Ukey program updating method and system

By pre-installing authorization and signing certificates in the Ukey device and using offline authorization devices for identity authentication and trusted transmission, the security and legitimacy issues of offline updates for Ukey devices are resolved, enabling secure and convenient program updates.

CN121807334APending Publication Date: 2026-04-07FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Ukey devices lack security controls for offline program updates, posing a risk of unauthorized program implantation. Online updates are also limited, leading to high costs and compatibility issues.

Method used

By connecting the client device and the offline authorization device via a wired connection, and using the pre-installed authorization certificate and signature certificate of the offline authorization device to perform mutual identity recognition between devices, a physically isolated communication link is established to ensure the legality and security of program updates, and a closed-loop mechanism of offline authorization and trusted transmission is adopted.

Benefits of technology

This technology enables secure updates of Ukey programs in offline environments, blocking network attack paths, preventing the implantation of unauthorized programs, reducing costs, and improving the convenience and security of updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121807334A_ABST
    Figure CN121807334A_ABST
Patent Text Reader

Abstract

The invention discloses a Ukey program updating method and system, and the method comprises the steps: carrying out the interaction with to-be-updated Ukey equipment and offline authorization equipment, so as to obtain offline authorization; and after the authorization is successful, acquiring the Ukey program to be updated, and sending the Ukey program to be updated to the Ukey equipment to be updated, so as to update the old Ukey program of the Ukey equipment to be updated into the Ukey program to be updated. According to the method, after offline authorization is completed, the Ukey device to be updated does not have the active communication capability, the client device serves as a trusted intermediary to transmit the Ukey program to be updated, and it is guaranteed that the program transmission process cannot be tampered through physical connection of a hardware level. According to the whole method, a multi-level security barrier is established before the program is updated through a closed-loop mechanism of cooperative verification, offline authorization and trusted transmission among equipment, so that the offline environment operation requirement is met, and the implantation risk of illegal programs is effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of program updating, in particular to a Ukey program updating method and system. BACKGROUND

[0002] UKey (USB Key) is a kind of hardware client device connected to computer through USB interface, which is widely used in identity authentication, digital signature and data encryption scenes. The sensitive data such as keys and certificates stored in UKey are managed by a special program, which needs to be updated regularly to fix vulnerabilities or enhance functions.

[0003] In the related art, the update of UKey program lacks strict security control, and there is a great security risk. SUMMARY

[0004] The technical problem to be solved by the present application is to provide a Ukey program updating method and system, which can update the Ukey program offline and ensure the legality of the updated program, and improve data security.

[0005] In order to solve the above technical problems, a technical solution adopted by the present application is: A Ukey program updating method for a client device, the client device being wiredly connected to an offline authorization device and a Ukey device to be updated, the method comprising: interacting with the Ukey device to be updated and the offline authorization device to obtain offline authorization; after successful authorization, obtaining a Ukey program to be updated, and sending the Ukey program to be updated to the Ukey device to be updated to update the old Ukey program of the Ukey device to be updated to the Ukey program to be updated.

[0006] In order to solve the above technical problems, another technical solution adopted by the present application is: An electronic device comprising a memory, a processor and a computer program stored in the memory and running on the processor, the processor executing the computer program to implement each step of the above-mentioned Ukey program updating method The beneficial effects of the present application are that: the Ukey device to be updated and the offline authorization device establish a physically isolated communication link through the client device, and the identity of the devices is mutually recognized by using the pre-installed authorization work certificate in the offline authorization device, so as to fundamentally block the network attack path. The pre-installed authorization work certificate in the offline authorization device serves as a trust anchor, ensuring that the program update operation can only be performed between strictly authenticated devices, thereby ensuring that the Ukey program updated by the Ukey device to be updated is legal in origin and ensuring the security of the Ukey program update. After offline authorization is completed, since the Ukey device to be updated itself does not have active communication capability, the Ukey program to be updated is transmitted by the client device as a trusted intermediary, and the program transmission process is ensured to be tamper-proof through physical connection at the hardware level. The entire method establishes a multi-level security barrier before program update through the closed-loop mechanism of device collaborative verification, offline authorization and trusted transmission, which not only meets the operation requirements in offline environment, but also effectively prevents the risk of illegal program implantation. BRIEF DESCRIPTION OF DRAWINGS

[0007] Figure 1 A step flowchart of a Ukey program update method provided by an embodiment of the present application is implemented in a client device; Figure 2 A step flowchart of a Ukey program update method provided by an embodiment of the present application is implemented in an offline authorization device; Figure 3 A step flowchart of a Ukey program update method provided by an embodiment of the present application is implemented in a Ukey device to be updated; Figure 4 A system block diagram of a Ukey program update system provided by an embodiment of the present application; Figure 5 A composition schematic diagram of a Ukey program update system provided by an embodiment of the present application; Figure 6 A timing diagram of a Ukey program update method provided by an embodiment of the present application is implemented in a system. Figure 4 DETAILED DESCRIPTION

[0008] In order to make the technical problems, technical solutions and beneficial effects of the present application clearer, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0009] ​In the following description, for purposes of explanation and not limitation, specific details are set forth such as particular architectures, techniques, etc. in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known methods, devices, circuits, and

[0010] It is to be understood that the terminology "including", "comprising", "consisting" and "consisting essentially of" used in the specification and the appended claims, indicates the presence of the stated features, integers, steps, operations, elements, and / or components but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0011] Reference throughout this specification to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. Thus, the appearances of the phrases "in one embodiment" or "in an embodiment" or "in a various embodiment" or "in some embodiments" in various places throughout this specification are not necessarily referring to the same embodiment, unless otherwise specified. The terms "including", "comprising", "consisting essentially of" and "consisting of" are used interchangeably, unless otherwise specified.

[0012] In the related art, Ukey (USB Key, also known as USB Token or Crypto Lock), is a small hardware-based security device, usually connected with a computer through a USB interface, used for identity authentication, data encryption, digital signature, and other security operations. Its core functions mainly include the following: 1. Identity authentication, storing user certificates, used for logging into systems (such as banks, government systems, enterprise VPNs, etc.); 2. Digital signature, signing files / transactions through the built-in private key (such as electronic contracts, blockchain transactions); 3. Data encryption, supporting AES (Advanced Encryption Standard), RSA (a type of asymmetric encryption algorithm), SM2 / SM4 (national encryption algorithm), etc. encryption methods; 4. Secure storage, protecting sensitive data (such as keys, certificates) from malicious software theft. The program running in the Ukey device is responsible for managing sensitive data such as keys and certificates in the Ukey device, so if the Ukey device is updated with an illegal program by someone, the illegal program may output sensitive data, leading to the leakage of sensitive data, thereby affecting the security of Ukey use.

[0013] In the related art, the Ukey device generally does not support program updating, mainly because: first, the Ukey device itself does not have active communication capability and cannot independently perform online authorization update, and must rely on the client to realize the communication function, so that the update process is greatly limited; second, the Ukey device is used as an offline device in many application scenarios and is in a network disconnected environment, so that even if it is connected to the client, it cannot realize online update; third, when updating in an offline environment, it is difficult to ensure the legality and security of the updated program, and there is a risk of being implanted by malicious programs. Therefore, when the Ukey device needs to add new functions or fix security vulnerabilities, it is usually necessary to reissue new UKey devices to replace old UKey devices. This approach results in high costs and additional expenses for recycling old UKey devices. If old UKey devices are not replaced, the server and client need to be compatible with multiple versions of UKey, and as the number of versions increases, the compatibility cost increases, and known security vulnerabilities exist the risk of being maliciously exploited.

[0014] To solve the above problems, please refer to Figure 1 The application provides a Ukey program updating method, which is used for a client device, and the client device is wiredly connected with an offline authorization device and a Ukey device to be updated. The client device can be a PC client, which is connected with the offline authorization device and the Ukey device to be updated through a USB interface. The offline authorization device includes a POS machine, a cash register, a code scanning terminal and other devices with high security, and can also be a device with IC card recognition and IC card payment function.

[0015] The method includes steps 110 to 120.

[0016] Step 110, interacting with the Ukey device to be updated and the offline authorization device to obtain offline authorization.

[0017] Step 120, after authorization succeeds, obtaining the Ukey program to be updated, and sending the Ukey program to be updated to the Ukey device to be updated, so as to update the old Ukey program of the Ukey device to be updated to the Ukey program to be updated. The offline authorization device includes a device capable of providing authorization information and completing identity mutual authentication between devices, such as a POS machine.

[0018] From the above embodiment, the to-be-updated Ukey device and the offline authorization device establish a physically isolated communication link through the client device, and the identity of the devices is mutually recognized by using the pre-set authorization information in the offline authorization device, so that the network attack path is fundamentally blocked. The authorization information pre-set in the offline authorization device serves as a trust anchor, and ensures that the program update operation can only be performed between devices that have passed strict identity verification. After the offline authorization is completed, since the to-be-updated Ukey device itself does not have active communication capability, the client device is used as a trusted intermediary to transmit the target program, and the program transmission process is ensured to be tamper-proof through the physical connection at the hardware level. The entire method establishes a multi-level security barrier before program updating through the closed-loop mechanism of device collaborative verification, offline authorization and trusted transmission, which not only meets the operation demand in offline environment, but also effectively prevents the risk of illegal program implantation.

[0019] In an embodiment of the present application, step 110 includes steps 111 to 113.

[0020] Step 111, obtaining the authorization request generated by the to-be-updated Ukey device, and forwarding the authorization request to the offline authorization device.

[0021] Step 112, receiving the authorization reply data corresponding to the authorization request returned by the offline authorization device, and sending the authorization reply data to the to-be-updated Ukey device to instruct the to-be-updated Ukey device to verify the identity of the offline authorization device through the authorization reply data, and to confirm the authorization result according to the identity verification result.

[0022] Step 113, receiving the authorization result of the to-be-updated Ukey device.

[0023] From the above embodiment, the to-be-updated Ukey device and the offline authorization device establish a physically isolated communication link through the client device, and the identity of the devices is mutually recognized by using the pre-set authorization information in the offline authorization device, so that the network attack path is fundamentally blocked. The authorization information pre-set in the offline authorization device serves as a trust anchor, and ensures that the program update operation can only be performed between devices that have passed strict identity verification. After the offline authorization is completed, since the to-be-updated Ukey device itself does not have active communication capability, the client device is used as a trusted intermediary to transmit the target program, and the program transmission process is ensured to be tamper-proof through the physical connection at the hardware level. The entire method establishes a multi-level security barrier before program updating through the closed-loop mechanism of device collaborative verification, offline authorization and trusted transmission, which not only meets the operation demand in offline environment, but also effectively prevents the risk of illegal program implantation.

[0024] In an embodiment of the present application, step 111 includes steps 1111 to 1112.

[0025] Step 1111: Send a program update command to the Ukey device to be updated. The program update command is used to instruct the Ukey device to generate a random number.

[0026] Step 1112: Receive the random number sent by the Ukey device to be updated, and send the random number to the offline authorization device.

[0027] As can be seen from the above embodiments, after the client device sends a program update command to the Ukey device to be updated, the Ukey device to be updated generates a random number as a dynamic parameter, which is then transmitted to the offline authorization device through the client device. This ensures that each authorization process is unique and avoids the risk of fixed credentials being intercepted and reused.

[0028] In one embodiment of this application, step a is included before step 110.

[0029] Step a: Store the authorization certificate, the private key corresponding to the authorization certificate, and the access password for accessing the IC card in the IC card of the offline authorization device. The Ukey device to be updated has a pre-installed parent certificate of the authorization certificate, i.e., the authorization root certificate; and a pre-installed parent certificate of the signing certificate, i.e., the signing root certificate.

[0030] As can be seen from the above embodiments, the upper-level certificate of the authorization working certificate and the upper-level certificate of the signing working certificate are pre-installed in the Ukey device to be updated. The legality of the authorization working certificate can be verified by the authorization root certificate, and the legality of the signing working certificate can be verified by the signing root certificate. If they are legal, it means that the offline authorization device with the authorization working certificate is legal, and the client device with the signing working certificate is legal. Only when both are legal will the Ukey device to be updated update the Ukey program. This ensures the legality of the update process while updating the Ukey program in the Ukey device to be updated.

[0031] In one embodiment of this application, step 112 further includes step 1121.

[0032] Step 1121: Receive the authorization response data returned by the offline authorization device. The authorization response data includes the signature data of the random number and the authorization certificate. Send the authorization response data to the Ukey device to be updated to instruct the Ukey device to verify the identity of the offline authorization device through the signature data and process the authorization certificate according to the identity verification result.

[0033] As can be seen from the above embodiments, the offline authorization device uses a pre-set authorization work certificate to digitally sign the random number, generating an authorization signature containing dynamic parameters. This signature contains both the offline authorization device's identity authentication information and the random number bound to the current session, forming a dual verification element. After the updated Ukey device receives the authorization reply data, it can verify the signature data through the authorization work certificate to determine whether the offline authorization device's identity is secure.

[0034] In one embodiment of this application, step 112, confirming the authorization result based on the authentication result, includes completing offline authorization based on the authorization work certificate in the authorization response data if the authentication is successful.

[0035] As can be seen from the above embodiments, after successful identity verification, it indicates that the offline authorization device that sent the authorization reply data is secure and has the corresponding permissions. Then, the offline authorization process is completed according to the authorization certificate it sent, allowing the Ukey program in the Ukey device to be updated to be updated, thus ensuring the security of the Ukey program's update authorization.

[0036] In one embodiment of this application, step 112 is further defined as step 1122.

[0037] Step 1122: Receive the authorization response data corresponding to the authorization request returned by the offline authorization device, send the authorization response data to the Ukey device to be updated, so as to instruct the Ukey device to be updated to verify the legality of the authorization working certificate in the authorization response data through the preset authorization root certificate, and confirm the authorization result according to the verification result.

[0038] As described in the above embodiments, after the client device sends the authorization response data back to the Ukey device to be updated, the Ukey device to be updated performs the offline authorization determination. Specifically, it checks the validity of the authorization working certificate by verifying the pre-set authorization root certificate. If the certificate is valid, the authorization permissions corresponding to the offline authorization device are determined. This can also be combined with the random number verification process in step 1121, using a dynamic parameter-response mechanism to replace the static authorization method, effectively preventing man-in-the-middle attacks and replay attacks, and solving the illegal authorization vulnerability caused by fixed authorization credentials in traditional offline updates.

[0039] In one embodiment of this application, step 120, which involves sending the Ukey program to be updated to the Ukey device to be updated, includes steps 121 to 122.

[0040] Step 121: Obtain the program signature by signing the program using the private key to be updated Ukey corresponding to the signing work certificate.

[0041] Step 122: Send the Ukey program to be updated, the signing certificate, and the program signature to the Ukey device to be updated.

[0042] As described above, when a client device sends a UKey program to be updated, it signs the UKey program using the private key corresponding to the signing certificate to obtain a program signature. The signing certificate and program signature are then sent to the UKey device along with the UKey program. Before installing the UKey program, the UKey device can verify the client's identity through the program signature and the signing certificate. That is, after offline authorization, the client device's authentication must also be successful before the UKey device will update according to the UKey program, ensuring that the updated program originates from a legitimate client device and has not been tampered with. This ensures the security of the source of the UKey program and thus guarantees the security of the UKey program itself.

[0043] In one embodiment of this application, step 122 includes step 1221.

[0044] Step 1221: Send the Ukey program to be updated, the signing working certificate, and the program signature to the Ukey device to be updated, so as to instruct the Ukey device to verify the legality of the signing working certificate according to the pre-stored working root certificate, and after the verification is successful, verify the legality of the program signature according to the signing working certificate. If the program signature is legal, install the Ukey program to be updated.

[0045] As described above, the Ukey device to be updated verifies the legitimacy of the signing working certificate based on the pre-stored working root certificate. If it is legitimate, it means that the owner of the signing working certificate has the corresponding authority. The signing working certificate is then used to verify the legitimacy of the program signature, preventing the Ukey program to be updated from being tampered with during transmission. The Ukey program to be updated is only installed after both the signing working certificate and the program signature have been verified. This ensures that the source of the installed Ukey program is legitimate and that the Ukey program itself has not been tampered with, thereby ensuring the security of the Ukey program update process.

[0046] Furthermore, while verifying the data signature confirms the download of a legitimate Ukey program, the Ukey device, being a secure device, requires stricter control over program updates. This means that even after granting update permissions, the device must ensure the Ukey program it receives is also legitimate; it must receive the program from a legitimate peer. This necessitates authentication of the peer (client device). In online update scenarios, if the server directly sends the Ukey program to the device, the device can directly authenticate the server's identity online. If the client sends the program, the server can verify the client's identity, for example, via a mobile authorization code (verification code). However, both methods require online verification. To ensure security, Ukey devices typically cannot directly connect to the internet. Therefore, a secure offline authorization device is used to authenticate the device, ensuring a secure connection between the Ukey device and the peer.

[0047] This application also provides a Ukey program update method for offline authorization devices, including IC card devices, which are connected to client devices. For example, the offline authorization device can be a POS machine, cash register, or other device with its own IC card that requires security verification to unlock corresponding functions, thus ensuring the security of the device itself capable of offline authorization.

[0048] A method for updating a Ukey program includes the following steps 210.

[0049] Step 210: Interact with the client device, issue offline authorization, and instruct the client device to execute the various steps in the above-mentioned Ukey program update method for user client devices.

[0050] In one embodiment of this application, steps 201 to 202 are included before step 210.

[0051] Step 201: Pre-store the access password corresponding to the IC card.

[0052] Step 202: Receive the input password. If the input password matches the access password, obtain the authorization certificate from the IC card.

[0053] Step 210 includes steps 211 to 212.

[0054] Step 211: Receive the random number sent by the client, and sign the random number using the private key corresponding to the authorized work certificate to obtain the signature data of the random number.

[0055] Step 212: Send the signature data and authorization certificate to the client device.

[0056] As described above, by pre-storing the access password in the IC card, users must enter the correct access password to access the authorized work certificate stored in the IC card, thus achieving identity verification for offline authorization. Simultaneously, by signing the received random number to generate authorization reply data, the Ukey device to be updated can verify whether the data has been tampered with during transmission. If the random number does not match the sent random number, it indicates that the message source may be illegitimate, and the Ukey will not perform the corresponding offline authorization, thus preventing the Ukey program from being updated and ensuring the security of the Ukey device to be updated. Furthermore, an authorized work certificate is provided, allowing the Ukey to further verify the legitimacy of the offline authorized device. If the certificate is illegitimate, the data will not be parsed, thereby ensuring system security.

[0057] This application also provides a Ukey program update method for a Ukey device to be updated, wherein the Ukey device to be updated is connected to a client device.

[0058] The method includes the following steps 310 to 330.

[0059] Step 310: Interact with the client device to receive offline authorization.

[0060] Step 320: Verify offline authorization. If the verification is successful, send an authorization success notification to the client device to instruct the client device to send the Ukey program to be updated obtained by the Ukey program update method implemented by the client device described above.

[0061] Step 330: Update the old Ukey program to the Ukey program to be updated.

[0062] In one embodiment of this application, step 301 is also included: after the Ukey program is written for the first time, the original manufacturer's update channel of the Ukey program is closed.

[0063] As described above, subsequent updates to the Ukey program can only be completed through offline authorization, and cannot be completed through the original manufacturer's update channel. This avoids the vulnerability of the original manufacturer's update channel bypassing the security verification of the offline authorization settings. It ensures that each Ukey program update requires dual authentication from both the offline authorization device and the client device, thereby guaranteeing the security of the Ukey program's source and preventing the installation of illegal Ukey programs.

[0064] In one embodiment of this application, step 310 includes steps 311 to 314.

[0065] Step 311: After receiving the program update instruction from the client device, generate a random number and send the random number to the client device.

[0066] Step 312: Receive the authorization response data sent by the client device. The authorization response data includes the signature data of the random number and the authorization certificate.

[0067] Step 313: Verify the authorization working certificate with the stored authorization root certificate. If the verification is successful, verify the signature data with the authorization working certificate. If the verification is successful, the authorization is successful.

[0068] Step 314: Send the authorization result (if authorization is successful) to the client device.

[0069] As described above, after the Ukey device to be updated receives the program update instruction, it generates a random number and sends it to the client device. Subsequently, upon receiving the authorization response data sent by the client device, it can use the random number to determine whether the source of the authorization response data is legitimate and whether the message has been forged or tampered with during transmission. Furthermore, the Ukey device to be updated has a pre-stored authorization root certificate. Only authorization working certificates that can pass the verification of the authorization root certificate are considered to be legitimate authorization working certificates. This ensures that only a predetermined set of offline authorization devices can complete the offline authorization operation, rather than any random offline authorization device being able to authorize the Ukey device to be updated. After the authorization working certificate is verified, the random number signature is verified based on the authorization working certificate. Only when multiple verifications pass will the Ukey device to be updated continue to receive the Ukey program to be updated, ensuring the security of the update process.

[0070] In one embodiment of this application, after sending the authorization success notification to the client device in step 320, step 321 is also included.

[0071] Step 321: Receive the Ukey program to be updated, the signing certificate, and the program signature sent by the client device.

[0072] Step 330 includes step 331.

[0073] Step 331: Verify the signing working certificate using the pre-stored signature root certificate. If the verification is successful, verify the signature program based on the signature working certificate. If the verification is successful, update the old Ukey program to the Ukey program to be updated.

[0074] As described above, even after the offline authorization device completes offline authorization, the client device sends not only the Ukey program to be updated, but also a signing working certificate and a program signature. The program signature is obtained by the client device signing the Ukey program to be updated using the private key corresponding to the signing working certificate. After receiving the Ukey program to be updated, the Ukey device first verifies the signing working certificate through the pre-stored signature root certificate. If it is valid, it then verifies the program signature through the signing working certificate. Only if both are valid will the old Ukey program be updated to the Ukey program to be updated. Thus, after verification by the offline authorization device, it also needs to be verified by the client device, providing double protection to ensure the security of the Ukey program to be updated.

[0075] Please refer to Figure 4 This application also provides a Ukey program update system 400, including a Ukey device 401 to be updated, a client device 402, and an offline authorization device 403, wherein the client device 402 is connected to the Ukey device 401 to be updated and the offline authorization device 403 respectively.

[0076] Reference Figure 5 In this application, the client device can be a PC client device; the offline authorization device can be an IC card device, such as a POS machine. The Ukey device is connected to the PC client device, and the PC client device is connected to the IC card device via a USB cable, enabling communication between the offline authorization device and the Ukey device through the client device.

[0077] The client device executes the aforementioned method for updating a Ukey program for a client device; the Ukey device to be updated executes the aforementioned method for updating a Ukey program for a Ukey device to be updated; and the offline authorization device executes the aforementioned method for updating a Ukey program for an offline authorization device.

[0078] Please refer to Figure 6 The overall description outlines the steps of implementing a method for updating a Ukey program in a system for updating a Ukey program, including steps 510 to 590.

[0079] Step 510: After the Ukey program is first burned into the Ukey device to be updated, the original chip manufacturer's flashing method will be permanently disabled. Subsequent updates will only be allowed via offline authorization. The IC card of the offline authorization device stores the authorization certificate, the corresponding private key, and the access password for accessing the IC card. The Ukey device to be updated has a pre-installed parent certificate of the authorization certificate (i.e., the authorization root certificate) and a pre-installed parent certificate of the signing certificate (i.e., the signing root certificate). This is equivalent to step a above.

[0080] Step 520: The offline authorization device receives the entered password and compares it with the access password. If they match, the IC card verification is successful, and the IC card function can then be used to obtain the authorization certificate. This is equivalent to steps 201 to 202 above.

[0081] Step 530: The client device sends a program update command to the Ukey device to be updated, initiating the program update process. This is equivalent to step 1111 above.

[0082] Step 540: The Ukey device to be updated generates a random number R and returns it to the client device. The client device then sends the random number R to the offline authorization device. This is equivalent to step 1112 above.

[0083] Step 550: The offline authorization device uses the private key corresponding to the authorization certificate in the IC card to sign the random number R, and returns the signature data of the random number R and the authorization certificate to the client device. This is equivalent to step 1121 above.

[0084] Step 560: The client device sends the signature data of the random number R and the authorization certificate to the Ukey device to be updated. This is equivalent to step 1121 above.

[0085] Step 570: The Ukey device to be updated uses the authorized root certificate to verify the legitimacy of the authorized working certificate, and uses the public key in the authorized working certificate to verify the signature data of R. If it is legitimate, the authorization is completed, and the program update process can proceed to step 580. This is equivalent to step 1121 above.

[0086] Step 580: The client device obtains the Ukey program to be updated, and signs the Ukey program to be updated using the private key corresponding to the signing certificate to obtain the program signature; the client device sends the Ukey program to be updated, the signing certificate, and the program signature to the Ukey device to be updated. This is equivalent to steps 121 to 122 above.

[0087] Step 590: After the Ukey device to be updated obtains the Ukey program to be updated, the signing certificate, and the program signature, it uses the parent certificate of the signing certificate, i.e., the signing root certificate, to verify the legality of the signing certificate. If it is legal, it continues to use the signing certificate to verify the legality of the program signature. If the signature is legal, the program update is completed. This is equivalent to step 1221 above.

[0088] In summary, this invention provides a Ukey program update method and system. By pre-installing the authorization root certificate required for verifying the offline authorization device and the signature root certificate required for verifying the client device in the Ukey device to be updated, all received messages must be verified by either the authorization root certificate or the signature root certificate before execution, thus ensuring the security of the source of the Ukey program to be updated. In this application, after writing the Ukey program into the Ukey device to be updated, the original manufacturer's update channel is disabled. Subsequent updates to the Ukey program can only be performed through offline verification, requiring verification by the offline authorization device. This ensures the legitimacy of the Ukey program's source. Furthermore, the offline authorization method guarantees that the Ukey device to be updated will only initiate the offline update process to obtain the Ukey program from the client device after obtaining authorization from the offline authorization device, and will only receive update programs sent by legitimate clients.

[0089] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A method for updating a Ukey program, characterized in that, For a client device, the client device is wired to both an offline authorization device and a Ukey device to be updated, the method includes: Interact with the Ukey device to be updated and the offline authorization device to obtain offline authorization; After successful authorization, the Ukey program to be updated is obtained and sent to the Ukey device to be updated, so as to update the old Ukey program of the Ukey device to the new Ukey program.

2. The Ukey program update method according to claim 1, characterized in that, The interaction with the Ukey device to be updated and the offline authorization device to obtain offline authorization includes: Obtain the authorization request generated by the Ukey device to be updated, and forward the authorization request to the offline authorization device; The system receives authorization response data corresponding to the authorization request returned by the offline authorization device, sends the authorization response data to the Ukey device to be updated, and instructs the Ukey device to be updated to verify the identity of the offline authorization device through the authorization response data, and confirm the authorization result based on the identity verification result. Receive the authorization result of the Ukey device to be updated.

3. The Ukey program update method according to claim 2, characterized in that, The step of obtaining the authorization request generated by the Ukey device to be updated and forwarding the authorization request to the offline authorization device includes: A program update command is sent to the Ukey device to be updated, the program update command being used to instruct the Ukey device to generate a random number; Receive a random number sent by the Ukey device to be updated, and send the random number to the offline authorization device.

4. The Ukey program update method according to claim 3, characterized in that, Also includes: The system receives authorization response data returned by the offline authorization device, the authorization response data including the signature data of the random number and the authorization working certificate, and sends the authorization response data to the Ukey device to be updated, so as to instruct the Ukey device to be updated to verify the identity of the offline authorization device through the signature data, and process the authorization working certificate according to the identity verification result.

5. A Ukey program update method according to claim 3, characterized in that, The confirmation of authorization results based on the authentication results includes: If identity verification is successful, offline authorization is completed based on the authorization work certificate in the authorization response data.

6. A Ukey program update method according to claim 2, characterized in that, Also includes: The system receives authorization response data corresponding to the authorization request returned by the offline authorization device, sends the authorization response data to the Ukey device to be updated, and instructs the Ukey device to be updated to verify the legality of the authorization working certificate in the authorization response data through a preset authorization root certificate, and confirm the authorization result based on the verification result.

7. A Ukey program update method according to claim 1, characterized in that, Sending the Ukey program to be updated to the Ukey device to be updated includes: The program signature is obtained by signing the Ukey program to be updated using the private key corresponding to the signing work certificate. Send the Ukey program to be updated, the signing certificate, and the program signature to the Ukey device to be updated.

8. A Ukey program update method according to claim 7, characterized in that, Sending the Ukey program to be updated, the signing certificate, and the program signature to the Ukey device to be updated includes: The Ukey program to be updated, the signing working certificate, and the program signature are sent to the Ukey device to be updated, instructing the Ukey device to verify the legality of the signing working certificate based on the pre-stored working root certificate, and after the verification is successful, to verify the legality of the program signature based on the signing working certificate. If the program signature is legal, the Ukey program to be updated is installed.

9. A Ukey program update method according to claim 1, characterized in that, Also includes: After the Ukey device is first programmed with the Ukey program, the original manufacturer's update channel for the Ukey device is disabled.

10. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the computer program to implement the various steps of a Ukey program update method according to any one of claims 1 to 9.