节点文献
基于双LFSR动态密钥与ECC的以太网Bootloader设计
Design of Ethernet Bootloader based on dual LFSR dynamic key and ECC
【摘要】 提出一种面向微控制器单元的网络Bootloader安全固件升级方案。针对传统TEA(Tiny Encryption Algorithm)算法密钥更新机制弱的问题,设计了一种基于双线性反馈移位寄存器(Linear Feedback Shift Register, LFSR)的动态密钥生成方法,通过引入多项式位异或操作优化单LFSR结构,缓解周期性伪随机问题,并采用双LFSR异步错位异或机制,进一步提升了密钥的随机性与抗破解能力。为确保改进型TEA加密过程中密钥传输的安全性,方案在通信双端预置ECC (Elliptic Curve Cryptography)密钥,实现对对称密钥的安全加密与传输,从而保障整个固件升级流程的机密性与完整性。开发了上位机加密工具链与支持A/B分区的Bootloader程序,通过密钥敏感性分析、雪崩效应测试,验证了方案的安全性和执行上的有效性。
【Abstract】 This paper proposes a secure firmware upgrade scheme for microcontroller units using a network Bootloader. Addressing the weakness of key update mechanism in the traditional TEA algorithm, a dynamic key generation method based on a double linear feedback shift register(LFSR)is designed. By introducing polynomial bit XOR operations to optimize the single LFSR structure, the periodic pseudo-randomness issue is mitigated. Additionally, a double LFSR asynchronous misalignment XOR mechanism is adopted to further enhance the randomness and anti cracking ability of the key. To ensure the security of key transmission in the improved TEA encryption process, elliptic curve cryptography(ECC)keys are pre-deployed on both communicating ends. This enables secure encryption and transmission of the symmetric keys, thereby ensuring the confidentiality and integrity of the entire firmware upgrade process. An upper-level machine encryption toolchain and a Bootloader program that supports A/B partitions are developed. Through key sensitivity analysis and avalanche effect test, the effectiveness of the scheme in security and execution efficiency is verified.
【Key words】 Bootloader; microcontroller; cybersecurity; security encryption;
- 【文献出处】 江苏理工学院学报 ,Journal of Jiangsu University of Technology , 编辑部邮箱 ,2025年04期
- 【分类号】TP393.11;TN918.4
- 【下载频次】12