A method, apparatus and system for searching and upgrading devices over Ethernet
Patent Information
- Application Number
- CN202511220050.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2045-08-29
AI Technical Summary
[0007]本发明提供一种通过以太网搜索和升级设备的方法、装置及系统,以解决现有设备升级技术存在升级效率低下、用户体验差、安全风险高以及无法适配网络环境差异的问题
[0056] 1. This invention searches for devices across network segments via UDP broadcast and automatically resolves IP addresses and subnet masks, eliminating the need for manual inquiry of device IPs or resetting device parameters. This completely solves the problems of low IP acquisition efficiency and heavy user workload in existing technologies, significantly shortens upgrade preparation time, and improves operational convenience.
Smart Images

Figure CN121357167B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of firmware upgrade technology, and more specifically to a method, apparatus, and system for searching and upgrading devices via Ethernet. Background Technology
[0002] After equipment leaves the factory, the firmware, as its core operating program, often needs to be upgraded to optimize performance and fix defects (such as improving product stability, expanding functional compatibility, and fixing known operational vulnerabilities) in order to continuously improve product quality and extend equipment lifespan. However, when upgrading Ethernet firmware for equipment already installed in the field (such as factory workshops, outdoor base stations, building control systems, etc.) or returned for repair, existing technologies face many key bottlenecks, making it difficult to meet the requirements for efficient, convenient, and secure upgrades. Specific shortcomings are as follows:
[0003] First, low efficiency in obtaining device IP addresses or poor user experience is a core obstacle to Ethernet upgrades. Since the IP addresses of field devices or returned devices are often configured by users based on the actual network environment, upgrade operations require obtaining this IP address before establishing a network connection. Currently, there are two main methods for obtaining this IP address: one is to ask the device user for the IP address, but this process requires multiple communications and confirmations with the user, especially when there are many devices, a wide distribution, or the user is unfamiliar with the network parameters, resulting in extremely high communication costs and very low upgrade preparation efficiency; the other method is to reset the device parameters to factory defaults, restoring the device IP address to the preset factory IP. However, after resetting, the user needs to reconfigure the device's network and functional parameters for normal use, which not only increases the user's workload but may also cause the device to be unable to connect to the original system due to incorrect parameter configuration, severely impacting the user experience.
[0004] Secondly, the lack of a device legitimacy verification mechanism poses a serious security risk. In the current upgrade process, upgrade tools or systems can only establish a connection with the device via IP address, and cannot verify the device's identity and legitimacy. They cannot identify whether the device is unauthorized or illegal, nor can they check whether the device certificate has been leaked or expired. This directly leads to the possibility that illegal devices may be mistakenly upgraded, or that legitimate devices may have their firmware tampered with by illegal upgrade tools, posing a great risk to the security and stability of the system to which the device belongs.
[0005] Finally, it cannot adapt to different network environments, resulting in extremely poor scenario adaptability. In actual upgrade scenarios, the network conditions of the device deployment environment vary significantly. Existing technologies cannot provide compatible solutions for the two core scenarios of "with public network" and "without public network": In the environment with public network, although firmware and verification information can be transmitted over the network, the lack of standardized online verification processes and firmware adaptation mechanisms still requires manual screening of firmware versions that match the device model. Moreover, the verification process relies on third-party tools, making the operation cumbersome and prone to errors. In the environment without public network (such as outdoor equipment in remote areas, factory intranet isolation scenarios, and on-site situations with sudden network outages), existing technologies completely lack effective upgrade support. It is impossible to obtain verification information of legitimate devices in advance to ensure upgrade security, and it is also impossible to conveniently store the adapted firmware (it often requires manual copying via physical media such as USB flash drives, which can easily lead to firmware version confusion, virus infection, or omission of key verification files). Ultimately, this makes it difficult to promote device upgrades in scenarios without public network, or causes device failure due to forced upgrades.
[0006] In summary, existing equipment upgrade technologies have shortcomings in three aspects: IP acquisition, legality verification, and scenario adaptation. This not only leads to low upgrade efficiency and poor user experience, but also poses serious security risks. They cannot meet the diverse upgrade needs of field equipment and equipment under repair. There is an urgent need for a technical solution that can overcome the above bottlenecks. Summary of the Invention
[0007] This invention provides a method, apparatus, and system for searching and upgrading devices via Ethernet, to solve the problems of low upgrade efficiency, poor user experience, high security risks, and inability to adapt to different network environments in existing device upgrade technologies.
[0008] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0009] This invention provides a method for searching and upgrading devices via Ethernet, including an online upgrade method and an offline upgrade method. The online upgrade method executes steps A1-A5, and the offline upgrade method executes steps A0-A5.
[0010] A0. Offline resource preparation: In a public network environment, the upgrade device receives the target device serial number input by the user, downloads the firmware, certificate hash and signature public key corresponding to the serial number from the verification server in advance, and stores them in a local database in encryption.
[0011] A1. Cross-network segment device search: The upgrade device uses UDP broadcast to send device discovery data packets to all devices in the network segment, receives device response data packets returned by the target device, and parses them to obtain the device IP address, subnet mask and device information;
[0012] A2. Dynamically configure network connection: Based on the device IP address and subnet mask obtained in step A1, the upgrade device adds a temporary IP address on the network card that is in the same network segment as the target device;
[0013] A3. Verify device legitimacy: This includes online and offline verification steps. If an online upgrade method is used, the online verification steps are employed; if an offline upgrade method is used, the offline verification steps are employed. If verification is successful, proceed to step A4; if verification fails, proceed to step A5.
[0014] Online verification steps: In an environment with a public network, the upgrade device sends a certificate request frame to the target device via a TCP connection and receives a certificate response frame returned by the target device; the certificate information in the certificate response frame is sent to the verification server, and the verification server verifies the legitimacy of the target device;
[0015] Offline verification steps: In an environment without a public network, the upgrade device sends a certificate request frame to the target device via a TCP connection and receives a certificate response frame returned by the target device; it then calls the local database and uses the certificate hash and signing public key to verify the legitimacy of the target device.
[0016] A4. Target device upgrade: Includes online upgrade steps and offline upgrade steps; if the online upgrade method is performed, the online upgrade steps shall be used; if the offline upgrade method is performed, the offline upgrade steps shall be used.
[0017] Online upgrade steps: The upgrade device downloads firmware compatible with the target device from the verification server, sends firmware data frames to the target device via TCP connection, receives upgrade response frames returned by the target device, and the target device receives the firmware data frames and completes the device upgrade.
[0018] Offline upgrade steps: The upgrade device retrieves the firmware corresponding to the target device from the local database, sends firmware data frames to the target device via TCP connection, receives upgrade response frames returned by the target device, and the target device receives the firmware data frames and completes the device upgrade.
[0019] A5. Cleanup and Result Indication: The upgrade device deletes the temporary IP address added in step A2 and outputs the upgrade result through its own display module.
[0020] Furthermore, in step A1, the content of the data packet discovered by the device includes: packet header identifier, function code, frame sequence number, reserved fields, and CRC frame check; the content of the data packet responded by the device includes: device IP address, subnet mask, packet header identifier, function code, frame sequence number, device type, device software version number, device hardware version number, and CRC frame check.
[0021] Furthermore, in step A3, the specific process of the online verification step is as follows:
[0022] (1) The upgrade device sends a request parameter to the verification server. The request parameter includes the certificate information in the certificate response frame, specifically including the serial number of the target device, the certificate hash and the signature public key.
[0023] (2) The verification server queries the whitelist database through the verification service interface to confirm whether the serial number of the target device exists; if it does not exist, the log audit module records the illegal serial number and the verification service interface returns an "invalid" result; if it exists, the revocation list (CRL) module is queried to confirm whether the serial number has been revoked.
[0024] (3) If the serial number has been revoked, the log audit module records the revocation access and the verification service interface returns an "invalid" result; if it has not been revoked, the certificate signature is verified using the public key issued by the Certificate Authority (CA) and the certificate hash is compared with the hash value in the whitelist database.
[0025] (4) If the certificate signature is valid and the hash value matches, the log audit module records a "verification successful" result and the verification service interface returns a "valid" result; if they do not match, a "invalid" result is returned.
[0026] The Certificate Authority (CA), verification service interface, whitelist database, log audit module, and revocation list (CRL) module are all components of the verification server.
[0027] Furthermore, in step A3, the specific process of the offline verification step is as follows:
[0028] (1) The upgrade device sends a certificate request frame to the target device via a TCP connection;
[0029] (2) After receiving the certificate request frame, the target device returns a certificate response frame;
[0030] (3) The upgrade device parses the certificate response frame and extracts the serial number and certificate data of the target device;
[0031] (4) The upgrade device calls the resources encrypted and stored in the local database in step A0, and matches the corresponding certificate hash and signature public key according to the extracted serial number;
[0032] (5) The upgrade device extracts the hash value from the target device certificate data and compares it with the certificate hash matched in the local database; at the same time, it uses the locally stored signature public key to verify the signature validity of the certificate data.
[0033] (6) If the certificate hash match and the signature verification is successful, the target device is deemed legitimate; if any step fails, the target device is deemed illegitimate and the subsequent upgrade operation is terminated.
[0034] Furthermore, in step A4, the content of the firmware data frame includes: packet header identifier, function code, frame sequence number, total firmware length, data frame sequence number, current frame data length, firmware data, and CRC frame check; the content of the upgrade response frame includes: packet header identifier, function code, frame sequence number, reserved fields, and CRC frame check.
[0035] The present invention also provides an apparatus for searching and upgrading devices via Ethernet, configured as the upgrade apparatus in the above method, including a device access detection module, a device authentication module, a firmware download module, a firmware and verification information pre-download module, a firmware upgrade module, and a storage management module, all of which are connected to the main control module.
[0036] The device access detection module is used to send the device discovery data packet, receive the device response data packet, and manage the addition and deletion of temporary IP addresses of the network card;
[0037] The device authentication module is used to send the certificate request frame, receive the certificate response frame, and verify the legitimacy of the device;
[0038] The firmware download module is used to download firmware compatible with the target device from the verification server in an environment with a public network.
[0039] The firmware and verification information pre-download module is configured to download the target device's firmware, certificate hash, and signature public key from the verification server in a public network environment, and encrypt and store them in a local database.
[0040] The firmware upgrade module is used to send the firmware data frame and receive the upgrade response frame;
[0041] The storage management module is used to classify and store online and offline resources, device information, authentication and upgrade logs, and supports fast read and write and emergency data protection;
[0042] The main control module is connected to the display module. After receiving the upgrade results from the target device, the display module displays the upgrade results.
[0043] Furthermore, the device also includes Ethernet RJ45 interface, USB interface, RS232 interface, RS485 interface, TTL interface, WiFi interface, LoRa interface, 4G module, antenna, button module, hardware watchdog, power module, and power output interface, all of which are connected to the main control module.
[0044] The present invention also provides a system for searching and upgrading devices via Ethernet, performing the above-described method for searching and upgrading devices via Ethernet to upgrade a target device, including:
[0045] The upgrade device is configured as the upgrade device provided in the above solution;
[0046] Target device: Built-in unique digital certificate, configured to receive the device discovery data packet sent by the upgrade device and return the device response data packet, receive the certificate request frame and return the certificate response frame, receive the firmware data frame and return the upgrade response frame, and perform firmware upgrade operation;
[0047] The verification server stores information on legitimate devices, a list of revoked certificates, and compatible firmware. It provides online device legitimacy verification services, as well as real-time firmware downloads for online upgrades and pre-download resources for offline upgrade preparation.
[0048] Furthermore, the verification server includes a Certificate Authority (CA) system, a whitelist database, a Certificate Revocation List (CRL) module, a verification service interface, and a log auditing module;
[0049] The Certificate Authority (CA) system is used to issue digital certificates containing serial numbers, public keys, and signatures to legitimate target devices.
[0050] The whitelist database is used to store the serial numbers and certificate hashes of legitimate target devices;
[0051] The Revocation List (CRL) module is used to revoke the certificates of target devices that have been leaked or are obsolete;
[0052] The verification service interface is used to receive certificate information sent by the upgrade device, query the whitelist database and revocation list (CRL) module, verify the certificate signature using the CA public key, and return the verification result.
[0053] The log auditing module is used to record the time of the verification request, the target device serial number, the verification result, and the request IP.
[0054] Furthermore, the Revocation List (CRL) module is configured to update the certificate information of leaked or obsolete target devices in real time.
[0055] By adopting the above technical solution, the present invention has the following beneficial effects:
[0056] 1. This invention searches for devices across network segments via UDP broadcast and automatically resolves IP addresses and subnet masks, eliminating the need for manual inquiry of device IPs or resetting device parameters. This completely solves the problems of low IP acquisition efficiency and heavy user workload in existing technologies, significantly shortens upgrade preparation time, and improves operational convenience.
[0057] 2. This invention sets up a dual online and offline device legitimacy verification mechanism. In the online scenario, it verifies the whitelist query of the verification server, CRL revocation verification, and CA public key signature verification. In the offline scenario, it verifies the certificate hash and signature public key stored locally. This effectively identifies illegal devices and invalid certificates, avoids unauthorized upgrades or firmware tampering, and significantly reduces system security risks.
[0058] 3. This invention distinguishes between online and offline upgrade methods. In the online scenario, the compatible firmware is obtained in real time from the verification server. In the offline scenario, resources are pre-downloaded and encrypted and stored through the A0 step. It is perfectly compatible with both public and offline scenarios, breaking through the bottleneck of existing technologies that cannot be compatible with different network environments.
[0059] 4. The present invention sets up a dynamic network connection configuration step in the upgrade device, automatically adds a temporary IP address in the same network segment as the target device, eliminates the need for manual configuration of network card parameters, and automatically deletes the temporary IP after the upgrade, avoiding interference from residual IPs to subsequent network communication, reducing human error, and ensuring the stability of the network environment.
[0060] 5. This invention sets up a CRC frame verification mechanism for device discovery data packets, certificate frames, and firmware data frames, and receives upgrade response frames from the target device in real time during firmware transmission. This can promptly detect data loss, tampering, and other problems, ensure data transmission integrity, and avoid upgrade failures or device malfunctions caused by data errors.
[0061] 6. The verification server of this invention integrates a log auditing module, which can record the verification request time, target device serial number, verification result and request IP. At the same time, the CRL module updates the invalid certificate information in real time, which facilitates subsequent traceability and upgrade operations, investigation of security risks, and improves the system's operability and security.
[0062] 7. The upgrade device of this invention supports multiple communication methods such as Ethernet RJ45, USB, WiFi, LoRa, and 4G, adapting to different interface types and meeting the communication needs of different deployment scenarios. It can also upgrade the firmware of multiple devices simultaneously, improving the operability and efficiency of device upgrades. A hardware watchdog is included, which can trigger reset protection in case of device malfunction, enhancing the device's environmental adaptability and operational stability.
[0063] 8. The storage management module of this invention classifies and stores online / offline resources, device information, and upgrade logs, and supports emergency data protection. Offline resources are stored in an encrypted manner, which avoids problems such as firmware version confusion and virus infection, and can protect critical data in case of power failure or other emergencies, thus ensuring the reliability of the upgrade process.
[0064] 9. In offline verification and upgrades, this invention associates the pre-downloaded certificate hash, signature public key, and firmware with the target device serial number, eliminating the need for manual resource screening and matching. This achieves accurate "serial number-resource" correspondence, avoids device malfunctions caused by firmware version mismatches, and improves upgrade accuracy.
[0065] 10. This invention outputs the upgrade results in real time through the display module, and directly executes the cleanup step when the verification fails, without the need for manual intervention to finish the process, simplifying the operation process. Even non-professionals can easily complete the upgrade, significantly improving the user experience.
[0066] 11. This invention supports batch device upgrade operations. In online scenarios, multiple target devices can be searched at once via UDP broadcast and a device list can be generated. The verification server can return the legality results and compatible firmware of multiple devices in batches. In offline scenarios, the serial number associated resources of multiple devices can be downloaded in batches via A0 steps. The upgrade device completes the verification and upgrade in sequence according to the device list, which greatly improves the upgrade efficiency of multiple devices and avoids the repetitive and tedious operation of a single device.
[0067] 12. In the device search phase, this invention can automatically identify the type, hardware version number, and software version number of the target device by parsing the device response data packet, eliminating the need for manual querying or input of device information. In the firmware acquisition phase, in online scenarios, the latest compatible firmware can be automatically matched and downloaded from the verification server based on the identified device information. In offline scenarios, the latest version can be selected from the pre-stored firmware by the storage management module according to the "device type-version number" association relationship. The entire process eliminates the need for manual firmware selection, avoids the risk of version mismatch, further reduces manual intervention, and significantly improves upgrade efficiency and accuracy. Attached Figure Description
[0068] Figure 1 This is a flowchart of the method provided by the present invention;
[0069] Figure 2 This is a flowchart of the online verification process in the method provided by the present invention;
[0070] Figure 3 This is a flowchart of the offline verification process in the method provided by the present invention;
[0071] Figure 4 This is a software functional block diagram of the device provided by the present invention;
[0072] Figure 5 This is a hardware connection block diagram of the device provided by the present invention;
[0073] Figure 6 This is a circuit diagram of the main control module in the device provided by the present invention;
[0074] Figure 7This is a circuit schematic diagram of the LoRa interface in the device provided by the present invention;
[0075] Figure 8 This is a circuit schematic diagram of the RS485 interface in the device provided by the present invention;
[0076] Figure 9 This is a circuit diagram of the USB interface in the device provided by the present invention;
[0077] Figure 10 This is a circuit diagram of the WiFi interface in the device provided by the present invention;
[0078] Figure 11 This is a circuit diagram of the power module in the device provided by the present invention;
[0079] Figure 12 This is a circuit schematic diagram of the Ethernet RJ45 interface in the device provided by the present invention;
[0080] Figure 13 This is a circuit schematic diagram of the TTL interface in the device provided by the present invention;
[0081] Figure 14 This is a circuit schematic diagram of the RS232 interface in the device provided by the present invention;
[0082] Figure 15 This is a circuit diagram of the display module in the device provided by the present invention;
[0083] Figure 16 This is a circuit diagram of the 4G module in the device provided by the present invention. Detailed Implementation
[0084] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0085] like Figure 1-3 As shown, the present invention provides a method for searching and upgrading devices via Ethernet, including an online upgrade method and an offline upgrade method. The online upgrade method executes steps A1-A5, and the offline upgrade method executes steps A0-A5.
[0086] A0. Offline Resource Preparation: In a public network environment, the upgrade device receives the target device serial number input by the user, downloads the firmware, certificate hash, and signing public key corresponding to that serial number from the verification server in advance, and stores them encrypted in the local database. This step is optional; it is not required if the online upgrade method is performed.
[0087] A1. Cross-network segment device search: The upgrade device uses UDP broadcast to send device discovery data packets to all devices within the network segment, receives device response data packets returned by the target device, and parses them to obtain the device IP address, subnet mask, and device information.
[0088] The data packet detected by the device includes: packet header identifier, function code, frame sequence number, reserved fields, and CRC frame checksum. The specific format is as follows:
[0089] 8E8E 01
[0090] The device response data packet includes: device IP address, subnet mask, packet header identifier, function code, frame sequence number, device type, device software version number, device hardware version number, and CRC frame checksum. The specific format is as follows:
[0091]
[0092] UDP broadcasts do not require prior knowledge of the target device's IP address; as long as a specific broadcast address (255.255.255.255) is used, all devices within the same router can receive it.
[0093] A2. Dynamically configure network connection: Based on the device IP address and subnet mask obtained in step A1, the upgrade device adds a temporary IP address on the network card that is in the same network segment as the target device.
[0094] A3. Verify device legitimacy: This includes online and offline verification steps. If an online upgrade method is used, the online verification steps are employed; if an offline upgrade method is used, the offline verification steps are employed. If verification passes, proceed to step A4; if verification fails, proceed to step A5.
[0095] Online verification steps: In an environment with a public network, the upgrade device sends a certificate request frame to the target device via a TCP connection, receives a certificate response frame returned by the target device, and sends the certificate information in the certificate response frame to the verification server to verify the legitimacy of the target device.
[0096] The specific format of the certificate request frame is as follows:
[0097] 8E8E 02
[0098] The specific format of the certificate response frame is as follows:
[0099]
[0100] like Figure 2 As shown, the specific process of online verification is as follows:
[0101] (1) The upgrade device sends a request parameter to the verification server. The request parameter includes the certificate information in the certificate response frame, specifically including the serial number of the target device, the certificate hash and the signature public key.
[0102] (2) The verification server queries the whitelist database through the verification service interface to confirm whether the serial number of the target device exists; if it does not exist, the log audit module records the illegal serial number and the verification service interface returns an "invalid" result; if it exists, the revocation list (CRL) module is queried to confirm whether the serial number has been revoked.
[0103] (3) If the serial number has been revoked, the log audit module records the revocation access and the verification service interface returns an "invalid" result; if it has not been revoked, the certificate signature is verified using the public key issued by the Certificate Authority (CA) and the certificate hash is compared with the hash value in the whitelist database.
[0104] (4) If the certificate signature is valid and the hash value matches, the log audit module records a "verification successful" result and the verification service interface returns a "valid" result; if they do not match, a "invalid" result is returned.
[0105] The Certificate Authority (CA), verification service interface, whitelist database, log audit module, and revocation list (CRL) module are all components of the verification server.
[0106] Offline verification steps: In an environment without a public network, the upgrade device sends a certificate request frame to the target device via a TCP connection, receives a certificate response frame returned by the target device, calls the local database, and uses the certificate hash and signature public key to verify the legitimacy of the target device.
[0107] like Figure 3 As shown, the specific process of offline verification is as follows:
[0108] (1) The upgrade device sends a certificate request frame to the target device via a TCP connection;
[0109] (2) After receiving the certificate request frame, the target device returns a certificate response frame;
[0110] (3) The upgrade device parses the certificate response frame and extracts the serial number and certificate data of the target device;
[0111] (4) The upgrade device calls the resources encrypted and stored in the local database in step A0, and matches the corresponding certificate hash and signature public key according to the extracted serial number;
[0112] (5) The upgrade device extracts the hash value from the target device certificate data and compares it with the certificate hash matched in the local database; at the same time, it uses the locally stored signature public key to verify the signature validity of the certificate data.
[0113] (6) If the certificate hash match and the signature verification is successful, the target device is deemed legitimate; if any step fails, the target device is deemed illegitimate and the subsequent upgrade operation is terminated.
[0114] A4. Target device upgrade: Includes online upgrade steps and offline upgrade steps; if the online upgrade method is performed, the online upgrade steps shall be used, and if the offline upgrade method is performed, the offline upgrade steps shall be used.
[0115] Online upgrade steps: The upgrade device downloads firmware compatible with the target device from the verification server, sends firmware data frames to the target device via TCP connection, receives upgrade response frames returned by the target device, and the target device receives the firmware data frames and completes the device upgrade.
[0116] The firmware data frame includes the following content: packet header identifier, function code, frame sequence number, total firmware length, data frame sequence number, current frame data length, firmware data, and CRC frame checksum. The specific format is as follows:
[0117]
[0118] The upgrade response frame includes: a header identifier, a function code, a frame sequence number, reserved fields, and a CRC frame checksum. The specific format is as follows:
[0119] 8E8E 03
[0120] Offline upgrade steps: The upgrade device retrieves the firmware corresponding to the target device from the local database, sends firmware data frames to the target device via TCP connection, receives upgrade response frames returned by the target device, and the target device receives the firmware data frames and completes the device upgrade.
[0121] A5. Cleanup and Result Indication: The upgrade device deletes the temporary IP address added in step A2 and outputs the upgrade result through its own display module.
[0122] The temporary IP address is a network segment address configured by the upgrade device to establish a dedicated network connection with the current target device. Deleting it after the upgrade avoids IP conflicts between the residual IP address and devices accessing other network segments (e.g., preventing new devices from being assigned the same IP address, leading to communication interruptions). It also frees up network resources such as ARP cache and routing tables, reducing the upgrade device's operating load and ensuring the real-time performance of subsequent operations. Furthermore, the temporary IP address's validity period only matches the current upgrade process. Deleting it prevents unauthorized devices from using the residual IP address to impersonate the upgrade device and launch network attacks. It also prevents users from accidentally using the temporary IP address to access other devices, ensuring that the upgrade device's network configuration is always adapted to the current usage scenario. This ensures the stability and security of the overall network environment from four dimensions: conflict avoidance, resource optimization, security protection, and standardized operation.
[0123] This invention also provides an apparatus for searching and upgrading devices via Ethernet, configured as the upgrade apparatus in the above method, including a device access detection module, a device authentication module, a firmware download module, a firmware and verification information pre-download module, a firmware upgrade module, and a storage management module, all connected to the main control module. See details below. Figure 4 .
[0124] The device access detection module is used to send the device discovery data packet, receive the device response data packet, and manage the addition and deletion of temporary IP addresses of the network card.
[0125] The device authentication module is used to send the certificate request frame, receive the certificate response frame, and verify the legitimacy of the device.
[0126] The firmware download module is used to download firmware compatible with the target device from the verification server in an environment with a public network.
[0127] The firmware and verification information pre-download module is configured to download the target device's firmware, certificate hash, and signature public key from the verification server in a public network environment, and then encrypt and store them in a local database.
[0128] The firmware upgrade module is used to send the firmware data frame and receive the upgrade response frame.
[0129] The storage management module is used to classify and store online and offline resources, device information, authentication and upgrade logs, and supports fast read and write operations as well as emergency data protection.
[0130] The main control module is connected to the display module. After receiving the upgrade results from the target device, the display module displays the upgrade results.
[0131] The device also includes Ethernet RJ45 interfaces, USB interfaces, RS232 interfaces, RS485 interfaces, TTL interfaces, WiFi interfaces, LoRa interfaces, 4G modules, antennas, button modules, hardware watchdogs, power modules, and power output interfaces, all connected to the main control module. See details... Figure 5-6 .
[0132] This invention provides common communication interfaces: USB, Ethernet RJ45, RS232, RS485, TTL, WiFi, and LoRa, meeting the upgrade needs of various devices, with only one of each interface available. For Ethernet RJ45, RS485, WiFi, and LoRa interfaces, multiple devices on the same network can be upgraded simultaneously. For field devices without a public network, firmware and verification information can be downloaded via a firmware and verification information pre-download module in an environment with a public network, and then the upgrade can be performed at the device site.
[0133] The present invention also provides a system for searching and upgrading devices via Ethernet, performing the above-described method for searching and upgrading devices via Ethernet to upgrade a target device, including:
[0134] The upgrade device is configured as the upgrade device provided in the above solution;
[0135] Target device: Built-in unique digital certificate, configured to receive the device discovery data packet sent by the upgrade device and return the device response data packet, receive the certificate request frame and return the certificate response frame, receive the firmware data frame and return the upgrade response frame, and perform firmware upgrade operation;
[0136] The verification server stores information on legitimate devices, a list of revoked certificates, and compatible firmware. It provides online device legitimacy verification services, as well as real-time firmware downloads for online upgrades and pre-download resources for offline upgrade preparation.
[0137] The verification server includes a Certificate Authority (CA) system, a whitelist database, a Revocation List (CRL) module, a verification service interface, and a log auditing module.
[0138] The Certificate Authority (CA) system is used to issue digital certificates containing serial numbers, public keys, and signatures to legitimate target devices.
[0139] The whitelist database is used to store the serial numbers and certificate hashes of legitimate target devices.
[0140] The Certificate Revocation List (CRL) module is used to revoke the certificates of leaked or obsolete target devices. The CRL module is configured to update the certificate information of leaked or obsolete target devices in real time.
[0141] The verification service interface is used to receive certificate information sent by the upgrade device, query the whitelist database and revocation list (CRL) module, verify the certificate signature using the CA public key, and return the verification result.
[0142] The log auditing module is used to record the time of the verification request, the target device serial number, the verification result, and the request IP.
[0143] This invention provides multiple interfaces and can simultaneously upgrade firmware for multiple devices, improving the operability and efficiency of device upgrades. Through intelligent firmware download and management, it intelligently identifies and automatically upgrades devices, reducing manual operation steps and lowering labor costs. This invention improves system security by intelligently authenticating and verifying the legitimacy of devices. This invention achieves offline verification and offline upgrades for devices through a firmware and verification information pre-download module, broadening its application scenarios. Compared with existing offline verification and upgrade methods, it eliminates the need to download firmware for each device, significantly reducing storage consumption. The device verification information downloaded in this invention is separated from the firmware, allowing for large-scale storage of device verification information and providing upgrades for a large number of devices simultaneously. The firmware downloaded in this invention remains general-purpose firmware and can be used for upgrading other devices.
[0144] The above description is a detailed description of the preferred embodiments of the present invention. However, the embodiments are not intended to limit the scope of the patent application of the present invention. All equivalent changes or modifications made under the technical spirit of the present invention should fall within the patent scope covered by the present invention.
Claims
1. A method for searching and upgrading devices via Ethernet, characterized in that, This includes online upgrade methods and offline upgrade methods. The online upgrade method executes steps A1-A5, and the offline upgrade method executes steps A0-A5. A0. Offline resource preparation: In a public network environment, the upgrade device receives the target device serial number input by the user, downloads the firmware, certificate hash and signature public key corresponding to the serial number from the verification server in advance, and stores them in a local database in encryption. A1. Cross-network segment device search: The upgrade device uses UDP broadcast to send device discovery data packets to all devices in the network segment, receives device response data packets returned by the target device, and parses them to obtain the device IP address, subnet mask and device information; A2. Dynamically configure network connection: Based on the device IP address and subnet mask obtained in step A1, the upgrade device adds a temporary IP address on the network card that is in the same network segment as the target device; A3. Verify device legitimacy: This includes online and offline verification steps. If an online upgrade method is used, the online verification steps are employed; if an offline upgrade method is used, the offline verification steps are employed. If verification is successful, proceed to step A4; if verification fails, proceed to step A5. Online verification steps: In an environment with a public network, the upgrade device sends a certificate request frame to the target device via a TCP connection and receives a certificate response frame returned by the target device; The certificate information in the certificate response frame is sent to the verification server, which verifies the legitimacy of the target device. Offline verification steps: In an environment without a public network, the upgrade device sends a certificate request frame to the target device via a TCP connection and receives a certificate response frame returned by the target device. The system calls the local database and uses the certificate hash and signing public key to verify the legitimacy of the target device. A4. Target device upgrade: Includes online upgrade steps and offline upgrade steps; if the online upgrade method is performed, the online upgrade steps shall be used; if the offline upgrade method is performed, the offline upgrade steps shall be used. Online upgrade steps: The upgrade device downloads firmware compatible with the target device from the verification server, sends firmware data frames to the target device via TCP connection, receives upgrade response frames returned by the target device, and the target device receives the firmware data frames and completes the device upgrade. Offline upgrade steps: The upgrade device retrieves the firmware corresponding to the target device from the local database, sends firmware data frames to the target device via TCP connection, receives upgrade response frames returned by the target device, and the target device receives the firmware data frames and completes the device upgrade. A5. Cleanup and Result Indication: The upgrade device deletes the temporary IP address added in step A2 and outputs the upgrade result through its own display module; In step A3, the online verification process is as follows: (1) The upgrade device sends a request parameter to the verification server. The request parameter includes the certificate information in the certificate response frame, specifically including the serial number of the target device, the certificate hash, and the signature public key. (2) The verification server queries the whitelist database through the verification service interface to confirm whether the serial number of the target device exists; if it does not exist, the log audit module records the illegal serial number and the verification service interface returns an "invalid" result; if it exists, the revocation list CRL module is queried to confirm whether the serial number has been revoked. (3) If the serial number has been revoked, the log audit module records the revocation access and the verification service interface returns an "invalid" result; if it has not been revoked, the public key issued by the certificate issuance system CA is used to verify the certificate signature and the certificate hash is compared with the hash value in the whitelist database. (4) If the certificate signature is valid and the hash value matches, the log audit module records "verification successful" and the verification service interface returns "valid"; if they do not match, it returns "invalid". Among them, the Certificate Issuance System (CA), the verification service interface, the whitelist database, the log audit module, and the revocation list (CRL) module are all components of the verification server; In step A3, the specific process of the offline verification step is as follows: (1) The upgrade device sends a certificate request frame to the target device via a TCP connection; (2) After receiving the certificate request frame, the target device returns a certificate response frame; (3) The upgrade device parses the certificate response frame and extracts the serial number and certificate data of the target device; (4) The upgrade device calls the resources encrypted and stored in the local database in step A0, and matches the corresponding certificate hash and signature public key according to the extracted serial number; (5) The upgrade device extracts the hash value from the target device certificate data and compares it with the certificate hash matched in the local database; at the same time, it uses the locally stored signature public key to verify the signature validity of the certificate data. (6) If the certificate hash match and the signature verification is successful, the target device is deemed legitimate; if any step fails, the target device is deemed illegitimate and the subsequent upgrade operation is terminated.
2. The method for searching and upgrading devices via Ethernet according to claim 1, characterized in that, In step A1, the contents of the data packet discovered by the device include: packet header identifier, function code, frame sequence number, reserved fields, and CRC frame check; the contents of the data packet responded by the device include: device IP address, subnet mask, packet header identifier, function code, frame sequence number, device type, device software version number, device hardware version number, and CRC frame check.
3. The method for searching and upgrading devices via Ethernet according to claim 1, characterized in that, In step A4, the firmware data frame includes: packet header identifier, function code, frame sequence number, total firmware length, data frame sequence number, current frame data length, firmware data, and CRC frame check; the upgrade response frame includes: packet header identifier, function code, frame sequence number, reserved fields, and CRC frame check.
4. An apparatus for searching and upgrading devices via Ethernet, characterized in that, The device is configured as an upgrade device as described in any one of claims 1-3, comprising a device access detection module, a device authentication module, a firmware download module, a firmware and verification information pre-download module, a firmware upgrade module, and a storage management module, all of which are connected to the main control module. The device access detection module is used to send the device discovery data packet, receive the device response data packet, and manage the addition and deletion of temporary IP addresses of the network card; The device authentication module is used to send the certificate request frame, receive the certificate response frame, and verify the legitimacy of the device; The firmware download module is used to download firmware compatible with the target device from the verification server in an environment with a public network. The firmware and verification information pre-download module is configured to download the target device's firmware, certificate hash, and signature public key from the verification server in a public network environment, and encrypt and store them in a local database. The firmware upgrade module is used to send the firmware data frame and receive the upgrade response frame; The storage management module is used to classify and store online and offline resources, device information, authentication and upgrade logs, and supports fast read and write and emergency data protection; The main control module is connected to the display module. After receiving the upgrade results from the target device, the display module displays the upgrade results.
5. The apparatus for searching and upgrading devices via Ethernet according to claim 4, characterized in that, It also includes Ethernet RJ45 interface, USB interface, RS232 interface, RS485 interface, TTL interface, WiFi interface, LoRa interface, 4G module, antenna, button module, hardware watchdog, power module, and power output interface, all of which are connected to the main control module.
6. A system for searching and upgrading devices via Ethernet, characterized in that, Upgrading a target device by performing the method of searching and upgrading devices via Ethernet as described in any one of claims 1-3 includes: An upgrade device, configured as an upgrade device as described in any one of claims 4-5; Target device: Built-in unique digital certificate, configured to receive the device discovery data packet sent by the upgrade device and return the device response data packet, receive the certificate request frame and return the certificate response frame, receive the firmware data frame and return the upgrade response frame, and perform firmware upgrade operation; The verification server stores information on legitimate devices, a list of revoked certificates, and compatible firmware. It provides online device legitimacy verification services, as well as real-time firmware downloads for online upgrades and pre-download resources for offline upgrade preparation.
7. A system for searching and upgrading devices via Ethernet according to claim 6, characterized in that, The verification server includes a Certificate Authority (CA) system, a whitelist database, a Revocation List (CRL) module, a verification service interface, and a log auditing module. The Certificate Authority (CA) system is used to issue digital certificates containing serial numbers, public keys, and signatures to legitimate target devices. The whitelist database is used to store the serial numbers and certificate hashes of legitimate target devices; The CRL (Revocation List) module is used to revoke the certificates of target devices that have been leaked or are obsolete. The verification service interface is used to receive certificate information sent by the upgrade device, query the whitelist database and the revocation list CRL module, verify the certificate signature using the CA public key, and return the verification result. The log auditing module is used to record the time of the verification request, the target device serial number, the verification result, and the request IP.
8. A system for searching and upgrading devices via Ethernet according to claim 7, characterized in that, The CRL (Certificate Revocation List) module is configured to update the certificate information of leaked or obsolete target devices in real time.
Citation Information
Patent Citations
Batch upgrading method and device for vehicle-mounted equipment software
CN115361119A
Software upgrading method of Internet of Things terminal
CN118647016A