Equipment security upgrading method
By establishing a secure data channel and differential packet transmission mechanism during the device upgrade process, the problems of firmware loss, leakage, or tampering are solved, and secure device upgrades are achieved.
Patent Information
- Application Number
- CN202511024523.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-11-07
AI Technical Summary
Firmware loss, leakage, or tampering during device updates and upgrades can prevent devices from being upgraded securely.
By establishing a first secure data channel between the data interaction server and the local device, the device identification information is encrypted and verified to ensure the device's legitimacy; the integrity of the firmware package to be upgraded is verified, and a differential packet is generated for encrypted transmission to ensure the integrity and security of the firmware.
This improves the security of device upgrades, prevents firmware loss, leakage, or tampering, and ensures the reliability and integrity of the device during the upgrade process.
Smart Images

Figure CN120910903A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the field of firmware upgrade, in particular, to a device security upgrade method. BACKGROUND
[0002] With the continuous progress of science and technology, surveying and mapping devices are increasingly widely used in the fields of geographic information, geological exploration, agriculture, urban planning, etc., and these devices need to maintain high reliability and accuracy when performing various tasks. Conventional device update and upgrade is often performed by personnel on site, and the firmware is directly transmitted to the receiver through a wireless network or a wired network. The receiver receives the firmware and directly writes the firmware into the corresponding disk hardware device. After the writing is completed, the upgrade operation is completed.
[0003] However, during the update and upgrade of the device, the firmware is often lost, leaked or tampered with, resulting in the device being unable to be safely upgraded. SUMMARY
[0004] Embodiments of the present application provide a device security upgrade method to at least solve the problem that the firmware is lost, leaked or tampered with during the device update and upgrade in the related art, resulting in the device being unable to be safely upgraded.
[0005] According to an aspect of an embodiment of the present application, a device security upgrade method is provided, applied to a data interaction server, the method comprising: obtaining encrypted device identification information of a local device through a first secure data channel between the local device and the data interaction server, decrypting the encrypted device identification information, and verifying the decrypted device identification information; the device identification information is encrypted by the local device according to a target encryption algorithm; in the case that the device identification information verification is passed, obtaining an encrypted firmware package to be upgraded, and verifying the integrity of the encrypted firmware package to be upgraded; the firmware package to be upgraded includes a plurality of sub-firmware packages; in the case that the integrity verification of the encrypted firmware package to be upgraded is passed, determining at least one group of target sub-firmware packages to be updated by the local device from the encrypted plurality of sub-firmware packages, and compressing the at least one group of target sub-firmware packages to obtain a difference package; transmitting the difference package to the local device through the first secure data channel, so that the local device decrypts the difference package according to a target decryption algorithm corresponding to the target encryption algorithm to obtain the at least one group of target sub-firmware packages, and upgrades the local firmware according to the at least one group of target sub-firmware packages.
[0006] According to another aspect of the embodiments of the present application, a device security upgrade method applied to a local device is further provided, and the method comprises the following steps: encrypting device identification information of the local device according to a target encryption algorithm, and transmitting the encrypted device identification information to a data interaction server through a first secure data channel between the local device and the data interaction server, so that the data interaction server decrypts the encrypted device identification information, and checks the decrypted device identification information; if the device identification information passes the check, an encrypted firmware package to be upgraded is obtained, the firmware package to be upgraded comprises a plurality of sub-firmware packages, and the integrity of the encrypted firmware package to be upgraded is checked; if the integrity of the encrypted firmware package to be upgraded passes the check, at least one group of target sub-firmware packages to be updated by the local device is determined from the encrypted plurality of sub-firmware packages, and the at least one group of target sub-firmware packages is compressed to obtain a difference package; the difference package is received through the first secure data channel, and the difference package is decrypted according to a target decryption algorithm corresponding to the target encryption algorithm to obtain the at least one group of target sub-firmware packages, and the local firmware is upgraded according to the at least one group of target sub-firmware packages.
[0007] According to still another aspect of the embodiments of the present application, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is configured to be executed by a processor to perform the steps in any of the method embodiments.
[0008] According to still another aspect of the embodiments of the present application, a computer program product or a computer program is provided, and the computer program product or the computer program comprises computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to enable the computer device to perform the steps in any of the method embodiments.
[0009] According to still another aspect of the embodiments of the present application, an electronic device is provided, and the electronic device comprises a memory and a processor. The memory stores a computer program, and the processor is configured to execute the computer program to perform the steps in any of the method embodiments.
[0010] Through the present application, five layers of security mechanisms are set. The first layer of security mechanism is to establish a first secure data channel between the data interaction server and the local device, so as to avoid the loss, leakage or tampering of the encrypted differential package in the transmission process. The second layer of security mechanism is to encrypt the device identification information uploaded by the local device, and the data interaction server decrypts and checks the encrypted device identification information of the local device, effectively blocking the access of unauthorized local devices and ensuring the legality of the local device. The third layer of security mechanism is to check the integrity of the encrypted firmware package to be upgraded, so as to ensure that the firmware package to be upgraded is not damaged or tampered with in the transmission process, and improve the integrity and reliability of the firmware to be upgraded. The fourth layer of security mechanism is that the data interaction server determines at least one group of target sub-firmware packages from the encrypted sub-firmware packages, and compresses the at least one group of target sub-firmware packages to generate an encrypted differential package, so as to reduce the data transmission amount, and the differential package is transmitted in an encrypted manner, thereby improving the security of the differential package. The fifth layer of security mechanism is to transmit the encrypted differential package to the local device through the first secure data channel, so that the local device can use a target decryption algorithm to decrypt the differential package, so that the local device can upgrade the local firmware according to the decrypted differential package, thereby improving the security of the local device upgrade and avoiding the risk of illegal modification. Therefore, the problem of loss, leakage or tampering of the firmware in the device update and upgrade process in the related art is solved, and the problem that the device cannot be safely upgraded is solved. BRIEF DESCRIPTION OF DRAWINGS
[0011] Figure 1 is an application scenario diagram of a device security upgrade method according to an embodiment of the present application.
[0012] Figure 2 is a flow diagram of an optional device security upgrade method according to an embodiment of the present application.
[0013] Figure 3 is a diagram of another optional device security upgrade method according to an embodiment of the present application.
[0014] Figure 4 is a diagram of the generation of a differential package of firmware according to an embodiment of the present application.
[0015] Figure 5 is a diagram of the splitting of firmware according to an embodiment of the present application.
[0016] Figure 6 is a framework diagram of an optional device security upgrade method according to an embodiment of the present application.
[0017] Figure 7 is a flow diagram of another optional device security upgrade method according to an embodiment of the present application.
[0018] Figure 8 is a flow diagram of another optional device security upgrade method according to an embodiment of the present application.
[0019] Figure 9 is a structural block diagram of an optional device security upgrade apparatus according to an embodiment of the present application.
[0020] Figure 10 is a structural block diagram of yet another optional device security upgrade apparatus according to an embodiment of the present application.
[0021] Figure 11 is a computer system structural block diagram of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] In order to make the personnel in the technical field better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should belong to the scope of protection of the present application.
[0023] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0024] According to an aspect of an embodiment of the present application, a device security upgrade method is provided. Optionally, in the present embodiment, the above-mentioned device security upgrade method can be applied in a hardware environment including a data interaction server 104 and a local device 102 as shown in Figure 1 The data interaction server 104 can be connected with the local device 102 through a network, can be used for data interaction for the local device 102, and a database can be set on the data interaction server 104 or independently of the data interaction server 104, for providing data storage service for the data interaction server 104.
[0025] The network can include, but is not limited to, at least one of the following: a wired network, a wireless network. The wired network can include, but is not limited to, at least one of the following: a wide area network, a metropolitan area network, a local area network. The wireless network can include, but is not limited to, at least one of the following: Wireless Fidelity (WIFI), Bluetooth. The data interaction server 104 can be, but is not limited to, a cloud server, a server cluster or other server types. The local device 102 can be, but is not limited to, a smart mapping controller, a UAV flight control system, etc.
[0026] The device security upgrade method of the embodiment of the application can be executed by the data interaction server 104, or by the local device 102, or by the data interaction server 104 and the local device 102 together. The device security upgrade method of the embodiment of the application executed by the local device 102 can also be executed by the client installed thereon.
[0027] Taking the device security upgrade method executed by the data interaction server 104 as an example, Figure 2 is a flowchart of an optional device security upgrade method according to an embodiment of the application, as Figure 2 shown, the flow of the method can include steps S202 to S208.
[0028] Step S202: Obtain encrypted device identification information of the local device through a first secure data channel between the local device, decrypt the encrypted device identification information, and verify the decrypted device identification information. The device identification information is encrypted by the local device according to a target encryption algorithm.
[0029] Step S204: If the device identification information is verified, obtain an encrypted firmware package to be upgraded, and verify the integrity of the encrypted firmware package to be upgraded. The firmware package to be upgraded includes a plurality of sub-firmware packages.
[0030] Step S206: If the integrity of the encrypted firmware package to be upgraded is verified, determine at least one group of target sub-firmware packages to be updated by the local device from the encrypted plurality of sub-firmware packages, and compress the at least one group of target sub-firmware packages to obtain a difference package.
[0031] Step S208: Transmit the difference package to the local device through the first secure data channel, so that the local device decrypts the difference package according to a target decryption algorithm corresponding to the target encryption algorithm to obtain at least one group of target sub-firmware packages, and upgrades the local firmware according to the at least one group of target sub-firmware packages.
[0032] The device security upgrade method in the embodiment can be applied to the field of firmware upgrade and applied to the scene of securely upgrading firmware of an agricultural surveying and mapping device.
[0033] In the related art, the update and upgrade of a device is performed by personnel on site, and firmware is directly transmitted to a receiver (local device) through WIFI or wired network. The receiver directly writes the firmware into the corresponding disk hardware device after receiving the firmware, and the upgrade operation is completed after the writing is completed.
[0034] However, personnel are usually required to perform the operation on site in the process of the above device update and upgrade, and no security encryption measure is considered in the transmission and upgrade process, which easily leads to the attack of the device by illegal persons during the period, thereby causing the abnormality of the machine. Meanwhile, the attacker can easily obtain the information content in the machine firmware; and the data written into the disk is not protected and confirmed in any way, and the machine is easily attacked and modified. In addition, the system file is generally more than 20 MB, and the upgrade transmission time generally needs 3 to 5 minutes, and the upgrade time needs to be close to 1 minute, which greatly introduces the risk during the period.
[0035] In order to at least partially solve the above technical problems, in the embodiment, a first secure data channel is constructed between the data interaction server and the local device to obtain the encrypted device identification information of the local device, the device identification information is decrypted and verified, the access of the unauthorized local device is effectively blocked, the integrity of the encrypted firmware package to be upgraded is verified under the condition that the verification of the identification information of the local device is passed, and the integrity and reliability of the firmware are guaranteed. A group of sub-firmware packages to be updated by the local device is confirmed from the encrypted multiple sub-firmware packages, and a difference package is compressed and generated to be transmitted to the local device, which greatly reduces the data transmission amount, shortens the upgrade period, and improves the security of the device upgrade. Therefore, the problem that the firmware is lost, leaked or tampered with in the device update and upgrade process in the related art, thereby causing the device to be unable to be safely upgraded, is solved.
[0036] The embodiment is applied to a data interaction server. The data interaction server can acquire encrypted device identification information of a local device through a first secure data channel between the data interaction server and the local device. The device identification information can refer to information used to uniquely identify the local device. For example, the device identification information can include, but is not limited to, a model of the local device, a version, a magic value (a kind of predefined special number or string used to identify the type and format of a file or a data block), a machine unique identifier (Identifier, referred to as ID), and the like. The local device can encrypt the device identification information according to a preset target encryption algorithm. The target encryption algorithm can be an asymmetric encryption algorithm, for example, an RSA encryption algorithm (Rivest-Shamir-Adleman), an elliptic curve encryption algorithm (Elliptic Curve Cryptography, referred to as ECC), or the like. The target encryption algorithm can also be a symmetric encryption algorithm, for example, an advanced encryption standard (Advanced Encryption Standard, referred to as AES), a data encryption standard (Data Encryption Standard, referred to as DES), or the like. The target encryption algorithm can also be a hash algorithm, for example, a secure hash algorithm 256-bit (Secure Hash Algorithm, referred to as SHA-256), a message digest algorithm 5 (Message-Digest Algorithm 5, referred to as MD5), or the like. The target encryption algorithm can be set according to actual conditions, and is not specifically limited herein.
[0037] The first secure data channel can be an encrypted communication channel for data transmission between the data interaction server and the local device. The first secure data channel can be used to securely transmit and receive the device identification information of the local device and the encrypted firmware package to be upgraded. Figure 3 is a schematic diagram of another optional device security upgrade method according to an embodiment of the present application, as shown in Figure 3As shown, the data interaction server obtains the encryption algorithm supported by the local device, after the data interaction server selects the encryption algorithm, the data interaction server sends the digital certificate of the data interaction server to the local device, the local device uses the secret number encrypted by the public key of the data interaction server to decrypt, the data interaction server uses the secret number to generate a session key for the local device, in this way, the first secure data channel is successfully established. The local device transmits the detailed information of the local device to the data interaction server, and the data interaction server generates a differential package and transmits it to the local device. In this embodiment, the digital certificate is used to realize key exchange and digital signature through the asymmetric encryption algorithm RSA, the server uses the private key to sign, and the local program uses the public key to verify the signature to ensure the security of the identity authentication, and the safety of the communication part is ensured through the deployment of TLS (Transport Layer Security, referred to as Transport Layer Security) and CA (Certificate Authority, referred to as Certificate Authority) certificate.
[0038] The data interaction server decrypts the encrypted device identification information of the local device, that is, the data interaction server can decrypt the encrypted device identification information of the local device according to the preset target decryption algorithm, and the target decryption algorithm can be a decryption algorithm corresponding to the target encryption algorithm. At the same time, the data interaction server checks the decrypted device identification information to determine the legitimacy of the local device, and determines the local device whose device identification information passes the check as an authorized device.
[0039] For example, after the data interaction server and the local device establish the first secure data channel, the data interaction server and the receiver (local device) first perform the check of the device identification information such as model, version, magic value, and machine unique ID. The device identification information in the local device can be accessed and modified only by the corresponding encryption and decryption of the secure encryption chip, so as to prevent the information from being obtained by a fake model and prevent malicious users from invading the local device.
[0040] In the case where the device identification information passes the check, the data interaction server obtains the encrypted firmware package to be upgraded, which can include a set of new codes and configuration files for updating the software of the local device. The firmware package to be upgraded is encrypted to protect the firmware content from being accessed by unauthorized devices. It should be noted that the encrypted firmware package to be upgraded obtained by the data interaction server can be in a compressed state, and the data interaction server can unpack the compressed encrypted firmware package to be upgraded, and the data interaction server can perform integrity check on the unpacked encrypted firmware package to be upgraded to ensure that the firmware package to be upgraded has not been modified by unauthorized devices.
[0041] The integrity check can be a hash algorithm-based integrity check. Optionally, a hash value of the original firmware package is calculated using a hash algorithm before the to-be-upgraded firmware package is encrypted. The calculated hash value is also encrypted and transmitted to the data interaction server together with the encrypted to-be-upgraded firmware package. After receiving the encrypted to-be-upgraded firmware package and the encrypted hash value, the data interaction server performs hash calculation on the just-received encrypted to-be-upgraded firmware package using the same hash algorithm, and decrypts the received encrypted hash value and compares it with the hash value before encryption. If the two values match, it indicates that the to-be-upgraded firmware package has not been tampered with in the transmission process, and the integrity is guaranteed. The integrity check can also be a message authentication code (MAC). Optionally, a MAC value is calculated using a shared key and the content of the to-be-upgraded firmware package, and the MAC value is transmitted together with the to-be-upgraded firmware package to the data interaction server. The data interaction server can calculate a MAC value of the to-be-upgraded firmware package using the same shared key and compare it with the received MAC value. If the two MAC values match, the to-be-upgraded firmware package is complete.
[0042] To improve the upgrading efficiency, in the embodiments of the present application, the differential method is used for upgrading. In the related art, the differential method uses a differential tool such as bsdiff and hidiff to compare the differences between two versions of firmware on the server side or locally. The comparison is made on complete bin files, and the generated differential file can be relatively small. Figure 4 is a schematic diagram of an optional differential package of firmware according to an embodiment of the present application, as shown in Figure 4As shown, the latest firmware package of the server is 1, the firmware package in the machine (local device) is 2, and the corresponding difference package is finally generated. However, this part (that is, the difference package) has great uncertainty, and the version of the firmware package in the machine can be 3, 4, 5, or 6, and the required firmware package version can be 1, 2, or 7. Among them, the version in the server will also have a large number of versions, which requires the server to have a complex management mechanism, increasing the risk of mistakes. At the same time, when the difference package is combined with the local file of the machine into the correct firmware package 1 by using the bsdiff tool and the like, the required CPU computing power and space are also required. Therefore, in order to solve the technical problems existing in the related difference mode, in the embodiment of the present application, the to-be-upgraded firmware package includes a plurality of sub-firmware packages, that is, each sub-firmware package is in an encrypted state. In the case that the integrity of the encrypted to-be-upgraded firmware package is passed, the data interaction server can determine at least one group of target sub-firmware packages to be updated by the local device from the to-be-upgraded firmware package according to the actual requirement of the firmware of the local device, and then compress the at least one group of target sub-firmware packages to generate a difference package. As can be seen, the data interaction server only obtains the corresponding to-be-upgraded firmware package in the case that the device identification information of the local device is verified, and the data interaction server only obtains the corresponding to-be-upgraded firmware package according to the required firmware version of the local device. The data interaction server does not store a plurality of firmware version corresponding firmware packages, compared with the related art in which the server needs to maintain different versions of to-be-upgraded firmware packages. In the embodiment of the present application, the data interaction server only stores the to-be-upgraded firmware package required by the local device, does not need a complex management mechanism, reduces the risk of mistakes, and reduces the required CPU computing power.
[0043] For example, Figure 5 is a schematic diagram of an optional firmware according to an embodiment of the present application, such as Figure 5As shown, the firmware package is "modularized", that is, the files of the firmware package to be upgraded are "sliced", and the data interaction server only needs to transmit the verification data (such as device identification information) when interacting with the local device. Each firmware and each file in the machine is an independent individual, and each large individual is composed of small individuals. After the data interaction server transmits the verification data to the local device and verifies, the data interaction server deletes the firmware to be upgraded and the same local files such as file 2, file 4, file 5, and file 6, and only leaves file 1, file 3, and file 7. After compression and verification of the final file 1, file 3, and file 7, a difference package is formed and transmitted to the local device. In the local device, file 1, file 3, and file 7 are verified and replaced in the local device. Each file 1, file 2, file 3, file 4, file 5, and file 6 is very small, each file is less than 1KB, which can achieve the best modularization, and the transmission time can also be the fastest. At the same time, the difference package making algorithm can integrate a complete verification anti-cracking mechanism, sha256 mechanism, etc., to ensure the integrity, consistency and anti-cracking of the difference package.
[0044] Many devices in the related art do not have a high-speed wifi network transmission bus, so in the embodiment, on the basis of the original large firmware, an encrypted difference transmission algorithm is developed, which can extract only the necessary upgrade files from the original 20MB firmware, and then repackage the difference upgrade firmware of several hundred KB size. Instead of using traditional bsdiff, hdiff and other methods to generate differences, a specified encryption algorithm is used to compare each file, and the generated firmware package is further packaged twice. This ensures that all new and old machines can directly support the new upgrade method.
[0045] After the data interaction server obtains the difference package, the difference package can be transmitted to the local device through the first secure data channel, so that the local device decrypts the difference package according to a target decryption algorithm corresponding to a target encryption algorithm to obtain at least one target sub-firmware package, and upgrades the local firmware according to the at least one target sub-firmware package. It should be noted that before the local device decrypts the difference package, the local device can first unpack the compressed difference package to obtain at least one encrypted target sub-firmware package, and then decrypt the at least one encrypted target sub-firmware package to obtain at least one decrypted target sub-firmware package.
[0046] For example, when the data interaction server performs differential interaction of firmware, the local device has complete information of the size, md5, etc. of all firmware files, and backup information of the last upgrade. After the local device and the data interaction server interact once, the local device is checked and determined to be a legal device. The data interaction server obtains the firmware package to be upgraded, unpacks the firmware package to be upgraded, checks the integrity of the firmware package to be upgraded, and generates and compresses a new differential package with only the files to be upgraded after the data interaction server and the local device completely interact. The data interaction server uses the security chip of the data interaction server to encrypt the complete firmware data stream into an encrypted data stream, and securely transmits the complete firmware data stream. After the local device receives the firmware data stream, the local device restores the firmware data stream to correct firmware that can be recognized through the local security chip. In this way, even if the differential package is leaked, the operator cannot perform upgrade cracking and other operations on the local device.
[0047] Therefore, in the present embodiment, the secure differential upgrade not only repairs vulnerabilities, but also improves the overall credibility of the device, enhances the user's trust in the device, and at the same time, the agricultural device may have software vulnerabilities, security vulnerabilities, or functional problems, and the secure upgrade provides an opportunity to repair these problems, as well as an opportunity to introduce new functions and improvements; in addition, the agricultural surveying and mapping device usually involves processing sensitive geographic data and user information, and the secure upgrade ensures that the data is not lost, leaked, or tampered with during the upgrade process.
[0048] Through the embodiments provided in the present application, five-layer security mechanisms are set. The first-layer security mechanism is to establish a first secure data channel between the data interaction server and the local device to avoid the loss, leakage or tampering of encrypted differential packages in the transmission process. The second-layer security mechanism is to encrypt the device identification information uploaded by the local device, and the data interaction server decrypts and checks the encrypted device identification information of the local device, effectively blocking the access of unauthorized devices and ensuring the legality of the local device. The third-layer security mechanism is to check the integrity of the encrypted firmware package to be upgraded to ensure that the firmware package to be upgraded is not damaged or tampered with in the transmission process, thereby improving the integrity and reliability of the firmware to be upgraded. The fourth-layer security mechanism is for the data interaction server to determine at least one group of target sub-firmware packages from the encrypted sub-firmware packages and compress the at least one group of target sub-firmware packages to generate encrypted differential packages, thereby reducing the amount of data transmission and improving the security of the differential packages. The fifth-layer security mechanism is to transmit the encrypted differential packages to the local device through the first secure data channel, so that the local device can use a target decryption algorithm to decrypt the differential packages, thereby enabling the local device to upgrade the local firmware according to the decrypted differential packages, improving the security of the local device upgrade, and avoiding the risk of illegal modification. Therefore, the problem of firmware loss, leakage or tampering in the device update and upgrade process in the related art, which leads to the inability of the device to safely upgrade, is solved.
[0049] In some example embodiments, in the case where the device identification information verification is passed, the encrypted firmware package to be upgraded is obtained, including: in the case where the device identification information verification is passed, performing security authentication with the firmware deployment server according to a first preset authentication method, and obtaining the encrypted firmware package to be upgraded from the firmware deployment server after the security authentication is passed; the firmware package to be upgraded is a firmware package obtained by a packaging server by splitting firmware information and firmware content into a plurality of sub-firmware packages, generating a check data according to the plurality of sub-firmware packages, and encrypting and compressing the plurality of sub-firmware packages and the check data according to a target encryption algorithm, and the firmware package to be upgraded is deployed to the firmware deployment server after the packaging server performs security authentication with the firmware deployment server according to a second preset authentication method.
[0050] In the embodiment, the firmware deployment server mentioned above can refer to a server used to store, manage and distribute the firmware package to be upgraded. The data interaction server performs security verification on the firmware deployment server according to a first preset authentication method, wherein the first preset authentication method refers to a method of identity verification between the data interaction server and the firmware deployment server. For example, the first preset authentication method can include but is not limited to TLS, Secure Sockets Layer (SSL), CA certificate, etc. The data interaction server can perform security authentication on the firmware deployment server according to at least one of the first preset authentication method. In the embodiment, the firmware deployment server must support the TLS / SSL protocol, use a digital certificate and implement key exchange and digital signature through the asymmetric encryption algorithm RSA.
[0051] After the security authentication is passed, the data interaction server obtains the encrypted firmware package to be upgraded from the firmware deployment server, wherein the firmware package to be upgraded can be a firmware package obtained by a packaging server by splitting firmware information and firmware content into multiple sub firmware packages, generating a check data according to the multiple sub firmware packages, and encrypting and compressing the multiple sub firmware packages and the check data according to a target encryption algorithm. The packaging server mentioned above can refer to a server used to split firmware information and firmware content into multiple sub firmware packages, generate a check data according to the multiple sub firmware packages, and encrypt and compress the multiple sub firmware packages and the check data. The check data is data used to check the integrity of the firmware package to be upgraded. For example, the check data includes firmware meta information of each sub firmware package, wherein the firmware meta information refers to basic attribute information of the sub firmware package. For example, the firmware meta information can be version number, file size, modification timestamp and hash value, etc., which are not limited here.
[0052] The firmware package to be upgraded mentioned above can be deployed to the firmware deployment server by the packaging server after the packaging server passes the security authentication with the firmware deployment server according to a second preset authentication method, wherein the second preset authentication method can be an authentication method used to verify the firmware package to be upgraded between the packaging server and the firmware deployment server. The second preset authentication method can be the same as the first preset authentication method, which is not described here again. Moreover, the packaging server can perform security authentication with the firmware deployment server through a network, and deploy the firmware package to be upgraded to the firmware deployment server after the authentication is passed.
[0053] It should be noted that the security transmission between the packaging server and the firmware deployment server is local, and the cloud of the firmware deployment server and the cloud of the data server (data interaction server) are local public networks, which are closed within the environment.
[0054] By the embodiment, the data interaction server is relieved of management pressure and CPU computing power by generating the to-be-upgraded firmware package by the packaging server and encrypting the to-be-upgraded firmware package, and the to-be-upgraded firmware package is deployed to the firmware deployment server, which stores and manages the to-be-upgraded firmware package, thereby relieving the data interaction server of storage pressure. The first preset authentication method is used to perform security authentication with the firmware deployment server, thereby enhancing the security and efficiency of the firmware upgrade process. In addition, the integrity of the to-be-upgraded firmware package is ensured by generating the check data according to the plurality of sub firmware packages and encrypting and compressing the plurality of sub firmware packages and the check data according to the target encryption algorithm to obtain a firmware, thereby improving the reliability of the firmware upgrade. The plurality of encryption mechanisms, such as packaging encryption, pure handshake encryption, and local encryption, are used to ensure the credibility of the local firmware upgrade.
[0055] In some example embodiments, the integrity of the encrypted to-be-upgraded firmware package is verified, including: unpacking the encrypted to-be-upgraded firmware package to obtain a plurality of sub firmware packages and check data; obtaining and decrypting current firmware meta information of the local device, and verifying the integrity of the to-be-upgraded firmware package according to firmware meta information of the plurality of sub firmware packages in the check data and the current firmware meta information.
[0056] In the embodiment, the data interaction server unpacks the obtained encrypted to-be-upgraded firmware package, thereby obtaining a plurality of sub firmware packages and check data. The check data can include firmware meta information of the plurality of sub firmware packages. In addition, the data interaction server obtains encrypted current firmware meta information of the local device and decrypts the encrypted current firmware meta information. The integrity of the to-be-upgraded firmware package is verified according to the check data and the current firmware meta information. For example, the data interaction server can compare firmware meta information of the plurality of sub firmware packages in the check data obtained from the to-be-upgraded firmware package with current firmware meta information obtained from the local device, thereby verifying the integrity of the to-be-upgraded firmware package.
[0057] By the embodiment, the encrypted to-be-upgraded firmware package is decrypted to obtain a plurality of sub firmware packages and firmware meta information of the plurality of sub firmware packages in the check data, which can effectively prevent the risk of leakage and tampering of the to-be-upgraded firmware package during transmission. In addition, the current firmware meta information of the local device is obtained and decrypted, and the integrity of the to-be-upgraded firmware package is verified according to firmware meta information of the plurality of sub firmware packages in the check data and the current firmware meta information, which can effectively detect whether the to-be-upgraded firmware package is complete and avoid upgrade failure caused by data loss or damage.
[0058] In some example embodiments, in the scenario where the local device is an agricultural device, most agricultural devices are installed in remote areas, and the network environment is limited. Therefore, in addition to the conventional network upgrade solution, the embodiment also reserves a local secure differential upgrade solution for the terminal device, to ensure that the secure differential upgrade can be normally performed in various complex scenarios. The above method further includes: performing secure authentication with the terminal device through a second secure data channel between the terminal device and the data interaction server according to a third preset authentication method, and transmitting the to-be-upgraded firmware package to the terminal device through the second secure data channel after the secure authentication is passed; in the case of an exception of the data interaction server, continuing to perform the step of obtaining the encrypted device identification information of the local device through a third secure data channel between the terminal device and the local device until the local device completes the firmware update.
[0059] In the embodiment, the data interaction server performs secure authentication with the terminal device through a second secure data channel between the terminal device and the data interaction server according to a third preset authentication method. The second secure data channel can be an encrypted communication channel for data transmission between the data interaction server and the terminal device, and the establishment method is the same as that of the first secure data channel, which will not be repeated here. The third preset authentication method can be used to authenticate the security of the data interaction server and the terminal device to determine whether the terminal device is an authorized device, wherein the third preset authentication method can be the same as the first preset authentication method and the second preset authentication method described above, which will not be repeated here.
[0060] The terminal device is a tablet computer, and the local device is a local controller. The tablet computer and the data interaction server first interact to obtain the corresponding to-be-upgraded firmware package, and then the tablet computer takes the responsibility of the data interaction server and performs corresponding secure differential interaction with the local device. Specifically, in the case where the data interaction server is abnormal (such as the first secure data channel between the data interaction server and the local device is disconnected, etc.) and the secure authentication between the data interaction server and the terminal device is passed, the data interaction server transmits the to-be-upgraded firmware package to the terminal device through the second secure data channel, the terminal device and the local device interact through a local serial port line, and the terminal device performs the step of obtaining the encrypted device identification information of the local device through a third secure data channel between the terminal device and the local device, wherein the third secure data channel can be an encrypted communication channel for data transmission between the terminal device and the local device. The terminal device verifies the device identification information and the current firmware information of the local device, and in the case where both are verified, the terminal device transmits the differential package to the local device to make the local device complete the firmware update.
[0061] Through the embodiment, the second secure data channel enables secure transmission of the to-be-upgraded firmware package from the data interaction server to the terminal device, and the third secure data channel provides a backup upgrade path when the data interaction server is abnormal, so that the terminal device can directly establish a secure connection with the local device, obtain device identification information, and transmit and upgrade the firmware package, thereby effectively preventing security threats such as data leakage, tampering, and unauthorized access that may occur during the upgrade process.
[0062] The device security upgrade method in the embodiment of the application is explained and described below in combination with optional examples. In the optional examples, the local device is a local controller, and the terminal device is a tablet, Figure 6 is a framework schematic diagram of an optional device security upgrade method according to an embodiment of the application, as Figure 6 shown, the packaging server encrypts the to-be-upgraded firmware package through the secure chip, including encrypting the firmware information and the firmware information, the packaging server securely and encryptedly transmits the encrypted to-be-upgraded firmware package to the firmware deployment server, the firmware deployment server has TLS authentication, a CA certificate, and RSA encryption, the firmware deployment server is authenticated through the cloud with the data interaction server, and the data interaction server and the local device have two modes for firmware transmission. In the first mode, the data interaction server directly and securely differentially interacts with the local device, transmits the differential package to the local device, and the local device performs local security analysis through the secure chip. In the second mode, the data interaction server securely and encryptedly transmits the encrypted to-be-upgraded firmware package to the terminal device, the terminal device generates the differential package, the terminal device and the local device perform local security differential interaction, the terminal device securely transmits the differential package to the local device through the local serial port, and the local device performs local security analysis through the secure chip.
[0063] According to another aspect of the embodiment of the application, a device upgrade method is also provided, which is applied to a local device, and the method comprises:
[0064] I. encrypting the device identification information of the local device according to a target encryption algorithm, and transmitting the encrypted device identification information to a data interaction server through a first secure data channel between the local device and the data interaction server, so that the data interaction server decrypts the encrypted device identification information, checks the decrypted device identification information, obtains an encrypted to-be-upgraded firmware package in the case where the device identification information passes the check, the to-be-upgraded firmware package includes a plurality of sub-firmware packages, checks the integrity of the encrypted to-be-upgraded firmware package, determines at least one group of target sub-firmware packages to be updated by the local device from the encrypted plurality of sub-firmware packages in the case where the integrity of the encrypted to-be-upgraded firmware package passes the check, and compresses the encrypted at least one group of target sub-firmware packages to obtain a differential package.
[0065] II. receiving the differential package through the first secure data channel, and decrypting the differential package according to a target decryption algorithm corresponding to the target encryption algorithm to obtain at least one target sub-firmware package, and upgrading the local firmware according to the at least one target sub-firmware package.
[0066] In the embodiment, the local device can encrypt the device identification information of the local device according to the target encryption algorithm. The target encryption algorithm can be an asymmetric encryption algorithm, such as an RSA encryption algorithm (Rivest-Shamir-Adleman), an elliptic curve encryption algorithm (ECC), etc. The target encryption algorithm can also be a symmetric encryption algorithm, such as an AES (Advanced Encryption Standard), a DES (Data Encryption Standard), etc. The target encryption algorithm can also be a hash algorithm, such as a SHA-256 (Secure Hash Algorithm), an MD5 (Message-Digest Algorithm 5), etc. The target encryption algorithm can be set according to actual conditions, and is not specifically limited herein.
[0067] The local device can transmit the encrypted device identification information to the data interaction server through the first secure data channel between the local device and the data interaction server, so that the data interaction server performs corresponding operations. The specific operations can be understood with reference to the above description.
[0068] After the data interaction server generates the differential package, the local device can receive the differential package through the first secure data channel, and decrypt the differential package according to a target decryption algorithm corresponding to the target encryption algorithm to obtain at least one target sub-firmware package, and upgrade the local firmware of the local device according to the at least one target sub-firmware package.
[0069] By the embodiment, five-layer security mechanisms are set. The first-layer security mechanism is to establish a first secure data channel between the data interaction server and the local device to avoid loss, leakage or tampering of the encrypted differential package in the transmission process. The second-layer security mechanism is to decrypt and verify the encrypted device identification information of the local device by the data interaction server to effectively block the access of unauthorized local devices and ensure the legality of the local device. The third-layer security mechanism is to verify the integrity of the encrypted to-be-upgraded firmware package to ensure that the to-be-upgraded firmware package is not damaged or tampered with in the transmission process and improve the integrity and reliability of the to-be-upgraded firmware. The fourth-layer security mechanism is to determine at least one group of target sub-firmware packages from the encrypted sub-firmware packages by the data interaction server and to compress and generate encrypted differential packages from the at least one group of target sub-firmware packages to reduce the data transmission amount and improve the security of the differential packages. The fifth-layer security mechanism is to transmit the encrypted differential packages to the local device through the first secure data channel so that the local device can decrypt the differential packages using a target decryption algorithm, thereby enabling the local device to upgrade the local firmware according to the decrypted differential packages and improving the security of the local device upgrade to avoid the risk of illegal modification. Therefore, the problem of loss, leakage or tampering of the firmware in the device update and upgrade process in the related art, which causes the device to be unable to be safely upgraded, is solved.
[0070] In some example embodiments, the to-be-upgraded firmware package further includes a verification data; the verification data includes firmware meta information of the plurality of sub-firmware packages.
[0071] After the encrypted device identification information is transmitted to the data interaction server through the first secure data channel between the data interaction server and the local device, the device security upgrade method further includes:
[0072] In the case where the device identification information verification is passed, the current firmware meta information of the local device is encrypted according to a target encryption algorithm, and the encrypted current firmware meta information is transmitted to the data interaction server through the first secure data channel, so that the data interaction server unpacks the encrypted to-be-upgraded firmware package to obtain the plurality of sub-firmware packages and the verification data, and verifies the integrity of the to-be-upgraded firmware package according to the firmware meta information of the plurality of sub-firmware packages in the verification data and the decrypted current firmware meta information.
[0073] In the embodiment, in the case where the device identification information of the local device is verified by the data interaction server, the local device encrypts the current firmware meta information of the local device according to a target encryption algorithm to obtain encrypted current firmware meta information, and the local device transmits the encrypted current firmware meta information to the data interaction server through the first secure data channel, so that the data server performs corresponding operations.
[0074] By encrypting the current firmware meta information of the local device, the current firmware meta information can be effectively prevented from being leaked and tampered during transmission, and the data interaction server can effectively perform integrity checking on the firmware package to be upgraded.
[0075] In some example embodiments, before the device identification information of the local device is encrypted according to the target encryption algorithm, the device security upgrade method further comprises:
[0076] After the local device is powered on, it is checked whether the local firmware is legal. If the local firmware is not legal, the historical legal firmware is obtained from the backup system, and the local firmware is updated according to the historical legal firmware. If the local firmware is legal, it is checked whether the local device is in the state to be upgraded. If the local device is in the state to be upgraded, the step of encrypting the device identification information of the local device according to the target encryption algorithm is performed.
[0077] In this embodiment, after the local device is powered on, the local device can check whether the local firmware is legal. In an optional embodiment, the local device reads the metadata of the local firmware, including version information, digital signature, hash value, etc., to verify whether the local firmware is tamper-free and trusted. For example, the local device calculates the hash value of the current local firmware, checks whether the digital signature of the local firmware is valid, and compares the local firmware version with the expected legal version.
[0078] If the local firmware is not legal, the local device can obtain the historical legal firmware from the backup system and update the local firmware according to the historical legal firmware. The backup system can be an independent system that saves the historical legal firmware. For example, the backup system can be a system in the linux operating system, a separate system composed of ramfs+kernel, an independent system entered by different key inputs or different environment variables during the boot of the local device, which runs completely in memory, so that even if the formal system of the local device is damaged, the backup system can be entered to upgrade the formal system and perform repair and restoration operations. For another example, the backup system can be a closed small system generated by kernel rootfs and device tree.
[0079] If the local firmware is legal, the local device further checks whether the local device is in the state to be upgraded. If the local device is in the state to be upgraded, the step of encrypting the device identification information of the local device according to the target encryption algorithm is performed. If the local device is not in the state to be upgraded, the normal startup procedure can be performed.
[0080] For example, Figure 7 is another optional flowchart of a device security upgrade method according to an embodiment of the present application.Figure 7 As shown, the local firmware is checked for legality, if the local firmware is not legal, the backup system is entered to restore to legal firmware, if the local firmware is legal, the local device is normally started, after starting, it is checked whether the local device needs to be upgraded, if the local device needs to be upgraded, the backup system is entered for upgrade operation, if the local device does not need to be upgraded, the normal starting program is started.
[0081] In an optional embodiment, the backup system is entered for upgrade by setting a flag in the local system, and if the local file is abnormally modified, illegally damaged, or fails to pass the starting check, or the machine is dead and cannot be normally started, the corresponding restoration operation in the backup system can also be performed. In addition, if the upgrade process is powered off and the formal system cannot be started, the backup system is also entered for corresponding upgrade operation.
[0082] In another optional embodiment, the backup system upgrade and the conventional system upgrade are both directly performed in the local system or in uboot.
[0083] Through the embodiment, the legality of the local firmware is checked, and the historical legal firmware is restored from the backup system when the local firmware is not legal. The legality of the local firmware is checked, and the local device is restored to legal firmware in the backup system when the local firmware is abnormally modified, the starting check fails, or the local device is dead and cannot be normally started, thereby avoiding the possibility of being damaged and ensuring that the local device always runs in a safe and trusted state. After the legality of the firmware is confirmed, the device identification information is further encrypted, ensuring the safe transmission of information during firmware upgrade, effectively reducing the security risks caused by leakage of local firmware, and improving the stability and security of the device during firmware upgrade.
[0084] In some example embodiments, each target sub-firmware package in at least one group of target sub-firmware packages corresponds to a firmware category identifier; and the local firmware is upgraded according to the at least one group of target sub-firmware packages, including:
[0085] In the conventional system, the local firmware is upgraded according to a first group of target sub-firmware packages in the at least one group of target sub-firmware packages, which are identified as application programs according to firmware category identifiers; and in the backup system, the local firmware is upgraded according to a second group of target sub-firmware packages in the at least one group of target sub-firmware packages, which are identified as operating systems according to firmware type identifiers.
[0086] In the embodiment, the firmware category identifier can be a classification label of each target sub-firmware package, used to indicate the update type or system layer corresponding to the target sub-firmware package on the local device, such as an application, an operating system kernel, a device driver, etc. For example, the firmware category identifier can include a kernel and a device tree blob (dtb). The regular system can refer to the main operating system running on the local device, which can be used for daily operation and function implementation of the local device.
[0087] For the first group of target sub-firmware packages with the firmware category identifier as an application, the upgrade operation is performed in the regular system, which means that the local firmware can be upgraded by replacing the code or data of the existing application in the normal operation state of the local device and under the regular system. For example, the firmware such as code for data processing, user interface, or specific function module is updated.
[0088] For the second group of target sub-firmware packages with the firmware type identifier as an operating system, the upgrade operation is performed in the backup system, which is an independent operating system storing historical legal firmware, used to boot the device and restore it to a legal state when the regular system fails. Updating the firmware package of the operating system in the backup system means that the kernel, system library, or device tree and other key components can be safely updated without affecting the current operation state of the device.
[0089] In an optional embodiment, when the local device and the data interaction server perform firmware transmission through the first secure channel, the local device receives and upgrades the first group of target sub-firmware packages in the regular system to update the application; and when the operating system needs to be updated, the local device enters the backup system to receive and upgrade the second group of target sub-firmware packages.
[0090] It should be noted that for the backup system part, based on the open source version, private security verification work can be performed, only the backup system that has passed encryption authentication can normally run, and a dynamic security authentication password is set to prevent external personnel from damaging and modifying the formal system by cracking the backup system.
[0091] Through the embodiment, the target sub-firmware packages are classified using the firmware category identifier, and the applications and operating systems are updated in the regular system and the backup system, respectively, which not only improves the efficiency and security of firmware upgrade, but also reduces the impact of upgrade on device operation.
[0092] In some example embodiments, upgrading the local firmware in the backup system according to the second group of target sub-firmware packages with the firmware type identifier as an operating system in the at least one group of target sub-firmware packages includes:
[0093] The first system environment version of the second group of target sub-firmware packages is compared with the second system environment version of the local device, a third group of target sub-firmware packages in which the first system environment version is consistent with the second system environment version is determined from the second group of target sub-firmware packages, and the local firmware is upgraded in the regular system according to the third group of target sub-firmware packages, and the local firmware is upgraded in the backup system according to the target sub-firmware packages other than the third group of target sub-firmware packages in the second group of target sub-firmware packages.
[0094] In the embodiment, the local device compares the first system environment version in the latest second group of target sub-firmware packages (the firmware type identifier is the operating system) with the second system environment version currently running on the local device, for example, by reading the version information in the second group of target sub-firmware packages and comparing it with the version information currently stored by the device. The first system environment version can be the operating system version information, which can be used to identify the state or configuration of the system environment, for example, the first system environment version can include but is not limited to the kernel version, the device tree version, the system library version, etc. The second system environment version can refer to the version information of the local firmware of the local device, which can be used to identify the state or configuration of the local firmware, for example, the first system environment version can include but is not limited to the kernel version, the device tree version, the system library version, etc.
[0095] By comparing the first system environment version of the second group of target sub-firmware packages with the second system environment version of the local device, a third group of target sub-firmware packages in which the first system environment version is consistent with the second system environment version is identified from the second group of target sub-firmware packages, wherein the third group of target sub-firmware packages can be a sub-firmware package consistent with the current system environment version of the local device, i.e. the third group of target sub-firmware packages can contain components matching the current system environment version of the local device, such as kernel modules, device drivers or system configuration files, etc.
[0096] For the regular system, the local firmware can be upgraded according to the third group of target sub-firmware packages, i.e. in the regular system, the local firmware can be upgraded according to the target sub-firmware of the firmware type identifier as application program in the third group of target sub-firmware, for example, the local firmware is upgraded according to the application program code, configuration file, etc. target sub-firmware in the third group of target sub-firmware.
[0097] For the backup system, the local firmware can be upgraded according to the target sub-firmware packages other than the third group of target sub-firmware packages in the second group of target sub-firmware packages, i.e. in the backup system, the local firmware can be upgraded according to the target sub-firmware of the firmware type identifier as operating system in the target sub-firmware packages other than the third group of target sub-firmware packages in the second group of target sub-firmware packages. For example, the target sub-firmware packages other than the third group of target sub-firmware packages in the second group of target sub-firmware packages can include but are not limited to the kernel, the device tree, etc.
[0098] In an optional embodiment, after the local device and the data interaction server establish a secure connection through the first secure data channel, the data interaction server transmits the differential package to the local device. On the local device, the third group of target sub-firmware packages are updated through the regular system first, and the application program is upgraded. Subsequently, the local device enters the backup system and performs the update of the operating system.
[0099] In another optional embodiment, when the local device performs offline differential upgrade through the terminal device, the terminal device and the local device establish a third secure data channel to generate the differential package. Then, the terminal device transmits the differential package to the local device, and the local device upgrades the local firmware according to the third group of target sub-firmware in the regular system, and upgrades the local firmware according to the target sub-firmware packages other than the third group of target sub-firmware in the second group of target sub-firmware packages in the backup system.
[0100] Through this embodiment, the local firmware to be upgraded is compatible with the current system environment of the local device by comparing the first system environment version and the second system environment version, which reduces the upgrade exceptions or device failures caused by inconsistent versions, and cooperatively performs the upgrade operation in the regular system and the backup system, which can effectively improve the efficiency, security and reliability of the firmware upgrade.
[0101] In some example embodiments, upgrading the local firmware according to the target sub-firmware packages other than the third group of target sub-firmware in the second group of target sub-firmware packages in the backup system comprises:
[0102] I. In the case that the rescue system flag bit is set, enter the backup system and upgrade the local firmware according to the target sub-firmware packages other than the third group of target sub-firmware in the second group of target sub-firmware packages in the backup system. The rescue system flag bit is used to represent whether the rescue system is in working state. The rescue system is used to guide the local device to enter a predefined recovery environment when the local device cannot start correctly.
[0103] II. Compare whether the updated local firmware and the memory file are consistent. In the case that the updated local firmware and the memory file are inconsistent, re-execute the step of upgrading the local firmware according to the target sub-firmware packages other than the third group of target sub-firmware in the second group of target sub-firmware packages in the backup system, and count the number of updates.
[0104] III. In the case that the number of updates is greater than a preset number, or the updated local firmware and the memory file are consistent, reset the rescue system flag bit and exit the backup system.
[0105] In the embodiment, the brick rescue system flag can be used to mark whether the brick rescue system needs to enter a working state. The brick rescue system flag can be a binary flag. For example, when the local device encounters a situation where it cannot be started normally, the brick rescue system flag is set, triggering the local device to enter the brick rescue system for firmware recovery and upgrade. The brick rescue system can be used to guide the local device to enter a predefined recovery environment when the local device cannot be started correctly, where the predefined recovery environment can refer to a set of environments in the brick rescue system, which are pre-installed with necessary drivers, tools and firmware, and are used to guide the local device to enter a safe environment to perform recovery and upgrade operations when the local device encounters firmware damage or startup failure.
[0106] When the local device is started, the state of the brick rescue system flag can be detected. If the brick rescue system flag is set (i.e., the value of the brick rescue system flag is 1), it indicates that a startup attempt on the device has failed and there can be firmware damage. At this time, the local device automatically jumps into the backup system. In the backup system, the local device upgrades the local firmware according to the target sub-firmware packages in the second group of target sub-firmware packages except the third group of target sub-firmware packages.
[0107] After the local firmware is updated in the backup system, the local device can perform a consistency check between the updated local firmware and the memory file content to determine whether the update operation has introduced new errors or caused data inconsistency. In the case where the updated local firmware and the memory file content are inconsistent, the backup system will re-execute the update step, i.e., perform the step of upgrading the local firmware according to the target sub-firmware packages in the second group of target sub-firmware packages except the third group of target sub-firmware packages in the backup system, while recording the number of retries of the update.
[0108] In the case where the updated local firmware and the memory file content are consistent, the brick rescue system flag is reset, i.e., the value of the brick rescue system flag is set to a state other than 1, and the backup system is exited and returned to the normal system; or in the case where the number of updates is greater than a preset number, the brick rescue system flag is reset, i.e., the value of the brick rescue system flag is set to a state other than 1, and the backup system is exited and returned to the normal system. The preset number can be set to prevent infinite update attempts. Once the preset number is reached, the backup system will consider that the current firmware package can not be suitable for the local device or there are other unforeseen problems, and thus take further troubleshooting measures.
[0109] For example, Figure 8 is a flowchart of another optional device security upgrade method of the embodiment of the application, as Figure 8As shown, in the conventional system (update_machine part), it is checked whether the kernel / dtb identifier exists in the set of target sub-firmware packages in the differential package. If not, the system upgrade ends, and the local firmware is upgraded in the conventional system according to the set of target sub-firmware packages. If yes, it is checked whether the kernel version and / or dtb version of the second set of target sub-firmware packages with the firmware type identifier as the operating system in the set of target sub-firmware packages is consistent with the local device. In the case where the kernel version and / or dtb version is consistent with the local device, the local firmware is upgraded in the conventional system according to the third set of target sub-firmware packages with the first system environment version consistent with the second system environment version. In the case where the kernel version and / or dtb version is inconsistent with the local device, the backup system upgrade flag bit is set and the system is restarted. It is judged whether the rescue brick system flag bit is 1. If the rescue brick system flag bit is not 1, it ends and enters the conventional system. If the rescue brick system flag bit is 1, it enters the backup system (initramfs part). It is judged whether the system upgrade flag bit is 1. If the system upgrade flag bit is not 1, it enters the rescue brick mode. If the system upgrade flag bit is 1, the system image is upgraded, i.e., the local firmware is upgraded in the backup system according to the target sub-firmware packages in the second set of target sub-firmware packages except the third set of target sub-firmware packages. It is compared whether the contents of the image file and the norflash file are consistent. If the contents of the image file and the norflash file are inconsistent, it is judged whether the number of kernel / dtb upgrades is greater than 3. If the number of kernel / dtb upgrades is not greater than 3 (i.e., less than or equal to 3), the system image is upgraded again, and it is compared again whether the contents of the image file and the norflash file are consistent. If the number of kernel / dtb upgrades is greater than 3, the rescue brick system flag bit is set to be not 1, and the upgrade state flag bit is written to be not 1, i.e., the upgrade ends and enters the conventional system. If the contents of the image file and the norflash file are consistent, the rescue brick system flag bit is set to be not 1, and the upgrade state flag bit is written to be not 1, i.e., the firmware upgrade ends and enters the conventional system.
[0110] By this embodiment, the rescue brick system flag bit is set to enter the backup system, so that the local device can automatically start the rescue recovery process when encountering firmware damage or startup anomaly, greatly enhancing the self-repairing ability and reliability of the local device. By comparing the consistency of the updated local firmware and the memory file content, errors that may occur in the updating process can be timely discovered and corrected, ensuring the accuracy and safety of the firmware update, and avoiding device failure due to improper updating operation. The preset limit of the number of updates enables the local device to effectively avoid falling into an infinite loop of updating attempts when encountering unsolvable updating problems, saving time and computing resources, and reducing the risk of the device being in an uncertain state for a long time.
[0111] In summary, based on the background and needs of agricultural equipment, secure differential upgrade becomes a key measure to ensure the continuous and stable operation of the equipment and protect the security of user data. Secure differential upgrade can meet the requirements of different fields and industries, maintain the competitiveness and credibility of the equipment in the changing technical environment, and can also be completely reused on any product line.
[0112] It should be noted that, for the foregoing method embodiments, in order to simply describe, they are all expressed as a combination of a series of actions, but those skilled in the art should know that the present application is not limited by the order of the described actions, because according to the present application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily necessary for the present application.
[0113] From the above description of the embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and the necessary general hardware platform, of course, it can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory (ROM) / random access memory (RAM), a magnetic disk, an optical disk) and includes a plurality of instructions for causing an end device (which can be a mobile phone, a computer, a server, or a network device) to execute the method described in each embodiment of the present application.
[0114] According to another aspect of the embodiments of the present application, a device security upgrade apparatus is provided, which is applied to a data interaction server, such as Figure 9 As shown, the apparatus includes a first execution unit 902, a second execution unit 904, a third execution unit 906, and a fourth execution unit 908.
[0115] The first execution unit 902 is configured to obtain encrypted device identification information of the local device through a first secure data channel between the local device and the apparatus, decrypt the encrypted device identification information, and verify the decrypted device identification information. The device identification information is encrypted by the local device according to a target encryption algorithm.
[0116] The second execution unit 904 is configured to, in the case that the device identification information passes the verification, obtain an encrypted firmware package to be upgraded, and verify the integrity of the encrypted firmware package to be upgraded. The firmware package to be upgraded includes a plurality of sub-firmware packages.
[0117] The third execution unit 906 is configured to determine at least one set of target sub-firmware packages of the local device from the encrypted plurality of sub-firmware packages when the integrity check of the encrypted firmware package to be upgraded is passed, and compress the encrypted at least one set of target sub-firmware packages to obtain a differential package.
[0118] The fourth execution unit 908 is configured to transmit the differential package to the local device through the first secure data channel, so that the local device decrypts the differential package according to a target decryption algorithm corresponding to the target encryption algorithm to obtain the at least one set of target sub-firmware packages, and upgrades the local firmware according to the at least one set of target sub-firmware packages.
[0119] In an exemplary embodiment, the second execution unit 904 includes a first execution module configured to perform secure authentication with the firmware deployment server according to a first preset authentication method when the device identification information is passed, and obtain the encrypted firmware package to be upgraded from the firmware deployment server after the secure authentication is passed. The firmware package to be upgraded is a firmware package obtained by a packaging server from encrypting and compressing a plurality of sub-firmware packages and a check data according to a target encryption algorithm, wherein the plurality of sub-firmware packages are obtained by the packaging server from splitting firmware information and firmware content, and the firmware package to be upgraded is deployed to the firmware deployment server after the packaging server performs secure authentication with the firmware deployment server according to a second preset authentication method.
[0120] In an exemplary embodiment, the firmware package to be upgraded further includes a check data; the check data includes firmware element information of the plurality of sub-firmware packages; and the second execution unit 904 includes:
[0121] A second execution module configured to unpack the encrypted firmware package to be upgraded to obtain the plurality of sub-firmware packages and the check data, obtain and decrypt the current firmware element information of the local device, and check the integrity of the firmware package to be upgraded according to the firmware element information of the plurality of sub-firmware packages in the check data and the current firmware element information.
[0122] In an exemplary embodiment, the apparatus further includes:
[0123] A fifth execution unit configured to perform secure authentication with the terminal device according to a third preset authentication method through a second secure data channel between the terminal device and the apparatus, and transmit the firmware package to be upgraded to the terminal device through the second secure data channel after the secure authentication is passed.
[0124] A sixth execution unit configured to continue the step of obtaining the encrypted device identification information of the local device through a third secure data channel between the terminal device and the local device when the data interaction server is abnormal, until the local device completes the firmware update.
[0125] According to yet another aspect of the embodiments of the present application, a device security upgrade apparatus is provided, which is applied to a local device, such as Figure 10 As shown, the apparatus comprises a first encryption unit 1001 and a first decryption unit 1002.
[0126] The first encryption unit 1001 is configured to encrypt the device identification information of the local device according to a target encryption algorithm, and transmit the encrypted device identification information to a data interaction server through a first secure data channel between the local device and the data interaction server, so that the data interaction server decrypts the encrypted device identification information, and checks the decrypted device identification information. If the device identification information passes the check, the encrypted firmware package to be upgraded is obtained, the firmware package to be upgraded comprises a plurality of sub firmware packages, and the integrity of the encrypted firmware package to be upgraded is checked. If the integrity of the encrypted firmware package to be upgraded passes the check, at least one group of target sub firmware packages to be updated by the local device is determined from the encrypted plurality of sub firmware packages, and the at least one group of target sub firmware packages is compressed to obtain a differential package.
[0127] The first decryption unit 1002 is configured to receive the differential package through the first secure data channel, decrypt the differential package according to a target decryption algorithm corresponding to the target encryption algorithm, obtain the at least one group of target sub firmware packages, and upgrade the local firmware according to the at least one group of target sub firmware packages.
[0128] In an exemplary embodiment, the firmware package to be upgraded further comprises a check data; the check data comprises firmware meta information of the plurality of sub firmware packages; and the apparatus further comprises:
[0129] The second encryption unit is configured to, if the device identification information passes the check, encrypt the current firmware meta information of the local device according to the target encryption algorithm, and transmit the encrypted current firmware meta information to the data interaction server through the first secure data channel, so that the data interaction server unpacks the encrypted firmware package to be upgraded to obtain the plurality of sub firmware packages and the check data, and checks the integrity of the firmware package to be upgraded according to the firmware meta information of the plurality of sub firmware packages in the check data and the decrypted current firmware meta information.
[0130] In an exemplary embodiment, the apparatus further comprises:
[0131] The first obtaining unit is configured to, after the local device is powered on, check whether the local firmware is legal, and if the local firmware is not legal, obtain historical legal firmware from a backup system, and update the local firmware according to the historical legal firmware.
[0132] The third encryption unit is configured to, in the case that the local firmware is legitimate, check whether the local device is in a state of waiting for upgrading, and in the case that the local device is in the state of waiting for upgrading, perform the step of encrypting the device identification information of the local device according to the target encryption algorithm.
[0133] In an exemplary embodiment, each target sub-firmware package in the at least one group of target sub-firmware packages corresponds to a firmware category identifier; the first decryption unit 1002 comprises:
[0134] The first upgrading module is configured to upgrade the local firmware in the normal system according to a first group of target sub-firmware packages in the at least one group of target sub-firmware packages, the firmware category identifier of which is an application, and upgrade the local firmware in the backup system according to a second group of target sub-firmware packages in the at least one group of target sub-firmware packages, the firmware type identifier of which is an operating system.
[0135] In an exemplary embodiment, the first upgrading module comprises:
[0136] The first comparison sub-unit is configured to compare a first system environment version of the second group of target sub-firmware packages with a second system environment version of the local device, determine a third group of target sub-firmware packages in the second group of target sub-firmware packages, the first system environment version of which is consistent with the second system environment version, and upgrade the local firmware in the normal system according to the third group of target sub-firmware packages, and upgrade the local firmware in the backup system according to target sub-firmware packages in the second group of target sub-firmware packages other than the third group of target sub-firmware packages.
[0137] In an exemplary embodiment, the first comparison sub-unit comprises:
[0138] The first sub-module is configured to, in the case that the rescue system flag bit is set, enter the backup system, and upgrade the local firmware in the backup system according to target sub-firmware packages in the second group of target sub-firmware packages other than the third group of target sub-firmware packages; the rescue system flag bit is configured to represent whether the rescue system is in a working state; the rescue system is configured to guide the local device to enter a predefined recovery environment when the local device cannot be started correctly.
[0139] The second sub-module is configured to compare whether the updated local firmware and the memory file are consistent in content, and in the case that the updated local firmware and the memory file are not consistent in content, re-perform the step of upgrading the local firmware in the backup system according to target sub-firmware packages in the second group of target sub-firmware packages other than the third group of target sub-firmware packages, and count the number of updates.
[0140] The third sub-module is configured to, in the case that the number of updates is greater than a preset number or the updated local firmware and the memory file are consistent in content, reset the rescue system flag bit, and exit the backup system.
[0141] According to another aspect of the embodiments of this application, a computer-readable storage medium is provided, the computer-readable storage medium including a stored program, wherein the program executes the steps in any of the above method embodiments when it is run.
[0142] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, ROMs, RAMs, portable hard drives, magnetic disks, or optical disks.
[0143] According to another aspect of the embodiments of this application, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor is configured to perform the steps of any of the method embodiments described above via the computer program. In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0144] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.
[0145] According to another aspect of the embodiments of this application, a computer program product is also provided, comprising a computer program / instructions containing program code for performing the methods shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via communication section 1109, and / or installed from removable medium 1111. When the computer program is executed by central processing unit 901, it performs various functions provided in the embodiments of this application. The sequence numbers of the embodiments of this application above are merely descriptive and do not represent the superiority or inferiority of the embodiments.
[0146] Figure 11 A schematic block diagram of a computer system architecture for implementing embodiments of the present application is shown. Figure 11 As shown, the computer system 1100 includes a Central Processing Unit (CPU) 1101, which can perform various appropriate actions and processes based on programs stored in ROM 1102 or programs loaded into RAM 1103 from storage section 1108. Random access memory 1103 also stores various programs and data required for system operation. The CPU 1101, ROM 1102, and RAM 1103 are interconnected via bus 1104. Input / output (I / O) interface 1105 is also connected to bus 1104.
[0147] The following components are connected to the I / O interface 1105: an input part 1106 including a keyboard, a mouse, etc.; an output part 1107 including a display such as a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), etc., and a speaker, etc.; a storage part 1108 including a hard disk, etc.; and a communication part 1109 including a network interface card such as a LAN card, a modem, etc. The communication part 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to the input / output interface 1105 as necessary. A removable media 1111 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 1110 as necessary, so that a computer program read out therefrom is installed in the storage part 1108 as necessary.
[0148] In particular, according to embodiments of the present application, the processes described in the various method flowcharts can be implemented as a computer software program. For example, embodiments of the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program code for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via the communication part 1109, and / or installed from the removable media 1111. When the computer program is executed by the central processing unit 1101, various functions defined in the system of the present application are executed.
[0149] It should be noted that, Figure 11 The computer system 1100 of the electronic device shown is merely an example, and should not impose any limitation on the functions and usage range of embodiments of the present application.
[0150] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present application can be realized by general computing devices, which can be centralized on a single computing device, or distributed on a network composed of multiple computing devices, which can be realized by program codes executable by computing devices, so that they can be stored in storage devices and executed by computing devices, and in some cases, the steps shown or described can be executed in different order, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps can be manufactured into a single integrated circuit module. Thus, the present application is not limited to any particular combination of hardware and software.
[0151] The above merely provides preferred embodiments of the present application, and is not used to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application shall fall into the protective scope of the present application.
Claims
1. A method for upgrading equipment security, characterized in that, The method is applied to a data interaction server, and comprises the following steps: Obtaining encrypted device identification information of a local device through a first secure data channel between the local device and the data interaction server, decrypting the encrypted device identification information, and verifying the decrypted device identification information; the device identification information is encrypted by the local device according to a target encryption algorithm; In the case that the device identification information passes the verification, obtaining an encrypted firmware package to be upgraded, and verifying the integrity of the encrypted firmware package to be upgraded; the firmware package to be upgraded comprises a plurality of sub firmware packages; In the case that the integrity of the encrypted firmware package to be upgraded passes the verification, determining at least one group of target sub firmware packages to be updated by the local device from the encrypted plurality of sub firmware packages, compressing the at least one group of target sub firmware packages to obtain a difference package; Transmitting the difference package to the local device through the first secure data channel, so that the local device decrypts the difference package according to a target decryption algorithm corresponding to the target encryption algorithm to obtain the at least one group of target sub firmware packages, and upgrades the local firmware according to the at least one group of target sub firmware packages.
2. The method of claim 1, wherein, The step of obtaining the encrypted firmware package to be upgraded in the case that the device identification information passes the verification comprises the following steps: In the case that the device identification information passes the verification, performing secure authentication with a firmware deployment server according to a first preset authentication method, and obtaining the encrypted firmware package to be upgraded from the firmware deployment server after the secure authentication passes; the firmware package to be upgraded is a firmware package obtained by a packaging server by encrypting and compressing a plurality of sub firmware packages and a check data according to a target encryption algorithm, the plurality of sub firmware packages are obtained by the packaging server by splitting firmware information and firmware content into the plurality of sub firmware packages, and the check data is generated according to the plurality of sub firmware packages, and the firmware package to be upgraded is deployed to the firmware deployment server by the packaging server after the secure authentication passes according to a second preset authentication method.
3. The method of claim 1, wherein, The firmware package to be upgraded further comprises a check data; the check data comprises firmware meta information of the plurality of sub firmware packages; the step of verifying the integrity of the encrypted firmware package to be upgraded comprises the following steps: Decompressing the encrypted firmware package to be upgraded to obtain the plurality of sub firmware packages and the check data, obtaining and decrypting current firmware meta information of the local device, and verifying the integrity of the firmware package to be upgraded according to the firmware meta information of the plurality of sub firmware packages in the check data and the current firmware meta information.
4. The method according to any one of claims 1 to 3, characterized in that, The method further comprises the following steps: Performing secure authentication with a terminal device according to a third preset authentication method through a second secure data channel between the terminal device and the data interaction server, and transmitting the firmware package to be upgraded to the terminal device through the second secure data channel after the secure authentication passes. In the case of the data interaction server exception, the step of obtaining the encrypted device identification information of the local device is continued through a third secure data channel between the terminal device and the local device until the local device completes the firmware update.
5. A method of secure upgrade of a device, characterized by, The method is applied to a local device and includes the following steps: The device identification information of the local device is encrypted according to a target encryption algorithm, and the encrypted device identification information is transmitted to a data interaction server through a first secure data channel between the local device and the data interaction server, so that the data interaction server decrypts the encrypted device identification information and checks the decrypted device identification information. In the case where the device identification information passes the check, an encrypted firmware package to be upgraded is obtained, the firmware package to be upgraded includes a plurality of sub-firmware packages, and the integrity of the encrypted firmware package to be upgraded is checked. In the case where the integrity of the encrypted firmware package to be upgraded passes the check, at least one group of target sub-firmware packages to be updated by the local device is determined from the plurality of encrypted sub-firmware packages, and the at least one group of target sub-firmware packages is compressed to obtain a difference package. The difference package is received through the first secure data channel, and the difference package is decrypted according to a target decryption algorithm corresponding to the target encryption algorithm to obtain the at least one group of target sub-firmware packages, and the local firmware is upgraded according to the at least one group of target sub-firmware packages.
6. The method of claim 5, wherein, The firmware package to be upgraded further includes a check data; the check data includes firmware meta-information of the plurality of sub-firmware packages. After the encrypted device identification information is transmitted to the data interaction server through the first secure data channel between the local device and the data interaction server, the method further includes the following steps: In the case where the device identification information passes the check, the current firmware meta-information of the local device is encrypted according to the target encryption algorithm, and the encrypted current firmware meta-information is transmitted to the data interaction server through the first secure data channel, so that the data interaction server unpacks the encrypted firmware package to be upgraded to obtain the plurality of sub-firmware packages and the check data, and checks the integrity of the firmware package to be upgraded according to the firmware meta-information of the plurality of sub-firmware packages in the check data and the decrypted current firmware meta-information.
7. The method of claim 5, wherein, Before the device identification information of the local device is encrypted according to the target encryption algorithm, the method further includes the following steps: After the local device is powered on, it is checked whether the local firmware is legal. In the case where the local firmware is not legal, historical legal firmware is obtained from a backup system, and the local firmware is updated according to the historical legal firmware. In the case where the local firmware is legal, it is checked whether the local device is in an upgrade-ready state. In the case where the local device is in the upgrade-ready state, the step of encrypting the device identification information of the local device according to the target encryption algorithm is performed.
8. The method of claim 5, wherein, Each target sub-firmware package in the at least one group of target sub-firmware packages corresponds to a firmware category identifier; and In the regular system, the local firmware is upgraded according to a first group of target sub-firmware packages in the at least one group of target sub-firmware packages, which are applied to an application; and in the backup system, the local firmware is upgraded according to a second group of target sub-firmware packages in the at least one group of target sub-firmware packages, which are applied to an operating system.
9. The method of claim 8, wherein, The step of upgrading the local firmware according to the second group of target sub-firmware packages in the at least one group of target sub-firmware packages, which are applied to the operating system in the backup system, comprises: The first system environment version of the second group of target sub-firmware packages is compared with the second system environment version of the local device, and a third group of target sub-firmware packages, in which the first system environment version is consistent with the second system environment version, is determined from the second group of target sub-firmware packages; the local firmware is upgraded according to the third group of target sub-firmware packages in the regular system, and the local firmware is upgraded according to target sub-firmware packages other than the third group of target sub-firmware packages in the second group of target sub-firmware packages in the backup system.
10. The method of claim 9, wherein, The step of upgrading the local firmware according to target sub-firmware packages other than the third group of target sub-firmware packages in the second group of target sub-firmware packages in the backup system, comprises: In a case where a rescue system flag bit is set, the backup system is entered, and the local firmware is upgraded according to target sub-firmware packages other than the third group of target sub-firmware packages in the second group of target sub-firmware packages in the backup system; the rescue system flag bit is used to represent whether the rescue system is in a working state; and the rescue system is used to guide the local device to enter a predefined recovery environment when the local device cannot be started correctly; The updated local firmware and the memory file are compared to determine whether their contents are consistent; in a case where the contents of the updated local firmware and the memory file are inconsistent, the step of upgrading the local firmware according to target sub-firmware packages other than the third group of target sub-firmware packages in the second group of target sub-firmware packages in the backup system is re-executed, and the number of updates is counted; In a case where the number of updates is greater than a preset number or the contents of the updated local firmware and the memory file are consistent, the rescue system flag bit is reset, and the backup system is exited.