Embedded power equipment firmware integrity verification method and device, electronic equipment and storage medium

By chunking and distributed storage of the firmware of embedded power equipment, building a hash tree and calculating hash value, the problem of low firmware integrity verification efficiency for embedded power equipment is solved, and efficient firmware integrity verification and system response speed is achieved.

CN120491895APending Publication Date: 2025-08-15CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510556188.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, the firmware integrity verification efficiency of embedded power equipment is low, and it is impossible to effectively guarantee the reliability of the equipment and the safety of the power system.

Method used

By chunking and distributing storage of embedded power equipment, a hash tree is built, the hash value of each distributed node is calculated and spliced into a target hash value, and consistency verification is performed to determine firmware integrity.

Benefits of technology

It realizes efficient firmware integrity verification, avoids the pressure of centralized processing, improves verification efficiency and system response speed, and solves efficiency bottlenecks in large-scale and heterogeneous network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120491895A_ABST
    Figure CN120491895A_ABST
Patent Text Reader

Abstract

The invention discloses an embedded power equipment firmware integrity verification method and device, electronic equipment and a storage medium. The method comprises the following steps: partitioning firmware of the embedded power equipment to obtain a plurality of firmware data blocks corresponding to the firmware of the embedded power equipment; performing distributed storage on a plurality of firmware data blocks corresponding to firmware of the embedded power equipment to obtain a firmware data block set corresponding to a plurality of distributed nodes; for each distributed node, determining a hash value of a root node of a hash tree corresponding to the firmware data block set; and splicing the hash values of the root nodes of the hash tree corresponding to the firmware data block sets corresponding to the plurality of distributed nodes to obtain a target hash value of the firmware of the embedded power equipment, and performing consistency verification on the target hash value to obtain a firmware integrity verification result. According to the technical scheme, through distributed storage and distributed calculation of the hash value, the firmware integrity verification efficiency of the embedded power equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power systems, and in particular to a method, device, electronic device and storage medium for checking the integrity of firmware of an embedded power device. Background Art

[0002] With the proliferation of the Internet of Things (IoT) and embedded systems, inter-device communication and firmware management have become increasingly complex, particularly in power systems. Embedded devices in power systems are often distributed across a wide geographical area, performing critical tasks ranging from data acquisition and control to remote operation, ensuring stable power system operation. However, with the surge in the number of embedded power devices, effectively managing and ensuring the security and integrity of their firmware has become a core issue that needs to be addressed.

[0003] Firmware is the core code that executes tasks in embedded power devices. Its integrity is directly related to device reliability and the safety of the power system. Firmware integrity issues typically refer to the risk of firmware being tampered with, damaged, or replaced during operation. Once the firmware is tampered with or damaged, the embedded power device will not function properly and may even cause serious safety incidents.

[0004] In the process of implementing the present invention, it was found that there are at least the following technical problems in the prior art: the existing firmware integrity verification technical solution has the problem of low verification efficiency. Summary of the Invention

[0005] The present invention provides a method and device for checking the integrity of firmware of an embedded power device, an electronic device and a storage medium, so as to solve the problem of low efficiency of checking the integrity of firmware of the embedded power device.

[0006] According to one aspect of the present invention, a method for checking the integrity of firmware of an embedded power device is provided, comprising:

[0007] Dividing the firmware of the embedded power device into blocks to obtain a plurality of firmware data blocks corresponding to the firmware of the embedded power device;

[0008] Distributedly storing a plurality of firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to a plurality of distributed nodes;

[0009] For each distributed node, determine the hash value of the root node of the hash tree corresponding to the firmware data block set;

[0010] Concatenating hash values of root nodes of hash trees corresponding to firmware data block sets corresponding to multiple distributed nodes to obtain a target hash value of the firmware of the embedded power device;

[0011] The target hash value of the firmware of the embedded power device is subjected to consistency verification to obtain a firmware integrity verification result.

[0012] According to another aspect of the present invention, there is provided an apparatus for checking the integrity of firmware of an embedded power device, comprising:

[0013] An electric power equipment firmware block module is used to block the firmware of the embedded electric power equipment to obtain multiple firmware data blocks corresponding to the firmware of the embedded electric power equipment;

[0014] A data block distributed storage module is used to perform distributed storage on a plurality of firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to a plurality of distributed nodes;

[0015] A hash tree root node hash value determination module, configured to determine, for each distributed node, a hash value of a root node of a hash tree corresponding to a set of firmware data blocks;

[0016] A root node hash value splicing module is used to splice the hash values of the root nodes of the hash tree corresponding to the firmware data block sets corresponding to the multiple distributed nodes to obtain a target hash value of the firmware of the embedded power device;

[0017] The hash value consistency verification module is used to perform consistency verification on the target hash value of the firmware of the embedded power device to obtain a firmware integrity verification result.

[0018] According to another aspect of the present invention, an electronic device is provided, comprising:

[0019] at least one processor;

[0020] and a memory communicatively coupled to the at least one processor;

[0021] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the embedded power device firmware integrity verification method described in any embodiment of the present invention.

[0022] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the embedded power device firmware integrity verification method according to any embodiment of the present invention when executed.

[0023] The technical solution of the embodiment of the present invention is to obtain multiple firmware data blocks corresponding to the firmware of the embedded power device by dividing the firmware of the embedded power device into blocks, and then distribute the multiple firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to multiple distributed nodes; for each distributed node, determine the hash value of the root node of the hash tree corresponding to the set of firmware data blocks, and then splice the hash values of the root nodes of the hash tree corresponding to the sets of firmware data blocks corresponding to the multiple distributed nodes to obtain the target hash value of the firmware of the embedded power device, and then perform consistency verification on the target hash value of the firmware of the embedded power device to obtain the firmware integrity verification result. The above technical solution avoids the pressure of centralized processing of all firmware data through distributed storage and distributed calculation of hash values, realizes parallel calculation of multiple nodes, and thus improves the efficiency of firmware integrity verification of embedded power devices.

[0024] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0026] Figure 1 This is a flowchart of a method for checking the integrity of firmware of an embedded power device provided in accordance with the first embodiment of the present invention;

[0027] Figure 2 This is a flowchart of a method for checking the integrity of firmware of an embedded power device provided in accordance with a second embodiment of the present invention;

[0028] Figure 3 This is a flow chart of a method for checking the integrity of firmware of an embedded power device provided in an embodiment of the present invention;

[0029] Figure 4 2 is a schematic structural diagram of a device for checking the integrity of firmware of an embedded power device according to a third embodiment of the present invention;

[0030] Figure 5 The present invention is a schematic structural diagram of an electronic device for implementing the method for checking the integrity of firmware of an embedded power device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0031] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices. The acquisition, storage, use, processing, etc. of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.

[0033] Example 1

[0034] Figure 1 This is a flowchart of a method for checking the integrity of embedded power equipment firmware provided by the first embodiment of the present invention. This embodiment is applicable to the case of checking the firmware of embedded equipment in a large-scale power system. The method can be executed by an embedded power equipment firmware integrity checking device. The embedded power equipment firmware integrity checking device can be implemented in the form of hardware and / or software. The embedded power equipment firmware integrity checking device can be configured in electronic equipment such as distributed power systems. Figure 1 As shown, the method includes:

[0035] S110 , dividing the firmware of the embedded power device into blocks to obtain a plurality of firmware data blocks corresponding to the firmware of the embedded power device.

[0036] In the embodiments of the present invention, a power system refers to an embedded power system based on a distributed soft bus and may include multiple embedded power devices. The embedded power devices may be smart meters, substation automation equipment, distribution automation equipment, or power line carrier communication equipment, among others, without specific limitations herein. Firmware data blocks refer to data blocks obtained by partitioning the firmware of the embedded power device, and there may be multiple firmware data blocks.

[0037] Optionally, the firmware of the embedded power device includes a code area, a configuration area, a resource area, and a log and metadata area; accordingly, the firmware of the embedded power device is divided into blocks, including: for the code area, based on the first block size rule, the code area of the firmware of the embedded power device is divided into blocks; for the configuration area, based on the second block size rule, the configuration area of the firmware of the embedded power device is divided into blocks; for the resource area, based on the third block size rule, the resource area of the firmware of the embedded power device is divided into blocks; for the log and metadata area, based on the fourth block size rule, the log and metadata area of the firmware of the embedded power device is divided into blocks.

[0038] The code area is the firmware area containing the core program code. The configuration area is the firmware area containing content such as device configuration files and parameter settings. The resource area is the firmware area containing files such as images, audio, and icons. The log and metadata area is the firmware area that stores operation logs, version information, and diagnostic information.

[0039] Exemplarily, the first block size rule may be that the code area of the firmware may be divided into multiple data blocks with a size ranging from 16KB to 32KB, the second block size rule may be that the configuration area of the firmware may be divided into multiple data blocks with a size ranging from 4KB to 8KB, the third block size rule may be that the resource area of the firmware may be divided into multiple data blocks with a size ranging from 8KB to 16KB, and the fourth block size rule may be that the log and metadata area of the firmware may be divided into multiple data blocks with a size of 4KB or 8KB.

[0040] S120: Distributedly store multiple firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to multiple distributed nodes.

[0041] In an embodiment of the present invention, each firmware data block can be stored on multiple distributed nodes, that is, each distributed node is responsible for storing a portion of the firmware data blocks. A firmware data block set can include multiple firmware data blocks. In other words, each distributed node can store a portion of a firmware data block set consisting of multiple firmware data blocks.

[0042] It should be noted that by distributing the storage of multiple firmware data blocks corresponding to the firmware of embedded power equipment, the bottleneck caused by centralized storage can be avoided, the storage burden of the power system can be effectively reduced, and the scalability of the power system can be improved.

[0043] S130 . For each distributed node, determine the hash value of the root node of the hash tree corresponding to the firmware data block set.

[0044] In an embodiment of the present invention, a hash value of each firmware data block under the distributed node is obtained by performing a hash calculation on each firmware data block in the firmware data block set of the distributed node, and then a hash tree is constructed according to the hash value of each firmware data block under the distributed node, thereby obtaining the hash value of the root node of the hash tree of the distributed node, wherein the root node is the only node at the top level of the hash tree, and the hash value of the root node of the hash tree of the distributed node is used to characterize the integrity of the firmware stored in the distributed node.

[0045] S140 , concatenating hash values of root nodes of hash trees corresponding to firmware data block sets corresponding to multiple distributed nodes to obtain a target hash value of the firmware of the embedded power device.

[0046] Specifically, based on a preset order, the hash values of the root nodes of the hash trees corresponding to each distributed node are connected in sequence to obtain a target hash value of the firmware of an embedded power device, wherein the preset order can be a node arrangement order from left to right or from right to left, etc., which is not specifically limited here.

[0047] S150: Perform consistency verification on the target hash value of the firmware of the embedded power device to obtain a firmware integrity verification result.

[0048] Specifically, the original hash value of the firmware of the embedded power device is obtained; if the target hash value of the firmware of the embedded power device is the same as the original hash value of the firmware of the embedded power device, the firmware integrity check result is determined to be passed; if the target hash value of the firmware of the embedded power device is not the same as the original hash value of the firmware of the embedded power device, the firmware integrity check result is determined to be failed.

[0049] The original hash value refers to the original hash value of the firmware of the embedded power device, which can be pre-calculated through similar steps to determine the target hash value.

[0050] The technical solution of the embodiment of the present invention is to obtain multiple firmware data blocks corresponding to the firmware of the embedded power device by dividing the firmware of the embedded power device into blocks, and then distribute the multiple firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to multiple distributed nodes; for each distributed node, determine the hash value of the root node of the hash tree corresponding to the set of firmware data blocks, and then splice the hash values of the root nodes of the hash tree corresponding to the sets of firmware data blocks corresponding to the multiple distributed nodes to obtain the target hash value of the firmware of the embedded power device, and then perform consistency verification on the target hash value of the firmware of the embedded power device to obtain the firmware integrity verification result. The above technical solution avoids the pressure of centralized processing of all firmware data through distributed storage and distributed calculation of hash values, realizes parallel calculation of multiple nodes, and thus improves the efficiency of firmware integrity verification of embedded power devices.

[0051] Example 2

[0052] Figure 2 A flowchart of a method for verifying the integrity of firmware of an embedded power device provided in the second embodiment of the present invention is provided. The method of this embodiment can be combined with the various optional schemes in the method for verifying the integrity of firmware of an embedded power device provided in the above embodiments. The method for verifying the integrity of firmware of an embedded power device provided in this embodiment is further optimized. Optionally, for each distributed node, determining the hash value of the root node of the hash tree corresponding to the firmware data block set includes: for each distributed node, determining the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node; merging the hash values corresponding to each firmware data block in the firmware data block set corresponding to the distributed node to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node.

[0053] like Figure 2 As shown, the method includes:

[0054] S210 , dividing the firmware of the embedded power device into blocks to obtain a plurality of firmware data blocks corresponding to the firmware of the embedded power device.

[0055] S220 , performing distributed storage on a plurality of firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to a plurality of distributed nodes.

[0056] S230 . For each distributed node, determine a hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node.

[0057] In the embodiment of the present invention, the hash algorithm for determining the hash value may be MD5, SHA-1, SHA-256, or SHA-3, etc., which is not specifically limited here.

[0058] Optionally, the firmware data block includes a firmware version number, a firmware timestamp, a device identifier and a data block size; accordingly, determining the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node includes: determining the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node based on the firmware version number, the firmware timestamp, the device identifier and the data block size.

[0059] Exemplarily, the calculation formula for determining the hash value corresponding to the firmware data block is:

[0060] H i (V,T,ID,S)=Hash(D i ||V||T||ID||S);

[0061] Among them, D i represents the i-th firmware data block in the firmware data block set; V represents the firmware version number; T represents the firmware timestamp; ID represents the device identifier; S represents the data block size; Hash(·) represents the hash calculation of the input data; H i (·) represents the hash value corresponding to the i-th firmware data block in the firmware data block set.

[0062] It should be noted that by performing multi-dimensional hash value calculation based on the above four dimensional information, it can ensure that the firmware verification is more comprehensive and accurate.

[0063] S240: Merge the hash values corresponding to each firmware data block in the firmware data block set corresponding to the distributed node to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node.

[0064] Specifically, the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node is recursively merged to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node.

[0065] Exemplarily, the hash tree construction process includes:

[0066] The hash value of the i-th firmware data block is used as the leaf node of the firmware data block, and the leaf node value is:

[0067] L i =H i (V,T,ID,S);

[0068] Furthermore, we can pair the leaf nodes in pairs and merge each pair of leaf nodes to get the parent node hash value corresponding to each pair of leaf nodes:

[0069] P i =Hash(L i ||L i+1 );

[0070] Among them, L i represents the i-th leaf node, L i+1 represents the i+1th leaf node, P i Indicates the parent node hash value corresponding to the adjacent leaf node.

[0071] Furthermore, the parent nodes corresponding to each pair of leaf nodes are paired with each other, and each pair of parent nodes is spliced and merged to form a new layer. The above pairing and merging process is repeated for the new layer until only one node remains after the merger, completing the construction of the hash tree. It should be noted that the remaining node is the root node. In other words, the hash value of the root node can be calculated by recursively merging the hash values of the upper-level nodes:

[0072] R k =Hash(P1,||P2||…||P n );

[0073] Among them, R k Represents the hash value of the root node of the hash tree corresponding to the kth distributed node.

[0074] S250 , concatenating hash values of root nodes of hash trees corresponding to firmware data block sets corresponding to multiple distributed nodes to obtain a target hash value of the firmware of the embedded power device.

[0075] S260: Perform consistency verification on the target hash value of the firmware of the embedded power device to obtain a firmware integrity verification result.

[0076] Optionally, after determining the hash value of the root node of the hash tree corresponding to the firmware data block set, the method also includes: when the firmware of the embedded power device is updated, determining the hash value corresponding to the firmware data block in the firmware update area; based on the hash value corresponding to the firmware data block in the firmware update area, updating the hash value of the root node of the hash tree corresponding to the firmware data block set.

[0077] The firmware update area is a firmware area where the firmware update occurs, and may be one or more of a code area, a configuration area, a resource area, and a log and metadata area.

[0078] For example, for a firmware area, the hash value of the firmware area in the old version of the firmware is calculated, and then the hash value in the new version of the firmware is calculated. If the hash value in the new version of the firmware is not equal to the hash value in the old version of the firmware, the firmware area is determined to be a firmware update area, and an incremental update is performed on the firmware area. For one or more firmware data blocks in the firmware update area, the hash value corresponding to each firmware data block is recalculated. Furthermore, based on the recalculated hash value of each firmware data block in the firmware update area, the leaf node of the hash tree is updated, and the parent node of the leaf node is recursively updated until the root node of the hash tree is updated. This achieves a local update of the hash tree and improves the update efficiency of the hash tree.

[0079] The technical solution of the embodiment of the present invention determines the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node, and then merges the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node, thereby realizing distributed calculation of hash values, reducing the centralized calculation burden, and improving the efficiency of firmware integrity verification of embedded power equipment.

[0080] For example, Figure 3 This is a flowchart of a method for verifying the integrity of firmware for an embedded power device, according to an embodiment of the present invention. Specifically, the firmware of the embedded power device is partitioned to obtain multiple firmware data blocks corresponding to the firmware of the embedded power device. These multiple firmware data blocks corresponding to the firmware of the embedded power device are then distributed and stored to obtain a set of firmware data blocks corresponding to multiple distributed nodes. Furthermore, for each distributed node, a hash calculation is performed on the set of firmware data blocks to obtain a hash tree corresponding to the distributed node. Furthermore, the hash values of the root nodes of the hash trees corresponding to each distributed node are aggregated to a central node or a coordinating node, where the central node or coordinating node is used to aggregate, concatenate, and verify the consistency of the hash values.

[0081] Furthermore, the central node or the coordination node concatenates the hash values of the root nodes of the hash trees corresponding to the distributed nodes to obtain the target hash value of the firmware of the embedded power device. The specific calculation formula is as follows:

[0082] R final =Hash(R1||R2||…||R k );

[0083] Among them, R final Indicates the target hash value. Further, if the target hash value passes the integrity check, the check passes. If the target hash value fails the integrity check, an alarm is triggered in the power system, and firmware repair or rollback is performed.

[0084] The technical solutions of the embodiments of the present invention, through distributed storage and distributed computing, reduce the computational burden on central nodes, improving integrity verification efficiency and system response speed. Furthermore, the above-described embedded power equipment firmware integrity verification method overcomes the efficiency bottleneck of traditional centralized verification methods in large-scale and heterogeneous network environments, and achieves efficient and real-time firmware integrity verification.

[0085] Example 3

[0086] Figure 4 This is a schematic diagram of the structure of an embedded power equipment firmware integrity verification device provided by the third embodiment of the present invention. Figure 4 As shown, the device includes:

[0087] The power equipment firmware block module 310 is used to block the firmware of the embedded power equipment to obtain multiple firmware data blocks corresponding to the firmware of the embedded power equipment.

[0088] The data block distributed storage module 320 is used to perform distributed storage on the multiple firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to multiple distributed nodes;

[0089] A hash tree root node hash value determination module 330 is configured to determine, for each distributed node, a hash value of a root node of a hash tree corresponding to a set of firmware data blocks;

[0090] A root node hash value splicing module 340 is configured to splice the hash values of the root nodes of the hash trees corresponding to the firmware data block sets corresponding to the multiple distributed nodes to obtain a target hash value of the firmware of the embedded power device;

[0091] The hash value consistency verification module 350 is used to perform consistency verification on the target hash value of the firmware of the embedded power device to obtain a firmware integrity verification result.

[0092] The technical solution of the embodiment of the present invention is to obtain multiple firmware data blocks corresponding to the firmware of the embedded power device by dividing the firmware of the embedded power device into blocks, and then distribute the multiple firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to multiple distributed nodes; for each distributed node, determine the hash value of the root node of the hash tree corresponding to the set of firmware data blocks, and then splice the hash values of the root nodes of the hash tree corresponding to the sets of firmware data blocks corresponding to the multiple distributed nodes to obtain the target hash value of the firmware of the embedded power device, and then perform consistency verification on the target hash value of the firmware of the embedded power device to obtain the firmware integrity verification result. The above technical solution avoids the pressure of centralized processing of all firmware data through distributed storage and distributed calculation of hash values, realizes parallel calculation of multiple nodes, and thus improves the efficiency of firmware integrity verification of embedded power devices.

[0093] In some optional implementations, the firmware of the embedded power device includes a code area, a configuration area, a resource area, and a log and metadata area;

[0094] Accordingly, the power equipment firmware block module 310 is specifically configured to:

[0095] For the code area, based on a first block size rule, the code area of the firmware of the embedded power device is divided into blocks;

[0096] For the configuration area, dividing the configuration area of the firmware of the embedded power device into blocks based on a second block size rule;

[0097] For the resource area, dividing the resource area of the firmware of the embedded power device into blocks based on a third block size rule;

[0098] For the log and metadata area, the log and metadata area of the firmware of the embedded power device is divided into blocks based on a fourth block size rule.

[0099] In some optional implementations, the hash tree root node hash value determination module 330 includes:

[0100] a firmware data block hash value determining unit, configured to determine, for each distributed node, a hash value corresponding to each firmware data block in a firmware data block set corresponding to the distributed node;

[0101] The firmware data block hash value merging unit is used to merge the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node.

[0102] In some optional implementations, the firmware data block hash value determination unit may further be specifically configured to:

[0103] Based on the firmware version number, the firmware timestamp, the device identifier, and the data block size, a hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node is determined.

[0104] In some optional implementations, the firmware data block hash value merging unit may further be specifically configured to:

[0105] Recursively merge the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node.

[0106] In some optional implementations, the hash value consistency verification module 350 is specifically configured to:

[0107] Obtaining an original hash value of the firmware of the embedded power device;

[0108] If the target hash value of the firmware of the embedded power device is the same as the original hash value of the firmware of the embedded power device, determining that the firmware integrity check result is passed;

[0109] If the target hash value of the firmware of the embedded power device is different from the original hash value of the firmware of the embedded power device, it is determined that the firmware integrity check result is failed.

[0110] In some optional implementations, the embedded power equipment firmware integrity verification device further includes:

[0111] In the case where the firmware of the embedded power device is updated, determining a hash value corresponding to a firmware data block in a firmware update area;

[0112] Based on the hash value corresponding to the firmware data block in the firmware update area, the hash value of the root node of the hash tree corresponding to the firmware data block set is updated.

[0113] The embedded power equipment firmware integrity verification device provided by the embodiment of the present invention can execute the embedded power equipment firmware integrity verification method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0114] Example 4

[0115] Figure 5A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0116] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 and a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An I / O interface 15 is also connected to the bus 14.

[0117] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0118] The processor 11 may be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the embedded power device firmware integrity verification method, which includes:

[0119] Dividing the firmware of the embedded power device into blocks to obtain a plurality of firmware data blocks corresponding to the firmware of the embedded power device;

[0120] Distributedly storing a plurality of data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to a plurality of distributed nodes;

[0121] For each distributed node, determine the hash value of the root node of the hash tree corresponding to the firmware data block set;

[0122] Concatenating hash values of root nodes of hash trees corresponding to firmware data block sets corresponding to multiple distributed nodes to obtain a target hash value of the firmware of the embedded power device;

[0123] The target hash value of the firmware of the embedded power device is subjected to consistency verification to obtain a firmware integrity verification result.

[0124] In some embodiments, the embedded power device firmware integrity verification method can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the embedded power device firmware integrity verification method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to execute the embedded power device firmware integrity verification method in any other appropriate manner (e.g., via firmware).

[0125] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0126] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0127] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0128] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0129] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0130] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0131] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0132] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for checking the integrity of embedded power equipment firmware, characterized in that: include: Dividing the firmware of the embedded power device into blocks to obtain a plurality of firmware data blocks corresponding to the firmware of the embedded power device; Distributedly storing a plurality of firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to a plurality of distributed nodes; For each distributed node, determine the hash value of the root node of the hash tree corresponding to the firmware data block set; Concatenating hash values of root nodes of hash trees corresponding to firmware data block sets corresponding to multiple distributed nodes to obtain a target hash value of the firmware of the embedded power device; The target hash value of the firmware of the embedded power device is subjected to consistency verification to obtain a firmware integrity verification result.

2. The method according to claim 1, characterized in that The firmware of the embedded power device includes a code area, a configuration area, a resource area, and a log and metadata area; Accordingly, the firmware of the embedded power device is divided into blocks, including: For the code area, based on a first block size rule, the code area of the firmware of the embedded power device is divided into blocks; For the configuration area, dividing the configuration area of the firmware of the embedded power device into blocks based on a second block size rule; For the resource area, dividing the resource area of the firmware of the embedded power device into blocks based on a third block size rule; For the log and metadata area, the log and metadata area of the firmware of the embedded power device is divided into blocks based on a fourth block size rule.

3. The method according to claim 1, characterized in that The step of determining, for each distributed node, a hash value of a root node of a hash tree corresponding to a set of firmware data blocks includes: For each distributed node, determining a hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node; The hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node is merged to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node.

4. The method according to claim 3, characterized in that The firmware data block includes a firmware version number, a firmware timestamp, a device identifier, and a data block size; Accordingly, determining a hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node includes: Based on the firmware version number, the firmware timestamp, the device identifier, and the data block size, a hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node is determined.

5. The method according to claim 3, characterized in that The step of merging the hash values corresponding to each firmware data block in the firmware data block set corresponding to the distributed node to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node includes: Recursively merge the hash value corresponding to each firmware data block in the firmware data block set corresponding to the distributed node to obtain the hash value of the root node of the hash tree corresponding to the firmware data block set corresponding to the distributed node.

6. The method according to claim 1, characterized in that The step of performing consistency verification on a target hash value of the firmware of the embedded power device to obtain a firmware integrity verification result includes: Obtaining an original hash value of the firmware of the embedded power device; If the target hash value of the firmware of the embedded power device is the same as the original hash value of the firmware of the embedded power device, determining that the firmware integrity check result is passed; If the target hash value of the firmware of the embedded power device is different from the original hash value of the firmware of the embedded power device, it is determined that the firmware integrity check result is failed.

7. The method according to any one of claims 1 to 6, characterized in that: After determining the hash value of the root node of the hash tree corresponding to the firmware data block set, the method further includes: In the case where the firmware of the embedded power device is updated, determining a hash value corresponding to a firmware data block in a firmware update area; Based on the hash value corresponding to the firmware data block in the firmware update area, the hash value of the root node of the hash tree corresponding to the firmware data block set is updated.

8. An embedded power equipment firmware integrity verification device, characterized in that: include: An electric power equipment firmware block module is used to block the firmware of the embedded electric power equipment to obtain multiple firmware data blocks corresponding to the firmware of the embedded electric power equipment; A data block distributed storage module is used to perform distributed storage on a plurality of firmware data blocks corresponding to the firmware of the embedded power device to obtain a set of firmware data blocks corresponding to a plurality of distributed nodes; A hash tree root node hash value determination module, configured to determine, for each distributed node, a hash value of a root node of a hash tree corresponding to a set of firmware data blocks; A root node hash value splicing module is used to splice the hash values of the root nodes of the hash tree corresponding to the firmware data block sets corresponding to the multiple distributed nodes to obtain a target hash value of the firmware of the embedded power device; The hash value consistency verification module is used to perform consistency verification on the target hash value of the firmware of the embedded power device to obtain a firmware integrity verification result.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the embedded power device firmware integrity verification method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the embedded power device firmware integrity verification method according to any one of claims 1 to 7 when executed.