Device startup method, device, terminal device and storage medium
By using the channel switching module in a multi-core system to perform trustworthy detection on the storage module, the problem of each CPU in the multi-core system requiring multiple trustworthy measurement chips is solved, and the normal startup and trustworthy detection of the terminal device are achieved.
Patent Information
- Application Number
- CN202010437835.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-21
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2040-05-21
AI Technical Summary
In a multi-core system, each CPU requires a trusted measurement chip, which leads to chip waste.
Channel switching is performed on multiple storage modules through a channel switching module, and trustworthy detection is performed on each storage module. Trustworthy detection of all storage modules is achieved using one trustworthy module.
A trusted chip is used to complete the trusted detection of all storage modules, so that the terminal device can start normally and the number of trusted chips used is reduced.
Smart Images

Figure CN111783161B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security and trustworthy technologies, and in particular to a device startup method, apparatus, terminal device, and storage medium. Background Art
[0002] Trusted boot is typically used when booting a multi-core computer system. This approach addresses the issue of user data being tampered with when the computer loses power or is shut down. Multi-core systems include multiple CPUs, each of which has a corresponding storage module for storing system files or personal user files. Currently, trusted boot typically involves attaching a trust measurement chip to each CPU. This chip performs a trustworthy check on the storage module. For multi-core systems, this requires numerous trust measurement chips, resulting in wasted chips. Summary of the Invention
[0003] In view of the above problems, embodiments of the present invention are proposed to provide a device startup method, apparatus, terminal device, and storage medium that overcome the above problems or at least partially solve the above problems.
[0004] In a first aspect, an embodiment of the present invention provides a device startup method, the method being applied to a trusted module in a terminal device, the terminal device including multiple core modules, each of the core modules corresponding to a respective storage module, the trusted module, and a channel switching module, the multiple core modules, the multiple storage modules, and the trusted module being respectively connected to the channel switching module, comprising:
[0005] When the terminal device is abnormal and restarted, the channel switching module switches the channels of the multiple storage modules and performs a credibility check on each of the storage modules;
[0006] When each of the storage modules meets the trustworthy detection requirements, the channel switching module performs channel switching to open the channel between each of the storage modules and the core module corresponding to each of the storage modules, thereby starting the terminal device.
[0007] Optionally, when the terminal device becomes abnormal and restarts, performing channel switching on the multiple storage modules by the channel switching module and performing a credibility check on each of the storage modules includes:
[0008] Sending a first switching instruction to the channel switching module, wherein the first switching instruction includes the storage module identifier, so that the channel switching module establishes connections between the trusted modules and the storage modules corresponding to the storage module identifiers one by one according to the storage module identifiers;
[0009] Determining a current checksum value of a storage file in each of the storage modules;
[0010] The current check value is compared with a storage check value stored in the trusted module, wherein the storage check value is calculated by the trusted module based on the storage file in the storage module when an abnormality occurs in the terminal device.
[0011] Optionally, when each of the storage modules meets the trust detection requirement, performing channel switching by the channel switching module to open a channel between each of the storage modules and a core module corresponding to each of the storage modules, and starting the terminal device, includes:
[0012] If the current check value and the stored check value are the same, determining that the storage module corresponding to the current check value meets the trustworthy detection requirement;
[0013] Sending a second switching instruction to the channel switching module, wherein the second switching instruction includes the storage module identifier, so that the channel switching module opens the storage module corresponding to the storage module identifier and the storage channel of the core module corresponding to the storage module according to the storage module identifier in the second switching instruction;
[0014] In the case that each of the storage modules meets the trustworthy detection requirements, the channel switching module is used to open the storage channel of each storage module and the core module corresponding to the storage module, thereby starting the terminal device.
[0015] Optionally, determining the current checksum of the storage file in each storage module includes:
[0016] Obtaining the storage file in the storage module;
[0017] Calculating a hash value of a message digest algorithm of the stored file according to the content of the stored file in the storage module;
[0018] A hash value of the message digest algorithm is determined as the current check value.
[0019] Optionally, the channel switching module is a control module based on FPGA.
[0020] In a second aspect, an embodiment of the present invention provides a device startup apparatus, the apparatus being applied to a trusted module in a terminal device, the terminal device including multiple core modules, each of the core modules corresponding to a respective storage module, the trusted module, and a channel switching module, the multiple core modules, the multiple storage modules, and the trusted module being respectively connected to the channel switching module, the apparatus comprising:
[0021] a detection unit, configured to, when the terminal device becomes abnormal and restarts, switch channels of the plurality of storage modules through the channel switching module and perform a credibility check on each of the storage modules;
[0022] The opening unit is used to open the channel of each storage module and the core module corresponding to each storage module through the channel switching module when each storage module meets the trustworthy detection requirements, thereby starting the terminal device.
[0023] Optionally, the detection unit is used to:
[0024] Sending a first switching instruction to the channel switching module, wherein the first switching instruction includes the storage module identifier, so that the channel switching module establishes connections between the trusted modules and the storage modules corresponding to the storage module identifiers one by one according to the storage module identifiers;
[0025] Determining a current checksum value of a storage file in each of the storage modules;
[0026] The current check value is compared with a storage check value stored in the trusted module, wherein the storage check value is calculated by the trusted module based on the storage file in the storage module when an abnormality occurs in the terminal device.
[0027] Optionally, the opening unit is used to:
[0028] If the current check value and the stored check value are the same, determining that the storage module corresponding to the current check value meets the trustworthy detection requirement;
[0029] Sending a second switching instruction to the channel switching module, wherein the second switching instruction includes the storage module identifier, so that the channel switching module opens the storage module corresponding to the storage module identifier and the storage channel of the core module corresponding to the storage module according to the storage module identifier in the second switching instruction;
[0030] In the case that each of the storage modules meets the trustworthy detection requirements, the channel switching module is used to open the storage channel of each storage module and the core module corresponding to the storage module, thereby starting the terminal device.
[0031] Optionally, the detection unit is specifically configured to:
[0032] Obtaining the storage file in the storage module;
[0033] Calculating a hash value of a message digest algorithm of the stored file according to the content of the stored file in the storage module;
[0034] A hash value of the message digest algorithm is determined as the current check value.
[0035] Optionally, the channel switching module is a control module based on FPGA.
[0036] In a third aspect, an embodiment of the present invention provides a terminal device, comprising: at least one processor and a memory;
[0037] The memory stores a computer program; the at least one processor executes the computer program stored in the memory to implement the device startup method provided in the first aspect.
[0038] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed, the device startup method provided in the first aspect is implemented.
[0039] The embodiments of the present invention include the following advantages:
[0040] The device startup method, apparatus, terminal device and storage medium provided in the embodiment of the present invention provide a channel switching module. When the terminal device encounters an abnormality and restarts, the channel switching module is used to switch channels of multiple storage modules and perform trust detection on each storage module. When each storage module meets the trust detection requirements, the channel switching module is used to switch channels to open the channels of each storage module and the core module corresponding to each storage module, and the terminal device is started. In the embodiment of the present invention, a channel switching module is added, and only one trusted module is required. The channel switching module is used to switch between different channels, so that the trusted chip can access the storage modules of different core modules and perform trust detection on the storage modules one by one, thereby realizing that one trusted chip completes the trust detection of all storage modules, so that the terminal device starts normally. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 is a flowchart of steps of an embodiment of a device startup method of the present invention;
[0042] Figure 2 is a flowchart of steps of another device startup method embodiment of the present invention;
[0043] Figure 3 It is a structural schematic diagram of an embodiment of a device startup system of the present invention;
[0044] Figure 4 It is a structural diagram of another embodiment of a device startup system of the present invention;
[0045] Figure 5 It is a structural block diagram of an embodiment of a device starting device of the present invention;
[0046] Figure 6 It is a structural schematic diagram of a terminal device of the present invention. DETAILED DESCRIPTION
[0047] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0048] One embodiment of the present invention provides a device startup method for enabling a terminal device to boot normally after performing a trustworthy check on a storage module. This embodiment is performed by a device startup apparatus, which is disposed on a trusted module in a terminal device. The terminal device may be a computer, tablet computer, or mobile phone terminal. The computer may be a computer used for Internet communication, or a visual network terminal or server used for visual network communication.
[0049] Reference Figure 1 , shows a flowchart of the steps of an embodiment of a device startup method of the present invention. The method can be applied to a trusted module in a terminal device, wherein the terminal device includes multiple core modules, each of which corresponds to a respective storage module, the trusted module, and a channel switching module. The multiple core modules, the multiple storage modules, and the trusted module are respectively connected to the channel switching module. Specifically, the method may include the following steps:
[0050] S101: When the terminal device is abnormal and restarted, the channel switching module switches the channels of the multiple storage modules and performs a credibility check on each of the storage modules;
[0051] Specifically, before the terminal device is started, the trusted module will perform a trusted check on the storage module. In some cases, the terminal device will experience an abnormality, such as power failure or shutdown. When the terminal device needs to be restarted, the terminal device includes multiple core modules, such as multiple CPUs, and there are multiple storage modules corresponding to the multiple CPUs, such as flash memory or hard disks. The trusted module needs to perform a trusted check on each storage module. In the prior art, each CPU corresponds to a trusted module, and the trusted module performs a trusted check on the storage module corresponding to the CPU. In the embodiment of the present invention, only one trusted module is needed, and a channel switching module is provided. Through the channel switching module, the trusted module can access the storage modules one by one and perform a trusted check on each storage module.
[0052] S102: When each of the storage modules meets the trust detection requirement, the channel switching module performs channel switching to open a channel between each of the storage modules and a core module corresponding to each of the storage modules, and start the terminal device.
[0053] Specifically, if each storage module meets the trusted detection requirements, that is, the storage files in the storage module have not been modified, the trusted module opens the channel of each storage module and the core module corresponding to each storage module through the channel switching module. When all the CPUs and the channels of the storage modules corresponding to the CPUs are opened, the terminal device starts to start.
[0054] The device startup method provided by the embodiment of the present invention provides a channel switching module. When the terminal device encounters an abnormality and restarts, the channel switching module is used to switch channels of multiple storage modules and perform trust detection on each storage module. When each storage module meets the trust detection requirements, the channel switching module is used to switch channels to open the channels of each storage module and the core module corresponding to each storage module, so as to start the terminal device. In the embodiment of the present invention, a channel switching module is added, and only one trusted module is required. The channel switching module is used to switch between different channels, so that the trusted chip can access the storage modules of different core modules and perform trust detection on the storage modules one by one, thereby realizing that one trusted chip completes the trust detection of all storage modules, so that the terminal device starts normally.
[0055] Another embodiment of the present invention further supplements the device startup method provided in the above embodiment.
[0056] like Figure 2 FIG. 1 is a flowchart showing another embodiment of a device startup method of the present invention, which is applied to a trusted module in a terminal device. The terminal device includes multiple core modules, each of which corresponds to a respective storage module, the trusted module, and a channel switching module. The multiple core modules, the multiple storage modules, and the trusted module are respectively connected to the channel switching module. The device startup method includes:
[0057] S201: When the terminal device encounters an abnormality and restarts, sending a first switching instruction to the channel switching module, wherein the first switching instruction includes the storage module identifier, so that the channel switching module establishes connections between the trusted modules and the storage modules corresponding to the storage module identifiers one by one according to the storage module identifiers;
[0058] S202: Determine the current checksum of the storage file in each storage module;
[0059] Specifically, step S202 includes:
[0060] A. Obtain the storage file in the storage module;
[0061] B. Calculating a hash value of a message digest algorithm of the stored file according to the content of the stored file in the storage module;
[0062] Specifically, the trusted module calculates the MD5 value of the storage file, ie, the hash value of the message digest algorithm, according to the content of the storage file in the storage module.
[0063] MD5, or Message-Digest Algorithm 5 (MD5), is a hash function widely used in computer security to protect message integrity. The MD5 value is like a file ID and is unique. If the file has been modified (for example, by embedding a virus or Trojan horse), its MD5 value will change.
[0064] C. Determine the hash value of the message digest algorithm as the current check value.
[0065] S203, comparing the current check value with a stored check value stored in the trusted module, wherein the stored check value is calculated by the trusted module based on the stored file in the storage module when an abnormality occurs in the terminal device; if the current check value is the same, executing S204; if the current check value is different, executing S205;
[0066] Specifically, the trusted module needs to calculate the MD5 value of the storage file in the storage module of the terminal device before the abnormality occurs, and store the MD5 value in the trusted module, which is the storage verification value. After the abnormality occurs in the terminal device, the trusted module compares the stored verification value with the current verification value to perform a trustworthy detection.
[0067] S204: If the current check value and the stored check value are the same, determining that the storage module corresponding to the current check value meets the trusted detection requirement; sending a second switching instruction to the channel switching module, wherein the second switching instruction includes the storage module identifier, so that the channel switching module opens the storage module corresponding to the storage module identifier and the storage channel of the core module corresponding to the storage module according to the storage module identifier in the second switching instruction;
[0068] S205: If the current check value is different from the stored check value, the trusted module controls the power switch of the terminal device to turn off the power supply, so that the terminal device cannot be started.
[0069] S206 : When each of the storage modules meets the trust detection requirement, the channel switching module is used to open the storage channel of each storage module and the core module corresponding to the storage module, thereby starting the terminal device.
[0070] Figure 3 FIG. 1 is a schematic diagram of a device startup system embodiment of the present invention. Figure 3 As shown, the device startup system of the terminal device includes multiple CPUs and multiple storage modules, namely CPU-1 3012 and storage-1 3011, CPU-2 3022 and storage-2 3021, CPU-3 3032 and storage-3 3031, and all are connected to FPGA 304 through the NIFC storage interface. FPGA 304 is a channel switching module, and a trusted chip and trusted module 305 are connected to FPGA 304 through the NIFC. Trusted chip 305 is also connected to the power switch.
[0071] Figure 4 1 is a structural diagram of another embodiment of a device startup system of the present invention, the device startup system includes CPU-1 4012 and FLASH-1 4011, CPU-2 4022 and storage-2 4021, FPGA403 module includes a channel switching module, and a trusted module 404 is connected to FPGA403. Figure 4 It reflects the internal logical relationship of the channel switching module.
[0072] Specifically, the channel switching module is a control module based on an FPGA. An FPGA (Field-Programmable Gate Array) is a further development of programmable devices such as PALs, GALs, and CPLDs. As a semi-custom circuit within the application-specific integrated circuit (ASIC) field, it addresses the shortcomings of custom circuits while also overcoming the limited number of gates inherent in existing programmable devices.
[0073] When the terminal device is started, the trusted module pulls down the RST (reset pin) of all CPUs to put the CPUs in reset state.
[0074] The NFCI (storage interface) of the trusted module is connected to the FPGA. When the CPU is in reset state, the trusted module controls the channel switching logic of the FPGA to connect the NFCI interface of the trusted module to storage_1 through the FPGA.
[0075] After the connection is established, the trusted module begins checking the MD5 values of all files stored in Flash-1. The trusted module stores the MD5 values of all files up to the time of the last shutdown. By comparing the two, it can determine whether the files have been modified.
[0076] If the trusted module finds a difference in the MD5 value comparison, it controls the power switch of the terminal device to turn off the power, making the terminal device unable to start;
[0077] If the trusted module finds no difference in the MD5 value comparison, it controls the FPGA to perform channel conversion, opens the NFCI channel between CPU_1 and storage_1, and then pulls the RST pin of CPU_1 high, so that CPU_1 starts to work normally.
[0078] Similarly, the trusted module detects each storage module and controls the FPGA to open the NFCI channel between the storage module and the corresponding CPU, while releasing RST to a high level to start the terminal device.
[0079] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.
[0080] The device startup method provided by the embodiment of the present invention provides a channel switching module. When the terminal device encounters an abnormality and restarts, the channel switching module is used to switch channels of multiple storage modules and perform trust detection on each storage module. When each storage module meets the trust detection requirements, the channel switching module is used to switch channels to open the channels of each storage module and the core module corresponding to each storage module, so as to start the terminal device. In the embodiment of the present invention, a channel switching module is added, and only one trusted module is required. The channel switching module is used to switch between different channels, so that the trusted chip can access the storage modules of different core modules and perform trust detection on the storage modules one by one, thereby realizing that one trusted chip completes the trust detection of all storage modules, so that the terminal device starts normally.
[0081] Another embodiment of the present invention provides a device startup apparatus, which is used to execute the device startup method provided in the above embodiment.
[0082] Reference Figure 5, shows a structural block diagram of an embodiment of a device startup device of the present invention. The device can be applied to a trusted module in a terminal device. The terminal device includes multiple core modules, each of which corresponds to a respective storage module, the trusted module, and a channel switching module. The multiple core modules, the multiple storage modules, and the trusted module are respectively connected to the channel switching module. Specifically, the terminal device may include the following modules: a detection unit 501 and an activation unit 502, wherein:
[0083] The detection unit 501 is configured to, when the terminal device becomes abnormal and restarts, switch channels of the multiple storage modules through the channel switching module and perform a credibility check on each of the storage modules;
[0084] The opening unit 502 is used to open the channel of each storage module and the core module corresponding to each storage module through the channel switching module when each storage module meets the trust detection requirements, and start the terminal device.
[0085] The device startup device provided by the embodiment of the present invention provides a channel switching module. When the terminal device encounters an abnormality and restarts, the channel switching module is used to switch channels of multiple storage modules and perform trust detection on each storage module. When each storage module meets the trust detection requirements, the channel switching module is used to switch channels to open the channels of each storage module and the core module corresponding to each storage module, and the terminal device is started. In the embodiment of the present invention, a channel switching module is added, and only one trusted module is needed. The channel switching module is used to switch between different channels, so that the trusted chip can access the storage modules of different core modules and perform trust detection on the storage modules one by one, thereby realizing that one trusted chip completes the trust detection of all storage modules, so that the terminal device starts normally.
[0086] Another embodiment of the present invention provides further supplementary explanations for the device starting apparatus provided in the above embodiment.
[0087] Optionally, the detection unit 501 is configured to:
[0088] Sending a first switching instruction to the channel switching module, wherein the first switching instruction includes the storage module identifier, so that the channel switching module establishes connections between the trusted modules and the storage modules corresponding to the storage module identifiers one by one according to the storage module identifiers;
[0089] Determining a current checksum value of a storage file in each of the storage modules;
[0090] The current check value is compared with a storage check value stored in the trusted module, wherein the storage check value is calculated by the trusted module based on the storage file in the storage module when an abnormality occurs in the terminal device.
[0091] Optionally, the opening unit 502 is used to:
[0092] If the current check value is the same as the stored check value, determining that the storage module corresponding to the current check value meets the trustworthy detection requirement;
[0093] Sending a second switching instruction to the channel switching module, wherein the second switching instruction includes the storage module identifier, so that the channel switching module opens the storage module corresponding to the storage module identifier and the storage channel of the core module corresponding to the storage module according to the storage module identifier in the second switching instruction;
[0094] In the case that each of the storage modules meets the trustworthy detection requirements, the channel switching module is used to open the storage channel of each storage module and the core module corresponding to the storage module, thereby starting the terminal device.
[0095] Optionally, the detection unit 501 is specifically configured to:
[0096] Obtaining the storage file in the storage module;
[0097] Calculating a hash value of a message digest algorithm of the stored file according to the content of the stored file in the storage module;
[0098] A hash value of the message digest algorithm is determined as the current check value.
[0099] Optionally, the channel switching module is a control module based on FPGA.
[0100] It should be noted that each implementable method in this embodiment can be implemented separately, or can be implemented in combination in any combination without conflict, and this application does not limit it.
[0101] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0102] The device startup device provided by the embodiment of the present invention provides a channel switching module. When the terminal device encounters an abnormality and restarts, the channel switching module is used to switch channels of multiple storage modules and perform trust detection on each storage module. When each storage module meets the trust detection requirements, the channel switching module is used to switch channels to open the channels of each storage module and the core module corresponding to each storage module, and the terminal device is started. In the embodiment of the present invention, a channel switching module is added, and only one trusted module is needed. The channel switching module is used to switch between different channels, so that the trusted chip can access the storage modules of different core modules and perform trust detection on the storage modules one by one, thereby realizing that one trusted chip completes the trust detection of all storage modules, so that the terminal device starts normally.
[0103] Yet another embodiment of the present invention provides a terminal device for executing the device startup method provided in the above embodiment.
[0104] Figure 6 This is a schematic diagram of the structure of a terminal device of the present invention, such as Figure 6 As shown, the terminal device includes: at least one processor 601 and a memory 602;
[0105] The memory stores a computer program; and the at least one processor executes the computer program stored in the memory to implement the device startup method provided in the above embodiment.
[0106] The terminal device provided in this embodiment provides a channel switching module. When the terminal device encounters an abnormality and restarts, the channel switching module is used to switch channels of multiple storage modules and perform trust detection on each storage module. When each storage module meets the trust detection requirements, the channel switching module is used to switch channels to open the channels of each storage module and the core module corresponding to each storage module, and the terminal device is started. In the embodiment of the present invention, a channel switching module is added, and only one trusted module is needed. The channel switching module is used to switch between different channels, so that the trusted chip can access the storage modules of different core modules and perform trust detection on the storage modules one by one, thereby realizing that one trusted chip completes the trust detection of all storage modules, so that the terminal device starts normally.
[0107] Yet another embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed, the device startup method provided by any of the above embodiments is implemented.
[0108] According to the computer-readable storage medium of this embodiment, by providing a channel switching module, when the terminal device encounters an abnormality and restarts, the channel switching module is used to switch channels of multiple storage modules, and a trustworthy test is performed on each storage module; when each storage module meets the trustworthy test requirements, the channel switching module is used to switch channels to open each storage module and the channel of the core module corresponding to each storage module, and the terminal device is started. In the embodiment of the present invention, a channel switching module is added, and only one trusted module is needed. The channel switching module is used to switch between different channels, so that the trusted chip can access the storage modules of different core modules and perform trustworthy tests on the storage modules one by one, thereby realizing that one trusted chip completes the trustworthy test of all storage modules, so that the terminal device starts normally.
[0109] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0110] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, embodiments of the present invention may take the form of a fully hardware embodiment, a fully software embodiment, or an embodiment combining software and hardware. Furthermore, embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0111] The embodiments of the present invention are described with reference to flowcharts and / or block diagrams of methods, electronic devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing electronic device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing electronic device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0112] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing electronic device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0113] These computer program instructions can also be loaded onto a computer or other programmable data processing electronic device so that a series of operating steps are executed on the computer or other programmable electronic device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable electronic device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0114] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0115] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprises", or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or electronic device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements that are inherent to such process, method, article, or electronic device. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of additional identical elements in the process, method, article, or electronic device that includes the element.
[0116] The above is a detailed introduction to a device startup method and a device startup device provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A device startup method, characterized in that: The method is applied to a trusted module in a terminal device, the terminal device including multiple core modules, each of the core modules corresponding to a respective storage module, the trusted module, and a channel switching module, the multiple core modules, the multiple storage modules, and the trusted module being respectively connected to the channel switching module, the method comprising: When the terminal device is abnormal and restarted, the channel switching module switches the channels of the multiple storage modules and performs a credibility check on each of the storage modules; When each of the storage modules meets the trust detection requirement, the channel switching module performs channel switching to open a channel between each of the storage modules and a core module corresponding to each of the storage modules, thereby starting the terminal device; The step of opening a channel between each storage module and a core module corresponding to each storage module, and starting the terminal device, includes: The storage interface channel between each storage module and the core module corresponding to the storage module is opened, the reset pin of the core module corresponding to each storage module is released to a high level, and the terminal device is started.
2. The method according to claim 1, characterized in that When the terminal device is abnormal and restarted, the channel switching module is used to switch the channels of the multiple storage modules, and a credibility detection is performed on each of the storage modules, including: Sending a first switching instruction to the channel switching module, wherein the first switching instruction includes the storage module identifier, so that the channel switching module establishes connections between the trusted modules and the storage modules corresponding to the storage module identifiers one by one according to the storage module identifiers; Determining a current checksum value of a storage file in each of the storage modules; The current check value is compared with a storage check value stored in the trusted module, wherein the storage check value is calculated by the trusted module based on the storage file in the storage module when an abnormality occurs in the terminal device.
3. The method according to claim 2, characterized in that When each of the storage modules meets the trust detection requirement, performing channel switching by the channel switching module to open a channel between each of the storage modules and a core module corresponding to each of the storage modules, and starting the terminal device, includes: If the current check value is the same as the stored check value, determining that the storage module corresponding to the current check value meets the trustworthy detection requirement; Sending a second switching instruction to the channel switching module, wherein the second switching instruction includes the storage module identifier, so that the channel switching module opens the storage module corresponding to the storage module identifier and the storage channel of the core module corresponding to the storage module according to the storage module identifier in the second switching instruction; In the case that each of the storage modules meets the trustworthy detection requirements, the channel switching module is used to open the storage channel of each storage module and the core module corresponding to the storage module, thereby starting the terminal device.
4. The method according to claim 2, characterized in that Determining the current checksum of the storage file in each storage module includes: Obtaining the storage file in the storage module; Calculating a hash value of a message digest algorithm of the stored file according to the content of the stored file in the storage module; A hash value of the message digest algorithm is determined as the current check value.
5. The method according to any one of claims 1 to 4, characterized in that: The channel switching module is a control module based on FPGA.
6. A device starting device, characterized in that: The device is applied to a trusted module in a terminal device, the terminal device including multiple core modules, each of which corresponds to a respective storage module, the trusted module, and a channel switching module, the multiple core modules, the multiple storage modules, and the trusted module being connected to the channel switching module respectively, and the device including: a detection unit, configured to, when the terminal device becomes abnormal and restarts, switch channels of the plurality of storage modules through the channel switching module and perform a credibility check on each of the storage modules; An enabling unit is configured to enable, when each of the storage modules meets the trusted detection requirements, a channel switching through the channel switching module to enable a channel between each of the storage modules and a core module corresponding to each of the storage modules, thereby enabling the terminal device; enabling a channel between each of the storage modules and a core module corresponding to each of the storage modules to enable the terminal device, comprising: enabling a storage interface channel between each of the storage modules and the core module corresponding to the storage module, releasing a reset pin of the core module corresponding to each of the storage modules to a high level, thereby enabling the terminal device.
7. The device according to claim 6, characterized in that The detection unit is specifically used for: Sending a first switching instruction to the channel switching module, wherein the first switching instruction includes the storage module identifier, so that the channel switching module establishes connections between the trusted modules and the storage modules corresponding to the storage module identifiers one by one according to the storage module identifiers; Determining a current checksum value of a storage file in each of the storage modules; The current check value is compared with a storage check value stored in the trusted module, wherein the storage check value is calculated by the trusted module based on the storage file in the storage module when an abnormality occurs in the terminal device.
8. The device according to claim 7, characterized in that The opening unit is specifically used for: If the current check value is the same as the stored check value, determining that the storage module corresponding to the current check value meets the trustworthy detection requirement; Sending a second switching instruction to the channel switching module, wherein the second switching instruction includes the storage module identifier, so that the channel switching module opens the storage module corresponding to the storage module identifier and the storage channel of the core module corresponding to the storage module according to the storage module identifier in the second switching instruction; In the case that each of the storage modules meets the trustworthy detection requirements, the channel switching module is used to open the storage channel of each storage module and the core module corresponding to the storage module, thereby starting the terminal device.
9. A terminal device, characterized in that: include: at least one processor and memory; The memory stores a computer program; The at least one processor executes the computer program stored in the memory to implement the device startup method according to any one of claims 1 to 5.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed, implements the device startup method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Multi-core system and starting method thereof
CN102043648A
Module for starting multiple user programs by single Flash
CN102662718A
Trusted boot method and apparatus for mobile operation system
CN106384053A
A trusted computing platform architecture
CN109325352A