Patents by Inventor Haiwu Chen
Haiwu Chen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12585781Abstract: A secure boot method. The method may be performed by a communication device. According to the method, the communication device can flexibly perform secure boot by using different cryptographic algorithms based on different security requirements, to ensure security of the communication device. The communication device may obtain external secure boot code (ESBC). The ESBC includes a code segment of a first cryptographic algorithm. After the ESBC is obtained, the communication device may perform an integrity check on the ESBC, and after the integrity check on the ESBC succeeds, verify a signature of next-level software based on the first cryptographic algorithm. When a cryptographic algorithm used by the communication device cannot meet a security requirement, the ESBC may be obtained, and the first cryptographic algorithm included in the ESBC is used to perform the secure boot, to meet the security requirement.Type: GrantFiled: September 19, 2023Date of Patent: March 24, 2026Assignee: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Haiwu Chen, Honghong Dong, Bin Cao
-
Publication number: 20250165348Abstract: A processor, a method for obtaining information, a board, and a network device are provided. The processor includes a control circuit, a first register, and a cache, and the processor is communicatively connected to a reset-safe non-volatile storage medium. The control circuit is configured to: obtain a reset indication, where the reset indication is an indication generated when the processor runs abnormally; obtain related information of the processor based on the reset indication, where the related information includes at least one of register information of the first register or data stored in the cache; and store the related information in the reset-safe non-volatile storage medium. When the processor runs abnormally, the control circuit inside the processor can obtain the related information of the processor based on the reset indication, so that reliability of a manner of obtaining the related information is high.Type: ApplicationFiled: January 16, 2025Publication date: May 22, 2025Inventors: Youqing LIAO, Haiwu CHEN, Chengxu GAI
-
Patent number: 12294657Abstract: Embodiments of this application disclose a software integrity protection method and apparatus. A first device obtains a first software package, where the first software package includes a first signature made by a first party for a second software package by using a first private key; and the first device performs a signing operation on the first software package by using a second private key, to obtain a third software package including a second signature, where the first private key is controlled by the first party, and the second private key is controlled by a second party. The first device sends the third software package to a second device. The second device verifies the first signature and the second signature in the third software package respectively based on a first public key and a second public key that are prestored, to obtain a verification result.Type: GrantFiled: April 1, 2022Date of Patent: May 6, 2025Assignee: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Bin Cao, Haiwu Chen, Yan Chen, Bo Wang
-
Patent number: 12056260Abstract: A software verification method and apparatus are provided. The method includes: reading flag information, where the flag information is used to indicate a target digital certificate; selecting one of a plurality of digital certificates as a target digital certificate based on the flag information, where the plurality of digital certificates include a first digital certificate and a second digital certificate, and the target digital certificate includes a cryptographic resource; and verifying software deployed on a device based on the cryptographic resource. Using the foregoing technical solution can ensure continuity of the software verification service in the device.Type: GrantFiled: April 22, 2022Date of Patent: August 6, 2024Assignee: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Haiwu Chen, Bin Cao, Mengnan Zhang, Jianying Qian
-
Patent number: 12047388Abstract: A hardware detection method includes sending first verification data to a physical carrier, where the physical carrier carries a plurality of pieces of hardware; receiving a ciphertext and binding relationship information from the physical carrier, where the ciphertext is obtained after at least two of the pieces of hardware respectively encrypt the first verification data using respective keys, and where the binding relationship information indicates a binding relationship between the at least two pieces of hardware; verifying the ciphertext and the binding relationship information; and determining security of the at least two pieces of hardware based on a verification result.Type: GrantFiled: January 21, 2022Date of Patent: July 23, 2024Assignee: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Mengnan Zhang, Lizhong Qiao, Haiwu Chen
-
Patent number: 12021982Abstract: This application discloses a method for performing secure boot based on a redundant cryptographic algorithm and a device. The method includes: obtaining first indication information and second indication information, and updating first baseline information based on the first indication information and the second indication information. The first indication information uniquely identifies a first cryptographic algorithm, the second indication information is used to instruct a network device to update the first cryptographic resource baseline information stored in a secure storage entity, and the first cryptographic resource baseline information is used to perform integrity verification on a first cryptographic resource used by the network device in a secure boot process.Type: GrantFiled: November 21, 2022Date of Patent: June 25, 2024Assignee: Huawei Technologies Co., Ltd.Inventors: Haiwu Chen, Mengnan Zhang, Bin Cao
-
Publication number: 20240005007Abstract: A secure boot method. The method may be performed by a communication device. According to the method, the communication device can flexibly perform secure boot by using different cryptographic algorithms based on different security requirements, to ensure security of the communication device. The communication device may obtain external secure boot code (ESBC). The ESBC includes a code segment of a first cryptographic algorithm. After the ESBC is obtained, the communication device may perform an integrity check on the ESBC, and after the integrity check on the ESBC succeeds, verify a signature of next-level software based on the first cryptographic algorithm. When a cryptographic algorithm used by the communication device cannot meet a security requirement, the ESBC may be obtained, and the first cryptographic algorithm included in the ESBC is used to perform the secure boot, to meet the security requirement.Type: ApplicationFiled: September 19, 2023Publication date: January 4, 2024Applicant: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Haiwu CHEN, Honghong DONG, Bin CAO
-
Publication number: 20230095143Abstract: This application discloses a method for performing secure boot based on a redundant cryptographic algorithm and a device. The method includes: obtaining first indication information and second indication information, and updating first baseline information based on the first indication information and the second indication information. The first indication information uniquely identifies a first cryptographic algorithm, the second indication information is used to instruct a network device to update the first cryptographic resource baseline information stored in a secure storage entity, and the first cryptographic resource baseline information is used to perform integrity verification on a first cryptographic resource used by the network device in a secure boot process.Type: ApplicationFiled: November 21, 2022Publication date: March 30, 2023Inventors: Haiwu Chen, Mengnan Zhang, Bin Cao
-
Publication number: 20220245286Abstract: A software verification method and apparatus are provided. The method includes: reading flag information, where the flag information is used to indicate a target digital certificate; selecting one of a plurality of digital certificates as a target digital certificate based on the flag information, where the plurality of digital certificates include a first digital certificate and a second digital certificate, and the target digital certificate includes a cryptographic resource; and verifying software deployed on a device based on the cryptographic resource. Using the foregoing technical solution can ensure continuity of the software verification service in the device.Type: ApplicationFiled: April 22, 2022Publication date: August 4, 2022Inventors: Haiwu CHEN, Bin CAO, Mengnan ZHANG, Jianying QIAN
-
Publication number: 20220224546Abstract: Embodiments of this application disclose a software integrity protection method and apparatus. A first device obtains a first software package, where the first software package includes a first signature made by a first party for a second software package by using a first private key; and the first device performs a signing operation on the first software package by using a second private key, to obtain a third software package including a second signature, where the first private key is controlled by the first party, and the second private key is controlled by a second party. The first device sends the third software package to a second device. The second device verifies the first signature and the second signature in the third software package respectively based on a first public key and a second public key that are prestored, to obtain a verification result.Type: ApplicationFiled: April 1, 2022Publication date: July 14, 2022Applicant: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Bin Cao, Haiwu Chen, Yan Chen, Bo Wang
-
Publication number: 20220150260Abstract: A hardware detection method a includes sending first verification data to a physical carrier, where the physical carrier carries a plurality of pieces of hardware; receiving a ciphertext and binding relationship information from the physical carrier, where the ciphertext is obtained after at least two of the f pieces of hardware respectively encrypt the first verification data using respective keys, and where the binding relationship information indicates a binding relationship between the at least two pieces of hardware; verifying the ciphertext and the binding relationship information; and determining security of the at least two pieces of hardware based on a verification result.Type: ApplicationFiled: January 21, 2022Publication date: May 12, 2022Inventors: Mengnan Zhang, Lizhong Qiao, Haiwu Chen