invention can be a computer program (including program code) running in a computer device. For example, the protection system for upgrade data of the present invention is an application software, which can be used to execute the corresponding steps in the protection method for upgrade data of the present invention.
[0098] In some embodiments, the protection system for upgrade data of the present invention can be implemented in a combination of software and hardware. As an example, the protection system for upgrade data of the present invention can be a processor in the form of a hardware decoding processor, which is programmed to execute the protection method for upgrade data of the present invention. For example, the processor in the form of a hardware decoding processor can adopt one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), or other electronic components.
[0099] Among them, the modules described in the embodiments of the present invention can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the module itself in some cases.
[0100] An electronic device according to an embodiment of the present invention includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the protection method for upgrade data described in any of the above is implemented. That is to say, an electronic device according to an embodiment of the present invention may include, but is not limited to: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the protection method for upgrade data shown in any embodiment of the present invention by calling the computer program.
[0101] In an alternative embodiment, an electronic device is provided, as Figure 3 shown Figure 3 The electronic device 4000 shown includes: a processor 4001 and a memory 4003. Among them, the processor 4001 and the memory 4003 are connected, such as connected through a bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, and the transceiver 4004 may be used for data interaction between this electronic device and other electronic devices, such as data sending and / or data receiving, etc. It should be noted that in actual applications, the transceiver 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation to the embodiments of the present invention.
[0102] The processor 4001 may be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application-specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in connection with the disclosure of the present invention. The processor 4001 may also be a combination that implements a computing function, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0103] The bus 4002 may include a path for transmitting information between the above components. The bus 4002 may be a PCI (Peripheral Component Interconnect, peripheral component interconnect standard) bus or an EISA (Extended Industry Standard Architecture, extended industry standard structure) bus, etc. The bus 4002 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 3Only a thick line is used to represent bus 4002 in the figure, but it does not mean that there is only one bus or one type of bus.
[0104] The memory 4003 can be a ROM (Read Only Memory), or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory), or other types of dynamic storage devices that can store information and instructions. It can also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0105] The memory 4003 is used to store the application program code (computer program) for implementing the solution of the present invention, and is controlled by the processor 4001 for execution. The processor 4001 is used to execute the application program code stored in the memory 4003 to implement the content shown in the foregoing method embodiments.
[0106] Among them, the electronic device can also be a terminal device, and the terminal device can be any device that can install applications, including at least one of a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, a smart TV, and a smart vehicle device.
[0107] It should be noted that Figure 3 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention.
[0108] A computer-readable storage medium according to an embodiment of the present invention has a computer program stored thereon, and when the computer program is executed by a processor, it implements any one of the above-mentioned protection methods for upgrade data.
[0109] Optionally, the computer-readable storage medium can be a Read-Only Memory (ROM), a Random Access Memory (RAM), a Compact Disc Read-Only Memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.
[0110] In an exemplary embodiment, a computer program product or a computer program is further provided. The computer program product or the computer program includes computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions to cause the electronic device to perform the protection of the upgrade data as described in any one of the above.
[0111] Computer program code for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0112] It should be understood that the flowcharts and block diagrams in the drawings illustrate the possible architectures, functions, and operations of methods and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0113] The computer-readable storage medium provided by the embodiments of the present invention may be, but is not limited to, a system, device, or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EEPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or component.
[0114] The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to execute the method shown in the above embodiments.
[0115] The above description is only the preferred embodiments of the present invention and the description of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present invention is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present invention.
[0116] It should be noted that the terms "first", "second", etc. in the description and claims of this application are used to distinguish similar objects, and represent a limitation on a specific order or sequence. Under appropriate circumstances, the use order of similar objects can be interchanged so that the embodiments of this application described here can be implemented in an order other than the order shown or described.
[0117] Those skilled in the art know that the present invention can be implemented as a system, method, or computer program product. Therefore, the present invention can be specifically implemented in the following forms, that is: it can be completely hardware, can also be completely software (including firmware, resident software, microcode, etc.), and can also be in the form of a combination of hardware and software, which is generally referred to as "circuit", "module", or "system" in this article. In addition, in some embodiments, the present invention can also be implemented in the form of a computer program product in one or more computer-readable media, and the computer-readable media contains computer-readable program code.
[0118] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A method for protecting upgrade data, characterized in that: include: Using a preset encryption password, encrypt the upgrade data to obtain encrypted upgrade data; Obtaining a digital summary of the upgrade data, and signing the digital summary; The encrypted upgrade data, the preset encryption password and the signed digital summary are packaged to obtain security upgrade data.
2. The method for protecting upgrade data according to claim 1, characterized in that: The upgrade data is encrypted using the preset encryption password to obtain the encrypted upgrade data, including: The upgrade data is symmetrically encrypted using the preset encryption password to obtain the encrypted upgrade data.
3. The method for protecting upgrade data according to claim 2, characterized in that: Also includes: The preset encryption password is asymmetrically encrypted to obtain a protection password.
4. The method for protecting upgrade data according to claim 3, characterized in that: The encrypted upgrade data, the preset encryption password and the signed digital summary are packaged to obtain security upgrade data, including: The encrypted upgrade data, the protection password and the signed digital summary are packaged to obtain the security upgrade data.
5. A system for protecting upgraded data, characterized in that: include: A first encryption module, a signature module and a packaging module; The first encryption module is used to: encrypt the upgrade data using a preset encryption password to obtain encrypted upgrade data; The signature module is used to: obtain the digital summary of the upgrade data and sign the digital summary; The packaging module is used to package the encrypted upgrade data, the preset encryption password and the signed digital summary to obtain security upgrade data.
6. The upgrade data protection system according to claim 5, characterized in that: The first encryption module is specifically used to: use the preset encryption password to symmetrically encrypt the upgrade data to obtain the encrypted upgrade data.
7. The upgrade data protection system according to claim 6, characterized in that: It also includes a second encryption module, which is used to: perform asymmetrical encryption on the preset encryption password to obtain a protection password.
8. The upgrade data protection system according to claim 7, characterized in that: The packaging module is specifically used for: The encrypted upgrade data, the protection password and the signed digital summary are packaged to obtain the security upgrade data.
9. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, an upgrade data protection method as claimed in any one of claims 1 to 4 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for protecting upgrade data according to any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Secure upgrading method, secure upgrading apparatus, upgrading server, upgrading device and medium
CN108566381A
Vehicle software upgrading method and device and storage medium
CN115022092A
Automobile OTA upgrading system and method
CN115665138A
Software upgrading method and device, equipment and storage medium
CN117375858A