A flash boot system and method based on a credibility measurement mechanism
By expanding the SPI interface using TPCM and CPLD devices and combining it with a trusted measurement mechanism to achieve automatic switching between primary and backup Flash memory, the system's boot reliability problem caused by the single-channel SPI interface of domestic CPUs is solved, and the system's fault tolerance and security are improved.
Patent Information
- Application Number
- CN202511416800.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-03-20
- Estimated Expiration
- 2045-09-30
AI Technical Summary
Domestic CPUs (such as Loongson 3A6000) only support a single SPI interface, which makes the boot reliability heavily dependent on a single Flash memory. The system is prone to crashing in the event of hardware failure, and there is a lack of verification mechanism for the integrity and reliability of the boot firmware.
The system employs a Trusted Platform Control Module (TPCM) and a CPLD device, and extends the SPI interface through a trusted measurement mechanism to achieve automatic switching between primary and backup Flash memories and signal logic control. It also combines GPIO signal lines to transmit startup failure signals and reset control.
A hardware-level redundant boot architecture was constructed to prevent malicious boot firmware loading, improve system fault tolerance and security, and ensure that the system automatically switches to backup storage in the event of Flash failure, thereby improving system reliability and stability.
Smart Images

Figure CN121188846B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer startup, and particularly relates to a Flash startup system and method based on a credibility measurement mechanism. BACKGROUND
[0002] The abbreviations and key terms in the specification are defined as follows:
[0003] Trusted Platform Control Module (TPCM): Through the integration of RTM (Root of Trust Measurement), the active measurement of BIOS, startup firmware and other startup components is realized to ensure that the trust chain is transmitted from the hardware layer.
[0004] In the design of a motherboard based on a domestic CPU (such as Loongson 3A6000), startup reliability is the key to ensuring stable operation of the system. However, some domestic CPUs (such as Loongson 3A6000) only support a single SPI interface, and this hardware limitation leads to many technical difficulties. The following takes the Loongson 3A6000 CPU as an example for illustration:
[0005] 1. Physical limitation of single SPI interface
[0006] The single SPI interface design of the Loongson 3A6000 CPU cannot directly support the simultaneous connection of main and backup Flash memories at the hardware level. This means that, during the startup process, the CPU can only access the main Flash memory through the unique SPI interface. Once the main Flash memory fails (for example, the startup firmware is damaged, the chip is not in good contact, or the memory is aging, etc.), the CPU will not be able to obtain valid startup firmware, directly leading to system startup failure and further causing system downtime.
[0007] 2. Serious dependence on startup reliability
[0008] The traditional solution completely depends on the normal operation of a single Flash memory. If any failure occurs in the main Flash memory, the CPU will be stuck due to the inability to load the startup program, and the system stability cannot be guaranteed. This absolute dependence on a single Flash memory makes the system extremely vulnerable when facing hardware failures.
[0009] 3. Functional limitations of special switching devices
[0010] If a dedicated SPI signal switching device is used, although the connection of multiple Flash memories can be realized, such devices have significant limitations. They lack programmability, cannot realize intelligent switching control logic based on startup failure signals, and cannot dynamically adjust signal flow direction according to the startup state of the CPU. In addition, the existing architecture lacks a verification mechanism for the integrity and trustworthiness of the startup firmware in the Flash memory. If the startup firmware is maliciously tampered with (such as by implanting a Trojan, virus, or backdoor program) during storage or transmission, and is not effectively identified before being loaded into the CPU, once it is loaded and executed, it will cause serious security consequences, including sensitive data leakage, illegal control of the system, or destruction of critical business. Therefore, before startup, the trusted measurement of the startup firmware is an indispensable key link in building a secure startup system, and the lack of a hardware-level measurement and switching linkage mechanism is a core problem that needs to be solved in the field. SUMMARY
[0011] The purpose of the present application is to overcome the above technical problems and provide a Flash startup system based on a trusted measurement mechanism.
[0012] To achieve the above purpose, the technical solution adopted by the present application is as follows:
[0013] A Flash startup system based on a trusted measurement mechanism, characterized by comprising a domestic CPU, a CPLD device, a trusted platform control module TPCM, a main Flash memory, at least one backup Flash memory, and a GPIO signal line.
[0014] The domestic CPU has a single SPI interface and is electrically connected to the CPLD device through the SPI interface.
[0015] The CPLD device is used to expand the single SPI interface of the domestic CPU into a multi-channel SPI interface and to realize switching control between the main Flash memory and the backup Flash memory according to the measurement results fed back by the trusted platform control module TPCM.
[0016] The main Flash memory is electrically connected to the domestic CPU through one SPI interface of the CPLD device and is used to store the main startup firmware.
[0017] The backup Flash memory is electrically connected to the domestic CPU through other SPI interfaces of the CPLD device, and each backup Flash memory is used to store an independent backup startup firmware.
[0018] The trusted platform control module (TPCM) is electrically connected with the CPLD device, and is configured to perform a trusted measurement on the boot firmware stored in the main Flash memory and / or the backup Flash memory through the CPLD device after the system is powered on, and feed back the measurement result to the CPLD device.
[0019] The GPIO signal line is configured to transmit a boot failure signal and a reset control signal between the domestic CPU and the CPLD device, so as to realize automatic switching of the main and backup Flash memories.
[0020] Further, the CPLD device internally expands the single SPI interface of the domestic CPU into a multi-channel SPI interface through logical programming processing of programmable logic code.
[0021] Further, the logical programming processing of programmable logic code in the CPLD device includes switching logic processing of a clock signal, a chip selection signal, a data input signal and a data output signal of the SPI signal.
[0022] Further, the TPCM performs measurement on the boot firmware stored in the main Flash memory and / or the backup Flash memory through the CPLD device, and specifically:
[0023] The TPCM compares the measurement value calculated by the TPCM on the main Flash memory and / or the backup Flash memory with a hash value pre-stored by the TPCM, and if the two values are consistent, it indicates that the measurement is successful; if the two values are inconsistent, it indicates that the measurement fails.
[0024] Further, the number of the multi-channel SPI interface is equal to the total number of the main Flash memory and all backup Flash memories.
[0025] Further, the domestic CPU is a Loongson processor.
[0026] The application further provides a Flash boot method based on a trusted measurement mechanism, comprising the following steps:
[0027] S1: After the system is powered on, the TPCM performs measurement on the boot firmware of the main Flash memory through the CPLD device and obtains a measurement value, and then compares the measurement value with a hash value pre-stored by the TPCM, and if the two values are consistent, it indicates that the measurement is successful, and the next step is executed; if the two values are inconsistent, it indicates that the measurement fails, and step S4 is directly executed.
[0028] S2: the domestic CPU is powered on, the CPLD device switches the SPI signal to the main Flash memory, and the domestic CPU starts by loading the start firmware in the main Flash memory;
[0029] S3: if the main Flash memory fails to start, the domestic CPU sends a start failure signal to the CPLD device through the GPIO signal line; the CPLD device feeds back the start failure signal to the trusted platform control module TPCM;
[0030] S4: the trusted platform control module TPCM switches to an unmeasured backup Flash memory through the CPLD device to measure and obtain a measurement value, and then compares the measurement value with a hash value stored in advance by itself; if they are consistent, it indicates that the measurement is successful, and the execution continues; if they are inconsistent, it indicates that the measurement fails, and step S4 is executed in a loop until the measurement result is successful or all backup Flash memories are measured, if all backup Flash memories fail to measure, the system startup process is terminated;
[0031] S5: it is judged whether the domestic CPU has started, if not, the domestic CPU is powered on; if yes, the CPLD device operates the reset signal of the domestic CPU to trigger CPU reset, and switches the SPI signal to the backup Flash memory whose measurement is successful;
[0032] S6: after the domestic CPU is started, the CPLD device loads the start firmware of the switched backup Flash memory whose measurement is successful to start.
[0033] Further, the CPLD device in step S5 switches the SPI signal through programmable logic code for logic programming processing, including the switching logic of the clock signal, the chip selection signal, the data input signal and the data output signal.
[0034] Further, the specific method of the switching logic in step S5 is:
[0035] S51: after receiving the start failure signal sent by the domestic CPU, the internal logic circuit of the CPLD device generates a control signal according to the preset switching logic, and prepares to switch the output target of the clock signal;
[0036] S52: the CPLD device switches the output target of the clock signal from the main Flash memory to the selected backup Flash memory, to ensure that the clock signal can be correctly transmitted to the backup Flash memory;
[0037] S53: The CPLD device synchronously switches the chip select signal and controls the level of the chip select signal through its internal logic to ensure that only the selected spare Flash memory can respond to SPI bus commands, while other spare Flash memories are in an unselected state.
[0038] S54: The CPLD device adjusts the level of the data input signal and the data output signal according to the switching logic to ensure the stability and reliability of the communication between the SPI bus and the backup Flash memory, and to prevent data writing errors or communication interruptions.
[0039] S55: The CPLD device completes all SPI signal switching logic, ensuring a stable communication connection between the SPI bus and the backup Flash memory.
[0040] If the startup fails after step S6, the process returns to step S4 to switch to the next available backup Flash memory.
[0041] Beneficial effects of this invention:
[0042] 1. This invention innovatively combines the measurement mechanism of the Trusted Platform Control Module (TPCM) with Flash switching control. After the system powers on, the TPCM performs an integrity measurement on the boot firmware in the primary and backup Flash memory before the CPU loads the boot firmware, and only allows booting after the measurement is successful. This prevents the loading and execution of malicious boot firmware (such as Trojans and viruses) from the source, constructs a hardware-based trusted boot root, and provides a solid foundation for core system and data security.
[0043] 2. This invention expands the single-channel SPI interface of a domestic CPU into multiple channels using a CPLD, connecting them to primary and backup Flash memories to construct a hardware-level redundant boot architecture. When the primary Flash fails to boot due to physical damage, aging, or other reasons, the system can detect the fault through GPIO signals and automatically switch to the backup Flash, effectively avoiding system "freezing" or "crashing" caused by a single storage device failure, and greatly improving the system's fault tolerance and long-term operational reliability.
[0044] 3. Compared to traditional dedicated SPI signal switching devices, the CPLD device of this invention utilizes a more flexible and intelligent logic control method implemented through internal code. The CPLD device can precisely control the signal flow according to actual needs, effectively handling the logical interaction and boot process between the CPU and Flash. This innovative logic control method not only simplifies hardware design but also optimizes the boot process, improving the overall performance and stability of the system. Attached Figure Description
[0045] Figure 1The system architecture block diagram of the embodiment one of the application.
[0046] Figure 2 The simulation timing diagram when the main Flash memory switches to the standby Flash memory. DETAILED DESCRIPTION
[0047] The application will be described in detail below in combination with the drawings and embodiments. In order to more clearly describe the technical solutions of the application, the following embodiments take the Loongson 3A6000 as an example for description. Embodiment one
[0048] This embodiment describes a Flash starting system based on a trust measurement mechanism. As shown in the figure, the system includes a Loongson 3A6000 CPU, a CPLD device, a trusted platform control module TPCM, a main Flash memory, a standby Flash memory, and a GPIO signal line. Figure 1
[0049] The Loongson 3A6000 CPU has a single SPI interface, which is directly electrically connected with the CPLD device. The core role of the CPLD device is to expand the single SPI interface of the CPU into a multi-channel SPI interface through internal programmable logic code. Specifically, the logic programming processing inside the CPLD covers the complete switching logic of the clock signal, chip selection signal, data input signal and data output signal necessary for SPI communication.
[0050] The following is the core code of the CPLD device to realize the logic switching of the SPI signal:
[0051] / * Define the SPI clock idle state as high level (1) to ensure consistency with the device clock idle state of the main and standby Flash memories, and maintain signal compatibility * /
[0052] localparam SPI_CLK_IDLE_STATE = 1;
[0053] / * SPI clock signal selection logic:
[0054] * When SPI_TPCM_sel is valid (selecting the TPCM path), use the TPCM_SPI_CLK signal;
[0055] * Otherwise, directly use the SPI clock signal CPU_SPI_SCK of the CPU * /
[0056] assign CPLD_QSPI_SCK = (SPI_TPCM_sel? TPCM_SPI_CLK : CPU_SPI_SCK);
[0057] / * Define SPI chip select idle state as high (1), keep unselected state, prevent bus accidental data transmission* /
[0058] localparam SPI_CSN_IDLE_STATE = 1;
[0059] / * Main Flash chip select control logic:
[0060] * First determine spi_cs_High (standby / non-startup state) or SPI_TPCM_sel (TPCM path selection):
[0061] * - If TPCM path is selected and flash1_sel is valid, use TPCM_SPI_CS (TPCM chip select);
[0062] * - If TPCM path is selected but flash1_sel is not valid, forcibly disable (1'h1);
[0063] * - If TPCM path is not selected and flash1_sel is valid, use CPU chip select signal CPU_SPI_CSN;
[0064] * - In other cases, forcibly disable * /
[0065] assign CPLD_QSPI_CS0N =
[0066] spi_cs_High |
[0067] (SPI_TPCM_sel?
[0068] (flash1_sel? TPCM_SPI_CS : 1'h1) :
[0069] (flash1_sel? CPU_SPI_CSN : 1'h1) );
[0071] / * Backup Flash chip select control logic:
[0072] * Similarly, first determine spi_cs_High or SPI_TPCM_sel:
[0073] * - If TPCM path is selected and flash1_sel is valid, forcibly disable;
[0074] * - If TPCM path is selected but flash1_sel is not valid, use TPCM_SPI_CS;
[0075] * - If TPCM path is not selected and flash1_sel is active, then force disabled;
[0076] * - Otherwise use CPU chip select signal CPU_SPI_CSN * /
[0077] assign CPLD_QSPI_CS1N =
[0078] spi_cs_High |
[0079] (SPI_TPCM_sel?
[0080] (flash1_sel? 1'h1 : TPCM_SPI_CS) :
[0081] (flash1_sel? 1'h1 : CPU_SPI_CSN) );
[0083] / * Define SPI write protect idle state as high (1) and maintain non- write protect state * /
[0084] localparam SPI_WPN_IDLE_STATE = 1;
[0085] / * SPI write protect signal selection logic:
[0086] * Use idle state (SPI_WPN_IDLE_STATE) when TPCM path is selected;
[0087] * Otherwise use CPU SPI write protect signal CPU_SPI_WPN directly * /
[0088] assign CPLD_QSPI_WPN = (SPI_TPCM_sel? SPI_WPN_IDLE_STATE : CPU_SPI_WPN);
[0089] / * Define SPI hold signal idle state as high (1) and maintain non- hold state * /
[0090] localparam SPI_HOLDN_IDLE_STATE = 1;
[0091] / * SPI hold signal selection logic:
[0092] * Use idle state (SPI_HOLDN_IDLE_STATE) when TPCM path is selected;
[0093] * Otherwise use CPU's SPI hold signal directly
[0094] assign CPLD_QSPI_HOLDN = (SPI_TPCM_sel? SPI_HOLDN_IDLE_STATE : CPU_SPI_HOLDN);
[0095] The main Flash memory is connected to the first SPI interface extended by the CPLD device, and is used for storing the main boot firmware of the system; and the backup Flash memory is connected to the second SPI interface, and is used for storing a completely independent backup boot firmware.
[0096] The TPCM is electrically connected with the CPLD device, and immediately accesses the main and backup Flash memories through the CPLD after the system is powered on, and performs trust measurement on the boot firmware in the main and backup Flash memories, that is, the calculated hash value of the boot firmware is compared with the correct hash value pre-stored in the TPCM, if the comparison result is consistent, it indicates that the measurement is successful, otherwise, it indicates that the measurement fails; finally, the measurement result (success or failure) is fed back to the CPLD device. The GPIO signal line is connected between the CPU and the CPLD device, and is responsible for transmitting the boot failure signal and the reset control signal.
[0097] The TPCM is internally provided with a protected storage area, and the hash value (i.e. reference value) of the boot firmware of the main Flash memory is pre-stored in the protected storage area. The reference value can be updated through an authorized interface in a system security state.
[0098] The following will be described taking the main Flash memory measurement success and boot failure as an example, and the specific working steps are as follows:
[0099] S1: After the system is powered on, the TPCM first measures the boot firmware of the main Flash memory through the CPLD device and obtains a measurement value, and then compares the measurement value with the hash value stored in the TPCM, and the comparison result of the present embodiment is consistent, indicating that the measurement is successful;
[0100] S2: The Loongson 3A6000 CPU is powered on and starts, and the CPLD device switches the SPI signal to the main Flash memory, and the Loongson 3A6000 CPU starts through the boot firmware in the main Flash memory, and if the start is successful, the process ends; in the present embodiment, the start fails, and the process continues to be executed.
[0101] S3: If the main Flash memory fails to start, the Loongson 3A6000 CPU sends a start failure signal to the CPLD device through a GPIO signal line; the CPLD device feeds back the start failure signal to the trusted platform control module TPCM;
[0102] S4: The trusted platform control module TPCM switches to the backup Flash memory through the CPLD device to perform measurement and obtain a measurement value, and then compares the measurement value with the hash value stored by itself; if they are inconsistent, it indicates that the measurement fails, and the system ends the start; if they are consistent, it indicates that the measurement is successful, and the execution starts from step S5 and is sequentially executed;
[0103] S5: The CPLD device operates the reset signal of the Loongson 3A6000 CPU to trigger CPU reset, and switches the SPI signals (such as clock signal, chip select signal, data input signal and data output signal) to the backup Flash memory through programmable logic code for logic programming processing, and the specific method is:
[0104] S51: After receiving the start failure signal sent by the Loongson 3A6000 CPU, the internal logic circuit of the CPLD device generates a control signal according to the preset switching logic, and prepares to switch the output target of the clock signal;
[0105] S52: The CPLD device switches the output target of the clock signal from the main Flash memory to the selected backup Flash memory, ensuring that the clock signal can be correctly transmitted to the backup Flash memory;
[0106] S53: The CPLD device synchronously switches the chip select signal and controls the level of the chip select signal through its internal logic, ensuring that only the selected backup Flash memory can respond to the SPI bus command, while other backup Flash memories are in the unselected state;
[0107] S54: The CPLD device adjusts the level state of the data input signal and the data output signal according to the switching logic to ensure the stability and reliability of the communication between the SPI bus and the backup Flash memory, prevent data writing error or communication interruption;
[0108] S55: The CPLD device completes the switching logic of all SPI signals to ensure that a stable communication connection is established between the SPI bus and the backup Flash memory.
[0109] S6: The Loongson 3A6000 CPU restarts and loads the start firmware of the switched backup Flash memory with successful measurement to start.
[0110] The embodiment realizes automatic switching and trusted starting of the main and standby Flash by extending the SPI interface through the CPLD and combining the TPCM trusted measurement, and improves the system reliability and security. Embodiment Two
[0111] The difference from the above embodiment one is that the system includes three standby Flash memories, i.e., a first standby Flash memory, a second standby Flash memory and a third standby Flash memory.
[0112] The following takes the case of the main Flash memory measurement failure, the first standby Flash memory measurement failure, the second standby Flash memory measurement success and starting success as an example for illustration, and the specific working steps are as follows:
[0113] S1: After the system is powered on, the trusted platform control module TPCM first measures the starting firmware of the main Flash memory through the CPLD device and obtains a measurement value, and then compares the measurement value with the hash value stored in advance by itself, if they are consistent, it indicates that the measurement is successful; in this embodiment, if they are inconsistent, it indicates that the measurement fails, and then it is executed in turn;
[0114] S2: The trusted platform control module TPCM switches to the first standby Flash memory for measurement through the CPLD device and obtains a measurement value, and then compares the measurement value with the hash value stored in advance by itself, if they are consistent, it indicates that the measurement is successful; in this embodiment, if they are inconsistent, it indicates that the measurement fails, and the trusted platform control module TPCM measures the second standby Flash memory which has not been measured, if the measurement result of the second standby Flash memory is still failure, it continues to measure the standby Flash memory which has not been measured until the measurement is successful or all the standby Flash memories are measured; in this embodiment, the measurement of the second standby Flash memory is successful;
[0115] S3: The Loongson 3A6000 CPU is powered on and started, and the CPLD device switches to the second standby Flash memory through the programmable logic code for logical programming processing of the SPI signals (such as clock signal, chip selection signal, data input signal and data output signal), and the specific method is the same as the above embodiment;
[0116] S4: The Loongson 3A6000 CPU loads the starting firmware of the second standby Flash memory through the CPLD device for starting.
[0117] The embodiment adopts the design of multiple standby Flash memories, further enhances the fault tolerance of the system, and ensures that the system can still start normally when the main Flash and part of the standby Flash fail. Embodiment Three
[0118] The difference from the above embodiment one is that the system includes five backup Flash memories, i.e., a first backup Flash memory, a second backup Flash memory, a third backup Flash memory, a fourth backup Flash memory and a fifth backup Flash memory.
[0119] The following takes the case of the main Flash memory measurement failure, the first backup Flash memory measurement failure, the second backup Flash memory measurement failure, the third backup Flash memory measurement failure, the fourth backup Flash memory measurement success and startup failure as an example to illustrate the specific working steps as follows:
[0120] S1: After the system is powered on, the trusted platform control module TPCM first measures the startup firmware of the main Flash memory through the CPLD device and obtains a measurement value, and then compares the measurement value with the hash value stored in advance by itself. If they are consistent, it indicates that the measurement is successful. In this embodiment, they are inconsistent, which indicates that the measurement fails, and then the next one is executed in turn;
[0121] S2: The trusted platform control module TPCM switches to an unmeasured backup Flash memory for measurement through the CPLD device, such as switching to the first backup Flash memory for measurement and obtaining a measurement value, and then comparing the measurement value with the hash value stored in advance by itself. If they are consistent, it indicates that the measurement is successful, and the next step is executed. In this embodiment, they are inconsistent, which indicates that the measurement fails. The trusted platform control module TPCM measures the second backup Flash memory which has not been measured. In this embodiment, the measurement result of the second backup Flash memory is still failure, so the third backup Flash memory which has not been measured is continuously measured until the measurement is successful or all the backup Flash memories are measured. In this embodiment, the measurement result of the third backup Flash memory is still failure, so the fourth backup Flash memory which has not been measured is continuously measured. Since the measurement result of the fourth backup Flash memory in this embodiment is success, the measurement is stopped and the next step is directly executed;
[0122] S3: It is judged whether the Loongson 3A6000 CPU has been started or not. If yes, the domestic CPU reset and restart are triggered through the CPLD device. If not, the Loongson 3A6000 CPU is powered on and the SPI signals (such as clock signal, chip select signal, data input signal and data output signal) are switched to the backup Flash memory (such as the fourth backup Flash memory) whose measurement is successful in step S2 through the logic programming processing of the programmable logic code. The specific method is the same as the above embodiment;
[0123] S4: the Loongson 3A6000 CPU starts up by loading the start-up firmware of the fourth backup Flash memory through the CPLD device, and if the start-up fails, returns to step S2 to switch to the next available backup Flash memory.
[0124] This embodiment demonstrates the system's ability to cope with multiple Flash memory failures in succession, by measuring the backup Flash one by one, ultimately ensuring the successful start-up of the system, embodying high availability. Embodiment Four
[0125] This embodiment aims to further demonstrate the feasibility and robustness of the start-up system and its method through simulation verification means. Before actual deployment of hardware, an EDA tool is used to build a digital simulation platform containing a Loongson 3A6000 CPU behavior model, a CPLD programmable logic code, a master-slave Flash memory model, and a fault injection module. The CPLD logic code is exactly the same as described in Embodiment One. During the verification process, first, the simulation environment is initialized, and the CPLD routes the SPI signal to the master Flash model. Subsequently, the fault injection module simulates the failure of the master Flash, for example, making it return a start-up firmware check error. The simulation platform monitors whether the CPU model sends a start-up failure signal to the CPLD through the GPIO interface as expected. Next, the focus is on verifying the response of the CPLD: whether it can accurately generate a CPU reset signal and complete the switching of the SPI signal path within the preset clock period after receiving the failure signal.
[0126] From Figure 2 we can see that the left side of the red box A (time marker -4050 to -135 segment) is the timing signal of the master Flash memory. From the time marker -135 node, it is switched to the backup Flash memory, i.e., the timing signal of the backup Flash memory on the right side of the red box A. This simulation verification fully proves from the virtual environment that the system described in the invention can reliably perform switching actions when facing hardware failures, ensuring the high availability of the design.
[0127] It should be noted that the domestic CPU, CPLD device, Flash memory, etc. of the invention are all general-purpose devices, which can be flexibly selected in actual application. The above embodiments are only used for illustration by way of example.
[0128] Finally, it should be noted that the above examples are only used to illustrate the present application and are not intended to limit the technical solutions described in the present application; therefore, although the present application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that the present application can still be modified or equivalently replaced; and all technical solutions and improvements that do not deviate from the spirit and scope of the present application should be covered in the scope of the claims of the present application.
Claims
1. A Flash boot system based on a credibility measurement mechanism, characterized in that: This includes a domestically produced CPU, CPLD device, Trusted Platform Control Module (TPCM), main Flash memory, at least one spare Flash memory, and GPIO signal lines; The domestically produced CPU has a single SPI interface, which is electrically connected to the CPLD device through the SPI interface. The CPLD device is used to expand the single-channel SPI interface of the domestic CPU into a multi-channel SPI interface, and to realize the switching control between the main Flash memory and the backup Flash memory based on the measurement results fed back by the Trusted Platform Control Module (TPCM). The main Flash memory is electrically connected to the domestic CPU through one SPI interface of the CPLD device and is used to store the main boot firmware; The backup Flash memory is electrically connected to the domestic CPU through other SPI interfaces of the CPLD device, and each backup Flash memory is used to store independent backup boot firmware; The Trusted Platform Control Module (TPCM) is electrically connected to the CPLD device and is used to perform a trust measurement on the boot firmware stored in the main Flash memory and / or the backup Flash memory through the CPLD device after the system is powered on, and to feed back the measurement result to the CPLD device. The GPIO signal line is used to transmit startup failure signals and reset control signals between the domestic CPU and the CPLD device to realize automatic switching between primary and backup Flash memory.
2. The Flash boot system based on the credibility measurement mechanism according to claim 1, characterized in that: The CPLD device expands the single-channel SPI interface of the domestic CPU into a multi-channel SPI interface through logic programming using programmable logic code.
3. The flash boot system based on the credibility measurement mechanism according to claim 2, characterized in that: The CPLD device internally performs logic programming processing through programmable logic code, including switching logic processing of SPI signal clock signal, chip select signal, data input signal and data output signal.
4. The flash boot system based on the credibility measurement mechanism of claim 1, wherein: The Trusted Platform Control Module (TPCM) measures the boot firmware stored in the main Flash memory and / or the backup Flash memory through the CPLD device, specifically: The Trusted Platform Control Module (TPCM) compares the metric value it calculates for the main Flash memory and / or the backup Flash memory with its own pre-stored hash value. If they match, the metric is successful. If they are inconsistent, it indicates that the measurement has failed.
5. The Flash boot system based on a trust measurement mechanism according to claim 1, characterized in that: The number of the multiple SPI interfaces is equal to the total number of the main Flash memory and all spare Flash memories.
6. The flash boot system based on the credibility measurement mechanism according to claim 1, characterized in that: The domestically produced CPU mentioned is the Loongson processor.
7. A Flash booting method based on a credibility measurement mechanism, characterized in that, The steps for using the Flash boot system based on the trusted measurement mechanism as described in claim 1 are as follows: S1: After the system is powered on, the Trusted Platform Control Module (TPCM) first measures the boot firmware of the main Flash memory through the CPLD device and obtains the measurement value. Then, it compares the measurement value with its own pre-stored hash value. If they match, it indicates that the measurement is successful and continues to the next step. If they do not match, it indicates that the measurement has failed and directly executes step S4. S2: When the domestic CPU is powered on, the CPLD device switches the SPI signal to the main Flash memory, and the domestic CPU starts up by loading the boot firmware in the main Flash memory; S3: If the main Flash memory fails to boot, the domestic CPU sends a boot failure signal to the CPLD device through the GPIO signal line; The CPLD device then feeds back the startup failure signal to the Trusted Platform Control Module (TPCM). S4: The Trusted Platform Control Module (TPCM) switches to an unmeasured backup Flash memory via the CPLD device to perform measurement and obtain the measurement value. Then, it compares the measurement value with its own pre-stored hash value. If they match, it indicates that the measurement was successful and the process continues. If they are inconsistent, it indicates that the measurement has failed. Step S4 is executed repeatedly until the measurement result is successful or all spare Flash memories have been measured. If all spare Flash memories fail to be measured, the system startup process is terminated. S5: Determine whether the domestic CPU has been started. If it is not started, power on the domestic CPU to start it. If it is started, the CPLD device operates on the reset signal of the domestic CPU to trigger the CPU reset and switch the SPI signal to the backup Flash memory that has been successfully measured. S6: After the domestic CPU starts up, it loads the boot firmware of the successfully switched backup Flash memory through the CPLD device to start up.
8. The flash boot method based on the credibility measurement mechanism according to claim 7, characterized in that: In step S5, the CPLD device achieves the switching of SPI signals through logic programming using programmable logic code, including the switching logic of clock signals, chip select signals, data input signals, and data output signals.
9. The flash boot method based on the credibility measurement mechanism according to claim 8, characterized in that: The specific method for switching logic in step S5 is as follows: S51: After the CPLD device receives the start failure signal sent by the domestic CPU, the internal logic circuit first generates a control signal according to the preset switching logic, and prepares to switch the output target of the clock signal. S52: The CPLD device switches the output target of the clock signal from the main Flash memory to the selected backup Flash memory to ensure that the clock signal can be correctly transmitted to the backup Flash memory; S53: The CPLD device synchronously switches the chip select signal and controls the level of the chip select signal through its internal logic to ensure that only the selected spare Flash memory can respond to SPI bus commands, while other spare Flash memories are in an unselected state. S54: The CPLD device adjusts the level of the data input signal and the data output signal according to the switching logic to ensure the stability and reliability of the communication between the SPI bus and the backup Flash memory, and to prevent data writing errors or communication interruptions. S55: The CPLD device completes all SPI signal switching logic, ensuring a stable communication connection between the SPI bus and the backup Flash memory.
10. The Flash boot method based on a trust measurement mechanism according to any one of claims 7-9, characterized in that: If the startup fails after step S6, the process returns to step S4 to switch to the next available backup Flash memory.
Citation Information
Patent Citations
Bootrom backup method and apparatus
WO2012149716A1
Concurrent access method and system and interface device
WO2012155674A1