Electronic device and data integrity verification method

By retrieving the calibration signature tag in the non-volatile memory of the electronic device and adjusting its address, the problem of adjusting the access location of the firmware image file is solved, the flexibility of storage space planning is improved, the search time is reduced, and the rapid verification of data integrity is ensured.

CN114647870BActive Publication Date: 2025-09-05GIGA COMPUTING TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011508336.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-18
Publication Date
2025-09-05
Estimated Expiration
2040-12-18

AI Technical Summary

Technical Problem

In the prior art, updating the firmware file of an electronic device may cause the access location of the digital signature to be overwritten. It is difficult to adjust the digital signature location of the firmware image file without changing the data integrity verification algorithm, resulting in inconvenient storage space planning and excessively long search time.

Method used

By retrieving the calibration signature tag in the non-volatile memory and adjusting its address to freely adjust the access location of the digital signature, the non-volatile memory of the firmware image file is divided into multiple retrieval areas, and a preset displacement is used to determine whether the data to be confirmed is a calibration signature tag, thereby avoiding a full-domain search.

Benefits of technology

It enables the free adjustment of the digital signature position of the firmware image file without changing the data integrity verification algorithm, improves the flexibility of storage space planning, and significantly reduces the time consumption of searching for digital signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114647870B_ABST
    Figure CN114647870B_ABST
Patent Text Reader

Abstract

An electronic device and a data integrity verification method are disclosed. The electronic device includes a non-volatile memory and a security processor. The non-volatile memory includes a firmware image, an electronic check signature corresponding to the firmware image, and a calibration signature tag. The security processor retrieves the calibration signature tag from the non-volatile memory based on a preset identification code and, based on the calibration signature tag, obtains a predetermined area within the non-volatile memory. This predetermined area includes configuration table information, and the configuration table information includes an electronic check signature. The security processor then performs a data integrity verification on the firmware image based on the electronic check signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a data integrity verification technology, and more particularly to an electronic device and a data integrity verification method. Background Art

[0002] Currently, manufacturers do not want users to arbitrarily adjust the firmware or related settings in electronic devices (such as personal computers, laptops, and server equipment), which could cause the electronic devices to malfunction. To ensure the data integrity of firmware files in these electronic devices (especially firmware images required for specific components such as central processing units (CPUs) or baseboard management controllers (BMCs)), a digital signature corresponding to the file is typically stored in a specific location in non-volatile memory, for example, at the end of the file, thereby conveniently performing data integrity verification on the aforementioned file.

[0003] However, because the aforementioned files are frequently updated to adjust their content and the device's settings, the file size often increases, potentially overwriting the digital signature's access location. Furthermore, because the digital signature's access location is fixed in the device's hardware chip at the factory, it is virtually impossible to readjust or modify it. Summary of the Invention

[0004] The present invention provides an electronic device and a data integrity verification method, which freely adjusts the access location of the digital signature corresponding to the firmware image file in the non-volatile memory without changing the data integrity verification algorithm, thereby facilitating the planning of the non-volatile memory space.

[0005] The electronic device of the present invention includes a first non-volatile memory and a security processor. The first non-volatile memory includes a first firmware image file, a first electronic check signature corresponding to the first firmware image file, and a first calibration signature label. The security processor is coupled to the first non-volatile memory. The security processor retrieves the first calibration signature label from the first non-volatile memory based on a preset identification code. The security processor obtains a predetermined area located in the first non-volatile memory based on the first calibration signature label. The predetermined area includes configuration table information, and the configuration table information includes a first electronic check signature. The security processor performs a data integrity check on the first firmware image file based on the first electronic check signature.

[0006] The data integrity verification method of the present invention is applicable to an electronic device including a first non-volatile memory and a security processor. The first non-volatile memory includes a firmware image file and an electronic check signature corresponding to the first firmware image file. The data integrity verification method includes the following steps: retrieving a calibration signature tag in the first non-volatile memory based on a preset identification code; obtaining a predetermined area located in the first non-volatile memory based on the first calibration signature tag, wherein the predetermined area includes configuration table information, and the configuration table information includes a first electronic check signature; and performing a data integrity verification on the first firmware image file based on the first electronic check signature.

[0007] Based on the above, the electronic device and data integrity verification method described in the embodiment of the present invention will search for a calibration signature tag in a non-volatile memory having a firmware image file, read the address corresponding to this calibration signature tag (for example, the address located behind this calibration signature tag), and use this address to find the relevant information required to perform data integrity verification. Therefore, since the address corresponding to this calibration signature tag can be adjusted by updating or other methods, the access position of the digital signature corresponding to the firmware image file in the non-volatile memory can be freely adjusted without changing the algorithm for data integrity verification in the electronic device, thereby making it easy to plan the space of the non-volatile memory. On the other hand, the embodiment of the present invention also divides the non-volatile memory of the firmware image file into multiple retrieval areas, and by judging whether the data to be confirmed with a preset displacement is a calibration signature tag in each retrieval area, a full-domain search is avoided, thereby significantly reducing the time spent on searching for digital signatures. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 is a block diagram of an electronic device according to an embodiment of the present invention.

[0009] Figure 2 FIG. 1 is a schematic diagram of a security processor and a non-volatile memory in an electronic device according to an embodiment of the present invention.

[0010] Figure 3 4 is a flow chart of a method for verifying data integrity according to an embodiment of the present invention.

[0011] Figure 4 It is an explanation Figure 3 Detailed flowchart of step S320.

[0012] The following are the descriptions of the reference numerals:

[0013] 100: Electronic devices

[0014] 110: Security Processor

[0015] 120: CPU

[0016] 130: Baseboard Management Controller

[0017] 140, 141-144: Non-volatile memory

[0018] 151-154: Firmware

[0019] 210: Firmware image file

[0020] 220: Electronic inspection signature

[0021] 230: Preset identification code

[0022] 241-1, 242-1: Dashed squares

[0023] 243-1: Box

[0024] 243-2: Memory area for marking the predetermined location of the signature identification code

[0025] 241-244: Search area

[0026] 250: Reserved area

[0027] 250-1: Arrow

[0028] PAA: Predetermined Area Address

[0029] PKD: Public Key Information

[0030] GUID: GUID for identifying the signature

[0031] S310~S330, S410~S430: Steps DETAILED DESCRIPTION

[0032] Figure 1 1 is a block diagram of an electronic device 100 according to an embodiment of the present invention. The electronic device 100 of this embodiment can be a server, a personal computer, a laptop, a tablet computer, a smartphone, or similar electronic products. A server is used as an example of the electronic device 100.

[0033] The electronic device 100 primarily includes at least one nonvolatile memory and a security processor 110. The electronic device 100 of this embodiment also includes a central processing unit 120 and a baseboard management controller (BMC) 130. The electronic device 100 includes nonvolatile memories 141 and 143, and may also include nonvolatile memories 142 and 144. Nonvolatile memories 142-144 may be flash memories.

[0034] The non-volatile memory 141 (also referred to as the main non-volatile memory or the first non-volatile memory) is used to store the firmware image file ( Figure 1 The non-volatile memory 142 is used to back up the firmware image file (firmware 152) required by the central processing unit 140. That is to say, the non-volatile memory 142 (also referred to as the secondary non-volatile memory or the second non-volatile memory) is used to back up the non-volatile memory 141. When the non-volatile memory 141 cannot be read by the central processing unit 140 or the firmware image file in the non-volatile memory 141 is erroneous, the central processing unit 140 can operate normally through the firmware image file in the backup non-volatile memory 142. The firmware image file required by the central processing unit 140 can be a basic input and output system (BIOS). The firmware image file described in this embodiment can also be called firmware program code. Those who apply this embodiment can know that the firmware image file itself is a file that the manufacturer of the electronic device 100 does not want to be tampered with, so the firmware program code is stored in the corresponding non-volatile memory in the form of an image file.

[0035] Non-volatile memory 143 (also referred to as the primary non-volatile memory or first non-volatile memory) is used to store the firmware image file (firmware 153) required by the baseboard management controller 130. Non-volatile memory 144 (also referred to as the secondary non-volatile memory or second non-volatile memory) is used to back up the firmware image file (firmware 154) required by the baseboard management controller 130. In other words, non-volatile memory 144 serves as a backup for non-volatile memory 143. If the baseboard management controller 130 cannot read non-volatile memory 143 or the firmware image file in non-volatile memory 143 contains errors, the baseboard management controller 130 can continue to operate normally using the firmware image file in the backup non-volatile memory 144.

[0036] In this embodiment, to prevent firmware corruption due to damage to the non-volatile memories 141-144, these non-volatile memories 141-144 are implemented as separate memory devices. Users of this embodiment can also store files in the non-volatile memories 141-144 in different areas of the same memory device. However, if this memory device is damaged and cannot access data, the aforementioned files will be inaccessible, and the mutual redundancy mechanism between the non-volatile memories 141-142 and the non-volatile memories 143-144 may be ineffective.

[0037] The at least one non-volatile memory mentioned in this embodiment may be one of the non-volatile memories 141 - 144. The security processor 110 is configured to perform data integrity checks on the firmware image files in one or all of the non-volatile memories 141 - 144.

[0038] To prevent the corresponding firmware image file (also referred to as firmware) for the CPU 140 or BMC 130 in the electronic device 100 from being damaged, tampered with, or otherwise affecting the security of the firmware, the security processor 110 of this embodiment performs a data integrity check on the firmware in the non-volatile memories 141-144 before the CPU 140 or BMC 130 reads the firmware from the corresponding non-volatile memory, thereby ensuring the security of the firmware.

[0039] In this embodiment, the data integrity check requires the digital signature corresponding to the firmware. The embodiment of the present invention adjusts the access method of the digital signature in the security processor 110 so that the access location of the digital signature can be freely adjusted without changing the algorithm for data integrity verification in the electronic device 100. In detail, the security processor 110 of the embodiment of the present invention retrieves a calibration signature tag in the non-volatile memory having the firmware image file, reads the address corresponding to the calibration signature tag (for example, the address behind the calibration signature tag), and uses this address to find the relevant information required for performing the data integrity check. Since the content of the address corresponding to the calibration signature tag can be adjusted by updating or the like, the access location of the digital signature corresponding to the firmware image file in the non-volatile memory can be freely adjusted without changing the algorithm for data integrity verification in the electronic device 100. Another embodiment of the present invention further divides the non-volatile memory of the firmware image into multiple search areas. By determining whether the data to be verified at a predetermined offset in each search area is a calibration signature tag, this avoids a full search and significantly reduces the time required to search for digital signatures. The following figures and corresponding descriptions illustrate various embodiments of the present invention.

[0040] Figure 2 is a schematic diagram of the security processor 110 and the non-volatile memory 140 in the electronic device 100 according to an embodiment of the present invention. Figure 2 The non-volatile memory 140 is exemplified as one of the aforementioned non-volatile memories 141-144 and serves as an exemplary non-volatile memory for the security processor 110 to perform firmware data integrity verification in this embodiment of the present invention. The non-volatile memory 140 of this embodiment includes a firmware image 210, an electronic check signature 220 corresponding to the firmware image 210, and a GUID identifying the signature label.

[0041] During the firmware data integrity check of this embodiment, the security processor 110 has a built-in preset identifier 230 and searches the non-volatile memory 140 for the calibration signature identifier GUID based on the preset identifier 230. The security processor 110 of this embodiment can search the non-volatile memory 140 for the calibration signature identifier GUID in various ways. One method is to perform a global search, comparing the data corresponding to each address in the non-volatile memory 140 to see if it is identical to the preset identifier 230, thereby finding the calibration signature identifier GUID in the non-volatile memory 140. This method may consume significant hardware computing costs and a considerable amount of time in searching for the calibration signature identifier GUID.

[0042] The embodiment of the present invention provides another method to avoid global search and still quickly search for the GUID of the digital signature, thereby significantly reducing the time spent on searching for the digital signature. The security processor 110 divides the non-volatile memory 140 into multiple search areas (e.g., Figure 2 The security processor 110 retrieves the data to be confirmed at the predetermined offsets in the search areas 241-244 in the example. Specifically, the security processor 110 searches for the address corresponding to the predetermined offset in each search area of ​​the same size and retrieves the corresponding data to be confirmed. The size of the search areas 241-244 in this embodiment is 4096 bits by way of example. Users of this embodiment may adjust the size of the search areas as needed.

[0043] For example, it is assumed that the preset offset is "1000" bits. When the security processor 110 searches for the calibration signature identification code GUID, it first adds "1000" bits (i.e., the preset offset) to the first address in the first search area 241 and then searches for the address in the area corresponding to the address (e.g., Figure 2 Then, the security processor 110 compares the data to be confirmed in the dotted box 241-1 with the aforementioned preset identification code to determine whether the data to be confirmed is the calibration signature identification code GUID.

[0044] If the data to be confirmed in the dotted box 241-1 in the search area 241 is different from the aforementioned preset identification code, the security processor 110 continues to perform the aforementioned operation on the next search area 242 to 244 in sequence until the calibration signature identification code GUID is retrieved. In other words, the security processor 110 adds "1000" bits (preset offset) to the first address in the search area 242 and stores the corresponding address in the area (such as Figure 2Then, the security processor 110 compares the data to be confirmed in the dotted box 242-1 with the aforementioned preset identification code to determine whether the data to be confirmed is the calibration signature identification code GUID.

[0045] It is assumed that the data to be confirmed in the box 243-1 in the search area 243 of this embodiment is the same as the calibration signature identification code GUID. Therefore, when the security processor 110 obtains the corresponding preset displacement ( Figure 2 When the data to be confirmed is determined to be equal to the content of the calibration signature identification code GUID, it means that the calibration signature identification code GUID has been retrieved from the non-volatile memory 140.

[0046] At this time, the security processor 110 obtains a predetermined area (eg, Figure 2 250). In this embodiment, the predetermined area 250 includes configuration table information, and this configuration table information also includes the electronic check signature 220. In other words, the configuration table information in this embodiment is primarily used to store information such as the electronic digital signature corresponding to the firmware image file and the public key information PKD, which are required for data integrity verification. Each piece of information in the configuration table information is designed with a fixed offset, allowing the algorithm in the security processor 110 to obtain the required information upon obtaining the predetermined area 250.

[0047] The security processor 110 can obtain the predetermined area 250 based on the calibration signature identification code GUID in various ways. For example, the non-volatile memory 140 of this embodiment also includes a predetermined area address PAA. The predetermined area address PAA is located in the memory area 243-2 at the predetermined position of the calibration signature identification code GUID. For example, the predetermined area address PAA is located in the address space area 243-2 located after the calibration signature identification code GUID. After retrieving the calibration signature identification code GUID, the security processor 110 obtains the predetermined area address PAA from the address space area 243-2 located after the calibration signature identification code GUID. In addition, the security processor 110 searches the predetermined area 250 corresponding to the predetermined area address PAA in the non-volatile memory 140 (as indicated by arrow 250-1). Users of this embodiment can appropriately adjust the positional relationship between the calibration signature identification code GUID and the memory area 243-2 where the predetermined area address PAA is located according to their needs. For example, in some embodiments, the memory area 243-2 may be located before, after, above, or below the calibration signature identification code GUID, and / or there may be a preset offset between the memory area 243-2 and the calibration signature identification code GUID.

[0048] After obtaining the configuration table information in the predetermined area 250, the security processor 110 locates the electronic check signature 220 corresponding to the firmware image 210. Therefore, the security processor 110 performs a data integrity check on the firmware image 250 based on the electronic check signature 220. Specifically, the configuration table information 250 includes public key information PKD in addition to the electronic digital signature 220. The security processor 110 obtains the public key information PKD from the configuration table information 250 and calculates a predetermined hash value corresponding to the firmware image 210 based on the public key information PKD. This predetermined hash value serves as the basis for the data integrity check. Specifically, the security processor 110 calculates a check hash value for the firmware image 210 based on the electronic check signature 220 and compares the predetermined hash value with the check hash value to determine whether the data integrity check is successful. If the predetermined hash value and the check hash value are identical, the data integrity check on the firmware image 210 is successful and the firmware image 210 has not been tampered with or compromised. On the other hand, when the predetermined hash value and the check hash value are different, it indicates that the data integrity check of the firmware image file 210 has failed.

[0049] If the security processor 110 fails the firmware data integrity check, it indicates that the corresponding firmware of the CPU 140 or BMC 130 has security concerns. Therefore, the security processor 110 will disable the electronic device 100 from booting up and illuminate a warning light using a light-emitting diode (LED) on the motherboard of the electronic device 100, alerting the user or maintenance personnel of the electronic device 100 to the situation.

[0050] Please refer to Figure 1 The non-volatile memories 141-144 include firmware 151-154, electronic check signatures corresponding to the firmware 151-154 (eg, Figure 2 The electronic digital signature 220 in the Figure 2 The security processor performs a data integrity check on the firmware image files (ie, firmware 151 - 154 ) located in each non-volatile memory 141 - 144 according to the corresponding electronic check signature in each non-volatile memory 141 - 144 .

[0051] For example, if the firmware of the CPU 120 fails a data integrity check on the firmware image file (i.e., firmware 151) in the first non-volatile memory 141, the security processor 110 writes the firmware image file (i.e., firmware 152) in the second non-volatile memory 142, which passed the data integrity check, to the location of the firmware image file (i.e., firmware 151) in the first non-volatile memory 141, overwriting the first firmware image file. For example, if the firmware of the BMC 130 fails a data integrity check on the firmware image file (i.e., firmware 153) in the first non-volatile memory 143, the security processor 110 writes the firmware image file (i.e., firmware 154) in the second non-volatile memory 144, which passed the data integrity check, to the location of the firmware image file (i.e., firmware 153) in the first non-volatile memory 143, overwriting the first firmware image file.

[0052] Figure 3 4 is a flow chart of a method for verifying data integrity according to an embodiment of the present invention. Figure 3 The data integrity verification method is applicable to, for example, Figure 1 or Figure 2 The electronic device 100 includes at least one non-volatile memory and a security processor 110. Figure 2 The non-volatile memory 140 and the security processor 110 are used as examples to illustrate Figure 3 inspection method.

[0053] At Figure 3 In step S310, the security processor 110 retrieves the calibration signature tag GUID from the non-volatile memory 140 based on a predetermined identification code. In step S320, the security processor 110 obtains the predetermined area 250 located in the non-volatile memory 140 based on the calibration signature tag GUID. The predetermined area 360 includes configuration table information, and this configuration table information includes an electronic check signature 250. In step S330, the security processor 110 performs a data integrity check on the firmware code based on the electronic check signature 220.

[0054] Figure 4 It is an explanation Figure 3Detailed flow chart of step S320. In step S410, the security processor 110 divides the non-volatile memory 140 into multiple retrieval areas (retrieval areas 241 to 244 as shown in Figure 2). In step S420, the security processor 110 obtains the pending data corresponding to the preset displacement in each retrieval area in sequence. In step S430, the security processor 110 compares the aforementioned pending data with the aforementioned preset identification code to determine whether the pending data is a calibration signature label GUID. If step S430 is yes (the content of the aforementioned pending data is the same as the content of the aforementioned preset identification code), then enter Figure 3 Step S330. If the answer to step S430 is no (the content of the data to be confirmed is different from the content of the preset identification code), then return to step S330. Figure 4 In step S420, the data to be confirmed corresponding to the preset displacement is obtained in the next search area.

[0055] In summary, the electronic device and data integrity verification method described in the embodiment of the present invention will search for a calibration signature tag in a non-volatile memory having a firmware image file, read the address corresponding to this calibration signature tag (for example, the address located behind this calibration signature tag), and use this address to find the relevant information required to perform data integrity verification. Therefore, since the address corresponding to this calibration signature tag can be adjusted by updating or the like, the access position of the digital signature corresponding to the firmware image file in the non-volatile memory can be freely adjusted without changing the algorithm for data integrity verification in the electronic device, thereby facilitating the planning of the space of the non-volatile memory. On the other hand, the embodiment of the present invention also divides the non-volatile memory of the firmware image file into multiple retrieval areas, and by judging in each retrieval area whether the data to be confirmed with a preset displacement is a calibration signature tag, a full-domain search is avoided, thereby significantly reducing the time spent on searching for digital signatures.

Claims

1. An electronic device, characterized in that: The electronic device comprises: a first non-volatile memory comprising a first firmware image file, a first electronic check signature corresponding to the first firmware image file, and a first calibration signature label; and a security processor coupled to the first non-volatile memory, The security processor retrieves the first calibration signature tag identical to the preset identification code from the first non-volatile memory according to the preset identification code, Obtaining a predetermined area in the first non-volatile memory according to the first calibration signature tag, wherein the predetermined area includes a configuration table information, and the configuration table information includes the first electronic inspection signature, and performing a data integrity check on the first firmware image file based on the first electronic check signature, The first non-volatile memory further includes: A predetermined area address is located in an address space area behind the first marking signature label, After retrieving the first marking signature tag, the security processor obtains the predetermined area address from the address space area behind the first marking signature tag. Furthermore, the security processor searches the first non-volatile memory for the predetermined area corresponding to the predetermined area address.

2. The electronic device according to claim 1, wherein The security processor divides the first non-volatile memory into a plurality of retrieval areas, sequentially obtains a piece of data to be confirmed corresponding to a preset displacement in each retrieval area, compares the data to be confirmed with the preset identification code, and determines whether the data to be confirmed is the first calibration signature label.

3. The electronic device according to claim 1, wherein: The configuration table information also includes a public key information, After the security processor obtains the predetermined area in the first non-volatile memory, the security processor obtains the public key information in the configuration table information, calculates a predetermined hash value corresponding to the first firmware image file based on the public key information, calculates a check hash value for the first firmware image file based on the first electronic check signature, and compares the predetermined hash value with the check hash value to determine whether the data integrity check is successful.

4. The electronic device according to claim 1, wherein: The electronic device further comprises: a second non-volatile memory including a second firmware image file, a second electronic check signature corresponding to the second firmware image file, and a second calibration signature label; The security processor performs the data integrity check on the second firmware image file according to the second electronic check signature.

5. The electronic device according to claim 4, wherein: When the data integrity check is performed on the first firmware image file located in the first non-volatile memory but fails, the security processor writes the second firmware image file located in the second non-volatile memory, which succeeds in the data integrity check, to the location of the first firmware image file in the first non-volatile memory to overwrite the first firmware image file.

6. The electronic device according to claim 1, wherein: The electronic device further comprises: A central processing unit, wherein the first firmware image file is the firmware of the central processing unit, or A baseboard management controller (BMC) is provided, wherein the first firmware image file is the firmware of the baseboard management controller.

7. The electronic device according to claim 6, wherein: The security processor performs the data integrity check on the first firmware image file according to the first electronic check signature before the central processor loads the first firmware image file or the baseboard management controller loads the first firmware image file. Furthermore, when the security processor performs the data integrity check on the first firmware image file but fails, the electronic device is prevented from booting up.

8. A data integrity verification method, applicable to an electronic device comprising a first non-volatile memory and a security processor, characterized in that: The first non-volatile memory includes a first firmware image file and an electronic check signature corresponding to the first firmware image file. The data integrity verification method includes: Retrieving a first marking signature tag identical to the preset identification code from the first non-volatile memory according to the preset identification code; Obtaining a predetermined area in the first non-volatile memory according to the first marking signature label, wherein the predetermined area includes a configuration table information, and the configuration table information includes a first electronic inspection signature; and Performing a data integrity check on the first firmware image file based on the first electronic check signature, The step of obtaining the predetermined area in the first non-volatile memory according to the first calibration signature tag includes: After retrieving the first marking signature tag, obtaining a predetermined region address from an address space region located behind the first marking signature tag; and The predetermined area corresponding to the predetermined area address in the first non-volatile memory is searched.

9. The inspection method according to claim 8, wherein: The step of retrieving the first calibration signature tag from the first non-volatile memory according to the preset identification code includes: dividing the first non-volatile memory into a plurality of search areas; Sequentially obtain a piece of to-be-confirmed data corresponding to a preset displacement in each search area; Comparing the data to be confirmed with the preset identification code to determine whether the data to be confirmed is the first calibration signature label; and In a case where the data to be confirmed is not the first calibration signature label, the data to be confirmed corresponding to the preset displacement is obtained in a next search area.

10. The inspection method according to claim 8, wherein: The configuration table information also includes a public key information, The step of performing the data integrity check on the first firmware image file according to the first electronic check signature includes: Obtain the public key information in the configuration table information; Calculating a predetermined hash value corresponding to the first firmware image file according to the public key information; Calculating a check hash value for the first firmware image file based on the first electronic check signature; and The predetermined hash value and the check hash value are compared to determine whether the data integrity check is successful.

11. The inspection method according to claim 8, wherein: The electronic device further comprises: a second non-volatile memory including a second firmware image file, a second electronic check signature corresponding to the second firmware image file, and a second calibration signature label; The inspection method also includes: The data integrity check is performed on the second firmware image file according to the second electronic check signature.

12. The inspection method according to claim 11, wherein: The inspection method further comprises: Before a central processing unit of the electronic device loads the first firmware image file or a baseboard management controller of the electronic device loads the first firmware image file, performing the data integrity check on the first firmware image file according to the first electronic check signature; and When the data integrity check is performed on the first firmware image file located in the first non-volatile memory but fails, the second firmware image file located in the second non-volatile memory, which passes the data integrity check, is written to the location of the first firmware image file in the first non-volatile memory to overwrite the first firmware image file.

13. The inspection method according to claim 8, wherein: The inspection method further comprises: Before a central processing unit of the electronic device loads the first firmware image file or a baseboard management controller of the electronic device loads the first firmware image file, performing the data integrity check on the first firmware image file according to the first electronic check signature; and When the data integrity check is performed on the first firmware image file but fails, the electronic device is prevented from booting up.

Citation Information

Patent Citations

  • Embedded device and control method thereof

    CN103105783A

  • System-on-chip and booting method thereof

    TW201342238A