IP Library › Granted Patent US 11,829,479
Granted Patent B2
US 11,829,479 · App. 17/125,017 · Granted Nov 28, 2023

Firmware security verification method and device

Inventor: Longtao Gao (Shanghai, CN)
Assignee: INNOGRIT TECHNOLOGIES CO., LTD.
G06F21/572G06F21/602H04L9/30H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,829,479
App. No.
17/125,017
Granted
Nov 28, 2023
Kind
B2
Abstract

The present disclosure relates to a firmware security verification method and device, including a processor and a read-only memory for storing instructions executable by the processor. While executing the instructions, the processor implements the following steps: acquiring firmware data and a digital signature; verifying the digital signature with a pre-stored public key; and running the firmware data upon determining that the digital signature passes the verification. With the firmware security verification method and device provided in embodiments of the present disclosure, the security of the firmware data can be acquired before the running of firmware.

Claims (51)

1. A firmware security verification device, comprising:

a processor, and

a read-only memory for storing processor executable instructions, which when executed by the processor, cause the processor to:

acquire firmware data and a digital signature generated by encrypting the firmware data, a public key and a private key including:

encrypting the firmware data to generate encrypted firmware data;

encrypting a user identification, elliptic curve parameters and the public key to generate a first intermediate value;

encrypting the encrypted firmware data and the first intermediate value to generate a second intermediate value; and

encrypting the second intermediate value and the private key to generate the digital signature;

verify the digital signature with a pre-stored public key set in a one-time programmable (OTP) memory; and

in the case of determining that the digital signature passes the verification, run the firmware data.

2. The firmware security verification device of claim 1 , further comprising a one-time programmable memory, the one-time programmable memory is configured to store the public key.

3. The firmware security verification device of claim 2 , wherein the one-time programmable memory is further configured to store processor executable instructions, the processor is configured to execute the instructions to:

in the case of monitoring that the processor receives a power supply or receives new firmware data, start execution of the instructions stored in the read-only memory.

4. The firmware security verification device of claim 1 , wherein acquiring the firmware data and the digital signature for public key by the processor includes:

reading the firmware data and the digital signature from a programmable read-only memory, wherein the programmable read-only memory is electrically connected to the processor.

5. The firmware security verification device of claim 1 , wherein verifying the digital signature for public key by the processor with the pre-stored public key includes:

acquiring the public key used for verifying the digital signature;

in the case of determining that the public key used for verifying the digital signature matches the pre-stored public key, determining a digital signature to be verified according to the firmware data and the public key; and

in the case of determining that the digital signature to be verified matches the digital signature, determining that the digital signature passes the verification.

6. The firmware security verification device of claim 1 , wherein verifying the digital signature by the processor with the pre-stored public key includes:

determining an encryption algorithm used to generate the digital signature;

performing a self-test on the encryption algorithm; and

in the case of determining that a result from the self-test is correct, verifying the digital signature with the pre-stored public key.

7. The firmware security verification device of claim 1 , wherein before acquiring the firmware data and the digital signature, the processor is further configured to:

turn off physical interfaces with debug functions on the processor.

8. The firmware security verification device of claim 1 , wherein the firmware data includes data for a new firmware or upgrading data for an original firmware.

9. An electronic apparatus, comprising the firmware security verification device of claim 1 .

10. A firmware security verification method, comprising:

acquiring firmware data and a digital signature generated by encrypting the firmware data, a public key and a private key including:

encrypting the firmware data to generate encrypted firmware data;

encrypting a user identification, elliptic curve parameters and the public key to generate a first intermediate value;

encrypting the encrypted firmware data and the first intermediate value to generate a second intermediate value; and

encrypting the second intermediate value and the private key to generate the digital signature;

verifying the digital signature with a pre-stored public key set in a one-time programmable (OTP) memory; and

in the case of determining that the digital signature passes the verification, running the firmware data.

11. The firmware security verification method of claim 10 , wherein acquiring the firmware data and the digital signature for public key includes:

reading the firmware data and the digital signature from a programmable read-only memory.

12. The firmware security verification method of claim 10 , wherein verifying the digital signature for public key with the pre-stored public key includes:

acquiring the public key used for verifying the digital signature;

in the case that the public key used for verifying the digital signature matches the pre-stored public key, determining a digital signature to be verified according to the firmware data and the public key; and

in the case of determining that the digital signature to be verified matches the digital signature, determining that the digital signature passes the verification.

13. A non-transient computer read-only storage medium, when instructions in the storage medium are executed by a processor, the instructions cause the processor to perform the method of claim 10 .

14. A firmware data encryption method, comprising:

encrypting firmware data, a public key and a private key with an asymmetrical encryption algorithm to generate a digital signature including:

encrypting the firmware data to generate encrypted firmware data;

encrypting a user identification, elliptic curve parameters and the public key to generate a first intermediate value;

encrypting the encrypted firmware data and the first intermediate value to generate a second intermediate value; and

encrypting the second intermediate value and the private key to generate the digital signature; and

sending the firmware data, the public key, and the digital signature to be verified with a pre-stored public key set in a one-time programmable (OTP) memory.

15. A firmware data encryption device, comprising:

a processor and a memory for storing processor executable instructions, while executing the instructions, the processor is configured to perform the method of claim 14 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2020
From: GAO, LONGTAO
To: INNOGRIT TECHNOLOGIES CO., LTD.
Reel/Frame 054682/0075 →
Priority Claims (1)
CN 202010934468.3 · Sep 8, 2020 · national
Continuity (1)
Related Publication 20220075873A1 · Mar 10, 2022