A method, system, apparatus and storage medium for OTA package signing
Patent Information
- Application Number
- CN202510283677.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2026-09-18
AI Technical Summary
[0003]然而,这种技术的主要问题是安全性较低
[0040] After obtaining the OTA packet to be signed, the data segment within the OTA packet is identified. Since the private key used for signing is stored only in the encryption machine, the encryption machine interface is called. The encryption machine uses the private key to sign the data segment, generating a signature value. Then, based on the public key certificate and the signature value, a standard signature structure is constructed. Finally, the standard signature structure is embedded into the comment segment to form the signed OTA packet. In this way, because the encryption machine is a device with extremely high physical protection capabilities, storing the private key in the encryption machine effectively reduces the possibility of private key theft, and implementing the signing through calling the encryption machine interface improves the security of the OAT packet signing.
Smart Images

Figure CN122783243A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data encryption, and in particular to a method, system, apparatus and storage medium for signing OTA packets. Background Technology
[0002] With the rapid development of the internet and smart devices, OTA (Over-the-Air) technology has become the mainstream method for device firmware upgrades. Through OTA technology, device manufacturers can remotely push firmware updates to devices to fix vulnerabilities, optimize performance, or add new features.
[0003] However, the main problem with this technology is its low security. Specifically, the private key used for signing is stored in the host file system, making it vulnerable to software-level attacks and lacking the ability to prevent tampering and copying, thus making the private key easy to steal. If the private key is illegally obtained, it can be maliciously signed into the OTA package and then updated into the user's system, thereby replacing the original legitimate version, resulting in low security for OTA package signing. Summary of the Invention
[0004] To address the aforementioned technical problems, this application provides a method, system, apparatus, and storage medium for signing OTA packages, thereby improving the security of OTA package signing.
[0005] The technical solution provided in this application is described below:
[0006] The first aspect of this application provides a method for signing OTA packets, including:
[0007] Obtain the OTA package to be signed, the OTA package including a data segment and a comment segment;
[0008] The encryption machine interface is invoked, and the data segment is signed using the private key through the encryption machine to generate a signature value. The private key is stored in the encryption machine.
[0009] Construct a standard signature structure based on the public key certificate and the signature value;
[0010] The standard signature structure is embedded into the comment segment, and the comment length of the OTA package is updated to form the signed OTA package.
[0011] Optionally, the step of signing the data segment using the private key via the encryption machine to generate a signature value includes:
[0012] The encryption machine performs a hash calculation on the data segment to generate a hash value.
[0013] The encryption machine uses a private key to perform an RSA or ECC signature on the hash value, generating a signature value.
[0014] Optionally, before invoking the encryption machine interface, the method further includes:
[0015] Perform a hash calculation on the data segment to generate a hash value;
[0016] The step of signing the data segment using the private key via the encryption machine to generate a signature value includes:
[0017] The encryption machine uses a private key to perform an RSA or ECC signature on the hash value, generating a signature value.
[0018] Optionally, the method further includes:
[0019] When establishing a connection with multiple target devices, determine the network status of each target device;
[0020] Set the priority of each target device based on its network status.
[0021] Optionally, the method further includes:
[0022] The signed OTA packet is fragmented to obtain several signed OTA packets;
[0023] When the target device is of high priority, send the complete signed OTA packet to the target device;
[0024] When the target device is of low priority, the signed OTA packets are sent to the target device one by one.
[0025] Optionally, the method further includes:
[0026] When the target device changes from low priority to high priority, it is determined whether the number of fragmented OTA packets sent to the target device exceeds the threshold. If not, fragmented transmission is stopped, and a complete signed OAT packet is sent to the target device.
[0027] Optionally, the OTA package further includes a comment length field, wherein the comment length for updating the OTA package includes:
[0028] Update the comment length field.
[0029] A second aspect of this application provides a system for signing OTA packages, the system comprising:
[0030] An acquisition unit is used to acquire an OTA package to be signed, wherein the OTA package includes a data segment and an annotation segment;
[0031] The calling unit is used to call the encryption machine interface, and use the encryption machine to sign the data segment with a private key to generate a signature value. The private key is stored in the encryption machine.
[0032] A construction unit is used to construct a standard signature structure based on the public key certificate and the signature value;
[0033] An embedding unit is used to embed the standard signature structure into the comment segment and update the comment length of the OTA package to form a signed OTA package.
[0034] A third aspect of this application provides an apparatus for signing OTA packages, the apparatus comprising:
[0035] Processor, memory, input / output units, and bus;
[0036] The processor is connected to the memory, the input / output unit, and the bus;
[0037] The memory stores a program that the processor invokes to perform the first aspect and any optional method of signing the OTA package.
[0038] A fourth aspect of this application provides a computer-readable storage medium storing a program that, when executed on a computer, performs the OTA package signing method as described in the first aspect and any one of the first aspects.
[0039] As can be seen from the above technical solutions, this application has the following advantages:
[0040] After obtaining the OTA packet to be signed, the data segment within the OTA packet is identified. Since the private key used for signing is stored only in the encryption machine, the encryption machine interface is called. The encryption machine uses the private key to sign the data segment, generating a signature value. Then, based on the public key certificate and the signature value, a standard signature structure is constructed. Finally, the standard signature structure is embedded into the comment segment to form the signed OTA packet. In this way, because the encryption machine is a device with extremely high physical protection capabilities, storing the private key in the encryption machine effectively reduces the possibility of private key theft, and implementing the signing through calling the encryption machine interface improves the security of the OAT packet signing. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0042] Figure 1 An embodiment of the method for signing OTA packets provided in this application;
[0043] Figure 2 An embodiment of signing a data segment by calling the encryption machine interface provided in this application;
[0044] Figure 3 An embodiment of sending a signed OTA packet to a target device, provided for the purposes of this application;
[0045] Figure 4 An embodiment of a system for signing OTA packages provided in this application;
[0046] Figure 5 An embodiment of the apparatus for signing OTA packages provided in this application. Detailed Implementation
[0047] It should be noted that the method, system, apparatus and storage medium for signing OTA packages provided in this application are used to improve the security of OTA package signing.
[0048] It should be noted that the OTA package signing method provided in this application can be applied to terminals, systems, and servers. For example, the terminal can be a smartphone, computer, tablet, portable computer, or a desktop computer or other fixed terminal.
[0049] It should also be noted that the terms "first," "second," etc., in the specification and drawings are used to distinguish similar objects and are not necessarily used to describe a specific order, sequence, or importance. For ease of explanation, this application uses a server as the executing entity for illustrative purposes.
[0050] See Figure 1 As shown, Figure 1 An embodiment of the method for signing OTA packets provided in this application includes:
[0051] S101. Obtain the OTA package to be signed. The OTA package includes a data segment and a comment segment.
[0052] When device manufacturers need to update the operating system or applications of terminal devices, they typically use Over-The-Air (OTA) updates. To ensure the integrity and security of the update package, it must be signed before being sent. An OTA package is a file format used for remote updates, containing update data for the device firmware or software. OTA packages are generally divided into two parts: a data segment and a comment segment. The data segment contains the actual update data, such as firmware code and configuration files. The comment segment stores additional information, such as version number, description information, and signature information.
[0053] In this application, the OTA packet to be signed is first obtained from a storage device or network server. Then, the structure of the OTA packet is parsed to clearly distinguish between the data segment and the comment segment. The data segment contains the core content that needs to be signed, while the comment segment is used to store the information after signing.
[0054] S102. Call the encryption machine interface, use the encryption machine to sign the data segment with the private key, generate a signature value, and store the private key in the encryption machine;
[0055] After obtaining the OTA package to be signed, this application does not directly sign the data segment of the OTA package with a private key. Instead, it calls the API interface of the encryption machine, passing the data segment as input. The encryption machine uses its internally stored private key to perform a hash calculation on the data segment and encrypts the hash value to generate a signature value. In this application's scheme, the unique private key used for signing is stored only in the encryption machine. Because the encryption machine is a highly secure hardware device that effectively prevents unauthorized access, it is designed to be tamper-resistant. Any attempt to crack its internal data will trigger a data self-destruction mechanism, ensuring the security of the private key.
[0056] In some alternative embodiments, the encryption machine signs the data segment using its internally stored private key in a manner that includes RSA or ECC signing. The encryption machine hashes the data segment to generate a unique hash value, which serves as a digest of the data segment, ensuring data integrity. If the RSA algorithm is used, the encryption machine encrypts the hash value using its RSA private key to generate a signature value; if the ECC algorithm is used, the encryption machine signs the hash value using its ECC private key to generate a signature value.
[0057] S103. Construct a standard signature structure based on the public key certificate and the signature value;
[0058] To verify the legitimacy of the aforementioned signature, this application obtains the public key certificate corresponding to the private key before constructing the standard signature structure, and then constructs the standard signature structure by combining the obtained signature value. A standard signature structure is a signature data structure that conforms to specific specifications (such as PKCS#7, CMS, etc.), and this application does not limit the specific form of the standard signature structure.
[0059] S104. Embed the standard signature structure into the comment section and update the comment length of the OTA package to form the signed OTA package.
[0060] After constructing the standard signature structure, it is necessary to embed the standard signature structure into the comment section of the OTA packet and update the length field of the comment section to reflect the new length after embedding the signature structure. At this time, the OTA packet contains the signed data section and the updated comment section.
[0061] Optionally, if the OTA package also includes a comment length field, then update the comment length field.
[0062] In this embodiment, after obtaining the OTA packet to be signed, the data segment within the OTA packet is determined. Since the private key used for signing is only stored in the encryption machine, the encryption machine interface is called. The encryption machine uses the private key to sign the data segment, generating a signature value. Then, based on the public key certificate and the signature value, a standard signature structure is constructed. Finally, the standard signature structure is embedded into the comment segment to form the signed OTA packet. In this way, because the encryption machine is a device with extremely high physical protection capabilities, storing the private key in the encryption machine effectively reduces the possibility of private key theft. Furthermore, implementing the signing through calling the encryption machine interface improves the security of the OAT packet signing.
[0063] Figure 1 In this embodiment, one implementation method for signing a data segment by invoking an encryption machine is provided: the data segment is sent to the encryption machine, which performs a hash calculation, generates a hash value, and then signs the hash value. In some scenarios, when the data segment is large, transmitting the data segment takes time, and performing a hash calculation on the data segment also consumes significant computing resources of the encryption machine. See also... Figure 2 As shown, Figure 2 This embodiment is an example of signing a data segment by calling the encryption machine interface, including:
[0064] S201. Perform hash calculation on the data segment to generate a hash value;
[0065] In this application, after obtaining the data segment of the OTA packet to be signed, the data segment is not sent directly to the encryption machine. Instead, a hash calculation is first performed on the data segment locally, such as using the SHA-256 or SHA-3 hash algorithm, to generate a fixed-length hash value. This hash value serves as a unique digest of the data segment and is used for subsequent signing operations.
[0066] S202. Call the encryption machine interface and use the encryption machine to sign the hash value with RSA or ECC using the private key to generate a signature value.
[0067] The generated hash value is passed to the encryption machine. After receiving the hash value, the encryption machine performs an RSA or ECC signature operation on the hash value based on the private key stored in the encryption machine to generate a signature value.
[0068] In this embodiment, the hash calculation is completed on the local system, and the encryption machine is only responsible for the signing operation, which reduces the computing pressure on the encryption machine. This not only improves the interaction efficiency with the encryption machine, but also saves the computing resources of the encryption machine, making it suitable for scenarios where the encryption machine has limited performance or needs to process a large amount of data.
[0069] Combination Figure 1 or Figure 2 In an example, after the signed OTA packet is generated, refer to... Figure 3 As shown, Figure 3 One embodiment of sending a signed OTA packet to a target device includes:
[0070] S301. When establishing a connection with multiple target devices, determine the network status of each target device;
[0071] In some application scenarios, equipment manufacturers need to perform OTA package upgrades on multiple target devices simultaneously. Therefore, connections are established with multiple target devices at the same time. To improve the transmission efficiency of OTA packages, embodiments of this application can dynamically adjust the method of sending OTA packages based on the network status of each target device. First, the network status of each target device is determined. Specifically, the network status of each target device is evaluated and determined in the following way:
[0072] Measure bandwidth: Test the download speed of the target device.
[0073] Latency detection: Measure the network latency of the target device using Ping or a similar tool.
[0074] Assess stability: Detect whether the network connection of the target device is frequently interrupted.
[0075] S302. Set the priority of each target device according to the network status of each target device;
[0076] After assessing the network status of each target device, the devices are prioritized based on the assessment results: High priority: devices with good network status (high bandwidth, low latency, high stability); Low priority: devices with poor network status (low bandwidth, high latency, low stability). It should be noted that the specific criteria for judging bandwidth, latency, and stability can be manually set. Engineers can determine a range or frequency based on experience to assess the levels of bandwidth, latency, and stability.
[0077] S303. The signed OTA packet is fragmented to obtain several signed OTA packets.
[0078] To adapt to the transmission methods of target devices under different network conditions, after receiving the signed OTA packet, the OTA packet can be fragmented. Specifically, the fragmentation method can be as follows: determine the fragment size based on the target device's network condition and the total size of the OTA packet. For example, if the OTA packet size is 100MB, it can be divided into 100 1MB fragments. Optionally, the fragment size can also be dynamically adjusted based on the network condition. For example, when the target device's network condition is poor, smaller fragments (e.g., 512KB) can be used; when the network condition is good, larger fragments (e.g., 2MB) can be used.
[0079] After determining the fragment size, the specific fragmentation processing operations are performed: The OTA packet is read and loaded into memory after signing; the data is split according to the predetermined fragment size, dividing the OTA packet into multiple data fragments, for example, splitting a 100MB OTA packet into 100 1MB fragments; fragment information is added, adding metadata to each fragment, including: fragment sequence number (used to identify the order of fragments), total number of fragments (used to identify the total number of fragments), and checksum (such as CRC32, used to verify the integrity of the fragment).
[0080] It should be noted that if the network status of the multiple target devices establishing the connection is good, that is, all are set to high priority, then in this scenario, there is no need to fragment the OTA packet, and the whole packet can be sent directly.
[0081] S304. When the target device is of high priority, send a fully signed OTA packet to the target device;
[0082] S305. When the target device is of low priority, send several signed OTA packets to the target device one by one.
[0083] For high-priority target devices, the complete OTA packet is sent directly without fragmentation; for low-priority target devices, fragments are sent one by one, ensuring that each fragment is successfully transmitted before sending the next fragment. If a fragment fails to transmit, it can be retransmitted.
[0084] In some possible embodiments, when the target device changes from low priority to high priority, it is determined whether the number of fragmented OTA packets sent to the target device exceeds a threshold. If not, fragmented transmission is stopped, and a complete signed OAT packet is sent to the target device.
[0085] In this embodiment, the network status of multiple target devices can be monitored in real time to detect any changes. When the network status of a target device improves (e.g., increased bandwidth, reduced latency), its priority is adjusted from low to high. Then, the proportion of fragments sent is determined, and it is checked whether the number of fragmented OTA packets sent to the target device exceeds a threshold (e.g., 50%). If the threshold is not exceeded: fragment sending is stopped, and fully signed OTA packets are sent instead. If the threshold is exceeded: fragment sending continues until all fragments are transmitted.
[0086] The dynamic adjustment method in this embodiment enables timely switching to full packet transmission when network conditions improve, thereby increasing transmission efficiency. When network conditions do not significantly improve, fragmented transmission continues to ensure transmission reliability.
[0087] See Figure 4 As shown, Figure 4 One embodiment of the system for signing OTA packages provided in this application includes:
[0088] The acquisition unit 401 is used to acquire the OTA package to be signed, wherein the OTA package includes a data segment and an annotation segment;
[0089] Calling unit 402 is used to call the encryption machine interface, and use the encryption machine to sign the data segment with a private key to generate a signature value. The private key is stored in the encryption machine.
[0090] Construction unit 403 is used to construct a standard signature structure based on the public key certificate and the signature value;
[0091] The embedding unit 404 is used to embed the standard signature structure into the comment segment and update the comment length of the OTA package to form a signed OTA package.
[0092] Optionally, the calling unit 402 is specifically used for:
[0093] The step of signing the data segment using the private key via the encryption machine to generate a signature value includes:
[0094] The encryption machine performs a hash calculation on the data segment to generate a hash value.
[0095] The encryption machine uses a private key to perform an RSA or ECC signature on the hash value, generating a signature value.
[0096] Optionally, the system further includes:
[0097] The calculation unit 405 is used to perform hash calculation on the data segment and generate a hash value before the calling unit 402 calls the encryption machine interface;
[0098] The calling unit 402 is specifically used for:
[0099] The encryption machine uses a private key to perform an RSA or ECC signature on the hash value, generating a signature value.
[0100] Optionally, the system further includes:
[0101] The determining unit 406 is used to determine the network status of each target device when establishing a connection with multiple target devices;
[0102] Setting unit 407 is used to set the priority of each target device according to the network status of each target device.
[0103] Optionally, the system further includes:
[0104] Fragmentation unit 408 is used to fragment the signed OTA packet to obtain several signed OTA packets.
[0105] The sending unit 409 is used to send the complete signed OTA packet to the target device when the target device has a high priority; and to send the several signed OTA packets to the target device one by one when the target device has a low priority.
[0106] Optionally, the system further includes:
[0107] The judgment unit 410 is used to determine whether the fragmented OTA packets sent to the target device exceed a threshold when the target device changes from low priority to high priority.
[0108] The sending unit 409 is specifically used to stop fragmented sending when the threshold is exceeded, and send the complete signed OAT packet to the target device.
[0109] Optionally, the OTA package further includes an annotation length field, and updating the annotation length of the OTA package includes updating the annotation length field.
[0110] In this embodiment, the functions of each unit are the same as those described above. Figures 1 to 3 The steps in the method embodiments shown correspond to those in the examples, and will not be repeated here.
[0111] See Figure 5 As shown, Figure 5 One embodiment of the apparatus for signing OTA packages provided in this application includes:
[0112] Processor 501, memory 502, input / output unit 503, bus 504;
[0113] The processor 501 is connected to the memory 502, the input / output unit 503, and the bus 504;
[0114] The memory 502 stores a program, and the processor 501 calls the program to execute any of the above OTA package signing methods.
[0115] This application also relates to a computer-readable storage medium storing a program, characterized in that, when the program is run on a computer, it causes the computer to execute any of the above-mentioned OTA package signing methods.
[0116] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0117] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.
[0118] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0119] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0120] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A method for signing OTA packets, characterized in that, The method includes: Obtain the OTA package to be signed, the OTA package including a data segment and a comment segment; The encryption machine interface is invoked, and the data segment is signed using the private key through the encryption machine to generate a signature value. The private key is stored in the encryption machine. Construct a standard signature structure based on the public key certificate and the signature value; The standard signature structure is embedded into the comment segment, and the comment length of the OTA package is updated to form the signed OTA package.
2. The method according to claim 1, characterized in that, The step of signing the data segment using the private key via the encryption machine to generate a signature value includes: The encryption machine performs a hash calculation on the data segment to generate a hash value. The encryption machine uses a private key to perform an RSA or ECC signature on the hash value, generating a signature value.
3. The method according to claim 1, characterized in that, Prior to invoking the encryption machine interface, the method further includes: Perform a hash calculation on the data segment to generate a hash value; The step of signing the data segment using the private key via the encryption machine to generate a signature value includes: The encryption machine uses a private key to perform an RSA or ECC signature on the hash value, generating a signature value.
4. The method according to claim 1, characterized in that, The method further includes: When establishing a connection with multiple target devices, determine the network status of each target device; Set the priority of each target device based on its network status.
5. The method according to claim 4, characterized in that, The method further includes: The signed OTA packet is fragmented to obtain several signed OTA packets; When the target device is of high priority, send the complete signed OTA packet to the target device; When the target device is of low priority, the signed OTA packets are sent to the target device one by one.
6. The method according to claim 5, characterized in that, The method further includes: When the target device changes from low priority to high priority, it is determined whether the number of fragmented OTA packets sent to the target device exceeds the threshold. If not, fragmented transmission is stopped, and a complete signed OAT packet is sent to the target device.
7. The method according to any one of claims 1 to 6, characterized in that, The OTA package also includes a comment length field, wherein the comment length for updating the OTA package includes: Update the comment length field.
8. A system for signing OTA packets, characterized in that, The system includes: An acquisition unit is used to acquire an OTA package to be signed, wherein the OTA package includes a data segment and an annotation segment; The calling unit is used to call the encryption machine interface, and use the encryption machine to sign the data segment with a private key to generate a signature value. The private key is stored in the encryption machine. A construction unit is used to construct a standard signature structure based on the public key certificate and the signature value; An embedding unit is used to embed the standard signature structure into the comment segment and update the comment length of the OTA package to form a signed OTA package.
9. An apparatus for signing OTA packages, characterized in that, The device includes: Processor, memory, input / output units, and bus; The processor is connected to the memory, the input / output unit, and the bus; The memory stores a program, which the processor invokes to perform the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains a program that, when executed on a computer, performs the method as described in any one of claims 1 to 7.