Firmware encryption method and system based on device unique identifier and dynamic key verification

Through the encryption method based on the device's unique identification and dynamic key, dynamic keys are generated and verified, and the problems of easy cracking of static keys and portability of hardware copy boards are solved, improving the security and reliability of firmware protection and preventing bypass attacks.

CN120337243APending Publication Date: 2025-07-18SANY HEAVY EQUIP CO LTD +1

Patent Information

Application Number
CN202510365565.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the existing firmware protection technology, static keys are easily cracked, hardware copying is portable, and external encryption chips are vulnerable to bypass attacks, resulting in insufficient security and reliability.

Method used

Using a method based on device unique identification and dynamic key verification, a dynamic key is generated by obtaining unmodified hardware characteristic information, and a dual protection storage is encrypted using hardware isolation and logical encryption. The dynamic key is regenerated every time the device is started or firmware updated, and comparison verification is performed to control firmware operation.

Benefits of technology

Effectively prevent hardware copying and firmware transplantation, improve the security and reliability of firmware protection, avoid the risk of long-term exposure of static keys, and reduce the threat of bypass attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337243A_ABST
    Figure CN120337243A_ABST
Patent Text Reader

Abstract

The invention provides a firmware encryption method and system based on a device unique identifier and dynamic key verification, and relates to the technical field of firmware protection, and the method comprises the steps: obtaining a unique identifier of a device, the unique identifier being hardware feature information which cannot be modified; a dynamic key is generated based on the unique identifier and the random number, and the dynamic key is realized through an encryption algorithm and is regenerated every time the device is started or firmware is updated; the dynamic key is stored in a storage area protected by hardware, and the storage area is subjected to double protection of hardware isolation and logic encryption; and when the device is started, the dynamic key is regenerated, the unique identifier of the dynamic key and the unique identifier of the dynamic key stored in the storage area are compared and verified, if the dynamic key and the unique identifier are consistent, firmware operation is allowed, and otherwise, a safety response mechanism is triggered. According to the invention, the security and reliability of firmware protection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of firmware protection, and particularly to a firmware encryption method and system based on device unique identifier and dynamic key verification. Background Art

[0002] In today's digital age, embedded systems are widely used in various fields, from consumer electronics to industrial control, from smart home to automotive electronics, etc. Their security and stability are crucial. Among them, firmware, as the core software part of the embedded system, protecting it from being illegally obtained, tampered with, and used has become a key link to ensure the normal operation of the device and information security. With the intensification of market competition, the phenomena of hardware cloning and illegal firmware copying are becoming increasingly rampant, bringing huge economic losses and security risks to enterprises. Therefore, the research and development of firmware protection technology are imminent.

[0003] Currently, existing technologies mostly adopt static keys or encryption schemes based on a single device identifier for firmware protection. Taking the patent CN110737448B as an example, it uses a static key and a firmware matching verification mechanism, which ensures firmware security to a certain extent and realizes functions such as internal firmware checksum and upgrade verification in the system. However, such schemes have many problems that cannot be ignored. First, the static key remains fixed for a long time. Once it is leaked, attackers can easily crack the encrypted data and bypass the security protection mechanism, resulting in the collapse of the firmware security defense line. Second, in the face of hardware cloning behavior, due to the lack of a mechanism deeply bound to the hardware, even if the hardware circuit is copied, it is impossible to prevent the firmware from running on the new device, that is, there is a problem of portability of hardware cloning, which makes it difficult to effectively protect the intellectual property rights of enterprises. Moreover, some existing technologies rely on external encryption chips. Although the encryption effect is enhanced to a certain extent, new risks are brought. On the one hand, the external encryption chip increases the device cost; on the other hand, this chip is vulnerable to side-channel attacks during operation. For example, attackers can use power analysis to measure the power consumption changes of different operations of the chip during encryption operations with a high-precision current sensor, and infer the key in combination with the algorithm; or use electromagnetic radiation analysis to capture different electromagnetic radiation patterns generated by the chip during operation with an electromagnetic probe to obtain key information; they can also use execution time analysis to accurately measure the time difference of different operations of the encryption chip to infer the key, and then illegally copy the firmware and tamper with the data, seriously threatening system security and causing economic losses.

[0004] In summary, in the technical field of embedded system firmware protection, the existing encryption schemes cannot effectively solve problems such as easy cracking of static keys, portability of hardware cloning, and vulnerability to side-channel attacks of relying on external encryption chips. Therefore, there is an urgent need for a new technical solution to improve the security and reliability of firmware protection. Summary of the Invention

[0005] The present invention aims to solve at least one of the technical problems existing in the prior art or related technologies.

[0006] To this end, the present invention provides a firmware encryption method and system based on device unique identifier and dynamic key verification, which can improve the security and reliability of firmware protection.

[0007] According to a firmware encryption method based on device unique identifier and dynamic key verification provided by the first aspect of the present invention, it includes:

[0008] Obtain the unique identifier of the device, and the unique identifier is non-modifiable hardware feature information;

[0009] Generate a dynamic key based on the unique identifier and a random number, wherein the dynamic key is implemented through an encryption algorithm and is regenerated each time the device is started or the firmware is updated;

[0010] Store the dynamic key in a hardware-protected storage area, and the storage area is protected by both hardware isolation and logical encryption;

[0011] Regenerate the dynamic key when the device is started, and perform a comparison verification of the unique identifier with the dynamic key stored in the storage area. If they are consistent, the firmware is allowed to run; otherwise, a security response mechanism is triggered.

[0012] Optionally, obtaining the unique identifier of the device includes:

[0013] Write a reading program for the device unique identifier in the firmware startup code, and when the device is started, use the reading program to read the unique identifier of the device from the hardware module; or,

[0014] When the device is started, use a scanning device to read the QR code or barcode information set on the device surface and use it as the unique identifier of the device; or,

[0015] When the device is first connected to the network, send a registration request to the server, and receive the unique identifier feedback by the server to the device. The unique identifier is allocated to the device by the server according to a preset rule after responding to the registration request and is associated with the hardware information of the device for storage.

[0016] Optionally, the unique identifier of the device read by the reading program includes the chip ROM serial number or the physical fingerprint generated by the physical unclonable function PUF;

[0017] When the device is started, using the reading program to read the unique identifier of the device from the hardware module includes:

[0018] Add a register reading instruction to the reading program, which is used to read the chip ROM serial number from the chip ROM by executing the register reading instruction when the device is started; or,

[0019] Integrate the PUF interface call logic into the reading program to read the physical fingerprint generated by the PUF based on the PUF interface call logic when the device starts up.

[0020] Optionally, before generating the dynamic key based on the unique identifier and the random number, the method further includes:

[0021] Obtain the real-time clock value through the real-time clock module and use the real-time clock value as the random number; or,

[0022] Obtain the hardware entropy source and convert the random information contained in the hardware entropy source into a random number.

[0023] Optionally, the encryption algorithm is AES-256 or a hash function.

[0024] Optionally, the hardware isolation is implemented through the memory protection unit MPU, and the logical encryption is implemented through the Flash write protection bit configuration.

[0025] Optionally, the security response mechanism includes at least one of system suspension, self-destruction program, or clearing critical data.

[0026] A firmware encryption system based on device unique identifier and dynamic key verification according to the second aspect of the present invention includes:

[0027] A unique identifier module for obtaining and storing the non-modifiable unique identifier of the device;

[0028] A dynamic key generation module that generates a dynamic key based on the unique identifier and the random number, wherein the dynamic key is implemented through an encryption algorithm and is regenerated each time the device starts up or the firmware is updated;

[0029] A secure storage module configured to store the dynamic key through a dual protection mechanism of hardware isolation and logical encryption;

[0030] A verification execution module for regenerating the dynamic key when the device starts up and comparing and verifying it with the stored dynamic key, and controlling the running permission of the firmware according to the comparison and verification result.

[0031] Optionally, the storage address of the secure storage module is a protected fixed area in the chip Flash, and only the verification execution module is allowed to access it.

[0032] An electronic device according to the third aspect of the present invention includes: a processor and a memory, the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the method in the first aspect or its various implementation manners.

[0033] A computer-readable storage medium provided according to the fourth aspect of the present invention is used to store a computer program, and the computer program causes a computer to execute the method in the first aspect or its various implementation manners.

[0034] Through the technical solution provided by the present invention, a firmware encryption method and system based on device unique identifier and dynamic key verification are provided. First, the unique identifier of the device that cannot be modified can be obtained, and further a dynamic key is generated based on the unique identifier and a random number. Among them, the dynamic key is implemented through an encryption algorithm and is regenerated each time the device is started or the firmware is updated. Even if an attacker copies the hardware circuit, due to the lack of the unique identifier of the original device, a matching dynamic key cannot be generated, resulting in the firmware being unable to run on other devices, thereby achieving the effect of preventing hardware cloning. Further, by storing the dynamic key in a hardware-protected storage area, the storage area is protected by both hardware isolation and logical encryption, and the dynamic key is regenerated when the device is started and compared with the dynamic key stored in the storage area for verification. If they are consistent, the firmware is allowed to run, otherwise a security response mechanism is triggered. By binding the dynamic key to the hardware, even if the firmware is extracted and burned into other devices, the system cannot run due to the failure of key verification, thereby achieving the effect of preventing firmware transplantation. In addition, the temporariness and randomness of the dynamic key can also avoid the long-term exposure risk of traditional static keys and increase the difficulty of cracking. In summary, the technical solution in the present invention can systematically solve the core problems of easy leakage of static keys, poor portability of hardware cloning, and high risk of side-channel attacks in the prior art by deeply binding the dynamic key with hardware uniqueness, physically / logically double-protecting the key storage, and replacing the external chip with an internal security module, and can improve the security and reliability of firmware protection.

[0035] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. Other features and advantages of the present application will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0037] Figure 1 It is a schematic flow chart of a firmware encryption method based on device unique identifier and dynamic key verification provided for the embodiments of the present application;

[0038] Figure 2Schematic diagram of the system structure of a firmware encryption system based on device unique identifier and dynamic key verification provided by an embodiment of the present application;

[0039] Figure 3 Schematic diagram of the structure of an electronic device according to an embodiment provided by the present invention is shown. Detailed implementation manners

[0040] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0041] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0042] Currently, in the existing technology, static keys or encryption schemes based on a single device identifier are mostly adopted for firmware protection. Taking the patent CN110737448B as an example, it uses a static key and a firmware matching verification mechanism, which ensures the firmware security to a certain extent and realizes functions such as internal firmware checksum and upgrade verification in the system. However, there are many problems that cannot be ignored in such schemes. First of all, the static key remains unchanged for a long time. Once it is leaked, attackers can easily crack the encrypted data and bypass the security protection mechanism, resulting in the collapse of the firmware security defense line. Secondly, in the face of hardware cloning behavior, due to the lack of a mechanism deeply bound to the hardware, even if the hardware circuit is copied, it is impossible to prevent the firmware from running on the new device, that is, there is a problem of portability of hardware cloning, which makes it difficult to effectively protect the intellectual property rights of enterprises. Moreover, some existing technologies rely on external encryption chips. Although the encryption effect is enhanced to a certain extent, new risks are brought. On the one hand, the external encryption chip increases the device cost; on the other hand, this chip is vulnerable to side-channel attacks during operation. For example, attackers can perform power analysis, use a high-precision current sensor to measure the power consumption changes of different operations of the chip during encryption operations, and infer the key in combination with the algorithm; or perform electromagnetic radiation analysis, use an electromagnetic probe to capture different electromagnetic radiation patterns generated when the chip is working to obtain key information; they can also perform execution time analysis, accurately measure the time difference of different operations executed by the encryption chip to infer the key, and then illegally copy the firmware and tamper with the data, seriously threatening the system security and causing economic losses.

[0043] Therefore, the following technical problems exist in the existing technology:

[0044] 1. Static keys are easy to crack;

[0045] 2. Portability of hardware cloning;

[0046] 3. Relying on external encryption chips, increasing costs and being vulnerable to side-channel attacks.

[0047] Among them, side-channel attack refers to the act of not directly cracking the mathematical principle of the encryption algorithm itself, but inferring the encryption key or sensitive data by collecting some additional information (i.e., side-channel information) leaked during the operation of the encryption device. These side-channel information usually includes physical characteristics such as the power consumption, electromagnetic radiation, execution time, and sound of the device. The harm brought by side-channel attacks: Once the attacker obtains the key of the encryption chip through side-channel attacks, they can easily crack the encrypted data and bypass the security protection mechanism of the system. In the scenario of embedded system firmware protection, this means that attackers can illegally copy the firmware, tamper with the data, and even control the entire system, thus causing serious security threats and economic losses.

[0048] The reasons for being vulnerable to side-channel attacks in the scenario of relying on an external encryption chip are as follows:

[0049] Power consumption analysis: When the external encryption chip performs encryption operations, different operations (such as different key-bit operations) consume different amounts of power. An attacker can use a high-precision current sensor to measure the power consumption changes of the chip, and then by analyzing these power consumption curves, combined with specific algorithms and technologies, infer the key being used by the chip. For example, when the chip processes a certain bit of the key as "0" or "1", there may be subtle but detectable differences in its power consumption, and the attacker can use these differences to gradually crack the key.

[0050] Electromagnetic radiation analysis: The chip generates electromagnetic radiation when working, and different operation operations generate different electromagnetic radiation patterns. An attacker can use an electromagnetic probe to capture these radiation signals and analyze them. For example, certain encryption algorithms generate characteristic electromagnetic radiation within a specific frequency range when processing specific data, and the attacker can obtain information about the key or the encryption process by identifying these characteristics.

[0051] Execution time analysis: The execution time of the encryption operation may be affected by the key or input data. An attacker can accurately measure the time taken by the encryption chip to perform different operations and analyze the time differences to infer key information. For example, if the encryption algorithm processes some key values faster than others, the attacker can narrow down the possible range of the key by measuring the execution time multiple times.

[0052] To solve the above technical problems, the inventive concept of this application is: By deeply binding the dynamic key with the hardware uniqueness, providing dual physical / logical protection for key storage, and replacing the external chip with a built-in security module, the core problems of easy leakage of static keys, poor portability of hardware cloning, and high risk of side-channel attacks in the prior art can be systematically solved, and the security and reliability of firmware protection can be improved.

[0053] After introducing the application scenarios of the embodiments of this application, the technical solutions of this application will be elaborated in detail below:

[0054] Figure 1 It is a flowchart of a firmware encryption method based on device unique identifier and dynamic key verification provided for the embodiments of this application. As Figure 1 shown, the method may include the following steps:

[0055] Step 110, obtain the unique identifier of the device, and the unique identifier is non-modifiable hardware feature information.

[0056] For the embodiments of the present disclosure, when obtaining the unique identifier of a device, as a possible implementation, a program for reading the unique identifier can be written in the firmware startup code. For example, for the serial number of a chip Read-Only Memory (ROM), it is obtained through specific register read instructions; for the physical fingerprint generated by a Physical Unclonable Function (PUF), it is read through the PUF interface circuit. The read unique identifier is stored in the system as a global variable or constant and serves as the basic parameter for subsequent dynamic key generation.

[0057] For the embodiments of the present disclosure, when obtaining the unique identifier of a device, as another possible implementation, during the device production stage, a unique two-dimensional code or bar code can be generated for each device and pasted or etched on the device surface. At the same time, the corresponding identification information is recorded in a database. When the system reads, a code scanning device (such as a camera) is used to read the two-dimensional code or bar code information and transmit it to the system as the unique identifier.

[0058] For the embodiments of the present disclosure, when obtaining the unique identifier of a device, as yet another possible implementation, when the device is first connected to the network, it can send a registration request to the server. The server assigns a unique identifier to the device according to certain rules and stores it in the database in association with the device's hardware information (such as the Media Access Control (MAC) address, etc.). The device stores the received identifier locally and subsequently uses this unique identifier for operations such as key generation.

[0059] Correspondingly, for the embodiments of the present disclosure, the embodiment steps may include: writing a program for reading the device unique identifier in the firmware startup code, and when the device starts up, using the reading program to read the unique identifier of the device from the hardware module; or, when the device starts up, using a code scanning device to read the two-dimensional code or bar code information set on the device surface and using it as the unique identifier of the device; or, when the device is first connected to the network, sending a registration request to the server and receiving the unique identifier feedback by the server to the device. The unique identifier is assigned to the device by the server in response to the registration request according to a preset rule and is stored in association with the device's hardware information. Among them, the hardware module can be a chip ROM, a PUF circuit, etc., and the hardware information can be a MAC address, a serial number, etc.

[0060] For the first optional method described above, the built-in identifier of the chip or the PUF technology is not affected by the external environment, can stably provide a unique identifier, is difficult to be copied and tampered with, is not affected by the external environment, and can stably provide a unique identifier. Even if an attacker copies the hardware circuit, they will not be able to generate a matching dynamic key due to the lack of the unique identifier of the original device, resulting in the firmware being unable to run on other devices, thereby achieving the effect of preventing hardware cloning. For the second optional method described above, the advantage is that it is simple to implement, does not require relying on the built-in identifier of a specific chip, and has a relatively low cost. However, the disadvantage is that it is easy to be copied and tampered with, and the security is relatively low. Moreover, the two-dimensional code or barcode may not be able to be read normally due to reasons such as wear and dirt. For the third optional method described above, the advantage lies in that it can achieve centralized management and dynamic allocation of identifiers, but the device needs to have an Internet connection function and relies on the stability of the server. Therefore, for the embodiments of the present disclosure, when obtaining the unique identifier of the device, the first optional solution described above is preferably used.

[0061] In a specific application scenario, the unique identifier of the device read by the reading program includes the chip ROM serial number or the physical fingerprint generated by the physically unclonable function PUF. Correspondingly, when the device is started, using the reading program to read the unique identifier of the device from the hardware module may include: adding a register reading instruction in the reading program for reading the chip ROM serial number from the chip ROM by executing the register reading instruction when the device is started; or integrating the PUF interface call logic in the reading program for reading the physical fingerprint generated by the PUF based on the PUF interface call logic when the device is started.

[0062] Step 120: Generate a dynamic key based on the unique identifier and a random number, where the dynamic key is implemented through an encryption algorithm and is regenerated each time the device is started or the firmware is updated.

[0063] In a specific application scenario, the random number can obtain the real-time clock value through the real-time clock module as part of the random number; or the hardware entropy source, such as thermal noise, oscillator jitter, etc., can be used, and through a dedicated circuit, it is converted into a digital random number. Correspondingly, the steps of the embodiment may include: obtaining the real-time clock value through the real-time clock module and using the real-time clock value as the random number; or obtaining the hardware entropy source and converting the random information contained in the hardware entropy source into a random number. Through this method of generating the dynamic key, it is possible to ensure the temporariness and randomness of the dynamic key, avoid the long-term exposure risk of the traditional static key, and increase the difficulty of cracking.

[0064] Among them, the encryption algorithm can be AES-256 or a hash function. When generating a dynamic key using the encryption algorithm and the encryption algorithm is AES-256, as a possible implementation, the code can be written to implement the generation process of the dynamic key according to the example algorithm "dynamic key = AES-256(UID⊕random number, timestamp)". "⊕" represents the exclusive OR operation. When the binary bits corresponding to the unique identifier of the device and the random number are the same, the result of "UID⊕random number" is 0; when they are different, the result of "UID⊕random number" is 1; UID is the unique identifier of the device. The following is a simplified pseudo-code example:

[0065] import aes# Assume there is an AES encryption library

[0066] # Get the unique identifier of the device

[0067] UID = read_device_identifier()

[0068] # Get the random number

[0069] random_number = get_random_number()

[0070] # Get the timestamp

[0071] timestamp = get_timestamp()

[0072] # Exclusive OR operation

[0073] xor_result = UID^random_number

[0074] # Generate the dynamic key

[0075] dynamic_key = aes.encrypt(xor_result, timestamp, key_size = 256)

[0076] When generating a dynamic key using the encryption algorithm and the encryption algorithm is a hash function, as another possible implementation, a hash function (such as SHA-256) can be used for key generation. The example algorithm can be "dynamic key = SHA-256(UID||random number||timestamp)", where "||" represents string concatenation, and UID is the unique identifier of the device. The following is a simplified pseudo-code example:

[0077] import hashlib

[0078] # Get the unique identifier of the device

[0079] UID = read_device_identifier()

[0080] # Obtain a random number

[0081] random_number = get_random_number()

[0082] # Obtain a timestamp

[0083] timestamp = get_timestamp()

[0084] # Concatenate strings

[0085] input_string = str(UID) + str(random_number) + str(timestamp)

[0086] # Generate a dynamic key

[0087] dynamic_key = hashlib.sha256(input_string.encode()).hexdigest()

[0088] For the above two encryption algorithms, AES-256 is a symmetric encryption algorithm. The key length and encryption mode can be adjusted according to different requirements, which has higher security and can effectively resist various attack methods. Although the hash function has a fast calculation speed, once the key is leaked, there is a risk of information being cracked. Moreover, the output length of the hash function is fixed, with poor flexibility. Therefore, in the steps of this embodiment, it is preferably to use the AES-256 encryption algorithm to generate the dynamic key.

[0089] Step 130: Store the dynamic key in a hardware-protected storage area, and the storage area is protected by both hardware isolation and logical encryption.

[0090] Among them, hardware isolation is implemented through the Memory Protection Unit (MPU), and logical encryption is implemented through the configuration of the Flash write protection bit.

[0091] In a specific application scenario, when storing the dynamic key, as a possible implementation method, for the STM32 chip, the generated dynamic key can be written to the Flash address 0x08040000. Use the Flash programming interface of the chip in the code to write the key data to the specified address. In addition, the MPU memory protection unit can also be configured to set the access permission of this storage area, allowing only the verification execution module to access. At the same time, enable the Flash write protection bit to prevent external illegal writing to this area.

[0092] As yet another possible alternative, key storage and verification based on blockchain can be adopted. Specifically, the generated dynamic key can be stored on the blockchain, and the immutability and distributed storage characteristics of the blockchain are utilized to ensure the security and integrity of the key. When the device starts verification, the device queries the blockchain node for the stored key and compares the newly generated dynamic key with the key stored on the blockchain.

[0093] For the first optional method mentioned above, writing the dynamic key into the protected storage area of the chip and only allowing the verification execution module to access it can effectively prevent external reading or tampering. Only Flash storage and configuration of the MPU memory protection unit are required on the device's chip, without relying on a complex blockchain network, which can reduce the implementation cost and complexity. For the second optional method mentioned above, the advantage of this method lies in its high security and credibility, but it requires the support of a blockchain network, with a relatively high implementation complexity and possible certain latency. Therefore, the first optional method is preferably adopted to store the dynamic key. In this way, the key storage and verification process are completed on the local device, without the need to communicate with the blockchain node, with a faster response speed, and can meet application scenarios with high real-time requirements.

[0094] Step 140: Regenerate the dynamic key when the device starts, and compare and verify it with the dynamic key stored in the storage area. If they are consistent, the firmware is allowed to run; otherwise, trigger the security response mechanism.

[0095] For the embodiments of the present disclosure, when the newly generated dynamic key at device startup is consistent with the dynamic key stored in the storage area (i.e., the unique identifiers are the same), the firmware can be allowed to jump to the application program for execution; when the newly generated dynamic key at device startup is inconsistent with the dynamic key stored in the storage area (i.e., the unique identifiers are different), the security response mechanism can be triggered. Among them, the security response mechanism can include at least one of system suspension, self-destruction program, or clearing of critical data, or may also include other executable security response measures, which are not specifically limited herein.

[0096] For the embodiments of the present disclosure, the previously stored dynamic key can be read from the secure storage area, and the newly generated dynamic key is compared with the stored dynamic key for the unique identifier. The following is a simplified pseudo-code example:

[0097] # Regenerate the dynamic key

[0098] new_dynamic_key = generate_dynamic_key()

[0099] # Read the stored dynamic key

[0100] stored_key = read_stored_key()

[0101] # Compare keys

[0102] if new_dynamic_key == stored_key:

[0103] jump_to_application() # Allow jumping to the application for execution

[0104] else:

[0105] trigger_self_destruct() # Trigger the system suspension or self-destruction mechanism

[0106] In summary, according to the firmware encryption method based on device unique identifier and dynamic key verification provided by this application, first, the non-modifiable unique identifier of the device can be obtained, and further, a dynamic key is generated based on the unique identifier and a random number. Among them, the dynamic key is implemented through an encryption algorithm and is regenerated each time the device starts or the firmware is updated. Even if an attacker copies the hardware circuit, due to the lack of the unique identifier of the original device, a matching dynamic key cannot be generated, resulting in the firmware being unable to run on other devices, thereby achieving the effect of preventing hardware cloning. Further, by storing the dynamic key in a hardware-protected storage area, the storage area is protected by both hardware isolation and logical encryption, and the dynamic key is regenerated when the device starts and compared with the dynamic key stored in the storage area for verification. If they are consistent, the firmware is allowed to run; otherwise, a security response mechanism is triggered. By binding the dynamic key to the hardware, even if the firmware is extracted and burned into other devices, the system cannot run due to the failure of key verification, thereby achieving the effect of preventing firmware transplantation. In addition, the temporariness and randomness of the dynamic key can also avoid the long-term exposure risk of traditional static keys and increase the difficulty of cracking. In summary, the technical solution in the present invention can systematically solve the core problems of easy leakage of static keys, poor portability of hardware cloning, and high risk of side-channel attacks in the prior art by deeply binding the dynamic key with the hardware uniqueness, physically / logically double-protecting the key storage, and replacing the external chip with the built-in security module, and can improve the security and reliability of firmware protection.

[0107] Figure 2 FIG. is a schematic structural diagram of a firmware encryption system based on device unique identifier and dynamic key verification provided by an embodiment of the present invention. This system can execute the firmware encryption method based on device unique identifier and dynamic key verification as Figure 1 shown. As Figure 2As shown in the figure, the system may include: a unique identification module 21, a dynamic key generation module 22, a secure storage module 23, and a verification execution module 24; the unique identification module 21 is connected to the device and is used to obtain and store an unmodifiable unique identifier of the device; the dynamic key generation module 22 is connected to the unique identification module 21 and is used to generate a dynamic key based on the unique identifier and a random number, wherein the dynamic key is implemented through an encryption algorithm and is regenerated each time the device is started or the firmware is updated; the secure storage module 23 is connected to the dynamic key generation module 22 and is used to store the dynamic key through a dual protection mechanism of hardware isolation and logical encryption; the verification execution module 24 is connected to the dynamic key generation module 22 and the secure storage module 23 and is used to regenerate the dynamic key when the device is started and compare and verify it with the stored dynamic key, and control the running permission of the firmware on the device according to the comparison and verification result. Among them, the storage address of the secure storage module is a protected fixed area in the chip Flash, and only the verification execution module is allowed to access it.

[0108] In summary, according to the firmware encryption system based on device unique identification and dynamic key verification provided by the present invention, by deeply binding the dynamic key with hardware uniqueness, physically / logically double protecting the key storage, and replacing the external chip with the built-in security module, the core problems of easy leakage of static keys, poor portability of hardware cloning, and high risk of side-channel attacks in the prior art can be systematically solved, and the security and reliability of firmware protection can be improved.

[0109] Regarding the firmware encryption system based on device unique identification and dynamic key verification in the above embodiments, the specific manners of operations performed by each module have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0110] In the foregoing, the firmware encryption system based on device unique identifier and dynamic key verification according to the embodiments of the present invention has been described from the perspective of functional modules in conjunction with the accompanying drawings. It should be understood that the functional modules can be implemented in the form of hardware, or in the form of instructions in software, or in a combination of hardware and software modules. Specifically, the steps of the firmware encryption method embodiment based on device unique identifier and dynamic key verification in the embodiments of the present invention can be completed by the integrated logic circuit in hardware in the processor and / or instructions in the form of software. The steps of the firmware encryption method based on device unique identifier and dynamic key verification invented in conjunction with the embodiments of the present invention can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps in the firmware encryption method embodiment based on device unique identifier and dynamic key verification described above.

[0111] Figure 3 FIG. 4 is a schematic block diagram of an electronic device 300 according to an embodiment provided by the present invention.

[0112] As Figure 3 shown, the electronic device 300 may include:

[0113] A memory 310 and a processor 320. The memory 310 is used to store a computer program and transmit the program code to the processor 320. In other words, the processor 320 can call and run the computer program from the memory 310 to implement the method in the embodiments of the present invention.

[0114] For example, the processor 320 can be used to execute the above method embodiment according to the instructions in the computer program.

[0115] In some embodiments of the present invention, the processor 320 may include, but is not limited to:

[0116] A general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and the like.

[0117] In some embodiments of the present invention, the memory 310 includes, but is not limited to:

[0118] Volatile memory and / or non-volatile memory. Among them, the non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically Erasable PROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synch link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0119] In some embodiments of the present invention, the computer program can be divided into one or more modules, which are stored in the memory 310 and executed by the processor 320 to complete the method provided by the present invention. The one or more modules can be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the computer program in the controller.

[0120] As Figure 3 shown, the electronic device 300 may further include:

[0121] A transceiver 330, which can be connected to the processor 320 or the memory 310.

[0122] Among them, the processor 320 can control the transceiver 330 to communicate with other devices. Specifically, it can send information or data to other devices, or receive information or data sent by other devices. The transceiver 330 can include a transmitter and a receiver. The transceiver 330 may further include an antenna, and the number of antennas can be one or more.

[0123] It should be understood that the various components in the electronic device are connected through a bus system. Among them, the bus system includes, in addition to the data bus, a power bus, a control bus, and a status signal bus.

[0124] The present invention also provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a computer, the computer can execute the methods in the above method embodiments. Or rather, an embodiment of the present invention also provides a computer program product containing instructions. When the instructions are executed by a computer, the computer executes the methods in the above method embodiments.

[0125] When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access, or a data storage device such as a server or data center that contains one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a Digital Video Disc (DVD)), or a semiconductor medium (such as a Solid State Disk (SSD)), etc.

[0126] Those of ordinary skill in the art can realize that the modules and algorithm steps of the examples described in combination with the embodiments invented herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0127] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the devices or modules can be in electrical, mechanical, or other forms.

[0128] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules, that is, they can be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. For example, in each embodiment of the present invention, the functional modules can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.

[0129] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A firmware encryption method based on device unique identifier and dynamic key verification, characterized in that including: Obtaining a unique identifier of the device, where the unique identifier is non-modifiable hardware feature information; Generating a dynamic key based on the unique identifier and a random number, where the dynamic key is implemented through an encryption algorithm and is regenerated each time the device is started or the firmware is updated; Storing the dynamic key in a hardware-protected storage area, where the storage area is protected by both hardware isolation and logical encryption; Regenerating the dynamic key when the device is started and performing comparison verification of the unique identifier with the dynamic key stored in the storage area. If they are consistent, the firmware is allowed to run; otherwise, a security response mechanism is triggered.

2. The firmware encryption method based on device unique identifier and dynamic key verification according to claim 1, characterized in that, The obtaining of the unique identifier of the device includes: Writing a reading program for the device unique identifier in the firmware startup code, and when the device is started, using the reading program to read the unique identifier of the device from a hardware module; or, When the device is started, using a scanning device to read the QR code or barcode information set on the surface of the device and using it as the unique identifier of the device; or, When the device is first connected to the network, sending a registration request to the server and receiving the unique identifier feedback by the server to the device. The unique identifier is allocated by the server for the device according to a preset rule after responding to the registration request and is associated with the hardware information of the device for storage.

3. The firmware encryption method based on device unique identifier and dynamic key verification according to claim 2, wherein The unique identifier of the device read through the reading program includes the chip ROM serial number or the physical fingerprint generated by a physical unclonable function (PUF); The reading of the unique identifier of the device from the hardware module using the reading program when the device is started includes: Adding a register reading instruction in the reading program for reading the chip ROM serial number from the chip ROM by executing the register reading instruction when the device is started; or, Integrating PUF interface call logic in the reading program for reading the physical fingerprint generated by the PUF based on the PUF interface call logic when the device is started.

4. The firmware encryption method based on device unique identifier and dynamic key verification according to claim 1, characterized in that Before generating the dynamic key based on the unique identifier and the random number, the method further includes: Obtaining a real-time clock value through a real-time clock module and using the real-time clock value as the random number; or, Obtaining a hardware entropy source and converting the random information contained in the hardware entropy source into the random number.

5. The firmware encryption method based on device unique identifier and dynamic key authentication according to claim 1, wherein The encryption algorithm is AES-256 or a hash function.

6. The firmware encryption method based on device unique identifier and dynamic key authentication according to claim 1, characterized in that, The hardware isolation is implemented through a memory protection unit (MPU), and the logical encryption is implemented through Flash write protection bit configuration.

7. The firmware encryption method based on device unique identifier and dynamic key authentication according to claim 1, wherein The security response mechanism includes at least one of system suspension, self-destruction program, or clearing of critical data.

8. A firmware encryption system based on device unique identifier and dynamic key verification, characterized in that, including: A unique identification module for obtaining and storing a non-modifiable unique identifier of the device; A dynamic key generation module for generating a dynamic key based on the unique identifier and a random number, where the dynamic key is implemented through an encryption algorithm and is regenerated each time the device is started or the firmware is updated; A secure storage module configured to store the dynamic key through a dual protection mechanism of hardware isolation and logical encryption; The verification execution module is used to regenerate a dynamic key when the device starts up, compare and verify it with the stored dynamic key, and control the running permission of the firmware according to the comparison and verification result.

9. The firmware encryption system based on device unique identifier and dynamic key authentication according to claim 8, wherein, The storage address of the secure storage module is a protected fixed area in the chip Flash, and only the verification execution module is allowed to access it.

10. An electronic device, characterized in that, It includes: A processor and a memory. The memory is used to store computer programs, and the processor is used to call and run the computer programs stored in the memory to execute the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • A firmware encryption system incorporating a microcontroller and its firmware protection and upgrade method

    CN110737448B

Cited By

  • Firmware security updating method and device for Internet of Things equipment

    CN120653283A

  • Multi-encryption-based ship cargo data processing method and system

    CN120750638A

  • System and method for safely starting industrial personal computer under hardware identification

    CN121262256A

  • Memory encryption method and device, electronic equipment and readable storage medium

    CN121705208A

  • Equipment authentication and key derivation method based on FPGA physical binding and electronic equipment

    CN122333442A