US2021124820A1PendingUtilityA1

Application program integrity verification method and network device

Assignee: HUAWEI TECH CO LTDPriority: Nov 14, 2014Filed: Nov 5, 2020Published: Apr 29, 2021
Est. expiryNov 14, 2034(~8.3 yrs left)· nominal 20-yr term from priority
G06F 21/565H04L 63/0442G06F 21/56G06F 2212/1052H04L 9/3234G06F 21/57G06F 21/51H04L 63/0435G06F 21/64H04L 63/123G06F 12/1408H04L 63/061H04L 9/3247
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Embodiments of the present disclosure disclose an application program integrity verification method and a network device. The method includes: performing characteristic value calculation on data of an application program when the application program starts, to obtain a first digest of the application program; decrypting a stored digital signature of the application program according to a public key in an embedded key pair to obtain a second digest of the application program, where the digital signature is obtained, according to a private key in the key pair, by signing data of the application program each time the application program is updated, and the key pair is a manufacturer key pair corresponding to the application program; and determining that integrity verification of the application program passes if the first digest and the second digest are the same, otherwise, determining that integrity verification of the application program does not pass.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method performed by a trusted security engine, the method comprising:
 generating, based upon data of an application program, a first digest of the application program when the application program starts up;   decrypting a digital signature of the application program according to a public key in a key pair to obtain a second digest of the application program, wherein the digital signature is obtained, according to a private key in the key pair, by signing data of the application program when the application program has been updated recently, and the key pair is a manufacturer key pair corresponding to the application program; and   determining that integrity verification of the application program passes if the first digest matches the second digest.   
     
     
         2 . The method according to  claim 1 , wherein the second digest is obtained by performing a characteristic value calculation on data of the application program when the application program starts up. 
     
     
         3 . The method according to  claim 2 , wherein the characteristic value calculation on the data of the application program is performed in a static random access memory (SRAM) inside a security central processing unit (CPU) in which the trusted security engine is located. 
     
     
         4 . The method according to  claim 2 , wherein the characteristic value calculation on the data of the application program is performed by using one of: an SM3 cryptographic hash algorithm of Chinese commercial cryptographic hash algorithm standard published by State Cryptography Administration, a secure hash algorithm (SHA), an SHA2, an Rivest-Shamir-Adleman (RSA) algorithm, an ElGamal algorithm, a Fiat-Shamir algorithm, and a Schnorr algorithm. 
     
     
         5 . The method according to  claim 2 , wherein before the performing the characteristic value calculation on the data of the application program, the method further comprises:
 performing the characteristic value calculation on the data of the application program when receiving an update completion instruction, to obtain the second digest of the application program;   signing the second digest according to the private key to obtain the digital signature of the application program; and   storing the digital signature of the application program.   
     
     
         6 . The method according to  claim 1 , wherein the digital signature is read only by the trusted security engine. 
     
     
         7 . The method according to  claim 1 , wherein the digital signature is stored in a trusted non-volatile random access memory (NVRAM). 
     
     
         8 . The method according to  claim 1 , wherein the key pair is embedded in a device including the security engine. 
     
     
         9 . The method according to  claim 1 , wherein the data of the application program comprises a patch including a plurality of data fragments of the application program. 
     
     
         10 . The method according to  claim 1 , wherein the method is performed when patching or updating the application program without interrupting a service related with the application program. 
     
     
         11 . A device, comprising a processor, communicably coupled with a memory storing computer executable program codes, wherein the program codes comprise instructions that, when executed by the processor, cause the processor to:
 generate, based upon data of an application program, a first digest of the application program when the application program starts up;   decrypt a digital signature of the application program according to a public key in a key pair to obtain a second digest of the application program, wherein the digital signature is obtained, according to a private key in the key pair, by signing data of the application program when the application program has been updated recently, and the key pair is a manufacturer key pair corresponding to the application program; and   determine that integrity verification of the application program passes if the first digest matches the second digest.   
     
     
         12 . The device according to  claim 11 , wherein the second digest is obtained by performing a characteristic value calculation on data of the application program when the application program starts up. 
     
     
         13 . The device according to  claim 11 , wherein the processor is a security central processing unit (CPU) comprising a static random access memory (SRAM) involving a security engine. 
     
     
         14 . The device according to  claim 12 , wherein the characteristic value calculation on the data of the application program is performed by using one of: an SM3 cryptographic hash algorithm of Chinese commercial cryptographic hash algorithm standard published by State Cryptography Administration, a secure hash algorithm (SHA), an SHA2, an Rivest-Shamir-Adleman (RSA) algorithm, an ElGamal algorithm, a Fiat-Shamir algorithm, and a Schnorr algorithm. 
     
     
         15 . The device according to  claim 12 , wherein the program codes further comprise instructions that, when executed by the processor, cause the processor to:
 before the performing the characteristic value calculation on the data of the application program, sign the second digest according to the private key to obtain the digital signature of the application program; and   store the digital signature of the application program.   
     
     
         16 . The device according to  claim 11 , wherein the memory comprises a static random access memory (SRAM) involving a security engine. 
     
     
         17 . The device according to  claim 16 , wherein the security engine is in a security central processing unit (CPU). 
     
     
         18 . The device according to  claim 16 , wherein the digital signature is read only by the security engine. 
     
     
         19 . A non-transitory computer-readable storage medium comprising computer executable program codes, wherein the program codes comprise instructions that, when executed by a computer, cause the computer to:
 generate, based upon data of an application program, a first digest of the application program when the application program starts up;   decrypt a digital signature of the application program according to a public key in a key pair to obtain a second digest of the application program, wherein the digital signature is obtained, according to a private key in the key pair, by signing data of the application program when the application program has been updated recently, and the key pair is a manufacturer key pair corresponding to the application program; and   determine that integrity verification of the application program passes if the first digest matches the second digest.   
     
     
         20 . The non-transitory computer-readable storage medium according to  claim 19 , wherein the second digest is obtained by performing a characteristic value calculation on data of the application program when the application program starts up. 
     
     
         21 . The non-transitory computer-readable storage medium according to  claim 20 , further comprising instructions that, when executed by the computer, further cause the computer to:
 before the performing the characteristic value calculation on the data of the application program, sign the second digest according to the private key to obtain the digital signature of the application program; and   store the digital signature of the application program.

Join the waitlist — get patent alerts

Track US2021124820A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.