Method and system for preventing device information from being tampered and identifying device information from being tampered
The method and system secure device information in smart home systems by generating and storing verification codes and server information to prevent unauthorized modifications, ensuring device integrity and security.
Patent Information
- Application Number
- CN202311869849.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-08
AI Technical Summary
The challenge of protecting device information security in smart home systems from unauthorized modifications is prevalent, posing risks to safety and privacy.
A method and system that involves uploading device information to a server, generating a verification code based on device and server information, writing this code to a first storage memory, and writing part of the server information to a second storage memory, using hash and encryption processes to secure the device against tampering.
Enhances device security by enabling tamper-proofing, allowing for the detection and prevention of unauthorized modifications, thereby safeguarding device information integrity.
Smart Images

Figure CN120277652A_ABST
Abstract
Description
Technical Field
[0001] The present invention generally relates to the field of information security, and in particular, to a method for preventing device information from being tampered with, a system for preventing device information from being tampered with, a method for identifying that device information has been tampered with, and a system for identifying that device information has been tampered with. Background Art
[0002] With the continuous progress of technology, smart home systems are becoming increasingly popular among people. Smart homes can provide convenience and comfort for people's daily lives. However, the security issues of smart homes are also becoming increasingly prominent, bringing some security and privacy risks.
[0003] How to protect the security of device information and prevent device information from being tampered with is a challenge faced by smart home devices.
[0004] The content in the background art section is only the technology known to the inventor and does not of course represent the prior art in this field. Summary of the Invention
[0005] In view of one or more of the problems existing in the prior art, the present invention provides a method for preventing device information from being tampered with, which can protect the security of device information and prevent device information from being tampered with. The method includes:
[0006] Obtaining the device information of the device;
[0007] Uploading the device information to a server;
[0008] Receiving a verification code from the server, where the verification code is determined based on the device information and server information;
[0009] Writing the verification code into a first memory of the device; and
[0010] Writing at least part of the server information into a second memory of the device.
[0011] According to one aspect of the present disclosure, it further includes: enabling the anti-tampering function of the device by setting the logical state of the second memory.
[0012] According to one aspect of the present disclosure, the verification code is determined by the following method:
[0013] Hashing the device information and the server information to obtain a first hash value;
[0014] Performing salt hashing on the first hash value to obtain a second hash value; and
[0015] Encrypting the second hash value to obtain the verification code.
[0016] According to one aspect of the present disclosure, the first memory includes a multi-programmable memory; the second memory includes a one-time programmable memory.
[0017] According to one aspect of the present disclosure, the device information includes one or more of: device serial number, Mac address, device hardware ID, current version number of the Bootloader program, current version number of the Kernel program, and public key; the server information includes one or more of: server ID, minimum version number of the Bootloader program, minimum version number of the Kernel program, and private key; at least part of the server information includes the minimum version number of the Bootloader program and the minimum version number of the Kernel program; the public key and the private key are generated by the server.
[0018] The present disclosure also provides a system for preventing tampering of device information, including:
[0019] A device, including a first memory and a second memory;
[0020] A reader-writer, communicating with the device; and
[0021] A server, communicating with the reader-writer;
[0022] Wherein, the reader-writer is configured to:
[0023] Obtain the device information of the device;
[0024] Upload the device information to the server;
[0025] Receive a verification code from the server;
[0026] Write the verification code into the first memory; and
[0027] Write at least part of the server information into the second memory;
[0028] Wherein, the server is configured to:
[0029] Determine the verification code based on the device information and the server information.
[0030] According to one aspect of the present disclosure, the server is configured to: enable the anti-tampering function of the device by setting the logical state of the second memory.
[0031] According to one aspect of the present disclosure, the server is configured to:
[0032] Hash the device information and the server information to obtain a first hash value;
[0033] Salt-hash the first hash value to obtain a second hash value; and
[0034] Encrypt the second hash value to obtain the check code.
[0035] According to one aspect of the present disclosure, the first memory includes a multi-programmable memory; the second memory includes a one-time programmable memory.
[0036] According to one aspect of the present disclosure, the device information includes one or more of: device serial number, Mac address, device hardware ID, current version number of the Bootloader program, current version number of the Kernel program, and public key; the server information includes one or more of: server ID, minimum version number of the Bootloader program, minimum version number of the Kernel program, and private key; wherein at least part of the server information includes the minimum version number of the Bootloader program and the minimum version number of the Kernel program; wherein the public key and the private key are generated by the server.
[0037] The present disclosure also provides a method for identifying tampering of device information, including:[[]]
[0038] In the Bootloader stage:
[0039] Enable the anti-tampering function of the device;
[0040] Obtain the device information and server information of the device;
[0041] Based on the device information and the server information, determine a first actual hash value;
[0042] Determine whether the first actual hash value matches a first expected hash value to obtain a first matching result; and
[0043] Based on the first matching result, send the server information and the device information, or the server information and the processed device information to the kernel program;
[0044] In the kernel stage:
[0045] Based on the server information and the device information, or based on the server information and the processed device information, determine a second actual hash value;
[0046] Determine whether the second actual hash value matches a second expected hash value to obtain a second matching result; and
[0047] Based on the second matching result, determine whether the device information has been tampered with.
[0048] According to one aspect of the present disclosure, the step of determining whether the device information is tampered with based on the second matching result includes:
[0049] If the second actual hash value matches the second expected hash value, it is determined that the device information has not been tampered with;
[0050] If the second actual hash value does not match the second expected hash value, it is determined that the device information has been tampered with.
[0051] According to one aspect of the present disclosure, the first expected hash value or the second expected hash value is obtained by decrypting a check code stored in a first memory of the device; wherein the first memory includes a multi-programmable memory; wherein the check code is determined by the following method:
[0052] Hash the device information and the server information to obtain a first hash value;
[0053] Perform salt hashing on the first hash value to obtain a second hash value; and
[0054] Encrypt the second hash value to obtain the check code.
[0055] According to one aspect of the present disclosure, the device information includes one or more of a device serial number, a Mac address, a device hardware ID, the lowest version number of a Bootloader program, the lowest version number of a Kernel program, and a public key; wherein the lowest version number of the Bootloader program and the lowest version number of the kernel program are stored in a second memory of the device; wherein the second memory includes a one-time programmable memory; wherein the server information includes one or more of a server ID and a private key; the public key and the private key are generated by the server.
[0056] According to one aspect of the present disclosure, it further includes: in the Bootloader stage, determining whether the current version number of the Bootloader program is the lowest version number; in the kernel stage, determining whether the current version number of the kernel program is the lowest version number.
[0057] According to one aspect of the present disclosure, the step of enabling the anti-tampering function of the device includes: enabling the anti-tampering function of the device by setting the logical state of the second memory.
[0058] According to one aspect of the present disclosure, it further includes: when it is determined that the device information has been tampered with, an alarm is issued.
[0059] The present disclosure also provides a system for identifying tampering of device information, including:
[0060] a device; and
[0061] a server communicating with the device;
[0062] wherein the device is configured to send a request instruction to the server;
[0063] the server is configured to respond to the request instruction and execute the method as described above.
[0064] The present disclosure also provides a computer-readable storage medium including computer-executable instructions stored thereon, and the executable instructions, when executed by a processor, implement the method as described above, and / or implement the method as described above.
[0065] By writing a check code into the first memory of the device and writing at least part of the server information into the second memory of the device, the present disclosure can achieve an anti-tampering function, which is beneficial to protecting the security of device information. Based on the second matching result of whether the second actual hash value matches the second expected hash value, the present disclosure can identify whether the device information has been tampered with. In the case where it is identified that the device information has been tampered with, corresponding measures can be taken to timely maintain the security of device information. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention, and do not constitute a limitation to the present invention. In the drawings:
[0067] Figure 1 shows a flowchart of a method for preventing tampering of device information according to some embodiments of the present disclosure;
[0068] Figure 2 shows a schematic diagram of a device according to some embodiments of the present disclosure;
[0069] Figure 3 shows a schematic diagram of a system for preventing tampering of device information according to some embodiments of the present disclosure;
[0070] Figure 4 shows a flowchart of a method for identifying tampering of device information according to some embodiments of the present disclosure;
[0071] Figure 5 shows a schematic diagram of a system for identifying tampering of device information according to some embodiments of the present disclosure; and
[0072] Figure 6 shows a flowchart of a method for identifying tampering of device information according to some preferred embodiments of the present disclosure.
[0073] Reference numerals:
[0074] 10, 40, 60: Method
[0075] 20: Device
[0076] 30: System
[0077] 50: System
[0078] 201: First memory
[0079] 202: Second memory
[0080] 31: Reader
[0081] 32: Server
[0082] S1 - S5, S41 - S48, S411 - S412, S491 - S493, S4922: Steps
[0083] S451 - S452, S461 - S462, S481 - S482: Sub - steps Detailed implementation manners
[0084] In the following text, only some exemplary embodiments are simply described. As those skilled in the art can recognize, the described embodiments can be modified in various different ways without departing from the spirit or scope of the present invention. Therefore, the accompanying drawings and the description are considered to be exemplary in nature rather than restrictive.
[0085] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by terms such as "center", "longitudinal", "lateral", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", "counterclockwise", etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation to the present invention. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of the said features. In the description of the present invention, the meaning of "a plurality" is two or more, unless otherwise specifically defined.
[0086] In the description of the present invention, it should be noted that, unless otherwise clearly specified and defined, the terms "installation", "connection", and "coupling" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection: it may be a mechanical connection, an electrical connection, or a connection that allows mutual communication; it may be a direct connection, or an indirect connection through an intermediate medium, and it may be the internal connection of two components or the interaction relationship between two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0087] In the present invention, unless otherwise clearly specified and defined, the first feature being "on" or "under" the second feature may include the direct contact between the first and second features, or may include the situation where the first and second features are not in direct contact but in contact through other features therebetween. Moreover, the first feature being "above", "over" and "on top of" the second feature includes that the first feature is directly above and obliquely above the second feature, or simply means that the horizontal height of the first feature is higher than that of the second feature. The first feature being "under", "below" and "beneath" the second feature includes that the first feature is directly below and obliquely below the second feature, or simply means that the horizontal height of the first feature is lower than that of the second feature.
[0088] The following disclosure provides many different embodiments or examples for implementing different structures of the present invention. To simplify the disclosure of the present invention, the components and settings of specific examples are described below. Of course, they are only examples and are not intended to limit the present invention. In addition, the present invention may repeat reference numerals and / or reference letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed. In addition, the present invention provides examples of various specific processes and materials, but those of ordinary skill in the art may be aware of the application of other processes and / or the use of other materials.
[0089] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present invention, and are not used to limit the present invention.
[0090] The present disclosure provides a method for preventing device information from being tampered with. Figure 1 The flowchart of a method 10 for preventing device information from being tampered with according to some embodiments of the present disclosure is shown as Figure 1As shown, the method 10 includes steps S1 - S5. In step S1, device information of a device is obtained; in step S2, the device information is uploaded to a server; in step S3, an authentication code is received from the server, where the authentication code is determined based on the device information and server information; in step S4, the authentication code is written into a first memory of the device; in step S5, at least part of the server information is written into a second memory of the device. Details are introduced below.
[0091] Figure 2 FIG. shows a schematic diagram of a device 20 according to some embodiments of the present disclosure, as Figure 2 shown, the device 20 includes a first memory 201 and a second memory 202. The first memory 201 includes a multiple - time - programmable memory (MTP), such as a flash memory, an erasable programmable read - only memory (EPROM), an electrically erasable programmable read - only memory (EEPROM), etc. The second memory 202 includes a one - time - programmable memory (OTP), such as an electric - fuse (eFuse), an anti - fuse, etc.
[0092] Figure 3 FIG. shows a schematic diagram of a system 30 for preventing tampering of device information according to some embodiments of the present disclosure, as Figure 3 shown, the system 30 includes a device 20, a reader - writer 31, and a server 32, where the reader - writer 31 communicates with the device 20 and the server 32 respectively.
[0093] In some embodiments, the device 20 includes, but is not limited to, a smart phone, a tablet, a computer, a wearable device, a smart door, a smart door lock, a smart doorbell, a smart door eye, a smart switch, a smart knob, a smart drying rack, an electric curtain, a Bluetooth wireless switch, a smart care light, a central air - conditioner controller, a human body sensor, a floor - cleaning robot, a temperature - humidity sensor, a door - window sensor, an air purifier, a smart watch, a smart camera, a smart water purifier, a smart magnetic - adsorption spot - light, a smart magnetic - adsorption flood - light, a smart magnetic - adsorption grille - light, a smart ceiling - light, a smart light strip.
[0094] In some embodiments, the reader / writer 31 (Interface Device) can be a wired interface, such as a USB interface, a Universal Asynchronous Receiver / Transmitter (UART), an RS-232 interface, an RS-485 interface, an RS-422 interface, a Serial Peripheral Interface (SPI), an IIC (Inter-Integrated Circuit) interface, etc. In some embodiments, the reader / writer 31 can also be a wireless interface, such as Bluetooth, WiFi, ZigBee, NFC, etc. In some embodiments, the reader / writer 31 can further be a cloud interface. In some embodiments, the reader / writer 31 can be a factory-side tool.
[0095] In some embodiments, the server 32 can be a cloud server or a local server, and can be a general server or a dedicated server, depending on the actual situation.
[0096] In some embodiments, steps S1 - S2 of method 10 can be executed by the reader / writer 31. In step S1, the reader / writer 31 reads the device information of device 20. In step S2, the reader / writer 31 uploads the device information to the server 32. In some embodiments, the device information includes one or more of: Serial Number (SN), Mac address (Medium / Media Access Control), device hardware ID, the current version number of the Bootloader program, the current version number of the Kernel program, and Public Key.
[0097] In some embodiments, between step S2 and step S3, there is also step S3’ (not shown in the figure), which determines a check code based on the device information and the server information, and this step can be executed by the server 32. Specifically, after receiving the device information uploaded by the reader / writer 31, the server 32 can determine the check code based on the device information and the server information. In some embodiments, the server information includes one or more of: server ID, the lowest version number of the Bootloader program, the lowest version number of the Kernel program, and Private Key.
[0098] In some embodiments, the verification code can be determined in the following manner: First, the server 32 performs hashing (HASH) on the device information and the server information to obtain a first hash value H1; thereafter, the server 32 performs salted hashing (HASH+SALT) on the first hash value to obtain a second hash value H2; finally, the server 32 can encrypt the second hash value H2, for example, by encrypting the second hash value H2 with a private key, to obtain the verification code. By determining the verification code in this way, the difficulty of cracking the verification code can be increased, the difficulty of device tampering can be increased, and the data security of the device can be improved.
[0099] In some embodiments, the public key and the private key can be generated by the server 32.
[0100] In some embodiments, step S3' further includes: the server 32 sending the verification code to the reader-writer 31; and sending at least part of the server information to the reader-writer 31.
[0101] In some embodiments, steps S3-S5 can be executed by the reader-writer 31. In step S3, the reader-writer 31 receives the verification code from the server 32; and receives at least part of the server information from the server 32. In step S4, the reader-writer 31 writes the verification code into the first memory 201 of the device 20. In step S5, the reader-writer 31 writes at least part of the server information into the second memory 202 of the device 20.
[0102] In some embodiments, the at least part of the server information includes the lowest version number of the Bootloader program and the lowest version number of the Kernel program. In step S3, the reader-writer 31 receives the lowest version number of the Bootloader program and the lowest version number of the Kernel program from the server 32. In step S5, the reader-writer 31 writes the lowest version number of the Bootloader program and the lowest version number of the Kernel program into the second memory 202 of the device 20. It should be noted that the lowest version number of the Bootloader program and the lowest version number of the Kernel program refer to: the preset lowest version numbers that support the anti-tampering function. Writing the lowest version number of the Bootloader program and the lowest version number of the Kernel program into the second memory 202 of the device 20 can prevent the version rollback of the Bootloader program and the Kernel program and prevent the device from being tampered with.
[0103] In some embodiments, after the reader-writer 31 uploads the device information to the server 32, the server 32 can determine whether the current version number of the Bootloader program is the lowest version number and determine whether the current version number of the kernel program is the lowest version number.
[0104] If the server 32 determines that the current version number of the Bootloader program is not the lowest version number, the server 32 may send the lowest version number of the Bootloader program to the reader / writer 31. After receiving the lowest version number of the Bootloader program, the reader / writer 31 may write the lowest version number of the Bootloader program into the second memory 202 of the device 20. On the contrary, if the server 32 determines that the current version number of the Bootloader program is already the lowest version number, it means that the lowest version number of the Bootloader program has been written into the second memory 202. In this case, the server 32 does not have to send the lowest version number of the Bootloader program to the reader / writer 31, and the reader / writer 31 does not have to write the lowest version number of the Bootloader program into the second memory 202 of the device 20 either.
[0105] Similarly, if the server 32 determines that the current version number of the kernel program is not the lowest version number, the server 32 may send the lowest version number of the kernel program to the reader / writer 31. After receiving the lowest version number of the kernel program, the reader / writer 31 may write the lowest version number of the kernel program into the second memory 202 of the device 20. On the contrary, if it is determined that the current version number of the kernel program is already the lowest version number, it means that the lowest version number of the kernel program has been written into the second memory 202. In this case, the server 32 does not have to send the lowest version number of the kernel program to the reader / writer 31, and the reader / writer 31 does not have to write the lowest version number of the kernel program into the second memory 202 of the device 20 either.
[0106] In some other embodiments, after the reader / writer 31 uploads the device information to the server 32, the server 32 may send the lowest version number of the Bootloader program and the lowest version number of the kernel program to the reader / writer 31. After the reader / writer 31 receives the lowest version number of the Bootloader program and the lowest version number of the kernel program from the server 32, the reader / writer 31 may determine whether the current version number of the Bootloader program read from the device 20 is the lowest version number, and determine whether the current version number of the kernel program is the lowest version number. If the reader / writer 31 determines that the current version number of the Bootloader program is not the lowest version number, the reader / writer 31 may write the lowest version number of the Bootloader program into the second memory 202 of the device 20. Conversely, if the reader / writer 31 determines that the current version number of the Bootloader program is already the lowest version number, the reader / writer 31 may not need to write the lowest version number of the Bootloader program into the second memory 202 of the device 20. The version number processing logic of the reader / writer 31 for the kernel program is similar, which will not be elaborated here.
[0107] After the check code is written into the first memory 201 of the device 20, and the lowest version numbers of the Bootloader program and the kernel program are written into the second memory 202 of the device 20, the device 20 has an anti-tampering function. In some embodiments, the anti-tampering function of the device 20 can be enabled by setting the logical state of the second memory 202. For example, when the second memory 202 is set to "1", the anti-tampering function of the device 20 is enabled; when the second memory 202 is set to "0", the anti-tampering function of the device 20 is not enabled; or when the second memory 202 is set to "0", the anti-tampering function of the device 20 is enabled; when the second memory 202 is set to "1", the anti-tampering function of the device 20 is not enabled.
[0108] The above has introduced in detail the method 10 for anti-tampering of device information of the present disclosure, and the method 10 is applicable to scenarios such as before the device leaves the factory.
[0109] The present disclosure also relates to a system for anti-tampering of device information. Figure 3 The schematic diagram of a system 30 for anti-tampering of device information according to some embodiments of the present disclosure is shown, as Figure 3 shown, the system 30 includes a device 20, a reader / writer 31, and a server 32, wherein the device 20 includes a first memory 201 and a second memory 202; the reader / writer 31 communicates with the device 20; the server 32 communicates with the reader / writer 31.
[0110] In some embodiments, the reader 31 is configured to perform the following operations: obtain the device information of the device 20; upload the device information to the server 32; receive a verification code from the server 32; write the verification code into the first memory 201; and write at least part of the server information into the second memory 202. In other words, the reader 21 is configured to perform the foregoing steps S1-S5.
[0111] In some embodiments, the server 32 is configured to: determine a verification code based on the device information and the server information. In other words, the server 32 is configured to perform the foregoing step S3'.
[0112] In some embodiments, the server 32 is configured to: perform a hash (HASH) on the device information and the server information to obtain a first hash value H1; perform a salted hash (HASH+SALT) on the first hash value to obtain a second hash value H2; and encrypt the second hash value H2 to obtain the verification code.
[0113] In some embodiments, the first memory 201 includes a multiple-time-programmable (MTP) memory; the second memory 202 includes a one-time-programmable (OTP) memory.
[0114] In some embodiments, the server 32 is configured to: enable the anti-tampering function of the device 20 by setting the logical state of the second memory 202.
[0115] In some embodiments, the device information includes one or more of: a device serial number (SN), a Mac address, a device hardware ID, the current version number of the Bootloader program, the current version number of the Kernel program, and a public key.
[0116] In some embodiments, the server information includes one or more of: a server ID, the minimum version number of the Bootloader program, the minimum version number of the Kernel program, and a private key; wherein at least part of the server information includes the minimum version number of the Bootloader program and the minimum version number of the Kernel program.
[0117] In some embodiments, the public key and the private key can be generated by the server 32.
[0118] In some embodiments, before the device 20 leaves the factory, the above method 10 can be executed through the above system 30 to enable the device 20 to have an anti-tampering function. In other words, the reader 31 can be a factory-side tool.
[0119] The present disclosure also provides a method for identifying tampering of device information and a system for identifying tampering of device information. Figure 4 FIG. 40 is a flowchart showing a method for identifying tampering of device information according to some embodiments of the present disclosure. Figure 5 FIG. 50 is a schematic diagram showing a system for identifying tampering of device information according to some embodiments of the present disclosure. As Figure 4 and Figure 5 shown, the system 50 includes a device 20 and a server 32. The device 20 can communicate with the server 32. The device 20 is configured to send a request instruction to the server 32, and the server 32 is configured to respond to the request instruction and execute the method 40. The following is a detailed introduction.
[0120] In some embodiments, the communication between the device 20 and the server 32 can be implemented by a wired method or a wireless method.
[0121] The method 40 includes steps S41-S48, which are roughly divided into two stages, namely the Bootloader stage and the kernel stage. In the Bootloader stage: In step S41, enable the anti-tampering function of the device; in step S42, obtain the device information and the server information of the device; in step S43, determine a first actual hash value based on the device information and the server information; in step S44, determine whether the first actual hash value matches a first expected hash value to obtain a first matching result; in step S45, based on the first matching result, send the server information and the device information, or the server information and the processed device information to the kernel program. In the kernel stage: In step S46, determine a second actual hash value based on the server information and the device information, or based on the server information and the processed device information; in step S47, determine whether the second actual hash value matches a second expected hash value to obtain a second matching result; in step S48, based on the second matching result, determine whether the device information has been tampered with.
[0122] In some embodiments, the step of enabling the anti-tampering function of the device 20 (step S41) includes: enabling the anti-tampering function of the device 20 by setting the logical state of the second memory 202. The second memory 202 includes a one-time programmable memory. For example, the device 20 can send a request instruction to the server 32, and the server 32 responds to the request instruction sent by the device 20 and sets the logical state (such as "1" or "0") of the second memory 202 to enable the anti-tampering function of the device 20.
[0123] In some embodiments, in step S42, the server 32 may communicate with the device 20. The server 32 sends a request instruction to the device 20, and the device 20 responds to the request instruction sent by the server 32 and sends device information to the server 32. The device information includes one or more of a device serial number (SN), a Mac address, a device hardware ID, the minimum version number of the Bootloader program, the minimum version number of the Kernel program, and a public key; wherein the minimum version number of the Bootloader program and the minimum version number of the kernel program are stored in the second memory 202 of the device 20. The server information includes one or more of a server ID and a private key. The public key and the private key may be generated by the server 32.
[0124] In some embodiments, in step S43, the server 32 may determine a first actual hash value based on the device information and the server information. Specifically, the server 32 may hash the device information and the server information to obtain a first hash value; perform salt hashing on the first hash value to obtain a second hash value, and this second hash value is the first actual hash value. It should be noted that the first actual hash value is re-determined based on the device information and the server information.
[0125] In some embodiments, in step S44, it is determined whether the first actual hash value matches the first expected hash value to obtain a first matching result. The first expected hash value may be obtained by decrypting the check code stored in the first memory 201 of the device 20, for example, decrypting the check code with the private key. The first memory 201 includes a multi-programmable memory. The first matching result includes: the first actual hash value matches the first expected hash value; the first actual hash value does not match the first expected hash value. It should be understood that the determination method of the check code is similar to the foregoing. Hash the device information and the server information to obtain a first hash value; perform salt hashing on the first hash value to obtain a second hash value; encrypt the second hash value to obtain the check code.
[0126] In some embodiments, step S45 includes sub-step S451 and sub-step S452. Specifically, if the first actual hash value matches the first expected hash value, then sub-step S451 is executed to send the server information and the device information to the kernel program (refer to Figure 6 ), for example, send the server ID and the device serial number (SN) to the kernel program; if the first actual hash value does not match the first expected hash value, then sub-step S452 is executed to send the server information and the processed device information to the kernel program (refer to Figure 6 ), for example, send the server ID and the device serial number (SN) with a preset suffix name (and / or prefix name) to the kernel program.
[0127] In some embodiments, at step S46, in the kernel stage, a second actual hash value is determined based on the data sent in the Bootloader stage. In some embodiments, step S46 includes sub-step S461 and sub-step S462. Specifically, if the data sent to the kernel program in step S45 is server information and device information, then sub-step S461 is executed, and based on the server information and the device information, the second actual hash value is determined (refer to Figure 6 ). Correspondingly, if the data sent to the kernel program in step S45 is server information and processed device information, then sub-step S462 is executed, and based on the server information and the processed device information, the second actual hash value is determined (refer to Figure 6 ). It can be understood that the process of determining the second actual hash value is similar to the method of determining the foregoing first actual hash value, and will not be elaborated here.
[0128] In some embodiments, at step S47, it is determined whether the second actual hash value matches the second expected hash value, and a second matching result is obtained. Among them, the second expected hash value is obtained by decrypting the check code stored in the first memory 201 of the device 20, for example, by decrypting the check code with a private key. The second matching result includes: the second actual hash value matches the second expected hash value; the second actual hash value does not match the second expected hash value. It should be noted that the second expected hash value and the first expected hash value are obtained by decrypting the check code with the same private key.
[0129] In some embodiments, the step of determining whether the device information has been tampered with based on the second matching result (step S48) includes sub-steps S481 and S482 (refer to Figure 6 ). If the second actual hash value matches the second expected hash value, then sub-step S481 is executed to determine that the device information has not been tampered with; conversely, if the second actual hash value does not match the second expected hash value, then sub-step S482 is executed to determine that the device information has been tampered with.
[0130] In some embodiments, the method 40 further includes: in the Bootloader stage, determining whether the current version number of the Bootloader program is the lowest version number; in the kernel stage, determining whether the current version number of the kernel program is the lowest version number.
[0131] Figure 6 A flowchart of a method 60 for identifying tampering of device information according to some preferred embodiments of the present disclosure is shown. The method 60 is substantially the same as the method 50, and the differences between the two will be mainly described below.
[0132] As Figure 6As shown, in some preferred embodiments, the method 60 further includes: step S411, step S412, and step S493. Both step S411, step S412, and step S493 can be executed by the server 32. Step S411 can be executed in the Bootloader program. In some preferred embodiments, step S411 can be set after step S41 (refer to Figure 6 ). In some preferred embodiments, step S411 can also be set before step S41 (not shown in the figure). In step S411, it is determined whether the anti-tampering function is enabled. If it is determined that the anti-tampering function is enabled, step S42 can be executed. Conversely, if it is determined that the anti-tampering function is not enabled, step S412 can be executed to determine again whether the anti-tampering function is enabled. Step S412 can be executed in the kernel program. If it is determined again that the anti-tampering function is enabled, step S42 can be executed. Conversely, if it is determined again that the anti-tampering function is not enabled, step S493 can be executed to set the device SN status to None.
[0133] In some embodiments, the method 60 further includes: step S491, which can be executed by the server 32. Step S491 can be set after step S481. When it is determined that the device information has not been tampered with, step S491 is executed to set the device SN status to normal.
[0134] In some embodiments, the method 60 further includes: step S492, which can be executed by the server 32. Step S492 can be set after step S482. When it is determined that the device information has been tampered with, step S492 is executed to set the device SN status to abnormal.
[0135] In some embodiments, the method 60 further includes: step S4922, which can be executed by the server 32. Step S4922 can be set after step S482. When it is determined that the device information has been tampered with, step S4922 is executed to issue an alarm to notify the user. In some embodiments, step S4922 can also be set after step S492. When the device SN status is set to abnormal, step S4922 is executed. In some embodiments, step S492 and step S4922 can also be executed in parallel.
[0136] In some embodiments, when it is recognized that the device information has been tampered with, the server can be notified to take corresponding measures. For example, when it is recognized that the device information (such as SN) has been tampered with, the server can set the device information such as SN as abnormal, interrupt the working state of the device, and can also reconfigure the anti-tampering function of the device through the above method 10 and the above system 30. It can be understood that when it is recognized that other device information (such as Mac address, device hardware ID, current version number of the Bootloader program, current version number of the Kernel program, public key, etc.) has been tampered with, the server can set the corresponding device information as abnormal, interrupt the working state of the device, and can reconfigure the anti-tampering function of the device through the above method 10 and the above system 30, all of which are within the protection scope of the present disclosure. In summary, the system and method for anti-tampering of device information, and the method and system for recognizing that device information has been tampered with in the present disclosure have been introduced in detail. The system and method for anti-tampering of device information in the present disclosure can achieve the anti-tampering function and protect the security of device information by writing the check code into the first memory of the device and writing at least part of the server information into the second memory of the device. The method and system for recognizing that device information has been tampered with in the present disclosure can recognize whether the device information has been tampered with based on the second matching result of whether the second actual hash value matches the second expected hash value, and can take corresponding measures in the case of recognizing that the device information has been tampered with, so as to timely maintain the security of device information.
[0137] The present disclosure also relates to a computer-readable storage medium including computer-executable instructions stored thereon, and the executable instructions, when executed by a processor, implement the above method 10 / 40 / 60.
[0138] In some embodiments, computer-usable storage media include permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to: PRAM, SRAM, DRAM, other types of RAM, ROM, EEPROM, flash memory, or other memory technologies, compact disc read-only memory (CD-ROM), digital video disc (DVD), or other optical storage, magnetic cassette tapes, magnetic disk storage, or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0139] In some embodiments, the processor may include a Central Processing Unit (CPU), a Micro Control Unit (MCU), and may also include other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and other similar devices.
[0140] It should be noted that although several modules are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the above-described modules can be implemented in one module. Conversely, the features and functions of one module described above can be further divided and implemented by multiple modules.
[0141] It should be noted that this specification provides the method operation steps as described in the embodiments or the schematic diagrams, but based on routine or non-creative labor, there may be more or fewer operation steps. The order of the steps listed in the embodiments is only one of the execution orders of numerous steps and does not represent the only execution order. When the actual system or device product is executed, it can be executed in the order shown in the embodiments or the flowchart or executed in parallel.
[0142] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for preventing device information from being tampered with, comprising: Obtaining the device information of the device; Uploading the device information to a server; Receiving a verification code from the server, where the verification code is determined based on the device information and server information; Writing the verification code into the first memory of the device; And Writing at least part of the server information into the second memory of the device.
2. The method according to claim 1, further comprising: Enabling the anti-tampering function of the device by setting the logical state of the second memory.
3. The method according to claim 1, wherein the verification code is determined by the following method: Hashing the device information and the server information to obtain a first hash value; Performing salt hashing on the first hash value to obtain a second hash value; and Encrypting the second hash value to obtain the verification code.
4. The method according to claim 1, wherein the first memory includes a multi-programmable memory; the second memory includes a one-time programmable memory.
5. The method according to any one of claims 1-4, wherein the device information includes: One or more of a device serial number, a Mac address, a device hardware ID, the current version number of a Bootloader program, the current version number of a Kernel program, and a public key; the server information includes: one or more of a server ID, the minimum version number of a Bootloader program, the minimum version number of a Kernel program, and a private key; wherein at least part of the server information includes the minimum version number of the Bootloader program and the minimum version number of the Kernel program; wherein the public key and the private key are generated by the server.
6. A system for preventing device information from being tampered with, comprising: A device, including a first memory and a second memory; A reader-writer, communicating with the device; And A server, communicating with the reader-writer; Wherein, the reader-writer is configured to: Obtain the device information of the device; Upload the device information to the server; Receive a verification code from the server; Write the verification code into the first memory; and Write at least part of the server information into the second memory; Wherein, the server is configured to: Determine the verification code based on the device information and server information.
7. The system according to claim 6, wherein the server is configured to: enable the anti-tampering function of the device by setting the logical state of the second memory.
8. The system according to claim 6, wherein the server is configured to: Hash the device information and the server information to obtain a first hash value; Perform salt hashing on the first hash value to obtain a second hash value; and Encrypt the second hash value to obtain the verification code.
9. The system according to claim 6, wherein the first memory includes a multi-programmable memory; the second memory includes a one-time programmable memory.
10. The system according to any one of claims 6-9, wherein the device information includes: One or more of the device serial number, Mac address, device hardware ID, current version number of the Bootloader program, current version number of the Kernel program, and public key; the server information includes: one or more of the server ID, minimum version number of the Bootloader program, minimum version number of the Kernel program, and private key; wherein at least part of the server information includes the minimum version number of the Bootloader program and the minimum version number of the Kernel program; wherein the public key and the private key are generated by the server.
11. A method for identifying tampering of device information, comprising: In the Bootloader stage: Enable the anti-tampering function of the device; Obtain the device information and server information of the device; Based on the device information and the server information, determine the first actual hash value; Determine whether the first actual hash value matches the first expected hash value to obtain a first matching result; And Based on the first matching result, send the server information and the device information, or the server information and the processed device information to the kernel program; In the kernel stage: Based on the server information and the device information, or based on the server information and the processed device information, determine the second actual hash value; Determine whether the second actual hash value matches the second expected hash value to obtain a second matching result; And Based on the second matching result, determine whether the device information has been tampered with.
12. The method according to claim 11, wherein the step of determining whether the device information has been tampered with based on the second matching result comprises: If the second actual hash value matches the second expected hash value, determine that the device information has not been tampered with; If the second actual hash value does not match the second expected hash value, determine that the device information has been tampered with.
13. The method according to claim 11, wherein the first expected hash value or the second expected hash value is obtained by decrypting a check code stored in a first memory of the device; wherein the first memory includes a multi-programmable memory; wherein the check code is determined by the following method: Perform hashing on the device information and the server information to obtain a first hash value; Perform salt hashing on the first hash value to obtain a second hash value; and Encrypt the second hash value to obtain the check code.
14. The method according to any one of claims 11-13, wherein the device information includes one or more of a device serial number, a Mac address, a device hardware ID, a minimum version number of a Bootloader program, a minimum version number of a Kernel program, and a public key; wherein the minimum version number of the Bootloader program and the minimum version number of the kernel program are stored in a second memory of the device; Wherein The second memory includes a one-time programmable memory; Wherein the server information includes one or more of the server ID and the private key; the public key and the private key are generated by the server.
15. The method according to claim 14 further comprises: In the Bootloader stage, determine whether the current version number of the Bootloader program is the minimum version number; In the kernel stage, determine whether the current version number of the kernel program is the minimum version number.
16. The method according to claim 14, wherein the step of enabling the anti-tampering function of the device comprises: Enable the anti-tampering function of the device by setting the logical state of the second memory.
17. The method according to any one of claims 11-13 further comprises: When it is determined that the device information has been tampered with, issue an alarm.
18. A system for identifying tampering of device information, comprising: A device; And A server, communicating with the device; Wherein, the device is configured to send a request instruction to the server; The server is configured to respond to the request instruction and execute the method according to any one of claims 11-17.
19. A computer-readable storage medium, comprising computer-executable instructions stored thereon, the executable instructions, when executed by a processor, implement the method according to any one of claims 1-5, and / or implement the method according to any one of claims 11-17.