Charging pile firmware security upgrading method based on national secret algorithm
The described method enhances charging station firmware security by using SM3 hash and SM2 signature-based segmented verification, achieving EAL4+ security and low failure rates, effectively countering APT attacks and ensuring secure firmware updates.
Patent Information
- Application Number
- CN202510385000.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-15
AI Technical Summary
The existing charging pile firmware upgrade solutions generally adopt RSA signature verification, which has large amounts of signature verification, easy to tamper with the transmission process, and cannot effectively defend against advanced persistent threat (APT) attacks.
The National Secret algorithm is adopted to generate fingerprint chains through firmware blocking and SM3 hash calculations, SM2 signature fingerprint chain heads, SM4 encryption transmission, and verification is carried out step by step on the device side, combining the cloud upgrade server and the security module on the charging pile equipment side for upgrade process optimization.
It has achieved the ability to resist firmware tampering to reach EAL4+ security level, the upgrade failure rate is less than 0.1%, supports breakpoint continuous transmission, and effectively defends against APT attacks.
Smart Images

Figure CN120315733A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of charging pile firmware security upgrade, and specifically provides a method for securely upgrading charging pile firmware based on national cryptographic algorithms. Background Technique
[0002] Charging piles are devices that provide electric power charging for electric vehicles and are widely used in public places, parking lots, shopping malls, residential communities, etc. With the popularization of electric vehicles, the number and types of charging piles are also increasing continuously. They are generally divided into two types: direct current charging piles and alternating current charging piles to adapt to the charging needs of different electric vehicles. The functions of charging piles include: ① Battery charging: providing electric power with different powers for electric vehicles to meet the charging needs of the battery; ② Payment function: most charging piles are equipped with a payment function, and users can pay the charging fees by scanning codes, swiping cards, mobile phone apps, etc.; ③ Remote monitoring: charging piles are usually connected to the background management platform, and managers can remotely monitor the charging status, fault diagnosis, and equipment maintenance; ④ Charging records: recording users' charging data, such as charging duration, charging amount, fees, etc. for easy query by users and bill management.
[0003] The security of charging piles is crucial for ensuring the safety of electric vehicles and users. The secure upgrade of charging pile firmware is a key measure to ensure that charging pile devices can prevent various security threats and vulnerabilities during operation. With the popularization of charging piles in public places, it is particularly important to protect the security of charging piles because they involve sensitive information such as power transmission and user payment. The steps and methods for secure upgrade of charging pile firmware include firmware update management, encrypted communication, signature verification, vulnerability repair, access control, rollback mechanism, user privacy protection, security protection mechanism, etc.
[0004] Existing firmware upgrade solutions generally use RSA signature verification, which has problems such as large signature verification calculation volume and easy tampering during the transmission process. Traditional segmented verification mechanisms cannot defend against advanced persistent threat (APT) attacks. In response to this, this application proposes a method for securely upgrading charging pile firmware based on national cryptographic algorithms. Summary of the Invention
[0005] The purpose of the present invention is to provide a method for securely upgrading charging pile firmware based on national cryptographic algorithms to solve the problems in the existing technology that existing firmware upgrade solutions generally use RSA signature verification, which has problems such as large signature verification calculation volume and easy tampering during the transmission process, and traditional segmented verification mechanisms cannot defend against advanced persistent threat (APT) attacks.
[0006] To achieve the above purpose, the present invention provides the following technical solutions: In the first aspect of the present invention, a method for securely upgrading charging pile firmware based on national cryptographic algorithms is provided, including the following steps:
[0007] S1, Firmware chunking, SM3 hash calculation, generating a fingerprint chain;
[0008] S2, Signing the fingerprint chain head with SM2 and packaging it with the firmware;
[0009] S3, Encrypting the transmission with SM4 and performing step - by - step verification at the device end;
[0010] S4, Decrypting the firmware, writing it to Flash, and taking effect after restart.
[0011] Preferably, the step - by - step verification at the device end in S3 includes signature validity, fingerprint chain integrity, and chunk decryption and restoration.
[0012] The second aspect of the present invention provides an upgrade system architecture applying the method described in the first aspect of the present invention, including a cloud upgrade server and a charging pile device end;
[0013] The cloud upgrade server includes a firmware processing module, an encryption transmission engine, and an APT defense module;
[0014] The charging pile device end includes a secure boot module, a segmented verification module, and a trap code module.
[0015] Preferably, the firmware processing module performs chunk cutting, with each chunk being 512KB / block, and generates an SM3 hash fingerprint chain; the firmware processing module uses SM2 to digitally sign the fingerprint chain.
[0016] Preferably, the encryption transmission engine performs SM4 - CTR encryption and differential upgrade optimization.
[0017] Preferably, the APT defense module includes an attack feature library and log audit and tracking.
[0018] Preferably, the secure boot module performs Bootloader verification and whitelist management.
[0019] Preferably, the segmented verification module performs block - by - block verification of the hash chain and decryption buffer management.
[0020] Preferably, the trap code module includes a false key area and attack behavior entrapment.
[0021] The present invention has at least the following beneficial effects:
[0022] A method for secure upgrade of charging pile firmware based on national cryptography algorithms provided by the present invention. This solution is based on a segmented verification mechanism of the SM3 fingerprint chain, with the anti - firmware tampering ability reaching the EAL4 + security level, the upgrade failure rate < 0.1%, and supports resume - from - breakpoint transmission. Description of the Drawings
[0023] Figure 1 It is the upgrade flowchart of the present invention;
[0024] Figure 2 This is the system technical architecture diagram of the present invention. Detailed implementation manners
[0025] The technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0026] Embodiment 1
[0027] As Figure 1 shown, this embodiment provides a method for securely upgrading the firmware of a charging pile based on the national cryptographic algorithm, including the following steps:
[0028] S1. Firmware block division, SM3 hash calculation, and generation of a fingerprint chain;
[0029] S2. Sign the head of the fingerprint chain with SM2 and package it with the firmware;
[0030] S3. Encrypt and transmit with SM4, and perform step-by-step verification on the device side;
[0031] S4. Decrypt the firmware, write it into the Flash, and take effect after restart.
[0032] Combined with Figure 2 , that is, the cloud generates the head of the firmware fingerprint chain with SM2 signature, and 2. Encrypt and transmit the firmware blocks to the charging pile, and perform step-by-step verification on the device side:
[0033] Signature validity → Fingerprint chain integrity → Block decryption and restoration.
[0034] The upgrade system architecture of the above application method includes a cloud upgrade server and a charging pile device side;
[0035] The cloud upgrade server includes a firmware processing module, an encrypted transmission engine, and an APT defense module;
[0036] The charging pile device side includes a secure boot module, a segmented verification module, and a trap code module.
[0037] The firmware processing module performs block cutting, with each block being 512KB, and generates an SM3 hash fingerprint chain; the firmware processing module uses SM2 to digitally sign the fingerprint chain; the encryption transmission engine performs SM4-CTR encryption and differential upgrade optimization; the APT defense module includes an attack feature library and log audit tracking; the secure boot module performs Bootloader verification and whitelist management; the segmented verification module performs block-by-block verification of the hash chain and decryption buffer management; the trap code module includes a false key area and attack behavior entrapment.
[0038] Among them, in the implementation details design of this embodiment:
[0039] APT resistance design: Embed a trap code segment (invalid SM4 key data) in the firmware;
[0040] Differential upgrade: Only generate a new fingerprint chain for the modified part (reducing the transmission volume by 80%);
[0041] Rollback protection: Bidirectionally bind the firmware version number and the SM3 hash value.
[0042] In the technical solution of this embodiment:
[0043] 1. SM9 signature can be used to replace SM2 (PKG infrastructure needs to be deployed);
[0044] 2. The national cryptography SSL tunnel can be used to replace the custom encryption (increasing the computing overhead by 15%).
[0045] A method for secure upgrade of charging pile firmware based on national cryptography algorithms provided by the present invention, with a segmented verification mechanism based on the SM3 fingerprint chain, and the anti-firmware tampering ability reaches the EAL4+ security level; the upgrade failure rate < 0.1% (about 2.1 - 3.7% in the traditional scheme); supports resume from breakpoint (can resume from any block after network interruption). The comparison between the technical solution provided by the present invention and the traditional technical solution is shown in the following table:
[0046] Indicator Traditional whole - package signature Technical solution of the present invention Anti - partial - tampering ability None Block - hash - chain detection Upgrade failure rate 2.1%-3.7% <0.1% APT attack detection rate Not defended 92%-98%
[0047] The above shows and describes the basic principles, main features and advantages of the present invention. For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and can be implemented in other specific forms without departing from the spirit or basic features of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, it is intended to include all changes falling within the meaning and scope of the equivalent elements of the claims in the present invention.
[0048] Although embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for securely upgrading the firmware of a charging pile based on the national cryptographic algorithm, characterized in that It includes the following steps: S1. Firmware chunking, SM3 hash calculation, and generation of a fingerprint chain; S2. SM2 signature of the fingerprint chain head and packaging with the firmware; S3. SM4 encrypted transmission and hierarchical verification at the device end; S4. Decrypt the firmware, write it to Flash, and take effect after restart.
2. The method for securely upgrading the firmware of a charging pile based on the national cryptographic algorithm according to claim 1, wherein: The hierarchical verification at the device end in S3 includes signature validity, fingerprint chain integrity, and chunk decryption and restoration.
3. An upgraded system architecture applying the method according to any one of claims 1 to 2, characterized in that, It includes a cloud upgrade server and a charging pile device end; The cloud upgrade server includes a firmware processing module, an encrypted transmission engine, and an APT defense module; The charging pile device end includes a secure boot module, a segmented verification module, and a trap code module.
4. The upgrade system architecture according to claim 3, characterized in that: The firmware processing module performs chunk cutting, with each chunk being 512 KB, and generates an SM3 hash fingerprint chain; the firmware processing module uses SM2 to digitally sign the fingerprint chain.
5. The upgrade system architecture according to claim 3, wherein: The encrypted transmission engine performs SM4-CTR encryption and differential upgrade optimization.
6. The upgrade system architecture according to claim 3, wherein: The APT defense module includes an attack signature library and log audit and tracking.
7. The upgraded system architecture according to claim 1, wherein: The secure boot module performs Bootloader verification and whitelist management.
8. The upgrade system architecture according to claim 1, characterized in that: The segmented verification module performs block-by-block verification of the hash chain and decryption buffer management.
9. The upgrade system architecture according to claim 1, wherein: The trap code module includes a false key area and attack behavior entrapment.
Citation Information
Cited By
Communication method and device based on national cryptographic algorithm, and communication equipment
CN121603207A