A processing method and an electronic device
By pre-stored backup BIOS data in the electronic device and using the first processor for verification and recovery processing, the crash problem caused by BIOS update failure is solved, and the BIOS self-recovery function is realized, which improves the reliability and user experience of the device.
Patent Information
- Application Number
- CN202110347787.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-31
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-03-31
AI Technical Summary
During the BIOS update process of electronic devices, update failures or errors are prone to occur, resulting in BIOS crashes and unable to boot, and the lack of self-recovery mechanism affects product reliability and user experience.
By pre-stored backup BIOS data in the electronic device and verifying and restoring the first boot system with the first processor, the self-recovery function of the BIOS is realized.
It effectively solves the crash problem caused by BIOS update failure, improves the reliability and user experience of electronic devices, and realizes self-recovery processing when there are defects in BIOS.
Smart Images

Figure CN113051577B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer technology, and particularly relates to a processing method and an electronic device. Background Art
[0002] The BIOS (Basic Input Output System) of electronic devices such as computers is often updated due to reasons such as upgrades and defect repairs. During the update process, unexpected situations such as update failures and errors may occur, resulting in the BIOS crashing and the device being unable to boot. Therefore, in order to improve the reliability of the product and provide a better user experience for end-users, it is very necessary to provide a solution for the self-healing function of the BIOS for electronic devices. Summary of the Invention
[0003] For this reason, the present application discloses the following technical solutions:
[0004] A processing method includes:
[0005] Starting and running a first processor of the electronic device; the first processor can be used to boot a first boot system of the electronic device, and the first boot system can be used to boot an operating system of the electronic device;
[0006] Using the first processor to verify the first boot system to obtain a verification result;
[0007] If the verification result indicates that the first boot system fails the verification, using the first processor to perform a recovery process on the first boot system based on backup data of the first boot system pre-stored in the electronic device.
[0008] Optionally, the starting and running the first processor of the electronic device includes:
[0009] Starting and running a second processor included in the first processor of the electronic device;
[0010] Running a second boot system provided by the second processor within the second processor, and the second boot system can be used to boot the first boot system.
[0011] Optionally, the using the first processor to verify the first boot system includes:
[0012] Using the second boot system to perform a security verification on the first boot system;
[0013] And / or, using the second boot system to perform an integrity verification on the first boot system.
[0014] Optionally, the electronic device stores first initialization data of the first boot system in a first data area of the first boot system, and stores second initialization data of the first boot system in a second data area of the first boot system, and the backup data includes the second initialization data;
[0015] The security verification of the first boot system by using the second boot system includes:
[0016] Performing security verification on the first initialization data by using the second boot system;
[0017] The integrity verification of the first boot system by using the second boot system includes:
[0018] Performing integrity verification on the first initialization data by using the second boot system;
[0019] Optionally, the security verification of the first initialization data by using the second boot system includes:
[0020] Based on a first public key of the second processor, verifying whether a second public key of the first boot system is trustworthy;
[0021] If the second public key of the first boot system is trustworthy, verifying whether the first initialization data in the first data area is trustworthy based on the second public key of the first boot system;
[0022] If the first initialization data is trustworthy, the first initialization data passes the security verification;
[0023] The integrity verification of the first initialization data by using the second boot system includes:
[0024] Loading a compressed package of the first initialization data in the first data area;
[0025] Uncompressing the compressed package, and verifying the integrity of the first initialization data based on a predetermined verification algorithm during the decompression process.
[0026] Optionally, the repair process of the first boot system performed by using the first processor based on the backup data of the first boot system pre-stored in the electronic device includes:
[0027] Verifying the second initialization data by using the second boot system;
[0028] If the second initialization data passes the verification, the first boot system is started and run based on the second initialization data, and the second initialization data is written into the first data area to replace the first initialization data in the first data area with the second initialization data;
[0029] Among them, the verification of the second initialization data includes security verification and / or integrity verification of the second initialization data.
[0030] Optionally, the above method further includes:
[0031] Determine whether there is a situation where the first boot system passes the verification but the electronic device fails to start;
[0032] If there is, perform a predetermined trigger process to trigger the step of using the first processor to perform a repair process on the first boot system based on the backup data of the first boot system pre-stored in the electronic device.
[0033] Optionally, the determining whether there is a situation where the first boot system passes the verification but the electronic device fails to start includes:
[0034] Determine whether the embedded controller of the electronic device receives the first notification information of the first boot system within a predetermined time period; the first notification information indicates that the first boot system has completed the initialization process based on the first initialization data;
[0035] If not received, there is a situation where the first boot system passes the verification but the electronic device fails to start.
[0036] Optionally, the performing the predetermined trigger process includes:
[0037] Use the embedded controller to modify the data at a predetermined position in the first data area;
[0038] Or, use the embedded controller to send a second notification information to the first processor, and the second notification information is used to instruct the first processor to perform a repair process on the first boot system based on the backup data.
[0039] An electronic device includes:
[0040] A first boot system;
[0041] A first processor capable of guiding the first boot system;
[0042] The first processor is further used for:
[0043] Start and run when the electronic device is powered on; and during the running process, verify the first boot system of the electronic device to obtain a verification result; if the verification result indicates that the first boot system fails the verification, perform a repair process on the first boot system based on the backup data of the first boot system pre-stored in the electronic device.
[0044] According to the above solution, it can be known that for the processing method and electronic device disclosed in this application, a first processor capable of booting the first boot system of the electronic device is started and run, and the first processor is used to verify the first boot system of the electronic device. In the case where the first boot system fails the verification, the first processor is further used to perform a recovery process on the first boot system based on the backup data pre-stored in the electronic device. Thus, it can be seen that in this application, by using a first processor capable of booting the first boot system of the electronic device to verify the first boot system and perform a recovery process when the verification fails, the self-recovery problem of the boot system (such as, BIOS) of the electronic device is solved, and the electronic device is supported to perform a self-recovery process of the boot system when there are defects in its boot system. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0046] Figure 1 is a schematic flowchart of a processing method disclosed in an embodiment of the present application;
[0047] Figure 2 is a flowchart of a processing process for performing a security verification on the first initialization data disclosed in an embodiment of the present application;
[0048] Figure 3 is a logical schematic diagram for verifying the BIOS security based on the Boot loader in the AMD PSP disclosed in an embodiment of the present application;
[0049] Figure 4 is a flowchart of a processing process for performing an integrity verification on the first initialization data disclosed in an embodiment of the present application;
[0050] Figure 5 is another schematic flowchart of a processing method disclosed in an embodiment of the present application;
[0051] Figure 6 is an example diagram for using the EC to modify data in the corresponding PEI block in the SPI disclosed in an embodiment of the present application;
[0052] Figure 7 is a schematic structural diagram of an electronic device disclosed in an embodiment of the present application;
[0053] Figure 8 is another schematic structural diagram of an electronic device disclosed in an embodiment of the present application;
[0054] Figure 9 is still another schematic structural diagram of an electronic device disclosed in an embodiment of the present application. Detailed implementation manners
[0055] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0056] Currently, a BIOS self-healing function has been introduced on the Intel platform. This function uses the WDT (watch dog timer) in the EC (Embed Controller, embedded controller) to determine whether the BIOS has been successfully started. If the BIOS fails to start successfully, the EC then notifies the CPU (Central Processing Unit) through hardware to enter the self-healing mode, so that the CPU performs BIOS self-healing processing.
[0057] However, the CPU designs of the AMD platform and the Intel platform are different. On the AMD platform, there is no reserved communication channel between the CPU and the EC, which results in the inability to import the above BIOS self-healing solution of the Intel platform for use on the AMD platform.
[0058] In view of the above problems, the present application discloses a processing method and an electronic device to provide a self-healing solution for a boot system (such as BIOS) that can at least be applicable to the AMD platform.
[0059] Among them, in Figure 1 shows a schematic flowchart of a processing method in an embodiment of the present application. This method can be applied to, but not limited to, intelligent terminals or computer devices such as smart phones, tablet computers, notebooks, desktop computers, or all-in-one computers.
[0060] As Figure 1 shown, in this embodiment, the above processing method at least includes:
[0061] Step 101: Start and run the first processor of the electronic device; the first processor can be used to boot the first boot system of the electronic device, and the first boot system can be used to boot the operating system of the electronic device.
[0062] In the embodiments of the present application, the first processor is the central processing unit (CPU) of the electronic device. The first boot system can be, but is not limited to, a boot system such as BIOS, EFI (Extensible Firmware Interface), or UEFI (Unified Extensible Firmware Interface) that can be used to boot the operating system of the electronic device.
[0063] In this step 101, starting and running the first processor of the electronic device can be specifically implemented as:
[0064] Start and run the second processor included in the first processor of the electronic device; run the second boot system provided by the second processor within the second processor, and the second boot system can be used to boot the above-mentioned first boot system.
[0065] Typically, the method of the present application can be applied to electronic devices based on the AMD platform or other platform electronic devices with platform characteristics similar to those of the AMD platform.
[0066] Among them, the above-mentioned second processor can be, but is not limited to, the PSP (Platform Security Processor) of the AMD platform.
[0067] The PSP is flashed with a bootloader, such as BIOS, which can be used to boot the first boot system of the electronic device. For the convenience of distinguishing from the first boot system such as BIOS of the electronic device, the bootloader in the PSP is described as the second boot system in the embodiments of the present application. In addition to being able to boot the first boot system of the electronic device, the second boot system can also perform hardware initialization on a part of the hardware of the electronic device. Specifically, the second boot system is mainly used to perform hardware initialization on the device memory, and the initialization work of other hardware is the responsibility of the first boot system such as BIOS.
[0068] In implementation, the PSP can be integrated inside the CPU of the electronic device and used as an internal chip of the electronic device's CPU.
[0069] Taking the first processor, the second processor, and the first boot system as the CPU, AMD PSP, and BIOS respectively, when the electronic device is powered on and started, the AMD PSP in the CPU of the electronic device can be started and run, and the second boot system Boot Loader provided by it can be run in the AMD PSP. Subsequently, the verification and self-recovery trigger processing of the first boot system such as the BIOS will be mainly performed through the second boot system Boot Loader.
[0070] Step 102: Verify the first boot system by using the above-mentioned first processor to obtain a verification result.
[0071] Optionally, when verifying the first boot system by using the first processor, the second boot system can be specifically used to perform security verification and / or integrity verification on the first boot system. For example, specifically use the Boot Loader in the AMD PSP of the CPU to perform security verification and / or integrity verification on the BIOS, etc.
[0072] To facilitate the electronic device to perform self-recovery processing on the first boot system when the first boot system such as the BIOS has defects, in the embodiments of the present application, two sets of data are pre-stored in the electronic device for the first boot system: the first initialization data and the second initialization data (such as two sets of initialization data of the BIOS, etc.).
[0073] Among them, the first initialization data is specifically stored in the first data area of the first boot system of the electronic device, and the second initialization data is stored in the second data area of the first boot system. The first initialization data is used for the startup of the first boot system. Taking the BIOS as an example, the first initialization data can be the data in the corresponding PEI (Pre-EFI Initialization, pre-EFI initialization) block in the BIOS for starting the BIOS. Correspondingly, the above-mentioned first data area can be the data area corresponding to the corresponding PEI block in the BIOS.
[0074] The second initialization data is backup data, which is used to support the self-recovery processing of the first boot system as backup data when the first initialization data has defects and causes abnormal device startup. In implementation, the second initialization data can be, but is not limited to, stored in other PEI blocks in the BIOS that are different from the block where the first initialization data is located.
[0075] In view of this, when performing security verification and / or integrity verification on the first boot system by using the second boot system, the second boot system can be specifically used to perform security verification and / or integrity verification on the above-mentioned first initialization data.
[0076] Step 103: If the verification result indicates that the first boot system fails the verification, use the first processor to perform a repair process on the first boot system based on the backup data of the first boot system pre-stored in the electronic device.
[0077] The backup data here is the above-mentioned second initialization data stored in the second data area of the first boot system.
[0078] Among them, if the verification result indicates that the first boot system fails the verification, for example, the first boot system fails the security verification, or fails the integrity verification, or fails both the security verification and the integrity verification, then the recovery process of the first boot system can be triggered, and specifically, the first processor, that is, the CPU, uses the pre-stored second initialization data as backup data to perform the recovery process on the first boot system. On the contrary, if the verification is passed, the first boot system can be directly started without performing the recovery process on the first boot system.
[0079] Among them, the first processor uses the second initialization data to perform the repair process on the first boot system, which may specifically include:
[0080] Verify the above-mentioned second initialization data using the second boot system;
[0081] If the second initialization data passes the verification, start and run the first boot system based on the second initialization data, and write the second initialization data into the first data area to use the second initialization data to replace the first initialization data in the first data area, so as to correct the first initialization data in the first data area.
[0082] Among them, the verification of the second initialization data is similar to the verification of the first initialization data, and may include but is not limited to: security verification and / or integrity verification of the second initialization data.
[0083] In implementation, when starting and running the first boot system based on the second initialization data and writing the second initialization data into the first data area, an optional implementation method is for the CPU to directly load the second initialization data from the second data area, start the first boot system based on the loaded second initialization data, and write the second initialization data in the second data area into the first data area to replace the first initialization data in the first data area.
[0084] Another optional implementation method is to first write the second initialization data in the second data area into the first data area to replace the defective first initialization data in the first data area. On this basis, the CPU directly loads the newly written second initialization data from the first data area and starts the first boot system based on the loaded second initialization data.
[0085] In addition, during implementation, when updating the data of the first boot system of an electronic device due to reasons such as an upgrade (e.g., updating BIOS data), specifically, the first initialization data in the first data area used to start the first boot system is updated, while the second initialization data in the second data area is not updated (i.e., the boot system data stored in the second data area remains the data before the update). In this way, when the electronic device is started later, once the upgraded first initialization data in the first data area is defective and fails the verification, it can be restored based on the second initialization data in the second data area to at least ensure the normal startup of the first boot system.
[0086] In the case where the upgraded first initialization data in the first data area is not defective and can pass the verification (and the first boot system can be normally started based on this data), then the upgraded first initialization data in the first data area is synchronized to the second data area to update the second initialization data in the second data area for use as backup data during the next boot system verification (defect detection) and self-recovery process.
[0087] According to the above solution, the processing method disclosed in this embodiment starts and runs a first processor that can be used to boot the first boot system of an electronic device, and uses this first processor to verify the first boot system of the electronic device. In the case where the first boot system fails the verification, the first processor is further used to perform a recovery process on the first boot system based on the backup data pre-stored in the electronic device. It can be seen that this application solves the self-recovery problem of the boot system (e.g., BIOS) of an electronic device by using a first processor that can be used to boot the first boot system of the electronic device to verify the first boot system and perform a recovery process when the verification fails, and supports the electronic device to perform a self-recovery process of the boot system when there are defects in its boot system.
[0088] Moreover, since this application uses the Boot Loader of AMD PSP in the CPU's own components to verify the first boot system such as BIOS, and triggers the CPU to perform a recovery process on the BIOS when the BIOS fails the verification, thus, there is no need for communication between the EC and the CPU, following the characteristics of the AMD platform, and without modifying the AMD platform, the self-recovery process of the BIOS in the electronic device can be realized.
[0089] Optionally, when using the second boot system to perform a security verification on the first initialization data, refer to Figure 2 , specifically, the security verification of the first initialization data can be realized through the following processing procedure:
[0090] Step 201: Based on the first public key of the second processor, verify whether the second public key of the first boot system is trustworthy.
[0091] To support the security verification of the first initialization data for starting the first boot system in the first data area, in the embodiments of the present application, the second processor, such as the AMD PSP, corresponds to a set of asymmetric keys: the first public key and the first private key, and this set of keys is essentially the key of the AMD platform; the first boot system, such as the BIOS, also corresponds to a set of asymmetric keys: the second public key and the second private key. The set of asymmetric keys corresponding to the second processor and the first boot system respectively may be, but is not limited to, RSA keys.
[0092] In the embodiments of the present application, the first boot system is the BIOS and the second processor is the AMD PSP in the CPU as an example for scheme description.
[0093] In the case where the first boot system is the BIOS and the second processor is the AMD PSP in the CPU, in implementation, the following preprocessing work can be performed to support the security verification of the first initialization data by the second boot system when the electronic device is powered on:
[0094] I. Signature processing of the second public key of the BIOS:
[0095] 1) The device manufacturer pre-generates a set of keys (the second public key / the second private key) for the BIOS of the electronic device and sends the public key, that is, the second public key, to the AMD platform for signature.
[0096] Among them, the device manufacturer can pre-generate a set of keys for the BIOS using open ssl (secure sockets layer) and provide the following data information to the AMD platform as required: the public key configuration file, the public key hash file, and the second public key in the generated keys. The public key configuration file includes at least the device manufacturer ID (Identity document), and in addition, may include, but is not limited to, information such as the relevant version number / serial number of the device. The public key hash file is used to provide the hash algorithm required for signature to the AMD platform.
[0097] 2) The AMD platform signs the second public key and returns the signature information so that the signed second public key is written to the specified location of the BIOS.
[0098] The AMD platform calculates the hash value of the second public key according to the hash algorithm specified in the public key hash file, and encrypts the calculated hash value using its own first private key to complete the signature of the second public key, obtains the signature information, and returns the.stkn file carrying the signature information.
[0099] The device manufacturer receives this file returned by the AMD platform and stores the file at a specified location in the BIOS. Exemplarily, specifically, the file is stored at the location corresponding to Entry5 in the PSP table of the BIOS (which is the PSP firmware list stored in the BIOS).
[0100] II. Signature processing of the first initialization data and the second initialization data:
[0101] After the BIOS data is updated due to reasons such as upgrade, use the second private key of the BIOS to sign the first initialization data (upgraded BIOS data) in the first data area, and use the second private key of the BIOS to sign the second initialization data (BIOS data that has not been updated yet) in the second data area, obtain the signature information of the data in the two data areas, and store the signature information at different specified locations in the BIOS respectively.
[0102] For example, use the second private key of the BIOS to sign the data in PEI block 1 (used to start the BIOS), and use the second private key of the BIOS to sign the data in PEI block 2 (used as backup data), and store the signature information of PEI block 1 and the signature information of PEI block 2 at the locations corresponding to level1 Entry7 and level2 Entry7 in the PSP table of the BIOS respectively.
[0103] On this basis, refer to Figure 3 the provided logical schematic diagram for verifying the security of the BIOS. After the electronic device is powered on, the Boot loader (i.e., the second boot system) in the AMD PSP first loads the signed second public key from the corresponding location in the PSP table of the BIOS, and uses the first public key of the AMD platform to verify whether the second public key of the BIOS is trustworthy.
[0104] The verification process is a standard public key signature verification process, specifically including:
[0105] The Boot loader in the AMD PSP loads the signed second public key from the PSP table of the BIOS (such as the location corresponding to Entry5), uses the first public key of the AMD platform (which can also be called the first public key of the second processor) to decrypt the signed second public key to obtain the decryption result; uses the hash algorithm specified when signing the second public key to perform a hash operation on the second public key pre-stored in the AMD PSP, and verifies the consistency between the hash operation result and the above decryption result. If the two are consistent, the second public key of the BIOS passes the verification, otherwise, it fails.
[0106] Step 202: If the second public key of the first boot system is trusted, verify whether the first initialization data in the first data area is trusted based on the second public key of the first boot system.
[0107] If, after verification, the second public key of the BIOS is trusted, then further use the second public key of the BIOS to verify whether the first initialization data in the first data area is trusted. For the above example, it is to use the second public key to verify whether the data in the PEI block 1 is trusted.
[0108] Specifically, with reference to Figure 3 , the Boot loader in the AMD PSP loads the signed first initialization data from the PSP table of the BIOS (at the position corresponding to level1Entry7), decrypts the signed first initialization data using the second public key of the BIOS, and compares the decryption result with the hash calculation result of the first initialization data in the first data area. If the two are consistent, the first initialization data in the first data area is trusted; otherwise, if the two are inconsistent, the first initialization data in the first data area is not trusted.
[0109] Step 203: If the first initialization data is trusted, the first initialization data passes the security verification.
[0110] Step 204: If the first initialization data is not trusted, the first initialization data fails the security verification.
[0111] If through the above verification process, it is determined that the first initialization data is trusted, then the first initialization data passes the security verification; otherwise, the first initialization data fails the security verification.
[0112] In this embodiment, after the electronic device is powered on, by performing a security verification on the first initialization data used to start the first boot system, the security of the first boot system can be ensured, and in the case where the first boot system fails the security verification, by triggering the self-recovery process of the first boot system of the electronic device, non-secure startup of the first boot system can be avoided.
[0113] Optionally, when using the second boot system to perform an integrity verification on the first initialization data, refer to Figure 4 , and specifically, the integrity verification of the first initialization data can be implemented through the following processing procedure:
[0114] Step 401: Load the compressed package of the first initialization data in the first data area.
[0115] In this embodiment, when the BIOS data is updated due to reasons such as an upgrade, and the updated first initialization data is stored in the first data area accordingly, specifically, the updated first initialization data is compressed, and the formed compressed package is written into the first data area.
[0116] Furthermore, the formed compressed package can be written into the corresponding PEI data block position in the SPI chip for storing the first initialization data. Here, SPI, namely Serial Peripheral Interface, is a serial peripheral device interface and is a chip that carries the BIOS firmware.
[0117] Step 402: Decompress the above compressed package, and verify the integrity of the first initialization data based on a predetermined verification algorithm during the decompression process.
[0118] Subsequently, after the electronic device is powered on, when the integrity verification of the BIOS is required, specifically, the compressed package corresponding to the first initialization data can be loaded from the first data area, decompressed, and the integrity of the first initialization data is verified based on a predetermined verification algorithm during the decompression process.
[0119] Optionally, the above-mentioned predetermined verification algorithm can be, but is not limited to, an integrity verification algorithm based on a digital digest.
[0120] Specifically, in this integrity verification algorithm based on a digital digest, when the BIOS data is updated due to reasons such as an upgrade, a digest calculation process can be performed on the first initialization data to be updated to the first data area. For example, specifically, any one of the MD (Message-Digest Algorithm) series of algorithms can be used to calculate the digest of each file in the first initialization data to be updated to the first data area, and the corresponding relationship information between each file and its digest value is recorded.
[0121] It should be noted that when the first initialization data (upgraded BIOS data) to be updated to the first data area is written to the first data area of the BIOS, unexpected situations such as writing failure or error may occur. Therefore, performing the above-mentioned digest value calculation and information recording process in advance before writing can provide a data basis for subsequent integrity verification of the first initialization data written to the first data area.
[0122] On this basis, when the electronic device is started, when loading the compressed package corresponding to the first initialization data from the first data area and decompressing the loaded compressed package, the digest information of each decompressed file can be calculated respectively, and the calculated file digest information is compared with the previously recorded digest information. If the calculated digest information of each file is finally compared and consistent with the recorded digest information, it can be determined that the first initialization data passes the integrity verification. Otherwise, if there is at least one file whose calculated digest information is inconsistent with the recorded digest information, it is determined that the first initialization data fails the integrity verification.
[0123] In this embodiment, after the electronic device is powered on, by performing integrity verification on the first initialization data used to start the first boot system, the reliability of the first boot system can be guaranteed. In the case where the first boot system fails the integrity verification, by triggering the electronic device to perform self-recovery processing on the first boot system, it avoids the unreliable startup of the first boot system when its data is incomplete (such as problems such as poor BIOS startup stability or inability to start due to incomplete data or defective data).
[0124] Subsequently, if the first initialization data in the first data area fails the verification, for example, the first initialization data fails the security verification, or fails the integrity verification, or both the security verification and the integrity verification fail, etc., the CPU performs recovery processing on the first boot system based on the second initialization data stored in the second data area.
[0125] During the process of the CPU performing recovery processing on the first boot system based on the second initialization data stored in the second data area, first, the second boot system is used to perform security verification and / or integrity verification on the second initialization data. If the second initialization data passes the verification (for example, the second initialization data passes the security verification and the integrity verification), the first boot system is started and run based on the second initialization data, and the second initialization data is written into the first data area.
[0126] Among them, the security verification of the second initialization data is similar to the security verification process of the first initialization data, and specifically includes:
[0127] The Boot loader in the AMD PSP loads the signed second initialization data from the PSP table of the BIOS (the position corresponding to level2 Entry7), decrypts the signed second initialization data using the second public key of the BIOS, and compares the consistency of the decryption result with the hash calculation result of the second initialization data in the second data area (PEI block 2). If the two are consistent, the second initialization data in the second data area is trusted. Otherwise, if the two are inconsistent, the second initialization data in the second data area is not trusted.
[0128] The integrity verification of the second initialization data is similar to that of the first initialization data, and specifically includes:
[0129] Load and decompress the compressed package corresponding to the second initialization data from the second data area. During the decompression of the loaded compressed package, calculate the digest information of each decompressed file respectively, and compare the calculated file digest information with the digest information of each file in the pre-recorded second initialization data. If the calculated digest information of each file is finally compared and consistent with the previously recorded digest information, it can be determined that the second initialization data passes the integrity verification. Otherwise, if there is at least one file whose calculated digest information is inconsistent with the previously recorded digest information, it is determined that the second initialization data fails the integrity verification.
[0130] After the second initialization data passes the verification, the CPU can further load the second initialization data, start the first boot system based on the loaded second initialization data, and write the second initialization data into the first data area to replace the unverified first initialization data therein, thereby realizing the recovery of the first boot system.
[0131] It should be noted that when the data of the first boot system is updated due to reasons such as upgrade (such as BIOS data update), only the first initialization data used to start the first boot system is upgraded and updated, while the second initialization data used as backup data is not updated temporarily. Subsequently, if it is verified that the updated first initialization data passes the verification and can successfully start the first boot system (safe / reliable start), the first initialization data can be further synchronized to the second data area to update the second initialization data therein. The updated second initialization data in the second data area can be used as backup data for the next self-recovery process of the first boot system.
[0132] In the prior art, for the boot data (the first initialization data) used to start the first boot system such as BIOS and the backup data (the second initialization data) used to support self-recovery, two SPI chips are used to store the boot data and the backup data respectively, which will increase the cost and the verification time. In the embodiment of the present application, only one SPI chip is adopted, and the boot data and the backup data of the first boot system are stored in different PEI blocks in one SPI chip, which reduces the cost consumption and also reduces the verification processing time for data verification by interacting with the corresponding blocks.
[0133] When designing the AMD BIOS self - recovery solution, the applicant found through research that there may be a phenomenon where the first initialization data in the first data area passes the verification, but the electronic device fails to start. The reason for this phenomenon is that there are problems such as infinite loops in the first initialization data due to code design, but this problem cannot be detected by security verification or integrity verification.
[0134] When this phenomenon occurs, the electronic device cannot start and cannot trigger self - recovery processing (because the first initialization data has passed the verification, so the self - recovery process will not be triggered).
[0135] To solve the above problems, optionally, in an embodiment, refer to Figure 5 the flowchart of the processing method provided. After step 103, the processing method disclosed in this application may further include:
[0136] Step 104: Determine whether there is a situation where the first boot system passes the verification but the electronic device fails to start.
[0137] In this embodiment, that the first boot system passes the verification but the electronic device fails to start specifically means that the first initialization data in the first data area for starting the first boot system passes the verification, but the electronic device fails to start.
[0138] This step 104 can specifically determine whether there is a situation where the first initialization data passes the verification but the electronic device fails to start through the following processing:
[0139] 1) Determine whether the embedded controller of the electronic device receives the first notification message of the first boot system within a predetermined time period; this first notification message indicates that the first boot system has completed the initialization process based on the first initialization data;
[0140] 2) If not received, there is a situation where the first initialization data passes the verification but the electronic device fails to start.
[0141] In this embodiment, specifically use the embedded controller EC of the electronic device to detect whether the above - mentioned phenomenon exists. Taking BIOS as an example, specifically, start a WDT (watch dog timer) in the EC, and set the WDT to start timing when the BIOS starts, and set that when the BIOS runs to a stage indicating successful BIOS startup (such as, PEI exit), notify the EC to close the WDT.
[0142] Based on this setting, during the startup process of the electronic device, if the EC has not received the notification to turn off the WDT within a predetermined time period, resulting in a timeout, it is determined that the startup of the first boot system fails. At this time, it is considered that the above-mentioned situation where the first initialization data passes the verification but the electronic device fails to start occurs. On the contrary, if the EC receives the notification to turn off the WDT within the predetermined time period, it indicates that the first boot system has been successfully started.
[0143] Step 105: If it exists, perform a predetermined trigger process to trigger step 103 of the above-mentioned repair process of the first boot system by using the first processor based on the backup data of the first boot system pre-stored in the electronic device.
[0144] When there is the above situation, in order to successfully start the first boot system such as BIOS and achieve the self-recovery of the first boot system, in this embodiment, the EC is used to modify the data at a specified position in the first data area. For example, modify the data at a specific position in the PEI block 1 of the SPI, etc., based on this data modification event, and trigger the subsequent verification failure of the first initialization data in the first data area. Correspondingly, the self-repair process can be triggered based on the verification result that the first initialization data fails to pass the verification, and then the first boot system can be successfully started by using the backup data (the second initialization data) based on the self-repair process.
[0145] After the EC completes the data modification at a specific position in the PEI block of the SPI, it can automatically shut down, then power on again, and trigger the PSP to re-verify the first initialization data in the first data area of the BIOS. Since the EC has modified the data at the specified position in the first data area, it will cause it to fail the verification (after the data is modified, it cannot pass the security verification and integrity verification). Correspondingly, the self-recovery process will be triggered according to the verification result to avoid the first boot system from failing to start.
[0146] Among them, the above-mentioned specific position during data modification can be a position specified in advance according to requirements. See Figure 6 , which provides an example of using the EC to modify the data in the corresponding PEI block in the SPI in this embodiment.
[0147] Moreover, preferably, during the implementation, information interaction with the user can be carried out through the UI (User Interface) during the BIOS data detection (i.e., security / integrity verification) and the BIOS recovery process, so that the user can timely perceive the processing progress during device startup and the corresponding relevant detection verification information or self-recovery information at the corresponding progress, so as to avoid confusion and improve the user experience.
[0148] This embodiment follows the characteristics of the AMD platform. Without the need for the EC to send a corresponding notification to the CPU, in the case where the first boot system passes verification but fails to start, it can trigger the CPU to execute the self-recovery process for the first boot system.
[0149] Optionally, in another embodiment, the AMD platform can also be improved by adding a communication channel between the EC and the CPU on the AMD platform. On this basis, when the EC detects that the first boot system such as the BIOS fails to start based on the WDT, it can directly send a corresponding notification to the CPU based on the communication channel with the CPU, thereby triggering the CPU to enter the self-repair process of the first boot system.
[0150] In summary, the processing method disclosed in the embodiments of the present application has at least the following advantages:
[0151] 1) According to the AMD characteristics (there is no reserved communication channel between the CPU and the EC), this application uses the AMD PSP to verify the security and / or integrity of the BIOS to determine whether the BIOS is reliable. When it is detected that the BIOS is unreliable, it switches to loading the backup BIOS data to start the BIOS recovery process, so that the self-healing function can also be introduced on the AMD platform;
[0152] 2) Since the BIOS verification and the triggering of self-healing in the case of failed verification are performed through the Boot loader in the PSP, essentially, the detection of BIOS data corruption and the triggering of the self-healing process are implemented based on software, and self-healing can be triggered without additional hardware support, reducing hardware dependence;
[0153] 3) Software detection can accurately judge the corruption of BIOS data, which is more accurate. Compared with the hardware method, it can effectively avoid false triggering (for example, under the Intel platform, the EC notifies the CPU to trigger self-healing);
[0154] 4) There is UI interaction with the user during the recovery process, which can avoid confusion and improve the user experience.
[0155] Corresponding to the above processing method, the present application also discloses an electronic device, as Figure 7 shown in the schematic structural diagram of the electronic device, including at least:
[0156] The first boot system 10;
[0157] The first processor 20 capable of booting the first boot system 10;
[0158] The first processor 20 is further used for:
[0159] Start and run when the electronic device is powered on; and during the running process, verify the first boot system 10 of the electronic device to obtain a verification result; if the verification result indicates that the first boot system 10 fails the verification, perform a repair process on the first boot system 10 based on the backup data of the first boot system 10 pre-stored in the electronic device.
[0160] In an alternative embodiment of the embodiment of the present application, refer to Figure 8 , the first processor 20 includes a second processor 30, and the second processor 30 provides a second boot system 40 that can be used to boot the first boot system 10;
[0161] Start and run the first processor 20 when the electronic device is powered on, specifically including:
[0162] Start and run the second processor 30 included in the first processor 20 of the electronic device;
[0163] Run the second boot system 40 provided therein within the second processor 30.
[0164] In an alternative embodiment of the embodiment of the present application, when the first processor 20 verifies the first boot system 10 of the electronic device, it is specifically used for:
[0165] Use the second boot system 40 to perform a security verification on the first boot system 10;
[0166] And / or, use the second boot system 40 to perform an integrity verification on the first boot system 10.
[0167] In an alternative embodiment of the embodiment of the present application, the electronic device stores first initialization data of the first boot system 10 in the first data area of the first boot system 10, and stores second initialization data of the first boot system 10 in the second data area of the first boot system 10. The above-mentioned backup data includes the second initialization data;
[0168] When the first processor 20 uses the second boot system 40 to perform a security verification on the first initialization data of the first boot system 10, it is specifically used for: using the second boot system 40 to perform a security verification on the first initialization data;
[0169] When the first processor 20 uses the second boot system 40 to perform an integrity verification on the first boot system 10, it is specifically used for: using the second boot system 40 to perform an integrity verification on the first initialization data.
[0170] In an alternative embodiment of the embodiment of the present application, when the first processor 20 uses the second boot system 40 to perform a security verification on the first initialization data, it is specifically used for:
[0171] Verify whether the second public key of the first boot system 10 is trustworthy based on the first public key of the second processor 20;
[0172] If the second public key of the first boot system 10 is trustworthy, verify whether the first initialization data in the first data area is trustworthy based on the second public key of the first boot system 10;
[0173] If the first initialization data is trustworthy, the first initialization data passes the security verification;
[0174] When the first processor 20 performs integrity verification on the first initialization data by using the second boot system 40, it is specifically used for:
[0175] Load the compressed package of the first initialization data in the first data area;
[0176] Decompress the compressed package, and verify the integrity of the first initialization data based on a predetermined verification algorithm during the decompression process.
[0177] In an alternative embodiment of the embodiment of the present application, when the first processor 20 performs a repair process on the first boot system 10 based on the backup data of the first boot system 10 pre-stored in the electronic device, it is specifically used for:
[0178] Verify the second initialization data by using the second boot system 40;
[0179] If the second initialization data passes the verification, start and run the first boot system 10 based on the second initialization data, and write the second initialization data into the first data area to replace the first initialization data in the first data area with the second initialization data;
[0180] Among them, the verification of the second initialization data includes security verification and / or integrity verification of the second initialization data.
[0181] In an alternative embodiment of the embodiment of the present application, the first processor 20 is further used for:
[0182] Determine whether there is a situation where the first boot system 10 passes the verification but the electronic device fails to start;
[0183] If so, perform a predetermined trigger process to trigger the step of using the first processor 20 to perform a repair process on the first boot system 10 based on the backup data of the first boot system 10 pre-stored in the electronic device.
[0184] In an alternative embodiment of the embodiment of the present application, as Figure 9 shown, the electronic device disclosed in the present application further includes an embedded controller 50;
[0185] When determining whether there is a situation where the first boot system 10 passes the verification but the electronic device fails to start, the first processor 20 is specifically configured to:
[0186] Determine whether the embedded controller 50 of the electronic device receives the first notification message of the first boot system 10 within a predetermined time period; the first notification message indicates that the first boot system 10 has completed the initialization process based on the first initialization data;
[0187] If not received, there is a situation where the first boot system 10 passes the verification but the electronic device fails to start.
[0188] In an alternative embodiment of the present application, when the first processor 20 performs the above-mentioned predetermined trigger process, it is specifically configured to:
[0189] Use the embedded controller 50 to modify the data at a predetermined position in the first data area;
[0190] Or, use the embedded controller 50 to send a second notification message to the first processor 20, and the second notification message is used to instruct the first processor 20 to perform a repair process on the first boot system 10 based on the above-mentioned backup data.
[0191] It should be noted that the various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.
[0192] For the convenience of description, when describing the above system or device, it is divided into various modules or units according to functions for description. Of course, when implementing the present application, the functions of each unit can be implemented in one or more software and / or hardware.
[0193] From the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of the present application.
[0194] Finally, it should also be noted that in this text, relational terms such as first, second, third, and fourth are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.
[0195] The above are only the preferred embodiments of the present application. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present application.
Claims
1. A processing method, comprising: starting and running a first processor of an electronic device; the first processor can be used to boot a first boot system of the electronic device, and the first boot system can be used to boot an operating system of the electronic device; using the first processor to verify the first boot system to obtain a verification result; if the verification result indicates that the first boot system fails the verification, using a second boot system of a second processor of the electronic device to verify second initialization data; wherein, the second boot system can be used to boot the first boot system; if the second initialization data passes the verification, starting and running the first boot system based on the second initialization data, and writing the second initialization data into a first data area to replace first initialization data in the first data area with the second initialization data.
2. The method according to claim 1, wherein starting and running the first processor of the electronic device comprises: starting and running a second processor included in the first processor of the electronic device; running a second boot system provided by the second processor within the second processor.
3. The method according to claim 2, wherein using the first processor to verify the first boot system comprises: using the second boot system to perform a security verification on the first boot system; and / or, using the second boot system to perform an integrity verification on the first boot system.
4. The method according to claim 3, wherein, the electronic device stores first initialization data of the first boot system in a first data area of the first boot system, and stores second initialization data of the first boot system in a second data area of the first boot system; the using the second boot system to perform a security verification on the first boot system comprises: using the second boot system to perform a security verification on the first initialization data; the using the second boot system to perform an integrity verification on the first boot system comprises: using the second boot system to perform an integrity verification on the first initialization data.
5. The method according to claim 4, wherein using the second boot system to perform a security verification on the first initialization data comprises: verifying whether a second public key of the first boot system is trustworthy based on a first public key of the second processor; if the second public key of the first boot system is trustworthy, verifying whether the first initialization data in the first data area is trustworthy based on the second public key of the first boot system; if the first initialization data is trustworthy, the first initialization data passes the security verification; the using the second boot system to perform an integrity verification on the first initialization data comprises: loading a compressed package of the first initialization data in the first data area; uncompressing the compressed package, and verifying the integrity of the first initialization data based on a predetermined verification algorithm during the uncompression process.
6. The method according to claim 1, wherein the verification of the second initialization data includes a security verification and / or an integrity verification of the second initialization data.
7. The method according to claim 1, wherein, further comprising: determining whether there is a situation where the first boot system passes verification but the electronic device fails to start; if so, performing a predetermined trigger process to trigger the step of using the first processor to perform a recovery process on the first boot system based on the backup data of the first boot system pre-stored in the electronic device.
8. The method according to claim 7, wherein the determining whether there is a situation where the first boot system passes verification but the electronic device fails to start, comprises: determining whether the embedded controller of the electronic device receives the first notification information of the first boot system within a predetermined time period; the first notification information indicates that the first boot system completes the initialization process based on the first initialization data; the first initialization data is stored in the first data area of the first boot system; if not received, there is a situation where the first boot system passes verification but the electronic device fails to start.
9. The method according to claim 8, wherein the performing the predetermined trigger process, comprises: using the embedded controller to modify the data at a predetermined position in the first data area; or, using the embedded controller to send a second notification information to the first processor, the second notification information is used to instruct the first processor to perform a recovery process on the first boot system based on the backup data.
10. An electronic device, comprising: a first boot system; a first processor capable of booting the first boot system; the first processor is further configured to: start and run when the electronic device is powered on; and during the running process, verify the first boot system of the electronic device to obtain a verification result; if the verification result indicates that the first boot system fails to pass verification, verify the second initialization data using the second boot system of the second processor of the electronic device; wherein, the second boot system is capable of booting the first boot system; if the second initialization data passes verification, start and run the first boot system based on the second initialization data, and write the second initialization data into the first data area to replace the first initialization data in the first data area with the second initialization data.
Citation Information
Patent Citations
Operation system security bootstrap device and bootstrap device
CN102650944A
Method and device for boot startup of processor operating system, and processor system
CN108363918A