Safety upgrade method and device for energy storage pcs equipment based on signature header pre-fixing solidification
Patent Information
- Application Number
- CN202611005885.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-07
- Publication Date
- 2026-09-25
AI Technical Summary
[0008]本发明提供一种基于签名头前置固化的储能PCS设备安全升级方法、装置及存储介质,用以解决现有技术中PCS设备远程升级完整性保障不足、身份认证缺失、密钥管理脆弱、过度依赖云平台以及升级包结构标准化程度低等缺陷
[0019]实施本发明的基于签名头前置固化的储能PCS设备安全升级方法、装置及存储介质,具有以下有益效果:本发明通过采用SHA256强哈希算法替代传统的CRC32/MD5校验码,提供了抗碰撞的完整性保护,任何对固件的微小篡改都会导致摘要信息发生显著变化,从根本上克服了现有技术中校验码易被伪造的完整性缺陷;通过引入RSA非对称数字签名机制,并将数字签名信息固化在升级包文件头部,整个加密与解密过程仅在本地编码工具与设备端进行,脱离任何云服务器或第三方软件,只有持有私钥的授权方才能生成有效签名,有效防止中间人攻击与恶意固件伪造,克服了现有技术中身份认证可信度不足以及过度依赖云平台的缺陷;通过采用标准化的签名头结构,并在签名头中集成固件版本号、目标设备标识、时间戳等元数据,支持多维度的精细化升级策略管理,克服了现有技术中升级包结构标准化程度低、升级策略不灵活的缺陷;通过先验证、后升级的设备端自主验证流程与逐级校验、逐级返回错误码的机制,进一步提高了升级流程的安全性与可诊断性。
Smart Images

Figure CN122818367A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of embedded system security firmware management technology, and more particularly to a method, apparatus and storage medium for security upgrade of energy storage PCS devices based on signature header pre-fixing. Background Technology
[0002] The Power Conversion System (PCS) is the core component of an energy storage system. It typically integrates multiple embedded modules to perform key functions such as bidirectional power conversion, grid connection control, and condition monitoring. With the large-scale deployment of energy storage systems in the power sector, the firmware of PCS devices and their connected modules requires frequent remote upgrades to fix defects, optimize control strategies, or add new functions. Since PCS devices are directly related to grid security and operational stability, malicious tampering or the implantation of illegal programs in their firmware can lead to equipment damage, grid connection anomalies, or even large-scale power outages. Therefore, extremely high requirements are placed on the security, reliability, and integrity of remote firmware upgrades.
[0003] The existing remote upgrade solutions for PCS devices mainly include the following: Firstly, there's the upgrade method based on simple checksums. This method commonly uses CRC32 or MD5 checksums for integrity verification in traditional embedded device upgrades. The upgrade process involves the compiler generating a firmware package and its checksum, uploading it to a server, and the device downloading it, calculating the checksum, and comparing it. If the comparison passes, the upgrade is executed. The drawbacks of this approach are: firstly, insufficient security. CRC32 and MD5 algorithms have been proven to have collision vulnerabilities, allowing attackers to construct different firmware packages with the same checksum value, thus bypassing integrity verification; secondly, lack of authentication. This method only verifies data integrity and cannot confirm the legitimacy of the upgrade package's source, making it vulnerable to man-in-the-middle attacks; and thirdly, lack of key management. The generation of the checksum requires no key protection, meaning anyone who obtains the firmware package can recalculate the checksum and forge the firmware package.
[0004] Secondly, there's the upgrade method based on the device's backend webpage. Some devices upgrade by logging into the device's backend. The process is as follows: the firmware package is generated by the compilation tool, the user logs into the device's backend, configures the device to be upgraded, sends out the configuration information, verifies it, imports the upgrade package for verification, and then executes the upgrade. The drawbacks of this approach are: firstly, the upgrade process is cumbersome, requiring logging into the device's backend, sending out device configuration, and finally importing the upgrade package for each upgrade, resulting in numerous steps and relatively low efficiency; secondly, the upgrade process has weak security, lacking strict cryptographic security checks, and the relatively simple upgrade process is also vulnerable to man-in-the-middle attacks.
[0005] Thirdly, there is the centralized management and upgrade approach based on cloud platforms. Modern devices adopt a centralized management model using cloud platforms. Devices communicate with the cloud platform via Message Queuing Telemetry Transport Protocol (MQTT) or Hypertext Transfer Protocol (HTTP), with the cloud platform responsible for firmware version management, device grouping, and upgrade policy configuration. The drawbacks of this approach are: firstly, the risk of a single point of failure on the platform, making the cloud platform a security bottleneck for the entire upgrade system; if the platform is compromised, it could lead to a large number of devices being implanted with malicious firmware; secondly, the lack of device-side self-verification capabilities, as this method relies excessively on trust in the cloud platform, weakening the device's own verification capabilities; and thirdly, low standardization, with different manufacturers using different signature formats and verification protocols, lacking a unified standard, which is detrimental to cross-device and cross-version upgrade compatibility.
[0006] In summary, existing PCS device remote upgrade technologies generally struggle to ensure both integrity and identity authentication, rely excessively on external servers or manual configuration, and lack robust on-device security verification mechanisms and standardized upgrade package structures.
[0007] Therefore, a new solution is needed. Summary of the Invention
[0008] This invention provides a method, apparatus, and storage medium for secure upgrades of energy storage PCS devices based on pre-signature header hardening, in order to solve the defects in the prior art such as insufficient integrity guarantee for remote upgrades of PCS devices, lack of identity authentication, weak key management, excessive reliance on cloud platforms, and low standardization of upgrade package structure.
[0009] According to a first aspect of the present invention, a method for security upgrade of an energy storage PCS device based on pre-installed signature header is provided, the method comprising: Obtain the firmware to be upgraded; The firmware to be upgraded is digested to obtain digest information, and digital signature information is generated based on the digest information; The digest information and the digital signature information are encapsulated to form a signature header, and the signature header is embedded in the header of the upgrade package file to generate the target upgrade package; Send the target upgrade package to the energy storage PCS device; After receiving the target upgrade package, the energy storage PCS device parses the signature header, obtains the digest information and the digital signature information, and verifies the digital signature information using a local preset public key; it recalculates the digest information of the firmware data in the target upgrade package, and performs a consistency check between the recalculated digest information and the digest information in the signature header. After both the digital signature verification and digest consistency verification pass, the target firmware upgrade is performed; otherwise, the upgrade is terminated.
[0010] In a preferred embodiment of the present invention, the signature header is fixed at the beginning of the upgrade package file and includes at least digest information, digital signature information, firmware version number, target device identifier, and timestamp information.
[0011] In a preferred embodiment of the present invention, the digest information is obtained by calculating the firmware to be upgraded using the SHA256 hash algorithm.
[0012] In a preferred embodiment of the present invention, the digital signature information is generated by signing the digest information with an RSA private key; the energy storage PCS device verifies the digital signature information using a locally preset RSA public key.
[0013] In a preferred embodiment of the present invention, after the energy storage PCS device parses the signature header, it first uses the digital signature information to authenticate the source of the digest information. After the source authentication is passed, it recalculates the digest information of the firmware data in the target upgrade package and performs digest consistency verification.
[0014] In a preferred embodiment of the present invention, after parsing the signature header, the energy storage PCS device determines whether the target upgrade package meets the upgrade conditions based on the target device identifier and firmware version number in the signature header, and performs the digital signature verification and digest consistency verification when the upgrade conditions are met.
[0015] In a preferred embodiment of the present invention, when the target upgrade package does not meet the upgrade conditions, or the digital signature verification fails, or the digest consistency verification fails, the energy storage PCS device terminates the upgrade operation.
[0016] In a preferred embodiment of the present invention, when the energy storage PCS device recalculates the digest information, it includes: extracting firmware data from the target upgrade package except for the signature header, and recalculating the digest information of the firmware data using the same digest algorithm as when the target upgrade package was generated.
[0017] According to a second aspect of the present invention, a security upgrade device for an energy storage PCS device based on pre-signature header hardening is also provided, for implementing the method described above, comprising: The summary generation module is used to obtain the firmware to be upgraded and perform summary calculation on the firmware to generate summary information; A signature generation module is used to generate digital signature information based on the digest information; The upgrade package generation module is used to encapsulate the digest information and the digital signature information to form a signature header, and to fix the signature header in the header of the upgrade package file to generate the target upgrade package; The upgrade package distribution module is used to send the target upgrade package to the energy storage PCS device; The upgrade package verification module is used to receive the target upgrade package, parse the signature header, obtain the digest information and the digital signature information, verify the digital signature information using a local preset public key, recalculate the digest information of the firmware data in the target upgrade package, and perform a consistency check between the recalculated digest information and the digest information in the signature header. The upgrade control module is used to perform the target firmware upgrade when both digital signature verification and digest consistency verification pass, otherwise the upgrade is terminated.
[0018] According to a third aspect of the present invention, a computer-readable storage medium is also provided, on which a computer program is stored, wherein the computer program, when executed by a processor, implements the steps of the security upgrade method for energy storage PCS devices based on signature header pre-fixing as described above.
[0019] The present invention provides a secure upgrade method, apparatus, and storage medium for energy storage PCS devices based on pre-embedded signature headers, which has the following advantages: The present invention replaces the traditional CRC32 / MD5 checksum with the SHA256 strong hash algorithm, providing collision-resistant integrity protection. Any minor tampering with the firmware will cause a significant change in the digest information, fundamentally overcoming the integrity defect of easily forged checksums in existing technologies. By introducing the RSA asymmetric digital signature mechanism and embedding the digital signature information in the upgrade package file header, the entire encryption and decryption process is performed only on the local encoding tool and device, independent of any cloud server or third-party... Third-party software can only generate valid signatures if the authorized party holds the private key, effectively preventing man-in-the-middle attacks and malicious firmware forgery. This overcomes the shortcomings of insufficient identity authentication credibility and over-reliance on cloud platforms in existing technologies. By adopting a standardized signature header structure and integrating metadata such as firmware version number, target device identifier, and timestamp into the signature header, it supports multi-dimensional and refined upgrade strategy management, overcoming the shortcomings of low standardization of upgrade package structure and inflexible upgrade strategies in existing technologies. Through a device-side self-verification process that verifies before upgrading and a mechanism of step-by-step verification and error code return, the security and diagnostics of the upgrade process are further improved. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort: Figure 1This is a flowchart illustrating the security upgrade method for energy storage PCS devices based on pre-signature header hardening provided by the present invention. Figure 2 This is a schematic diagram of the structure of the energy storage PCS device security upgrade device based on signature header pre-fixing provided by the present invention; Figure 3 This is a schematic diagram of the physical structure of the electronic device provided by the present invention. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0022] Existing remote upgrade technologies for energy storage PCS equipment either use simple checksums such as CRC32 and MD5, which have collision vulnerabilities and lack identity authentication and key protection; or use device backend web page upgrades, which have cumbersome processes and weak security verification; or use cloud platform centralized management, which has the risk of single point of failure on the platform, weak device-side self-verification capabilities, and low standardization. They generally cannot achieve reliable source identity authentication while ensuring firmware integrity, and are also difficult to get rid of excessive dependence on external servers or manual configuration.
[0023] To address the aforementioned issues, this invention proposes a secure upgrade method for energy storage PCS devices based on pre-embedded signature header. In this method, a local encoding tool performs digest calculation on the firmware to be upgraded and generates digital signature information based on the digest. The digest and digital signature information are encapsulated into a signature header and embedded in the header of the upgrade package file, forming a standardized target upgrade package. After the target upgrade package is sent to the energy storage PCS device via a server, the device parses the signature header locally. It first uses a locally pre-set public key to authenticate the source of the digital signature information, then recalculates the digest information of the firmware data and performs a consistency check with the digest information in the signature header. This achieves a device-side autonomous secure upgrade process of verification before upgrade. Only after both digital signature verification and digest consistency check pass is the target firmware upgrade executed; otherwise, the upgrade is immediately terminated and the corresponding error code is returned. The entire encryption and verification process is performed only on the local encoding tool and the energy storage PCS device, independent of cloud server interference.
[0024] In the description of the embodiments of the present invention, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. In the description of the embodiments of the present invention, "a plurality of" means two or more, unless otherwise explicitly defined.
[0025] It should be noted that, in this embodiment of the invention, the energy storage PCS device refers to the energy storage converter and one or more embedded modules connected to it, such as monitoring modules, control modules, etc.; the firmware to be upgraded refers to the firmware program that needs to be updated to the module connected to the energy storage PCS device; and the local encoding tool refers to the software or device deployed locally for processing the firmware to be upgraded and generating the target upgrade package.
[0026] Figure 1 This is a flowchart illustrating the security upgrade method for energy storage PCS devices based on pre-signature header hardening provided by the present invention, as shown below. Figure 1 As shown, the method includes the following steps S1-S6.
[0027] Step S1: Obtain the firmware to be upgraded.
[0028] Specifically, this step is performed in a local encoding tool. The source file to be upgraded (i.e., the firmware to be upgraded) is imported into the local encoding tool as input for subsequent processing. The firmware to be upgraded can be a firmware binary file compiled by a compilation tool. In some implementations, the local encoding tool can also receive upgrade configuration information for this upgrade, which may include the target device identifier, firmware version number, etc., for subsequent encapsulation into the signature header.
[0029] Step S2: Perform digest calculation on the firmware to be upgraded to obtain digest information, and generate digital signature information based on the digest information.
[0030] Specifically, the local encoding tool performs a digest calculation on the firmware to be upgraded, obtaining digest information that uniquely represents the firmware content. In some implementations, the digest information is calculated using the SHA256 hash algorithm on all firmware data to be upgraded, resulting in a fixed-length (e.g., 32 bytes) hash value as the digest information. The advantage of using the SHA256 strong hash algorithm is its collision resistance; any minor modification to the firmware to be upgraded will cause a significant change in the calculated digest information, making it difficult for attackers to construct different firmware with the same digest information. This overcomes the collision vulnerability of traditional checksums such as CRC32 and MD5.
[0031] After obtaining the digest information, the local encoding tool generates a digital signature based on the digest information. In some implementations, the digital signature is generated by signing the digest information with an RSA private key. Specifically, the local encoding tool holds the private key from the RSA key pair and uses this private key to perform encryption operations on the digest information (or the digest information after pre-filling processing) to generate the digital signature. Since the private key is held only by the authorized party and is not disclosed to others, only the authorized party can generate valid digital signature information, thereby authenticating the identity of the upgrade package's origin.
[0032] It should be noted that this invention does not limit the specific types of hash algorithms and signature algorithms. In other implementations, the hash algorithm can be replaced with other strong hash algorithms such as SHA384, SHA512, and SM3, and the signature algorithm can be replaced with other asymmetric signature algorithms such as Elliptic Curve Digital Signature Algorithm (ECDSA) and SM2, as long as the purpose of integrity protection and source authentication can be achieved.
[0033] In some implementations, after generating digital signature information, the local encoding tool can also perform Base64 encoding on the digest information, digital signature information, or firmware data to facilitate transmission and parsing under text protocols (such as HTTP).
[0034] Step S3: Encapsulate the digest information and the digital signature information to form a signature header, and fix the signature header in the header of the upgrade package file to generate the target upgrade package.
[0035] Specifically, the local encoding tool encapsulates the digest information and digital signature information into a signature header according to a pre-agreed standardized data structure format, and then fixes the signature header into the header (i.e. the starting position) of the upgrade package file. Subsequently, the signature header and firmware data are packaged together and output to generate the target upgrade package.
[0036] In some implementations, the target upgrade package consists of two parts: a signature header at the beginning of the file and firmware data following the signature header. The signature header includes at least a digest, a digital signature, a firmware version number, a target device identifier, and a timestamp. The digest is used for integrity verification; the digital signature is used for source authentication; the firmware version number identifies the version of the firmware being upgraded and can be used for version compatibility assessment and preventing version rollback; the target device identifier identifies the device model or type to which the upgrade is applicable and can be used to determine if the upgrade package matches the device; and the timestamp records the generation time of the upgrade package and can be used for replay protection and upgrade auditing.
[0037] In some implementations, the signature header can also use a fixed-length header field to identify the overall length of the signature header and the offset and length of each metadata field. This allows the device to accurately parse the information in the signature header and precisely separate the signature header from the firmware data. By embedding the signature header in the upgrade package file header, a secure "verify first, upgrade later" model is implemented: after obtaining the upgrade package, the device only needs to read and parse the signature header located at the beginning of the file to complete the security verification first. This eliminates the need to fully read or cache the entire firmware data to determine the legitimacy of the upgrade package, thereby improving verification efficiency and saving device storage resources.
[0038] The adoption of an internally standardized signature header structure design enables different versions and models of energy storage PCS devices to parse the signature header in a unified format, thereby ensuring the compatibility and continuity of upgrade packages across different devices and overcoming the shortcomings of inconsistent signature formats and verification protocols among manufacturers and low standardization in existing technologies.
[0039] Step S4: Send the target upgrade package to the energy storage PCS device.
[0040] Specifically, the local encoding tool or its associated server distributes the generated target upgrade package to the energy storage PCS device via a communication protocol. In some implementations, the target upgrade package is distributed to the monitoring module in the energy storage PCS device via HTTP, and then the monitoring module forwards it or uses it directly to upgrade the connected modules. It should be noted that the server in this invention only serves as the transmission channel for the upgrade package and does not participate in the encryption, signing, or verification process of the upgrade package, thereby avoiding the risk of a large number of devices being implanted with malicious firmware due to a single point of failure in the cloud platform.
[0041] Step S5: After receiving the target upgrade package, the energy storage PCS device parses the signature header, obtains the digest information and the digital signature information, and verifies the digital signature information using a local preset public key; it recalculates the digest information of the firmware data in the target upgrade package, and performs a consistency check between the recalculated digest information and the digest information in the signature header.
[0042] Specifically, after receiving the target upgrade package, the energy storage PCS device splits the upgrade package and parses the digest information, digital signature information, and metadata such as firmware version number, target device identifier, and timestamp from the signature header located at the top of the file.
[0043] Furthermore, the energy storage PCS equipment employs a step-by-step verification method to validate the target upgrade package. If an error occurs at any step, the upgrade process is immediately terminated, and the corresponding error code is returned to facilitate fault location and diagnosis; if the verification passes, the next step is executed. The step-by-step verification process may include: First, the upgrade condition judgment. The energy storage PCS device determines whether the target upgrade package meets the upgrade conditions based on the target device identifier and firmware version number in the signature header. For example, it checks whether the target device identifier matches the model or type of the device, and whether the firmware version number is higher than the firmware version currently running on the device (i.e., to prevent version rollback). If the upgrade conditions are not met, the upgrade is terminated and the corresponding error code is returned.
[0044] Secondly, source authentication (digital signature verification). Under the condition that the upgrade conditions are met, the energy storage PCS device uses a locally pre-installed public key to verify the digital signature information in the signature header. In some implementations, the energy storage PCS device has a locally pre-installed RSA public key corresponding to the private key held by the local encoding tool. The energy storage PCS device uses this public key to decrypt the digital signature information, obtaining the digest information corresponding to the signature, and compares it with the digest information carried in the signature header to verify the validity of the digital signature. This confirms that the upgrade package indeed originates from the authorized party holding the corresponding private key, thus achieving source identity authentication. If the digital signature verification fails, the upgrade is terminated and the corresponding error code is returned.
[0045] Third, digest consistency verification (integrity verification). After source authentication is passed, the energy storage PCS device recalculates the digest information of the firmware data in the target upgrade package. Specifically, the energy storage PCS device extracts the firmware data from the target upgrade package except for the signature header, and recalculates the digest information of the firmware data using the same digest algorithm (e.g., SHA256) as when the local encoding tool generated the target upgrade package; then, it performs a consistency verification between the recalculated digest information and the digest information carried in the signature header. If they match, it indicates that the firmware data has not been tampered with during transmission, and its integrity is guaranteed; if they do not match, it indicates that the firmware data may have been tampered with or damaged during transmission, at which point the upgrade is terminated and the corresponding error code is returned.
[0046] It should be noted that this invention places source authentication before digest consistency verification. That is, the source of the digest information is first authenticated using digital signature information, and digest consistency verification is performed only after source authentication is successful. The advantage of this design is that it allows for rapid verification of the upgrade package's source with lower computational overhead before the relatively time-consuming firmware data digest recalculation. Upgrade packages with illegitimate sources can be terminated as early as possible, thus saving computing resources on the device side. In other implementations, digest consistency verification may be performed before source authentication, or both may be performed in parallel. This invention does not strictly limit the order of these two processes.
[0047] Step S6: After both the digital signature verification and digest consistency verification pass, perform the target firmware upgrade; otherwise, terminate the upgrade.
[0048] Specifically, only when both the digital signature verification and digest consistency verification pass (and in embodiments that include upgrade condition judgment, also upgrade condition judgment passing) will the energy storage PCS device determine that the target upgrade package is legitimate, complete, and of reliable origin, and then perform the target firmware upgrade, that is, write the firmware data in the upgrade package into the corresponding storage area of the module connected to the energy storage PCS device, thus completing the firmware update. During the upgrade process, the energy storage PCS device can gradually return to each step of the upgrade process and status of the upgraded device to facilitate monitoring of the upgrade progress.
[0049] Conversely, if any of the above verification steps fail, i.e., if the target upgrade package does not meet the upgrade conditions, or the digital signature verification fails, or the digest consistency verification fails, the energy storage PCS device will terminate the upgrade operation, not perform firmware writing, and return the corresponding error code, thereby ensuring that illegal or damaged firmware will not be written to the device and protecting the device security.
[0050] In summary, the overall processing flow of this embodiment of the invention can be described as follows: On the local encoding tool, the firmware to be upgraded is imported, and upgrade configuration, SHA256 digest calculation, RSA signing, Base64 encoding, signature header encapsulation (configuration information, digest information, signature information, etc.) are performed. The signature header is then fixed in the header of the upgrade package file, and the target upgrade package is packaged and output. On the server side, the target upgrade package is sent to the energy storage PCS device via the HTTP protocol. On the energy storage PCS device side, the target upgrade package is received and the upgrade package is split. Upgrade condition judgment, digital signature verification, and digest consistency verification are performed step by step. If any step fails, the upgrade is terminated and the corresponding error code is returned. After all verifications pass, the firmware upgrade of the corresponding device is executed, and the upgrade process status is gradually returned.
[0051] The following describes the security upgrade device for energy storage PCS equipment based on signature header pre-fixing provided by the present invention. The device described below and the method described above can be referred to in correspondence.
[0052] Figure 2 This is a schematic diagram of the security upgrade device for energy storage PCS equipment based on pre-signature header hardening provided by the present invention, as shown below. Figure 2 As shown, the device includes: The summary generation module 210 is used to obtain the firmware to be upgraded and perform summary calculation on the firmware to be upgraded to generate summary information; The signature generation module 220 is used to generate digital signature information based on the digest information; The upgrade package generation module 230 is used to encapsulate the digest information and the digital signature information to form a signature header, and to fix the signature header in the header of the upgrade package file to generate the target upgrade package; The upgrade package distribution module 240 is used to send the target upgrade package to the energy storage PCS device; The upgrade package verification module 250 is used to receive the target upgrade package, parse the signature header, obtain the digest information and the digital signature information, verify the digital signature information using a local preset public key, recalculate the digest information of the firmware data in the target upgrade package, and perform a consistency check between the recalculated digest information and the digest information in the signature header. The upgrade control module 260 is used to perform the target firmware upgrade when both digital signature verification and digest consistency verification pass, otherwise the upgrade is terminated.
[0053] Based on the above embodiments, the upgrade package generation module is specifically used to: fix the signature header at the beginning of the upgrade package file, and make the signature header include at least digest information, digital signature information, firmware version number, target device identifier and timestamp information.
[0054] Based on the above embodiments, the digest generation module is specifically used to calculate digest information using the SHA256 hash algorithm on the firmware to be upgraded; the signature generation module is specifically used to sign the digest information with the RSA private key to generate digital signature information; and the upgrade package verification module is specifically used to verify the digital signature information using a locally preset RSA public key.
[0055] Based on the above embodiments, the upgrade package verification module is specifically used to: after parsing the signature header, first use the digital signature information to authenticate the source of the digest information, and after the source authentication is passed, recalculate the digest information of the firmware data in the target upgrade package and perform digest consistency verification; and determine whether the target upgrade package meets the upgrade conditions based on the target device identifier and firmware version number in the signature header, and perform digital signature verification and digest consistency verification when the upgrade conditions are met.
[0056] Based on the above embodiments, the upgrade control module is further configured to: terminate the current upgrade operation and return the corresponding error code when the target upgrade package does not meet the upgrade conditions, or the digital signature verification fails, or the digest consistency verification fails.
[0057] It should be noted that, in some implementations of the present invention, the digest generation module, signature generation module, upgrade package generation module, and upgrade package distribution module can be set on the local encoding tool side, and the upgrade package verification module and upgrade control module can be set on the energy storage PCS device side. The two interact with each other through a server or communication network to jointly realize the above-mentioned security upgrade method.
[0058] Figure 3 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 3As shown, the electronic device may include: a processor 310, a communications interface 320, a memory 330, and a communication bus 340, wherein the processor 310, the communications interface 320, and the memory 330 communicate with each other through the communication bus 340. The processor 310 can call logical instructions in the memory 330 to execute a security upgrade method for energy storage PCS devices based on signature header pre-fixing, the method including: Obtain the firmware to be upgraded; The firmware to be upgraded is digested to obtain digest information, and digital signature information is generated based on the digest information; The digest information and the digital signature information are encapsulated to form a signature header, and the signature header is embedded in the header of the upgrade package file to generate the target upgrade package; Send the target upgrade package to the energy storage PCS device; After receiving the target upgrade package, the energy storage PCS device parses the signature header, obtains the digest information and the digital signature information, and verifies the digital signature information using a local preset public key; it recalculates the digest information of the firmware data in the target upgrade package, and performs a consistency check between the recalculated digest information and the digest information in the signature header. After both the digital signature verification and digest consistency verification pass, the target firmware upgrade is performed; otherwise, the upgrade is terminated.
[0059] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0060] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer is able to execute the energy storage PCS device security upgrade method based on signature header pre-fixing provided by the above methods.
[0061] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the above-described methods for security upgrade of energy storage PCS devices based on signature header pre-fixing.
[0062] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0063] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0064] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for security upgrade of energy storage PCS devices based on pre-signature header hardening, characterized in that, Includes the following steps: Obtain the firmware to be upgraded; The firmware to be upgraded is digested to obtain digest information, and digital signature information is generated based on the digest information; The digest information and the digital signature information are encapsulated to form a signature header, and the signature header is embedded in the header of the upgrade package file to generate the target upgrade package; Send the target upgrade package to the energy storage PCS device; After receiving the target upgrade package, the energy storage PCS device parses the signature header, obtains the digest information and the digital signature information, and verifies the digital signature information using a local preset public key; it recalculates the digest information of the firmware data in the target upgrade package, and performs a consistency check between the recalculated digest information and the digest information in the signature header. After both the digital signature verification and digest consistency verification pass, the target firmware upgrade is performed; otherwise, the upgrade is terminated.
2. The method according to claim 1, characterized in that, The signature header is embedded at the beginning of the upgrade package file and includes at least digest information, digital signature information, firmware version number, target device identifier, and timestamp information.
3. The method according to claim 1, characterized in that, The digest information is calculated using the SHA256 hash algorithm on the firmware to be upgraded.
4. The method according to claim 1, characterized in that, The digital signature information is generated by signing the digest information with an RSA private key; the energy storage PCS device verifies the digital signature information using a locally preset RSA public key.
5. The method according to claim 1, characterized in that, After parsing the signature header, the energy storage PCS device first uses the digital signature information to authenticate the source of the digest information. After the source authentication is successful, it recalculates the digest information of the firmware data in the target upgrade package and performs digest consistency verification.
6. The method according to claim 1, characterized in that, After parsing the signature header, the energy storage PCS device determines whether the target upgrade package meets the upgrade conditions based on the target device identifier and firmware version number in the signature header, and performs the digital signature verification and digest consistency check when the upgrade conditions are met.
7. The method according to claim 6, characterized in that, When the target upgrade package does not meet the upgrade conditions, or the digital signature verification fails, or the digest consistency verification fails, the energy storage PCS device terminates the upgrade operation.
8. The method according to claim 1, characterized in that, When the energy storage PCS device recalculates the digest information, it includes: extracting firmware data from the target upgrade package except for the signature header, and recalculating the digest information of the firmware data using the same digest algorithm as when the target upgrade package was generated.
9. A security upgrade device for energy storage PCS equipment based on pre-installed signature header, used to implement the method of any one of claims 1 to 8, characterized in that, include: The summary generation module is used to obtain the firmware to be upgraded and perform summary calculation on the firmware to generate summary information; A signature generation module is used to generate digital signature information based on the digest information; The upgrade package generation module is used to encapsulate the digest information and the digital signature information to form a signature header, and to fix the signature header in the header of the upgrade package file to generate the target upgrade package; The upgrade package distribution module is used to send the target upgrade package to the energy storage PCS device; The upgrade package verification module is used to receive the target upgrade package, parse the signature header, obtain the digest information and the digital signature information, verify the digital signature information using a local preset public key, recalculate the digest information of the firmware data in the target upgrade package, and perform a consistency check between the recalculated digest information and the digest information in the signature header. The upgrade control module is used to perform the target firmware upgrade when both digital signature verification and digest consistency verification pass, otherwise the upgrade is terminated.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the security upgrade method for energy storage PCS devices based on signature header pre-fixing as described in any one of claims 1 to 8.