A Two-Way Authentication Trusted Boot System and Method Based on TPCM Chip
Through the bidirectional authentication mechanism between the TPCM chip, the CPU and the FLASH memory chip, combined with the SPI interface and GPIO control, the system breach of trust caused by the tampering of the TPCM chip is solved, and the security verification of the TPCM chip and the trusted startup of the device operating environment are realized.
Patent Information
- Application Number
- CN202111244483.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-26
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-10-26
AI Technical Summary
In the prior art, the security of the TPCM chip itself has not been verified. Once tampered with, it will cause the entire system to be breached and the security of the computing environment cannot be guaranteed.
The two-way authentication mechanism between the TPCM chip and the CPU and FLASH memory chip is adopted, and the SPI interface is connected and GPIO control is used, and the forward and reverse measurement reference values and public key verification is combined to realize the two-way identity authentication between the TPCM chip and the CPU boot program, and a third-party trusted factor FLASH ID is introduced for security verification.
It realizes two-way identity authentication between the TPCM chip and the CPU boot program, prevents the authentication information from being held by the same party, ensures the security of the TPCM chip itself, and ensures the security of the device operating environment from the source.
Smart Images

Figure CN114077740B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a two-way authentication trusted startup system and method based on a TPCM chip, belonging to the technical field of computer security. Background Art
[0002] The trusted computing architecture establishes a valid hardware root of trust within the system and builds a trust chain from this root through layer-by-layer extension, ultimately achieving a trustworthy system operating environment. The root of trust is assumed to be unconditionally trusted, and the system does not verify its behavior. Therefore, whether the root of trust is truly trustworthy and whether it can be tampered with or replaced by attackers is crucial to verifying system trustworthiness.
[0003] The Trusted Platform Control Module (TPCM) is the root of trust for the active immune trust system, the system's source of trust, and the foundation for establishing a trusted chain. The basic principle of trusted boot is to initiate from the TPCM's initial trusted state and, through trusted extension technology, extend this initial trusted state to each stage of system startup, thereby building a complete trusted chain at system startup to ensure the initial trusted state of the operating environment after system startup. However, most current trusted boot methods fail to verify the security of the TPCM chip itself. Once the TPCM chip is tampered with, the entire system loses trust, making it impossible to guarantee the security of the computing environment. Summary of the Invention
[0004] Objective: To overcome the deficiencies in the prior art, the present invention provides a two-way authentication trusted startup system and method based on a TPCM chip.
[0005] Technical solution: To solve the above technical problems, the technical solution adopted by the present invention is:
[0006] In a first aspect, a two-way authentication trusted boot system based on a TPCM chip includes: a TPCM chip, a FLASH storage chip, and a CPU chip.
[0007] The TPCM chip includes: a main SPI interface and a slave SPI interface. The FLASH storage chip includes: a slave SPI interface. The CPU chip includes: a main SPI interface. The main SPI interface of the TPCM chip is connected to the slave SPI interface of the FLASH storage chip. The slave SPI interface of the TPCM chip is connected to the main SPI interface of the CPU chip. The main SPI interface of the CPU chip is also connected to the slave SPI interface of the FLASH storage chip. The GPIO output pin of the TPCM chip is connected to the RESET reset pin of the CPU chip to implement the startup control of the CPU chip. The STATE pin of the TPCM chip is connected to the GPIO pin of the CPU chip to notify the CPU whether the measurement process has ended and whether the TPCM is in the SPI master mode or the SPI slave mode.
[0008] As a preferred solution, the TPCM chip pre-stores a forward measurement reference value, a forward verification public key, and a reverse measurement reference value.
[0009] As a preferred solution, the FLASH storage chip pre-stores a reverse verification public key.
[0010] As a preferred solution, the TPCM chip has a unique forward verification public key and a reverse verification private key.
[0011] As a preferred solution, the forward measurement reference value is a digital signature value obtained by digitally signing the boot program with the forward verification private key in a clean running environment. The reverse measurement reference value is a digital signature value obtained by digitally signing the unique FLASH ID of the FLASH storage chip with the reverse verification private key in a clean running environment.
[0012] In a second aspect, a two-way authentication trusted startup method based on a TPCM chip includes the following steps:
[0013] After the system is powered on, the TPCM chip obtains the control right of the system and controls the CPU chip to be in the reset state.
[0014] The TPCM chip performs forward measurement on the boot program in the FLASH storage chip. If the measurement is successful, the TPCM releases the reset signal of the CPU chip, and the CPU chip starts to load the boot program.
[0015] After the CPU chip completes the loading of the boot program, it performs reverse measurement on the TPCM chip. If the measurement is successful, the boot program loads the kernel and starts the operating system.
[0016] As a preferred solution, when the TPCM chip performs forward measurement on the boot program in the FLASH storage chip, if the measurement fails, the TPCM maintains the reset signal of the CPU chip, terminates the current startup, and performs startup failure handling.
[0017] As a preferred solution, the bootloader includes: BOOT, PMON or BIOS.
[0018] As a preferred solution, after the CPU chip finishes loading the bootloader, it performs a reverse measurement on the TPCM chip. If the measurement fails, it stops loading the kernel, terminates the current startup, and performs startup failure handling.
[0019] As a preferred solution, the method for the TPCM chip to perform a forward measurement on the bootloader in the FLASH storage chip includes the following steps:
[0020] The TPCM chip communicates with the SPI slave device interface of the FLASH storage chip using the SPI master device interface. The TPCM chip reads the bootloader data and the bootloader signature value from the FLASH storage chip, and uses the forward verification public key in the TPCM chip to verify the signature of the bootloader data and the bootloader signature value. If the signature verification is successful, the TPCM chip releases the control right of the FLASH storage chip, the working mode of the TPCM chip is switched from the SPI master mode to the SPI slave mode, the STATE status line is switched from high level to low level, the TPCM chip notifies the CPU chip through the STATE status line that the measurement has been completed and the TPCM chip has been switched to the SPI slave mode, and then releases the CPU chip reset pin through GPIO to start the CPU chip.
[0021] If the signature verification fails, the loading process is stopped, the CPU chip is controlled to be in the reset state all the time, the TPCM chip records the audit log, and alarms externally to notify relevant personnel to perform subsequent exception handling.
[0022] As a preferred solution, the method for the CPU chip to perform a reverse measurement on the TPCM chip after the CPU chip finishes loading the bootloader includes the following steps:
[0023] After the CPU chip starts, the CPU chip obtains the control right of the FLASH storage chip using the SPI master device interface, and the CPU chip works in the SPI master mode and loads the bootloader data from the FLASH storage chip.
[0024] After the bootloader starts, the CPU reads the FLASH ID of the FLASH storage chip and the reverse verification public key.
[0025] After the CPU successfully reads, if the STATE status line is at a low level, the CPU uses the SPI master device interface to obtain control of the TPCM chip, reads the reverse verification reference value in the TPCM chip, and verifies the signature with the reverse verification public key. If the signature verification is successful, the kernel file is measured and the operating system is started; if the signature verification fails, the loading process is stopped, the audit log is recorded, and an alarm is issued to notify relevant personnel to perform subsequent exception handling; if the STATE status line is at a high level, wait for the TPCM chip to be available and record the audit log.
[0026] Beneficial effects: A two-way authentication trusted boot system and method based on a TPCM chip provided by the present invention can achieve two-way identity authentication between the TPCM chip and the CPU boot program. By introducing a third-party trusted factor, it is prevented that all authentication information is held by the same party during the identity authentication process, realizing the security verification of the TPCM chip itself, and ensuring the security of the device operating environment from the source. Brief Description of the Drawings
[0027] Figure 1 It is a schematic diagram of the structure of the device trusted boot system of the present invention.
[0028] Figure 2 It is a schematic diagram of the two-way authentication process of the present invention. Detailed Embodiments
[0029] The present invention will be further described in detail below with reference to specific embodiments.
[0030] As Figure 1 shown, a two-way authentication trusted boot system based on a TPCM chip includes a trusted platform control module TPCM chip, a FLASH chip for storing the system boot program, and a system central processing unit CPU chip.
[0031] The TPCM chip, the FLASH storage chip, and the CPU chip are interconnected through the SPI interfaces of their respective chips. Among them, the TPCM chip has a total of two SPI interfaces, one master and one slave. The FLASH chip has one slave SPI interface, and the CPU chip has one master SPI interface. When the SPI interfaces are interconnected, the master SPI interface of the TPCM chip is connected to the slave SPI of the FLASH chip, the slave SPI interface of the TPCM chip is connected to the master SPI interface of the CPU chip, and the master SPI interface of the CPU chip is connected to the slave SPI interface of the FLASH chip. In addition, the TPCM chip is connected to the RESET reset pin of the CPU chip through the GPIO output pin to realize the start control of the CPU chip. The TPCM chip is connected to the GPIO pin of the CPU chip through the STATE pin to notify the CPU whether the measurement process has ended and whether the TPCM is in the SPI master mode or the SPI slave mode.
[0032] The startup timing control process after the system is powered on is as follows: After power-on, the TPCM chip starts up prior to the CPU chip. The TPCM controls the output of GPIO to put the CPU chip in a reset state. At this time, the TPCM chip obtains the control right of the slave SPI interface of the FLASH chip through its main SPI interface. The TPCM chip actively measures the system boot program stored in the FLASH chip. If the measurement result of the TPCM is successful, the TPCM chip releases the control right of the FLASH chip, makes the STATE output the logic level indicating successful measurement, and the TPCM switches from the SPI master device state to the SPI slave device state. Then it releases the reset of the CPU chip to start the CPU chip. If the measurement result of the TPCM is failed, the CPU chip remains in the reset state, and the audit log is recorded and an alarm is issued.
[0033] Before the system is officially started and run, the forward measurement reference value, the forward verification public key, and the reverse measurement reference value should be stored in the TPCM chip in advance during the factory debugging stage of the newly produced board, and the reverse verification public key should be stored in the FLASH chip. The forward verification public key and private key are generated by the host computer. The reverse verification public key and private key are generated by the TPCM chip, and it can be considered that each TPCM chip has a unique public key and private key. The forward measurement reference value is the digital signature value obtained by digitally signing the boot program with the forward verification private key in a clean running environment. The reverse measurement reference value is the digital signature value obtained by digitally signing the unique FLASH ID of the FLASH chip with the reverse verification private key in a clean running environment.
[0034] After the above preparations are completed, the system can be started in a trusted manner, as Figure 2 shown, a two-way authentication trusted startup method based on the TPCM chip is carried out according to the following steps:
[0035] Step 1: After the system is powered on, the power-on timing control circuit ensures that the TPCM chip first obtains the main control right of the system and controls the CPU to be in the reset state. Then it sequentially proceeds to Step 2 for forward authentication and Step 3 for reverse authentication;
[0036] Step 2: The TPCM chip performs forward measurement on the boot program (such as BOOT / PMON / BIOS, etc.) pre-stored in the FLASH storage chip. If the measurement is successful, the TPCM releases the reset signal of the CPU, and then the CPU starts to load the boot program and proceeds to Step 3. If the measurement fails, the TPCM maintains the reset signal of the CPU, terminates this startup, and performs startup failure handling;
[0037] Step 3: After the CPU completes the loading of the bootloader, perform reverse measurement on the TPCM chip. If the measurement is successful, the bootloader loads the kernel and starts the operating system; if the measurement fails, stop loading the kernel, terminate the current startup, and perform startup failure handling.
[0038] The above Step 2 is forward authentication and Step 3 is reverse authentication, which together constitute a two-way authentication method, including the following steps:
[0039] Step A1: After power-on, the TPCM chip starts up before the CPU. The CPU is in the reset state. The TPCM chip communicates with the SPI slave device interface of the FLASH storage chip using the SPI master device interface, and the STATE status line is at a high level.
[0040] Step A2: The TPCM chip first reads the bootloader data and the bootloader signature value from the FLASH storage chip, and then uses the forward verification public key pre-stored in the TPCM chip to verify the signature of the bootloader data and the bootloader signature value. If the signature verification is successful, proceed to Step A3; if the signature verification fails, stop the loading process, control the CPU to remain in the reset state all the time, record the audit log by the TPCM chip, and give an external alarm to notify relevant personnel for subsequent exception handling.
[0041] Step A3: The TPCM chip releases the control right of the FLASH storage chip. The working mode of the TPCM chip switches from the SPI master mode to the SPI slave mode, and the STATE status line switches from high level to low level. The TPCM chip notifies the CPU through the STATE status line that the measurement has been completed and the TPCM chip has switched to the SPI slave mode, and then releases the CPU reset pin through GPIO to start the CPU.
[0042] Step A4: After the CPU starts, the CPU obtains the control right of the FLASH storage chip as the SPI master device. The CPU works in the SPI master mode and loads the bootloader file from the FLASH storage chip.
[0043] Step A5: After the bootloader starts, the CPU reads the FLASH ID of the FLASH storage chip and the reverse verification public key.
[0044] Step A6: After the CPU reads successfully, determine whether the TPCM chip is available through the STATE status line. If the STATE status line is at a low level, execute Step A7; if it is at a high level, wait for the TPCM chip to be available and record the audit log.
[0045] Step A7: After the CPU, as the SPI master device, obtains the control right of the TPCM chip, it reads the reverse verification reference value in the TPCM chip and performs signature verification using the reverse verification public key. If the signature verification is successful, it measures the kernel file and starts the operating system; if the signature verification fails, it stops the loading process, records the audit log, and issues an alarm to notify relevant personnel for subsequent exception handling.
[0046] Embodiment 1:
[0047] After the boot program starts, the present invention performs reverse identity authentication on the TPCM chip and supervises the trusted root, ensuring the true credibility of the TPCM chip. Using the FLASH ID of the storage chip as a third-party trusted factor removes the public factor in the identity authentication, preventing the public factor from being stolen or tampered with during the interaction process. It realizes the trusted verification of the source of the trusted chain and ensures the security of the device operating environment.
[0048] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0049] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0050] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0051] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to produce a computer-implemented process, thereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process or a plurality of processes and / or boxes Figure 1 one process or a plurality of processes and / or boxes Figure 1 steps for implementing the functions specified in one box or a plurality of boxes.
[0052] The above are only the preferred embodiments of the present invention, and it should be pointed out that: for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. A two-way authentication trusted boot system based on a TPCM chip, characterized in that: Including: TPCM chip, FLASH memory chip, and CPU chip; The TPCM chip includes: a main SPI interface and a slave SPI interface. The FLASH memory chip includes: a slave SPI interface. The CPU chip includes: a main SPI interface. The main SPI interface of the TPCM chip is connected to the slave SPI interface of the FLASH memory chip. The slave SPI interface of the TPCM chip is connected to the main SPI interface of the CPU chip. The main SPI interface of the CPU chip is also connected to the slave SPI interface of the FLASH memory chip. The GPIO output pin of the TPCM chip is connected to the RESET reset pin of the CPU chip to achieve startup control of the CPU chip. The STATE pin of the TPCM chip is connected to the GPIO pin of the CPU chip to notify the CPU whether the measurement process has ended and whether the TPCM chip is in SPI master mode or SPI slave mode; The two-way authentication trusted boot method of the two-way authentication trusted boot system specifically includes: After the system is powered on, the TPCM chip obtains the control right of the system and controls the CPU chip to be in a reset state; The TPCM chip performs forward measurement on the boot program in the FLASH memory chip. If the measurement is successful, the TPCM chip releases the reset signal of the CPU chip, and the CPU chip starts to load the boot program; After the CPU chip completes the loading of the boot program, it performs reverse measurement on the TPCM chip. If the measurement is successful, the boot program loads the kernel and starts the operating system; The method for the TPCM chip to perform forward measurement on the boot program in the FLASH memory chip includes the following steps: The TPCM chip communicates with the SPI slave device interface of the FLASH memory chip using the SPI master device interface. The TPCM chip reads the boot program data and the boot program signature value from the FLASH memory chip, and uses the forward verification public key in the TPCM chip to verify the signature of the boot program data and the boot program signature value. If the signature verification is successful, the TPCM chip releases the control right of the FLASH memory chip. The working mode of the TPCM chip is switched from SPI master mode to SPI slave mode, and the STATE status line is switched from high level to low level. The TPCM chip notifies the CPU chip through the STATE status line that the measurement has been completed and the TPCM chip has been switched to SPI slave mode, and then releases the CPU chip reset pin through GPIO to start the CPU chip; If the signature verification fails, the loading process is stopped, the CPU chip is controlled to be in a reset state all the time, the TPCM chip records the audit log, and alarms externally to notify relevant personnel for subsequent exception handling; The method for the CPU chip to perform reverse measurement on the TPCM chip after completing the loading of the boot program includes the following steps: After the CPU chip starts, the CPU chip obtains the control right of the FLASH memory chip using the SPI master device interface. The CPU chip operates in SPI master mode and loads the boot program data from the FLASH memory chip; After the bootloader starts, the CPU reads the FLASH ID of the FLASH memory chip and the reverse verification public key; After the CPU successfully reads, if the STATE status line is at a low level, the CPU uses the SPI master device interface to obtain control of the TPCM chip, reads the reverse measurement reference value in the TPCM chip, and performs signature verification using the reverse verification public key. If the signature verification is successful, the kernel file is measured and the operating system is started; if the signature verification fails, the loading process is stopped, the audit log is recorded, and an alarm is issued to notify relevant personnel for subsequent exception handling; if the STATE status line is at a high level, wait for the TPCM chip to be available and record the audit log.
2. The two-way authentication trusted boot system based on a TPCM chip according to claim 1, characterized in that: The TPCM chip pre-stores a forward measurement reference value, a forward verification public key, and a reverse measurement reference value.
3. A two-way authentication trusted boot system based on a TPCM chip according to claim 1, characterized in that: The FLASH memory chip pre-stores a reverse verification public key.
4. The two-way authentication trusted boot system based on a TPCM chip according to claim 2, characterized in that: The TPCM chip has a unique forward verification public key and a reverse verification private key.
5. The two-way authentication trusted boot system and method based on a TPCM chip according to claim 2, characterized in that: The forward measurement reference value is a digital signature value obtained by digitally signing the bootloader using the forward verification public key in a clean running environment; the reverse measurement reference value is a digital signature value obtained by digitally signing the unique FLASH ID of the FLASH memory chip using the reverse verification private key in a clean running environment.
6. A two-way authentication trusted boot method based on a TPCM chip, characterized in that: It includes the following steps: After the system is powered on, the TPCM chip obtains control of the system and controls the CPU chip to be in a reset state; The TPCM chip performs forward measurement on the bootloader in the FLASH memory chip. If the measurement is successful, the TPCM chip releases the reset signal of the CPU chip, and the CPU chip starts to load the bootloader; After the CPU chip completes the loading of the bootloader, it performs reverse measurement on the TPCM chip. If the measurement is successful, the bootloader loads the kernel and starts the operating system; The method for the TPCM chip to perform forward measurement on the bootloader in the FLASH memory chip includes the following steps: The TPCM chip communicates with the SPI slave device interface of the FLASH memory chip using the SPI master device interface. The TPCM chip reads the bootloader data and the bootloader signature value from the FLASH memory chip, and performs signature verification on the bootloader data and the bootloader signature value using the forward verification public key in the TPCM chip. If the signature verification is successful, the TPCM chip releases the control of the FLASH memory chip, the working mode of the TPCM chip switches from the SPI master mode to the SPI slave mode, the STATE status line switches from a high level to a low level, the TPCM chip notifies the CPU chip through the STATE status line that the measurement has been completed and the TPCM chip has switched to the SPI slave mode, and then releases the CPU chip reset pin through GPIO to start the CPU chip; If the signature verification fails, the loading process is stopped, the CPU chip is controlled to be in a reset state all the time, the TPCM chip records the audit log, and alarms externally to notify relevant personnel for subsequent exception handling; The method for the CPU chip to perform reverse measurement on the TPCM chip after completing the loading of the bootloader includes the following steps: After the CPU chip starts up, the CPU chip uses the SPI master device interface to obtain the control right of the FLASH storage chip. The CPU chip works in the SPI master mode and loads the boot program data from the FLASH storage chip; After the boot program starts, the CPU reads the FLASH ID and the reverse verification public key of the FLASH storage chip; After the CPU reads successfully, if the STATE status line is at a low level, the CPU uses the SPI master device interface to obtain the control right of the TPCM chip, reads the reverse measurement reference value in the TPCM chip, and performs signature verification with the reverse verification public key. If the signature verification is successful, then measure the kernel file and start the operating system; if the signature verification fails, then stop the loading process, record the audit log, and issue an alarm to notify relevant personnel to perform subsequent exception handling; if the STATE status line is at a high level, then wait for the TPCM chip to be available and record the audit log.
7. The two-way authentication trusted boot method based on a TPCM chip according to claim 6, wherein: The TPCM chip performs forward measurement on the boot program in the FLASH storage chip. If the measurement fails, the TPCM chip holds the reset signal of the CPU chip, terminates this startup, and performs startup failure handling.
8. The two-way authentication trusted boot method based on a TPCM chip according to claim 6, characterized in that: After the CPU chip completes the loading of the boot program, it performs reverse measurement on the TPCM chip. If the measurement fails, then stop loading the kernel, terminate this startup, and perform startup failure handling.
Citation Information
Patent Citations
Credible mainboard implementation method for realizing active measurement of firmware by utilizing TPCM
CN110119623A