Chip, server and system capable of realizing secure updating of firmware

Through multi-layer encryption, decryption and status flag recognition, the problem of insufficient security of firmware update of microcontroller units is solved, and the secure writing and operation protection of chip firmware is realized.

CN120295648APending Publication Date: 2025-07-11HUAZHONG UNIV OF SCI & TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510274588.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, the firmware update of microcontroller units lacks standardized security processes, resulting in the firmware being susceptible to reverse engineering leakage and insufficient security.

Method used

The multi-layer encryption and decryption process is adopted to generate the downloader and application key through the chip ID hashing. First write the downloader program, then write the application, and embed the verification module in the application to ensure that the ID matches before it can be successfully burned. Combined with the status flag to identify the update status, improve security.

Benefits of technology

It effectively improves the security of firmware updates, ensures that only legal chips can successfully write applications, prevent firmware leakage, and do not affect the execution efficiency of applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120295648A_ABST
    Figure CN120295648A_ABST
Patent Text Reader

Abstract

The invention belongs to the related technical field of software security, and discloses a chip, a server and a system capable of realizing firmware security update, the server generates and encrypts a downloader program based on a chip ID and transmits the downloader program to the chip for decryption programming; and the chip runs the downloader program to request the application program from the server, the server generates a customized firmware application program based on the ID, encrypts the customized firmware application program by using an application key randomly generated when the downloader program is generated previously, transmits the encrypted firmware application program to the chip for decryption programming, and erases the downloader program after decryption programming is completed. According to the method, the programmed firmware can only normally run on the unique chip with the corresponding ID, the downloader program can be regenerated during each downloading, one-time pad transmission of the application program is realized, the firmware security is improved, and firmware leakage is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field related to software security, and more specifically, relates to a chip, a server, and a system capable of realizing secure firmware update. Background Art

[0002] A micro control unit (MCU) is a chip-level computer that appropriately reduces the frequency and specifications of a central processing unit (CPU) and integrates interfaces such as memory, counters, a universal serial bus (USB), and a universal asynchronous receiver / transmitter (UART) on a single chip. It is also called a single-chip microcomputer and is commonly found in various control devices. Different firmware programs running on it can achieve different control functions in corresponding application scenarios.

[0003] There are many ways to burn and upgrade the firmware of a micro control unit, mainly including in-system programming (ISP), in-circuit programming (ICP), and in-application programming (IAP). These three methods have their own advantages and disadvantages in terms of programming speed, resource consumption, flexibility, etc. In-application programming IAP uses a user-defined bootloader. Users can choose to use various peripherals and protocols to upgrade the chip, which has extremely high flexibility. However, it requires users to burn the bootloader into the flash in advance through other means and requires a host computer program matching the bootloader to provide the firmware. The characteristics of IAP are very suitable for updating and upgrading the firmware program of a product through a reserved communication interface after the product is released. In a common IAP process, the flash of the chip is divided into two parts: a bootloader and an app. The bootloader realizes the upgrade function and jump of the app, and the app realizes the core function of the firmware and can trigger the upgrade.

[0004] However, there is currently no standardized secure IAP process. There is a relatively high risk of reverse engineering for unprotected firmware obtained by attackers, resulting in firmware leakage. Summary of the Invention

[0005] In view of the above-mentioned deficiencies or improvement requirements of the prior art, the present invention provides a chip, a server, and a system capable of realizing secure firmware update, aiming to improve the security of firmware update.

[0006] To achieve the above object, the present invention provides a chip capable of realizing firmware secure update, which comprises:

[0007] A firmware update startup module for starting the firmware update operation;

[0008] An application erasure module for erasing the current application when the firmware update operation is started;

[0009] An update request module for sending the ID hash of the chip and the downloader program request to the server;

[0010] A downloader program writing module for performing the downloader program writing operation, where the downloader program writing includes: receiving the encrypted text of the downloader program fed back by the server, calculating the downloader key based on its own ID information, decrypting and writing the encrypted text of the downloader program; the encrypted text of the downloader program is the encrypted text obtained by the server encrypting the downloader program with the downloader key calculated based on the ID hash, and the downloader program carries an application key randomly generated by the server after receiving the downloader program request and indexable by the ID hash in the server;

[0011] A downloader program startup module for starting the downloader program, and the downloader program performs the application program writing operation, where the application program writing operation includes: symmetrically encrypting the ID of the chip with the application key it carries to generate an ID encrypted text, and sending the ID hash, the ID encrypted text and the download application program request to the server, then receiving the encrypted text of the application program fed back by the server, and decrypting and writing the encrypted text of the application program with the application key it carries; the encrypted text of the application program is the encrypted text obtained by the server encrypting the application program based on the application key indexed by the ID hash, the application program carries ID verification information, and the ID verification information is obtained by the server decrypting the ID encrypted text with the application key indexed by the ID hash to obtain the ID and then performing a verification calculation on it;

[0012] A downloader program erasure module for erasing the downloader program after the application program writing is completed;

[0013] An application startup module for starting the application program after writing;

[0014] An application verification module for periodically comparing the ID verification information of the chip and the ID verification information carried in the application program, and only when the comparison is successful can the application program continue to run.

[0015] Optionally, the firmware update startup module and the application verification module are controlled by the application program, and when the application program is started, the firmware update startup module and the application verification module are started.

[0016] Optionally, the firmware update startup module is used to obtain the firmware version number of the server and compare it with the current firmware version number in the chip. If the current firmware version in the chip is lower, the firmware update operation is started.

[0017] Optionally, the chip has a status space for storing status flags;

[0018] The update request module and the downloader program writing module are used to send a request to the server and complete the writing of the downloader program after reading the first status flag, and then the status flag is updated to the second status flag;

[0019] The downloader program startup module is used to execute the application program writing operation after reading the second status flag, and then the status flag is updated to the third status flag;

[0020] The downloader program erasing module is used to erase the downloader program after reading the third status flag, and then the status flag is updated to the fourth status flag;

[0021] The application program startup module is used to start the written application program after reading the fourth status flag;

[0022] When the firmware update startup module determines that firmware update is required, the status flag is updated to the fifth status flag;

[0023] The application program erasing module is used to erase the current application program after reading the fifth status flag, and then the status flag is updated to the first status flag.

[0024] Optionally, the chip also has a bootloader space, a downloader program space, and an application program space:

[0025] The bootloader space stores a bootloader, and the bootloader includes the application program erasing module, the downloader program writing module, the downloader program startup module, and the application program startup module;

[0026] The downloader program space is used to store the written downloader program;

[0027] The application program space is used to store the written application program.

[0028] Optionally, the bootloader space, the downloader program space, the application program space, and the status space are all located in the FLASH space of the chip.

[0029] The present invention also provides a server for firmware updating of the chip as described in any one of the above, which includes:

[0030] The downloader program ciphertext generation module is used to, when receiving the ID hash of the chip and the downloader program request, calculate the downloader key based on the ID hash, randomly generate the application key of the application program, record it in the database and index it by the ID hash, write the application key into the downloader program, and then encrypt the downloader program using the downloader key to generate the downloader program ciphertext and send it to the chip;

[0031] The application program ciphertext generation module is used to, when receiving the ID hash, ID ciphertext and the download application program request, query the application key in the database with the received ID hash as the index, decrypt the ID ciphertext to obtain the ID, perform verification calculation on the ID to obtain the ID verification information and write it into the application program, and then encrypt the application program using the application key to generate the application program ciphertext and send it to the chip.

[0032] Optionally, both the downloader program ciphertext generation module and the application program ciphertext generation module use the CBC mode to encrypt the program.

[0033] The present invention also provides a firmware update system for a chip, which includes:

[0034] The chip as described in any one of the above;

[0035] The server as described above; and,

[0036] A client for realizing information forwarding between the chip and the server.

[0037] Optionally, the client communicates with the chip through a serial port, and the client communicates with the server through an HTTPS protocol network.

[0038] Generally speaking, compared with the prior art by the above technical solutions conceived by the present invention, the present invention mainly has the following beneficial effects:

[0039] 1. During the firmware update, the present invention involves multiple interactions and encryption / decryption processes between the chip and the server. The chip does not directly request to burn the application program. Instead, it first requests to burn the downloader program. The server randomly generates an application key bound to the ID of the chip according to the ID of the chip, writes it into the downloader program, and encrypts the downloader program based on the ID to form a ciphertext and sends it to the chip. The chip performs the first decryption. Only when the ID matches successfully can the chip successfully burn the downloader program. After that, the chip calls the downloader program to implement the burning of the application program. When burning the application program, the request sent to the server includes the ID hash, the ID ciphertext, and the request to download the application program. The purpose of resending the ID hash is to enable the server to find the application key bound to it based on the current ID hash, encrypt the application program to form a ciphertext and send it to the chip. The chip then performs the second decryption, that is, decrypts it using the application key carried by the downloader program. Only when the ID hash provided when the downloader program requests is the same as the ID hash provided by the application program request can the application key in the downloader program successfully decrypt the application ciphertext. In this way, it can be ensured that the downloader program request and the application program request come from the same chip, and the chip can successfully burn the application program, further improving the security of the firmware upgrade. Moreover, in the application program, the verification information of the ID is also carried to realize the binding of the application program and the chip ID. Even if the application program is burned into the chip, if the chip running the application program cannot successfully compare with the ID verification information in the application program, the application program cannot be run either. In this way, the security of the application program running can be ensured. Generally speaking, the present invention effectively improves the security of the chip firmware update through multiple security measures such as the encryption / decryption of the downloader program burning, the encryption / decryption of the application program burning, and the information verification of the application program running.

[0040] 2. Optionally, by embedding the firmware update startup module and the application program verification module in the application program, the application program can determine whether an update is required. If so, it enters the upgrade process, erases the current application program through the Bootloader boot program and requests the latest application program. Embedding the firmware update startup module in the application program, the bootloader does not need to open the serial port to receive information anymore, so that the execution efficiency of the application program can be not affected; the application program verification module supports verification based on the ID of the CPU in the running state of the application program. If the ID of the CPU is different from the one pre-written in the binary file, the verification fails and it enters the abnormal state, and the program cannot achieve the normal function.

[0041] 3. Optionally, the status of the firmware security update can be determined through status flag recognition, and it can be determined whether to enter the corresponding operation. In the case of update exceptions, the update can continue from the previous state, improving the robustness of the update process and ensuring the integrity of the burned program. Brief Description of the Drawings

[0042] Figure 1 is a schematic structural diagram of a chip capable of realizing firmware security update in an embodiment of the present invention;

[0043] Figure 2 is a schematic diagram of the space allocation of the FLASH area of the chip in an embodiment of the present invention;

[0044] Figure 3 is a schematic structural diagram of a server in an embodiment of the present invention;

[0045] Figure 4 is a system architecture diagram of a firmware update system in an embodiment of the present invention;

[0046] Figure 5 is a schematic flow diagram of information interaction among a chip, a client, and a server in an embodiment of the present invention. Detailed Embodiments

[0047] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0048] Embodiment 1

[0049] The present invention claims to protect a chip capable of realizing firmware security update.

[0050] As Figure 1 shown is a schematic structural diagram of a chip capable of realizing firmware security update in an embodiment of the present invention, which includes a firmware update start module, an application program erasure module, an update request module, a downloader program writing module, a downloader program start module, a downloader program erasure module, an application program start module, and an application program verification module.

[0051] The firmware update start module is used to start the firmware update operation.

[0052] The application program erasure module is used to erase the current application program after starting the firmware update operation.

[0053] The update request module is used to send the ID hash of the chip and the downloader program request to the server.

[0054] The downloader program flashing module is used to perform the operation of flashing the downloader program. The downloader program flashing includes: receiving the encrypted text of the downloader program feedback by the server, calculating its own ID information to generate a downloader key, and decrypting and flashing the encrypted text of the downloader program; the encrypted text of the downloader program is the encrypted text obtained by the server encrypting the downloader program with the downloader key calculated based on the ID hash. The downloader program carries an application key randomly generated by the server after receiving the downloader program request and can be indexed by the ID hash on the server.

[0055] The downloader program startup module is used to start the downloader program, and the downloader program performs the operation of flashing the application program. The operation of flashing the application program includes: symmetrically encrypting the ID of the chip with the application key it carries to generate an encrypted ID text, and sending the ID hash, the encrypted ID text, and the request for downloading the application program to the server. Subsequently, it receives the encrypted text of the application program feedback by the server, and decrypts and flashes the encrypted text of the application program with the application key it carries; the encrypted text of the application program is the encrypted text obtained by the server encrypting the application program based on the application key indexed by the ID hash. The application program carries ID verification information, and the ID verification information is obtained by the server decrypting the encrypted ID text with the application key indexed by the ID hash to obtain the ID and then performing a verification calculation on it.

[0056] The downloader program erasing module is used to erase the downloader program after the application program flashing is completed.

[0057] The application program startup module is used to start the application program after flashing.

[0058] The application program verification module is used to periodically compare the ID verification information of the chip and the ID verification information carried in the application program, and the application program can continue to run only when the comparison is successful.

[0059] In a specific embodiment, the firmware update startup module and the application program verification module are embedded in the application program. During the operation of the application program, the firmware update startup module and the application program verification module are in a running state. That is, the firmware update startup module and the application program verification module are added to the chip with the burning of the application program. In other embodiments, the firmware update startup module and the application program verification module can also be the fixed Bootloader boot program of the chip. By embedding the firmware update startup module and the application program verification module in the application program, the application program can determine whether an update is required. If so, it enters the upgrade process, erases the current application program through the Bootloader boot program and requests the latest application program, and embeds the firmware update startup module in the application program. The bootloader does not need to open the serial port to receive information anymore, so that the execution efficiency of the application program can be unaffected; the application program verification module supports verification based on the ID of the CPU in the running state of the application program. If the ID of the CPU is different from the pre-written one in the binary file, the verification fails and it enters an abnormal state, and the program cannot implement normal functions.

[0060] The application program erasure module, the update request module, the downloader program burning module, the downloader program startup module, the downloader program erasure module, and the application program startup module can all be the fixed Bootloader boot program of the chip.

[0061] In one embodiment, the firmware update startup module is used to obtain the firmware version number of the server and compare it with the current firmware version number in the chip. If the current firmware version in the chip is lower, the firmware update operation is started; otherwise, the firmware update operation is not started.

[0062] In one embodiment, the chip has a status space for storing status flags, and it is identified whether to enter the corresponding operation through the status flags.

[0063] After the update request module and the downloader program burning module read the first status flag, they send a request to the server and complete the burning of the downloader program, and then the status flag is updated to the second status flag;

[0064] After the downloader program startup module reads the second status flag, it executes the application program burning operation, and then the status flag is updated to the third status flag;

[0065] After the downloader program erasure module reads the third status flag, it erases the downloader program, and then the status flag is updated to the fourth status flag;

[0066] The application program startup module starts the application program after burning after reading the fourth status flag;

[0067] When the firmware update start module determines that a firmware update is required, the status flag is updated to the fifth status flag;

[0068] After the application erasure module reads the fifth status flag, it erases the current application, and then the status flag is updated to the first status flag.

[0069] In the above embodiments, the status of the firmware security update can be determined by identifying the status flag, and it can be determined whether to enter the corresponding operation. In the case of update exceptions, the update can continue from the previous state, improving the robustness of the update process and ensuring the integrity of the programmed program.

[0070] In one embodiment, the chip also has a bootloader program space, a downloader program space, and an application program space. The bootloader program space stores a bootloader program, which includes the application erasure module, the downloader program writing module, the downloader program start module, and the application start module; the downloader program space is used to store the written downloader program; the application program space is used to store the written application program.

[0071] As Figure 2 shown is a schematic diagram of the FLASH area space allocation of the MCU, and its allocation is as follows:

[0072] (1) The Bootloader boot program, located at the position where the FLASH space starts to execute, will perform jumps between programs according to the update status flag in the MCU status information, and is not bound to the ID of the MCU. It is burned into the MCU before executing the firmware update method of this solution;

[0073] (2) The downloader program, located after the Bootloader boot program, is bound to the ID of the MCU and is downloaded by the Bootloader boot program. It is used to download and decrypt the application program, and each write contains different application keys;

[0074] (3) The application program, located after the downloader program, is bound to the ID of the MCU and executes the functions required by the MCU. It is the core firmware of the MCU;

[0075] (4) The MCU status information, at the end of the FLASH space, includes the current firmware version number, the latest firmware version number (informed by the client during communication with the client), and the update status flag.

[0076] Among them, the version number length is 16 bytes, and the update status flag length is 2 bytes.

[0077] The following is illustrated with a specific example.

[0078] There are 5 types of update status flags, namely:

[0079] The first status flag is 0xFFFF, which is the update initial state. At this time, only the Bootloader program is in the MCU, and the FLASH spaces corresponding to the downloader program and the application program are empty. In this state, the update request module in the Bootloader program and the downloader program burning will request and download the downloader program. After the downloader program burning is completed, the update status flag is changed to the second status flag 0x0000.

[0080] The second status flag is 0x0000, which is the application program download state. At this time, the Bootloader program and the downloader program are burned in the MCU. In this state, the application program needs to be downloaded. In this state, after the MCU is started, the downloader program startup module in the Bootloader program will directly jump to the start address of the downloader program according to this state and execute the downloader program. The downloader program will request the application program firmware from the client, decrypt and burn it after obtaining the encrypted application program firmware. After completion, the update status flag is changed to the third status flag 0x0010.

[0081] The third status flag is 0x0010, which is the downloader erasure state. At this time, the Bootloader program, the downloader program, and the application program are burned in the MCU. To reduce the risk of the downloader program being cracked, in this state, the downloader program erasure module in the Bootloader program will erase the downloader program. After completion, the update status flag is changed to the fourth status flag 0x1000.

[0082] The fourth status flag is 0x1000, which is the application program running state. At this time, the Bootloader program and the application program are burned in the MCU. In this state, the application program needs to run normally. In this state, after the MCU is started, the application program startup module in the Bootloader program will directly jump to the start address of the application program according to this state and execute the application program. The application program contains the logic for upgrade judgment. If the application program needs to be upgraded, the application program will modify the update status flag to the fifth status flag 0x0011.

[0083] The fifth status flag 0x0011 is the request for upgrade status. At this time, the Bootloader boot program and the application program are burned in the MCU. In this state, the application program needs to be erased to start the upgrade process. When the MCU starts in this state, the application program erasure module in the Bootloader boot program will erase the application program according to this status and enter the update initial state to facilitate the subsequent download of the latest version of the application program. Therefore, after completion, the update status flag is changed to the first status flag 0xFFFF.

[0084] Embodiment 2

[0085] The present invention also protects a server for firmware update of the above chip.

[0086] As Figure 3 shown is a schematic structural diagram of a server in an embodiment of the present invention, which includes a downloader program ciphertext generation module and an application program ciphertext generation module.

[0087] The downloader program ciphertext generation module is used for, when receiving the ID hash of the chip and the downloader program request, calculating the downloader key for the ID hash, randomly generating the application key of the application program, recording it in the database and indexing it by the ID hash, writing the application key into the downloader program, and then encrypting the downloader program with the downloader key to generate the downloader program ciphertext and sending it to the chip.

[0088] The application program ciphertext generation module is used for, when receiving the ID hash, the ID ciphertext and the download application program request, querying the application key in the database with the received ID hash as the index, decrypting the ID ciphertext to obtain the ID, calculating the ID verification information for the ID and writing it into the application program, and then encrypting the application program with the application key to generate the application program ciphertext and sending it to the chip.

[0089] Embodiment 3

[0090] The present invention also protects a firmware update system for a chip.

[0091] As Figure 4 shown is a system architecture diagram of a firmware update system in an embodiment of the present invention. The system includes the chip introduced in Embodiment 1, the server introduced in Embodiment 2, and a client for realizing information forwarding between the chip and the server. Information interaction occurs among the chip, the client, and the server to achieve firmware burning of the chip.

[0092] As Figure 5 shown is a schematic flowchart of information interaction among the chip, the client, and the server.

[0093] S1. The client accesses the server to obtain the latest version number of the firmware and informs the chip.

[0094] In this embodiment, specifically, if an upgrade is required, generally the client is first started, and the user logs in so that the server can verify the user's identity. After the verification passes, the user opens the serial port in the client. During this process, the client will send a GET request to the server in the background to obtain the version number of the current latest firmware template. More specifically, the version number can be obtained by the server performing a hash calculation on the firmware template it stores. After the server returns the version number, the client will send update query information containing the version number through the serial port to ask whether the chip needs to perform a firmware update and download.

[0095] S2. The chip determines whether to update the firmware according to the received version number. If no update is required, the process ends. If an update is required, the ID hash obtained by performing a hash operation on its ID and the downloader program request are forwarded to the server by the client.

[0096] Specifically, when the chip is connected to the client through the serial port and obtains the version number, the following process is executed:

[0097] S21. The firmware update start module in the chip decides whether to update the firmware. If no update is required, the process ends. If an update is required, the firmware update start module is run to erase the current application program.

[0098] Specifically, the chip queries the position in the FLASH where the current firmware version number is stored, compares the current version number with the latest version number provided by the client to determine whether an update is required. If no update is required, the chip will reply to the client with the corresponding instruction of no update required, and the process ends. If an update is required, the chip temporarily stores the latest version number provided by the client in the FLASH and runs the firmware update start module in the Bootloader boot program to erase the current application program.

[0099] S22. The update request module in the chip reads the ID of the chip according to the address, then performs a hash calculation on the ID to obtain the ID hash, and packs the ID hash and the downloader program request for the downloader program to be burned and sends them to the client through the serial port.

[0100] The ID is generally 24 bytes. For example, the corresponding address of the chip GD32F303 is 0x1FFFF7E8, and the ID corresponding to this address is read and a hash calculation is performed.

[0101] S23. The client parses the serial port information and passes the ID hash, the downloader program request, along with the timestamp, check code, and cookie used to improve communication security to the server.

[0102] Through S1 to S2, the client accesses the server to determine the latest version number of the current firmware and informs the chip. The chip determines whether to download the firmware based on the version number. If an upgrade is required, the Bootloader bootloader is started to send a downloader program request to the client and attach the ID hash of the chip, and then the client submits it to the server.

[0103] S3. The server creates a space indexed by the received ID hash in the database, calculates the ID hash to generate a downloader key, randomly generates an application key for the application program and records it in this space, writes the application key into the downloader program, and then encrypts the downloader program using the downloader key to generate a downloader program ciphertext and forwards it to the chip via the client.

[0104] In this step, the server generates and encrypts a customized downloader program bound to the chip based on the ID hash of the chip, that is, when the server receives the information sent by the client in S2, it performs the following operations:

[0105] S31. The server verifies the timestamp, verification code, and cookie. After passing the verification, it extracts the ID hash.

[0106] S32. The server creates a space in the database for the chip according to the ID hash to record information related to the chip.

[0107] S33. The server calculates the ID hash to generate a downloader key.

[0108] S34. The server randomly generates an application key for the application program and records it in the database.

[0109] S35. The server writes the application key into the downloader program template by binary modification to generate a dedicated downloader program for the chip.

[0110] S35. The server encrypts the downloader program using the downloader key to obtain a downloader program ciphertext and returns it to the client.

[0111] S36. The client passes the downloader program ciphertext to the chip through the serial port.

[0112] Specifically, the client serial port uses the Ymodem protocol for information transmission.

[0113] Furthermore, the database can be updated to record some key information of the above process in the database.

[0114] S4. The downloader program burning module in the chip calculates the ID hash to generate a downloader key, decrypts and burns the encrypted downloader program ciphertext. It uses the application key carried by the downloader program to symmetrically encrypt the ID of the chip to generate an ID ciphertext, and forwards the ID hash, ID ciphertext, and download application program request to the server through the client.

[0115] In this step, after the chip receives the information sent by the client in S3, it executes the following process:

[0116] S41. The downloader program burning module calculates the ID hash of the chip to generate a downloader key, uses this downloader key to decrypt and burn the encrypted downloader program ciphertext, and runs the downloader program after the burning is completed.

[0117] It can be understood that the algorithm for the chip to calculate the ID hash to generate a downloader key is the same as that of the server. In this way, only when the ID hash of the chip is the same as the ID hash used for the encrypted downloader program ciphertext can the decryption of the encrypted downloader program ciphertext be achieved. If the encrypted downloader program ciphertext is transmitted to other chips, the decryption process will fail, ensuring the security of the firmware upgrade.

[0118] After passing the verification without error, the downloader program is extracted and burned into the chip.

[0119] In a specific embodiment, in S3, the server encrypts the downloader program in CBC (Cipher-block chaining) mode to generate a series of ciphertexts, and passes the ciphertexts to the chip frame by frame through the client. After the chip decrypts each program block, it decrypts and burns it. In this way, the encryption complexity can be enhanced, and the chip does not need to store the complete ciphertext for decryption, and can achieve decryption and burning at the same time, accelerating the entire upgrade process.

[0120] S42. The downloader program reads the chip ID and symmetrically encrypts the ID using the application key carried by the downloader program.

[0121] Specifically, the downloader program reads the ID of the 24-byte MCU according to the address.

[0122] S43. The downloader program sends the download application program request, ID ciphertext, and ID hash to the client.

[0123] Among them, the downloader program can directly extract the ID hash generated by the chip in S2, or directly perform a hash operation on the ID again to obtain it.

[0124] Specifically, the download application program request, ID ciphertext, and ID hash are sent to the client through the serial port.

[0125] S43. The client transfers the ID ciphertext, ID hash, and application request, along with the timestamp, verification code, and cookie used to enhance communication security, to the server.

[0126] S5. The server queries the application key in the database using the received ID hash, decrypts the ID ciphertext to obtain the ID, writes the verification information of the ID into the application, and then encrypts the application using the application key to generate the application ciphertext, which is forwarded to the chip by the client.

[0127] Specifically, after the server receives the information transmitted by the client in S4, the following process is executed:

[0128] S51. The server verifies the timestamp, verification code, and cookie. After passing the verification, it extracts the ID ciphertext and ID hash.

[0129] S52. The server searches for the application key in the database according to the ID hash and decrypts the ID ciphertext to obtain the ID.

[0130] Specifically, the server searches for the record of the chip in the database according to the hash of the ID; after matching the record, it reads the application key and decrypts the ID ciphertext to obtain the ID.

[0131] S53. The server writes the verification information of the ID into the application template in a binary modification manner to generate a dedicated application corresponding to the chip.

[0132] Specifically, the server calculates the ID of the MCU and writes it to the corresponding position of the application binary file. In this way, when the application runs subsequently, it can compare the pre-written verification content with the content calculated by reading the ID of the MCU during runtime. If the two are different, it means that the binary file is not the customized firmware for the current chip and the program cannot run properly; if they are the same, the verification passes.

[0133] S54. The server encrypts the application using the application key to obtain the application ciphertext and returns it to the client.

[0134] Specifically, since the server randomly generates the application key each time it performs an upgrade task, that is, the application key used for each upgrade is different, it realizes the encryption of the application in a "one-time pad" manner, greatly improving the security of firmware upgrade.

[0135] S36. The client transfers the application ciphertext to the chip through the serial port.

[0136] Specifically, the client serial port uses the Ymodem protocol for information transmission.

[0137] Furthermore, the database can be updated to record some key information of the above process in the database.

[0138] S6. The chip runs the downloader program, enabling it to decrypt and burn the application program ciphertext using the carried application key. After the burning is completed, the downloader program erasure module is used to erase the downloader program.

[0139] In this step, after the chip receives the information sent by the client in S5, it performs the following process:

[0140] S61. The downloader program decrypts and burns the application program ciphertext using the carried application key.

[0141] Since the application key has been written into the downloader program, the downloader program can decrypt the application program ciphertext using the carried application key and burn it into the FLASH of the chip.

[0142] S62. Erase the downloader program after the burning is completed.

[0143] The Bootloader boot program erases the corresponding block of the downloader program in the FLASH, and the burning and upgrading process is completed.

[0144] When the chip runs the application program, the application program periodically requests the chip to provide the current chip ID verification information for comparison with the verification information carried in the application program. The application program can continue to run only when the comparison is successful.

[0145] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification. It should be noted that the "in one embodiment", "for example", "again, for example", etc. of the present invention are intended to illustrate the present invention, rather than to limit the present invention.

[0146] The above embodiments only represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent application. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can be made, and these all belong to the protection scope of the present invention.

Claims

1. A chip capable of realizing firmware security update, characterized in that, including; a firmware update startup module for starting a firmware update operation; an application erasure module for erasing the current application when the firmware update operation is started; an update request module for sending the ID hash of the chip and a downloader program request to a server; a downloader program flashing module for performing a downloader program flashing operation, where the downloader program flashing includes: receiving a downloader program ciphertext fed back by the server, calculating a downloader key based on its own ID information, decrypting and flashing the downloader program ciphertext; the downloader program ciphertext is the ciphertext obtained by the server encrypting the downloader program using the downloader key calculated based on the ID hash, and the downloader program carries an application key randomly generated by the server after receiving the downloader program request and indexable by the ID hash at the server; a downloader program startup module for starting the downloader program, and the downloader program performs an application flashing operation, where the application flashing operation includes: symmetrically encrypting the ID of the chip using the application key it carries to generate an ID ciphertext, and sending the ID hash, the ID ciphertext, and a download application program request to the server, then receiving an application program ciphertext fed back by the server, and decrypting and flashing the application program ciphertext using the application key it carries; the application program ciphertext is the ciphertext obtained by the server encrypting the application program based on the application key indexable by the ID hash, the application program carries ID verification information, and the ID verification information is obtained by the server decrypting the ID ciphertext using the application key indexable by the ID hash to get the ID and then performing a verification calculation on it; a downloader program erasure module for erasing the downloader program after the application flashing is completed; an application startup module for starting the flashed application; an application verification module for periodically comparing the ID verification information of the chip with the ID verification information carried in the application program, and only when the comparison is successful can the application program continue to run.

2. The chip capable of realizing firmware security update as claimed in claim 1, wherein The firmware update startup module and the application verification module are controlled by the application program. When the application program is started, the firmware update startup module and the application verification module are started.

3. The chip capable of implementing firmware security update as claimed in claim 1, wherein, The firmware update startup module is used to obtain the firmware version number of the server and compare it with the current firmware version number in the chip. If the current firmware version in the chip is lower, the firmware update operation is started.

4. The chip capable of implementing firmware security update as claimed in claim 1, wherein The chip has a status space for storing status flags; The update request module and the downloader program flashing module are used to send a request to the server and complete the flashing of the downloader program after reading the first status flag, and then the status flag is updated to the second status flag; The downloader program startup module is used to perform an application flashing operation after reading the second status flag, and then the status flag is updated to the third status flag; The downloader program erasure module is used to erase the downloader program after reading the third status flag, and then the status flag is updated to the fourth status flag; The application startup module is used to start the flashed application after reading the fourth status flag; When the firmware update start module determines that a firmware update is required, the status flag is updated to the fifth status flag; The application erasure module is used to erase the current application after reading the fifth status flag, and then the status flag is updated to the first status flag.

5. The chip capable of implementing firmware security update as claimed in claim 4, wherein, The chip also has a bootloader space, a downloader program space, and an application space: The bootloader space stores a bootloader, which includes the application erasure module, the downloader program writing module, the downloader program start module, and the application start module; The downloader program space is used to store the written downloader program; The application space is used to store the written application.

6. The chip capable of realizing firmware security update according to claim 5, characterized in that, The bootloader space, the downloader program space, the application space, and the status space are all located in the FLASH space of the chip.

7. A server for firmware update of the chip according to any one of claims 1 to 6, characterized in that, Including: A downloader program ciphertext generation module, which is used to calculate a downloader key for the ID hash when receiving the ID hash of the chip and the downloader program request, randomly generate an application key for the application program, record it in the database and can be indexed by the ID hash, write the application key into the downloader program, and then encrypt the downloader program using the downloader key to generate a downloader program ciphertext and send it to the chip; An application program ciphertext generation module, which is used to query the application key in the database with the received ID hash as the index and decrypt the ID ciphertext to obtain the ID when receiving the ID hash, ID ciphertext, and download application program request, calculate the ID verification information for the ID and write it into the application program, and then encrypt the application program using the application key to generate an application program ciphertext and send it to the chip.

8. The server according to claim 7, characterized in that, Both the downloader program ciphertext generation module and the application program ciphertext generation module encrypt the program using the CBC mode.

9. A firmware update system for a chip, characterized in that, Including: The chip according to any one of claims 1 to 6; The server according to claim 7 or 8; and, A client for realizing information forwarding between the chip and the server.

10. The system according to claim 9, wherein, The client communicates with the chip through a serial port, and the client communicates with the server through an HTTPS protocol network.