System based on hybrid algorithm protection, protection method, BIOS and computer
The system is protected by a hybrid algorithm. The core code uses strong encryption signatures and RSA digital signatures, and the non-core code uses lightweight algorithms. This solves the problems of system code tampering and hash collisions, and achieves a balance between system security and performance.
Patent Information
- Application Number
- CN202510820204.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-09-26
AI Technical Summary
Existing technologies have shortcomings in protecting the integrity and credibility of system code, especially the inability to effectively prevent code tampering and hash collision attacks, and the complex digital signature process affects system performance.
A hybrid algorithm is used to protect the system. The core code uses a strong collision-resistant encryption signature algorithm and RSA digital signature combined with symmetric encryption. The non-core code uses a lightweight encryption signature algorithm, and the algorithm is dynamically selected according to the frequency of use, and stored and verified in a hierarchical manner.
It enhances system security, reduces computational complexity, improves system efficiency, and achieves a balance between security and performance, making it suitable for systems with sensitive startup times.
Smart Images

Figure CN120705893A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer science and technology, and in particular to a system, protection method, BIOS and computer based on hybrid algorithm protection. Background Art
[0002] In modern computer systems, the integrity of system code is a crucial component of ensuring system security. With the rapid development of computer technology and the diversification of its application scenarios, the attacks faced by systems are becoming increasingly complex and diverse. This is especially true of evolving attack vectors targeting low-level systems such as the BIOS (Basic Input / Output System) and firmware. If an attacker successfully tampered with system code, not only could it cause system anomalies but could also be used as a gateway to spread malware, steal data, or conduct more advanced attacks.
[0003] Especially on the X86 platform, system boot security directly depends on the integrity of the BIOS code. As the interface between the system and the hardware, the BIOS's core function is to initialize the system hardware and boot the operating system. If the BIOS code is tampered with, an attacker can insert malicious code into the boot chain, compromising not only the security of the operating system but also potentially putting the entire system at risk of becoming uncontrollable.
[0004] To ensure the integrity and security of system codes, existing technologies mainly use the following methods to encrypt system codes: (1) Symmetric encryption (such as AES): protects the confidentiality of the code, but cannot prevent the code from being tampered with; (2) Digital signature (such as RSA): verifies the source and integrity of the code, but the signature and verification process is computationally complex and may affect system performance; (3) Hash check (such as SHA-256): generates a code digest for integrity verification, but using a hash algorithm alone has the risk of replacing the legitimate hash value or suffering a hash collision attack.
[0005] Although there are a variety of system code encryption and protection methods listed above, the existing technologies still have some problems and limitations in protecting system code. First, existing encryption technology is mainly used to protect the confidentiality of the code, but encryption technology alone cannot effectively prevent the code from being tampered with or damaged during storage and operation. Second, although existing digital signature technology can verify the source and integrity of the code, its signing and verification process involves complex calculations, which may affect the performance of the system in resource-constrained or performance-intensive systems. In addition, although existing hash functions can generate fixed-length message digests of the code, relying solely on hash functions for verification has shortcomings. Attackers may replace legitimate hash values or exploit hash collision attacks, causing the integrity and credibility of the code to be threatened. Therefore, the existing technologies still have certain shortcomings in protecting the integrity and credibility of system code.
[0006] The disclosure of the above background technology content is only used to assist in understanding the inventive concept and technical solution of the present invention. It does not necessarily belong to the prior art of the present application, nor does it necessarily provide technical guidance. In the absence of clear evidence that the above content has been disclosed before the filing date of the present application, the above background technology should not be used to evaluate the novelty and creativity of the present application. Summary of the Invention
[0007] The purpose of the present invention is to provide a system, protection method, BIOS and computer based on hybrid algorithm protection, which can improve the security of the system.
[0008] In order to achieve the above object, the technical solution adopted by the present invention is as follows:
[0009] A system based on hybrid algorithm protection includes a core code module and a dynamic loading module, wherein the core code module is configured to store and / or load the core code of the system, and the dynamic loading module is configured to store and / or load non-core code of the system, wherein the security level of the non-core code is lower than the security level of the core code;
[0010] The core code is protected using a first protection strategy, the first protection strategy including:
[0011] Calculating the encrypted signature value of the core code using a first encrypted signature algorithm to obtain an original first encrypted signature value;
[0012] Digitally signing the original first encrypted signature value using an RSA private key to generate original signature data;
[0013] Encrypting the original signature data using a first symmetric encryption algorithm to generate an encrypted original verification code;
[0014] Storing the original first encrypted signature value and the original verification code in a first storage area, where the first storage area is a secure storage area;
[0015] The non-core code is protected by a second protection strategy, wherein the second protection strategy includes:
[0016] Dividing the non-core code into multiple consecutive sub-code segments; for each sub-code segment, calculating an encrypted signature value of the sub-code using a second encryption signature algorithm to obtain a sub-original encryption signature value; synthesizing the multiple sub-original encryption signature values into an original second encryption signature value, wherein the first encryption signature algorithm has stronger collision resistance than the second encryption signature algorithm;
[0017] The original second encrypted signature value is stored in a second storage area, and the security level of the first storage area is higher than the security level of the second storage area.
[0018] Furthermore, based on any one of the technical solutions or a combination of multiple technical solutions described above, the second protection strategy also includes: for two adjacent segments of the sub-code, using two different second encryption signature algorithms to calculate the encryption signature value of the sub-code.
[0019] Furthermore, based on any one of the above technical solutions or a combination of multiple technical solutions, if the usage frequency of the non-core code is not less than a preset first frequency value, the second encryption signature algorithm adopts the FNV-1 algorithm;
[0020] If the usage frequency of the non-core code is lower than a preset first frequency value, the second encryption signature algorithm adopts the CRC-32 algorithm.
[0021] Furthermore, based on any one of the technical solutions or a combination of multiple technical solutions described above, the second encryption signature algorithm includes a CRC-32 algorithm and an FNV-1 algorithm.
[0022] Furthermore, based on any one of the above technical solutions or a combination of multiple technical solutions, the second protection strategy further includes verifying the security of the non-core code in the following manner:
[0023] Each time the non-core code is loaded or periodically, the encrypted signature value of the non-core code is recalculated using the second encrypted signature algorithm to obtain a current second encrypted signature value;
[0024] The consistency of the current second encrypted signature value and the original second encrypted signature value is verified. If they are consistent, it is determined that the non-core code is safe; if they are inconsistent, it is determined that the non-core code is unsafe.
[0025] Further, based on any one of the above technical solutions or a combination of multiple technical solutions, the second storage area includes RAM, flash memory, HDD and SSD; and / or,
[0026] The dynamic loading module includes multiple sub-modules, each sub-module is configured to store and / or load different non-core codes, and the second encryption signature algorithm used by each sub-module is the same or different.
[0027] Furthermore, based on any one of the above technical solutions or a combination of multiple technical solutions, the first protection strategy further includes verifying the security of the core code in the following manner:
[0028] Decrypting the original verification code using the first symmetric encryption algorithm to obtain decrypted signature data;
[0029] Calculating the encrypted signature value of the current core code using the first encrypted signature algorithm to obtain a current first encrypted signature value;
[0030] The decrypted signature data is verified using the RSA public key, and the consistency of the current first encrypted signature value and the original first encrypted signature value is verified. If both verifications pass, the current core code is determined to be secure; otherwise, the current core code is determined to be unsafe.
[0031] Further, based on any one of the above technical solutions or a combination of multiple technical solutions, the first storage area includes ROM, HSM and TPM chip; and / or,
[0032] The first encryption signature algorithm includes SHA-256 algorithm, SHA-3 algorithm, SM3 algorithm and BLAKE2 algorithm; and / or,
[0033] The first symmetric encryption algorithm includes AES-256 algorithm, SM4-128 algorithm, Camellia-256 algorithm, and Serpent-256 algorithm.
[0034] According to another aspect of the present invention, the present invention provides a system code protection method based on a hybrid algorithm, comprising the following steps:
[0035] Determining a core code in the system code and protecting the core code using a first protection strategy includes:
[0036] Calculating the encrypted signature value of the core code using a first encrypted signature algorithm to obtain an original first encrypted signature value;
[0037] Digitally signing the original first encrypted signature value using an RSA private key to generate original signature data;
[0038] Encrypting the original signature data using a first symmetric encryption algorithm to generate an encrypted original verification code;
[0039] Storing the original verification code in a first storage area, where the first storage area is a secure storage area;
[0040] Determining non-core code in the system code, where the security level of the core code is higher than the security level of the non-core code, and protecting the non-core code using a second protection strategy, including:
[0041] calculating the encrypted signature value of the non-core code using a second encrypted signature algorithm to obtain an original second encrypted signature value, including dividing the non-core code into multiple consecutive sub-code segments, and calculating the encrypted signature value of each sub-code segment using the second encrypted signature algorithm to obtain a sub-original encrypted signature value, thereby combining the multiple sub-original encrypted signature values into the original second encrypted signature value, wherein the first encrypted signature algorithm has stronger collision resistance than the second encrypted signature algorithm;
[0042] The original second encrypted signature value is stored in a second storage area, and the security level of the first storage area is higher than the security level of the second storage area.
[0043] Furthermore, based on any one of the above technical solutions or a combination of multiple technical solutions, the second protection strategy also includes verifying the security of the non-core code in the following manner:
[0044] Each time the non-core code is loaded, the second encryption signature algorithm is used to calculate the encryption signature value of the non-core code to obtain a second encryption signature value;
[0045] The second encrypted signature value is verified to be consistent with the original second encrypted signature value. If they are consistent, the non-core code is determined to be safe; if they are inconsistent, the non-core code is determined to be unsafe.
[0046] Furthermore, based on any one of the above technical solutions or a combination of multiple technical solutions, the first protection strategy further includes verifying the security of the core code in the following manner:
[0047] Decrypting the original verification code using the first symmetric encryption algorithm to obtain decrypted signature data;
[0048] Calculating the encrypted signature value of the current core code using the first encrypted signature algorithm to obtain a current first encrypted signature value;
[0049] The decrypted signature data is verified using the RSA public key, and the consistency of the current first encrypted signature value and the original first encrypted signature value is verified. If both verifications pass, the current core code is determined to be secure; otherwise, the current core code is determined to be unsafe.
[0050] According to another aspect of the present invention, a BIOS is provided, which is configured as a system based on hybrid algorithm protection as described in any one of the above technical solutions or a combination of multiple technical solutions.
[0051] According to another aspect of the present invention, a computer is provided, comprising the system based on hybrid algorithm protection as described in any one of the above technical solutions or a combination of multiple technical solutions.
[0052] The beneficial effects brought about by the technical solution provided by the present invention are as follows:
[0053] a. The hybrid algorithm-based protection system provided by the present invention uses a highly collision-resistant first encryption signature algorithm to calculate the encryption signature value of the system's core code, and combines RSA digital signatures with a first symmetric encryption algorithm to form a multi-level protection mechanism for the core code. This can enhance the anti-collision capability of encryption signature verification, effectively prevent encryption signature collision attacks or threats of replacing legitimate encryption signature values, and thus prevent the core code from being tampered with or replaced during storage and loading, significantly enhancing system security.
[0054] b. This invention divides system code into core code and non-core code, adopts a second encryption signature algorithm with lower computational complexity for the non-core code, and dynamically selects the appropriate second encryption signature algorithm based on the frequency of code usage. This reduces the computational complexity and computational overhead of the signature verification process for the non-core code, making it particularly suitable for systems with sensitive startup times.
[0055] c. By using different second encryption signature algorithms for multiple sub-codes of non-core code, and encrypting adjacent sub-codes using different lightweight encryption algorithms, the present invention can further improve the overall security of the system while ensuring system efficiency. Even if some non-core code is attacked, the spread range and speed of the attacked object can be reduced.
[0056] d. The present invention divides core code into core code and non-core code, and adopts protection strategies with different security levels for different codes. This ensures system security while taking into account system performance. In particular, a lightweight verification mechanism is adopted for non-core codes with high usage frequency, thereby improving the overall efficiency of the system and achieving a balance between system security and performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0058] Figure 1 A flowchart of an encryption protection process for core code provided for an exemplary embodiment of the present invention;
[0059] Figure 2 A flowchart of a core code verification process provided for an exemplary embodiment of the present invention;
[0060] Figure 3 A schematic diagram of the partitioning of the system code provided for an exemplary embodiment of the present invention;
[0061] Figure 4 A flowchart of an encryption protection process for non-core code provided for an exemplary embodiment of the present invention;
[0062] Figure 5 A flowchart of a process for encrypting and protecting non-core code based on usage frequency is provided for an exemplary embodiment of the present invention;
[0063] Figure 6 A flowchart of a lightweight and highly secure encryption protection process for non-core code provided by an exemplary embodiment of the present invention;
[0064] Figure 7 A flowchart of a verification process for non-core code is provided for an exemplary embodiment of the present invention. DETAILED DESCRIPTION
[0065] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0066] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0067] In one embodiment of the present invention, a system based on hybrid algorithm protection is provided, which includes a core code module, wherein the core code module is configured to store and / or load the core code of the system;
[0068] See also Figure 1 , using a first protection strategy to protect the core code, the first protection strategy including:
[0069] Calculating the encrypted signature value of the core code using a first encrypted signature algorithm to obtain an original first encrypted signature value;
[0070] Digitally signing the original first encrypted signature value using an RSA private key to generate original signature data;
[0071] Encrypting the original signature data using a first symmetric encryption algorithm to generate an encrypted original verification code;
[0072] The original first encrypted signature value and the original verification code are stored in a first storage area, which is a secure storage area.
[0073] The first cryptographic signature algorithm is a highly collision-resistant cryptographic signature algorithm, such as SHA-256, SHA-3, SM3, and BLAKE2. Preferably, the first cryptographic signature algorithm uses SHA-256, and SHA-256 is used to calculate the cryptographic signature value of the core code to generate a unique code digest set, namely the original first cryptographic signature value.
[0074] SHA-256 is a widely recognized cryptographic signature algorithm with strong collision resistance, effectively preventing malicious code tampering because the cryptographic signature values it generates are unique and the probability of collision (i.e., two different inputs producing the same cryptographic signature value) is extremely low. Using SHA-256 to calculate the cryptographic signature value of the core code generates a unique code digest, allowing the core code to be verified in subsequent steps. If the core code is tampered with, its cryptographic signature value will change, making it easier to detect.
[0075] RSA is an asymmetric encryption algorithm that uses a public-private key pair for encryption and decryption. The private key is used to generate the signature, and the public key is used to verify the authenticity of the signature. The RSA private key is selected to digitally sign the original signature data, generating a digital signature data, the original signature data. The original signature data can be used to verify the integrity and origin of the core code. During the verification process, the public key is used to decrypt the signature data, confirming that the code has not been tampered with and is indeed signed by the legitimate private key holder, thereby ensuring that the code has not been tampered with by a third party.
[0076] The first symmetric encryption algorithm adopts a high-security algorithm such as AES-256, SM4-128, Camellia-256, Serpent-256, etc. Preferably, AES-256 is used to encrypt the original signature data to generate the original verification code.
[0077] AES (Advanced Encryption Standard) is a symmetric encryption algorithm with a 256-bit key providing extremely high encryption strength. Using AES-256 to encrypt the original signature data prevents unauthorized third-party access or tampering. The encrypted signature data, also known as the original checksum, provides enhanced security during storage. Even if an attacker gains access to the stored content, they cannot directly access or modify the signature.
[0078] Specifically, the original first encrypted signature value and the original check code are stored in a secure storage area. In the computer field, the secure storage area refers to a storage area protected by hardware. The encrypted original check code (i.e., the encrypted signature data) and the original first encrypted signature value are stored in an area protected by hardware, for example, using a dedicated hardware security module (HSM), read-only memory (ROM) or TPM chip or other protected storage area. These areas can prevent unauthorized access and can only be read and verified by the system at startup. The encrypted check code stored in the hardware protection area ensures that even if an attacker obtains the storage device through physical access, the signature data of the code cannot be easily tampered with or modified.
[0079] In this embodiment, the first protection strategy further includes verifying the security of the core code in the following manner:
[0080] Decrypting the original verification code using the first symmetric encryption algorithm to obtain decrypted signature data;
[0081] Calculating the encrypted signature value of the current core code using the first encrypted signature algorithm to obtain a current first encrypted signature value;
[0082] The decrypted signature data is verified using the RSA public key, and the consistency of the current first encrypted signature value and the original first encrypted signature value is verified. If both verifications pass, the current core code is determined to be secure; otherwise, the current core code is determined to be unsafe.
[0083] See also Figure 2 The core code verification process is as follows: When the system boots up, it first reads the encrypted signature data, namely the original checksum, from the hardware-protected area, namely the first storage area, and decrypts it using AES. The system then verifies the decrypted signature data using the RSA public key and verifies the consistency between the encrypted signature value of the current core code and the original first encrypted signature value. If both verifications pass, the core code has not been tampered with, and the system continues to boot up. If they are inconsistent, the system aborts the boot and issues a security warning.
[0084] For example, for a server, its BIOS core code is responsible for initializing the hardware and loading the operating system. The specific protection implementation process for the core code in this system is as follows.
[0085] Core code (such as hardware initialization code): This part of the code will perform system hardware initialization operations, including the detection and configuration of devices such as the CPU, memory, hard disk, and graphics card. To ensure that this part of the code has not been tampered with at startup, the SHA-256 algorithm is first used to calculate the SHA-256 encryption signature value of the code. The calculated SHA-256 encryption signature value is digitally signed with the RSA private key to generate a digital signature data. At this time, the RSA signature data guarantees the source and integrity of the code, and any unauthorized modification will cause the signature verification to fail. The generated digital signature data is encrypted using the AES-256 algorithm. The encrypted signature data is stored in a protected storage area, such as a hardware security module (HSM). This storage area can only be accessed by authorized operating systems or hardware to prevent unauthorized access.
[0086] During the verification process, after the system loads the core code, it recalculates the encrypted signature value of the currently loaded code using a highly collision-resistant cryptographic signature algorithm (such as SHA-256). When recalculating the encrypted signature value, the SHA-256 cryptographic signature algorithm ensures that the generated encrypted signature value is unique, and any minor modification will result in a significant change in the encrypted signature value, making it easier to detect.
[0087] The decrypted digital signature is verified using the RSA public key. The digital signature is generated by the private key, and the public key is used to verify the validity of the signature. Check whether the original first digital signature value matches the recalculated encrypted signature value. If they match, it means that the source of the core code is reliable and has not been tampered with. If the digital signature cannot be verified, it means that the integrity of the core code is threatened, the system will stop booting and trigger a security warning. Through digital signature and public key verification, the system can confirm whether the loaded code comes from a trusted source and ensure that its content has not been tampered with during storage. Digital signature verification can effectively prevent malware from compromising system security by replacing core code and ensure startup security.
[0088] Countermeasures for verification failure: (1) System interruption startup. If the integrity check of the core code fails, the system will immediately interrupt the startup process; at this time, the system will not continue to load the operating system or other modules to prevent the execution of any malicious code or damaged code. (2) Security warning The system will trigger a security warning to inform the user or administrator that the code integrity check has failed. The warning content usually describes the reason for the verification failure in detail (such as signature mismatch, inconsistent encryption signature value, etc.) and requires the administrator to take further security measures. (3) Prevent the damaged code from running. By interrupting the startup and displaying the warning, the system effectively prevents the damaged or tampered core code from running. At this time, the administrator can check the system log, perform repair operations, or reinstall the system (such as BIOS) code to ensure system security.
[0089] In one embodiment of the present invention, the system based on hybrid algorithm protection also includes a dynamic loading module, which is configured to store and / or load non-core code of the system, and the security level of the non-core code is lower than the security level of the core code.
[0090] The second protection strategy is used to protect the non-core code. Figure 4 , the second protection strategy includes:
[0091] Calculating the encrypted signature value of the non-core code using a second encrypted signature algorithm to obtain an original second encrypted signature value, where the first encrypted signature algorithm has stronger collision resistance than the second encrypted signature algorithm; the second encrypted signature algorithm is a lightweight encryption algorithm, and specifically, CRC-32 or FNV-1 may be used;
[0092] The original second encrypted signature value is stored in a second storage area. The security level of the first storage area is higher than that of the second storage area. The second storage area can use a non-read-only storage unit, such as RAM, flash memory, HDD, SSD, etc.
[0093] See also Figure 7 The second protection strategy further includes verifying the security of the non-core code by: recalculating the encryption signature value of the non-core code using the second encryption signature algorithm each time the non-core code is loaded or periodically to obtain a current second encryption signature value; and verifying the consistency of the current second encryption signature value with the original second encryption signature value. If they are consistent, the non-core code is determined to be secure; if they are inconsistent, the non-core code is determined to be unsafe.
[0094] Dynamically loaded modules are typically system drivers, extended function modules, and other components that are required to be loaded and executed after startup. Using computationally complex cryptographic signature algorithms can slow module loading, impacting system performance. Therefore, lightweight algorithms such as CRC-32 and FNV-1 can provide fast and effective integrity verification. These algorithms provide fast integrity verification without significantly impacting system performance and are suitable for frequently loaded and updated dynamically loaded modules. Certain embedded systems or low-power devices have limited computing resources, and using complex cryptographic algorithms can overburden the system. Therefore, using lightweight algorithms such as CRC-32 and FNV-1 ensures module security while maintaining reasonable computational efficiency.
[0095] The following example illustrates the protection and verification process for dynamically loaded modules. Assume a server runs on an operating system that contains multiple dynamically loaded modules, such as network card drivers, graphics card drivers, and other peripheral drivers. These modules are dynamically loaded when the operating system boots up and subsequently perform corresponding hardware initialization and resource configuration tasks.
[0096] First loading of a dynamically loaded module and calculation of a second cryptographic signature value for its corresponding non-core code: When the system first loads the network card driver net_driver.dll, it uses the CRC-32 algorithm to calculate the cryptographic signature value of the driver's program code. For example, the calculated cryptographic signature value is C1F9B01F. This cryptographic signature value is stored in the system's persistent storage as a unique identifier for the driver.
[0097] Cryptographic signature verification during dynamic module loading: When the operating system reloads the network card driver, it calculates the CRC-32 cryptographic signature of the net_driver.dll file and compares it with the original cryptographic signature. If the calculated cryptographic signature matches the original (C1F9B01F), the driver has not been tampered with, and the system continues loading the driver.
[0098] Suppose net driver.dll is tampered with during loading. The recalculated encryption signature value is D2A8C041, which does not match the original encryption signature value (C1F9B01F). The system detects the inconsistency, triggers a security warning, and refuses to load the module, protecting the system from potential security threats.
[0099] Legal module update and updated cryptographic signature: When a system administrator updates the network card driver version, the updated driver file, net_driver_v2.dll, is loaded. The system recalculates the cryptographic signature of this file and updates the stored cryptographic signature to ensure that the new driver version passes integrity checks.
[0100] In this embodiment, the system code is divided into core code and non-core code according to different security requirement levels of the code in the system, and two different protection strategies are adopted.
[0101] like Figure 3 As shown in the figure, taking BIOS as an example, BIOS code is classified into core and non-core code based on its importance and functional characteristics. Core code includes the critical parts of system startup and hardware initialization and requires the highest level of security protection. Non-core code extends system functionality and requires a balance between security and performance. Security policies are formulated for different code areas, implementing strong security measures for core code and lightweight verification mechanisms for non-core code in dynamically loaded modules.
[0102] The core code module refers to the key part in the early stages of system startup that is required to ensure normal system startup and provide a stable operating environment for the operating system. Specifically, the core code functions in the core code module generally include:
[0103] Hardware initialization: Responsible for the initialization of computer hardware, including the detection and configuration of CPU, memory, hard disk, graphics card, input and output devices, etc. This is the basis for ensuring the normal operation of the computer;
[0104] Booting and loading the operating system: The core code is responsible for guiding the loading of the operating system. It will load the operating system's startup image through the boot manager to ensure that the system can successfully enter the operating system environment;
[0105] BIOS configuration management: including management of user-defined BIOS settings, such as date and time, boot order, etc., to ensure that user-defined configuration information is correctly applied;
[0106] These functions are crucial to computer system security. If an attacker tampers with any core code, they could potentially insert malicious code during startup or prevent the operating system from loading, causing the system to malfunction. Therefore, this code must be strictly protected to ensure it cannot be tampered with throughout the system's operation.
[0107] Dynamically loaded modules refer to auxiliary function code modules that are loaded after the system starts and executed as needed. Specifically, the functions of dynamically loaded modules usually include:
[0108] Drivers: Some hardware drivers, such as network card drivers and graphics card drivers, are usually loaded after the operating system starts and are loaded dynamically as needed;
[0109] System extension functions: some non-core system function extensions, such as debugging tools, log collection modules, security inspection tools, etc. These function modules may be dynamically loaded at runtime;
[0110] Firmware update and configuration tools: Some BIOS support modules for updating firmware or modifying configurations after the operating system is started.
[0111] Compared to core code modules, dynamically loaded modules have a smaller impact on system security. While these modules must ensure data integrity and prevent tampering, their security requirements are less stringent than those of core code, prioritizing performance and flexibility. Therefore, these modules typically employ lightweight validation mechanisms to ensure system performance is not significantly impacted.
[0112] CRC-32 offers significant advantages in terms of performance and computational efficiency. CRC-32 is a widely used cyclic redundancy check algorithm that quickly calculates the cryptographic signature value of data. Although its collision resistance is relatively weak, computational speed and efficiency are more critical for dynamically loaded modules, making CRC-32 suitable for verifying the integrity of these modules. For example, when the system loads a dynamic module (such as a hardware driver or system extension module), it needs to verify a network card driver, net_driver.dll. The system calculates the CRC-32 cryptographic signature value for this file, generating a 32-bit cryptographic signature value that serves as the module's "fingerprint."
[0113] Each time a module is dynamically loaded, the system recalculates the module's cryptographic signature. The recalculated signature is compared with the stored original CRC-32 signature. If the two signatures match, the module has not been tampered with, and the system continues loading the module.
[0114] FNV-1 is another lightweight cryptographic signature algorithm that is simpler than CRC-32, provides fast cryptographic signature calculations, and performs well when processing smaller modules. FNV-1 can achieve efficient cryptographic signature calculations in memory-constrained environments and is suitable for small modules that require fast verification. For smaller, frequently used modules (such as a device driver), the FNV-1 algorithm can be used to calculate the cryptographic signature and generate the module's cryptographic signature value. Similarly, the cryptographic signature value recalculated using the FNV-1 algorithm is compared with the stored cryptographic signature value to ensure the integrity of the module.
[0115] If the recalculated cryptographic signature value doesn't match the stored one, the system will assume the module may have been tampered with, triggering an alarm or refusing to load the module to prevent malicious code from running. If the module is legitimately updated, the new version will recalculate the cryptographic signature value and update the stored one. This way, the system can always verify the integrity of the module.
[0116] Therefore, in one embodiment of the present invention, see Figure 5 If the usage frequency of the non-core code is not lower than the preset first frequency value, the second encryption signature algorithm adopts the FNV-1 algorithm. If the usage frequency of the non-core code is lower than the preset first frequency value, the second encryption signature algorithm adopts the CRC-32 algorithm. The present invention divides the system code into core code and non-core code, adopts a second encryption signature algorithm with lower computational complexity for the non-core code, and dynamically selects a suitable algorithm according to the frequency of code usage, thereby reducing the computational complexity of the signature verification process, reducing the computational overhead of the verification process, and improving the verification efficiency. It is particularly suitable for systems that are sensitive to startup time.
[0117] In one embodiment of the present invention, see Figure 6, the second protection strategy also includes: dividing the non-core code into multiple consecutive sub-codes; for each segment of the sub-code, using the second encryption signature algorithm to calculate the encryption signature value of the sub-code to obtain the sub-original encryption signature value; storing the sub-original encryption signature value in the second storage area. More preferably, for two adjacent segments of the sub-code, two different second encryption signature algorithms are used to calculate the encryption signature value of the sub-code. For example, for two adjacent segments of sub-code, one sub-code uses the CRC-32 algorithm and the other sub-code uses the FNV-1 algorithm. Based on this approach, while achieving lightweight protection for the dynamically loaded module, the security of the dynamically loaded module can be further improved, and a balance between system security and performance can be achieved.
[0118] In one embodiment of the present invention, a system code protection method based on a hybrid algorithm is provided. Figure 1 、 Figure 2 、 Figure 4 and Figure 7 , the method includes the following steps.
[0119] The core code and non-core code in the system code are determined, the security level of the core code is higher than the security level of the non-core code, and the non-core code is protected by adopting a second protection strategy.
[0120] The core code is protected by a first protection strategy, including: using a first encryption signature algorithm to calculate the encryption signature value of the core code to obtain an original first encryption signature value; using an RSA private key to digitally sign the original first encryption signature value to generate original signature data; using a first symmetric encryption algorithm to encrypt the original signature data to generate an encrypted original verification code; and storing the original verification code in a first storage area, which is a secure storage area.
[0121] The security of the core code is verified in the following manner: the original verification code is decrypted using the first symmetric encryption algorithm to obtain decrypted signature data; the encrypted signature value of the current core code is calculated using the first encryption signature algorithm to obtain the current first encrypted signature value; the decrypted signature data is verified using the RSA public key, and the consistency of the current first encrypted signature value and the original first encrypted signature value is verified. If both verifications are passed, the current core code is determined to be secure; otherwise, the current core code is determined to be unsafe.
[0122] A second cryptographic signature algorithm is used to calculate the cryptographic signature value of the non-core code to obtain an original second cryptographic signature value, wherein the first cryptographic signature algorithm has stronger collision resistance than the second cryptographic signature algorithm. The original second cryptographic signature value is stored in a second storage area, wherein the security level of the first storage area is higher than the security level of the second storage area.
[0123] The non-core code is protected by the second protection strategy, further comprising: each time the non-core code is loaded, the encrypted signature value of the non-core code is calculated by the second encryption signature algorithm to obtain a second encryption signature value; and the second encryption signature value is verified to be consistent with the original second encryption signature value. If they are consistent, the non-core code is determined to be safe; if they are inconsistent, the non-core code is determined to be unsafe.
[0124] In one embodiment of the present invention, a BIOS is provided. The BIOS is configured as a system based on hybrid algorithm protection as described in any one or more of the above embodiments.
[0125] In one embodiment of the present invention, a computer is provided, comprising the system based on hybrid algorithm protection as described in any one or a combination of multiple embodiments above.
[0126] It should be noted that the system code protection method, BIOS and computer embodiments based on the hybrid algorithm provided by the present invention have the same inventive concept as the above-mentioned system code protection method embodiment based on the hybrid algorithm, and all the contents of the system code protection method embodiment based on the hybrid algorithm are incorporated into the system code protection method, BIOS and computer embodiments based on the hybrid algorithm by introduction.
[0127] The BIOS code integrity protection method based on a hybrid algorithm proposed in this technical solution has significant security and performance advantages and has broad application prospects in multiple fields. First, in the field of computer system security, this solution can effectively prevent the BIOS code from being tampered with or replaced, thereby improving the security of the system startup process. With the increasing threats of hardware-level attacks and firmware malware, protecting the integrity of low-level system codes such as BIOS has become critical. This technical solution provides a solution that takes into account both security and performance, and is suitable for computing environments that require high security, such as personal computers, servers, and large data centers.
[0128] Thirdly, in the fields of industrial control and critical infrastructure, such as electricity, transportation, and energy, system reliability and security are of paramount importance. This technical solution can be used to protect the firmware code of industrial control systems, prevent security incidents caused by code tampering, and ensure the stable operation of the system. In addition, in fields with extremely high security requirements such as finance, medical care, and government agencies, this solution can provide a high level of system code integrity protection, prevent potential security vulnerabilities from being exploited, and protect the security of sensitive data and critical businesses. Finally, with the popularization of cloud computing and virtualization technology, the security of the virtual machine monitor (Hypervisor) and firmware layer has also received increasing attention. This technical solution can be applied to the protection of firmware and system code in a virtualized environment to enhance the security of the cloud environment.
[0129] In summary, this technical solution ensures high security while also balancing system performance, addressing the high computational overhead and insufficient attack resistance issues of existing technologies. It has broad application prospects, meeting the needs of various industries for system code integrity protection, and possesses significant market value and promotional significance.
[0130] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0131] The above is only a specific implementation method of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A system based on hybrid algorithm protection, characterized in that: The system comprises a core code module and a dynamic loading module, wherein the core code module is configured to store and / or load the core code of the system, and the dynamic loading module is configured to store and / or load the non-core code of the system, wherein the security level of the non-core code is lower than the security level of the core code; The core code is protected using a first protection strategy, the first protection strategy including: Calculating the encrypted signature value of the core code using a first encrypted signature algorithm to obtain an original first encrypted signature value; Digitally signing the original first encrypted signature value using an RSA private key to generate original signature data; Encrypting the original signature data using a first symmetric encryption algorithm to generate an encrypted original verification code; Storing the original first encrypted signature value and the original verification code in a first storage area, where the first storage area is a secure storage area; The non-core code is protected by a second protection strategy, wherein the second protection strategy includes: Dividing the non-core code into multiple consecutive sub-code segments; for each sub-code segment, calculating an encrypted signature value of the sub-code using a second encryption signature algorithm to obtain a sub-original encryption signature value; synthesizing the multiple sub-original encryption signature values into an original second encryption signature value, wherein the first encryption signature algorithm has stronger collision resistance than the second encryption signature algorithm; The original second encrypted signature value is stored in a second storage area, and the security level of the first storage area is higher than the security level of the second storage area.
2. The system based on hybrid algorithm protection according to claim 1, characterized in that: The second protection strategy further includes: using two different second encryption signature algorithms to calculate the encryption signature values of the sub-codes for two adjacent segments of the sub-codes.
3. The system based on hybrid algorithm protection according to claim 1, characterized in that: If the usage frequency of the non-core code is not lower than the preset first frequency value, the second encryption signature algorithm adopts the FNV-1 algorithm; If the usage frequency of the non-core code is lower than a preset first frequency value, the second encryption signature algorithm adopts the CRC-32 algorithm.
4. The system based on hybrid algorithm protection according to claim 1, characterized in that: The second encryption signature algorithm includes a CRC-32 algorithm and an FNV-1 algorithm.
5. The system based on hybrid algorithm protection according to claim 1, characterized in that: The second protection strategy further includes verifying the security of the non-core code in the following manner: Each time the non-core code is loaded or periodically, the encrypted signature value of the non-core code is recalculated using the second encrypted signature algorithm to obtain a current second encrypted signature value; Verifying the consistency between the current second encrypted signature value and the original second encrypted signature value, and if they are consistent, determining that the non-core code is secure; If they are inconsistent, it is determined that the non-core code is unsafe.
6. The system based on hybrid algorithm protection according to claim 1, characterized in that: The second storage area includes RAM, flash memory, HDD and SSD; and / or, The dynamic loading module includes multiple sub-modules, each sub-module is configured to store and / or load different non-core codes, and the second encryption signature algorithm used by each sub-module is the same or different.
7. The system based on hybrid algorithm protection according to claim 1, characterized in that: The first protection strategy also includes verifying the security of the core code in the following manner: Decrypting the original verification code using the first symmetric encryption algorithm to obtain decrypted signature data; Calculating the encrypted signature value of the current core code using the first encrypted signature algorithm to obtain a current first encrypted signature value; Use the RSA public key to verify the decrypted signature data and verify the consistency of the current first encrypted signature value with the original first encrypted signature value. If both verifications pass, the current core code is determined to be secure. Otherwise, it is determined that the current core code is unsafe.
8. The system based on hybrid algorithm protection according to claim 1, characterized in that: The first storage area includes ROM, HSM and TPM chip; and / or, The first encryption signature algorithm includes SHA-256 algorithm, SHA-3 algorithm, SM3 algorithm and BLAKE2 algorithm; and / or, The first symmetric encryption algorithm includes AES-256 algorithm, SM4-128 algorithm, Camellia-256 algorithm, and Serpent-256 algorithm.
9. A system code protection method based on a hybrid algorithm, characterized in that: The following steps are involved: Determining a core code in the system code and protecting the core code using a first protection strategy includes: Calculating the encrypted signature value of the core code using a first encrypted signature algorithm to obtain an original first encrypted signature value; Digitally signing the original first encrypted signature value using an RSA private key to generate original signature data; Encrypting the original signature data using a first symmetric encryption algorithm to generate an encrypted original verification code; Storing the original verification code in a first storage area, where the first storage area is a secure storage area; Determining non-core code in the system code, where the security level of the core code is higher than the security level of the non-core code, and protecting the non-core code using a second protection strategy, including: Dividing the non-core code into multiple consecutive sub-code segments, calculating an encrypted signature value of each sub-code segment using a second encryption signature algorithm to obtain a sub-original encryption signature value, combining multiple sub-original encryption signature values into an original second encryption signature value, wherein the first encryption signature algorithm has stronger collision resistance than the second encryption signature algorithm; The original second encrypted signature value is stored in a second storage area, and the security level of the first storage area is higher than the security level of the second storage area.
10. The system code protection method based on hybrid algorithm according to claim 9, characterized in that: The second protection strategy also includes verifying the security of the non-core code in the following manner: Each time the non-core code is loaded, the second encryption signature algorithm is used to calculate the encryption signature value of the non-core code to obtain a second encryption signature value; Verifying the consistency between the second encrypted signature value and the original second encrypted signature value, and if they are consistent, determining that the non-core code is secure; If they are inconsistent, it is determined that the non-core code is unsafe.
11. The system code protection method based on hybrid algorithm according to claim 9, characterized in that: The first protection strategy also includes verifying the security of the core code in the following manner: Decrypting the original verification code using the first symmetric encryption algorithm to obtain decrypted signature data; Calculating the encrypted signature value of the current core code using the first encrypted signature algorithm to obtain a current first encrypted signature value; Use the RSA public key to verify the decrypted signature data and verify the consistency of the current first encrypted signature value with the original first encrypted signature value. If both verifications pass, the current core code is determined to be secure. Otherwise, it is determined that the current core code is unsafe.
12. A BIOS, characterized in that: The BIOS is configured as a system based on the hybrid algorithm protection according to any one of claims 1 to 8.
13. A computer, characterized in that: The invention comprises a system based on hybrid algorithm protection as claimed in any one of claims 1 to 8.