Firmware extraction method, apparatus, device, storage medium, and program product

By loading the program to open the debug interface, configuring the startup mode and resetting, and obtaining and comparing the memory image file, the problem of destructive firmware extraction from electronic device chips in existing technologies is solved, and lossless firmware extraction is achieved.

CN122432019APending Publication Date: 2026-07-21CHINA ELECTRONICS RELIABILITY AND ENVIRONMENTAL TESTING INSTITUTE ((THE FIFTH INSTITUTE OF ELECTRONICS MINISTRY OF INDUSTRY AND INFORMATION TECHNOLOGY) (CHINA SAIBAO LABORATORY)
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA ELECTRONICS RELIABILITY AND ENVIRONMENTAL TESTING INSTITUTE ((THE FIFTH INSTITUTE OF ELECTRONICS MINISTRY OF INDUSTRY AND INFORMATION TECHNOLOGY) (CHINA SAIBAO LABORATORY)
Filing Date
2026-03-31
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing firmware extraction methods require opening the chip of electronic devices, which is somewhat destructive and cannot quickly and reliably obtain the firmware content of electronic devices.

Method used

By loading the first program onto the target device to open the debug interface, obtaining the memory image file, configuring the boot mode to flash boot mode and resetting, obtaining the second memory image file using the debug interface, and determining the contents of the firmware file by comparing the two image files.

Benefits of technology

It enables the rapid and reliable extraction of firmware files without physically modifying or damaging the target device, thus ensuring the integrity of the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122432019A_ABST
    Figure CN122432019A_ABST
Patent Text Reader

Abstract

The application relates to a firmware extraction method, device, equipment, storage medium and program product. The method comprises the following steps: firstly, a first program for opening a debugging interface of a target device is loaded to the target device, a first memory image file of the target device is acquired through the debugging interface after the debugging interface is opened, then, a start mode of the target device is configured as a flash start mode, and the target device is reset to load a firmware file in the flash, a second memory image file of the target device is acquired through the debugging interface after the target device is reset, and finally, the content of the firmware file is determined according to the first memory image file and the second memory image file. The method can extract the firmware of the target device without any physical modification or damage to the chip of the target device, does not involve destructive operation, and guarantees the integrity of the target device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of firmware information extraction technology, and in particular to a firmware extraction method, apparatus, device, storage medium, and program product. Background Technology

[0002] With increasing emphasis on information security, security assessments of electronic devices require simulating the capabilities of potential attackers and evaluating the devices' resilience. For devices using third-party chips, in-depth analysis of the firmware is necessary to identify potential security vulnerabilities or threats. Therefore, the ability to quickly and reliably obtain the firmware of electronic devices has become a pressing technical challenge.

[0003] However, current firmware extraction methods, such as physical extraction, require opening the chip of the electronic device, which is somewhat destructive. Summary of the Invention

[0004] Therefore, it is necessary to provide a firmware extraction method, apparatus, device, storage medium, and program product to address the aforementioned technical problems.

[0005] Firstly, this application provides a firmware extraction method, which includes:

[0006] Load the first program onto the target device; the first program is used to open the debug interface of the target device.

[0007] After the debug interface is opened, the first memory image file of the target device can be obtained through the debug interface;

[0008] Configure the target device's boot mode to flash boot mode and reset the target device to load the firmware file from the flash memory.

[0009] After the target device is reset, the second memory image file of the target device is obtained through the debugging interface;

[0010] The contents of the firmware file are determined based on the first memory image file and the second memory image file.

[0011] In one embodiment, loading a first program onto the target device includes:

[0012] Configure the target device's boot mode to serial port boot mode;

[0013] The first program is loaded onto the target device using a serial communication tool.

[0014] In one embodiment, obtaining the first memory image file of the target device through a debugging interface includes:

[0015] After the first program completes its execution, the target device's boot mode is configured to debug mode, and a reset is performed.

[0016] After the target device is reset, the first memory image file is obtained through the debugging interface.

[0017] In one embodiment, after the target device is reset, the first memory image file of the target device is obtained through a debugging interface, including:

[0018] After the target device is reset, a second program is loaded onto the target device through the debugging interface; the second program is used to set the target storage space of the target device to a preset value.

[0019] After the second program runs on the target device, the first memory image file is obtained through the debugging interface.

[0020] In one embodiment, after the target device is reset, a second memory image file of the target device is obtained through a debugging interface, including:

[0021] After the target device is reset, obtain the status of the debug interface;

[0022] If the debug interface is closed, load the first program onto the target device;

[0023] After the debug interface is opened, the second memory image file is obtained through the debug interface.

[0024] In one embodiment, determining the contents of the firmware file based on the first memory image file and the second memory image file includes:

[0025] The first and second memory image files are compared byte by byte to determine the differences.

[0026] Based on the difference data, determine the contents of the firmware file.

[0027] Secondly, this application also provides a firmware extraction device, which includes:

[0028] The loading module is used to load the first program onto the target device; the first program is used to open the debug interface of the target device.

[0029] The first acquisition module is used to acquire the first memory image file of the target device through the debugging interface after the debugging interface is opened;

[0030] The configuration module is used to configure the boot mode of the target device to flash boot mode and to reset the target device so that the target device loads the firmware file in flash memory;

[0031] The second acquisition module is used to acquire the second memory image file of the target device through the debugging interface after the target device is reset;

[0032] The determination module is used to determine the contents of the firmware file based on the first memory image file and the second memory image file.

[0033] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in any one of the first aspects above.

[0034] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any one of the first aspects above.

[0035] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in any one of the first aspects above.

[0036] The aforementioned firmware extraction method, apparatus, device, storage medium, and program product first load a first program for opening the target device's debug interface onto the target device. After the debug interface is opened, a first memory image file of the target device is obtained through the debug interface. Then, the target device's boot mode is configured to flash boot mode, and the target device is reset to load the firmware file from the flash memory. After the target device resets, a second memory image file of the target device is obtained through the debug interface. Finally, the contents of the firmware file are determined based on the first and second memory image files. This method, by opening the target device's debug interface and obtaining the target device's memory image file through the debug interface to determine the firmware file's contents, does not require any physical modification or damage to the target device's chip during firmware extraction, does not involve destructive operations, and ensures the integrity of the target device. Attached Figure Description

[0037] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1 This is a diagram illustrating the application environment of the firmware extraction method in one embodiment;

[0039] Figure 2 This is a flowchart illustrating a firmware extraction method in one embodiment;

[0040] Figure 3 This is a flowchart illustrating the first program loading step in one embodiment;

[0041] Figure 4 This is a flowchart illustrating the first memory image file acquisition step in one embodiment;

[0042] Figure 5 This is a flowchart illustrating the first memory image file acquisition step in another embodiment;

[0043] Figure 6 This is a flowchart illustrating the second memory image file acquisition step in one embodiment;

[0044] Figure 7 This is a flowchart illustrating the firmware file determination step in one embodiment;

[0045] Figure 8 This is a schematic diagram of the memory address mapping of a target device in one embodiment;

[0046] Figure 9 This is a flowchart illustrating the second memory image file acquisition step in one embodiment;

[0047] Figure 10 This is a flowchart illustrating the second memory image file acquisition step in one embodiment;

[0048] Figure 11 This is a flowchart illustrating the firmware extraction method in another embodiment;

[0049] Figure 12 This is a structural block diagram of a firmware extraction device in one embodiment;

[0050] Figure 13 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0051] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0052] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0053] The firmware extraction method provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, electronic device 10 serves as the hardware development platform for target device 20, which requires firmware extraction. Electronic device 10 is communicatively connected to target device 20. Electronic device 10 is also equipped with external DDR (Double Data Rate) memory 102 and SPIFlash (Serial Peripheral Interface Flash) 104. Electronic device 10 also features a standard 14-pin JTAG (Joint Test Action Group) debugging interface, RS232 or USB-to-serial communication interface, hardware configuration supporting multiple boot mode switching, and corresponding emulators and development tools. Electronic device 10 can be a general-purpose hardware development board for target device 20.

[0054] In one exemplary embodiment, such as Figure 2 As shown, a firmware extraction method is provided, which can be applied to... Figure 1 Taking an electronic device as an example, the explanation includes the following steps 201 to 205. Wherein:

[0055] Step 201: Load the first program onto the target device.

[0056] The first program is used to open the debug interface of the target device. The target device is the device from which firmware extraction is required. The target device can be a DSP (Digital Signal Processing) chip. For some types of DSP chips, the debug interface is usually locked or requires authentication in production versions, making it impossible to obtain data from the target device through the debug interface. Therefore, in order to extract the firmware from the target device, the first program needs to be loaded onto the target device first to open the target device's debug interface. The debug interface can be a JTAG debug interface or a UART interface.

[0057] The first program can be loaded onto the target device via a serial port or a network interface; this embodiment does not limit this.

[0058] Step 202: After the debug interface is opened, obtain the first memory image file of the target device through the debug interface.

[0059] Once the debug interface of the target device is enabled, input or output operations can be performed on the target device through the debug interface, such as loading programs into the target device or reading data from the target device's memory.

[0060] The data at a specified memory address of the target device is obtained through the debugging interface to obtain the first memory image file. Since the firmware file stored in Flash has not yet been loaded in the target device at this time, the first memory image file is the initial data of the memory in the target device.

[0061] Step 203: Configure the target device's boot mode to flash boot mode and reset the target device to load the firmware file in the flash memory.

[0062] For example, the boot mode of the target device is used to indicate the location where the program is read when the target device is reset and restarted. It can include serial port boot mode, debug interface boot mode, and flash boot mode, etc. The flash boot mode is also known as the Flash boot mode. The serial port boot mode reads the boot program from the serial port, the debug interface boot mode reads the boot program from the debug interface, and the flash boot mode reads the boot program from the flash memory.

[0063] While ensuring uninterrupted power supply to the target device, configure its boot mode to flash memory boot mode, then reset the target device. The target device restarts and executes the normal boot process, loading the firmware file from the flash memory. The boot process includes: the ROM (Read-Only Memory) boot code reading the encrypted firmware from external Flash memory, using the hardware key to encrypt and decrypt the client's encryption key, then using the client's encryption key to decrypt the firmware body, and finally loading the decrypted firmware into DDR for execution. Wait for the firmware to boot completely and run stably; at this point, the DDR already contains the decrypted firmware file.

[0064] Step 204: After the target device is reset, obtain the second memory image file of the target device through the debugging interface.

[0065] After the target device is reset and running stably, the firmware file is included in the DDR, which is the memory. The second memory image file of the target device is obtained through the debugging interface. The memory address corresponding to the second memory image file is the same as the memory address corresponding to the first memory image file, that is, the memory data at the same location is obtained twice.

[0066] It is understandable that if the firmware file in Flash is loaded and the debug interface is closed, the steps in step 201 above can be repeated to reconfigure the debug interface to be open, and then the data of the target device can be read through the debug interface.

[0067] Step 205: Determine the contents of the firmware file based on the first memory image file and the second memory image file.

[0068] The first and second memory image files contain data corresponding to the same memory addresses. Since DDR data is retained even without power interruption, the data in the second memory image file that differs from the first memory image file represents the memory regions overwritten during firmware loading. By comparing the first and second memory image files, the content information of the firmware file is determined based on the comparison results.

[0069] In the above embodiments, firstly, a first program for opening the debug interface of the target device is loaded into the target device. After the debug interface is opened, a first memory image file of the target device is obtained through the debug interface. Then, the boot mode of the target device is configured to flash boot mode, and the target device is reset to load the firmware file in flash memory. After the target device is reset, a second memory image file of the target device is obtained through the debug interface. Finally, the contents of the firmware file are determined based on the first and second memory image files. This method, by opening the debug interface of the target device and obtaining the memory image file of the target device through the debug interface, thereby determining the contents of the firmware file, does not require any physical modification or damage to the chip of the target device during the firmware extraction process, and does not involve destructive operations, thus ensuring the integrity of the target device.

[0070] In the embodiments of this application, the loading of a first program onto a target device via a serial port is used for illustration, such as... Figure 3 As shown, it includes:

[0071] Step 301: Configure the target device's boot mode to serial port boot mode.

[0072] Before loading the first program onto the target device via the serial port, the target device's boot mode is configured to serial port boot mode. This allows the target device to boot from the serial port after loading the first program, read the program, and run it. The boot mode can be configured by setting the pin levels of the target device. For example, BOOTMODE[4:0] represents the five pins of the target device, and different pin levels correspond to different boot modes. The electronic device sets the BOOTMODE[4:0] pins to 00101 via a DIP switch, thus setting the target device's boot mode to serial port boot mode.

[0073] Step 302: Load the first program into the target device via a serial communication tool.

[0074] The first program is loaded onto the target device via a serial communication tool. After loading, a reset signal is output while keeping the target device powered on, so that the target device is reset without power interruption. The first program is then read and run. After the program is run, the JTAG debugging interface of the target device is opened by modifying the configuration file related to the JTAG debugging interface of the target device.

[0075] Then, the boot mode of the target device can be switched to the debug interface boot mode, that is, set BOOTMODE[4:0]=01111. At the same time, the target device is kept powered on throughout the process. In this case, the JTAG debug interface will remain open, so that data in the target device can be obtained through the JTAG debug interface later.

[0076] In embodiments of this application, the first memory image file of the target device is obtained through a debugging interface, such as... Figure 4 As shown, it includes:

[0077] Step 401: After the first program finishes running, configure the target device's startup mode to debug mode and perform a reset.

[0078] After the first program completes its execution, it configures the target device's JTAG debug interface to be enabled, maintains uninterrupted power supply to the DSP, and configures the target device's startup mode to debug interface startup mode via a DIP switch. The JTAG debug interface remains enabled, allowing subsequent data acquisition from the target device via the JTAG debug interface. Then, the target device is reset. Figure 5 As shown, the steps also include:

[0079] Step 501: After the target device is reset, load the second program into the target device through the debugging interface.

[0080] The second procedure sets the target storage space of the target device to a preset value. The target storage space is the memory address range read by the first or second memory image file, and can be the area where firmware files are loaded during the operation of the target device.

[0081] Since the initial data in the memory space of the target device may be random values, the comparison between the first memory image file and the second memory image file may not be able to determine whether the data is modified by the firmware file or the original initial data in the memory. Therefore, in order to facilitate quick identification of the firmware file, a second program can be loaded into the target device in advance. The second program sets the target storage space of the target device to a preset value, which can be 00 or FF. This application embodiment does not limit this.

[0082] For example, a debugging connection is established with the target device through the JTAG debugging interface, and a pre-compiled second program is loaded into the target device.

[0083] Step 502: After the second program runs on the target device, obtain the first memory image file through the debugging interface.

[0084] After the second program runs stably on the target device, the values ​​in the target storage space are all preset values. The data in the target storage space is then read using the electronic device's memory browsing function to obtain the first memory image file. The first memory image file records the contents of the target storage space after the second program has been executed.

[0085] Step 402: After the target device is reset, obtain the first memory image file through the debugging interface.

[0086] In the above embodiments, before obtaining the first memory image file, a second program is first loaded onto the target device to configure the target storage space of the target device to a preset value, and then the first memory image file is obtained, thereby avoiding interference from random data and facilitating comparison with the second memory image file to determine the firmware file.

[0087] In one embodiment, after the target device is reset, a second memory image file of the target device is obtained through a debug interface, such as... Figure 6 As shown, it includes:

[0088] Step 601: After the target device is reset, obtain the status of the debugging interface.

[0089] Since the firmware file may reconfigure the state of the target device's debug interface during operation, the debug interface state of the target device should be obtained after the target device loads the firmware file from Flash, resets, and starts up stably. If the debug interface is enabled, the second memory image file can be obtained directly through the debug interface.

[0090] Step 602: If the debugging interface is in the closed state, load the first program onto the target device.

[0091] If the debug interface is disabled, the steps to enable it described above need to be repeated. This involves configuring the target device's boot mode to serial boot mode while maintaining power to the target device, and loading the first program onto the target device via the serial port to enable the debug interface. Since the target device remains powered throughout the process, the data in memory will not be lost due to mode switching; both some data from the second program and the newly loaded firmware file data are retained.

[0092] Step 603: After the debug interface is opened, obtain the second memory image file through the debug interface.

[0093] After the debug interface is opened, the second memory image file is obtained by obtaining the memory data of the target storage space through the debug interface, just like the method described above for obtaining the first memory image file.

[0094] In the embodiments of this application, after obtaining the first memory image file before firmware file loading and the second memory image file after firmware file loading, the step of determining the content of the firmware file based on the first memory image file and the second memory image file is as follows: Figure 7 As shown, it may include:

[0095] Step 701: Compare the first memory image file and the second memory image file byte by byte to determine the differences.

[0096] Since data in memory, such as data in DDR memory, will not be lost without power interruption, after multiple boot processes, the first memory image data before the firmware file is loaded and the second memory image file after the file is estimated are recorded and compared. Based on the difference data, that is, the content updated when the firmware file is loaded, the firmware file is obtained.

[0097] Step 702: Determine the contents of the firmware file based on the difference data.

[0098] By comparing the first and second memory image files byte by byte, XOR operations can be used to quickly identify the differences and determine the discrepancies. Analyzing the address distribution, size, and content characteristics of this discrepancy data allows for the accurate extraction of complete firmware file information, including code and data segments.

[0099] In the embodiments of this application, a firmware extraction method is provided. For ease of understanding, the method is illustrated using a DSP chip as the target device. The hardware environment is an electronic device, specifically the development board of the target device, equipped with external DDR memory and SPI Flash. The software environment includes a DSP debugging and development environment, serial communication tools, a JTAG emulator, and corresponding drivers. The steps include:

[0100] (1) Generate the original .out executable file based on the firmware file being tested. Encrypt the firmware file using a preset encryption tool and a key to generate an encrypted .bin file, and burn it into the SPI Flash of the target device.

[0101] (2) Load the first program onto the target device, configure the target device to serial port boot mode, load the first program through a serial port tool, open the JTAG debugging interface of the target device, and after the program executes successfully, keep the power supply status of the target device unchanged and obtain the first memory image file. Optionally, the memory mapping diagram of the target device can be as follows: Figure 8 As shown, the address range of the target storage space can be determined based on the memory mapping diagram. Firmware data may reside in DDR, or it may be stored in the on-chip L1P / L1D cache (32KB each) or L2 unified cache (256KB) for execution. If stored in DDR, the memory address range of the target storage space is set as follows: the starting address is the DDR mapping start address (0xC0000000 in this embodiment), and the length depends on the actual DDR size (maximum 256MB, ending address 0xCFFFFFFF). If stored in L1 or L2 cache, the data in the L1 or L2 cache can also be exported using the memory browsing function of the debugging tool, thus enabling firmware extraction. In this case, the memory address range of the target storage space includes: L1P program cache: address range 0x00E00000-0x00E07FFF; L1D data cache: address range 0x00F00000-0x00F07FFF; L2 unified cache: address range 0x00800000-0x0083FFFF. Specifically, the range of the target storage space to be read can be configured according to the actual firmware storage location of the target device, and this application does not impose any restrictions on this.

[0102] (3) Without interrupting power to the target device, switch the boot mode to Flash boot mode and then trigger a reset of the target device. At this time, the target device executes the normal boot process, automatically decrypts the encrypted firmware in Flash and loads it into DDR memory.

[0103] (4) Switch the target device to serial port boot mode again and reload the first program to open the debug interface and read the data content in DDR through the debug interface to obtain the second memory image file.

[0104] (5) Compare the first memory image file and the second memory image file to obtain the contents of the firmware file. For example... Figure 9 and Figure 10 As shown, the contents of the firmware file obtained by the firmware extraction method are basically the same as the contents of the original .out file.

[0105] Because .out files are compiler-generated executable file formats containing metadata such as file headers and segment tables, the displayed addresses are internal offsets within the file. When firmware is loaded into DDR for execution, it is placed at the actual execution address specified by the linker script. This address is determined by the firmware's memory mapping configuration. During firmware loading, bootloader code or data structures may be added before the firmware code, causing an offset in the starting address of the actual code segment. The memory browsing function displays the physical address space of DDR, which has a mapping relationship with the internal offset address of the file, rather than a direct correspondence. Therefore, the comparison results may have a certain address offset. In applications, the correct address mapping relationship can be determined by analyzing the firmware's entry point address and segment information.

[0106] In embodiments of this application, a firmware advance method is provided, such as... Figure 11 As shown, it includes:

[0107] Step 1101: Configure the target device's boot mode to serial port boot mode.

[0108] Step 1102: Load the first program into the target device via a serial communication tool.

[0109] Step 1103: After the first program finishes running, configure the target device's startup mode to debug mode and perform a reset.

[0110] Step 1104: After the target device is reset, load the second program into the target device through the debugging interface.

[0111] Step 1105: After the second program runs on the target device, obtain the first memory image file through the debugging interface.

[0112] Step 1106: Configure the target device's boot mode to flash boot mode and reset the target device to load the firmware file in the flash memory.

[0113] Step 1107: After the target device is reset, obtain the status of the debugging interface.

[0114] Step 1108: If the debugging interface is in the closed state, load the first program onto the target device.

[0115] Step 1109: After the debug interface is opened, obtain the second memory image file through the debug interface.

[0116] Step 1110: Determine the contents of the firmware file based on the first memory image file and the second memory image file.

[0117] In the above embodiments, the firmware file of the target device can be obtained by configuring the state of the target device's JTAG debugging interface. This method is easy to implement, requires no complex dedicated equipment such as high-bandwidth oscilloscopes or laser devices, has a high success rate, and is low in cost. Furthermore, this method is independent of specific firmware content, encryption keys, or application scenarios, and is applicable to all devices based on this architecture, demonstrating strong versatility.

[0118] Furthermore, this application provides a practical and efficient technical means for device security assessment, with dual application value: first, in security assessment applications, it extracts firmware files to detect potential security vulnerabilities, weaknesses, or malicious code in devices, assesses the device's resistance to attacks, and guides improvements to security protection measures; second, in compliance audit applications, it extracts and analyzes firmware to obtain its technical information, including key information such as communication protocols, control algorithms, and system architecture, providing technical support for third-party device security certification and compliance checks. Ensuring the information security of electronic devices and improving device trustworthiness is of significant practical importance. This application is applicable to the following application scenarios: product security assessment, supply chain security review, interoperability research, and security protection strategy development.

[0119] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0120] Based on the same inventive concept, this application also provides a firmware extraction apparatus for implementing the firmware extraction method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more firmware extraction apparatus embodiments provided below can be found in the limitations of the firmware extraction method described above, and will not be repeated here.

[0121] In one exemplary embodiment, such as Figure 12 As shown, a firmware extraction device 1200 is provided, comprising: a loading module, a first acquisition module, a configuration module, a second acquisition module, and a determination module, wherein:

[0122] The loading module is used to load the first program onto the target device; the first program is used to open the debug interface of the target device.

[0123] The first acquisition module is used to acquire the first memory image file of the target device through the debugging interface after the debugging interface is opened;

[0124] The configuration module is used to configure the boot mode of the target device to flash boot mode and to reset the target device so that the target device loads the firmware file in flash memory;

[0125] The second acquisition module is used to acquire the second memory image file of the target device through the debugging interface after the target device is reset;

[0126] The determination module is used to determine the contents of the firmware file based on the first memory image file and the second memory image file.

[0127] In one embodiment, the loading module is specifically used to configure the target device's boot mode as a serial port boot mode; and to load the first program to the target device via a serial communication tool.

[0128] In one embodiment, the first acquisition module is specifically used to configure the startup mode of the target device to debug mode and perform a reset process after the first program finishes running; after the target device is reset, it acquires the first memory image file through the debug interface.

[0129] In one embodiment, the first acquisition module is specifically used to load a second program onto the target device through a debugging interface after the target device is reset; the second program is used to set the target storage space of the target device to a preset value; after the target device runs the second program, the first memory image file is acquired through the debugging interface.

[0130] In one embodiment, the second acquisition module is specifically used to acquire the status of the debug interface after the target device is reset; if the debug interface is closed, load the first program into the target device; and acquire the second memory image file through the debug interface after the debug interface is opened.

[0131] In one embodiment, the determining module is specifically used to compare the first memory image file and the second memory image file byte by byte to determine the difference data; and to determine the content of the firmware file based on the difference data.

[0132] Each module in the aforementioned firmware extraction device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.

[0133] In one exemplary embodiment, an electronic device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 13 As shown, this electronic device includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interface. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface is used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a firmware extraction method. The display unit is used to form a visually visible image and can be a display screen, projection device, or virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the electronic device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the electronic device, or external keyboards, touchpads, or mice, etc.

[0134] Those skilled in the art will understand that Figure 13 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the electronic device to which the present application is applied. The specific electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0135] In an exemplary embodiment, an electronic device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps: loading a first program onto a target device; the first program is used to open a debug interface of the target device; after the debug interface is opened, a first memory image file of the target device is obtained through the debug interface; configuring the boot mode of the target device to flash boot mode, and resetting the target device to load a firmware file in flash memory; after the target device is reset, a second memory image file of the target device is obtained through the debug interface; and the contents of the firmware file are determined based on the first memory image file and the second memory image file.

[0136] In one embodiment, when the processor executes the computer program, it further performs the following steps: configuring the boot mode of the target device to serial port boot mode; and loading the first program into the target device via a serial port communication tool.

[0137] In one embodiment, when the processor executes the computer program, it further performs the following steps: after the first program finishes running, it configures the boot mode of the target device to debug mode and performs a reset process; after the target device is reset, it obtains the first memory image file through the debug interface.

[0138] In one embodiment, when the processor executes the computer program, it further performs the following steps: after the target device is reset, a second program is loaded onto the target device through a debug interface; the second program is used to set the target storage space of the target device to a preset value; after the target device runs the second program, a first memory image file is obtained through the debug interface.

[0139] In one embodiment, when the processor executes the computer program, it further performs the following steps: after the target device is reset, it obtains the status of the debug interface; if the debug interface is closed, it loads the first program into the target device; and after the debug interface is opened, it obtains the second memory image file through the debug interface.

[0140] In one embodiment, when the processor executes the computer program, it further performs the following steps: comparing the first memory image file and the second memory image file byte by byte to determine the difference data; and determining the content of the firmware file based on the difference data.

[0141] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it performs the following steps: loading a first program onto a target device; the first program is used to open a debug interface of the target device; after the debug interface is opened, obtaining a first memory image file of the target device through the debug interface; configuring the boot mode of the target device to flash boot mode, and resetting the target device to load a firmware file in flash memory; after the target device is reset, obtaining a second memory image file of the target device through the debug interface; and determining the contents of the firmware file based on the first memory image file and the second memory image file.

[0142] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: configuring the boot mode of the target device to serial port boot mode; and loading the first program into the target device via a serial port communication tool.

[0143] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: after the first program finishes running, the boot mode of the target device is configured to debug mode and a reset process is performed; after the target device is reset, the first memory image file is obtained through the debug interface.

[0144] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: after the target device is reset, a second program is loaded onto the target device through a debugging interface; the second program is used to set the target storage space of the target device to a preset value; after the target device runs the second program, a first memory image file is obtained through the debugging interface.

[0145] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: after the target device is reset, it obtains the status of the debug interface; if the debug interface is closed, it loads the first program into the target device; and after the debug interface is opened, it obtains the second memory image file through the debug interface.

[0146] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: comparing the first memory image file and the second memory image file byte by byte to determine the difference data; and determining the content of the firmware file based on the difference data.

[0147] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps: loading a first program onto a target device; the first program being used to open a debug interface of the target device; after the debug interface is opened, obtaining a first memory image file of the target device through the debug interface; configuring the boot mode of the target device to flash boot mode, and resetting the target device to load a firmware file from flash memory; after the target device is reset, obtaining a second memory image file of the target device through the debug interface; and determining the contents of the firmware file based on the first memory image file and the second memory image file.

[0148] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: configuring the boot mode of the target device to serial port boot mode; and loading the first program into the target device via a serial port communication tool.

[0149] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: after the first program finishes running, the boot mode of the target device is configured to debug mode and a reset process is performed; after the target device is reset, the first memory image file is obtained through the debug interface.

[0150] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: after the target device is reset, a second program is loaded onto the target device through a debugging interface; the second program is used to set the target storage space of the target device to a preset value; after the target device runs the second program, a first memory image file is obtained through the debugging interface.

[0151] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: after the target device is reset, it obtains the status of the debug interface; if the debug interface is closed, it loads the first program into the target device; and after the debug interface is opened, it obtains the second memory image file through the debug interface.

[0152] In one embodiment, when the computer program is executed by the processor, it further performs the following steps: comparing the first memory image file and the second memory image file byte by byte to determine the difference data; and determining the content of the firmware file based on the difference data.

[0153] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0154] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0155] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0156] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A firmware extraction method, characterized in that, The method includes: Load a first program onto the target device; the first program is used to open the debugging interface of the target device. After the debugging interface is opened, the first memory image file of the target device is obtained through the debugging interface; Configure the boot mode of the target device to flash boot mode, and reset the target device to load the firmware file in the flash memory; After the target device is reset, the second memory image file of the target device is obtained through the debugging interface; The contents of the firmware file are determined based on the first memory image file and the second memory image file.

2. The method according to claim 1, characterized in that, Loading the first program onto the target device includes: Configure the target device to boot in serial port mode; The first program is loaded into the target device using a serial communication tool.

3. The method according to claim 1, characterized in that, The step of obtaining the first memory image file of the target device through the debugging interface includes: After the first program finishes running, the target device is configured to start in debug mode and a reset is performed. After the target device is reset, the first memory image file is obtained through the debugging interface.

4. The method according to claim 3, characterized in that, After the target device is reset, obtaining the first memory image file of the target device through the debugging interface includes: After the target device is reset, a second program is loaded onto the target device through the debugging interface; the second program is used to set the target storage space of the target device to a preset value. After the target device runs the second program, the first memory image file is obtained through the debugging interface.

5. The method according to claim 1, characterized in that, After the target device is reset, obtaining the second memory image file of the target device through the debugging interface includes: After the target device is reset, the status of the debugging interface is obtained; If the debugging interface is in a closed state, load the first program onto the target device; After the debugging interface is opened, the second memory image file is obtained through the debugging interface.

6. The method according to claim 1, characterized in that, The step of determining the content of the firmware file based on the first memory image file and the second memory image file includes: The first memory image file and the second memory image file are compared byte by byte to determine the differences. The contents of the firmware file are determined based on the difference data.

7. A firmware extraction device, characterized in that, The device includes: A loading module is used to load a first program onto a target device; the first program is used to open the debugging interface of the target device. The first acquisition module is used to acquire the first memory image file of the target device through the debugging interface after the debugging interface is opened; The configuration module is used to configure the boot mode of the target device to flash boot mode and to reset the target device so that the target device loads the firmware file in flash memory; The second acquisition module is used to acquire the second memory image file of the target device through the debugging interface after the target device is reset. The determining module is used to determine the contents of the firmware file based on the first memory image file and the second memory image file.

8. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.