This invention provides a method and
system for secure
firmware upgrades of
electricity meters. At the
master station, an
upgrade package is constructed, consisting of a structured header,
firmware payload,
authentication tag, and
digital signature. The structured header includes a specially configured extensible
flag field to flexibly define the context parameter combinations, security policies, and compression policies involved in
encryption operations, improving
upgrade compatibility. At the device end, all core security operations, such as signature
verification, key derivation, and decryption
authentication, are executed independently by a secure element, and the keys are never exposed, fundamentally preventing
key leakage and unauthorized tampering. The overall solution, through multiple pre-
verification checks combined with
encryption authentication, digital signatures, and CRC checks, forms an end-to-end, multi-layered
protection system, comprehensively ensuring the
confidentiality, integrity, source credibility, and device compatibility of
firmware upgrades. It effectively resists various attacks and significantly improves the security, reliability, and
operational stability of
electricity meter firmware upgrades.