Security policy updating method and apparatus, embedded device, and medium

By implementing interface functions output encryption seeds and receiving encryption post-encrypted security policies in the firmware of embedded devices, the risks of device damage and information leakage caused by the update of embedded devices' security policy are solved, and the security and flexibility of security policy updates are improved.

WO2025112870A1PCT designated stage expired Publication Date: 2025-06-05ROLLING WIRELESS SARL +1

Patent Information

Application Number
PCT/CN2024/121405
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-30
Filing Date
2024-09-26
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

In the prior art, security policy updates of embedded devices usually require re-downloading of firmware carrying different certificate chains, resulting in failure of firmware updates that may lead to device damage, and the updated function cannot be turned off before the firmware is updated again in time, which poses a risk of information leakage.

Method used

By implementing preset interface functions in the firmware of embedded devices, outputting random strings as encryption seeds, and receiving encryption security policies, decrypting and enabling them, ensuring that security policy updates do not rely on traditional firmware update methods, avoiding device corruption, and automatically recovering security policies by configuring deletion policies.

Benefits of technology

It effectively avoids the risk of equipment damage caused by firmware updates, and automatically restores security policies, promptly closes the debugging function to avoid information leakage, and improves the security and flexibility of security policy updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024121405_05062025_PF_FP_ABST
    Figure CN2024121405_05062025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a security policy updating method and apparatus, an embedded device, and a medium. The security policy updating method comprises: outputting a random character string as an encryption seed on the basis of a first preset interface function of firmware of the embedded device; and receiving an encrypted security policy on the basis of a second preset interface function of the firmware of the embedded device, decrypting the encrypted security policy to obtain a decrypted security policy, and enabling the decrypted security policy, wherein the encrypted security policy is obtained by encrypting the updated security policy on the basis of the encryption seed.
Need to check novelty before this filing date? Find Prior Art

Description

Security policy updating method, device, embedded device and medium

[0001] Citation of Related Applications

[0002] This disclosure claims all rights and interests in the Chinese invention patent application with application number 202311630956.5, filed with the State Intellectual Property Office of the People's Republic of China on November 30, 2023, and entitled "A security policy update method, apparatus, embedded device and medium", and incorporates the entire contents thereof into this disclosure by reference.

[0003] field

[0004] The present disclosure generally relates to the field of security policy update technology, and more particularly to a security policy update method, apparatus, embedded device, and medium.

[0005] background

[0006] Currently, embedded devices widely use fuses as a security solution. This solution requires a root certificate, whose signature is burned into the fuses of the embedded device's chip. The root certificate itself, or as part of a certificate chain derived from the root certificate, is attached to the embedded device's firmware. The certificate chain contains security policies that enable or disable features such as secure boot, partition image export, RAM (Random Access Memory) dumps, JTAG (Joint Test Action Group), and debug logging. Once the fuse-based security solution is activated, the firmware reads the root certificate signature in the fuses and verifies it against the certificate chain attached to the firmware after the device boots. If the verification passes, the security policy in the certificate chain is read and applied throughout the device's boot and operation. If the verification fails, the device is prohibited from booting.

[0007] Typically, after deployment, the security policy in the certificate chain within the embedded device firmware disables all debugging features. This means secure boot is enabled, but features like image export, RAM dump, JTAG, and logging are disabled. If debugging is needed for some purpose, a new firmware with a different certificate chain must be downloaded to update the security policy. However, firmware updates inevitably carry the risk of damaging the embedded device due to firmware update failure.

[0008] Overview

[0009] In a first aspect, the present disclosure relates to a security policy update method, which is applied to an embedded device and includes:

[0010] Outputting a random string as an encryption seed based on a first preset interface function of its own firmware; and

[0011] The second preset interface function based on its own firmware receives the encrypted security policy, decrypts the encrypted security policy to obtain the decrypted security policy, and enables the decrypted security policy; wherein, the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed.

[0012] In some embodiments, after decrypting the encrypted security policy to obtain the decrypted security policy, the security policy updating method further includes:

[0013] Determining a storage location of the decrypted security policy based on the configuration information of the decrypted security policy; wherein the storage location is a random access memory or a non-volatile memory;

[0014] The decrypted security policy is stored according to the storage location.

[0015] In some embodiments, before receiving the encrypted security policy based on the second preset interface function of the own firmware, the security policy updating method further includes:

[0016] When the embedded device is powered on, the certificate chain in the firmware is verified for legitimacy based on the signature of the root certificate obtained from the fuse register;

[0017] If the verification passes and the historical decrypted security policy is stored in the non-volatile memory, the historical decrypted security policy is enabled to complete the startup;

[0018] If the verification passes and no historical decrypted security policy is stored in the non-volatile memory, the security policy in the certificate chain is enabled to complete the startup.

[0019] In some embodiments, the configuration information further carries a deletion policy for the decrypted security policy; the deletion policy is to delete the policy at a scheduled time or after a preset number of restarts;

[0020] The security policy updating method further includes: deleting the decrypted security policy based on the deletion policy.

[0021] In some embodiments, after the first preset interface function based on the own firmware outputs a random string as an encryption seed, the security policy update method further includes:

[0022] Set the expiration time of the encrypted seed.

[0023] In some embodiments, the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed and the encryption private key, and decrypting the encrypted security policy to obtain the decrypted security policy includes:

[0024] The encrypted security policy is decrypted based on the locally stored public key and the encryption seed to obtain the decrypted security policy.

[0025] In some embodiments, the first preset interface function based on the own firmware outputs a random string as an encryption seed, including:

[0026] When receiving the instruction sent by the security policy server, the first preset interface function of the firmware of the device outputs a random string as an encryption seed, and uploads the encryption seed to the security policy server;

[0027] The second preset interface function based on the own firmware receives the encrypted security policy, including: the second preset interface function based on the own firmware receives the encrypted security policy returned by the security policy server.

[0028] In a second aspect, the present disclosure relates to a security policy update method, which is applied to a security policy server and includes:

[0029] Obtain an encryption seed; the encryption seed is a random string output by a first preset interface function; the first preset interface function is an interface function of the firmware of the embedded device; and

[0030] The updated security policy is encrypted based on the encryption seed to obtain an encrypted security policy; the encrypted security policy is received and decrypted by a second preset interface function of the firmware to obtain a decrypted security policy, and the decrypted security policy is enabled in the embedded device.

[0031] In a third aspect, the present disclosure relates to a security policy updating apparatus, which is applied to an embedded device and includes:

[0032] An encryption seed output module, configured to output a random string as an encryption seed based on a first preset interface function of its own firmware;

[0033] The security policy processing module is configured to receive the encrypted security policy based on a second preset interface function of its own firmware, decrypt the encrypted security policy to obtain a decrypted security policy, and enable the decrypted security policy; wherein the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed.

[0034] In a fourth aspect, the present disclosure relates to an embedded device, comprising a memory and a processor, wherein:

[0035] The memory is configured to store a computer program;

[0036] The processor is configured to execute the computer program to implement the security policy updating method described in the present disclosure.

[0037] In a fifth aspect, the present disclosure provides a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the security policy updating method described in the present disclosure.

[0038] In certain embodiments, a random string is output as an encryption seed through a preset interface function of the embedded device firmware, and an encrypted security policy is received, and the encrypted security policy is decrypted to obtain a decrypted security policy, and the decrypted security policy is enabled. In this way, the update of the security policy is implemented through the firmware interface function, which can effectively avoid device damage caused by firmware updates and improve the security of security policy updates.

[0039] BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are merely embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0041] FIG1 is a flow chart of a security policy updating method provided by an embodiment of the present disclosure;

[0042] FIG2 is a schematic diagram of a security policy update solution provided by an embodiment of the present disclosure;

[0043] FIG3 is a flowchart of starting an embedded device according to an embodiment of the present disclosure;

[0044] FIG4 is a schematic diagram of the structure of a security policy updating device provided by an embodiment of the present disclosure; and

[0045] FIG5 is a structural diagram of an embedded device provided in an embodiment of the present disclosure.

[0046] Details

[0047] The following will clearly and completely describe the technical solutions in the embodiments of the present disclosure in conjunction with the accompanying drawings. Obviously, the described embodiments are only some of the embodiments of the present disclosure, and not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present disclosure without inventive effort are within the scope of protection of the present disclosure.

[0048] Usually, the security policy in the certificate chain in the final deployed embedded device firmware will disable all debugging functions, that is, secure boot will be enabled, while image export, RAM DUMP, JTAG, print log and other functions will be disabled. At this time, if a certain debugging function is needed for some purpose, it is necessary to re-download a firmware carrying a different certificate chain to update the security policy. However, updating the firmware inevitably brings the risk of damage to the embedded device due to firmware update failure. In addition, the function turned on by updating the firmware will always be enabled and will not be turned off due to power failure or restart, unless the firmware is updated again to turn off the function. Therefore, if the firmware is not upgraded again in time to turn off a certain debugging function, there will be a risk of information leakage. To this end, the present disclosure provides a security policy update solution that can improve the security and flexibility of security policy updates.

[0049] As shown in FIG1 , an embodiment of the present disclosure discloses a security policy update method, which is applied to an embedded device and includes:

[0050] Step S11: outputting a random string as an encryption seed based on a first preset interface function of its own firmware; and

[0051] Step S12: Receive the encrypted security policy based on a second preset interface function of the firmware, decrypt the encrypted security policy to obtain a decrypted security policy, and activate the decrypted security policy; wherein the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed.

[0052] In certain embodiments, the first preset interface function and the second preset interface function can be implemented in the firmware of the embedded device. It can be understood that the first preset interface function and the second preset interface function are both APIs (i.e., Application Programming Interface). In certain embodiments, when an instruction sent by the security policy server is obtained, the first preset interface function based on the firmware itself outputs a random string as an encryption seed. In certain embodiments, a preset user operation can be detected, and the first preset interface function based on the firmware itself outputs a random string as an encryption seed. That is, the user can operate the embedded device, and the embedded device outputs a random string as an encryption seed based on the first preset interface function of the firmware itself. In certain embodiments, it can also be that when an instruction sent by the user terminal device is received, the first preset interface function based on the firmware itself outputs a random string as an encryption seed.

[0053] In certain embodiments, the disclosed embodiments may also configure an expiration time for the encryption seed. It should be noted that encryption security policies require the use of an encryption seed generated on an embedded device. By configuring an expiration time for the encryption seed, the encrypted security policy can be applied only to a specific embedded device within a specific time period, thereby ensuring the security of the security policy application.

[0054] In certain embodiments, the firmware of the embedded device provides a second preset interface function for receiving an encrypted security policy, decrypting the encrypted security policy to obtain a decrypted security policy, and enabling the decrypted security policy. The encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed and the encryption private key. In certain embodiments, the encrypted security policy can be decrypted based on a locally stored public key and the encryption seed to obtain a decrypted security policy.

[0055] In some embodiments, after the embedded device outputs a random string as an encryption seed based on the first preset interface function of its own firmware, it can also upload the encrypted seed to the security policy server. In some embodiments, the encrypted security policy is obtained by the security policy server encrypting the updated security policy based on the encryption seed and the encryption private key. The embodiment of the present disclosure can receive the encrypted security policy returned by the security policy server based on the second preset interface function of its own firmware. The encrypted private key can be stored in the security policy server. The security policy in the security policy server can be uploaded by the user-end device, which can be a personal computer, mobile terminal, etc. When there is an updated security policy, the user-end device uploads the updated security policy to the security policy server. In this way, the private key for encryption is stored on the security policy server, and the public key for decryption is stored on the embedded device, thereby ensuring that only the security policy server with a legitimate private key can update the security policy.

[0056] In certain embodiments, after decrypting the encrypted security policy to obtain the decrypted security policy, a storage location for the decrypted security policy is determined based on the configuration information of the decrypted security policy; wherein the storage location is a random access memory or a non-volatile memory; and the decrypted security policy is stored according to the storage location. Furthermore, the configuration information may also carry a deletion policy for the decrypted security policy; the deletion policy may be a scheduled deletion policy or a deletion policy after a preset number of restarts; accordingly, the decrypted security policy may be deleted based on the deletion policy. It is understood that in the disclosed embodiments, the application period of the security policy can be flexibly configured using the configuration information of the security policy. In certain embodiments, the configuration information requires that the security policy be stored in the RAM of the embedded device to achieve power failure; or the configuration information can be used to encrypt the security policy and securely store it in the non-volatile memory of the embedded device to achieve long-term validity until the user deletes the security policy through the firmware API (i.e., Application Programming Interface); or the security policy in the RAM and non-volatile memory can be automatically deleted after a limited number of restarts or a limited time period to achieve automatic recovery of the security policy. It should be noted that in the prior art, functions enabled by updating firmware remain enabled and will not be disabled due to power outages or reboots unless the firmware is updated again to disable the function. Therefore, if the firmware is not updated again in a timely manner to disable certain debugging functions, there is a risk of information leakage. The solution provided by the embodiments of the present disclosure allows for flexible policy configuration, automatically restoring security policies without having to update them again, and disabling corresponding debugging functions in a timely manner to avoid information leakage, providing greater flexibility.

[0057] In certain embodiments, when the embedded device is powered on, the legitimacy of the certificate chain in the firmware is checked based on the signature of the root certificate obtained from the fuse register. If the check fails, the normal startup process is terminated and exception handling is entered. If the check passes and a historical decrypted security policy is stored in the non-volatile memory, the historical decrypted security policy is enabled to complete the startup; if the check passes and no historical decrypted security policy is stored in the non-volatile memory, the security policy in the certificate chain is enabled to complete the startup. After the startup is completed, the first preset interface function and the second preset interface function begin to provide services. When the second preset interface function based on its own firmware receives the encrypted security policy and decrypts the encrypted security policy to obtain the decrypted security policy, the decrypted security policy is enabled; wherein, the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed output by the first preset interface.

[0058] It can be seen that the embodiment of the present disclosure first outputs a random string as an encryption seed based on the first preset interface function of its own firmware, and receives the encrypted security policy based on the second preset interface function of its own firmware, decrypts the encrypted security policy to obtain the decrypted security policy, and activates the decrypted security policy; wherein the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed. That is, the embodiment of the present disclosure outputs a random string as an encryption seed, receives the encrypted security policy, decrypts the encrypted security policy to obtain the decrypted security policy, and activates the decrypted security policy through the preset interface function of the embedded device firmware. In this way, updating the security policy through the firmware interface function can effectively avoid device damage caused by firmware updates, and by configuring the policy to be deleted or written to random access memory, the policy can be automatically restored, avoiding the risk of information security leakage caused by failure to update the firmware again in a timely manner, thereby improving the security and flexibility of security policy updates.

[0059] Refer to Figure 2, which is a schematic diagram of the security policy update solution provided by an embodiment of the present disclosure. It is completed by two entities, a security policy server and an embedded device. The security policy server is responsible for encrypting the security policy file and providing the private key and encryption algorithm required for encrypting the security policy file. The embedded device is responsible for providing the encryption seed required for encrypting the policy file, the public key required for decrypting the security policy file, and the decryption algorithm. The firmware of the embedded device provides two APIs, one API is responsible for outputting a random string as an encryption seed, and this API is denoted as FW_API1; the other API is responsible for receiving the encrypted security policy file and decrypting and applying the policy file, and this API is denoted as FW_API2. The specific implementation steps may include:

[0060] (1) The user edits the security policy file through the user terminal device and uploads the updated security policy file to the security policy server. (2) The user operates the embedded device and obtains a random string as an encryption seed through FW_API1. (3) The security policy server uses the security policy file generated in step (1), the encryption seed generated in step (2), and the locally stored private key as input to the encryption algorithm to generate an encrypted security policy file. (4) The user inputs the encrypted security policy file generated in step (3) into the embedded device through FW_API2, or the security policy server directly sends the encrypted security policy file to the embedded device. (5) The embedded device uses the locally stored public key, the encryption seed generated in step (2), and the encrypted security policy file provided in step (4) as input to the decryption module. The output of the decryption module is the security policy file generated in step (1). (6) The embedded device parses and applies the security policy file obtained in step (5). The duration of applying the security policy can be flexibly determined according to the configuration in the policy file. For example, the policy file can be stored in the RAM of the embedded device through configuration requirements to prevent power failure; or the policy file can be encrypted through policy configuration and securely stored in the non-volatile memory of the embedded device to achieve long-term effectiveness until the user deletes the policy file through the firmware API; or the security policy file in the RAM and non-volatile memory can be automatically deleted after a limited number of restarts or a limited time period to achieve automatic recovery of the security policy.

[0061] In the present disclosure, the update of the security policy file is not achieved through the traditional firmware update method, but is achieved using the API provided by the firmware. An encryption seed is generated on the embedded device side as input for the security policy server to encrypt the security policy file. The private key for encrypting the policy file is stored on the security policy server, and the public key for decryption is stored on the embedded device. In this way, since the update of the security policy file is not achieved through the traditional firmware update method, but is achieved using the API provided by the firmware, the risk of device damage caused by firmware update failure and the risk of security policy being unable to be changed before the firmware is updated again are avoided. In addition, the encryption seed generated on the embedded device is required to encrypt the security policy file, which can make the encrypted security policy file applicable only to a specific embedded device within a specific time period, thereby ensuring the security of security policy application. In addition, because the private key for encryption is stored on the security policy server and the public key for decryption is stored on the embedded device, it is guaranteed that only the security policy server with a legitimate private key can update the security policy.

[0062] Referring to Figure 3, which is a flowchart of the startup process of an embedded device provided by an embodiment of the present disclosure, after adopting the security policy update method provided by the present disclosure, under the condition that the fuse-based security solution is activated, the startup process of the embedded device is shown in Figure 3. When the embedded device is powered on, the embedded device reads the fuse to obtain the signature of the root certificate. The embedded device reads the certificate chain in the firmware and uses the root certificate signature obtained from the fuse to verify the legitimacy of the certificate chain in the firmware. If the verification passes, the security policy is read from the certificate chain in the firmware image. If the verification fails, the normal startup process ends and the exception handling process begins. The non-volatile memory is determined to contain a security policy file that was previously decrypted successfully through the FW_API2 interface. If no security policy file has been previously decrypted successfully through the FW_API2 interface, the security policy file read from the firmware image certificate chain is used. If a security policy file has been previously decrypted successfully through the FW_API2 interface, the security policy file read from the non-volatile memory is used and the security policy is applied. Other startup processes are completed according to the security policy, and FW_API1 and FW_API2 begin to provide services. If FW_API2 receives the encrypted security policy file, the embedded device decrypts the received security policy file. If the security policy file is successfully decrypted, the decrypted security policy is applied.

[0063] An embodiment of the present disclosure discloses a security policy update method, which is applied to a security policy server and includes:

[0064] Obtain an encryption seed; the encryption seed is a random string output by a first preset interface function; the first preset interface function is an interface function of the firmware of the embedded device;

[0065] The updated security policy is encrypted based on the encryption seed to obtain an encrypted security policy; the encrypted security policy is received and decrypted by a second preset interface function of the firmware to obtain a decrypted security policy, and the decrypted security policy is enabled in the embedded device.

[0066] In certain embodiments, encrypting the updated security policy based on the encryption seed to obtain the encrypted security policy includes: encrypting the updated security policy based on the encryption seed, a locally stored private key, and calling a preset encryption algorithm to obtain the encrypted security policy.

[0067] Referring to FIG. 4 , FIG. 4 is a diagram illustrating a security policy updating apparatus disclosed in an embodiment of the present disclosure, which is applied to an embedded device and includes:

[0068] The encryption seed output module 11 is configured to output a random string as an encryption seed based on a first preset interface function of its own firmware; and

[0069] The security policy processing module 12 is configured to receive the encrypted security policy based on a second preset interface function of its own firmware, decrypt the encrypted security policy to obtain a decrypted security policy, and enable the decrypted security policy; wherein the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed.

[0070] The disclosed embodiment first outputs a random string as an encryption seed based on the first preset interface function of its own firmware, and receives the encrypted security policy based on the second preset interface function of its own firmware, decrypts the encrypted security policy to obtain the decrypted security policy, and activates the decrypted security policy; wherein the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed. That is, the disclosed embodiment outputs a random string as an encryption seed and receives the encrypted security policy through the preset interface function of the embedded device firmware, and decrypts the encrypted security policy to obtain the decrypted security policy, and activates the decrypted security policy. In this way, by implementing the security policy update through the firmware interface function, it can effectively avoid device damage caused by the firmware update and improve the security of the security policy update.

[0071] In certain embodiments, the security policy processing module 12 further includes a security policy storage submodule, which is configured to, after decrypting the encrypted security policy to obtain the decrypted security policy, determine the storage location of the decrypted security policy based on the configuration information of the decrypted security policy; wherein the storage location is a random access memory or a non-volatile memory; and store the decrypted security policy according to the storage location.

[0072] In certain embodiments, the security policy update device also includes: a startup processing module, configured to, when the embedded device is powered on, perform a legitimacy check on the certificate chain in the firmware based on the signature of the root certificate obtained from the fuse register; if the check passes and a historical decrypted security policy is stored in the non-volatile memory, the historical decrypted security policy is enabled to complete the startup; if the check passes and no historical decrypted security policy is stored in the non-volatile memory, the security policy in the certificate chain is enabled to complete the startup.

[0073] In certain embodiments, the configuration information also carries a deletion policy for the decrypted security policy; the deletion policy is timed deletion or deletion after a preset number of restarts; the security policy update device also includes a policy deletion module, configured to delete the decrypted security policy based on the deletion policy.

[0074] In some embodiments, the device further includes an expiration time setting module configured to set the expiration time of the encryption seed after the encryption seed output module 11 outputs a random string as the encryption seed based on the first preset interface function of its own firmware.

[0075] In some embodiments, the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed and the encryption private key, and the security policy processing module 12 is configured to decrypt the encrypted security policy based on the locally stored public key and the encryption seed to obtain the decrypted security policy.

[0076] In certain embodiments, the encryption seed output module 11 is configured to output a random string as an encryption seed based on a first preset interface function of its own firmware when an instruction sent by the security policy server is obtained, and upload the encrypted seed to the security policy server; the security policy processing module 12 is configured to receive the encrypted security policy returned by the security policy server based on a second preset interface function of its own firmware.

[0077] As shown in Figure 5, an embodiment of the present disclosure discloses an embedded device 20, which includes a processor 21 and a memory 22; wherein the memory 22 is configured to store a computer program; and the processor 21 is configured to execute the computer program to implement the security policy update method described in the present disclosure.

[0078] Regarding the process of the above-mentioned security policy updating method, reference may be made to the corresponding contents disclosed in the aforementioned embodiments, which will not be described in detail here.

[0079] In some embodiments, the memory 22 serves as a carrier for resource storage, which may be a read-only memory, a random access memory, a magnetic disk, or an optical disk, etc. The storage method may be temporary storage or permanent storage.

[0080] In some embodiments, the embedded device 20 also includes a power supply 23, a communication interface 24, an input / output interface 25 and a communication bus 26; wherein, the power supply 23 is configured to provide an operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and an external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present disclosure, and is not specifically limited here; the input / output interface 25 is configured to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0081] An embodiment of the present disclosure further discloses a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the security policy updating method described in the present disclosure.

[0082] Regarding the process of the above-mentioned security policy updating method, reference may be made to the corresponding contents disclosed in the aforementioned embodiments, which will not be described in detail here.

[0083] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the same or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.

[0084] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0085] The security policy update method, apparatus, embedded device, and medium provided by the present disclosure are introduced in detail above. Specific examples are used herein to illustrate the principles and implementation methods of the present disclosure. The description of the above embodiments is only used to help understand the method and core ideas of the present disclosure. At the same time, for those skilled in the art, according to the ideas of the present disclosure, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present disclosure.

Claims

1. A security policy update method, applied to an embedded device, comprising: Outputting a random string as an encryption seed based on a first preset interface function of its own firmware; as well as The second preset interface function based on its own firmware receives the encrypted security policy, decrypts the encrypted security policy to obtain the decrypted security policy, and enables the decrypted security policy; wherein the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed.

2. The security policy updating method according to claim 1, wherein after decrypting the encrypted security policy to obtain the decrypted security policy, the security policy updating method further comprises: Determining a storage location of the decrypted security policy based on the configuration information of the decrypted security policy; wherein the storage location is a random access memory or a non-volatile memory; and The decrypted security policy is stored according to the storage location.

3. The security policy updating method according to claim 1 or 2, wherein before receiving the encrypted security policy based on the second preset interface function of its own firmware, the security policy updating method further comprises: When the embedded device is powered on, the certificate chain in the firmware is verified for legitimacy based on the signature of the root certificate obtained from the fuse register; If the verification passes, and the historical decrypted security policy is stored in the non-volatile memory, the historical decrypted security policy is enabled to complete the startup; If the verification passes and there is no historical decrypted security policy stored in the non-volatile memory, the security policy in the certificate chain is enabled to complete the startup.

4. The security policy updating method according to any one of claims 1 to 3, wherein the configuration information also carries a deletion policy of the decrypted security policy; the deletion policy is scheduled deletion or deletion after a preset number of restarts; The security policy updating method further includes: The decrypted security policy is deleted based on the deletion policy.

5. The security policy updating method according to any one of claims 1 to 4, wherein the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed and the encryption private key, and the decrypting the encrypted security policy to obtain the decrypted security policy comprises: The encrypted security policy is decrypted based on the locally stored public key and the encryption seed to obtain the decrypted security policy.

6. The security policy updating method according to any one of claims 1 to 5, wherein the first preset interface function based on the own firmware outputs a random string as an encryption seed, comprising: When an instruction sent by the security policy server is obtained, a random string is output as an encryption seed based on a first preset interface function of its own firmware, and the encryption seed is uploaded to the security policy server; The second preset interface function based on the own firmware receives the encrypted security policy, including: the second preset interface function based on the own firmware receives the encrypted security policy returned by the security policy server.

7. A security policy update method, applied to a security policy server, comprising: Get encrypted seeds; The encryption seed is a random string output by the first preset interface function; The first preset interface function is an interface function of the firmware of the embedded device; as well as Encrypting the updated security policy based on the encryption seed to obtain the encrypted security policy; The encrypted security policy is received and decrypted by the second preset interface function of the firmware to obtain the decrypted security policy, and the decrypted security policy is enabled in the embedded device.

8. A security policy updating device, applied to an embedded device, comprising: The encrypted seed output module is configured to output the first preset interface function based on its own firmware. Output a random string as encryption seed; as well as The security policy processing module is configured to receive the encrypted security policy based on the second preset interface function of its own firmware, decrypt the encrypted security policy to obtain the decrypted security policy, and enable the decrypted security policy; wherein the encrypted security policy is obtained by encrypting the updated security policy based on the encryption seed.

9. An embedded device comprising a memory and a processor, wherein: The memory is configured to store a computer program; The processor is configured to execute the computer program to implement the security policy updating method according to any one of claims 1 to 6.

10. A computer-readable storage medium for storing a computer program, wherein: When the computer program is executed by a processor, the security policy updating method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Method, device and system for updating security policy

    CN112788593A

  • Security policy updating method and device, embedded equipment and medium

    CN117521080A

  • Security policy encycripting method and IntrusionPrevention System for implementing the method

    KR1020060129618A

  • Method for updating selinux security policy, and terminal

    WO2019084737A1

Cited By

  • Secure starting method and secure starting system of embedded terminal

    CN122241682A

  • Method and system for secure boot of an embedded terminal

    CN122241682B