According to the
firmware security updating method suitable for
the Internet of Things equipment, the integrity and the high efficiency of the updating process are ensured while a user is supported to select a function module combination for customized updating according to needs. According to the method, a chameleon
hash chain is adopted at an update management
server side to construct a cross-module credible
verification mechanism, hash abstracts are generated for functional modules one by one and are linked to form an integrity chain, and
verification failure can be caused by any unauthorized tampering or missing, so that the overall credibility of a customized
firmware update
package is guaranteed. In order to reduce the burden of the resource-constrained device, a
workload verification mechanism is introduced, the
server completes calculation of the
functional module block and generation of verification parameters in advance, and the device end can confirm the validity of the update
package only by quickly verifying the
hash chain and the verification parameters. Meanwhile, in combination with a cache
multiplexing strategy, the generated function module combination update
package is stored and multiplexed, and when a result is found preferentially and the result is not matched, the function module combination update package is dynamically generated and added into the cache.