Control Method and Electronic Device
After the electronic device is powered on and self-test, the memory of the boot system is set to an inaccessible state and the update data is stored in the accessible second memory, the problem of the boot program being illegally attacked is solved, and the security and reliability of the boot system are achieved.
Patent Information
- Application Number
- CN202110346707.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-31
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-07-22
AI Technical Summary
The prior art cannot effectively prevent the boot program of electronic devices from being illegally attacked, resulting in abnormal operation.
After the electronic device is powered on and self-tested, the first memory of the storage boot system is set to an inaccessible state through the controller and the second memory is set to an accessible state for storing the updated data of the boot system. The host system filters operation requests through the controller and transfers the legal requests to the second memory.
It effectively avoids attacks on the boot system by illegal operations, ensuring the normal operation and data security of the boot system.
Smart Images

Figure CN113051576B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technologies, and more particularly, to a control method and an electronic device. Background Art
[0002] If the boot program such as the Basic Input Output System (BIOS) in an electronic device is attacked by some illegal operations, it will cause the electronic device or device where the boot program is located to operate abnormally.
[0003] Currently, it is only possible to restore the boot program by some methods after the boot program is attacked, but it is impossible to reduce the illegal attacks on the boot program. Summary of the Invention
[0004] This application provides a control method and an electronic device.
[0005] An electronic device includes:
[0006] A controller;
[0007] A first memory connected to the controller, storing at least a boot system;
[0008] A second memory connected to the controller, for storing update data of the boot system;
[0009] After the electronic device completes the power-on self-test, the controller controls the first memory to be in an inaccessible state and controls the second memory to be in an accessible state.
[0010] In a possible implementation, the electronic device further includes: a host system connected to the first memory;
[0011] The host system is used to load and run the boot system in the first memory during the startup process of the electronic device;
[0012] The host system is further used to obtain an operation request for the boot system after the electronic device completes the power-on self-test, where the operation request is used to request an operation on the boot system; if it is confirmed that the operation request is not an illegal operation, the operation request is forwarded to the controller;
[0013] The controller is further used to store update data for the boot system in the second memory based on the operation request.
[0014] In yet another possible implementation, the controller controls the power supply to the first memory to be cut off, so as to control the first memory to be in an inaccessible state.
[0015] In yet another possible implementation, the electronic device further includes: a power supply module;
[0016] The first memory is connected to the power supply module through a controllable port on the controller;
[0017] The controller realizes cutting off the power supply to the first memory by controlling the connection between the controllable port and the power supply module to be cut off, so that the first memory is in an inaccessible state.
[0018] In yet another aspect, the present application further provides a control method, including:
[0019] During the startup process of the electronic device, the host system loads and runs the boot system in the first memory;
[0020] After the electronic device completes the power-on self-check, the controller controls the first memory to be in an inaccessible state and controls the second memory to be in an accessible state. The second memory is connected to the controller and is used to store the updated data of the boot system.
[0021] In a possible implementation, the method further includes:
[0022] After the electronic device completes the power-on self-check, the host system obtains an operation request for the boot system, and the operation request is used to request to operate the boot system;
[0023] If it is confirmed that the operation request does not belong to an illegal operation, the host system sends the operation request to the controller to store the updated data generated by the operation in the second memory through the controller.
[0024] In yet another possible implementation, the step of if it is confirmed that the operation request does not belong to an illegal operation, the host system sends the operation request to the controller includes:
[0025] If the host system detects a system management interrupt indication and confirms that the operation request does not belong to an illegal operation, the operation request is sent to the controller.
[0026] In yet another possible implementation, the step of the host system confirming that the operation request does not belong to an illegal operation includes:
[0027] It is confirmed by the host system that the operation request meets the legal operation conditions, where the legal operation conditions at least include: the system management interrupt indication is generated by a software program with triggering permission, and / or the verification data carried in the operation request is configured legal verification data.
[0028] In another possible implementation manner, the legal operation conditions further include:
[0029] If the operation request is used to request an update of the parameter data of the boot system, the parameter data requested to be updated by the operation request conforms to the parameter variable format defined in the system specification of the boot system.
[0030] In another possible implementation manner, it further includes:
[0031] During the power-on self-test process, the boot system in the first memory is updated according to the update data.
[0032] On the other hand, the present application also provides a computer-readable storage medium, in which at least one instruction, at least one program, a code set or an instruction set is stored, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by a processor to implement the control method described in any one of the above embodiments.
[0033] It can be seen from the above solutions that after the electronic device completes the power-on self-test, the present application will control, through a controller, the first memory in the electronic device for storing the boot system to be in an inaccessible state, and control the second memory to be in an accessible state, so that operations on data related to the boot system are transferred to the second memory, and the first memory where the boot system is located cannot be operated, thereby avoiding directly operating on the boot system in the first memory, and thus reducing the risk of the boot system being attacked due to illegal operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0035] Figure 1 It is a schematic structural diagram of a composition of an electronic device provided by an embodiment of the present application;
[0036] Figure 2 It is another schematic structural diagram of a composition of an electronic device provided by an embodiment of the present application;
[0037] Figure 3 Schematic diagram of the composition structure of the electronic device provided in the embodiment of the present application in an application example;
[0038] Figure 4 Schematic flowchart of a control method provided in the embodiment of the present application;
[0039] Figure 5 Another schematic flowchart of the control method provided in the embodiment of the present application.
[0040] Terms such as "first", "second", "third", "fourth", etc. (if any) in the description, claims and the above-mentioned drawings are used to distinguish similar parts, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than that illustrated here. Detailed implementation manners
[0041] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application.
[0042] For the convenience of understanding, the composition structure of the electronic device of the present application will be introduced first.
[0043] As Figure 1 shown, it shows a schematic diagram of the composition structure of the electronic device provided by the present application. The electronic device in this embodiment may include:
[0044] Controller 101;
[0045] The first memory 102, connected to the controller, stores at least a boot system;
[0046] And the second memory 103, connected to the controller, is used to store update data of the boot system.
[0047] Among them, after the electronic device completes the power-on self-test, the controller 101 controls the first memory to be in an inaccessible state and controls the second memory to be in an accessible state.
[0048] Among them, the first memory is the memory where the boot system is located. Therefore, the electronic device runs the boot system based on the data of the boot system in the first memory.
[0049] The second memory can be set in this application and is used to store updated data requested for operations on the boot system after the boot system runs. Therefore, the second memory does not store the complete data of the boot system, but only stores operation data related to the operations of the boot system.
[0050] It can be understood that there are many possible types of memories used for the first memory and the second memory, and this application does not limit this. For example, if the controller communicates with the memory based on the Serial Peripheral Interface (SPI), the first memory and the second memory can be SPI flash devices.
[0051] In this application, the boot system can be a firmware program in a component of an electronic device or the system firmware program of the electronic device. Depending on the different boot systems, the first memory and its setting position in the electronic device will also be different. Several possible situations will be used as examples for explanation later.
[0052] In the application, the specific form of the controller can have many possibilities and can be specifically set according to needs. For example, the controller can be an Embedded Controller (EC), a Field Programmable Gate Array (FPGA), or other control chips, etc.
[0053] In this application, the controller controlling the first memory to be in an inaccessible state actually makes the first memory invisible to the electronic device, so that the electronic device cannot access the first storage device.
[0054] As can be seen from the above, in this application, after the electronic device completes the power-on self-test, the controller will control the first memory in the electronic device used to store the boot system to be in an inaccessible state, thereby avoiding illegal operations on the boot system in the first memory, and naturally avoiding illegal operation attacks on the boot system in the first memory.
[0055] At the same time, when the controller controls the first memory to be in an inaccessible state and controls the second memory to be in an accessible state, the operations of the electronic device on the data related to the boot system are transferred to the second memory without affecting the normal operations on the data related to the boot system.
[0056] It can be understood that there are many possibilities for the boot system of this application, and several possible situations will be used as examples for explanation below.
[0057] In a possible implementation, in addition to including a system boot program for implementing power-on self-test (POST) of the electronic device and system self-test, the boot system may further include a firmware program of the processor device in the electronic device.
[0058] For example, the boot system may include a firmware program in an embedded controller (EC). Correspondingly, the first memory may store the firmware program of the EC. In the case where the EC cannot access the firmware program stored in its own memory, the boot program may access the firmware program in the first memory. In this case, the controller may be the aforementioned FPGA or another EC separately provided outside the EC.
[0059] For another example, the boot system may include a firmware program in a graphics card. Correspondingly, the first memory may be a memory that stores the firmware program of the graphics card, and the graphics card may access the firmware program in the first memory through the boot system.
[0060] In yet another possible implementation, the boot system may be a system boot program for implementing power-on self-test of the electronic device and system self-test.
[0061] For example, the boot system may be a Basic Input Output System (BIOS), or a Unified Extensible Firmware Interface (UEFI).
[0062] Correspondingly, the first memory may be a memory in the electronic device for storing the BIOS system or the UEFI system, also known as the system memory.
[0063] For example, the first memory may be a memory connected to the host system in the electronic device.
[0064] Next, taking the boot system as a system boot program such as BIOS or UEFI as an example, the electronic device of the present application will be introduced. As Figure 2 shown, it shows another schematic structural diagram of the electronic device provided by the present application.
[0065] In an embodiment of the present application, the electronic device includes:
[0066] A host system 201;
[0067] A first memory 202 connected to the host system;
[0068] A controller 203 connected to the first memory and the host system;
[0069] And a second memory 204 connected to the controller 203.
[0070] Among them, the first memory 202 stores at least a boot system, such as a BIOS or UEFI system.
[0071] The host system 201 is used to load and run the boot system in the first memory during the startup process of the electronic device. Among them, by running the boot program, related operations such as power-on self-test of the electronic device can be completed.
[0072] For example, taking the BIOS system as the boot system, after the electronic device is powered on and starts up, the electronic device will load and run the BIOS system, and complete related operations such as power-on self-test through the BIOS system.
[0073] Among them, the host system is the core part of the electronic device, and the operating system of the electronic device can run on the host system.
[0074] The host system can at least include the central processing unit (CPU) of the electronic device. For example, the host system can be a system including a CPU and a south bridge. Another example is that the host system can be a motherboard chip integrated with a CPU, etc.
[0075] In this application, after the electronic device completes the power-on self-test, the controller 203 will control the first memory to be in an inaccessible state and control the second memory to be in an accessible state.
[0076] It can be understood that when the first memory is in an accessible state, the operating system, boot system, and programs running on the host system can all access the first memory; while when the first memory is in an inaccessible state, the operating system, boot system, and other programs cannot access the first memory.
[0077] It can be understood that since the second memory is not connected to the host system, the host system cannot directly access the second memory. Therefore, all operations of the host system on the second memory need to go through the controller.
[0078] Furthermore, in order to reduce illegal operations on the second memory, the host system can also perform filtering processing first after obtaining an operation request, and then forward the operation request that is not an illegal operation after filtering to the controller.
[0079] Specifically, the host system 201 is further used to obtain an operation request for the boot system after the electronic device completes the power-on self-test, and the operation request is used to request an operation on the boot system; if it is confirmed that the operation request is not an illegal operation, the operation request is forwarded to the controller 203.
[0080] Among them, the operation request can be a write operation or a modification operation on the data of the boot system, etc.
[0081] Among them, the operation request not being an illegal operation means that it belongs to the operation requests set by the host system that will not attack the data of the boot system.
[0082] Correspondingly, the controller is further configured to store, based on the operation request, updated data for the boot system in the second memory.
[0083] Among them, the updated data of the boot system is determined based on the operation request and is the latest data that the boot system ultimately needs to be updated to.
[0084] For example, if the operation request is a write operation, the controller can store the data of the boot system requested to be written by the write operation in the second memory.
[0085] Another example, if the operation request is a modification operation for requesting to modify the data of the boot system, since the boot system is not stored in the second memory but only the data generated by the operation request for the boot system is stored, therefore, the data item of the boot system expected to be modified by the modification operation and the target value expected by the data item can be directly stored in the second memory. For example, if the operation request is to change the value of parameter A in the boot system from a to b, then the operation request can indicate to modify parameter A to the value b, so the value of parameter A can be stored as b in the second memory.
[0086] It can be understood that in this embodiment, after the electronic device completes the power-on self-test, the controller can control the first storage system connected to the host system and used for storing the boot system to be in an inaccessible state, so that the host system and the like cannot access the first memory. Therefore, even if there are illegal operations, the boot system cannot be directly attacked.
[0087] Meanwhile, a second memory is connected to the controller outside the host system. Since the second memory is not directly connected to the host system, the host system and the like cannot directly access the second memory. Moreover, by filtering the operation requests through the host system and forwarding the operation requests that do not belong to illegal operations to the controller, the updated data of the boot system stored in the second memory by the controller will not contain illegal data, thus ensuring the data security in the second memory.
[0088] It can be understood that after the electronic device completes the power-on self-check, the boot system in the first memory of the electronic device can be accessed. Therefore, in order to ensure the normal operation of the data for the boot system after the electronic device powers on and performs the self-check, the present application stores the updated data of the boot system in the second memory. On this basis, in order to enable the user to make the updated data of the boot system take effect, after the electronic device shuts down, if the electronic device powers on again, the boot system in the first memory can be updated according to the updated data stored in the second memory.
[0089] Therefore, in an optional manner, during the power-on self-check process of the electronic device, the host system can also update the boot system in the first memory according to the updated data stored in the second memory.
[0090] It can be understood that in practical applications, there are various ways for the controller to control the first memory to be in an inaccessible state. For example, in a possible implementation, the controller can control the power supply to the first memory to be cut off to control the first memory to be in an inaccessible state.
[0091] In a possible implementation, the electronic device may also include a power supply module. On this basis, the first memory can be connected to the power supply module through a controllable port on the controller.
[0092] Correspondingly, the controller can cut off the connection between the controllable port and the power supply module to cut off the power supply to the first memory, making the first memory in an inaccessible state.
[0093] For example, the controllable port can be a General-purpose input / output (GPIO) port, etc., without limitation.
[0094] To facilitate understanding of the solution of the present application, the following describes an application example of the electronic device of the present application. Taking the controller as the embedded controller in the electronic device and the boot system as the BIOS system as an example, and assuming that the host system and the controller communicate through SPI, for example Figure 3 , which shows the schematic diagram of the composition structure of the electronic device of the present application in an application example.
[0095] From Figure 3 it can be seen that the electronic device includes: a host system 301 and an embedded controller 302 connected to the host system.
[0096] Among them, the host system 301 may be connected to a first SPI flash device 303, and the first SPI flash device is used to store the BIOS program.
[0097] It can be understood that, according to different types of host systems, the connection method between the first SPI flash device and the host system will also be different. For example, when the host system is a motherboard including a CPU system, the first SPI flash device can be set on the motherboard, thus serving as a part of the host system, such as Figure 1 This is illustrated by taking this case as an example.
[0098] For another example, when the host system is a chip integrated with a CPU, etc., the host system can be connected with a first SPI flash device, and there is no restriction on this.
[0099] In Figure 3 it is illustrated by taking the host system including a CPU and a south bridge as an example. The CPU is connected to the first SPI flash device through the south bridge. Among them, the south bridge can also include an SPI interface controller, and the south bridge is connected to the first SPI flash device through the SPI interface controller. The SPI interface controller is used for connection control of devices based on the SPI standard protocol. Such as Figure 3 As shown, a first SPI flash device and an embedded controller are connected through the SPI interface controller in the host system.
[0100] Among them, in the present application, an embedded controller 302 is externally connected with a second SPI flash device 304, and the second SPI flash device 304 is used for storing updated data for requesting to operate the BIOS program after the electronic device performs power-on self-test.
[0101] Such as Figure 3 As shown, the embedded controller 302 is provided with GPIO ports, and the first SPI flash device is connected to a power input terminal 305 of a power supply module through the GPIO ports.
[0102] On this basis, when the embedded controller 302 controls the GPIO ports to control the connection between the power input terminal and the first SPI device, the power supply module can supply power to the first SPI device.
[0103] Correspondingly, if the embedded controller 302 cuts off the connection between the power input terminal and the first SPI device through the GPIO ports, the first SPI flash device is in a power-off state. At this time, the first SPI flash device is invisible to the host system. Therefore, the operating system and software programs on the electronic device cannot access the first SPI flash device.
[0104] And the embedded controller 302 is connected to the second SPI flash device. For example, the embedded controller 302 can be connected to the second SPI flash device through the SPI interface controller.
[0105] Among them, the second SPI flash device is directly connected to the power input terminal 306 of a power supply module to ensure that the second SPI flash device is in a continuous power supply state, so that the embedded controller can access the second SPI flash device.
[0106] In this application, after the electronic device is started, the host system will load and run the BIOS program in the first SPI flash device to complete related operations such as power-on self-test through this BIOS program.
[0107] Correspondingly, after the host system completes the power-on self-test, the host system sends a notification indicating the completion of the power-on self-test to the embedded controller. After obtaining this notification, the embedded controller will cut off the power supply of the first SPI flash device in the above manner. On this basis, the electronic device obtains an operation request for the BIOS through the host system (such as the operating system running on the host system), and the host system (such as through the BIOS program on the host) filters the operation request for risks and forwards the operation request that does not belong to an illegal operation to the embedded controller.
[0108] Combined with the above introduction of the structure of the electronic device, the control method of this application will be introduced below with reference to the flowchart.
[0109] As Figure 4 shown, it shows a schematic flowchart of a control method according to an embodiment of this application. The method of this embodiment may include:
[0110] S401, during the startup process of the electronic device, load and run the boot system in the first memory through the host system.
[0111] The first memory is connected to the host system and is used to store the boot system.
[0112] S402, after the electronic device completes the power-on self-test, control the first memory to be in an inaccessible state through the controller and control the second memory to be in an accessible state.
[0113] Among them, the second memory is connected to the controller and is used to store the update data of the boot system. For specific details, please refer to the relevant introduction above and will not be elaborated here.
[0114] Similar to the previous device embodiment, after the electronic device completes the power-on self-test, the controller will control the first memory in the electronic device that stores the boot system to be in an inaccessible state, thus avoiding any operation on the boot system in the first memory and naturally avoiding an illegal operation from attacking the boot system in the first memory.
[0115] Meanwhile, when the controller controls the first memory to be in an inaccessible state and the second memory to be in an accessible state, the operations of the electronic device on the boot system-related data are transferred to the second memory without affecting the normal operations on the boot system-related data.
[0116] It can be understood that, in order to reduce the storage of update data in the second storage device that may attack the boot system, in this application, after the electronic device completes the power-on self-test, an operation request for the boot system can be obtained through the host system, and this operation request is used to request operating the boot system. For example, the host system can obtain this operation request through the operating system or the boot system.
[0117] Correspondingly, if the host system confirms that the operation request is not an illegal operation, the operation request is sent to the controller through the host system, so that the update data generated by the operation can be stored in the second memory through the controller.
[0118] For example, the host system can judge whether the operation request is an illegal request through the operating system.
[0119] In an alternative manner, the host system can judge whether the operation request is an illegal operation through the boot system, and forward the operation request to the controller when the boot system confirms that the operation request is not an illegal operation.
[0120] It can be understood that there are various possible specific implementations for the host system to judge whether the operation request is an illegal operation request.
[0121] For example, in a possible case, in order to ensure that the operation request is not an illegal operation, generally the operation request needs to carry verification data for characterizing legality. If the verification carried by the operation request belongs to the pre-configured legality verification data, it can be confirmed that the operation request is not an illegal operation.
[0122] Among them, the legality verification data can be one or several of the passwords set by the user in the boot system, the manufacturer key signature of the boot system, etc., and can be specifically set according to needs.
[0123] In another possible case, if the operation request is used to request updating the parameter data of the boot system, it can also be judged whether the parameter data requested to be updated by the operation request conforms to the parameter variable format defined in the system specification of the boot system. Correspondingly, if the parameter data requested to be updated by the operation request conforms to the parameter variable format defined in the system specification of the boot system, it can be confirmed that the operation request is not an illegal operation.
[0124] It can be understood that in practical applications, the above two possible situations can also be combined to comprehensively determine whether an operation request belongs to an illegal operation request. For example, when an operation request is used to request an update of the parameter data of the boot system, it is necessary to simultaneously meet the condition that the verification data carried by the operation request is legal verification data, and the parameter data requested to be updated by the operation request conforms to the parameter variable format defined in the system specification of the boot system, so as to determine that the operation request does not belong to an illegal operation request.
[0125] Of course, there may be other possibilities for the judgment conditions of illegal operation requests, and there is no restriction on this.
[0126] It can be understood that in order to ensure that an operation request for the boot system can be transferred to the second memory, in this application, after the operating system or some application programs initiate an operation request to the host system, a system management interrupt (SMI) indication can be triggered and generated through a preset software program. In this application, the SMI is combined to enable the host to perform an illegal detection on the operation request.
[0127] Specifically, for example, when the host system detects a system management interrupt indication and confirms that the operation request does not belong to an illegal operation, the operation request is sent to the controller.
[0128] Among them, the host system's confirmation that the operation request does not belong to an illegal operation can be to confirm that the operation request meets the legal operation conditions, and the legal operation conditions can include: the system management interrupt indication is triggered and generated by a software program with the trigger permission.
[0129] It can be understood that when the operation request is a legal operation request, after the operating system or application program generates the operation request, a software program with the function of triggering the system management interrupt will inevitably be called to generate the system management interrupt. On this basis, the host system will analyze the legality of the operation request, and when the operation request does not belong to an illegal operation, the operation request is forwarded to the controller. Therefore, the host system can judge whether the operation request is legal based on whether the detected system management interrupt indication is legal.
[0130] It can be understood that the legal operation conditions can also be one or several of the above-mentioned possible situations that do not belong to illegal operations, and there is no restriction on this.
[0131] Among them, the method of judging whether it is an illegal operation can refer to one or several of the mentioned situations, and there is no restriction on this.
[0132] In an alternative manner, after the host system obtains the SMI indication, it will enter the System Management Mode (SMM) of the host system (such as the CPU), enabling the BIOS system (also known as the BIOS program) or the UFFI system (also known as the UEFI program) to process the operation request. Therefore, in this application, after the BIOS system or the UEFI system detects that the operation request is not an illegal operation request, it can be forwarded to the controller for processing.
[0133] The following takes the boot system as the BIOS system, the controller as the embedded controller, and the BIOS program processes the operation request after the host system obtains the system management interrupt as an example for illustration.
[0134] As Figure 5 shown, it shows a schematic flowchart of another embodiment of a control method of this application. The method of this embodiment may include:
[0135] S501, during the startup process of the electronic device, the BIOS system in the first memory is loaded and run through the host system.
[0136] S502, after the electronic device completes the power-on self-test, the embedded controller is used to control the power supply of the first memory to be cut off, and the power supply of the second memory connected to the controller is maintained.
[0137] For example, if the BIOS system notifies the embedded controller that the power-on self-test has been completed after the power-on self-test, the embedded controller will cut off the power supply of the first memory.
[0138] This step takes an implementation manner in which the controller controls the first memory to be in an inaccessible state and the second memory to be in an accessible state as an example for illustration, and other implementation manners are also applicable to this embodiment.
[0139] S503, the operation request for the BIOS program is obtained through the host system.
[0140] Among them, the operation request is used to request to operate the BIOS system.
[0141] S504, if the host system obtains the system management interrupt indication of the target object for the operation request, control the host system to enter the system management mode so that the BIOS system running on the host system processes the operation request.
[0142] Among them, the target object may be an application program or an operating system running on the host system, etc.
[0143] It can be understood that if the host system obtains a system management interrupt indication while or after obtaining an operation request, the host system confirms that the operation request for the BIOS system (similarly for replacing it with other boot systems) does not belong to the mode of updating the BIOS system to the second memory through an embedded controller (or a controller such as FEPA). However, since the first memory is in an inaccessible mode at this time, the host system cannot directly operate on the first memory based on the operation request either. Therefore, the host system also considers this operation request illegal and can directly discard or ignore this operation request to avoid attacks on boot systems such as BIOS.
[0144] It should be noted that in this embodiment, the BIOS system is taken as an example of the boot system. In other cases where the boot system is different, after the host system obtains a system management interrupt, it will still trigger the entry into the SMM mode, and the BIOS system (or UEFI system) will trigger this operation request.
[0145] S505, if the BIOS system confirms that the target object belongs to a software program with the permission to trigger a system management interrupt, determine the data type required for the operation of this operation request through the BIOS system.
[0146] It can be understood that the write operation or modification operation on the BIOS system (or other boot systems) can be to modify the data parameters or program code of the BIOS system. Therefore, this data type can be divided into two types: parameter data and code.
[0147] Among them, the software program with the permission to trigger a system management interrupt can be one or more, and the types of software programs can include an operating system or a specified application program, such as an application program provided by the manufacturer of the boot system (such as the BIOS system).
[0148] S506, if the BIOS system confirms that the data type required for the operation of this operation request is parameter data, detect through the BIOS system whether the parameter data requested to be updated by this operation request conforms to the parameter variable format defined in the system specification of the BIOS system, and the verification data carried by the operation request is the configured legal verification data. If so, execute step S508; if not, ignore this operation request.
[0149] In this embodiment, in the case where the operation request is used to request an update of the parameter data of the BIOS system, when the system management interrupt indication corresponding to the operation request is from a set legal software program, the parameter data requested to be updated by the operation request conforms to the parameter variable format defined in the system specification of the BIOS system, and the verification data carried by the operation request is the configured legal verification data, then it is determined that this operation request is a legal operation request.
[0150] S507. If the BIOS system confirms that the data type required for the operation request is code, the BIOS system checks whether the verification data carried in the operation request is the configured legal verification data. If so, S508 is executed; if not, the operation request is ignored.
[0151] In the case where the operation request is used to request an update to the BIOS system code, the operation request is determined to be a legal operation request only when the system management interrupt corresponding to the operation request indicates a set legal software program and the verification data carried in the operation request is the configured legal verification data.
[0152] Of course, steps S506 and S508 are only illustrated by taking one case of determining that the operation request is not an illegal operation as an example, and the other cases mentioned above are also applicable to this embodiment.
[0153] S508. The BIOS system sends the operation request to the embedded controller.
[0154] S509. The embedded controller stores the update data generated by the operation corresponding to the operation request in the second memory.
[0155] It should be noted that this embodiment is illustrated by taking the controller as an embedded controller as an example. If the embedded controller is replaced with other controllers, it is also applicable.
[0156] It can be understood that in the above method embodiment, after the electronic device restarts, it is necessary to update the boot system based on the update data of the configured boot system so that the update data of the boot system takes effect. Therefore, during the power-on self-test process of the electronic device, the host system can update the boot system in the first memory according to the update data in the second memory.
[0157] It can be understood that in the method embodiment, the descriptions of the interaction control between various components in the electronic device and between various components are relatively simple. For details, reference can be made to the relevant embodiments of the electronic device mentioned above, and details are not described herein again.
[0158] On the other hand, the present application also provides a computer-readable storage medium, in which at least one instruction, at least one program, a code set or an instruction set is stored, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by a processor to implement the control method described in any one of the above embodiments.
[0159] It should be noted that the various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the embodiments can be referred to each other. At the same time, the features described in each embodiment in this specification can be replaced or combined with each other, enabling those skilled in the art to implement or use this application. For device embodiments, since they are basically similar to method embodiments, they are described relatively simply, and the relevant parts can be referred to the corresponding descriptions in the method embodiments.
[0160] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. An electronic device, comprising: A controller; A first memory, connected to the controller, and storing at least a boot system; A second memory, connected to the controller, for storing update data of the boot system; A host system connected to the first memory; the host system is connected to the controller, and the host system is not connected to the second memory; Wherein, the host system is configured to load and run the boot system in the first memory during the startup process of the electronic device; After the electronic device completes power-on self-test, the controller controls the first memory to be in an inaccessible state and controls the second memory to be in an accessible state, so that the operations of the electronic device on the boot system are transferred to the second memory. The second memory does not store the complete data of the boot system, but only stores the update data related to the operations on the boot system.
2. The electronic device according to claim 1, The host system is further configured to obtain an operation request for the boot system after the electronic device completes power-on self-test. The operation request is used to request an operation on the boot system; if it is confirmed that the operation request is not an illegal operation, the operation request is forwarded to the controller; The controller is further configured to store the update data for the boot system in the second memory based on the operation request.
3. The electronic device according to claim 1, wherein the controller controls the first memory to be in an inaccessible state by controlling the power supply to the first memory to be cut off.
4. The electronic device according to claim 3 further comprises: A power supply module; The first memory is connected to the power supply module through a controllable port on the controller; The controller realizes cutting off the power supply to the first memory by controlling the connection between the controllable port and the power supply module to be cut off, so that the first memory is in an inaccessible state.
5. A control method, comprising: During the startup process of the electronic device, loading and running the boot system in the first memory through the host system; After the electronic device completes power-on self-test, controlling the first memory to be in an inaccessible state and controlling the second memory to be in an accessible state through the controller, so that the operations of the electronic device on the boot system are transferred to the second memory. The second memory does not store the complete data of the boot system, but only stores the update data related to the operations on the boot system. The second memory is connected to the controller and is used to store the update data of the boot system; wherein, the host system is connected to the controller, and the host system is not connected to the second memory.
6. The method according to claim 5, further comprising: After the electronic device completes power-on self-test, obtaining an operation request for the boot system through the host system. The operation request is used to request an operation on the boot system; If it is confirmed that the operation request is not an illegal operation, sending the operation request to the controller through the host system, so as to store the update data generated by the operation in the second memory through the controller.
7. The method according to claim 6, wherein if it is confirmed that the operation request is not an illegal operation, sending the operation request to the controller through the host system includes: If a system management interrupt indication is detected by the host system and it is confirmed that the operation request is not an illegal operation, sending the operation request to the controller.
8. The method according to claim 7, wherein confirming that the operation request is not an illegal operation through the host system includes: Confirming by the host system that the operation request meets the legal operation conditions, and the legal operation conditions at least include: the system management interrupt indication is generated by a software program with triggering authority, and / or the verification data carried in the operation request is configured legal verification data.
9. The method according to claim 8, wherein the legal operation conditions further include: If the operation request is used to request an update of the parameter data of the boot system, the parameter data requested to be updated by the operation request conforms to the parameter variable format defined in the system specification of the boot system.
10. The method according to claim 6 further includes: During the power-on self-test process, updating the boot system in the first memory according to the update data.
Citation Information
Patent Citations
Computer having special purpose subsystems and cyber-terror and virus immunity and protection features
US20060277433A1