Firmware updating method and device and electronic equipment
By receiving and binding user-defined identification information, using the identification information of the target firmware and the firmware to be updated to verify, and combining encryption algorithms to protect identity information, the security issues in the firmware update mechanism are solved, and user-initiated updates and device security are achieved.
Patent Information
- Application Number
- CN202510898322.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-10-03
AI Technical Summary
The existing firmware update mechanism has potential risks. Unauthorized entities may maliciously tamper with the firmware version without the user's knowledge or consent, and the security of electronic devices cannot be guaranteed.
By receiving and binding user-defined identification information, using the identification information of the target firmware and the firmware to be updated to verify, the firmware is updated only when the verification passes. Combined with encryption algorithms to protect identity information, the legitimacy and security of the firmware update are ensured.
It enables firmware updates to be performed at the user's initiative, preventing passive updates, improving the security of electronic devices and the matching of firmware with user information, and facilitating IT management.
Smart Images

Figure CN120744906A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and more specifically to a firmware updating method, device, and electronic device. Background Art
[0002] The current firmware update mechanism carries potential risks. Unauthorized actors (such as cyber attackers, malicious intruders, computer intruders, and vulnerability exploiters) or unauthorized software pushes could maliciously tamper with the firmware version without the user's knowledge or consent. This unavoidable passive firmware update without the user's knowledge or consent cannot guarantee the security of electronic devices. Summary of the Invention
[0003] In view of the above problems, the present application provides a firmware update method, device and electronic device that avoid passive firmware updates.
[0004] According to the first aspect of the present application, a firmware update method is provided, including: receiving input first identification information and binding the first identification information with a target firmware; in response to a firmware update request, obtaining first identification information corresponding to the target firmware and second identification information corresponding to the firmware to be updated, wherein the second identification information is information bound to the firmware to be updated and input in response to a firmware first-installation configuration request; verifying the first identification information and the second identification information; and when the first identification information and the second identification information are verified, using the target firmware to update the firmware to be updated.
[0005] According to an embodiment of the present application, the response to the firmware first installation configuration request includes: receiving input second identification information; and binding the second identification information with the firmware to be updated using the corresponding first interface in the firmware to be updated; wherein the first interface is used to implement the writing of the second identification information.
[0006] According to an embodiment of the present application, the use of the corresponding first interface in the firmware to be updated to bind the second identification information with the firmware to be updated includes: using the first interface to write the second identification information into the first identity information area; wherein, the first identity information area includes at least a partial area in the read-only memory of the electronic device that stores firmware data.
[0007] According to an embodiment of the present application, binding the first identification information with the target firmware includes: using the corresponding second interface in the target firmware to write the first identification information into the second identity information area of the target firmware; wherein the second interface is used to implement the writing of the first identification information.
[0008] According to an embodiment of the present application, the receiving of the input first identification information includes: loading the target firmware; and receiving the first identification information input for the loaded target firmware.
[0009] According to an embodiment of the present application, the method further includes: encrypting the first identification information bound to the target firmware based on a first encryption algorithm; wherein the first encryption algorithm includes one or more of a symmetric encryption algorithm, a reversible encryption function, and an asymmetric encryption algorithm.
[0010] According to an embodiment of the present application, the method further includes: encrypting the second identification information bound to the firmware to be updated based on a second encryption algorithm; wherein the second encryption algorithm includes one or more of the symmetric encryption algorithm, the reversible encryption function, and the asymmetric encryption algorithm; the first encryption algorithm and the second encryption algorithm are of the same or different types.
[0011] According to an embodiment of the present application, obtaining the first identification information corresponding to the target firmware and the second identification information corresponding to the firmware to be updated includes: decrypting the first identification information bound to the target firmware based on a first decryption algorithm corresponding to the first encryption algorithm, and obtaining the first identification information corresponding to the target firmware; and decrypting the second identification information bound to the firmware to be updated based on a second decryption algorithm corresponding to the second encryption algorithm, and obtaining the second identification information corresponding to the firmware to be updated.
[0012] The second aspect of the present application provides a firmware update device, including: a binding module for receiving input first identification information and binding the first identification information with the target firmware; a response module for obtaining the first identification information corresponding to the target firmware and the second identification information corresponding to the firmware to be updated in response to a firmware update request, wherein the second identification information is the information bound to the firmware to be updated and input in response to a firmware first-installation configuration request; a verification module for verifying the first identification information and the second identification information; and an update module for updating the firmware to be updated using the target firmware when the first identification information and the second identification information are verified.
[0013] The third aspect of the present application provides an electronic device, comprising: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of a firmware update method; the firmware update method comprises: receiving input first identification information, and binding the first identification information with the target firmware; in response to a firmware update request, obtaining first identification information corresponding to the target firmware and second identification information corresponding to the firmware to be updated, wherein the second identification information is information bound to the firmware to be updated and input in response to a firmware first-installation configuration request; verifying the first identification information and the second identification information; and when the first identification information and the second identification information are verified, using the target firmware to update the firmware to be updated. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The above contents and other objects, features and advantages of the present application will become more apparent through the following description of the embodiments of the present application with reference to the accompanying drawings, in which:
[0015] Figure 1 The following schematically illustrates an application scenario diagram of a firmware update method, device, and electronic device according to an embodiment of the present application;
[0016] Figure 2 The following schematically shows a flowchart of a firmware update method according to an embodiment of the present application;
[0017] Figure 3 A second identification information binding flow chart of the firmware update method according to an embodiment of the present application is schematically shown;
[0018] Figure 4 The following schematically shows a flow chart of obtaining identification information of a firmware update method according to an embodiment of the present application;
[0019] Figure 5 A BIOS firmware update flow chart of a firmware update method according to an embodiment of the present application is schematically shown;
[0020] Figure 6 A schematic diagram of a structure of a firmware update device according to an embodiment of the present application is shown; and
[0021] Figure 7 A block diagram of an electronic device suitable for implementing a firmware update method according to an embodiment of the present application is schematically shown. DETAILED DESCRIPTION
[0022] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present application. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present application. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present application.
[0023] The terms used herein are only for describing specific embodiments and are not intended to limit the present application. The terms "comprise," "include," etc. used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0024] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0025] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0026] In the technical solution of this application, the user information involved (including but not limited to user personal identity information, user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0027] In the scenario of using personal information for automated decision-making, the methods, devices, and systems provided in the embodiments of the present application all provide users with corresponding operation portals for users to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered. The expression "automated decision-making" here refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests and hobbies, or economic, health, credit status, etc. through computer programs and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by people who specialize in a certain field, have specialized experience, knowledge and skills, and have reached a certain level of professionalism.
[0028] Currently, firmware updates and upgrades primarily rely on the following models: Users can download the firmware installation package from official websites published on the web and manually perform the upgrade on their local device; or they can receive and complete push upgrades through Windows Update (WU) or dedicated software. When users need to upgrade firmware, these methods provide a convenient version upgrade solution. However, the current firmware upgrade mechanism also carries potential risks. Unauthorized entities (such as network attackers, malicious intruders, computer intruders, and vulnerability exploiters) or software pushes without user confirmation may maliciously tamper with the firmware version without the user's intention or knowledge. Existing technologies cannot prevent users from passively updating firmware without their knowledge or consent, and cannot guarantee the security of electronic devices.
[0029] An embodiment of the present application provides a firmware update method, which receives input first identification information and binds the first identification information to the target firmware; in response to a firmware update request, obtains first identification information corresponding to the target firmware and second identification information corresponding to the firmware to be updated, wherein the second identification information is information bound to the firmware to be updated and input in response to a firmware first-installation configuration request; verifies the first identification information and the second identification information; and, if the first identification information and the second identification information are verified, uses the target firmware to update the firmware to be updated.
[0030] In an embodiment of the present application, the user can customize his or her own identity information and write it into the firmware of the user's electronic device and the target firmware downloaded from the Internet, corresponding to the second identification information and the first identification information respectively, so that the target firmware downloaded by the user becomes a file that is uniquely matched with the current user's electronic device, and the user's identity information is verified during the firmware update process, so that the firmware can only be updated when the user takes the initiative, so that the firmware version on the electronic device is always what the user requires, preventing the user from passively updating the firmware of the electronic device without knowing or being willing, improving the security of the electronic device and firmware, ensuring the matching of the firmware and user-specific information, and facilitating IT management.
[0031] Figure 1The application scenario diagram of the firmware update method, device and electronic device according to the embodiments of the present application is schematically shown.
[0032] like Figure 1 As shown, the application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is used as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links or optical fiber cables.
[0033] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).
[0034] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.
[0035] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices.
[0036] It should be noted that the firmware update method provided in the embodiment of the present application can generally be executed by the server 105. Accordingly, the firmware update device provided in the embodiment of the present application can generally be set in the server 105. The firmware update method provided in the embodiment of the present application can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the firmware update device provided in the embodiment of the present application can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.
[0037] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0038] The following will be based on Figure 1 The scene described by Figures 2 to 5 The firmware update method according to the embodiment of the present application is described in detail.
[0039] Figure 2 The flowchart of the firmware update method according to the embodiment of the present application is schematically shown.
[0040] like Figure 2 As shown, the firmware update method of this embodiment includes operations S210 to S240. The firmware update method does not limit the specific execution subject. The execution subject can be any electronic device, such as a terminal device or a server device, etc. The execution subject can also be any software application or client. Firmware updates include but are not limited to updates of BIOS firmware, unified extensible firmware interface UEFI, baseboard management controller BMC, embedded firmware, industrial control firmware, medical device firmware, and other firmware.
[0041] In operation S210 , input first identification information is received, and the first identification information is bound to a target firmware.
[0042] The first identification information is user-defined identity information when updating firmware, and is stored in the target firmware. This first identification information includes, but is not limited to, character information, biometric information, graphic information, and voice information. This information can be entered through tools such as a graphical user interface, command line interface, biometric sensor tools, touch tools, firmware management tools, and voice interaction tools.
[0043] When users need to update their firmware, they first need to obtain the target firmware. This target firmware can be downloaded from a web release. Web releases distribute and disseminate software, files, and content via a network platform, allowing users to access and obtain the relevant version resources online. After downloading the firmware, users can use tools and interfaces to bind customized identification information to the downloaded target firmware, making it uniquely compatible with their current device.
[0044] In operation S220, in response to the firmware update request, first identification information corresponding to the target firmware and second identification information corresponding to the firmware to be updated are obtained, wherein the second identification information is information bound to the firmware to be updated and input in response to the firmware first installation configuration request.
[0045] Secondary identification information is user-defined identification information when the firmware is first installed. This information is stored in the electronic device for the firmware itself. Secondary identification information includes, but is not limited to, character information, biometric information, graphic information, and voice information. This information can be entered through tools such as graphical user interfaces, command line interfaces, biometric sensing tools, touch tools, and voice interaction tools.
[0046] When updating the firmware, a firmware update request is initiated. The electronic device can parse the customized target firmware that the user wants to update, read the customized identity identification information (first identification information) therein, and verify it with the customized identity information (second identification information) stored in itself.
[0047] In operation S230 , the first identification information and the second identification information are verified.
[0048] Verification methods include but are not limited to hashing algorithms, content matching, and checksum verification.
[0049] Hash algorithm: Generate unique hash values for the first and second identification information using a hash algorithm (such as MD5 or SHA-256), and compare the hash values to see if they are consistent.
[0050] Content matching: Comparing the data content of the first identification information and the second identification information byte by byte or field by field.
[0051] Verification code verification: calculate the verification code (such as CRC check, parity check) for the first identification information and the second identification information, and compare whether the verification codes match.
[0052] In operation S240 , if the first identification information and the second identification information are verified to be successful, the firmware to be updated is updated using the target firmware.
[0053] If the verification passes, the current firmware to be updated in the electronic device is updated according to the target firmware. If the verification fails, the firmware update is blocked and the user is notified. The user may be notified that the update failed or that the firmware identification information does not match. This ensures that the electronic device can only run firmware with the same customized information, and cannot run firmware that has not been customized by the user. This ensures that the firmware in the user's electronic device can only be updated by the user's willingness and initiative, preventing malicious changes.
[0054] During a firmware update, the configuration and data of the target firmware are backed up to prevent functional malfunctions caused by update failures. Based on the firmware type, the corresponding update tool (such as a local flash program or a built-in system upgrade module) is then invoked to transfer the target firmware to the device's designated storage area (such as a ROM chip). The transfer is performed byte by byte, while the integrity of the written data is verified in real time to prevent transmission errors. After the write is complete, the system restarts and loads the target firmware, initializing the hardware components and verifying the proper functioning of the target firmware's functional modules (such as communications and drivers). If an anomaly is detected during the boot process, the system automatically rolls back to the backed-up older firmware version to ensure device availability.
[0055] In an embodiment of the present application, the user can customize his or her own identity information and write it into the firmware of the user's electronic device and the target firmware downloaded from the Internet, corresponding to the second identification information and the first identification information respectively, so that the target firmware downloaded by the user becomes a file that is uniquely matched with the current user's electronic device, and the user's identity information is verified during the firmware update process, so that the firmware can only be updated when the user takes the initiative, so that the firmware version on the electronic device is always what the user requires, preventing the user from passively updating the firmware of the electronic device without knowing or being willing, improving the security of the electronic device and firmware, ensuring the matching of the firmware and user-specific information, and facilitating IT management.
[0056] According to an embodiment of the present application, receiving the input first identification information in operation S210 includes: loading target firmware; and receiving the first identification information input for the loaded target firmware.
[0057] For the target firmware, you can use the firmware management tool to load and receive user-defined identity information, facilitate identity management, and realize personalized identity settings.
[0058] According to an embodiment of the present application, binding the first identification information with the target firmware in operation S210 includes: using a corresponding second interface in the target firmware to write the first identification information into a second identity information area of the target firmware; wherein the second interface is used to implement the writing of the first identification information.
[0059] The corresponding second interface in the target firmware is a customized interface for writing user-defined identity information. The second identity information area is a storage area for storing the first identification information. The first identity information area may include a portion of the target firmware's data storage area. It is worth noting that the firmware released via the Web release includes a customized user identity interface and identity information area to facilitate custom binding of user-defined identity information to the firmware.
[0060] The target firmware released via Web release now includes a customized user identity interface (second interface) and an identity information area. This customized interface allows you to write identity information to a dedicated area, enabling identity binding for the target firmware. This facilitates identity verification during updates.
[0061] Figure 3 The second identification information binding flow chart of the firmware update method according to an embodiment of the present application is schematically shown.
[0062] like Figure 3 As shown, according to an embodiment of the present application, in operation S220 responding to the firmware first installation configuration request, it includes: operation S310 to operation S320.
[0063] In operation S310 , input second identification information is received.
[0064] After the user receives a new electronic device, when it is run for the first time, a firmware first installation configuration request is initiated. The user can set custom identity identification information, that is, second identification information, and customize the binding of the custom identity identification information to the firmware of the current electronic device. The current computer firmware is then a unique firmware.
[0065] In operation S320, the second identification information is bound to the firmware to be updated using the corresponding first interface in the firmware to be updated; wherein the first interface is used to implement writing of the second identification information.
[0066] The corresponding first interface in the firmware to be updated is a customized interface for writing user-defined identity information in the firmware to be updated. The user-defined information is written into a specific storage area through the firmware customized interface to achieve customized binding of the user-defined information and the current device firmware.
[0067] According to an embodiment of the present application, in operation S320, the second identification information is bound to the firmware to be updated using the corresponding first interface in the firmware to be updated, including: using the first interface to write the second identification information into the first identity information area; wherein the first identity information area includes at least a partial area in the read-only memory of the electronic device that stores firmware data.
[0068] During electronic device development, custom user identification interfaces and identity information areas are added to the firmware. Users can write customized information into the device's firmware and read-only memory upon receipt. These interfaces and areas are included by default in the firmware of electronic devices shipped from the factory. For special orders, if the user has specific requirements, custom identity information can be bound to the firmware by initiating firmware configuration during factory production.
[0069] The first identity information area is a storage area for storing the second identification information. The first identity information area includes at least a portion of the area storing firmware data in the read-only memory of the electronic device. The first identity information area may also include a portion of the area storing data for the firmware to be updated. The second identification information is stored in the read-only memory and cannot rewrite the initial owner identity information of the machine. This identity information is used as a verification basis to prevent passive updates of the firmware and protect information autonomy.
[0070] According to an embodiment of the present application, after binding the first identification information and the target firmware in operation S210, the firmware update method also includes: encrypting the first identification information bound to the target firmware based on a first encryption algorithm; wherein the first encryption algorithm includes one or more of a symmetric encryption algorithm, a reversible encryption function, and an asymmetric encryption algorithm.
[0071] Exemplarily, the process of encrypting the first identification information includes:
[0072] (1) Key generation: Select a reversible encryption algorithm (such as AES, DES, RSA symmetric / asymmetric algorithm) to generate or obtain the encryption key.
[0073] (2) Preprocessing the original information: Standardize the format of the first identification information (such as text, data) (such as encoding it into UTF-8) to ensure algorithm compatibility.
[0074] (3) Segmentation and padding: Split the information according to the algorithm block size (such as 16-byte blocks for AES-128), and fill the insufficient part with specific characters (such as PKCS#7 padding).
[0075] (4) Key and information operations: The key and information are subjected to mathematical operations (such as substitution, shift, and XOR) through encryption functions to generate ciphertext. For example, the AES algorithm implements encryption through multiple layers of transformations such as round key addition and byte substitution.
[0076] According to an embodiment of the present application, after binding the second identification information and the firmware to be updated in operation S320, the firmware update method also includes: encrypting the second identification information bound to the firmware to be updated based on a second encryption algorithm; wherein the second encryption algorithm includes one or more of a symmetric encryption algorithm, a reversible encryption function, and an asymmetric encryption algorithm.
[0077] The encryption process of the second identification information is similar to that of the first identification information, and no further details are given here.
[0078] It should be noted that the first and second encryption algorithms can be of the same or different types. Each encryption algorithm corresponds to its own firmware. Simply using the corresponding decryption algorithm to fully recover the user-defined identity information is sufficient for verification. Therefore, the encryption algorithm is reversible, allowing the original information to be fully recovered.
[0079] In the embodiments of the present application, a specific encryption algorithm is used to encrypt the custom identity identification information in the identity information area in the firmware to prevent theft and tampering, enhance identity confidentiality, and improve security.
[0080] Figure 4 The following schematically shows a flow chart of obtaining identification information of a firmware update method according to an embodiment of the present application.
[0081] like Figure 4 As shown, according to an embodiment of the present application, obtaining the first identification information corresponding to the target firmware and the second identification information corresponding to the firmware to be updated in operation S220 includes: operations S410 to S420.
[0082] In operation S410, first identification information bound to the target firmware is decrypted based on a first decryption algorithm corresponding to the first encryption algorithm to obtain first identification information corresponding to the target firmware.
[0083] Exemplarily, the process of decrypting the first identification information includes:
[0084] (1) Obtaining ciphertext and corresponding key: Receive the encrypted ciphertext and the matching decryption key (which must be consistent with the encryption key or have a mathematical correspondence, such as the private key of asymmetric encryption).
[0085] (2) Verify the integrity of the ciphertext: Use a hash value (such as SHA-256) to verify whether the ciphertext has been tampered with to ensure the validity of the decryption. This integrity verification can be an optional step. In cases where the firmware security requirements are high, this step can be added to ensure that the information in the firmware has not been changed.
[0086] (3) Reverse operation to restore information: Use the decryption function and key to perform reverse operation on the ciphertext (such as reverse byte replacement and reverse round key addition of the AES algorithm) to restore the original segmented data.
[0087] (4) Removing padding and restoring the format: Remove redundant characters according to the padding rules during encryption and convert the binary data into the original information format (such as text, data structure).
[0088] In operation S420, the second identification information bound to the firmware to be updated is decrypted based on a second decryption algorithm corresponding to the second encryption algorithm to obtain the second identification information corresponding to the firmware to be updated.
[0089] The encryption process of the second identification information is similar to the decryption process of the first identification information, and no further details are given here.
[0090] By utilizing the respective decryption algorithms in the firmware, the identity information of the target firmware and the identity information of the firmware to be updated can be accurately obtained, which facilitates rapid and accurate verification of identity consistency and quickly determines whether to update the target firmware to the electronic device.
[0091] Take BIOS firmware update as an example, Figure 5 The following schematically shows a BIOS firmware update flow chart of the firmware update method according to an embodiment of the present application. Figure 5 As shown, a portion of space is reserved in the BIOS file as an area for custom identity identification information, namely the identity information area. The specific process is as follows:
[0092] For local computers: During factory generation, the BIOS file is burned and flashed to the local computer. When the user boots up the computer for the first time, a screen pops up during the POST (Power On Self Test) window, prompting the user to enter custom identification information. After entering this information, the BIOS processes it through the UEFI Protocol interface (which defines specific functions and data structures that allow different software entities to access and utilize the services provided by the UEFI firmware). The BIOS then writes this information to the custom identification information area within the BIOS Region of the local computer's SPIROM. SPI ROM, a read-only memory (ROM) connected via the SPI interface, is commonly used in computers to store important firmware data, such as the BIOS. Within the SPI ROM, a dedicated area is allocated to store BIOS (Basic Input / Output System)-related data and program code; this area is called the BIOS Region. Writing this processed custom identification information to the BIOS Region integrates this information into the computer's BIOS firmware, enabling the BIOS to utilize these customized configurations and settings.
[0093] For BIOS files downloaded from a web release: After downloading the target BIOS file from the official website, the user opens the official tool and loads the BIOS file. Enter custom identification information in the tool interface, and the tool changes this information to the custom identification information area in the BIOS file.
[0094] When the user updates the BIOS, the target BIOS file with the added custom identity information will be loaded onto the local computer. The local computer's BIOS will parse the custom identity information area in the BIOS to be updated and compare the parsed information with the identity information stored on the local computer. The decision on whether to continue flashing is based on the matching result. If the information matches, the local computer's BIOS will continue to be updated. If the information does not match, the update of the local computer's BIOS will be blocked and a corresponding prompt will be given. This allows users to customize their own identity information and write it to the user's computer's BIOS and the downloaded BIOS. The downloaded BIOS becomes a file that uniquely matches the current user's computer, and the user's identity information is verified during the BIOS update process. This means that the BIOS can only be updated when the user actively updates it, ensuring that the BIOS version on the machine is always the version the user requires.
[0095] Based on the above firmware update method, this application also provides a firmware update device. Figure 6 The device is described in detail.
[0096] Figure 6 The following schematically shows a structural block diagram of a firmware updating device according to an embodiment of the present application.
[0097] like Figure 6 As shown, the firmware updating apparatus 600 of this embodiment includes a binding module 610 , a response module 620 , a verification module 630 and an updating module 640 .
[0098] The binding module 610 is used to receive the input first identification information and bind the first identification information to the target firmware. In one embodiment, the binding module 610 can be used to perform the operation S210 described above, which will not be repeated here.
[0099] Response module 620 is configured to, in response to the firmware update request, obtain first identification information corresponding to the target firmware and second identification information corresponding to the firmware to be updated, where the second identification information is information bound to the firmware to be updated and input in response to the firmware first-install configuration request. In one embodiment, response module 620 may be configured to perform operation S220 described above, which will not be further described here.
[0100] The verification module 630 is used to verify the first identification information and the second identification information. In one embodiment, the verification module 630 can be used to perform the operation S230 described above, which will not be repeated here.
[0101] The update module 640 is used to update the firmware to be updated using the target firmware when the first identification information and the second identification information are verified. In one embodiment, the update module 640 can be used to perform the operation S240 described above, which will not be repeated here.
[0102] According to embodiments of the present application, any multiple modules among the binding module 610, response module 620, verification module 630, and update module 640 may be combined into a single module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present application, at least one of the binding module 610, response module 620, verification module 630, and update module 640 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or may be implemented in any one of the three implementation methods of software, hardware, and firmware, or any appropriate combination of any of these. Alternatively, at least one of the binding module 610, response module 620, verification module 630, and update module 640 may be at least partially implemented as a computer program module that, when executed, performs the corresponding functionality.
[0103] Figure 7 A block diagram of an electronic device suitable for implementing a firmware update method according to an embodiment of the present application is schematically shown.
[0104] like Figure 7 As shown, an electronic device 900 according to an embodiment of the present application includes a processor 901, which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 902 or programs loaded from a storage unit 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or related chipsets and / or a dedicated microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiment of the present application.
[0105] Various programs and data required for the operation of the electronic device 900 are stored in the RAM 903. The processor 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. The processor 901 performs various operations of the method flow according to the embodiment of the present application by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 may also perform various operations of the method flow according to the embodiment of the present application by executing the programs stored in one or more memories.
[0106] According to an embodiment of the present application, electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to bus 904. Electronic device 900 may also include one or more of the following components connected to I / O interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 908 including a hard disk; and a communication section 909 including a network interface card such as a LAN card or modem. Communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to I / O interface 905 as needed. Removable media 911, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 910 as needed, so that computer programs read from the removable media can be installed into storage section 908 as needed.
[0107] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of this application is implemented.
[0108] According to an embodiment of the present application, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present application, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present application, a computer-readable storage medium may include the ROM 902 and / or RAM 903 described above and / or one or more memories other than ROM 902 and RAM 903.
[0109] The embodiments of the present application also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the firmware update method provided in the embodiments of the present application.
[0110] The computer program executes the above functions defined in the system / device of the embodiment of the present application when the processor 901 executes the computer program. According to the embodiment of the present application, the system, device, module, unit, etc. described above can be implemented by a computer program module.
[0111] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 909, and / or installed from a removable medium 911. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.
[0112] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from a removable medium 911. When the computer program is executed by the processor 901, the above-mentioned functions defined in the system of the embodiment of the present application are performed. According to the embodiment of the present application, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.
[0113] According to an embodiment of the present application, the program code for executing the computer program provided by the embodiment of the present application can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).
[0114] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of the boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0115] Those skilled in the art will appreciate that the features described in the various embodiments of this application may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in this application. In particular, the features described in the various embodiments of this application may be combined and / or coupled in various ways without departing from the spirit and teachings of this application. All such combinations and / or couplings fall within the scope of this application.
Claims
1. A firmware update method, comprising: receiving input first identification information, and binding the first identification information with the target firmware; In response to the firmware update request, obtaining first identification information corresponding to the target firmware and second identification information corresponding to the firmware to be updated, wherein the second identification information is information bound to the firmware to be updated and input in response to the firmware first-install configuration request; verifying the first identification information and the second identification information; and When the first identification information and the second identification information are verified to be successful, the firmware to be updated is updated using the target firmware.
2. The method according to claim 1, wherein responding to the firmware first installation configuration request comprises: receiving input second identification information; as well as Using the corresponding first interface in the firmware to be updated, binding the second identification information with the firmware to be updated; The first interface is used to implement writing of the second identification information.
3. The method according to claim 2, wherein the step of binding the second identification information to the firmware to be updated by using the corresponding first interface in the firmware to be updated comprises: Using the first interface, writing the second identification information into the first identity information area; The first identity information area at least includes a portion of the area storing firmware data in the read-only memory of the electronic device.
4. The method according to claim 3, wherein binding the first identification information with the target firmware comprises: Using a corresponding second interface in the target firmware, writing the first identification information into a second identity information area of the target firmware; The second interface is used to implement writing of the first identification information.
5. The method according to claim 1, wherein receiving the input first identification information comprises: Loading the target firmware; as well as First identification information input for the loaded target firmware is received.
6. The method according to claim 1, further comprising: Encrypting the first identification information bound to the target firmware based on a first encryption algorithm; The first encryption algorithm includes one or more of a symmetric encryption algorithm, a reversible encryption function, and an asymmetric encryption algorithm.
7. The method according to claim 6, further comprising: Encrypting the second identification information bound to the firmware to be updated based on a second encryption algorithm; The second encryption algorithm includes one or more of the symmetric encryption algorithm, the reversible encryption function, and the asymmetric encryption algorithm; the first encryption algorithm and the second encryption algorithm are of the same or different types.
8. The method according to claim 7, wherein obtaining the first identification information corresponding to the target firmware and the second identification information corresponding to the firmware to be updated comprises: decrypting the first identification information bound to the target firmware based on a first decryption algorithm corresponding to the first encryption algorithm to obtain the first identification information corresponding to the target firmware; as well as The second identification information bound to the firmware to be updated is decrypted based on a second decryption algorithm corresponding to the second encryption algorithm to obtain the second identification information corresponding to the firmware to be updated.
9. A firmware update device, comprising: a binding module, configured to receive input first identification information and bind the first identification information to a target firmware; a response module, configured to obtain, in response to a firmware update request, first identification information corresponding to the target firmware and second identification information corresponding to the firmware to be updated, wherein the second identification information is information bound to the firmware to be updated and input in response to a firmware first-install configuration request; a verification module, configured to verify the first identification information and the second identification information; and An updating module is configured to update the firmware to be updated using the target firmware when the first identification information and the second identification information are verified to be successful.
10. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the firmware update method; The firmware update method includes: receiving input first identification information, and binding the first identification information with target firmware; In response to the firmware update request, obtaining first identification information corresponding to the target firmware and second identification information corresponding to the firmware to be updated, wherein the second identification information is information bound to the firmware to be updated and input in response to the firmware first-install configuration request; verifying the first identification information and the second identification information; and When the first identification information and the second identification information are verified to be successful, the firmware to be updated is updated using the target firmware.