Security starting method of high-level security chip and smart television
By employing a secure boot method based on an advanced security chip, the boot signature and partition signature of the smart TV are verified, thus resolving the security, reliability, and privacy data leakage issues of the smart TV system and achieving system security, reliability, and integrity.
Patent Information
- Application Number
- CN202110367564.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-06
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2041-04-06
AI Technical Summary
In existing technologies, the software systems of smart TVs are not very secure and reliable, and are easily threatened by hacker attacks and the leakage of user privacy data.
The system employs a secure boot method using an advanced security chip. It verifies the boot signature to determine the boot mode and verifies the kernel and recovery partition signatures to ensure system security.
It improves the security of smart TV systems, prevents malicious flashing and leakage of user privacy data, and ensures the reliability and integrity of the system.
Smart Images

Figure CN113032031B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of intelligent television, and particularly relates to a security starting method of an advanced security chip, an intelligent television and a computer readable storage medium. BACKGROUND
[0002] Television is an important tool for spreading culture and information, and television programs are rich in education and entertainment, and are also a source of knowledge. Sitting at home and watching television can know about national and world events, expand knowledge, and relax tense learning, which can better prepare for learning and learn standard Mandarin. Watching television can also broaden one's horizons and bring joy to the mind and body.
[0003] As a terminal and center of home network, television is used by all members of the family, and the security of television is facing more and more serious security threats. The security of television products mainly involves the television product itself, data transmission, IPTV, multi-screen mobile terminal and other levels. Therefore, it is necessary to analyze the security threats and take corresponding security measures to avoid hacking attacks on the television software system or malicious flashing, so as to ensure the security and reliability of the television software system and prevent user privacy data leakage.
[0004] Therefore, the prior art still needs to be improved and developed. SUMMARY
[0005] The main purpose of the present application is to provide a security starting method of an advanced security chip, an intelligent television and a computer readable storage medium, which aims to solve the problem of low security and reliability of the television software system and user privacy data leakage in the prior art
[0006] To achieve the above purpose, the present application provides a security starting method of an advanced security chip, which comprises the following steps:
[0007] When the intelligent television is started, the Boot signature of the advanced security chip is checked, and it is judged whether the security check is successful;
[0008] If the security check is successful, the current starting mode is judged according to the flag bit, and the starting mode includes Recovery mode and Kernel mode;
[0009] If the current starting mode is Kernel mode, the Kernel partition signature is checked, and if the Kernel partition signature check is successful, the Kernel partition is started;
[0010] If the current starting mode is Recovery mode, the Recovery partition signature is checked, and if the Recovery partition signature check is successful, the Recovery partition is started.
[0011] Optionally, the secure boot method of the advanced security chip, wherein the security check of the Boot signature after the smart television is started and the judgment of whether the check is successful, further comprises:
[0012] If the security check fails, reset to start the security check of the Boot signature again.
[0013] Optionally, the secure boot method of the advanced security chip, wherein if the current boot mode is the Kernel mode, the Kernel partition signature is checked, and the method further comprises:
[0014] If the Kernel partition signature check fails, enter the Recovery mode and check the Recovery partition signature.
[0015] Optionally, the secure boot method of the advanced security chip, wherein if the current boot mode is the Recovery mode, the Recovery partition signature is checked, and the method further comprises:
[0016] If the Recovery partition signature check fails, reset to start the security check of the Boot signature again.
[0017] Optionally, the secure boot method of the advanced security chip, wherein the security check of the Boot signature of the advanced security chip further comprises:
[0018] When the smart television is started, the BootRom code fixed in the content of the chip is executed by the advanced security chip.
[0019] The public key is obtained by checking the KeyArea region signature, the Param region signature is checked by using the public key, and the Boot area data is loaded to the DDR by using the Param to continue the signature check.
[0020] Optionally, the secure boot method of the advanced security chip, wherein the secure boot method of the advanced security chip further comprises:
[0021] During the Boot booting process, the Bootargs, the Kernel and the sensitive partition are checked, and if the check fails, the Recovery interface is automatically entered to wait for the system to be upgraded.
[0022] Optionally, the secure boot method of the advanced security chip, wherein the secure boot method of the advanced security chip further comprises:
[0023] If the Recovery partition signature check succeeds, enter the Recovery mode to wait for the upgrade.
[0024] If the signature check of the Recovery partition fails, the smart TV is restarted, the Recovery partition is repeatedly verified, and the Recovery partition needs to be re-burned and then normally started.
[0025] Optionally, the secure starting method of the high-level security chip further comprises:
[0026] When the Kernel partition is normally started, the system partition is started.
[0027] When the system partition is modified, the system partition is remounted in the shell.
[0028] In addition, to achieve the above object, the application further provides a smart TV, wherein the smart TV comprises a memory, a processor, and a secure starting program of a high-level security chip stored in the memory and executable on the processor, and the secure starting program of the high-level security chip, when executed by the processor, implements the steps of the secure starting method of the high-level security chip.
[0029] In addition, to achieve the above object, the application further provides a computer readable storage medium, wherein the computer readable storage medium stores a secure starting program of a high-level security chip, and the secure starting program of the high-level security chip, when executed by a processor, implements the steps of the secure starting method of the high-level security chip.
[0030] In the application, when the smart TV is started, the Boot signature of the high-level security chip is checked, and it is determined whether the security check is successful; if the security check is successful, it is determined according to a flag bit whether the current starting mode is a Recovery mode or a Kernel mode; if the current starting mode is the Kernel mode, the signature of the Kernel partition is checked, and if the signature check of the Kernel partition is successful, the Kernel partition is started; if the current starting mode is the Recovery mode, the signature of the Recovery partition is checked, and if the signature check of the Recovery partition is successful, the Recovery partition is started. BRIEF DESCRIPTION OF DRAWINGS
[0031] Figure 1is a flow chart of a preferred embodiment of the security starting method of the advanced security chip of the present application;
[0032] Figure 2 is a schematic diagram of the principle of the whole execution process in the preferred embodiment of the security starting method of the advanced security chip of the present application;
[0033] Figure 3 is a schematic diagram of the running environment of the preferred embodiment of the smart TV of the present application. DETAILED DESCRIPTION
[0034] In order to make the object, technical solutions and advantages of the present application clearer and more explicit, the present application is further described in detail below with reference to the drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0035] The security starting method of the advanced security chip according to the preferred embodiment of the present application, as shown in Figure 1 and Figure 2 includes the following steps:
[0036] Step S10, when the smart TV is started, the security check of the Boot signature of the advanced security chip is performed, and it is determined whether the security check is successful.
[0037] The advanced security chip (referred to as high security chip) is a chip that can provide more secure protection measures. Compared with the traditional chip, the security information processing module is added, the unique mark CHIPID (i.e. chip ID) is provided, the binding with the digital all-in-one machine CA card is facilitated, the Boot (Boot refers to the boot program, which can enter the system first, obtain the control right of the system, and then import all the operating system programs) security starting is supported, the Boot signature check and encryption mechanism are provided, the security CPU is built-in, and the JTAG (Joint Test Action Group, international standard test protocol) protection is supported.
[0038] For example, taking the HiSilicon V811 high security chip as an example, the high security chip will complete the signature check of the Boot image when starting, ensuring the Boot security. For non-Boot image, the high security chip provides two methods of specific signature mode and general signature mode to check it, ensuring the partition security. The specific signature mode is used in the scene where the image needs to be encrypted, and the structure thereof is usually signature head, image and signature tail. The general signature mode is used in the scene where the security requirement is not high, and the image is stored in the Flash in plaintext, and the structure thereof is usually image and signature tail.
[0039] When the smart TV is started, the system of the smart TV will perform the security check of the Boot signature of the advanced security chip, and it is determined whether the security check is successful.
[0040] Step S20, if the security check is successful, then determine the current boot mode according to the flag bit, the boot mode including Recovery mode and Kernel mode.
[0041] When the security check is successful, determine the current boot mode according to the flag bit, the boot mode including Recovery mode (Recovery is an Android device backup function, which refers to a mode that can modify the data or system inside the Android device, in this mode, the existing system can be backed up or upgraded, and the factory settings can also be restored) and Kernel mode (Kernel mode, in the kernel mode, the code being executed has complete and unrestricted access to the underlying hardware, it can execute any CPU instructions and reference any memory address. Kernel mode is usually reserved for the lowest level of the operating system, the most trusted function), that is, according to the flag bit, start the Recovery partition or the Kernel partition respectively.
[0042] Further, as shown in Figure 2 If the security check fails, reset and start the security check of the Boot signature again.
[0043] Step S30, if the current boot mode is Kernel mode, then check the Kernel partition signature, and if the Kernel partition signature check is successful, start the Kernel partition.
[0044] When the boot mode is Kernel mode, check the Kernel partition signature, and determine whether the Kernel partition signature check is successful, if the Kernel partition signature check is successful, start the Kernel partition, that is, if the Kernel partition check is successful, normally enter the Android system.
[0045] Further, as shown in Figure 2 If the Kernel partition signature check fails, enter the Recovery mode, and check the Recovery partition signature.
[0046] Step S40, if the current boot mode is Recovery mode, then check the Recovery partition signature, and if the Recovery partition signature check is successful, start the Recovery partition.
[0047] When the boot mode is Recovery mode, check the Recovery partition signature, and determine whether the Recovery partition signature check is successful, if the Recovery partition signature check is successful, start the Recovery partition, that is, enter the Recovery upgrade mode.
[0048] Further, as shown in Figure 2 If the Recovery partition signature verification fails, the reset restarts the Boot signature security verification.
[0049] For example, there is an OTP module in HiSilicon chips. OTP (One Time Program) is a secure and sensitive data storage area in the chip, which can only be programmed once. This secure storage area is used to store verification keys, ITVID, etc. The data stored in OTP can be permanently saved and cannot be tampered with. During the boot-up process, the image to be loaded and run is checked for integrity to prevent malicious tampering of system software.
[0050] Further, to prevent malicious flashing, the system based on the HiAn chip will perform signature verification on the boot-up boot module. When the smart TV is powered on, the HiAn chip will first execute the BootRom code (BootRom is a small mask ROM or write-protected flash memory embedded in the processor chip, which contains the first code executed by the processor when powered on or reset) fixed in the content of the chip. By verifying the KeyArea (key or sensitive area) region signature, the public key is obtained, the Param region signature is verified with the public key, and then the Param loads the Boot region data to the DDR to continue the signature verification. After the verification is passed, it jumps to Boot, that is, the system Bootloader performs the next step of starting. The whole process is completed by the HiAn chip without the need for software system processing. The HiSilicon security chip has a unified fastboot design, that is, non-HiAn fastboot and HiAn signature Finalboot are compatible, and non-secure chips can also start with HiAn signature Finalboot. Therefore, during the Flash burning stage of mass production, the HiAn signature Finalboot can be directly burned.
[0051] Unlike conventional systems, BootLoader needs to perform signature verification on the corresponding partition when starting Kernel. Because the HiAn chip only guarantees the safety of BootLoader when starting, other partitions are not subject to verification. At this time, BootLoader needs to ensure the safety of sensitive areas. During the Boot startup process, Bootargs, Kernel, and other sensitive partitions will be checked. If the verification fails, it will automatically enter the Recovery interface and wait for the system to be upgraded again.
[0052] When the Recovery mode is triggered, the BootLoader will guide the system to start the Recovery. Since the upgrade package verification is an important part of the security link, the Recovery partition is also usually subjected to signature verification. The regular partition signature verification is completed when the Kernel is started, and here only the signature verification of the Recovery partition is needed. After the verification passes, the Recovery mode is entered, and the upgrade is waited for. After the verification fails, the smart TV is restarted, and the Recovery partition is repeatedly verified. At this time, the Recovery partition needs to be re-burned to normally start.
[0053] Android system security, the system will start the Kernel partition after the normal start, and then the system partition will be started. The system partition is mounted as a read-only partition in init.rc to ensure that it will not be damaged. When the developer modifies the system partition, the system partition will be re-mounted in the shell. Therefore, the shell command needs to be limited. The Android system enters the shell through the serial port or the adb command to interact with the system. In order to be compatible with development and security, the trigger can be set in init.rc to control the console and adbd service switch to facilitate shell interaction, and the switch will be closed later. The init.rc script is modified as follows:
[0054] The adbd service is disabled, and the switch is controlled by the attribute persist.sys.openadb:
[0055] on property:persist.sys.openadb=1;
[0056] start adbd;
[0057] on property:persist.sys.openadb=0;
[0058] stop adbd;
[0059] on property:persist.sys.openconsole=1;
[0060] start console;
[0061] on property:persist.sys.openconsole=0;
[0062] stop console;
[0063] Add the entry to control the two attributes, and remove it later. The whole system defaults to turn off the two attributes, so add persist.sys.openadb=0 and persist.sys.openconsole=0 in the system configuration file build.prop, which ensures that the default factory software turns off the serial port and adb command interaction.
[0064] Further, the method for compiling a secure signed image file is changed as follows:
[0065] (1) Take HiSilicon V811-Q80 as an example, modify mk of lunch V811-Q80:
[0066] Before modification:
[0067] HISI_SDK_ANDROID_CFG := sky_hi3751v811_A9H88_Q80_android_64bit_3072M_4layer_cfg.mak ATF_FILE_NAME := atf.bin
[0068] EMMC_OUT := $(PRODUCT_OUT) / Emmc UPDATE_SCRIPT_FILE := bootable / recovery / etc / META-INF / com / google / android / updater-script-emmc
[0069] After modification:
[0070] HISI_SDK_ANDROID_CFG := sky_hi3751v811_A9H88_Q80_android_64bit_3072M_4layer_tee_cfg.mak ATF_FILE_NAME := atf_tee.bin
[0071] EMMC_OUT := $(PRODUCT_OUT) / Security_L2 / PRODUCTION UPDATE_SCRIPT_FILE := bootable / recovery / etc / META-INF / com / google / android / updater-script-emmc-security
[0072] Add:
[0073] HISILICON_TEE := true
[0074] BOARD_WITH_TEEOS:=true.
[0075] (2) Modification of the corresponding cfg.mak configuration file:
[0076] Before modification:
[0077] CFG_HI_KERNEL_CFG=hi3751v810_arm64_android_defconfig;
[0078] After modification:
[0079] CFG_HI_KERNEL_CFG=hi3751v810_arm64_android_tee_defconfig;
[0080] Add:
[0081] CFG_HI_ADVCA_SUPPORT=y;
[0082] CFG_ADVCA_OTHER=y;
[0083] CFG_HI_ADVCA_TYPE=OTHER;
[0084] CFG_HI_ADVCA_USE_EXT1_RSA_KEY=y;
[0085] CFG_HI_TVP_SUPPORT=y.
[0086] (3) Modify the partition table:
[0087] Since the secure version will compile trustedcore.img and securestore.ext4, it is necessary to make relevant definitions for its upgrade and burning, otherwise it cannot work normally. Modify the xml partition table file as follows, and add these two partitions:
[0088] <Part Sel="1"PartitionName="trustedcore"FlashType="emmc"FileSystem="none"Start="135M"Length="25M"SelectFile="trustedcore.img" / >;
[0089] <Part Sel="1" PartitionName="securestore" FlashType="emmc" FileSystem="ext3 / 4" Start="160M" Length="10M" SelectFile="securestore.ext4" / >.
[0090] Further, an application software security verification mechanism is applied to ensure that legal applications can be normally downloaded and installed by applying self-signature and manufacturer application store signature, and unknown or unreliable source applications cannot be installed.
[0091] Self-signature of the application is to identify the developer of the application program and establish a trust relationship between the application programs by digital signature, which is completed by the application developer. The signature does not need to be authenticated by an authoritative digital certificate signature authority, and it is only used for self-authentication of the application package. The main function is to ensure the integrity of the application. Self-signature of the application is completed by the application developer, which is to sign each file in the application package. If someone maliciously modifies the files in the application during the application flow, and the modifier does not have the private key of the original author, then the original signature will fail, which can ensure the integrity of the application and protect the copyright of the author.
[0092] The self-signed file is stored in the META-INF directory in the application directory structure, which includes the following files: MANIFEST.MF, CERT.SF, and CERT.RSA.
[0093] MANIFEST.MF: generates a summary of all files in the installation package.
[0094] CERT.SF: saves the summary value of MANIFEST.MF and the summary value of each summary item in MANIFEST.MF.
[0095] CERT.RSA: saves the signature data of CERT.SF and the public key of the developer, etc.
[0096] Further, the manufacturer application store signature:
[0097] To ensure the security of the application, in addition to the necessary function, performance, compatibility, etc. Test before listing the application, the security needs to be detected, only the application that passes the detection is allowed to be published to the application store, and is downloaded and installed through the terminal. The application store signature can ensure that the application comes from a legal application store, and can identify the security and legality of the application program.
[0098] The application store signs the application, which is to sign the application self-signature file in META-INF. After signing the three files in META-INF, a signature folder named CERT-INF is formed. The principle is the same as the application self-signing, which ensures that an app has both the application's own signature and the manufacturer's application store signature, and is verified during installation.
[0099] Further, the application installation verification process is as follows:
[0100] During the installation process, the signature file under META-INF\CERT-INF in the app is first verified with the system pre-installed public key, and only then can the next installation action be performed. If the verification fails, it means that the app is not signed by the manufacturer's application store, and installation is not allowed.
[0101] After the application store signature verification, if the app is an update upgrade, it is also necessary to verify whether the application self-signature is consistent with the original app. Only the same application signature can be upgraded. If the app is installed for the first time, the application signature installation is recorded.
[0102] The present application adds security policies to the boot-up process, the BootLoader starting Kernel, the BootLoader starting Recovery, the Android system security, and the secure signature image file compilation method. The application software security verification mechanism ensures that legal applications can be normally downloaded and installed through application self-signing and manufacturer application store signing, and unknown or unreliable source applications cannot be installed.
[0103] The present application provides a method for designing an Android operating system for high-security chip televisions from the software system architecture and application software security verification, and adding security policies to the system boot, kernel, upgrade, and application software. The system has good security, can be quickly promoted, and has wide application value.
[0104] Further, as shown in Figure 3 Based on the above high-security chip security boot-up method, the present application also correspondingly provides an intelligent television, which comprises a processor 10, a memory 20, and a display 30. Figure 3 Only part of the components of the intelligent television are shown, but it should be understood that all the shown components are not required to be implemented, and more or fewer components can be alternatively implemented.
[0105] The memory 20 can be an internal storage unit of the smart TV in some embodiments, such as a hard disk or a memory of the smart TV. The memory 20 can also be an external storage device of the smart TV in other embodiments, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. Further, the memory 20 can include both the internal storage unit and the external storage device of the smart TV. The memory 20 is used to store application software and various data installed on the smart TV, such as program codes of the smart TV, etc. The memory 20 can also be used to temporarily store data that has been output or will be output. In an embodiment, the memory 20 stores a secure boot program 40 of the advanced security chip, which can be executed by the processor 10 to implement the secure boot method of the advanced security chip.
[0106] The processor 10 can be a central processing unit (CPU), a microprocessor or other data processing chip in some embodiments, which is used to run program codes or process data stored in the memory 20, such as to execute the secure boot method of the advanced security chip, etc.
[0107] The display 30 can be an LED display, a liquid crystal display, a touch liquid crystal display, an OLED (Organic Light-Emitting Diode) touch, etc. in some embodiments. The display 30 is used to display information of the smart TV and to display a visual user interface. The components 10-30 of the smart TV communicate with each other through a system bus.
[0108] In an embodiment, the following steps are implemented when the processor 10 executes the secure boot program 40 of the advanced security chip in the memory 20:
[0109] When the smart TV is started, the security check of the Boot signature of the advanced security chip is performed, and whether the security check is successful is determined;
[0110] If the security check is successful, the current boot mode is determined according to a flag bit, and the boot mode includes a Recovery mode and a Kernel mode;
[0111] If the current boot mode is the Kernel mode, the Kernel partition signature is checked, and if the Kernel partition signature check is successful, the Kernel partition is started;
[0112] If the current start mode is the Recovery mode, the Recovery partition signature is checked, and if the Recovery partition signature check is successful, the Recovery partition is started.
[0113] The security check of the Boot signature is performed after the smart TV is started, and it is determined whether the check is successful, and the method further comprises:
[0114] If the security check fails, the security check of the Boot signature is restarted.
[0115] If the current start mode is the Kernel mode, the Kernel partition signature is checked, and the method further comprises:
[0116] If the Kernel partition signature check fails, the Recovery mode is entered, and the Recovery partition signature is checked.
[0117] Optionally, the security start method of the advanced security chip, wherein if the current start mode is the Recovery mode, the Recovery partition signature is checked, and the method further comprises:
[0118] If the Recovery partition signature check fails, the security check of the Boot signature is restarted.
[0119] The security check of the Boot signature of the advanced security chip further comprises:
[0120] When the smart TV is started, the BootRom code fixed in the content of the chip is executed by the advanced security chip.
[0121] The public key is obtained by checking the KeyArea region signature, the Param region signature is checked by using the public key, and the Boot area data is loaded to the DDR by using the Param to continue the signature check.
[0122] The security start method of the advanced security chip further comprises:
[0123] In the Boot start process, the Bootargs, the Kernel and the sensitive partition are checked, and if the check fails, the Recovery interface is automatically entered, and the system is waited to be upgraded.
[0124] The security start method of the advanced security chip further comprises:
[0125] If the Recovery partition signature check is successful, the Recovery mode is entered, and the upgrading is waited.
[0126] If the signature check of the Recovery partition fails, the smart TV is restarted, the Recovery partition is repeatedly verified, and the Recovery partition needs to be re-burned and then normally started.
[0127] Optionally, the secure starting method of the high-security chip further comprises:
[0128] After the Kernel partition is normally started, the system partition is started.
[0129] When the system partition is modified, the system partition is remounted in the shell.
[0130] The application further provides a computer readable storage medium, wherein the computer readable storage medium stores a secure starting program of a high-security chip, and the secure starting program of the high-security chip, when executed by a processor, implements the steps of the secure starting method of the high-security chip.
[0131] To sum up, the application provides a secure starting method of a high-security chip and a smart TV, and the method comprises the following steps: after the smart TV is started, the Boot signature of the high-security chip is checked, and it is determined whether the check is successful; if the check is successful, it is determined according to a flag bit whether the current starting mode is a Recovery mode or a Kernel mode; if the current starting mode is the Kernel mode, the signature of the Kernel partition is checked, and if the check is successful, the Kernel partition is started; if the current starting mode is the Recovery mode, the signature of the Recovery partition is checked, and if the check is successful, the Recovery partition is started. The application adds a security policy to the boot, kernel, upgrade and application software of the system from the software system architecture and the application software security check, has good security, can be rapidly promoted, has wide application value, and can ensure the safety and reliability of the television software system and avoid the leakage of user private data.
[0132] It should be noted that, in this document, the terms "comprise", "comprise", or any other variant thereof are intended to cover non-exclusive inclusions, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or device. Without more limitations, the element defined by the statement "comprises a" does not exclude the presence of another identical element in the process, method, article or device comprising the element.
[0133] Of course, those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing relevant hardware (such as a processor, a controller, etc.) through a computer program. The program can be stored in a computer-readable computer-readable storage medium, and the program can include the processes of the above-mentioned method embodiments when executed. The computer-readable storage medium can be a memory, a disk, an optical disk, etc.
[0134] It should be understood that the application is not limited to the above examples, and those skilled in the art can make improvements or changes according to the above description, and all these improvements and changes shall belong to the protection scope of the appended claims of the application.
Claims
1. A security booting method of an advanced security chip, characterized by, The security starting method of the high-level security chip comprises the following steps: When the smart TV is started, the high-level security chip executes the BootRom code fixed in the chip content, acquires a public key by checking the KeyArea area signature, checks the Param area signature by using the public key, loads the Boot area data to the DDR by using the Param, and continues to check the signature, checks the Boot signature of the high-level security chip, and judges whether the security check is successful; If the security check is successful, the current starting mode is judged according to a flag bit, and the starting mode comprises a Recovery mode and a Kernel mode; If the current starting mode is the Kernel mode, the Kernel partition signature is checked, and if the Kernel partition signature check is successful, the Kernel partition is started; If the current starting mode is the Recovery mode, the Recovery partition signature is checked, and if the Recovery partition signature check is successful, the Recovery partition is started; During the Boot starting process, the Bootargs, Kernel and sensitive partition are checked, and if the check fails, the Recovery interface is automatically entered, and the system is re-upgraded. The security policy is added to the whole starting process.
2. The secure booting method of an advanced security chip according to claim 1, wherein, When the smart TV is started, the Boot signature is checked, and whether the check is successful is judged, and the following steps are further included: If the security check fails, the Boot signature is checked again.
3. The secure booting method of an advanced security chip according to claim 1, wherein, If the Kernel partition signature check fails, the Recovery mode is entered, and the Recovery partition signature is checked. If the Recovery partition signature check fails, the Boot signature is checked again.
4. The secure booting method of a high security chip according to claim 1 or 3, wherein The security starting method of the high-level security chip further comprises the following steps: If the Recovery partition signature check is successful, the Recovery mode is entered, and the system is upgraded; 5. The secure booting method of an advanced security chip according to claim 1, wherein, If the Recovery partition signature check fails, the smart TV is restarted, the Recovery partition is repeatedly verified, and the Recovery partition needs to be re-burned and then normally started. The security starting method of the high-level security chip further comprises the following steps: When the Kernel partition is normally started, the system partition is started; 6. The secure booting method of an advanced security chip according to claim 1, wherein, When the system partition is modified, the system partition is re-mounted in the shell. The smart TV comprises a memory, a processor, and a security starting program of a high-level security chip stored in the memory and capable of being run on the processor, and the security starting program of the high-level security chip is executed by the processor to realize the steps of the security starting method of the high-level security chip according to any one of claims 1-6. 7. A smart television, characterized by 8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a secure boot program of the advanced security chip, and the secure boot program of the advanced security chip, when executed by the processor, implements the steps of the secure boot method of the advanced security chip according to any one of claims 1-6.
Citation Information
Patent Citations
Start verification method and system
CN104200153A
Embedded equipment and starting method thereof
CN104951328A