Safety updating method and system for engineering machinery controller
The unique identification and private key mechanism generated by the SM9 algorithm solves the problems of firmware source and terminal/software security verification in engineering machinery controller updates, and realizes a secure firmware update process.
Patent Information
- Application Number
- CN202510838083.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-09-19
AI Technical Summary
The existing technology lacks security verification of the source of engineering machinery controller firmware updates and the update control terminal/software, which poses a risk of data leakage and tampering.
The SM9 algorithm is used to generate unique identifiers for the controller and firmware update terminal/software. The legitimacy is verified through signature and encryption private keys. A secure channel is established, and a session key encryption mechanism is used to protect data transmission, ensuring the security of firmware updates.
It implements security verification of the source of updated firmware and the update control terminal/software, preventing data leakage and tampering, and ensuring the security and integrity of the firmware update process.
Smart Images

Figure CN120671148A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of vehicle-mounted controllers, and relates to a method and system for securely updating an engineering machinery controller, and specifically to a method and system for updating the firmware of an engineering machinery controller based on a national secret algorithm. Background Art
[0002] With the development of technology, electronic control devices and software-defined functions are being used more and more widely in engineering machinery control systems. The design, production, use and maintenance processes of engineering machinery require more frequent updates to controller applications.
[0003] Firmware security is the foundation of controller system security. The firmware updated by the controller can only be legitimate firmware data authorized and authenticated by its provider. Therefore, the controller update process needs to address security issues such as data leakage, data tampering, and data integrity damage.
[0004] The boot loader is solidified in the memory Flash and is the first program executed after the controller is powered on. After completing the initialization of the CPU and related hardware, it jumps to the application running starting point also solidified in the Flash and loads the application into the RAM space for execution. Its application in the field of engineering machinery controllers has become very popular.
[0005] Chinese patent application CN 116910779 A discloses a firmware burning protection method and system based on a national secret algorithm. After the secure downloader is connected to the host software, a session key is jointly established based on the unique identification information of both parties. Based on the session key, the firmware is encrypted and transmitted between the host software and the secure downloader. The secure downloader encrypts the received firmware and stores the encrypted firmware in the flash memory of the secure downloader. After the secure downloader is connected to the microcontroller, the encrypted firmware is decrypted and sent to the boot loader BSL, and the firmware is burned into the microcontroller. The unique identification information of the secure downloader and the host software is used to perform multiple encryption protections on the firmware, especially encryption of key information based on a domestic cryptographic algorithm and encryption chip, to ensure the efficiency and security of firmware transmission and burning between the host software and the microcontroller.
[0006] Chinese patent application CN 112165396 A discloses a secure firmware update method for smart cards / MCUs, including a pre-download mechanism, a ciphertext protection mechanism, and an identity verification mechanism. The pre-download mechanism filters out illegal data; the ciphertext protection mechanism protects the target data content; and the identity verification mechanism confirms the legitimacy of the data.
[0007] Although both of the above patent applications have adopted encryption measures for data transmission during the update process to ensure information security during the transmission process, they lack security verification of the update firmware source and the update control terminal / software. Summary of the Invention
[0008] The purpose of the present invention is to provide a method and system for secure updating of engineering machinery controllers, which can realize security verification of the source of updated firmware and the updated control terminal / software.
[0009] In order to solve the above technical problems, the present invention is implemented by adopting the following technical solutions.
[0010] In a first aspect, the present invention proposes a construction machinery controller security update system, comprising: a controller manufacturer, an update terminal / software, and a controller;
[0011] The controller manufacturer is used to generate a signature master key Ms and an encryption master key Me, assign a unique identifier Sid to the update terminal / software S, and assign a unique identifier Cid to the controller;
[0012] The update terminal / software is in communication with the controller, sends the software to be updated to the controller, and completes the update of the software to be updated through the upgrade program built into the controller; the update terminal / software S has a built-in signature private key Ss and encryption private key Se corresponding to the unique identifier Sid;
[0013] The controller receives the software to be updated, verifies the legitimacy of the source of the software to be updated and performs the update operation; the controller has a built-in signature private key Cs and encryption private key Ce corresponding to the unique identifier Cid.
[0014] In combination with the first aspect, further, the signature master key Ms includes a signature master private key Mspr and a signature master public key Mspu, wherein the signature master public key is made public and the signature master private key is kept secret by the controller manufacturer;
[0015] The encryption master key Me includes the encryption master private key Mepr and the encryption master public key Mepu, wherein the encryption master public key is made public and the encryption master private key is kept secret by the controller manufacturer.
[0016] In combination with the first aspect, further, the signature private key Ss is generated by the controller manufacturer using the signature master private key Msr and the unique identifier Sid of the update terminal / software, and is used for identity authentication. The message signed by the signature private key Ss is confirmed to have its source confirmed by the unique identifier Sid.
[0017] The encryption private key Se is generated by the controller manufacturer using the encryption master private key Mepr and the unique identifier Sid of the update terminal / software, and is used for key exchange to determine the session key. Data encrypted by the unique identifier Sid can be decrypted by the encryption private key Se.
[0018] In combination with the first aspect, further, the signature private key Cs is generated by the controller manufacturer using the signature master private key Mspr and the controller's unique identifier Cid, and is used for identity authentication. The message signed by the signature private key Cs can be confirmed to have a source by the unique identifier Cid.
[0019] The encryption private key Ce is generated by the controller manufacturer using the encryption master private key Mepr and the controller's unique identifier Cid, and is used for key exchange to determine the session key. Data encrypted by the unique identifier Cid is decrypted by the encryption private key Ce.
[0020] In a second aspect, the present invention provides a method for securely updating a construction machinery controller, wherein the method updates the software to be updated using the above-mentioned update system, and includes the following steps:
[0021] Step S1, preparing for the update of the software to be updated; the preparation includes the controller manufacturer assigning a unique identifier Sid to the update terminal / software, generating a signature private key Ss and an encryption private key Se; the controller manufacturer assigning a unique identifier Cid to the controller, generating a signature private key Cs and an encryption private key Ce;
[0022] Step S2: updating the software to be updated.
[0023] In conjunction with the second aspect, further, when the software to be updated is unencrypted, the pre-update preparation for the software to be updated includes:
[0024] Step S11: The controller manufacturer assigns a unique identifier Sid to the update terminal / software S, generates a signature private key Ss and an encryption private key Se, both of which are built into the update terminal / software S for release;
[0025] Step S12: The controller manufacturer assigns a unique identifier Cid to the controller, generates a signature private key Cs and an encryption private key Ce, both of which are built into the controller C and released;
[0026] Step S13: The controller manufacturer calculates the hash value of the unencrypted software to be updated and signs the hash value with the signature master private key;
[0027] Step S14: The controller manufacturer releases the unencrypted software to be updated, followed by the corresponding hash value and hash value signature.
[0028] In conjunction with the second aspect, further, when the software to be updated is encrypted, updating the software to be updated includes:
[0029] Step S21: The update terminal / software calculates the hash value of the unencrypted software to be updated and compares it with the hash value attached to the unencrypted software to be updated. If they are inconsistent, the process ends and the next step is entered if they are consistent.
[0030] Step S22: After the comparison in step S21 is passed, the update terminal / software verifies the hash value signature attached to the unencrypted software to be updated with the public signature master public key. If the verification fails, the process ends; otherwise, the process proceeds to the next step.
[0031] Step S23: After the verification in step S22 is passed, the update terminal / software signs the unique identifier Sid with the signature private key Ss according to the digital signature generation algorithm in SM9 to obtain the signature Ssid;
[0032] Step S24: The update terminal / software connects to the controller and sends the unique identifier Sid and signature Ssid in plain text to the controller;
[0033] Step S25: The controller verifies the signature Ssid with the received unique identifier Sid according to the digital signature verification algorithm in SM9. If the verification fails, the process ends; otherwise, the process proceeds to the next step.
[0034] Step S26: After the verification in step S25 is passed, the controller signs the unique identifier Cid with the signature private key Cs according to the digital signature generation algorithm in SM9 to obtain the signature Csid;
[0035] Step S27: The controller sends the unique identifier Cid and signature Csid in plain text to the update terminal / software;
[0036] Step S28: The update terminal / software verifies the signature Csid with the received unique identifier Cid according to the digital signature verification algorithm in SM9. If the verification fails, the process ends; if the verification passes, it proceeds to the next step;
[0037] Step S29: After the verification in step S28 is passed, according to the SM9 key exchange protocol, the update terminal / software S acts as the initiator and the controller acts as the responder, and the encryption private key Se and the encryption private key Ce are used to perform key exchange. The key obtained by the exchange is called Ks;
[0038] Step S210: The update terminal / software sends the unencrypted software to be updated and its attached hash value and hash value signature to the controller. The transmitted content is encrypted using the key Ks. The encryption method can be SM4 algorithm or AES algorithm.
[0039] Step S211: The controller decrypts the received data using the key Ks to obtain the unencrypted software to be updated and its attached hash value and hash value signature;
[0040] Step S212: The controller calculates the hash value of the unencrypted software to be updated and compares it with the hash value attached to the unencrypted software to be updated. If they are inconsistent, the process ends; if they are consistent, the process proceeds to the next step;
[0041] Step S213: After the comparison in step S212 is passed, the controller verifies the hash value signature attached to the unencrypted software to be updated with the signature master public key published by the controller manufacturer. If the verification fails, the process ends; if the verification passes, the process proceeds to the next step;
[0042] Step S214: the controller updates the firmware using the unencrypted software to be updated, and the updating process ends.
[0043] In conjunction with the second aspect, further, when the software to be updated is encrypted, the pre-update preparation for the software to be updated includes:
[0044] Step 1-1: The controller manufacturer assigns a unique identifier Sid to the update terminal / software S, generates a signature private key Ss and an encryption private key Se based on SM9, and both are built into the update terminal / software S release;
[0045] Step 1-2: The controller manufacturer assigns a unique identifier Cid to the controller and generates a signature private key Cs and an encryption private key Ce based on SM9. Both are built into the controller C and released.
[0046] Step 1-3: The controller manufacturer uses the SM9 encryption algorithm to encrypt the unencrypted software to be updated with the unique identifiers (CIDs) of all published controllers to generate encrypted software to be updated that corresponds to each controller.
[0047] Step 1-4: The controller manufacturer calculates the hash value of the encrypted software to be updated and signs the hash value with the signature master private key;
[0048] Steps 1-5: The controller manufacturer releases the encrypted software to be updated, followed by the corresponding hash value and hash value signature.
[0049] In conjunction with the second aspect, further, when the software to be updated is encrypted, updating the software to be updated includes:
[0050] Step 2-1: The update terminal / software calculates the hash value of the encrypted software to be updated and compares it with the hash value attached to the encrypted software to be updated. If they are inconsistent, the process ends and proceeds to the next step;
[0051] Step 2-2: After the comparison in step S2-1 is passed, the update terminal / software verifies the hash value signature attached to the encrypted software to be updated with the public signature master public key. If the verification fails, the process ends; if the verification passes, the process proceeds to the next step;
[0052] Step 2-3: After the verification in step S2-2 is passed, the update terminal / software uses the signature private key Ss to sign the unique identifier Sid according to the digital signature generation algorithm in SM9 to obtain the signature Ssid;
[0053] Step 2-4: Update the terminal / software to connect to the controller and send the unique identifier Sid and signature Ssid in plain text to the controller;
[0054] Step 2-5: The controller verifies the signature SSID with the received unique identifier Sid according to the digital signature verification algorithm in SM9. If the verification fails, the process ends. If the verification passes, it proceeds to the next step.
[0055] Step 2-6: After the verification in step S2-5 is passed, the controller signs the unique identifier Cid with the signature private key Cs according to the digital signature generation algorithm in SM9 to obtain the signature Csid;
[0056] Step 2-7: The controller sends the unique identifier Cid and signature Csid in plain text to the update terminal / software;
[0057] Step 2-8: The updated terminal / software verifies the signature Csid with the received unique identifier Cid according to the digital signature verification algorithm in SM9. If the verification fails, the process ends. If the verification passes, it proceeds to the next step.
[0058] Step 2-9: After the verification in step S2-8 is passed, according to the SM9 key exchange protocol, the update terminal / software acts as the initiator and the controller acts as the responder, using the encrypted private key Se and the encrypted private key Ce to perform key exchange. The key obtained by the exchange is called Ks;
[0059] Step 2-10: The update terminal / software sends the encrypted software to be updated and its attached hash value and hash value signature to the controller. The transmitted content is encrypted using the key Ks. The encryption method can use the SM4 algorithm or the AES algorithm.
[0060] Step 2-11: The controller decrypts the received data using the key Ks to obtain the encrypted software to be updated and its attached hash value and hash value signature;
[0061] Step 2-12: The controller calculates the hash value of the encrypted software to be updated and compares it with the hash value attached to the encrypted software to be updated. If they are inconsistent, the process ends; if they are consistent, it proceeds to the next step;
[0062] Step 2-13: After the comparison in step S2-12 is passed, the controller verifies the hash value signature attached to the encrypted software to be updated with the signature master public key published by the controller manufacturer. If the verification fails, the process ends; otherwise, the process proceeds to the next step.
[0063] Step 2-14: The controller decrypts the encrypted software to be updated using the encryption private key Ce according to the SM9 decryption algorithm to obtain the unencrypted software to be updated;
[0064] Step 2-15: The controller updates the firmware with the unencrypted software to be updated, and the update process ends.
[0065] In a third aspect, the present invention provides a computer device, comprising:
[0066] memory for storing computer programs;
[0067] A processor is used to execute the computer program to implement the steps of the above-mentioned engineering machinery controller security update method.
[0068] Compared with the prior art, the present invention has the following beneficial effects:
[0069] (1) The present invention is based on the SM9 algorithm and can realize the security verification of the update firmware source and the update control terminal / software.
[0070] (2) The present invention uses the unique identifier of the controller and firmware update terminal / software as the public key. The controller manufacturer acts as the KGC (Key Generation Center) to generate and distribute signature private keys and encryption private keys for each controller and firmware update terminal / software. The legitimacy of the controller and firmware update terminal / software is verified through signatures. The session encryption mechanism is used to ensure the security of the update link. A firmware signature mechanism is provided to verify the source of the firmware, and an optional firmware encryption mechanism is provided to protect intellectual property.
[0071] (2) The controller manufacturer of the present invention acts as a KGC to assign unique identifiers to the updated terminals / software and controllers it releases, and generates built-in signature private keys and encryption private keys.
[0072] (3) The present invention uses the unique identifier of the update terminal / software as the signature public key and verifies the legitimacy of the update terminal / software, controller, and firmware based on the digital signature algorithm provided by the SM9 algorithm.
[0073] (4) The present invention uses the unique identifier of the controller as the encryption public key. KGC generates encrypted firmware for each controller and decrypts it using the encryption private key built into the controller. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] Figure 1 This is a schematic diagram of Example 1 of the present invention where the software to be updated is not encrypted separately, and the updating terminal / software S can obtain the plain text of the software data, which cannot defend against man-in-the-middle attacks;
[0075] Figure 2This is a schematic diagram showing that the software to be updated is separately encrypted in embodiment 2 of the present invention, and the updating terminal / software S cannot obtain the plain text of the software data, which can prevent man-in-the-middle attacks. DETAILED DESCRIPTION
[0076] The technical solution of the present invention is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations on the technical solution of the present invention. In the absence of conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0077] The term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. Additionally, the character " / " generally indicates an "or" relationship between the related objects.
[0078] Example 1
[0079] like Figure 1 and Figure 2 As shown, the engineering machinery controller security update system of this embodiment includes:
[0080] Key Generation Center (KGC): Usually the controller manufacturer, generates the signature master key Ms and encryption master key Me.
[0081] The signature master key Ms includes the signature master private key Mspr and the signature master public key Mspu, wherein the signature master public key is made public and the signature master private key is kept secret by KGC.
[0082] The encryption master key Me includes the encryption master private key Mepr and the encryption master public key Mepu, wherein the encryption master public key is made public and the encryption master private key is kept secret by KGC.
[0083] Update terminal / software S: Establishes a communication connection with controller C, verifies the legitimacy of controller C, establishes a secure channel, sends the software to be updated to controller C, completes the update of the software to be updated through the upgrade program built into controller C, and assigns a unique identifier Sid to the update terminal / software S through the controller manufacturer (KGC). According to the SM9 algorithm, the update terminal / software S has a built-in signature private key Ss and encryption private key Se corresponding to the unique identifier Sid.
[0084] Signature private key Ss: A signature private key generated by KGC using the signature master private key Mspr and the unique identifier Sid of the update terminal / software S. It is used for identity authentication. The source of the message signed by the signature private key Ss can be confirmed by the unique identifier Sid.
[0085] Encryption private key Se: The encryption private key generated by KGC using the encryption master private key Mepr and the unique identifier Sid of the update terminal / software S. It is used for key exchange to determine the session key (symmetric encryption key). Data encrypted by the unique identifier Sid can be decrypted by the encryption private key Se.
[0086] Controller C: Establishes a communication connection with the update terminal / software S, verifies the legitimacy of the update terminal / software S, establishes a secure channel, receives the software to be updated, verifies the legitimacy of the source of the software to be updated, and performs the update operation; the controller manufacturer (KGC) assigns a unique identifier Cid to controller C. According to the SM9 algorithm, controller C has a built-in signature private key Cs and encryption private key Ce corresponding to the unique identifier Cid.
[0087] Signature private key Cs: A signature private key generated by KGC using the signature master private key Mspr and the unique identifier Cid of the controller C. It is used for identity authentication. The source of the message signed by the signature private key Cs can be confirmed by the unique identifier Cid.
[0088] Encryption private key Ce: An encryption private key generated by KGC using the encryption master private key Mepr and the unique identifier Cid of the controller C. It is used for key exchange to determine the session key (symmetric encryption key). Data encrypted by the unique identifier Cid can be decrypted by the encryption private key Ce.
[0089] Software to be updated: Software data that needs to be securely transmitted to controller C. This data can be transmitted unencrypted. Alternatively, the controller manufacturer (KGC) can encrypt the data using controller C's unique identifier, Cid, and then transmit it. Controller C can then decrypt the data using the encrypted private key, Ce.
[0090] Hash digest signature: The hash calculation can use the SM3 algorithm or the SHA256 algorithm and is signed with the signature master private key kept confidential by the controller manufacturer (KGC). The controller C and the update terminal / software S can verify the source of the software to be updated.
[0091] like Figure 1 As shown, when the software to be updated is unencrypted, the secure update method for the engineering machinery controller of this embodiment includes the following steps:
[0092] Step S1, preparing the unencrypted software to be updated before updating;
[0093] Step S2: updating the unencrypted software to be updated.
[0094] In a specific implementation of this embodiment, step S1 specifically includes the following steps:
[0095] Step S11: KGC (controller manufacturer) assigns a unique identifier Sid to the update terminal / software S, generates a signature private key Ss and an encryption private key Se, both of which are built into the update terminal / software S release.
[0096] Step S12: KGC (controller manufacturer) assigns a unique identifier Cid to controller C, generates a signature private key Cs and an encryption private key Ce, both of which are built into controller C and released.
[0097] Step S13: The KGC (controller manufacturer) calculates the hash value of the software to be updated (unencrypted) and signs the hash value with the signature master private key.
[0098] Step S14: KGC (controller manufacturer) publishes the software to be updated (unencrypted), followed by the corresponding hash value and hash value signature.
[0099] In a specific implementation of this embodiment, step S2 specifically includes the following steps:
[0100] Step S21: The updating terminal / software S calculates the hash value of the software to be updated (unencrypted) and compares it with the hash value attached to the software to be updated (unencrypted). If they are inconsistent, the process ends and the next step is entered.
[0101] Step S22: After the comparison in step S21 is passed, the update terminal / software S uses the public signature master public key to verify the hash value signature attached to the software to be updated (unencrypted). If the verification fails, the process ends; if the verification passes, the process proceeds to the next step.
[0102] Step S23: After the verification in step S22 is passed, the update terminal / software S signs the unique identifier Sid with the signature private key Ss according to the digital signature generation algorithm in SM9 to obtain the signature Ssid.
[0103] Step S24: The update terminal / software S connects to the controller C and sends the unique identifier Sid and signature Ssid in plain text to the controller C.
[0104] Step S25: Controller C verifies the signature Ssid with the received unique identifier Sid according to the digital signature verification algorithm in SM9. If the verification fails, the process ends; otherwise, the process proceeds to the next step.
[0105] Step S26: After the verification in step S25 is passed, the controller C signs the unique identifier Cid with the signature private key Cs according to the digital signature generation algorithm in SM9 to obtain the signature Csid.
[0106] Step S27: The controller C sends the unique identifier Cid and the signature Csid in plain text to the update terminal / software S.
[0107] Step S28: The update terminal / software S verifies the signature Csid with the received unique identifier Cid according to the digital signature verification algorithm in SM9. If the verification fails, the process ends; otherwise, the process proceeds to the next step.
[0108] Step S29: After step S28 is verified, according to the SM9 key exchange protocol, the update terminal / software S acts as the initiator and the controller C acts as the responder, using the encrypted private key Se and the encrypted private key Ce to exchange keys. The key obtained by the exchange is called Ks.
[0109] Step S210: The update terminal / software S sends the software to be updated (unencrypted) and its attached hash value and hash value signature to the controller C. The transmitted content is encrypted using the key Ks. The encryption method can be SM4 algorithm or AES algorithm.
[0110] Step S211: the controller C decrypts the received data using the key Ks to obtain the software to be updated (unencrypted) and its attached hash value and hash value signature.
[0111] Step S212: Controller C calculates the hash value of the software to be updated (unencrypted) and compares it with the hash value attached to the software to be updated (unencrypted). If they are inconsistent, the process ends; if they are consistent, the process proceeds to the next step.
[0112] Step S213: After the comparison in step S212 is passed, controller C uses the signature master public key published by KGC (controller manufacturer) to verify the hash value signature attached to the software to be updated (unencrypted). If the verification fails, the process ends; if the verification passes, the process proceeds to the next step.
[0113] Step S214: the controller C updates the firmware using the software to be updated (unencrypted), and the updating process ends.
[0114] Example 2
[0115] like Figure 2 As shown, when the software to be updated is encrypted, the secure update method for the engineering machinery controller of this embodiment includes the following steps:
[0116] Step S1, preparing the encrypted software to be updated before updating;
[0117] Step S2: updating the encrypted software to be updated.
[0118] In a specific implementation of this embodiment, step S1 specifically includes the following steps:
[0119] Step 1-1: KGC (controller manufacturer) assigns a unique identifier Sid to the update terminal / software S, generates a signature private key Ss and an encryption private key Se based on SM9, both of which are built into the update terminal / software S release.
[0120] Step 1-2: KGC (controller manufacturer) assigns a unique identifier Cid to controller C, generates a signature private key Cs and an encryption private key Ce based on SM9, and both are built into controller C and released.
[0121] Steps 1-3: The KGC (controller manufacturer) encrypts the software to be updated (unencrypted) using the unique identifiers (CIDs) of all published controllers using the SM9 encryption algorithm to generate the software to be updated (encrypted) that corresponds to each controller.
[0122] Steps 1-4: The KGC (controller manufacturer) calculates the hash value of the software to be updated (encrypted) and signs the hash value with the signature master private key.
[0123] Steps 1-5: KGC (controller manufacturer) publishes the software to be updated (encrypted), followed by the corresponding hash value and hash value signature.
[0124] In a specific implementation of this embodiment, step S2 specifically includes the following steps:
[0125] Step 2-1: The updating terminal / software S calculates the hash value of the software to be updated (encrypted) and compares it with the hash value attached to the software to be updated (encrypted). If they are inconsistent, the process ends and if they are consistent, proceed to the next step.
[0126] Step 2-2: After the comparison in step S2-1 is passed, the update terminal / software S uses the public signature master public key to verify the hash value signature attached to the software to be updated (encrypted). If the verification fails, the process ends; if the verification passes, it proceeds to the next step.
[0127] Step 2-3: After step S2-2 is verified, the update terminal / software S signs the unique identifier Sid with the signature private key Ss according to the digital signature generation algorithm in SM9 to obtain the signature Ssid.
[0128] Step 2-4: The update terminal / software S connects to the controller C and sends the unique identifier Sid and signature Ssid in plain text to the controller C.
[0129] Step 2-5: Controller C verifies the signature Ssid with the received unique identifier Sid according to the digital signature verification algorithm in SM9. If the verification fails, the process ends; if the verification passes, it proceeds to the next step.
[0130] Step 2-6: After the verification in step S2-5 is passed, the controller C signs the unique identifier Cid with the signature private key Cs according to the digital signature generation algorithm in SM9 to obtain the signature Csid.
[0131] Step 2-7: The controller C sends the unique identifier Cid and signature Csid in plain text to the update terminal / software S.
[0132] Step 2-8: The update terminal / software S verifies the signature Csid with the received unique identifier Cid according to the digital signature verification algorithm in SM9. If the verification fails, the process ends; if the verification passes, it proceeds to the next step.
[0133] Step 2-9: After step S2-8 is verified, according to the SM9 key exchange protocol, the update terminal / software S acts as the initiator and the controller C acts as the responder, using the encrypted private key Se and the encrypted private key Ce to exchange keys. The key obtained by the exchange is called Ks.
[0134] Step 2-10: The update terminal / software S sends the software to be updated (encrypted) and its attached hash value and hash value signature to the controller C. The transmitted content is encrypted using the key Ks. The encryption method can use the SM4 algorithm or the AES algorithm.
[0135] Step 2-11: Controller C decrypts the received data using the key Ks to obtain the software to be updated (encrypted) and its attached hash value and hash value signature.
[0136] Step 2-12: Controller C calculates the hash value of the software to be updated (encrypted) and compares it with the hash value attached to the software to be updated (encrypted). If they are inconsistent, the process ends; if they are consistent, it proceeds to the next step.
[0137] Step 2-13: After the comparison in step S2-12 is passed, controller C uses the signature master public key published by KGC (controller manufacturer) to verify the hash value signature attached to the updated software (encrypted). If the verification fails, the process ends; if the verification passes, it proceeds to the next step.
[0138] Step 2-14: Controller C decrypts the software to be updated (encrypted) using the encryption private key Ce according to the SM9 decryption algorithm to obtain the software to be updated (unencrypted).
[0139] Step 2-15: Controller C updates the firmware with the software to be updated (unencrypted), and the update process ends.
[0140] Example 3
[0141] Based on the same inventive concept as other embodiments, this embodiment introduces a computer device, including: a memory for storing a computer program; a processor for executing the computer program to implement the steps of the above-mentioned engineering machinery controller security update method.
[0142] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0143] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0144] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0145] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0146] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Ordinary technicians in this field can also make many forms under the guidance of the present invention, which all fall within the protection of the present invention.
Claims
1. A construction machinery controller security update system, characterized in that: include: Controller manufacturers, update terminals / software and controllers; The controller manufacturer is used to generate a signature master key Ms and an encryption master key Me, assign a unique identifier Sid to the update terminal / software S, and assign a unique identifier Cid to the controller; The update terminal / software is in communication with the controller, sends the software to be updated to the controller, and completes the update of the software to be updated through the upgrade program built into the controller; the update terminal / software S has a built-in signature private key Ss and encryption private key Se corresponding to the unique identifier Sid; The controller receives the software to be updated, verifies the legitimacy of the source of the software to be updated and performs the update operation; the controller has a built-in signature private key Cs and encryption private key Ce corresponding to the unique identifier Cid.
2. The engineering machinery controller security update system according to claim 1, characterized in that: The signature master key Ms includes the signature master private key Mspr and the signature master public key Mspu, wherein the signature master public key is public and the signature master private key is kept secret by the controller manufacturer; The encryption master key Me includes the encryption master private key Mepr and the encryption master public key Mepu, wherein the encryption master public key is made public and the encryption master private key is kept secret by the controller manufacturer.
3. The engineering machinery controller security update system according to claim 1, characterized in that: The signature private key Ss is generated by the controller manufacturer using the signature master private key Mspr and the unique identifier Sid of the update terminal / software, and is used for identity authentication. The message signed by the signature private key Ss is confirmed to have its source by the unique identifier Sid; The encryption private key Se is generated by the controller manufacturer using the encryption master private key Mepr and the unique identifier Sid of the update terminal / software, and is used for key exchange to determine the session key. Data encrypted by the unique identifier Sid can be decrypted by the encryption private key Se.
4. The engineering machinery controller security update system according to claim 1, characterized in that: The signature private key Cs is generated by the controller manufacturer using the signature master private key Mspr and the controller's unique identifier Cid, and is used for identity authentication. The message signed by the signature private key Cs can be confirmed to have a source by the unique identifier Cid; The encryption private key Ce is generated by the controller manufacturer using the encryption master private key Mepr and the controller's unique identifier Cid, and is used for key exchange to determine the session key. Data encrypted by the unique identifier Cid is decrypted by the encryption private key Ce.
5. A method for securely updating an engineering machinery controller, characterized in that: Updating the software to be updated by the update system according to any one of claims 1 to 4 comprises the following steps: Step S1, preparing for the update of the software to be updated; the preparation includes the controller manufacturer assigning a unique identifier Sid to the update terminal / software, generating a signature private key Ss and an encryption private key Se; the controller manufacturer assigning a unique identifier Cid to the controller, generating a signature private key Cs and an encryption private key Ce; Step S2: updating the software to be updated.
6. The engineering machinery controller security update method according to claim 5, characterized in that: When the software to be updated is unencrypted, the preparation for updating the software to be updated includes: Step S11: The controller manufacturer assigns a unique identifier Sid to the update terminal / software S and generates a signature private key Ss and an encryption private key Se; Step S12: The controller manufacturer assigns a unique identifier Cid to the controller and generates a signature private key Cs and an encryption private key Ce; Step S13: The controller manufacturer calculates the hash value of the unencrypted software to be updated and signs the hash value with the signature master private key; Step S14: The controller manufacturer releases the unencrypted software to be updated, followed by the corresponding hash value and hash value signature.
7. The engineering machinery controller security update method according to claim 5, characterized in that: When the software to be updated is encrypted, updating the software to be updated includes: Step S21: The update terminal / software calculates the hash value of the unencrypted software to be updated and compares it with the hash value attached to the unencrypted software to be updated. If they are inconsistent, the process ends and the next step is entered if they are consistent. Step S22: After the comparison in step S21 is passed, the update terminal / software verifies the hash value signature attached to the unencrypted software to be updated with the public signature master public key. If the verification fails, the process ends; otherwise, the process proceeds to the next step. Step S23: After the verification in step S22 is passed, the update terminal / software signs the unique identifier Sid with the signature private key Ss to obtain the signature Ssid; Step S24: The update terminal / software connects to the controller and sends the unique identifier Sid and signature Ssid in plain text to the controller; Step S25: The controller verifies the signature Ssid with the received unique identifier Sid. If the verification fails, the process ends; if the verification passes, the process proceeds to the next step; Step S26: After the verification in step S25 is passed, the controller signs the unique identifier Cid with the signature private key Cs to obtain the signature Csid; Step S27: The controller sends the unique identifier Cid and signature Csid in plain text to the update terminal / software; Step S28: The update terminal / software verifies the signature Csid with the received unique identifier Cid. If the verification fails, the process ends; if the verification passes, the process proceeds to the next step; Step S29: After the verification in step S28 is passed, the update terminal / software S acts as the initiator and the controller acts as the responder, and uses the encryption private key Se and the encryption private key Ce to perform a key exchange. The key obtained by the exchange is called Ks. Step S210: The update terminal / software sends the unencrypted software to be updated and its attached hash value and hash value signature to the controller, and the transmitted content is encrypted using the key Ks; Step S211: The controller decrypts the received data using the key Ks to obtain the unencrypted software to be updated and its attached hash value and hash value signature; Step S212: The controller calculates the hash value of the unencrypted software to be updated and compares it with the hash value attached to the unencrypted software to be updated. If they are inconsistent, the process ends; if they are consistent, the process proceeds to the next step; Step S213: After the comparison in step S212 is passed, the controller verifies the hash value signature attached to the unencrypted software to be updated with the signature master public key published by the controller manufacturer. If the verification fails, the process ends; if the verification passes, the process proceeds to the next step; Step S214: the controller updates the firmware using the unencrypted software to be updated, and the updating process ends.
8. The engineering machinery controller security update method according to claim 5, characterized in that: When the software to be updated is encrypted, the preparation for updating the software to be updated includes: Step 1-1: The controller manufacturer assigns a unique identifier Sid to the update terminal / software S and generates a signature private key Ss and an encryption private key Se; Step 1-2: The controller manufacturer assigns a unique identifier Cid to the controller and generates a signature private key Cs and an encryption private key Ce; Step 1-3: The controller manufacturer uses all published controller unique identifiers (CIDs) to encrypt the unencrypted software to be updated, generating encrypted software to be updated that corresponds to each controller one-to-one. Step 1-4: The controller manufacturer calculates the hash value of the encrypted software to be updated and signs the hash value with the signature master private key; Steps 1-5: The controller manufacturer releases the encrypted software to be updated, followed by the corresponding hash value and hash value signature.
9. The engineering machinery controller security update method according to claim 5, characterized in that: When the software to be updated is encrypted, updating the software to be updated includes: Step 2-1: The update terminal / software calculates the hash value of the encrypted software to be updated and compares it with the hash value attached to the encrypted software to be updated. If they are inconsistent, the process ends and proceeds to the next step; Step 2-2: After the comparison in step S2-1 is passed, the update terminal / software verifies the hash value signature attached to the encrypted software to be updated with the public signature master public key. If the verification fails, the process ends; if the verification passes, the process proceeds to the next step; Step 2-3: After the verification in step S2-2 is passed, the update terminal / software signs the unique identifier Sid with the signature private key Ss to obtain the signature Ssid; Step 2-4: Update the terminal / software to connect to the controller and send the unique identifier Sid and signature Ssid in plain text to the controller; Step 2-5: The controller verifies the signature Ssid with the received unique identifier Sid. If the verification fails, the process ends. If the verification passes, it proceeds to the next step. Step 2-6: After the verification in step S2-5 is passed, the controller signs the unique identifier Cid with the signature private key Cs to obtain the signature Csid; Step 2-7: The controller sends the unique identifier Cid and signature Csid in plain text to the update terminal / software; Step 2-8: The update terminal / software verifies the signature Csid with the received unique identifier Cid. If the verification fails, the process ends. If the verification passes, it proceeds to the next step. Step 2-9: After the verification in step S2-8 is passed, the update terminal / software acts as the initiator and the controller acts as the responder, and uses the encryption private key Se and the encryption private key Ce to perform a key exchange. The key obtained by the exchange is called Ks; Step 2-10: The update terminal / software sends the encrypted software to be updated and its attached hash value and hash value signature to the controller. The transmitted content is encrypted using the key Ks. Step 2-11: The controller decrypts the received data using the key Ks to obtain the encrypted software to be updated and its attached hash value and hash value signature; Step 2-12: The controller calculates the hash value of the encrypted software to be updated and compares it with the hash value attached to the encrypted software to be updated. If they are inconsistent, the process ends; if they are consistent, it proceeds to the next step; Step 2-13: After the comparison in step S2-12 is passed, the controller verifies the hash value signature attached to the encrypted software to be updated with the signature master public key published by the controller manufacturer. If the verification fails, the process ends; otherwise, the process proceeds to the next step. Step 2-14: The controller decrypts the encrypted software to be updated using the encryption private key Ce to obtain the unencrypted software to be updated; Step 2-15: The controller updates the firmware with the unencrypted software to be updated, and the update process ends.
10. A computer device, characterized in that: include: Memory for storing computer programs; A processor is used to execute the computer program to implement the steps of the engineering machinery controller security update method according to any one of claims 6 to 9.
Citation Information
Patent Citations
Secure firmware updating method
CN112165396A
Firmware burning protection method and system based on national cryptographic algorithm
CN116910779A