A method for preventing MCU firmware copying based on SPI Flash parameter locking

CN122674031APending Publication Date: 2026-09-01古桥信息科技(郑州)有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610803896.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-05
Publication Date
2026-09-01

AI Technical Summary

Technical Problem

其中,内部读保护机制虽然能够在一定程度上防止通过调试接口直接读取程序,但其安全性依赖于芯片本身的防护等级,一旦被破解或通过物理手段绕过,则无法有效阻止固件泄露;采用独立加密芯片或安全元件虽然能够提升安全性,但会显著增加硬件成本及系统复杂度,不利于成本敏感型产品的推广应用;而单纯的软件加密方案往往缺乏与硬件特征的绑定,容易被整体复制或通过逆向分析恢复加密逻辑,从而降低防护效果

Benefits of technology

本发明通过将防护参数存储于外接SPI Flash的加密保护区,并结合微控制器内部唯一标识信息参与动态参数计算,实现了固件与具体设备之间的一一绑定关系。即使攻击者获取了某一设备中的固件数据,由于缺乏对应设备的唯一标识信息及防护参数,也无法在其他设备上正常还原和运行,从而有效防止固件被复制和跨设备使用,显著提升了系统的防复制能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122674031A_ABST
    Figure CN122674031A_ABST
Patent Text Reader

Abstract

This invention discloses a method for preventing firmware copying in microcontrollers based on SPI Flash parameter locking. This method is applied to microcontroller systems with internal Flash and external SPI Flash. It involves pre-storing protection parameter data in the SPI Flash and locking it with write protection. Simultaneously, it incorporates the microcontroller's unique identifier information into dynamic parameter calculation, encrypting the firmware and storing it in the internal Flash. Upon system power-up, the bootloader executes first, reading the protection parameters from the SPI Flash and generating dynamic parameters using the unique identifier information. This decrypts and restores the encrypted firmware, and a hardware CRC module performs integrity verification on the decrypted firmware. If the verification result is correct, the application program runs; otherwise, a locking mechanism is triggered to prevent system operation. This method eliminates the need for additional hardware encryption modules, utilizing existing storage resources to achieve firmware-device binding and anti-copying protection. It offers advantages such as low cost, high security, simple implementation, and wide applicability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of embedded system security technology, and more specifically, to a method for preventing MCU firmware copying based on SPI Flash parameter locking. Background Technology

[0002] With the widespread application of embedded systems in industrial control, IoT terminals, smart sensors, and consumer electronics, the security of device firmware, as the core carrier for functional control and logic processing, is becoming increasingly prominent. Especially in mass production and large-scale deployment scenarios, firmware is often burned with a uniform version. Once illegally read or copied, it can easily lead to product counterfeiting, functional tampering, and even intellectual property disputes and security risks. Therefore, how to achieve reliable firmware anti-copying and anti-tampering while ensuring controllable system costs has become one of the key issues in embedded system design.

[0003] In existing technologies, common firmware protection methods mainly include enabling internal read protection mechanisms in the microcontroller, using encryption chips or secure storage modules, and encrypting the firmware through software algorithms. While internal read protection mechanisms can prevent direct program reading via debug interfaces to some extent, their security depends on the chip's own protection level. Once cracked or bypassed by physical means, they cannot effectively prevent firmware leakage. Using independent encryption chips or secure elements can improve security, but it significantly increases hardware costs and system complexity, hindering the widespread application of cost-sensitive products. Simple software encryption schemes often lack binding to hardware features, making them easy to copy entirely or recover the encryption logic through reverse engineering, thus reducing their protective effectiveness.

[0004] Furthermore, a prominent problem with existing technologies is the lack of effective linkage between firmware protection mechanisms and individual devices. Most solutions only perform uniform encryption on the firmware itself, without combining it with the unique identification information of each device for differentiated protection. This allows the same firmware to run universally across different devices, making it difficult to achieve true "device-level binding." Simultaneously, some solutions lack a complete verification mechanism during system startup, failing to jointly verify firmware integrity and parameter consistency. If critical parameters are tampered with or the firmware is replaced, the system may still continue to operate, posing a security risk.

[0005] Therefore, there is an urgent need for a firmware anti-copying method that can make full use of existing storage resources without increasing additional hardware costs, and can combine protection parameter locking, device unique identifier binding, and boot-stage integrity verification to improve the overall security and reliability of embedded systems.

[0006] Therefore, there is an urgent need to design a method for preventing MCU firmware copying based on SPI Flash parameter locking to solve the above problems. Summary of the Invention

[0007] The purpose of this invention is to solve the technical problems mentioned in the background section and to provide a method for preventing MCU firmware copying based on SPIFlash parameter locking.

[0008] The objective of this invention is achieved through the following technical solution: a method for preventing MCU firmware copying based on SPI Flash parameter locking, comprising the following steps: In a microcontroller system with internal Flash and external SPI Flash, protection parameter data is pre-stored in the SPI Flash, and the firmware is dynamically encrypted based on the protection parameter data and the microcontroller's unique identification information. After the system is powered on, the Bootloader module takes priority in execution, reads the protection parameter data through the SPI interface, performs dynamic parameter calculations in combination with the microcontroller's unique identification information, and decrypts and restores the encrypted firmware stored in the internal Flash. After the firmware is decrypted, the integrity of the restored firmware is verified by the hardware CRC module, and the verification result is compared with the verification base value pre-stored in the SPI Flash. If the verification result matches, the process jumps to the application execution; otherwise, a locking mechanism is triggered to prevent the system from continuing to run, thereby achieving firmware anti-copy protection.

[0009] As a preferred technical solution of the present invention, the protection parameter data includes at least three calculation factors A, B, and C and corresponding CRC32 check values. The protection parameter data is stored in the encryption protection zone of the SPI Flash and is write-protected and locked through the SPI Flash status register.

[0010] As a preferred technical solution of the present invention, the unique identification information of the microcontroller is the unique UID data inside the MCU, and its low-order byte is read from a fixed address as the input for dynamic parameter calculation.

[0011] As a preferred technical solution of the present invention, the dynamic parameter is calculated by combining the calculation factors A, B, and C with the low-order data of the UID, and taking the modulus of the calculation result to obtain the dynamic parameter M. The M is used to control the offset and transformation rules in the firmware encryption and decryption process.

[0012] As a preferred technical solution of the present invention, the firmware encryption process includes: performing cyclic shift and bit-inverting operations on the M bytes of data after the firmware start address to form encrypted firmware data, and writing the encrypted firmware into a designated area of ​​the microcontroller's internal Flash memory.

[0013] As a preferred technical solution of the present invention, the Bootloader execution process includes: Initialize the SPI interface and hardware CRC module; Read protection parameter data from SPI Flash; When the number of consecutive read failures reaches a set number or a data verification error occurs, the internal Flash is erased and the device enters a locked state.

[0014] As a preferred technical solution of the present invention, the firmware decryption process includes: performing bit-inverting and cyclic shifting inverse operations on the encrypted firmware based on the recalculated dynamic parameter M to restore the original firmware data, and storing the decryption result in a temporary verification area.

[0015] As a preferred technical solution of the present invention, the integrity verification calculates the CRC32 value of the decrypted firmware through a hardware CRC module and compares it with the CRC32 baseline value pre-stored in the SPI Flash to determine whether the firmware has been tampered with.

[0016] As a preferred technical solution of the present invention, the locking mechanism includes: when abnormal protection parameters, illegal dynamic parameter calculation results or CRC verification failure are detected, an internal Flash erase operation is performed and a low-power lock state is entered, thereby preventing the illegal firmware from running.

[0017] As a preferred technical solution of the present invention, the SPI Flash is connected to the microcontroller through the SPI interface. The SPI Flash is used to store protection parameters, user data and firmware upgrades, and is divided into an encrypted protection area and a data storage area, wherein the encrypted protection area is in a read-only locked state.

[0018] Compared with the prior art, the present invention has the following beneficial effects: This invention achieves a one-to-one binding relationship between firmware and specific devices by storing protection parameters in an encrypted protected area of ​​an external SPI Flash and combining this with the unique identifier information inside the microcontroller for dynamic parameter calculation. Even if an attacker obtains firmware data from a device, the lack of the corresponding device's unique identifier information and protection parameters prevents normal restoration and operation on other devices, thus effectively preventing firmware from being copied and used across devices and significantly improving the system's anti-copying capability.

[0019] This invention features a closed-loop process during system startup where the bootloader handles parameter reading, dynamic parameter calculation, firmware decryption, and integrity verification. A hardware CRC module performs rapid verification of the decrypted firmware. If any abnormal parameters or firmware tampering are detected, a locking mechanism is triggered, preventing further system operation. This mechanism enables security verification before application execution, effectively preventing unauthorized firmware from entering the runtime phase, thereby improving system security and reliability.

[0020] This invention eliminates the need for additional encryption chips or security modules, achieving firmware copy protection solely through existing SPI Flash resources and microcontroller internal hardware resources. It boasts advantages such as simplicity, low cost, and ease of integration. Furthermore, this method exhibits low hardware platform dependence, is compatible with various general-purpose MCUs equipped with SPI interfaces and unique identification information, and possesses excellent versatility and scalability, making it suitable for widespread application in industrial control, IoT devices, and consumer electronics. Attached Figure Description

[0021] Figure 1 The principle of this invention Figure 1 ; Figure 2 The principle of this invention Figure 2 . Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of this invention clearer, the following description is provided in conjunction with embodiments and appendices. Figures 1-2 The present invention will be further described in detail below. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0023] This invention provides a method for preventing MCU firmware copying based on SPI Flash parameter locking, applicable to embedded systems with internal Flash and external SPI Flash. In one specific embodiment, the system uses a GD32F303RET6 as the core control unit and an external W25Q64 as the parameter and extended storage medium. The two are connected via a standard SPI interface, with interface signals including chip select, clock, data input, and data output signals. Pull-up resistors and decoupling capacitors ensure communication stability and power supply reliability. The microcontroller's internal Flash is divided into a Bootloader area, an application area, and a temporary verification area. The Bootloader area is used for firmware decryption and verification process control, the application area stores the encrypted firmware, and the temporary verification area stores the decrypted firmware data for integrity verification. The W25Q64 is divided into an encrypted protection area and a normal data area. The encrypted protection area stores protection parameter data, including calculation factors A, B, and C and their corresponding CRC32 checksums. This area is write-protected and locked by the SPI Flash status register to prevent unauthorized tampering.

[0024] During the production or firmware burning stage, the original firmware to be burned is first preprocessed on the PC. Calculation factors A, B, and C, as well as the range of dynamic parameters, are pre-set, and the low-order bits of the microcontroller's unique identifier information are read from the target device as input values ​​for the calculations. The calculation factors and the unique identifier information are combined to obtain the dynamic parameter M used to control the encryption process. Based on the dynamic parameter, a specified length of data after the starting address of the original firmware is bitwise inverted and cyclically shifted to generate encrypted firmware. The encrypted firmware is then written to the application area of ​​the microcontroller's internal Flash memory. Simultaneously, the calculation factors A, B, and C, and the corresponding CRC32 checksum of the firmware are written to the encryption protection area of ​​the W25Q64. Finally, a write protection bit is set through the status register of the SPI Flash, making this area in an ineradicable and writable state, thus completing parameter locking.

[0025] When the device powers on, the system first enters the Bootloader execution phase. The Bootloader performs basic system initialization, including SPI interface configuration, clock initialization, and hardware CRC module initialization, and sets internal Flash access permissions. It then accesses the W25Q64's encrypted protection zone via the SPI interface, reads protection parameter data, and performs validity checks on the read process. If multiple consecutive read failures or abnormal data are detected, the system determines it to be in an abnormal state, performs an internal Flash erase operation, and enters a locked state, preventing subsequent program execution and thus preventing the execution of unauthorized firmware.

[0026] After successful parameter reading, the Bootloader reads the low-order bits of the unique identifier from the microcontroller's internal registers and combines them with the calculation factor in the protection parameters to regenerate the dynamic parameter M. If the calculation result exceeds the preset range or is an illegal value, the locking mechanism is also triggered. Subsequently, the system performs reverse processing on the encrypted firmware stored in the application area according to the dynamic parameter, that is, performs the inverse operation of bit-by-bit inversion and cyclic shift on the corresponding data, and writes the decrypted firmware data into the temporary verification area.

[0027] After firmware decryption, the system calls the hardware CRC module to perform integrity verification on the firmware data in the temporary verification area and compares the calculated CRC32 value with the verification baseline value stored in the W25Q64 encrypted protection area. When they match, it indicates that the firmware has not been tampered with and the device is correctly matched, and the bootloader jumps to the application area to execute the user program; when they do not match, the system determines that it is an illegal copy or data corruption, performs internal Flash erasure, and enters a low-power lockout state to prevent the system from being used illegally.

[0028] In practical applications, because the encryption process relies on the unique identification information of each device, even if different devices have identical firmware, their encryption results will differ. This enables device-level binding, effectively preventing firmware from being copied and run on other devices. Simultaneously, the protection parameters are stored in external SPI Flash and locked by hardware, increasing the difficulty for attackers to obtain critical parameters. Furthermore, the complete parameter reading, dynamic calculation, firmware decryption, and CRC verification process is completed during the Bootloader stage, enabling the system to perform security verification before application execution, further enhancing overall protection capabilities.

[0029] This implementation method does not require the addition of an extra encryption chip and can achieve firmware anti-copy protection using only existing SPI Flash resources. It features low cost, simple implementation, and strong adaptability, and can be widely used in scenarios with high firmware security requirements, such as industrial control equipment, intelligent sensing terminals, IoT devices, and consumer electronics products.

[0030] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments, but the present invention is not limited to these embodiments. Equivalent modifications made by those skilled in the art without departing from the principles of the present invention should fall within the protection scope of the present invention.

[0031] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for preventing MCU firmware copying based on SPI Flash parameter locking, characterized in that, Includes the following steps: In a microcontroller system with internal Flash and external SPI Flash, protection parameter data is pre-stored in the SPI Flash, and the firmware is dynamically encrypted based on the protection parameter data and the microcontroller's unique identification information. After the system is powered on, the Bootloader module takes priority in execution, reads the protection parameter data through the SPI interface, performs dynamic parameter calculations in combination with the microcontroller's unique identification information, and decrypts and restores the encrypted firmware stored in the internal Flash. After the firmware is decrypted, the integrity of the restored firmware is verified by the hardware CRC module, and the verification result is compared with the verification base value pre-stored in the SPI Flash. If the verification result matches, the process jumps to the application execution; otherwise, a locking mechanism is triggered to prevent the system from continuing to run, thereby achieving firmware anti-copy protection.

2. The method according to claim 1, characterized in that: The protection parameter data includes at least three calculation factors A, B, and C and their corresponding CRC32 check values. The protection parameter data is stored in the encrypted protection zone of the SPI Flash and is write-protected and locked through the SPI Flash status register.

3. The method according to claim 1, characterized in that: The unique identifier of the microcontroller is the unique UID data inside the MCU, and its low-order byte is read from a fixed address as the input for dynamic parameter calculation.

4. The method according to claim 1 or 3, characterized in that: The dynamic parameter is calculated by combining the calculation factors A, B, and C with the low-order data of the UID, and taking the modulo of the calculation result to obtain the dynamic parameter M. M is used to control the offset and transformation rules in the firmware encryption and decryption process.

5. The method according to claim 1, characterized in that: The firmware encryption process includes: performing cyclic shift and bit-inverting operations on the M bytes of data after the firmware start address to form encrypted firmware data, and writing the encrypted firmware into a designated area of ​​the microcontroller's internal Flash memory.

6. The method according to claim 1, characterized in that: The Bootloader execution process includes: Initialize the SPI interface and hardware CRC module; Read protection parameter data from SPI Flash; When the number of consecutive read failures reaches a set number or a data verification error occurs, the internal Flash is erased and the device enters a locked state.

7. The method according to claim 1, characterized in that: The firmware decryption process includes: performing bit-inverting and cyclic shifting operations on the encrypted firmware based on the recalculated dynamic parameter M to recover the original firmware data, and storing the decryption result in a temporary verification area.

8. The method according to claim 1, characterized in that: The integrity verification calculates the CRC32 value of the decrypted firmware using a hardware CRC module and compares it with the CRC32 baseline value pre-stored in the SPI Flash to determine whether the firmware has been tampered with.

9. The method according to claim 1, characterized in that: The locking mechanism includes: when abnormal protection parameters, illegal dynamic parameter calculation results, or CRC check failure are detected, an internal Flash erase operation is performed and a low-power lock state is entered, thereby preventing the operation of illegal firmware.

10. The method according to claim 1, characterized in that: The SPI Flash is connected to the microcontroller via the SPI interface. The SPI Flash is used to store protection parameters, user data, and firmware upgrades. It is divided into an encrypted protection area and a data storage area, with the encrypted protection area in a read-only locked state.