A network-based computer hardware secure booting technique method and system
By performing security verification on the hardware initialization process through a network server, the risk of data theft in the hardware environment is eliminated, enabling secure booting of computer hardware and reducing security risks.
Patent Information
- Application Number
- CN202111245942.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-26
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2041-10-26
AI Technical Summary
In existing technologies, hardware-based security verification methods pose a risk of data theft and decryption when stored locally, indicating insufficient security of the hardware environment.
By using the network to perform trust measurement on electronic devices and hardware environments, and by using programs on the network server to perform security verification and protection on each node of the hardware initialization process, the keys are no longer stored locally but are encrypted and stored on the server, thus enabling secure booting of computer hardware.
It reduces security risks in the hardware environment, enables secure booting of computer hardware, and lowers the possibility of key theft.
Smart Images

Figure CN113961935B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of hardware startup, and particularly relates to a network-based computer hardware secure startup technical method and system. BACKGROUND
[0002] The hardware environment is a computer physical system composed of a computer and its peripheral devices, namely hardware facilities, which refers to an environment constructed by summing up those material conditions and tangible conditions required by a propagation activity. The hardware environment of a computer should be safe and reliable, such as the Boot Guard and BIOS Guard technologies of Intel Corporation.
[0003] However, the present inventors have found at least the following technical problems in the above-mentioned technologies during the implementation of the technical solutions of the embodiments of the present application.
[0004] The existing technologies are all based on hardware security verification, and the data saved locally is at risk of being stolen and decrypted. SUMMARY
[0005] The embodiments of the present application provide a network-based computer hardware secure startup technical method and system, which solve the technical problem that the existing technologies are all based on hardware security verification, and the data saved locally is at risk of being stolen and decrypted, achieve the technical effect that the credibility of an electronic device and a hardware environment is measured through a network, and each node of a hardware initialization process is verified and protected by a program on a network server, so that the key is not saved locally but encrypted and saved on the server, the security risk is reduced, and the secure startup of computer hardware is realized.
[0006] In view of the above problems, the present application is proposed to provide a method that overcomes the above problems or at least partially solves the above problems.
[0007] In a first aspect, the embodiments of the present application provide a network-based computer hardware secure booting technical method, which comprises: powering on and initializing a coprocessor, judging whether the coprocessor is normally started; if the coprocessor is normally started, initializing a network controller through the coprocessor; after the network controller is initialized, communicating with a server to obtain a first hardware key; the coprocessor decrypts the first hardware key through a first private key to obtain first decryption information; initializing first host hardware, and comparing the first decryption information with a hash value of first hardware information to obtain a first comparison result; if the first comparison result is that the first decryption information and the hash value of the first hardware information are the same, the state of the first host hardware is normal, and the first host hardware is continuously initialized; after the first host hardware is initialized, decrypting an OS loader through an OS loader key, and starting an operating system.
[0008] In another aspect, the present application also provides a network-based computer hardware secure booting technical system, which comprises: a first judging unit, which is used for powering on and initializing a coprocessor, and judging whether the coprocessor is normally started; a first initializing unit, which is used for initializing a network controller through the coprocessor if the coprocessor is normally started; a first obtaining unit, which is used for communicating with a server after the network controller is initialized to obtain a first hardware key; a second obtaining unit, which is used for the coprocessor decrypting the first hardware key through a first private key to obtain first decryption information; a third obtaining unit, which is used for initializing first host hardware, and comparing the first decryption information with a hash value of first hardware information to obtain a first comparison result; a second initializing unit, which is used for continuously initializing the first host hardware if the first comparison result is that the first decryption information and the hash value of the first hardware information are the same; and a first starting unit, which is used for decrypting an OS loader through an OS loader key after the first host hardware is initialized, and starting an operating system.
[0009] In a third aspect, the embodiments of the present application provide an electronic device, which comprises a bus, a transceiver, a memory, a processor and a computer program stored in the memory and capable of running on the processor, the transceiver, the memory and the processor are connected through the bus, and the computer program is executed by the processor to implement the steps in the method for controlling output data according to any one of the preceding aspects.
[0010] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps of the method for controlling output data.
[0011] The one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:
[0012] Since the coprocessor is powered on and initialized, it is determined whether the coprocessor is normally started; if the coprocessor is normally started, the network controller is initialized by the coprocessor; after the network controller is initialized, the server is communicated to obtain a first hardware key; the first hardware key is decrypted by the coprocessor through a first private key to obtain first decryption information; the first host hardware is initialized, if the first decryption information and the hash value of the first hardware information are the same, the state of the first host hardware is normal, and the first host hardware is continuously initialized; after the first host hardware is initialized, the OS loader is decrypted through the OS loader key, and the operating system is started. Further, the electronic device and the hardware environment are measured for credibility through the network, the nodes of the hardware initialization process are checked and protected by the program on the network server, the key is not saved locally but encrypted and saved on the server, the security risk is reduced, and the technical effect of the secure start of the computer hardware is achieved.
[0013] The above description is only a summary of the technical solutions of the present application, in order to more clearly understand the technical means of the present application, the specific embodiments of the present application can be implemented according to the content of the specification, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0014] Figure 1 The flowchart of a computer hardware security start technology method based on network according to an embodiment of the present application is shown;
[0015] Figure 2 The structure diagram of a computer hardware security start technology system based on network according to an embodiment of the present application is shown;
[0016] Figure 3 The structure diagram of an electronic device for executing the method for controlling output data according to an embodiment of the present application is shown.
[0017] Explanation of reference signs: first judging unit 11, first initial unit 12, first obtaining unit 13, second obtaining unit 14, third obtaining unit 15, second initial unit 16, first starting unit 17, bus 1110, processor 1120, transceiver 1130, bus interface 1140, memory 1150, operating system 1151, application program 1152, and user interface 1160. DETAILED DESCRIPTION
[0018] In the description of the embodiments of the present application, those skilled in the art shall understand that the embodiments of the present application can be implemented as a method, an apparatus, an electronic device and a computer readable storage medium. Therefore, the embodiments of the present application can be specifically implemented in the following forms: complete hardware, complete software (including firmware, resident software, microcode, etc.), and a combination of hardware and software. In addition, in some embodiments, the embodiments of the present application can also be implemented in the form of a computer program product in one or more computer readable storage media, which contains computer program code.
[0019] The above computer readable storage medium can adopt any combination of one or more computer readable storage media. The computer readable storage medium includes an electrical, magnetic, optical, electromagnetic, infrared or semiconductor system, device or component, or any combination thereof. More specific examples of the computer readable storage medium include a portable computer diskette, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, a flash memory, an optical fiber, an optical disk read-only memory, an optical storage device, a magnetic storage device, or any combination thereof. In the embodiments of the present application, the computer readable storage medium can be any tangible medium containing or storing a program that can be used or combined with an instruction execution system, device or component.
[0020] SUMMARY
[0021] The embodiments of the present application are described by flowcharts and / or block diagrams.
[0022] It should be understood that each block of the flowchart and / or block diagram and combinations of blocks in the flowchart and / or block diagram can be realized by computer readable program instructions. These computer readable program instructions can be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing apparatus, so as to produce a machine, so that these computer readable program instructions executed by the computer or other programmable data processing apparatus produce an apparatus that implements the functions / operations specified in the block of the flowchart and / or block diagram.
[0023] These computer readable program instructions can also be stored in a computer readable storage medium that can cause one or more computer or other programmable data processing devices to function in a specific manner, such that the computer readable program instructions which are stored in the computer readable storage medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.
[0024] The computer readable program instructions can also be loaded onto a computer, other programmable data processing device or other device to cause a series of operational steps to be performed on the computer, other programmable data processing device or other device to produce a computer implemented process such that the instructions which are executed on the computer or other programmable data processing device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0025] The embodiments of the present application will be described below with reference to the accompanying drawings.
[0026] Example One
[0027] As Figure 1 shown, the present application provides a network-based computer hardware security startup technology method, wherein the method comprises:
[0028] Step S100: power-on initialization of the coprocessor, and determining whether the coprocessor is normally started;
[0029] Specifically, the hardware environment is a computer physical system composed of a computer and its peripheral devices, i.e. hardware facilities, which refers to an environment built by those material conditions and tangible conditions required by a propagation activity. The hardware environment of a computer should be safe and reliable. After the mainboard is connected to the power supply, the system is first checked by a power-on self-test program to check all internal devices. At the time of power-on, the central processing unit is not initialized, and the coprocessor is initialized first. The coprocessor is a processor developed and applied to assist the central processing unit to complete the processing work which cannot be executed or is executed with low efficiency and effect. The coprocessor is power-on initialized, i.e. the coprocessor parameters are initialized and set at the time of power-on, and whether the coprocessor is normally started is determined, which is used for subsequent hardware security and reliability check.
[0030] Step S200: if the coprocessor is normally started, initializing the network controller by the coprocessor;
[0031] Specifically, if the co-processor is normally started, the network controller, also known as a network card controller, is a piece of computer hardware designed to allow computers to communicate over a computer network. Since the network card controller has a MAC address, it allows users to connect to each other through cables or wirelessly, and each computer on the network has a unique MAC address.
[0032] Step S300: After the network controller is initialized, the server is communicated to obtain a first hardware key;
[0033] Further, after the network controller is initialized, the server is communicated, and the embodiment of the application step S300 further comprises:
[0034] Step S310: The encrypted first machine identity information is sent to the server through the network controller;
[0035] Step S320: Based on the first machine identity information, the server sends the first hardware key encrypted by the public key to the co-processor through the network controller.
[0036] Specifically, after the network card controller is initialized, the encryption processor therein is directly connected with the server, and the co-processor sends the machine identity information of the computer to the server after encryption through the network controller. Based on the different first machine identity information, the corresponding first hardware key is obtained. The hardware key is a small piece of hardware, which is usually connected to a notebook computer or a desktop computer through a universal serial bus. The hardware key is a general term for several items, which can be used to authenticate the software of the client. The server sends the first hardware key encrypted by the public key to the co-processor through the network controller. The public key encryption, also known as asymmetric key encryption, refers to an encryption method composed of a pair of unique keys (i.e. public key and private key). The key is no longer saved locally but encrypted in the server. The encrypted hardware key is transmitted through the network, thereby reducing the security risk.
[0037] Step S400: The co-processor decrypts the first hardware key by the first private key to obtain first decryption information;
[0038] Step S500: The first host hardware is initialized, and the first decryption information and the hash value of the first hardware information are compared to obtain a first comparison result;
[0039] Specifically, the co-processor decrypts the first hardware key by a corresponding first private key to obtain first decrypted information after key decryption, to check the hardware state security. The host hardware is initialized, and the hardware key is used to compare the hash value of the hardware information when initializing the core hardware, to obtain a first comparison result, for determining the computer hardware security state.
[0040] Step S600: if the first comparison result is that the first decrypted information and the hash value of the first hardware information are the same, the state of the first host hardware is normal, and the initialization of the first host hardware is continued;
[0041] Specifically, if the first comparison result is that the first decrypted information and the hash value of the first hardware information are the same, the hardware hash value is a hash code generated according to the properties of the hardware and according to certain rules, and when the hash value is the same as the hardware key, it is determined that the state of the first host hardware is normal and the initialization is continued.
[0042] Step S700: after the initialization of the first host hardware is completed, the OS loader is decrypted by the OS loader key, and the operating system is started.
[0043] Further, after the initialization of the first host hardware is completed, the step S700 of the embodiment of the application further includes:
[0044] Step S710: downloading the OS loader key from the server;
[0045] Step S720: based on the OS loader key, decrypting the OS loader by the BIOS, and starting the operating system.
[0046] Specifically, after the initialization of the first host hardware is completed, the key of the OS loader is downloaded from the server, the OS loader refers to the operating system loader, the OS loader is decrypted by the BIOS by the OS loader key, and the operating system is started. The BIOS refers to the basic input and output system, which is a set of programs fixed to a ROM chip on the motherboard of a computer, which stores the most important basic input and output programs, self-checking programs after starting and system self-starting programs. It can read and write specific information set by the system from CMOS. The OS loader measures the credibility of the electronic device and the hardware environment through the operating system startup process, and uses the program on the network server to perform security verification and protection on each node of the hardware initialization process, thereby realizing the secure startup of the computer hardware.
[0047] Further, after judging whether the coprocessor is normally started, the embodiment of the application further comprises:
[0048] Step S110: if the coprocessor is not normally started, obtaining a first abort instruction;
[0049] Step S120: interrupting the coprocessor starting according to the first abort instruction, and prompting the user of abnormal boot state.
[0050] Specifically, the coprocessor is powered on and initialized, that is, the coprocessor parameters are initialized and set when powered on, it is judged whether the coprocessor is normally started, if the coprocessor is not normally started, a first abort instruction is obtained, and the coprocessor starting is interrupted according to the first abort instruction, and the user is prompted of abnormal boot state, so as to timely remind the user of abnormal hardware environment.
[0051] Further, the embodiment of the application further comprises:
[0052] Step S810: initializing the network controller by the coprocessor, and judging whether the network controller is normally started;
[0053] Step S820: if the network controller is normally started, communicating with the server, and obtaining the first hardware key.
[0054] Specifically, the network controller is initialized by the coprocessor, and it is judged whether the network controller is normally started, if the network controller is normally started, the encryption processor in the network controller is directly connected with the server after the initialization of the network controller is completed, and the first hardware key is obtained. The key is not saved locally but saved in the server after encryption, and the encrypted hardware key is transmitted through the network, so as to reduce the security risk.
[0055] Further, the embodiment of the application step S820 further comprises:
[0056] Step S821: if the network controller is not normally started, obtaining a second abort instruction;
[0057] Step S822: interrupting the network controller starting according to the second abort instruction, and prompting the user of network check failure.
[0058] Specifically, it is judged whether the network controller is normally started, if the network controller is not normally started, a second abort instruction is obtained, and the network controller starting is interrupted according to the second abort instruction, and the user is prompted of network check failure, so as to timely remind the user of abnormal hardware environment.
[0059] Further, the embodiments of the present application further include:
[0060] Step S910: if the first comparison result is that the hash values of the first decrypted information and the first hardware information are not the same, a third abort instruction is obtained;
[0061] Step S920: according to the third abort instruction, interrupting the first host hardware startup, and displaying alarm information to remind the user.
[0062] Specifically, the hash values of the first decrypted information and the first hardware information are compared, if the hash values of the first decrypted information and the first hardware information are not the same, it is determined that the hardware is attacked, according to the third abort instruction, interrupting the first host hardware startup, and displaying alarm information to remind the user, timely reminding the user of the hardware security anomaly, so as to achieve the technical effect of device security inspection and identification.
[0063] In summary, the network-based computer hardware security startup technical method and system provided by the embodiments of the present application has the following technical effects:
[0064] Because the coprocessor is powered on and initialized, it is determined whether the coprocessor is normally started; if the coprocessor is normally started, the network controller is initialized by the coprocessor; after the network controller is initialized, the server is communicated to obtain a first hardware key; the first hardware key is decrypted by the coprocessor through a first private key to obtain first decrypted information; the first host hardware is initialized, if the hash values of the first decrypted information and the first hardware information are the same, the state of the first host hardware is normal, the first host hardware is continuously initialized; after the first host hardware is initialized, the OS loader is decrypted by the OS loader key, and the operating system is started. Further, the technical effect of the security startup of the computer hardware is achieved by measuring the credibility of the electronic device and the hardware environment through the network, and the security of each node in the hardware initialization process is verified and protected by the program on the network server, so that the key is not saved locally but encrypted and saved on the server, the security risk is reduced, and the security startup of the computer hardware is realized.
[0065] Example Two
[0066] Based on the same inventive concept as the network-based computer hardware security startup technical method in the foregoing embodiments, the present application further provides a network-based computer hardware security startup technical system, as shown in Figure 2 The system includes:
[0067] A first judging unit 11 is configured to power on and initialize a coprocessor, and judge whether the coprocessor is normally started;
[0068] A first initializing unit 12 is configured to initialize a network controller by the coprocessor if the coprocessor is normally started;
[0069] A first obtaining unit 13 is configured to communicate with a server after the network controller is initialized, and obtain a first hardware key;
[0070] A second obtaining unit 14 is configured to decrypt the first hardware key by the coprocessor through a first private key, and obtain first decryption information;
[0071] A third obtaining unit 15 is configured to initialize a first host hardware, compare the first decryption information with a hash value of first hardware information, and obtain a first comparison result;
[0072] A second initializing unit 16 is configured to continue to initialize the first host hardware if the first comparison result is that the first decryption information and the hash value of the first hardware information are the same.
[0073] A first starting unit 17 is configured to decrypt an OS loader by an OS loader key after the first host hardware is initialized, and start an operating system.
[0074] Further, the system further comprises:
[0075] A fourth obtaining unit is configured to obtain a first abort instruction if the coprocessor is not normally started.
[0076] A first aborting unit is configured to interrupt the coprocessor starting according to the first abort instruction, and prompt a user of an abnormal boot state.
[0077] Further, the system further comprises:
[0078] A second judging unit is configured to initialize the network controller by the coprocessor, and judge whether the network controller is normally started.
[0079] A fifth obtaining unit is configured to communicate with the server if the network controller is normally started, and obtain the first hardware key.
[0080] Further, the system further comprises:
[0081] a sixth obtaining unit, configured to obtain a second abort instruction if the network controller is not normally started;
[0082] a second aborting unit, configured to interrupt the network controller starting according to the second abort instruction, and prompt a user that the network check fails.
[0083] Further, the system further comprises:
[0084] a first sending unit, configured to send the encrypted first machine identity information to the server through the network controller;
[0085] a second sending unit, configured to send the first hardware key encrypted by the public key by the server to the co-processor through the network controller based on the first machine identity information.
[0086] Further, the system further comprises:
[0087] a seventh obtaining unit, configured to obtain a third abort instruction if the first comparison result is that the first decrypted information and the hash value of the first hardware information are not the same;
[0088] a third aborting unit, configured to interrupt the first host hardware starting according to the third abort instruction, and display alarm information to remind the user.
[0089] a first downloading unit, configured to download an OS loader key from the server;
[0090] a second starting unit, configured to decrypt the OS loader through the BIOS based on the OS loader key, and start the operating system.
[0091] The foregoing Figure 1 The various variations and specific examples of the method for network-based computer hardware security starting technology in Embodiment One are also applicable to the system for network-based computer hardware security starting technology in this embodiment. Through the foregoing detailed description of the method for network-based computer hardware security starting technology, those skilled in the art can clearly understand the implementation method of the system for network-based computer hardware security starting technology in this embodiment. Therefore, for the sake of brevity of the specification, the implementation method of the system for network-based computer hardware security starting technology in this embodiment will not be described in detail here.
[0092] Further, the embodiment of the present application also provides an electronic device, comprising a bus, a transceiver, a memory, a processor and a computer program stored in the memory and capable of running on the processor, the transceiver, the memory and the processor are connected through the bus respectively, the computer program is executed by the processor to realize each process of the method for controlling output data and achieve the same technical effects, to avoid repetition, details are not described herein.
[0093] Exemplary electronic device
[0094] Specifically, referring to Figure 3 The embodiment of the present application also provides an electronic device, the electronic device comprising a bus 1110, a processor 1120, a transceiver 1130, a bus interface 1140, a memory 1150 and a user interface 1160.
[0095] In the embodiment of the present application, the electronic device further comprises a computer program stored in the memory 1150 and capable of running on the processor 1120, the computer program is executed by the processor 1120 to realize each process of the method for controlling output data.
[0096] The transceiver 1130 is used for receiving and sending data under the control of the processor 1120.
[0097] In the embodiment of the present application, the bus architecture (represented by the bus 1110) can include any number of interconnected buses and bridges, and the bus 1110 connects various circuits including one or more processors represented by the processor 1120 and the memory represented by the memory 1150 together.
[0098] The bus 1110 represents one or more of any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor or a local bus using any of a variety of bus architectures. As an example and not by way of limitation, such architectures include: Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, Extended ISA (EISA) bus, Video Electronics Standards Association (VESA) local bus.
[0099] The processor 1120 can be an integrated circuit chip having signal processing capability. In the implementation process, the steps of the above method embodiments can be completed by the integrated logic circuit or the instructions in the form of software in the processor. The above processor includes: general processor, central processing unit, network processor, digital signal processor, application specific integrated circuit, field programmable gate array, complex programmable logic device, programmable logic array, micro control unit or other programmable logic device, discrete gate, transistor logic device, discrete hardware component. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. For example, the processor can be a single-core processor or a multi-core processor, and the processor can be integrated into a single chip or located in multiple different chips.
[0100] The processor 1120 can be a microprocessor or any conventional processor. The method steps disclosed in combination with the embodiments of the present application can be directly executed by the hardware decoding processor, or by the combination of hardware and software modules in the decoding processor. The software modules can be located in the readable storage medium known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, register, etc. The readable storage medium is located in the memory, and the processor reads the information in the memory, and completes the steps of the above method in combination with the hardware thereof.
[0101] The bus 1110 can also connect various other circuits or devices, such as peripheral devices, voltage stabilizers or power management circuits, together. The bus interface 1140 provides an interface between the bus 1110 and the transceiver 1130, which are well known in the art. Therefore, the embodiments of the present application will not be further described.
[0102] The transceiver 1130 can be one element or multiple elements, such as multiple receivers and transmitters, which provide units for communicating with various other devices on the transmission medium. For example: the transceiver 1130 receives external data from other devices, and the transceiver 1130 is used to send data processed by the processor 1120 to other devices. Depending on the nature of the computer device, a user interface 1160 can also be provided, such as: touch screen, physical keyboard, display, mouse, speaker, microphone, trackball, joystick, stylus.
[0103] It is to be understood that the memory 1150 in the embodiments of the present application can further include a memory remotely located with respect to the processor 1120, which can be connected to a server through a network. One or more portions of the above-mentioned network can be a self-organizing network, an intranet, an extranet, a virtual private network, a local area network, a wireless local area network, a wide area network, a wireless wide area network, a metropolitan area network, the Internet, a public switched telephone network, a plain old telephone service network, a cellular telephone network, a wireless network, a Wi-Fi network, and a combination of two or more of the above-mentioned networks. For example, the cellular telephone network and the wireless network can be a global system for mobile communications, a code division multiple access device, a worldwide interoperability for microwave access device, a universal mobile telecommunications system device, a wideband code division multiple access device, a long term evolution device, an LTE frequency division duplex device, an LTE time division duplex device, an advanced long term evolution device, a universal mobile telecommunications system device, an enhanced mobile broadband device, a massive machine type communications device, an ultra-reliable low-latency communications device, and the like.
[0104] It is to be understood that the memory 1150 in the embodiments of the present application can be a volatile memory or a nonvolatile memory, or can include both volatile and nonvolatile memory. The nonvolatile memory includes a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, or a flash memory.
[0105] The volatile memory includes a random access memory used as an external cache. By way of example, and not limitation, many forms of RAM are available, for example, a static random access memory, a dynamic random access memory, a synchronous dynamic random access memory, a double data rate synchronous dynamic random access memory, an enhanced synchronous dynamic random access memory, a synchburst dynamic random access memory, and a direct memory bus random access memory. The memory 1150 of the electronic device described in the embodiments of the present application includes, but is not limited to, the above-mentioned and any other suitable type of memory.
[0106] In the embodiments of the present application, the memory 1150 stores an operating system 1151 and an application 1152 including the following elements: an executable module, a data structure, or a subset or an extended set thereof.
[0107] Specifically, the operating system 1151 includes various device programs, for example, a framework layer, a core library layer, a driver layer, and the like, for implementing various basic services and processing hardware-based tasks. The application 1152 includes various applications, for example, a media player, a browser, for implementing various application services. The program implementing the method of the embodiments of the present application can be included in the application 1152. The application 1152 includes applets, objects, components, logic, data structures, and other computer device executable instructions performing specific tasks or implementing specific abstract data types.
[0108] Further, the embodiment of the present application also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement each process of the above-mentioned method for controlling output data, and can achieve the same technical effects. To avoid repetition, it will not be repeated here.
[0109] The above describes only a specific implementation of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the embodiments of the present application, which should be covered within the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application should be subject to the protection scope of the claims.
Claims
1. A network-based computer hardware secure boot method, wherein, The method comprises: powering on the coprocessor to determine whether the coprocessor is normally started; if the coprocessor is normally started, initializing the network controller through the coprocessor; after the network controller is initialized, communicating with a server to obtain a first hardware key; the coprocessor decrypts the first hardware key through a first private key to obtain first decryption information; the first host hardware is initialized, and the first decryption information and a hash value of first hardware information are compared to obtain a first comparison result; if the first comparison result is that the first decryption information and the hash value of the first hardware information are the same, the state of the first host hardware is normal, and the first host hardware is continuously initialized; after the first host hardware is initialized, an OS loader is decrypted through an OS loader key, and an operating system is started; The method comprises: the network controller is initialized through the coprocessor to determine whether the network controller is normally started; if the network controller is normally started, the server is communicated with to obtain the first hardware key; if the network controller is not normally started, a second abort instruction is obtained; the network controller is interrupted according to the second abort instruction, and a user is prompted that network inspection is not passed; after the network controller is initialized and the server is communicated with, the method comprises: the encrypted first machine identity information is sent to the server through the network controller; based on the first machine identity information, the server sends the first hardware key encrypted by a public key to the coprocessor through the network controller; after it is determined whether the coprocessor is normally started, the method comprises: if the coprocessor is not normally started, a first abort instruction is obtained; the coprocessor is interrupted according to the first abort instruction, and a user is prompted that an abnormal boot state exists; after the first host hardware is initialized, the method comprises: the OS loader key is downloaded from the server; based on the OS loader key, the OS loader is decrypted through BIOS, and the operating system is started.
2. The method of claim 1, wherein, The method comprises: if the first comparison result is that the first decryption information and the hash value of the first hardware information are not the same, a third abort instruction is obtained; the first host hardware is interrupted according to the third abort instruction, and alarm information is displayed to remind a user.
3. A network-based computer hardware secure boot system, wherein, The system is used to execute the network-based computer hardware security boot method in any one of claims 1 to 2, and comprises: a first determination unit, which is used to power on the coprocessor to determine whether the coprocessor is normally started; a first initialization unit, which is used to initialize the network controller through the coprocessor if the coprocessor is normally started; a first obtaining unit, which is used to communicate with a server after the network controller is initialized to obtain a first hardware key; a second obtaining unit, configured to obtain first decryption information by decrypting the first hardware key by a first private key through the coprocessor; a third obtaining unit, configured to initialize the first host hardware, and compare the first decryption information and a hash value of first hardware information to obtain a first comparison result; a second initializing unit, configured to, if the first comparison result is that the first decryption information and the hash value of the first hardware information are the same, the state of the first host hardware is normal, and the initialization of the first host hardware is continued; a first starting unit, configured to, after the initialization of the first host hardware is completed, decrypt an OS loader by an OSloader key, and start an operating system.
4. A network-based computer hardware secure boot electronic device comprising a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor, the transceiver, the memory, and the processor connected by the bus, wherein, The computer program is executed by the processor to implement the steps in the method of any one of claims 1-2.
5. A computer readable storage medium having stored thereon a computer program, wherein, The computer program is executed by the processor to implement the steps in the method of any one of claims 1-2.
Citation Information
Patent Citations
Safe remote loading method of operating system
CN106940769A
Trusted starting method and device for operating system, mobile terminal and storage medium
CN112445537A