Method for improving security of system firmware data, and computer device and storage medium

By autonomously predicting partitions in embedded storage devices and writing critical data to the PSLC area, the problem of insufficient system firmware data security is solved, and data security is improved.

WO2026152756A1PCT designated stage Publication Date: 2026-07-23ARTMEM TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ARTMEM TECHNOLOGY CO LTD
Filing Date
2025-09-18
Publication Date
2026-07-23

Smart Images

  • Figure CN2025122268_23072026_PF_FP_ABST
    Figure CN2025122268_23072026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present application are a method for improving the security of system firmware data, and a computer device and a storage medium. The method comprises: acquiring data to be operated; when a preset condition is met, executing first operation processing on the data to be operated, wherein the preset condition comprises at least one of the following: a power-on period being shorter than a preset period, the number of P / E cycles being less than a preset number of P / E cycles, a power-on duration being shorter than a preset power-on duration, and the number of power-on cycles being less than a preset number of power-on cycles; on the basis of the first operation, obtaining first information of the data to be operated and recording a regional position of the data to be operated; and on the basis of the first information and the regional position, writing the data to be operated into the regional position. In the embodiments of the present application, under a preset condition, first information of data to be operated is obtained on the basis of a first operation and a regional position of the data to be operated is recorded, such that the data to be operated is written into the corresponding regional position, thereby realizing autonomous prediction and partitioning, and improving the security of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Methods, computer equipment and storage media for improving system firmware data security Technical Field

[0001] This application relates to the field of firmware data technology, and in particular to a method, computer device and storage medium for improving the security of system firmware data. Background Technology

[0002] In related technologies, the firmware data of embedded storage devices is generally stored within the physical blocks of PSLC (Pseudo-Level Cell). However, the system firmware data on the host side cannot be guaranteed to be stored within PSLC. Currently, embedded storage devices based on MLC (Multi-Level Cell Flash), TLC (Three-Level Cell Flash), or QLC (Quadruple-Level Cell Flash) offer a feature to partition enhancement partitions. Currently, the physical flash area for storing enhancement partition data is fixed in PSLC mode. If the host does not set up enhancement partitions for the storage device, system data will be stored together with regular data, resulting in relatively poor system data security. Summary of the Invention

[0003] This application aims to address at least one of the technical problems existing in the prior art. To this end, this application proposes a method, computer device, and storage medium for improving system firmware data security, aiming to achieve autonomous predictive partitioning and improve data security.

[0004] In a first aspect, embodiments of this application provide a method for improving the security of system firmware data, including:

[0005] Get the data to be operated on;

[0006] When preset conditions are met, the first operation processing is performed on the data to be operated, wherein the preset conditions include at least one of the following: power-on cycle is less than preset cycle, P / E count is less than preset P / E count, power-on time is less than preset power-on time, and power-on count is less than preset power-on count.

[0007] The first information of the data to be operated and the location of the region of the data to be operated are obtained according to the first operation;

[0008] The data to be operated on is written to the region location based on the first information and the region location.

[0009] According to some embodiments of this application, after performing the first operation on the data to be operated on, the method further includes:

[0010] When the logical address for performing the first operation is from the first logical address to the second logical address, the region location of the data to be operated is the first region, and the power-on cycle for performing the first operation is the first power-on cycle, wherein the first region is from the first logical address to the second logical address.

[0011] According to some embodiments of this application, the method further includes:

[0012] Perform a second operation on the data to be operated on;

[0013] The second information of the data to be operated is obtained according to the second operation, and the second region position of the data to be operated is recorded, wherein the second region position of the data to be operated is the second region;

[0014] When the overlap between the second region and the first region is greater than or equal to a first preset value, the second information of the data to be operated is the same as the first information of the data to be operated.

[0015] According to some embodiments of this application, the method further includes:

[0016] The first region is detected. When the second operation is performed within the first region and the logical address of the second operation is from the third logical address to the fourth logical address, the second region is obtained as the third logical address to the fourth logical address and the power-on time of the second operation is the first power-on time.

[0017] According to some embodiments of this application, the method further includes:

[0018] Perform a third operation on the data to be operated on;

[0019] The third information of the data to be operated is obtained according to the third operation, and the third region position of the data to be operated is recorded, wherein the third region position of the data to be operated is the third region;

[0020] When the third operation is not performed in the third region, the third information of the data to be operated is the same as the first information of the data to be operated.

[0021] According to some embodiments of this application, during the second power-on cycle and the first power-on time, the method further includes:

[0022] The second region is detected. When the third operation is performed within the second region and the logical address of the third operation is from the fifth logical address to the sixth logical address, the third region is found to be from the fifth logical address to the sixth logical address.

[0023] According to some embodiments of this application, when the number of power-on cycles of the data to be operated is greater than a first preset number of power-on cycles and less than a second preset number of power-on cycles, wherein the second preset number of power-on cycles is greater than the first preset number of power-on cycles, the method further includes:

[0024] When the location of the data to be operated is the target location and the power-on time of the data to be operated is less than the second preset power-on time, update the target location.

[0025] When the location of the data to be operated is the target location and the power-on time of the data to be operated is greater than or equal to the second preset power-on time, the update of the target location ends.

[0026] According to some embodiments of this application, it also includes:

[0027] If the number of power-on cycles of the data to be operated is less than the first preset number of power-on cycles or greater than the second preset number of power-on cycles, the data in the area location will be recycled.

[0028] Secondly, embodiments of this application provide a computer device, including:

[0029] At least one memory;

[0030] At least one processor;

[0031] At least one computer program;

[0032] The at least one computer program is stored in the at least one memory, and the at least one processor executes the at least one computer program to implement the method for improving system firmware data security as described in the first aspect above.

[0033] Thirdly, embodiments of this application provide a computer-readable storage medium storing a computer program for causing a computer to execute the method for improving system firmware data security described in the first aspect.

[0034] According to the technical solution of the embodiments of this application, at least the following beneficial effects are achieved: acquiring data to be operated; when preset conditions are met, performing a first operation on the data to be operated, wherein the preset conditions include at least one of the following: power-on cycle less than a preset cycle, P / E count less than a preset P / E count, power-on time less than a preset power-on time, and power-on count less than a preset power-on count; obtaining first information of the data to be operated and recording the region location of the data to be operated according to the first operation; writing the data to be operated to the region location according to the first information and the region location. The embodiments of this application, by obtaining the first information of the data to be operated according to the first operation and recording the region location of the data to be operated within preset conditions, write the data to be operated to the corresponding region location, thereby automatically writing key data into the PSLC area, achieving autonomous prediction and partitioning, and improving data security. Attached Figure Description

[0035] The accompanying drawings are used to provide a further understanding of the technical solutions of this application and constitute a part of the specification. They are used together with the embodiments of this application to explain the technical solutions of this application and do not constitute a limitation on the technical solutions of this application.

[0036] Figure 1 is a flowchart illustrating a method for improving system firmware data security according to an embodiment of this application;

[0037] Figure 2 is a flowchart illustrating a method for performing a second operation according to an embodiment of this application;

[0038] Figure 3 is a flowchart illustrating a method for performing a third operation according to an embodiment of this application;

[0039] Figure 4 is a schematic diagram of the area of ​​a method for improving system firmware data security according to an embodiment of this application;

[0040] Figure 5 is an overall flowchart of a method for improving system firmware data security provided in an embodiment of this application;

[0041] Figure 6 is a schematic diagram of the hardware structure of a computer device provided in one embodiment of this application. Detailed Implementation

[0042] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.

[0043] In the description of this application, it should be understood that the orientation descriptions, such as up, down, front, back, left, right, etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.

[0044] In the description of this application, "several" means one or more, "more than" means two or more, "greater than," "less than," and "exceeding" are understood to exclude the stated number, while "above," "below," and "within" are understood to include the stated number. The use of "first" and "second" in the description is merely for distinguishing technical features and should not be construed as indicating or implying relative importance, or implicitly indicating the number of indicated technical features, or implicitly indicating the order of the indicated technical features.

[0045] In the description of this application, unless otherwise expressly defined, terms such as "setup," "installation," and "connection" should be interpreted broadly, and those skilled in the art can reasonably determine the specific meaning of the above terms in this application in conjunction with the specific content of the technical solution.

[0046] First, let's analyze some of the terms used in this application:

[0047] Flash (Non-Volatile Memory): Flash memory retains its stored data even when power is off. It supports fast read and write operations, making it ideal for auxiliary storage in computers and other devices. Each cell in a Flash memory module has a limited number of erase / write cycles, typically between several thousand and tens of thousands. Flash memory is usually erased and written in blocks. This means that when updating data, the entire block must be erased before new data can be written.

[0048] Block storage is a data storage method where data is stored as blocks or sectors and can be accessed through unique identifiers (such as logical unit numbers, LUNs). Block storage allows users to manipulate storage volumes like hard drives, creating, deleting, and modifying files.

[0049] Pslc (Pseudo-Single Level Cell): This is a NAND flash memory technology that uses special control algorithms and management methods to simulate the working mode of SLC (Single Level Cell) memory cells on MLC (Multi-Level Cell) or TLC (Triple-Level Cell) flash memory chips.

[0050] P / E cycles (Program / Erase cycles): These refer to the number of programming and erasing cycles performed on the flash memory in a solid-state drive (SSD). Each time the entire SSD is programmed (i.e., written to) and erased once, it is counted as one P / E cycle.

[0051] Embedded storage devices typically store their own firmware data within the PSLC physical block. However, the host's system firmware data cannot be guaranteed to be stored within the PSLC. Currently, embedded storage devices based on MLC, TLC, or QLC offer a feature to create enhancement partitions. These enhancement partitions are currently stored in a fixed PSLC physical flash area. If the host does not configure enhancement partitions on the storage device, system data will be stored alongside regular user data. During garbage collection (GC), this data will be moved to non-PSLC physical blocks, resulting in relatively lower system data security.

[0052] The method, computer device, and storage medium for improving system firmware data security provided in this application are specifically described through the following embodiments. First, the method for improving system firmware data security in this application embodiment is described.

[0053] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) refers to the theories, methods, technologies, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0054] Foundational technologies for artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.

[0055] The method, computer device, and storage medium for improving system firmware data security provided in this application relate to the field of firmware data technology. The method for improving system firmware data security provided in this application can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, etc.; the server can be configured as an independent physical server, a server cluster composed of multiple physical servers, or a distributed system; it can also be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the method for improving system firmware data security, etc., but is not limited to the above forms.

[0056] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0057] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent will be obtained first. Furthermore, the collection, use, and processing of this data will comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user will be obtained through pop-ups or redirects to confirmation pages. Only after obtaining the user's separate permission or consent will the necessary user-related data for the normal operation of the embodiments of this application be obtained.

[0058] Please refer to Figure 1. Figure 1 is a flowchart illustrating a method for improving system firmware data security according to an embodiment of this application. As shown in Figure 1, the method for improving system firmware data security according to an embodiment of this application includes, but is not limited to, steps S110-S140. Each step will be described in turn below.

[0059] Step S110: Obtain the data to be operated on;

[0060] Step S120: When the preset conditions are met, the first operation processing is performed on the data to be operated. The preset conditions include at least one of the following: the power-on cycle is less than the preset cycle, the number of P / E cycles is less than the preset number of P / E cycles, the power-on time is less than the preset power-on time, and the number of power-on cycles is less than the preset number of power-on cycles.

[0061] Step S130: Obtain the first information of the data to be operated on and record the region location of the data to be operated on according to the first operation;

[0062] Step S140: Write the data to be operated on into the region location according to the first information and the region location.

[0063] In one embodiment, after the system acquires the data to be operated on, it checks whether preset conditions are met. These preset conditions include a power-on cycle shorter than a preset cycle, a P / E count shorter than a preset P / E count, a power-on time shorter than a preset power-on time, and a power-on count shorter than a preset power-on count. When any one of these conditions is met, the system performs a first operation on the acquired data. After performing the first operation, the system obtains the information of the data to be operated on and records the location information of the storage area where the data to be operated should be written. The system then writes the processed data to the previously recorded location. The system can autonomously predict and partition data based on the first operation, improving data security.

[0064] In one embodiment, after performing a first operation on the data to be operated, when the logical address of the first operation is from the first logical address to the second logical address, the region location of the data to be operated is obtained as the first region and the power-on cycle of the first operation is obtained as the first power-on cycle, wherein the first region is from the first logical address to the second logical address.

[0065] Referring to Figure 4, Figure 4 is a schematic diagram of the area of ​​a method for improving system firmware data security according to an embodiment of this application.

[0066] In one embodiment, within the first 5 power-ups recorded, the maximum P / E count of the block in the flash memory is less than 3. Within 5 minutes of power-up, a sequential write from logical address A to logical address B occurs. The storage device firmware records this event as occurring on the 3rd power-up, with the write area being from A to B.

[0067] Please refer to Figure 2, which is a flowchart illustrating a method for performing a second operation according to an embodiment of this application. As shown in Figure 2, this application provides a method for improving the security of system firmware data, including but not limited to steps S210-S230, which will be described in turn below.

[0068] Step S210: Perform the second operation on the data to be operated on;

[0069] Step S220: Obtain the second information of the data to be operated according to the second operation and record the second region position of the data to be operated, wherein the second region position of the data to be operated is the second region;

[0070] Step S230: When the overlap between the second region and the first region is greater than or equal to the first preset value, the second information of the data to be operated is the same as the first information of the data to be operated.

[0071] In one embodiment, the system processes the data that has already undergone the first operation a second time. After the second operation is completed, the system obtains second information about the data and records the location of the second region of the data. The system compares the degree of overlap between the second region and the first region. If the degree of overlap is greater than or equal to a preset threshold (first preset value), it means that the two regions have enough common parts, and the second information is the same as the first information.

[0072] It should be noted that, within the predetermined power-on time, predictions are made based on read and write behavior. This involves determining whether a large number of read operations hit the specified record area. If so, the storage device determines that the host is powering on and reading system data, further confirming that the recorded area stores host system data.

[0073] In one embodiment, a first region is detected. When a second operation is performed within the first region and the logical address of the second operation is from the third logical address to the fourth logical address, the second region is determined to be from the third logical address to the fourth logical address, and the power-on time for performing the second operation is determined to be the first power-on time.

[0074] Referring to Figure 4, Figure 4 is a schematic diagram of the area of ​​a method for improving system firmware data security according to an embodiment of this application.

[0075] In one embodiment, during the subsequent power-on cycles, under predetermined conditions, read behavior occurring between regions A and B is monitored and recorded, as well as records of the aforementioned write events. During the 4th to 6th power-on cycles, a read operation is detected between regions A and B within 1 minute of power-on, with a maximum read range of C to D. The storage device records the read region as C to D.

[0076] Please refer to Figure 3, which is a flowchart illustrating a method for performing a third operation according to an embodiment of this application. As shown in Figure 3, this application provides a method for improving the security of system firmware data, including but not limited to steps S310-S330, which will be described in turn below.

[0077] Step S310: Perform the third operation on the data to be operated on;

[0078] Step S320: Obtain the third information of the data to be operated on and record the third region position of the data to be operated on according to the third operation, wherein the third region position of the data to be operated on is the third region;

[0079] Step S330: When the third operation is not performed in the third region, the third information of the data to be operated is the same as the first information of the data to be operated.

[0080] In one embodiment, the system performs a third processing on the data that has already undergone the first and second operations. After the third operation is completed, the system obtains new information about the data (third information). The system also records the data in a third area on the storage medium. The system compares whether the third operation has been performed in the third area. If the third operation has not been performed in the third area, the system concludes that the third information is the same as the first information.

[0081] In one embodiment, the logical area of ​​this record is determined based on the write operation behavior. If it is not overwritten, it meets the read-only characteristics of the system partition and is further confirmed as host system data.

[0082] In one embodiment, during the second power-on cycle and the first power-on time, the second region is detected. When the third operation is performed within the second region and the logical address of the third operation is from the fifth logical address to the sixth logical address, the third region is obtained as from the fifth logical address to the sixth logical address.

[0083] Referring to Figure 4, Figure 4 is a schematic diagram of the area of ​​a method for improving system firmware data security according to an embodiment of this application.

[0084] In one embodiment, records of the aforementioned write and read events have been generated. Read events can be repeatedly detected (read operations can still be detected between regions A and B within one minute of power-on and during the next three power-on cycles, with a maximum read range of C to D). Furthermore, regions within C to D that have not been overwritten are monitored as E to F. The storage device records these unoverwritten regions as E to F (unoverwritten events).

[0085] In one embodiment, when the number of power-on cycles for the data to be operated is greater than a first preset number of power-on cycles but less than a second preset number of power-on cycles, wherein the second preset number of power-on cycles being greater than the first preset number of power-on cycles includes:

[0086] When the location of the data to be operated is the location of the target area and the power-on time of the data to be operated is less than the second preset power-on time, update the target area location.

[0087] When the location of the data to be operated is the same as the target location and the power-on time of the data to be operated is greater than or equal to the second preset power-on time, the update of the target location ends.

[0088] In one embodiment, when the data to be operated on has a regional location, the system first checks whether the number of power-on cycles of the data to be operated on falls between a first preset number of power-on cycles and a second preset number of power-on cycles. If the number of power-on cycles is greater than the first preset number of power-on cycles but less than the second preset number of power-on cycles, the system proceeds to the next step. The system then checks whether the power-on time of the data to be operated on is less than the second preset power-on time. If the regional location of the data to be operated on is the target regional location and the power-on time is less than the second preset power-on time, the system updates the target regional location. The system can adopt different data processing strategies at different stages of device use, thereby improving efficiency and reliability.

[0089] In one embodiment, when the data to be operated on has a region location, the system first checks whether the number of power-on times of the data to be operated on falls between a first preset number of power-on times and a second preset number of power-on times. If the number of power-on times is greater than the first preset number of power-on times and less than the second preset number of power-on times, the system will proceed to the next step of judgment. The system then checks whether the power-on time of the data to be operated on is greater than or equal to the second preset power-on time. If the region location of the data to be operated on is the target region location and the power-on time is greater than or equal to the second preset power-on time, the system will end the update of the target region location.

[0090] In one embodiment, when the number of power-on cycles of the data to be operated is less than a first preset number of power-on cycles or greater than a second preset number of power-on cycles, the data of the area location is recycled.

[0091] In one embodiment, the system sets two thresholds: a first preset number of power-ups and a second preset number of power-ups, where the second preset number of power-ups is greater than the first preset number of power-ups. These two thresholds define a range for a "normal" number of power-ups. The system monitors the number of power-ups of the data to be operated on in real time. This monitoring can be achieved through a hardware counter. Each time the device is powered on, the counter increments. When the number of power-ups is detected to exceed the preset range, the system will perform a data recycling operation on the data in the area where the data to be operated is located.

[0092] Referring to Figure 5, which is an overall flowchart of a method for improving system firmware data security according to an embodiment of this application, the method includes, but is not limited to, steps S5001-S5014, which will be described in detail below.

[0093] Step S5001: Begin;

[0094] Step S5002: Determine if there are no records in the target interval. If yes, proceed to step S5003; otherwise, proceed to step S5009.

[0095] Step S5003: Determine whether the number of power-on cycles is less than the set threshold. If yes, proceed to step S5004; otherwise, proceed to step S5014.

[0096] Step S5004: Determine whether the maximum number of PEs is less than the set threshold. If yes, proceed to step S5005; otherwise, proceed to step S5014.

[0097] Step S5005: Determine whether it is a sequential write. If yes, proceed to step S5006; otherwise, proceed to step S5014.

[0098] Step S5006: Determine whether the power-on time is less than the set threshold. If yes, proceed to step S5007; otherwise, proceed to step S5014.

[0099] Step S5007: Record or update the starting address and target range;

[0100] Step S5008: Record the number of power-on cycles N;

[0101] Step S5009: Determine whether the number of power-on times is less than the set threshold N+i. If yes, proceed to step S5010; otherwise, proceed to step S5013.

[0102] Step S5010: Determine whether the read / write operation hits the target range of the record. If yes, proceed to step S5011; otherwise, proceed to step S5010.

[0103] Step S5011: Determine whether the power-on time is less than the set threshold 2. If yes, proceed to step S5012; otherwise, proceed to step S5014.

[0104] Step S5012: Update the target range based on read and write operations;

[0105] Step S5013: Recycle the data in the target range to the block, mark the attributes, and it will not participate in recycling again in the future;

[0106] Step S5014, End.

[0107] In one embodiment, it is first determined whether there is no target interval record. If there is no target interval record, it is determined whether the number of power-on cycles is less than a set threshold. If there is a target interval record, it is determined whether the number of power-on cycles is less than a set threshold N+i. If the number of power-on cycles is less than the set threshold, it is further determined whether the maximum PE count is less than the set threshold. If the number of power-on cycles is greater than or equal to the set threshold, the process ends. If the maximum PE count is less than the set threshold, it is further determined whether it is a sequential write. If the maximum PE count is greater than or equal to the set threshold, the process ends. If it is determined to be a sequential write, it is further determined whether the power-on time is less than a set threshold. If the power-on time is less than the set threshold, the starting address and target interval are recorded or updated. If the power-on time is greater than or equal to the set threshold, the process ends. If the value is not met, the process ends. After recording or updating the starting address and target range, record the number of power-on operations N. If the number of power-on operations is less than the set threshold N+i, determine whether the read / write operation hits the recorded target range. If the number of power-on operations is greater than or equal to the set threshold N+i, reclaim the data in the target range to the block, mark the attribute, and it will not participate in the reclamation again. If the read / write operation hits the recorded target range, continue to determine whether the power-on time is less than the set threshold 2. If the read / write operation does not hit the recorded target range, re-determine the time. If the power-on time is less than the set threshold 2, update the target range according to the read / write operation, and then determine whether the read / write operation hits the recorded target range. If the power-on time is greater than or equal to the set threshold 2, the process ends.

[0108] This application also provides a computer device comprising: at least one memory, at least one processor, and at least one computer program. The at least one computer program is stored in the at least one memory, and the at least one processor executes the at least one computer program to implement any of the methods for improving system firmware data security described in the above embodiments. This computer device can be any smart terminal, including tablet computers, in-vehicle computers, etc.

[0109] Referring to Figure 6, which illustrates the hardware structure of a computer device according to another embodiment, the computer device includes:

[0110] The processor 610 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.

[0111] The memory 620 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 620 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 620 and is called and executed by the processor 610 to improve the system firmware data security method of the embodiments of this application.

[0112] The input / output interface 630 is used to realize information input and output;

[0113] The communication interface 640 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0114] Bus 650 transmits information between various components of the device (e.g., processor 610, memory 620, input / output interface 630, and communication interface 640);

[0115] The processor 610, memory 620, input / output interface 630 and communication interface 640 are connected to each other within the device via bus 650.

[0116] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for improving the security of system firmware data.

[0117] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0118] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0119] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0120] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0121] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0122] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0123] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0124] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0125] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0126] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0127] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0128] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and spirit of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for improving the security of system firmware data, characterized in that, include: Get the data to be operated on; When preset conditions are met, the first operation processing is performed on the data to be operated, wherein the preset conditions include at least one of the following: power-on cycle is less than preset cycle, P / E count is less than preset P / E count, power-on time is less than preset power-on time, and power-on count is less than preset power-on count. The first information of the data to be operated and the location of the region of the data to be operated are obtained according to the first operation; The data to be operated on is written to the region location based on the first information and the region location.

2. The method according to claim 1, characterized in that, After performing the first operation on the data to be operated on, the method further includes: When the logical address for performing the first operation is from the first logical address to the second logical address, the region location of the data to be operated is the first region, and the power-on cycle for performing the first operation is the first power-on cycle, wherein the first region is from the first logical address to the second logical address.

3. The method according to claim 2, characterized in that, The method further includes: Perform a second operation on the data to be operated on; The second information of the data to be operated is obtained according to the second operation, and the second region position of the data to be operated is recorded, wherein the second region position of the data to be operated is the second region; When the overlap between the second region and the first region is greater than or equal to a first preset value, the second information of the data to be operated is the same as the first information of the data to be operated.

4. The method according to claim 3, characterized in that, The method further includes: The first region is detected. When the second operation is performed within the first region and the logical address of the second operation is from the third logical address to the fourth logical address, the second region is obtained as the third logical address to the fourth logical address and the power-on time of the second operation is the first power-on time.

5. The method according to claim 4, characterized in that, The method further includes: Perform a third operation on the data to be operated on; The third information of the data to be operated is obtained according to the third operation, and the third region position of the data to be operated is recorded, wherein the third region position of the data to be operated is the third region; When the third operation is not performed in the third region, the third information of the data to be operated is the same as the first information of the data to be operated.

6. The method according to claim 5, characterized in that, During the second power-on cycle and the first power-on time, the method further includes: The second region is detected. When the third operation is performed within the second region and the logical address of the third operation is from the fifth logical address to the sixth logical address, the third region is found to be from the fifth logical address to the sixth logical address.

7. The method according to claim 1, characterized in that, When the number of power-on cycles for the data to be operated is greater than a first preset number of power-on cycles but less than a second preset number of power-on cycles, wherein the second preset number of power-on cycles is greater than the first preset number of power-on cycles, the method further includes: When the location of the data to be operated is the target location and the power-on time of the data to be operated is less than the second preset power-on time, update the target location. When the location of the data to be operated is the target location and the power-on time of the data to be operated is greater than or equal to the second preset power-on time, the update of the target location ends.

8. The method according to claim 1, characterized in that, Also includes: If the number of power-on cycles of the data to be operated is less than the first preset number of power-on cycles or greater than the second preset number of power-on cycles, the data in the area location will be recycled.

9. A computer device, characterized in that, include: At least one memory; At least one processor; At least one computer program; The at least one computer program is stored in the at least one memory, and the at least one processor executes the at least one computer program to implement the method as described in any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program for causing a computer to perform the method as described in any one of claims 1 to 8.