A version information upgrade method and system

By combining passive UHF RFID tags with handheld UHF RFID readers, and utilizing RSSI signal strength to calculate device priority and dynamic encryption keys, the network dependency and security verification issues in electronic device version information upgrades are resolved, achieving efficient and secure version information upgrade management.

CN121051756BActive Publication Date: 2026-04-21CETC ECRIEEPOWER (ANHUI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CETC ECRIEEPOWER (ANHUI) CO LTD
Filing Date
2025-08-18
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies have systemic defects in terms of network dependence, operational efficiency, security verification, and audit traceability when upgrading electronic device version information, making it difficult to meet the upgrade needs in complex scenarios.

Method used

By employing passive UHF RFID tags in conjunction with handheld UHF RFID readers, the device distance priority is dynamically calculated based on RSSI signal strength. Combined with dynamic command codes, a device-specific encryption key is generated. The system uses both encrypted digests and digital signatures for dual verification, enabling automated and highly secure version information upgrade management.

Benefits of technology

It enables end-to-end secure updates in contactless operation, improving upgrade efficiency, security and manageability, and meeting upgrade needs in complex scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121051756B_ABST
    Figure CN121051756B_ABST
Patent Text Reader

Abstract

This application discloses a version information upgrade method and system, relating to the field of electronic device version information upgrade management technology. It addresses current systemic deficiencies in network dependency, operational efficiency, security verification, and audit traceability during electronic device version information upgrades. The method includes: scanning the device tag of the device to be upgraded and obtaining the encrypted area data of the device tag; wherein the device tag is set on the device to be upgraded; decrypting the encrypted area data to determine the security verification result of the device tag; if the security verification result of the device tag is successful, obtaining the Received Signal Strength Indication (RSSI) data of the device tag; determining the device priority order of the devices to be upgraded based on the RSSI data of the device tag; and performing version information upgrades on the devices to be upgraded according to the device priority order. This application is used for version information upgrades of electronic devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of electronic device version information upgrade management technology, and in particular to a version information upgrade method and system. Background Technology

[0002] Version updates are a core component in ensuring the functionality, security, and performance of electronic devices, and are widely used in IoT devices, industrial control systems, and smart terminals. With the surge in the number of devices and the accelerated pace of feature iteration, efficient and secure version management has become an industry necessity. Currently, mainstream upgrade technologies include Over-the-Air Technology (OTA), local upgrades, and batch upgrade management, but all have limitations in environmental adaptability or efficiency, making it difficult to meet the upgrade needs of complex scenarios.

[0003] Radio Frequency Identification (RFID) technology, with its advantages of non-contact identification, batch reading of multiple tags, and low cost, has been maturely applied in asset tracking and equipment identification. Ultra High Frequency (UHF) RFID has even more long-range and high-speed scanning characteristics, but its application in version information upgrade management is still limited to the equipment identification stage, and it has not yet been deeply involved in key aspects of the upgrade process such as automated scheduling, security verification, or data encryption. Summary of the Invention

[0004] This application provides a version information upgrade method and system, which can solve the systemic defects in network dependence, operation efficiency, security verification and audit traceability when electronic devices upgrade version information at present.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] In a first aspect, this application provides a version information upgrade method, comprising: scanning the device tag of the device to be upgraded and obtaining the encrypted area data of the device tag; wherein the device tag is set on the device to be upgraded; decrypting the encrypted area data to determine the security verification result of the device tag; if the security verification result of the device tag is passed, obtaining the received signal strength indication (RSSI) data of the device tag; determining the device priority order of the device to be upgraded based on the RSSI data of the device tag; and upgrading the version information of the device to be upgraded according to the device priority order.

[0007] In one possible implementation, before scanning the device tag of the device to be upgraded and obtaining the encrypted area data of the device tag, the method further includes: obtaining the encrypted version information upgrade package from the version management server; decrypting the encrypted version information upgrade package to obtain the version information upgrade package.

[0008] In one possible implementation, the encrypted area data of the device tag includes: device information ciphertext and key information; wherein, the device information ciphertext includes the device unique identifier, production date information, operator number, current version information and historical version information, and the key information includes specific information and encrypted information.

[0009] In one possible implementation, upgrading the version information of the device to be upgraded specifically includes: determining whether the device needs to be upgraded based on the encrypted device information and the version information upgrade package; if the device needs to be upgraded, upgrading the device based on the version information upgrade package and encrypting and writing the device tag.

[0010] In one possible implementation, the encrypted writing of the device tag specifically includes: obtaining specific information; wherein the specific information includes at least one of the following: a unique device identifier and permission parameters; extracting a digest of the specific information to obtain a first digest; encrypting the first digest information according to the specific information and an encrypted dynamic instruction code to obtain encrypted information; and writing the specific information and the encrypted information into the encrypted area of ​​the device tag.

[0011] In one possible implementation, the encrypted data is decrypted to determine the security verification result of the device tag. Specifically, this includes: decrypting the encrypted information to obtain a second digest; determining a third digest based on specific information and a decryption dynamic instruction code; and comparing the second digest and the third digest to determine the security verification result of the device tag.

[0012] In one possible implementation, the device priority order of the devices to be upgraded is determined based on the RSSI data of the device tag. Specifically, this includes determining the actual distance between the scanning device and the device tag based on a preset distance calculation model. The preset distance calculation model can be an improved logarithmic distance path loss model, which is constructed according to the following formula:

[0013] Formula 1

[0014] in, This indicates the actual distance between the scanning device and the device label. Indicates a predefined reference distance. express The reference signal strength obtained from the calibration is The RSSI value represents the distance to the target being collected. This represents the path loss index. Indicates the noise compensation term;

[0015] A scheduling model is constructed based on a preset scheduling algorithm, and the priority order of devices to be upgraded is determined according to the actual distance between the scanning device and the device tag. The preset scheduling algorithm includes heuristic scheduling algorithms, and the scheduling model is constructed according to the following formula:

[0016] Formula 2

[0017] in, This represents the scheduling evaluation function value of the device to be upgraded. This represents the RSSI value for each device to be upgraded. This represents the priority of each device to be upgraded, and α represents the weight of the actual distance between the scanning device and the device tag on the scheduling priority.

[0018] In one possible implementation, after upgrading the version information of the device to be upgraded, the method further includes: generating an upgrade record for the device to be upgraded and uploading the upgrade record to the audit module.

[0019] In one possible implementation, the device tag is a radio frequency identification (RFID) tag, and the scanning device for scanning the device tag is a handheld UHF RFID reader.

[0020] Secondly, this application provides a version information upgrade system, including: a scanning device, a version management server, an audit module, and a device tag; the scanning device is used to scan the device tag of the device to be upgraded and obtain the encrypted area data of the device tag; wherein, the device tag is set on the device to be upgraded; the scanning device is also used to decrypt the encrypted area data and determine the security verification result of the device tag; the scanning device is also used to obtain the received signal strength indicator (RSSI) data of the device tag when the security verification result of the device tag is passed; the scanning device is also used to upload the upgrade record of the device to be upgraded to the audit module; the version management server is used to... The RSSI data of the backup tag determines the device priority order of the devices to be upgraded; the version management server is also used to upgrade the version information of the devices to be upgraded according to the device priority order; the version management server is also used to provide encrypted version information upgrade packages to the scanning devices; the audit module is used to receive the upgrade records of the devices to be upgraded uploaded by the scanning devices; the device tag is set on the device to be upgraded; the encrypted area data of the device tag includes: device information ciphertext and key information; wherein, the device information ciphertext includes device ID number, production date information, operator number, current version information and historical version information, and the key information includes specific information and encrypted information.

[0021] In one possible implementation, the scanning device is also used to decrypt the encrypted version information upgrade package to obtain the version information upgrade package.

[0022] In one possible implementation, the version management server is also used to determine whether the device to be upgraded needs a version upgrade based on the encrypted device information and the version information upgrade package; the version management server is also used to perform a version upgrade on the device to be upgraded based on the version information upgrade package when the device to be upgraded needs a version upgrade; the device scanning server is also used to encrypt and write the device tag.

[0023] In one possible implementation, the scanning device is further used to acquire specific information; wherein the specific information includes at least one of the following: a unique device identifier and permission parameters; the scanning device is further used to extract a digest of the specific information to obtain first digest information; the scanning device is further used to encrypt the first digest information according to the specific information and the encrypted dynamic instruction code to obtain encrypted information; the scanning device is further used to write the specific information and the encrypted information into the encrypted area of ​​the device tag.

[0024] In one possible implementation, the scanning device is further configured to decrypt the encrypted information to obtain a second digest; the scanning device is further configured to determine a third digest based on specific information and a decryption dynamic instruction code; and the scanning device is further configured to compare the second digest and the third digest to determine the security verification result of the device tag.

[0025] In one possible implementation, the version management server is also used to determine the actual distance between the scanning device and the device tag based on a preset distance calculation model; wherein, the preset distance calculation model can be an improved logarithmic distance path loss model, which is constructed according to the following formula:

[0026] Formula 1

[0027] in, This indicates the actual distance between the scanning device and the device label. Indicates a predefined reference distance. express The reference signal strength obtained from the calibration is The RSSI value represents the distance to the target being collected. This represents the path loss index. Indicates the noise compensation term;

[0028] The version management server is also used to construct a scheduling model based on a preset scheduling algorithm and determine the device priority order of devices to be upgraded based on the actual distance between the scanned device and the device tag. The preset scheduling algorithm includes heuristic scheduling algorithms, and the scheduling model is constructed according to the following formula:

[0029] Formula 2

[0030] in, This represents the scheduling evaluation function value of the device to be upgraded. This represents the RSSI value for each device to be upgraded. This represents the priority of each device to be upgraded, and α represents the weight of the actual distance between the scanning device and the device tag on the scheduling priority.

[0031] In one possible implementation, the scanning device is also used to generate an upgrade record for the device to be upgraded, and the upgrade record is uploaded to the audit module.

[0032] Thirdly, this application provides an apparatus, comprising: an acquisition unit and a processing unit. The acquisition unit is configured to scan a device tag of a device to be upgraded and acquire encrypted area data of the device tag; wherein the device tag is disposed on the device to be upgraded. The processing unit is configured to decrypt the encrypted area data and determine the security verification result of the device tag. The acquisition unit is configured to acquire Received Signal Strength Indication (RSSI) data of the device tag if the security verification result of the device tag is successful. The processing unit is configured to determine the device priority order of the device to be upgraded based on the RSSI data of the device tag. The processing unit is configured to upgrade the version information of the device to be upgraded according to the device priority order.

[0033] In one possible implementation, the acquisition unit is further configured to acquire the encrypted version information upgrade package from the version management server; the acquisition unit is further configured to decrypt the encrypted version information upgrade package to acquire the version information upgrade package.

[0034] In one possible implementation, the encrypted area data of the device tag includes: device information ciphertext and key information; wherein, the device information ciphertext includes the device unique identifier, production date information, operator number, current version information and historical version information, and the key information includes specific information and encrypted information.

[0035] In one possible implementation, the processing unit is further configured to determine whether the device to be upgraded needs to undergo a version upgrade based on the encrypted device information and the version information upgrade package; the processing unit is further configured to perform a version upgrade on the device to be upgraded based on the version information upgrade package and encrypt and write the device tag if the device to be upgraded needs to undergo a version upgrade.

[0036] In one possible implementation, the acquisition unit is further configured to acquire specific information; wherein the specific information includes at least one of the following: a unique device identifier and permission parameters; the processing unit is further configured to extract a digest of the specific information to obtain first digest information; the processing unit is further configured to encrypt the first digest information according to the specific information and the encrypted dynamic instruction code to obtain encrypted information; the processing unit is further configured to write the specific information and the encrypted information into the encrypted area of ​​the device tag.

[0037] In one possible implementation, the processing unit is further configured to decrypt the encrypted information to obtain second digest information; the processing unit is further configured to determine third digest information based on specific information and decryption dynamic instruction code; the processing unit is further configured to compare the second digest information and the third digest information to determine the security verification result of the device tag.

[0038] In one possible implementation, the processing unit is further configured to determine the actual distance between the scanning device and the device tag based on a preset distance calculation model; wherein the preset distance calculation model can be an improved logarithmic distance path loss model, which is constructed according to the following formula:

[0039] Formula 1

[0040] in, This indicates the actual distance between the scanning device and the device label. Indicates a predefined reference distance. express The reference signal strength obtained from the calibration is The RSSI value represents the distance to the target being collected. This represents the path loss index. Indicates the noise compensation term;

[0041] The processing unit is also used to construct a scheduling model based on a preset scheduling algorithm, and to determine the device priority order of the devices to be upgraded based on the actual distance between the scanning device and the device tag; wherein, the type of preset scheduling algorithm includes a heuristic scheduling algorithm, and the scheduling model is constructed according to the following formula:

[0042] Formula 2

[0043] in, This represents the scheduling evaluation function value of the device to be upgraded. This represents the RSSI value for each device to be upgraded. This represents the priority of each device to be upgraded, and α represents the weight of the actual distance between the scanning device and the device tag on the scheduling priority.

[0044] In one possible implementation, the processing unit is also used to generate an upgrade record for the device to be upgraded and upload the upgrade record to the audit module.

[0045] Fourthly, this application provides a computer-readable storage medium for storing one or more programs, the one or more programs including instructions that, when executed by an electronic device of this application, cause the electronic device to perform the version information upgrade method as described in the first aspect and any possible implementation thereof.

[0046] Fifthly, this application provides an electronic device, including: a processor and a memory; wherein the memory is used to store one or more programs, the one or more programs including computer-executable instructions, and when the electronic device is running, the processor executes the computer-executable instructions stored in the memory to cause the electronic device to perform the version information upgrade method as described in the first aspect and any possible implementation of the first aspect.

[0047] Sixthly, this application provides a computer program product containing instructions that, when executed on a computer, cause the electronic device of this application to perform the version information upgrade method as described in the first aspect and any possible implementation thereof.

[0048] In a seventh aspect, this application provides a chip system applied to a version information upgrade device; the chip system includes one or more interface circuits and one or more processors. The interface circuits and the processors are interconnected via lines; the interface circuits are used to receive signals from the memory of the version information upgrade device and send the signals to the processors, the signals including computer instructions stored in the memory. When the processor executes the computer instructions, the version information upgrade device performs a version information upgrade method as described in the first aspect and any possible design of the first aspect.

[0049] Based on the above technical solution, this application achieves automated and highly secure version information upgrade management through the collaboration of passive UHF RFID tags and handheld UHF RFID readers: it dynamically calculates device distance priority using RSSI signal strength, generates device-specific encryption keys by combining dynamic instruction codes, and uses dual verification of encrypted digests and digital signatures to ensure data integrity and source credibility. Finally, it completes end-to-end secure version information updates in contactless operation, and achieves full-process traceability through an audit module, significantly improving upgrade efficiency, security and manageability. Attached Figure Description

[0050] Figure 1 This application provides an architectural diagram of a version information upgrade system.

[0051] Figure 2 This application provides a schematic diagram of the architecture of a scanning device.

[0052] Figure 3 A flowchart illustrating a version information upgrade method provided in an embodiment of this application;

[0053] Figure 4 This is a schematic diagram of the structure of a version information upgrade device provided in an embodiment of this application;

[0054] Figure 5 This is a schematic diagram of another version information upgrade device provided in an embodiment of this application. Detailed Implementation

[0055] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0056] In this article, the character " / " generally indicates that the objects before and after it are in an "or" relationship. For example, A / B can be understood as A or B.

[0057] The terms "first" and "second" in the specification and claims of this application are used to distinguish different objects, not to describe a specific order of objects. For example, "first edge service node" and "second edge service node" are used to distinguish different edge service nodes, not to describe a characteristic order of edge service nodes.

[0058] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0059] Furthermore, in the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplarily" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the words "exemplarily" or "for example" is intended to present concepts in a concrete manner.

[0060] The following is a description of the technical terms used in this application:

[0061] 1. Radio Frequency Identification

[0062] Radio Frequency Identification (RFID) is a wireless communication technology that automatically identifies targets using radio waves. It consists of electronic tags (which store data) and readers (which read / write data), enabling information exchange without physical contact or line of sight, similar to a wireless upgrade of supermarket barcode scanning.

[0063] This technology is divided into low-frequency, high-frequency, and ultra-high-frequency types. Among them, ultra-high-frequency RFID is most commonly used in logistics and asset management, and can simultaneously and quickly identify hundreds of tags within a range of several meters. Compared with traditional barcodes, RFID has advantages such as being waterproof and stain-resistant, having rewritable data, and having a long reading distance.

[0064] RFID has already permeated daily life, appearing in scenarios such as public transport cards, unmanned supermarkets, and luggage tracking. In the industrial sector, it is also used for equipment identification management, but its potential in automation upgrades and security control has not yet been fully realized.

[0065] 2. Passive UHF RFID tags

[0066] Passive ultra-high frequency (UHF) RFID tags are wireless identification tags that do not require built-in batteries. They operate by obtaining energy from the radio waves emitted by the reader (similar to the principle of wireless charging). They use the ultra-high frequency band (860-960MHz) and can identify distances of several meters to tens of meters, making them suitable for scenarios requiring long-distance and rapid identification, such as logistics warehousing and retail management.

[0067] These tags have a simple structure, containing a microchip and an antenna, and offer advantages such as low cost, long lifespan, and the ability to be read in batches. Compared to active tags, although the communication distance is slightly shorter, they require no battery maintenance and are lighter, thinner, and more durable.

[0068] Typical applications include clothing tags, warehouse cargo tracking, and highway ETC systems. In the industrial sector, it is evolving from traditional asset identification to more intelligent applications such as equipment status monitoring and secure data exchange.

[0069] 3. Handheld UHF RFID reader

[0070] A handheld UHF RFID reader is a portable wireless identification device designed for tracking and managing items in mobile environments. It uses ultra-high frequency radio waves (860-960MHz) to simultaneously and quickly identify dozens of passive RFID tags within a range of several meters without requiring direct alignment or contact with the target, making it more efficient than traditional barcode scanners.

[0071] These devices are typically equipped with a display screen and operation buttons, have a built-in rechargeable battery, and support wireless transmission such as Wi-Fi / Bluetooth. Compared to fixed readers, they have the advantage of flexibility and mobility, adapting to the needs of mobile operations such as warehouse inventory, retail inspections, and outdoor asset checks.

[0072] Current mainstream handheld readers have integrated intelligent systems (such as Android) and can install dedicated applications to achieve functions such as inventory management and equipment inspection. They are widely used in logistics, retail, manufacturing and other fields, and are gradually replacing traditional manual recording methods.

[0073] The above describes the technical terms used in this application.

[0074] Currently, version information upgrades are a core component in ensuring the functionality, security, and performance of electronic devices, and are widely used in IoT devices, industrial control systems, and smart terminals. With the surge in the number of devices and the accelerated pace of feature iteration, efficient and secure version management has become an industry necessity. Current mainstream upgrade technologies include Over-the-Air (OTA) technology, local upgrades, and batch upgrade management, but all have limitations in environmental adaptability or efficiency, making it difficult to meet the upgrade needs of complex scenarios.

[0075] Radio frequency identification (RFID) technology, with its advantages of non-contact identification, batch reading of multiple tags, and low cost, has been maturely applied in asset tracking and equipment identification. UHF RFID has the characteristics of long-distance and high-speed scanning, but its application in version information upgrade management is still limited to the stage of equipment identification and has not yet been deeply involved in key aspects of the upgrade process such as automated scheduling, security verification, or data encryption.

[0076] In summary, the existing version upgrade technology has the following significant shortcomings:

[0077] (1) Environmental limitations: OTA relies on a stable network, and local upgrades require manual intervention, making it difficult to cover offline or large-scale device scenarios;

[0078] (2) Efficiency and accuracy deficiencies: Batch upgrades lack dynamic scheduling capabilities, which can easily lead to omissions or duplications;

[0079] (3) Security risks: Some solutions lack end-to-end encryption and source verification, making them vulnerable to man-in-the-middle attacks;

[0080] (4) Insufficient traceability: The offline device upgrade log is incomplete and cannot meet the requirements of high compliance audit.

[0081] These shortcomings highlight the urgent need for automated and secure version upgrade management using RFID technology. The inadequacies of existing technologies indicate a pressing need for an automated, secure, and scalable solution incorporating RFID technology.

[0082] In view of this, in order to solve the problems existing in the prior art, this application proposes a version information upgrade method and system, which can solve the systemic defects of the current electronic devices in terms of network dependence, operation efficiency, security verification and audit traceability when upgrading version information.

[0083] The method for upgrading version information provided in this application will be described in detail below with reference to the accompanying drawings:

[0084] For example, such as Figure 1 As shown, Figure 1The diagram below illustrates the architecture of the version information upgrade system provided in this application. The version information upgrade system 10 includes: a scanning device 11, a version management server 12, an audit module 13, and a device tag 14.

[0085] The scanning device 11 is used to scan the device tag of the device to be upgraded and obtain the encrypted area data of the device tag. The device tag is located on the device to be upgraded.

[0086] The scanning device 11 is also used to decrypt the data in the encrypted area and determine the security verification result of the device tag.

[0087] The scanning device 11 is also used to acquire the Received Signal Strength Indication (RSSI) data of the device tag if the security verification result of the device tag is passed.

[0088] For example, in this application embodiment, the scanning device 11 can be a handheld UHF RFID reader that supports reading more than 200 device tags per second, is configured to scan device tags in an offline environment, and interacts with a version management server through a secure communication protocol.

[0089] like Figure 2 As shown, when the scanning device 11 is specifically implemented as a handheld UHF RFID reader, the scanning device 11 may include two sub-modules: a control terminal 111 and an RFID radio frequency module 112.

[0090] It is understood that the control terminal 111 and the RFID radio frequency module 112 can communicate via a Universal Asynchronous Receiver / Transmitter (UART) or via a Serial Peripheral Interface (SPI). This application does not make any specific limitation in this regard.

[0091] Optionally, when the scanning device 11 is specifically implemented as a handheld UHF RFID reader, the scanning device 11 can communicate with the version management server 12 and the audit module 13 via wireless communication based on the control terminal 11.

[0092] For example, scanning device 11 can obtain the encrypted version information upgrade package of the device to be upgraded from version management server 12. Scanning device 11 can also send the encrypted device information of device tag 14 to version management server 12. In addition, scanning device 11 can upload the upgrade record of the device to be upgraded to audit module 13.

[0093] The functions of scanning device 11 and its sub-modules have been described above.

[0094] Version management server 12 is used to determine the device priority order of devices to be upgraded based on the RSSI data of the device tags.

[0095] Version management server 12 is also used to upgrade the version information of devices to be upgraded according to the priority order of the devices.

[0096] Version management server 12 is used to provide encrypted version information upgrade packages to scanning device 11. Version management server 12 uses AES-256 encryption algorithm to encrypt version information packages and verifies version integrity and legitimacy through SHA-256 digital signature to ensure the security of the upgrade process.

[0097] Optionally, after receiving the encrypted device information from the device tag 14 sent by the scanning device 11, the version management server 12 determines whether the device to be upgraded needs a version upgrade by comparing it with the latest version information in the version information upgrade package. When the device to be upgraded needs a version upgrade, a batch of version upgrade tasks are generated.

[0098] Optionally, the version management server 12 is also used to determine the device priority order of the devices to be upgraded based on the RSSI data of the device tags, and to execute batch version upgrade tasks according to the device priority order of the devices to be upgraded, so as to upgrade the version information of the devices to be upgraded.

[0099] Optionally, the version management server 12 is also used to maintain a central database, record upgrade events (time, version, operator) and compliance reports.

[0100] The audit module 13 is used to receive the upgrade records of the device to be upgraded uploaded by the scanning device 11, store the encrypted upgrade log in the RFID tag, including the upgrade time, version number and operator information, support offline compliance verification, and comply with the ISO27001 standard.

[0101] Specifically, audit module 13 records upgrade events in the server database and RFID tags, forming dual logs that support both offline and online auditing. Furthermore, audit module 13 also records encrypted logs (time, version, operator) stored on the tags, employing a write-protection mechanism to prevent tampering.

[0102] Device label 14 is set on the device to be upgraded. If there are multiple devices to be upgraded, there will be multiple device labels 14.

[0103] Optionally, the encrypted area data of the device tag 14 includes: device information ciphertext and key information; wherein, the device information ciphertext includes the device unique identifier, production date information, operator number, current version information and historical version information, and the key information includes specific information and encrypted information.

[0104] Specifically, the device's unique identifier, the device ID, is 64 bits, used to distinguish each device to be upgraded; the current version information includes a version number, which is 32 bits and supports dynamic updates; the historical version information includes a timestamp and version number, which is 128 bits and used to record the most recent upgrade operations; and the operator information includes an operator ID, which is 64 bits and used to record the operators who registered the device upgrade. It should be noted that the key information included in device label 14 is detailed in section S303 below and will not be repeated here.

[0105] In one possible implementation, device tag 14 supports encrypted storage (AES-128) to prevent unauthorized access or tampering, and the data format is standardized (such as JSON) to facilitate reader parsing.

[0106] Optionally, the device tag 14 also includes a digital signature (SHA-256, 256 bits) for tamper-proof verification.

[0107] In one possible implementation, the device tag 14 can be an RFID tag, specifically a passive UHF RFID tag. Passive UHF RFID tags operate in the 860-960 MHz frequency band, comply with the ISO 18000-6C standard, support encrypted storage, and use the AES-128 encryption algorithm to protect stored data from unauthorized access or tampering.

[0108] The architecture of the version information upgrade system 10 has been explained above.

[0109] For example, such as Figure 3 As shown, Figure 2 A flowchart illustrating a version information upgrade method provided in this application includes the following steps:

[0110] S301. The scanning device obtains the encrypted version information upgrade package from the version management server.

[0111] Understandably, the scanning device establishes a secure connection with the version management server via its built-in 4G / 5G / Wi-Fi module. In industrial scenarios, dedicated networks or encrypted channels are typically used to ensure transmission security.

[0112] Specifically, the scanning device first sends an authentication request to the version management server, typically using a two-way authentication mechanism to verify the authenticity of the server's certificate. The version management server then verifies the scanning device's device ID and operator permissions. After successful authentication, the scanning device sends an upgrade request containing information such as the type of device to be upgraded and the current version number.

[0113] Furthermore, the version management server retrieves a matching encrypted version information upgrade package based on the request information. This encrypted version information upgrade package typically contains: encrypted new version information data, a digital signature (used to verify the source), and version metadata (applicable device model, version number, etc.). After receiving the encrypted version information upgrade package, the scanning device first verifies the digital signature to ensure that the upgrade package has not been tampered with and its source is trustworthy. Verified upgrade packages are temporarily stored in the scanning device's secure storage area, usually using encrypted storage. Some devices have storage capacity warnings; when the remaining space is insufficient, they will prompt the user to clean up or expand the storage.

[0114] S302. The scanning device decrypts the encrypted version information upgrade package and obtains the version information upgrade package.

[0115] Optionally, when the encrypted version information upgrade package issued by the version management server contains a digital signature, the scanning device will also verify the authenticity of the encrypted version information upgrade package's origin through the digital signature before decrypting it. Furthermore, since the digital signature is generated based on the hash value of the encrypted version information upgrade package's content, even if the encrypted version information upgrade package is tampered with by one byte during transmission, the hash value comparison will fail during verification, thus preventing tampering of the encrypted version information upgrade package. This ensures that the object being decrypted is the original, undisturbed data.

[0116] In one possible implementation, the scanning device decrypts the encrypted version information upgrade package, which may specifically include:

[0117] (1) Key acquisition stage

[0118] The scanning device first retrieves the pre-configured decryption key from the secure storage module. This key may be obtained through the following methods: a temporary session key issued by the server (transmitted through a secure channel), a subkey derived from the device's pre-configured root key, or a key dynamically generated based on RFID tag characteristics.

[0119] (2) Decryption and execution phase

[0120] The scanning device uses the acquired key to decrypt the encrypted packet: first, it verifies the digital signature of the encrypted packet to ensure its integrity and authenticity of origin; then, it performs the decryption operation according to the encryption algorithm type (such as AES); finally, it separates the version information content, verification data, and additional instructions.

[0121] (3) Information verification stage

[0122] After decryption, multiple layers of verification are required: version number compliance check (to prevent version rollback), file hash value comparison (to ensure accurate decryption), and validity period verification (to avoid expired upgrade packages).

[0123] (4) Readiness stage

[0124] The verified version information will be temporarily stored in the secure memory area of ​​the scanning device: the version update content will be parsed according to the preset format, the corresponding RFID writing instruction sequence will be generated, and the upgrade process record template will be prepared.

[0125] Understandably, the entire decryption process is completed within the secure execution environment of the scanning device, and the decrypted data in memory is immediately cleared after use. If any verification step fails, the system automatically terminates the process and generates a security alarm log. For upgrade packages that need to be distributed, the scanning device can maintain their encrypted state and forward them directly to the target RFID tag.

[0126] S303. Scan the device tag of the device to be upgraded and obtain the encrypted area data of the device tag.

[0127] The device label is set on the device to be upgraded.

[0128] Optionally, the encrypted data includes: encrypted device information and key information; wherein, the encrypted device information includes a unique device identifier, production date information, operator number, current version information, and historical version information, and the key information includes specific information and encrypted information. See Table 1 below for details:

[0129] Table 1 Data Structure of Device Tags

[0130]

[0131] Specifically, the unique device identifier, or device ID, is 64 bits and is used to distinguish each device to be upgraded; the current version information includes the version number, which is 32 bits and supports dynamic updates; the historical version information includes a timestamp and version number, which is 128 bits and is used to record the most recent upgrade operations; and the operator information includes the operator's number, which is 64 bits and is used to record the operators who are registered to upgrade the devices.

[0132] Optionally, the specific information includes at least one of the following: a unique device identifier and permission parameters. Specifically, the specific information can be used in conjunction with dynamic command codes to obtain digest information through digital signatures. For example, the dynamic command codes may include decryption dynamic command codes required for decryption and encryption dynamic command codes required for encryption.

[0133] S304. Decrypt the data in the encrypted area to determine the security verification result of the device tag.

[0134] Optionally, this step may specifically include the following three sub-steps:

[0135] (1) The scanning device decrypts the encrypted information to obtain the second digest information;

[0136] Specifically, the control terminal of the scanning device uses a decryption algorithm to decrypt the encrypted information in the device tag to obtain the second digest information.

[0137] (2) The scanning device determines the third digest information based on specific information and the decrypted dynamic instruction code;

[0138] Specifically, the scanning device reads the encrypted information from the device tag and also obtains specific information stored in the device tag. Afterward, the scanning device's control terminal, based on the read tag-specific information and pre-stored decryption dynamic command codes, combines them with a digital signature to generate a KEY value, which is then re-encrypted to generate a third digest.

[0139] (3) The scanning device compares the second and third summary information to determine the security verification result of the device tag.

[0140] Specifically, the second and third digest information are compared. If they match, the security verification result of the device tag is considered to be passed; otherwise, the security verification result of the device tag is considered to be failed.

[0141] S305. If the security verification result of the device tag is passed, obtain the received signal strength indication (RSSI) data of the device tag.

[0142] Optionally, when there are multiple devices to be upgraded, the scanning device establishes communication with multiple device tags, collects the raw RSSI values ​​of the interactions in real time, and constructs a multi-label RSSI dataset for use in subsequent preset distance calculation models.

[0143] S306. Determine the device priority order of the devices to be upgraded based on the RSSI data of the device tags.

[0144] Optionally, this step may include the following sub-steps:

[0145] (1) The version management server determines the actual distance between the scanning device and the device tag based on the preset distance calculation model;

[0146] In one possible implementation, the version management server receives RSSI data of the device tag sent by the scanning device. The preset distance calculation model (1) adopts an improved logarithmic distance path loss model, as shown in the following formula:

[0147] Formula 1

[0148] in, This indicates the actual distance between the scanning device and the device label. Indicates a predefined reference distance. express The reference signal strength obtained from the calibration is The RSSI value represents the distance to the target being collected. This represents the path loss index. Indicates the noise compensation term;

[0149] (2) The version management server determines the priority order of the devices to be upgraded based on the actual distance between the scanning device and the device tag.

[0150] The preset scheduling algorithms include heuristic scheduling algorithms. The scheduling models include single-scan device scheduling models and multi-scan device scheduling models.

[0151] In one possible implementation, a single-scan device scheduling model corresponding to a single-scan device is constructed. That is, a hybrid priority scheduling algorithm is used, employing A... The heuristic graph search approach and scheduling model are constructed based on the following formula:

[0152] Formula 2

[0153] in, This represents the scheduling evaluation function value of the device to be upgraded. This represents the RSSI value for each device to be upgraded. This represents the priority of each device to be upgraded, and α represents the weight of the actual distance between the scanning device and the device tag on the scheduling priority.

[0154] It should be noted that the evaluation function value is calculated for each device to be upgraded. A priority queue is generated and sorted according to the size of the evaluation function value. Then, each time, the n devices with the smallest evaluation function value are selected for reading and writing.

[0155] In another possible implementation, when there are multiple scanning devices, a single-scanning-device scheduling model corresponding to multiple scanning devices can be constructed. Suppose there are k scanning devices, each capable of simultaneously reading and writing to a maximum of n devices to be upgraded. Given m devices to be upgraded, numbered from 1 to m, the signal strength matrix is ​​as shown in Formula 3 below:

[0156] Formula 3

[0157] Using a distributed collaborative scheduling method, each scanning device is responsible for the m / k devices with the strongest RSSI signals in the vicinity that need to be upgraded. The specific algorithm flow is as follows:

[0158] a. Initialization: Randomly select k initial cluster centers. ;

[0159] b. Allocation process: For each target device i, calculate its signal similarity with all readers j. The similarity calculation formula is shown in Formula 4 below:

[0160] Formula 4

[0161] Assign the device to be upgraded to the reader with the shortest distance. If a reader has already been assigned enough target devices, select the next best reader.

[0162] c. Update process: Recalculate the center c of each cluster j j Take the average signal value of all target devices within the cluster. , where c j It is the set of electronic devices assigned to read / write device j;

[0163] d. Iterate through steps b and c until the cluster centers reach the convergence condition;

[0164] e. Distributed scheduling: Apply a hybrid priority scheduling algorithm to each reader / writer after clustering to complete distributed collaborative scheduling.

[0165] The above describes the process by which the version management server determines the priority order of devices to be upgraded based on the actual distance between the scanned device and the device tag.

[0166] S307. Upgrade the version information of the devices to be upgraded according to the priority order of the devices.

[0167] It is understood that the device priority order has been determined according to S306. For example, this step may include the following sub-steps:

[0168] (1) Determine whether the device to be upgraded needs to be upgraded based on the encrypted device information and the version information upgrade package.

[0169] Specifically, after the scanning device obtains the encrypted data from the device tag, it sends the current version information from the encrypted device information to the version management server.

[0170] Optionally, after receiving the encrypted device information from the device tag sent by the scanning device, the version management server determines whether the device needs a version upgrade by comparing it with the latest version information in the version information upgrade package. When a device needs a version upgrade, a batch of version upgrade tasks are generated.

[0171] (2) When the device to be upgraded needs to be upgraded, upgrade the device according to the version information upgrade package and encrypt the device tag.

[0172] Optionally, the version management server is also used to determine the device priority order of the devices to be upgraded based on the RSSI data of the device tags, and to execute batch version upgrade tasks according to the device priority order of the devices to be upgraded, so as to upgrade the version information of the devices to be upgraded.

[0173] In one possible implementation, the device tag is encrypted and written, specifically including:

[0174] a. Scanning devices acquire specific information;

[0175] The specific information includes at least one of the following: unique device identifier and permission parameters.

[0176] Specifically, the control terminal of the scanning device reads specific information from the device tag and generates encrypted dynamic instruction codes for encryption based on built-in logic.

[0177] b. The scanning device extracts a summary of specific information to obtain the first summary information.

[0178] Specifically, the scanning device, combined with digital signatures, converts the encrypted dynamic instruction code into a KEY value; it then extracts a digest of the collected specific information to obtain the first digest information.

[0179] c. Based on specific information and encrypted dynamic instruction codes, encrypt the first digest information to obtain encrypted information.

[0180] Specifically: The scanning device generates 8-Bytes dynamic instruction code. Dynamic instruction code The KEY value is generated using the SHA256 algorithm.

[0181] The SHA256 calculation process is as follows: First, the dynamic instruction code is padded to a length of 448 mod 512 bits, and then eight 32-bit initial hash constants are generated. For each 512-bit block, perform the following operation: the first 16 words are directly taken from the current block, and the remaining 48 words are generated using Formula 5:

[0182] Formula 5

[0183] In the formula, , Indicates XOR, For circular right shift, For circular right shift, Then initialize 8 working variables. , respectively corresponding to the current hash value The following formula is used to iterate over the eight working variables:

[0184] Formula Six

[0185] In the formula, , , , , It is a constant. After each bit block is processed, the hash value is updated using formula seven:

[0186] Formula 7

[0187] The final hash value is the concatenated value. .

[0188] Following this, the encryption process is as follows: the scanning device calls the encryption algorithm, uses the KEY value to encrypt the digest information, and obtains the encrypted information; the encrypted information and specific information are then written into a specific storage area of ​​the RFID tag. Specifically: the first 16 bytes of the KEY value generated by the SHA256 algorithm are encrypted using the AES-128-CBC encryption algorithm, and then the encrypted information is written into a specific storage area of ​​the RFID tag.

[0189] The AES-128 encryption process is as follows: First, 11 128-bit subkeys are generated using a key expansion algorithm. Then, an initial round is set by XORing the data block with the initial key. Next, main round encryption is performed, with each round including byte substitution, row shifting, column obfuscation, and round key addition. Finally, the final round is performed, which includes byte substitution, row shifting, and round key addition. The final round outputs a 128-bit ciphertext block.

[0190] The calculation process for AES-128-CBC is as follows: a 16-byte initialization vector is randomly generated. Then, the plaintext is divided into 16-byte blocks, with padding added if necessary, and encrypted using the following formula:

[0191] Formula 8

[0192] in, This represents the i-th plaintext block. Finally, all encrypted blocks are concatenated to form the final ciphertext.

[0193] d. Write specific information and encrypted information into the encrypted area of ​​the device tag.

[0194] The above describes the process of encrypting and writing device tags.

[0195] S308. Generate upgrade records for the devices to be upgraded and upload the upgrade records to the audit module.

[0196] Specifically, the audit module records upgrade events in both the server database and RFID tags, creating dual logs that support both offline and online auditing. Additionally, audit module 13 records encrypted logs (time, version, operator) stored on the tags, employing a write-protection mechanism to prevent tampering.

[0197] Accordingly, in this embodiment of the application, in addition to the audit module, the version management server can also maintain a central database to record upgrade events (time, version, operator) and compliance reports.

[0198] Based on the above technical solution, this application achieves automated and highly secure version information upgrade management through the collaboration of passive UHF RFID tags and handheld UHF RFID readers: it dynamically calculates device distance priority using RSSI signal strength, generates device-specific encryption keys by combining dynamic instruction codes, and uses dual verification of encrypted digests and digital signatures to ensure data integrity and source credibility. Finally, it completes end-to-end secure version information updates in contactless operation, and achieves full-process traceability through an audit module, significantly improving upgrade efficiency, security and manageability.

[0199] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and module described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0200] This application provides a computer program product containing instructions. When the computer program product is run on the electronic device of this application, it causes the computer to execute the version information upgrade method described in the above method embodiment.

[0201] This application also provides a computer-readable storage medium storing instructions. When a computer executes these instructions, the electronic device of this application performs each step of the version information upgrade device in the method flow shown in the above method embodiment.

[0202] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), registers, hard disks, optical fibers, compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing, or any other form of computer-readable storage medium in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0203] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for upgrading version information, characterized in that, The method includes: Scan the device tag of the device to be upgraded and obtain the encrypted area data of the device tag; wherein, the device tag is set on the device to be upgraded; The encrypted data is decrypted to determine the security verification result of the device tag; If the security verification result of the device tag is passed, the Received Signal Strength Indication (RSSI) data of the device tag is obtained; Based on the RSSI data of the device tag, determine the device priority order of the devices to be upgraded; According to the device priority order, the version information of the device to be upgraded is upgraded; The step of determining the device priority order of the devices to be upgraded based on the RSSI data of the device tag specifically includes: The actual distance between the scanning device and the device tag is determined based on a preset distance calculation model; wherein, the preset distance calculation model is an improved logarithmic distance path loss model, which is constructed according to the following formula: Formula 1 in, This indicates the actual distance between the scanning device and the device tag. Indicates a predefined reference distance. express The reference signal strength obtained from the calibration is The RSSI value represents the distance to the target being collected. This represents the path loss index. Indicates the noise compensation term; A scheduling model is constructed based on a preset scheduling algorithm, and the device priority order of the devices to be upgraded is determined based on the actual distance between the scanning device and the device tag; wherein, the type of preset scheduling algorithm includes heuristic scheduling algorithms, and the scheduling model is constructed according to the following formula: Formula 2 in, This represents the scheduling evaluation function value of the device to be upgraded. This represents the RSSI value for each of the devices to be upgraded. The priority of each device to be upgraded is indicated by α, where α represents the weight of the influence of the actual distance between the scanning device and the device tag on the scheduling priority.

2. The version information upgrade method according to claim 1, characterized in that, Before scanning the device tag of the device to be upgraded and obtaining the encrypted area data of the device tag, the method further includes: Retrieve encrypted version information upgrade package from the version management server; The encrypted version information upgrade package is decrypted to obtain the version information upgrade package.

3. The version information upgrade method according to claim 2, characterized in that, The encrypted area data of the device tag includes: device information ciphertext and key information; wherein, the device information ciphertext includes the device unique identifier, production date information, operator number, current version information and historical version information, and the key information includes specific information and encrypted information.

4. The version information upgrade method according to claim 3, characterized in that, The process of upgrading the version information of the device to be upgraded specifically includes: Based on the encrypted device information and the version information upgrade package, determine whether the device to be upgraded needs to undergo a version upgrade; If the device to be upgraded needs to be upgraded, the device to be upgraded is upgraded according to the version information upgrade package, and the device tag is encrypted and written.

5. The version information upgrade method according to claim 4, characterized in that, The encryption writing of the device tag specifically includes: Obtain the specific information; wherein the specific information includes at least one of the following: unique device identifier, permission parameters; The specific information is then used to extract a summary, resulting in a first summary. Based on the specific information and the encrypted dynamic instruction code, the first digest information is encrypted to obtain encrypted information; The specific information and encrypted information are written into the encrypted area of ​​the device tag.

6. The version information upgrade method according to claim 5, characterized in that, The step of decrypting the encrypted data to determine the security verification result of the device tag specifically includes: The encrypted information is decrypted to obtain the second digest information; Based on the specific information and the decrypted dynamic instruction code, the third digest information is determined; The second digest information and the third digest information are compared to determine the security verification result of the device tag.

7. The version information upgrade method according to claim 1, characterized in that, After upgrading the version information of the device to be upgraded, the method further includes: An upgrade record for the device to be upgraded is generated, and the upgrade record is uploaded to the audit module.

8. The version information upgrade method according to any one of claims 1-7, characterized in that, The device tag is a radio frequency identification (RFID) tag, and the scanning device for scanning the device tag is a handheld ultra-high frequency (UHF) RFID reader.

9. A version information upgrade system, applied to the version information upgrade method according to any one of claims 1-8, characterized in that, The version information upgrade system includes: scanning equipment, version management server, audit module, and device tags; The scanning device is used to scan the device tag of the device to be upgraded and obtain the encrypted area data of the device tag; wherein the device tag is set on the device to be upgraded; the scanning device is also used to decrypt the encrypted area data and determine the security verification result of the device tag; the scanning device is also used to obtain the received signal strength indication (RSSI) data of the device tag if the security verification result of the device tag is passed; the scanning device is also used to upload the upgrade record of the device to be upgraded to the audit module; The version management server is used to determine the device priority order of the devices to be upgraded based on the RSSI data of the device tags; the version management server is also used to upgrade the version information of the devices to be upgraded according to the device priority order; the version management server is also used to provide the scanning device with an encrypted version information upgrade package. The audit module is used to receive the upgrade records of the device to be upgraded uploaded by the scanning device; The device tag is set on the device to be upgraded; the encrypted area data of the device tag includes: device information ciphertext and key information; wherein, the device information ciphertext includes device ID number, production date information, operator number, current version information and historical version information, and the key information includes specific information and encrypted information.

Citation Information

Patent Citations

  • Firmware upgrading method and apparatus, server, Internet of Things system and radio frequency tag

    CN107104839A

  • Method and apparatus for online upgrade of Bluetooth cluster

    CN109417691A