A microprocessor, a BIOS firmware update method, a computer device, and a storage medium
By introducing a cryptographic engine unit with a trusted execution environment into the microprocessor, multiple security verification of BIOS firmware is achieved, which solves the problem of authenticity identification in BIOS firmware updates, and improves the security and startup reliability of computer equipment.
Patent Information
- Application Number
- CN202210289223.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-22
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-03-22
AI Technical Summary
The prior art cannot effectively identify the authenticity of BIOS firmware. Computer equipment is vulnerable to attacks with virus firmware when the transmission channel is compromised, resulting in security risks.
The cryptographic engine unit in a trusted execution environment is introduced into the microprocessor, and the calculation information and certificate of the BIOS firmware are verified through the secure interface to ensure that the calculation results match the preset results before firing them. Combined with public key hash verification, multiple security verification is realized.
Improves the security of BIOS firmware updates, reduces the risk of algorithms being stolen and targeted cracking, and ensures the integrity of BIOS firmware and the boot security of computer equipment.
Smart Images

Figure CN114721693B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and in particular, to a microprocessor, a method for updating BIOS firmware, a computer device, and a storage medium. Background Art
[0002] BIOS (Basic Input Output System) firmware is a set of programs stored in the BIOS flash of a computer device, which includes the most important basic input and output programs, power-on self-test programs, and system self-boot programs in the computer device. Once the integrity of the BIOS firmware is damaged, the computer device cannot operate normally. Moreover, since the first section of code for the CPU (Central Processing Unit) to run is stored in the BIOS firmware, if malicious programs are implanted in the BIOS firmware, attackers can monitor the OS (Operating System) and can bypass the multiple protections of the operating system to record system input and output information, posing a great security risk.
[0003] Currently, in order to prevent the BIOS firmware from being maliciously attacked and its integrity from being damaged, usually the BIOS firmware to be updated and sent to the computer device is verified on the firmware sending side to ensure the security of the BIOS firmware.
[0004] However, in the above BIOS firmware update method, the computer device cannot identify the authenticity of the received BIOS firmware. If the transmission channel between the firmware sending side and the computer device is breached, virus-infected BIOS firmware can be pushed to the computer device through this transmission channel, causing the computer device to update the virus-infected BIOS firmware and posing a serious security risk. Summary of the Invention
[0005] The purpose of the embodiments of this application is to provide a microprocessor, a method for updating BIOS firmware, a computer device, and a storage medium, so as to improve the security of BIOS firmware updates.
[0006] An embodiment of the present application provides a microprocessor, including: a control unit, a cryptographic engine unit, and a BIOS flash memory. The microprocessor is equipped with a normal execution environment and a trusted execution environment, and information interaction between the normal execution environment and the trusted execution environment is carried out through a security interface; the cryptographic engine unit is set in the trusted execution environment, where: the control unit is used to, when obtaining a BIOS firmware to be updated, send the calculation information in the BIOS firmware to the cryptographic engine unit through the security interface to instruct the cryptographic engine unit to perform calculations according to the calculation information and obtain a calculation result; the control unit is further used to, when the calculation result matches a preset first result, write the BIOS firmware to be updated into the BIOS flash memory.
[0007] In the above implementation process, when the control unit of the microprocessor obtains the BIOS firmware to be updated, it does not directly perform the update. Instead, it sends the calculation information of the BIOS firmware to the cryptographic engine unit in the trusted execution environment through the security interface for calculation. Then, when the calculation result matches the preset first result, the BIOS firmware to be updated is written into the BIOS flash memory. In this way, through the calculation information in the BIOS firmware to be updated, the security verification of the BIOS firmware to be updated is realized, the security of the BIOS firmware update is improved, and thus the security of the computer device startup is improved. In addition, in the above implementation solution, the calculation information is calculated by the cryptographic engine unit in the trusted execution environment, that is, the algorithms used for verifying the BIOS firmware to be updated all run in the trusted execution environment. This reduces the risk of the algorithms being stolen, thereby reducing the risk of the algorithms being specifically cracked, ensuring the security of information verification, and further improving the security of the BIOS firmware update.
[0008] Further, the calculation information is the firmware information of the BIOS firmware; the calculation result is the hash value of the firmware information of the BIOS firmware; the preset first result is the hash value of the BIOS firmware carried in the BIOS firmware.
[0009] It should be understood that the hash value is the value obtained by calculating the data through the hash algorithm. Generally, for the same data, the calculated hash value is determined. Based on this, in the above implementation process, if the hash value calculated from the firmware information of the BIOS firmware matches the hash value carried in the BIOS firmware, it can be determined that the firmware information has not been tampered with, thereby achieving the effect of security verification of the BIOS firmware and improving the security of the BIOS firmware update.
[0010] Further, the control unit is further configured to, before sending the calculation information in the BIOS firmware to the password engine unit, send the certificate carried in the BIOS firmware to the password engine unit through the security interface, so as to instruct the password engine unit to verify the certificate and obtain a verification result; specifically, the control unit is configured to send the calculation information in the BIOS firmware to the password engine unit when the verification result matches a preset second result.
[0011] In the above implementation process, by first verifying the certificate carried in the BIOS firmware, the calculation information in the BIOS firmware is verified only after the verification is passed. In this way, through the dual verification of the certificate and the calculation information, the forgery difficulty of the BIOS firmware can be further increased, thereby further improving the security of the BIOS firmware update. In addition, in the above implementation solution, the password engine unit verifies the certificate in the trusted execution environment, that is, the algorithms for certificate verification and calculation of the calculation information both run in the trusted execution environment, thereby reducing the risk of the algorithm being stolen and further reducing the risk of the algorithm being specifically cracked, ensuring the security of information verification and improving the security of the BIOS firmware update.
[0012] Further, the control unit is further configured to, before sending the certificate to the password engine unit, send the public key of the certificate to the password engine unit through the security interface, so as to instruct the password engine unit to perform a hash calculation on the public key to obtain a unique identifier of the public key; specifically, the control unit is configured to send the certificate to the password engine unit when the unique identifier matches a preset identifier.
[0013] In the above implementation process, by first performing a hash calculation on the public key of the certificate to verify the legality of the public key of the certificate, and then further performing certificate verification when the public key is legal. In this way, on the one hand, the verification of the certificate can be realized based on the legal public key; on the other hand, through the triple verification of the public key, the certificate and the calculation information, the forgery difficulty of the BIOS firmware can be further increased, thereby further improving the security of the BIOS firmware update. In addition, in the above implementation solution, the password engine unit performs a hash calculation on the public key in the trusted execution environment, that is, the algorithms for public key hash calculation, certificate verification, and calculation of the calculation information all run in the trusted execution environment, thereby reducing the risk of each algorithm being stolen and further reducing the risk of the algorithm being specifically cracked, ensuring the security of information verification and improving the security of the BIOS firmware update.
[0014] Further, the BIOS firmware to be updated is the basic firmware and / or the system firmware; the basic firmware is the firmware running in the trusted execution environment, and when the basic firmware is executed, it is used to implement operations related to the microprocessor; the system firmware is the firmware running in the normal execution environment, and when the system firmware is executed, it is used to start the operating system.
[0015] In the above implementation process, the BIOS firmware is divided into two categories, namely basic firmware and system firmware, according to the implemented operations. Both types of BIOS firmware can be updated by the above method. In this way, when updating the BIOS firmware, different management and operations can be carried out according to the type of the BIOS firmware, different security performances can be achieved, and different security needs can be met. For example, the basic firmware implements operations related to the microprocessor. Once the basic firmware is tampered with, the resulting harm is often greater than that when the system firmware is tampered with. Therefore, when updating the BIOS firmware, the basic firmware can be burned into the storage area corresponding to the trusted execution environment in the BIOS flash memory to make it have higher security performance, while the system firmware is burned into the storage area corresponding to the normal execution environment in the BIOS flash memory to achieve differentiated management operations.
[0016] Further, when the BIOS firmware to be updated includes the basic firmware, the control unit is specifically configured to: burn the basic firmware into the storage area corresponding to the trusted execution environment in the BIOS flash memory under the highest running privilege.
[0017] It should be understood that the basic firmware implements operations related to the microprocessor. Once the basic firmware is tampered with, the resulting harm is often greater than that when the system firmware is tampered with. In the above implementation process, by configuring the control unit, the basic firmware can be burned into the storage area corresponding to the trusted execution environment in the BIOS flash memory only under the highest running privilege, which can effectively ensure the security of the basic firmware after writing, and also ensure the security of the system during the BIOS firmware update process.
[0018] Further, the control unit is further configured to: obtain the calculation result corresponding to the BIOS firmware information currently burned in the BIOS flash memory when the burning of the BIOS firmware to be updated ends; the control unit is further configured to: when the calculation result corresponding to the BIOS firmware information does not match the preset first result, re-burn the BIOS firmware to be updated into the BIOS flash memory.
[0019] In the above implementation process, when the burning of the BIOS firmware to be updated ends, the information of the currently burned BIOS firmware is calculated, and the calculation result is matched. When they do not match, the BIOS firmware to be updated is burned into the BIOS flash memory again. In this way, when the burning of the BIOS firmware to be updated fails, this situation can be captured, and thus the burning can be performed again to increase the probability that the BIOS firmware to be updated is successfully updated.
[0020] An embodiment of the present application also provides a BIOS firmware update method, which is applied to a microprocessor; the microprocessor includes a control unit, a cryptographic engine unit, and a BIOS flash memory, the microprocessor is equipped with a normal execution environment and a trusted execution environment, and the normal execution environment and the trusted execution environment perform information interaction through a security interface; the cryptographic engine unit runs in the trusted execution environment; the method includes: when the control unit obtains the BIOS firmware to be updated, through the security interface, sending the calculation information in the BIOS firmware to the cryptographic engine unit to instruct the cryptographic engine unit to perform a calculation based on the calculation information to obtain a calculation result; when the control unit determines that the calculation result matches a preset first result, burning the BIOS firmware into the BIOS flash memory.
[0021] In the above implementation process, through the calculation information in the BIOS firmware to be updated, the security verification of the BIOS firmware to be updated is realized, the security of the BIOS firmware update is improved, and thus the security of the computer device startup is improved. In addition, in the above implementation solution, the cryptographic engine unit performs the calculation on the calculation information in the trusted execution environment, that is, the algorithms used for verifying the BIOS firmware to be updated all run in the trusted execution environment, which reduces the risk of the algorithm being stolen, and thus reduces the risk of the algorithm being targeted and cracked, ensures the security of information verification, and further improves the security of the BIOS firmware update.
[0022] Further, the calculation information is the firmware information of the BIOS firmware; the calculation result is the hash value of the firmware information of the BIOS firmware; the preset first result is the hash value of the BIOS firmware carried in the BIOS firmware.
[0023] Further, before sending the calculation information in the BIOS firmware to the password engine unit, the method further includes: sending, by the control unit and the security interface, the certificate carried in the BIOS firmware to the password engine unit to instruct the password engine unit to verify the certificate and obtain a verification result; when it is determined by the control unit that the verification result matches a preset second result, performing the step of sending the calculation information in the BIOS firmware to the password engine unit.
[0024] Further, before sending the certificate carried in the BIOS firmware to the password engine unit, the method further includes: sending, by the control unit and the security interface, the public key of the certificate to the password engine unit to instruct the password engine unit to perform a hash calculation on the public key to obtain a unique identifier of the public key; when it is determined by the control unit that the unique identifier matches a preset identifier, performing the step of sending the certificate carried in the BIOS firmware to the password engine unit.
[0025] Further, the BIOS firmware to be updated is a base firmware and / or a system firmware; the base firmware is a firmware running in the trusted execution environment, and when the base firmware is executed, it is used to implement operations related to the microprocessor; the system firmware is a firmware running in the normal execution environment, and when the system firmware is executed, it is used to start an operating system.
[0026] Further, when the BIOS firmware to be updated includes the base firmware, burning the BIOS firmware into the BIOS flash memory includes: burning, by the control unit under the highest running privilege, the base firmware into the storage area corresponding to the trusted execution environment in the BIOS flash memory.
[0027] Further, the method further includes: when the burning of the BIOS firmware to be updated ends, obtaining, by the control unit, a calculation result corresponding to the BIOS firmware information currently burned into the BIOS flash memory; when it is determined by the control unit that the calculation result corresponding to the BIOS firmware information does not match the preset first result, burning the BIOS firmware to be updated into the BIOS flash memory again.
[0028] An embodiment of the present application further provides a computer device, including the foregoing microprocessor.
[0029] In an embodiment of the present application, a computer-readable storage medium is further provided. The computer-readable storage medium stores one or more instructions. When the one or more instructions are executed by one or more microprocessors, the microprocessors execute any one of the above BIOS firmware update methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0031] Figure 1 It is a schematic diagram of the basic structure of a microprocessor provided by an embodiment of the present application;
[0032] Figure 2 It is a schematic diagram of the architecture of a system software stack based on basic firmware provided by an embodiment of the present application;
[0033] Figure 3 It is a schematic diagram of a certain type of processor architecture provided by an embodiment of the present application;
[0034] Figure 4 It is a schematic flowchart of a BIOS firmware update method provided by an embodiment of the present application;
[0035] Figure 5 It is a schematic diagram of an architecture in an example solution provided by an embodiment of the present application;
[0036] Figure 6 It is a schematic diagram of a scenario where a server interacts with a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] The following will describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application.
[0038] Embodiment 1:
[0039] To reduce the update risk of BIOS firmware and improve the security when updating BIOS firmware, an embodiment of the present application provides a microprocessor and a BIOS firmware update method applied to the microprocessor.
[0040] It can be seen from Figure 1 shown that Figure 1The microprocessor provided by the embodiment of the present application is shown, including a control unit, a cryptographic engine unit, and a BIOS flash memory. In addition, the microprocessor is equipped with a normal execution environment and a trusted execution environment, and information interaction is carried out between the normal execution environment and the trusted execution environment through a security interface.
[0041] It should be noted that in the field of computers, certain types of processor architectures divide the processor hardware resources into two parts: the secure world (trusted execution environment) and the normal world (normal execution environment). When the processor runs in the trusted execution environment, it can access all hardware resources, but when the processor runs in the normal execution environment, it can only access the resources of the normal execution environment. Simply put, ordinary applications run in the normal execution environment, and applications with high security requirements run in the trusted execution environment.
[0042] In the embodiment of the present application, the microprocessor is also equipped with a normal execution environment and a trusted execution environment, and the cryptographic engine unit is set in the trusted execution environment.
[0043] In the embodiment of the present application, the control unit is used to send the calculation information in the BIOS firmware to the cryptographic engine unit through the security interface when obtaining the BIOS firmware to be updated, so as to instruct the cryptographic engine unit to perform calculations according to the calculation information and obtain a calculation result.
[0044] The control unit is also used to burn the BIOS firmware to be updated into the BIOS flash memory when the calculation result matches the preset first result.
[0045] It should be understood that in the embodiment of the present application, after the firmware sending side device issues the BIOS firmware to be updated, the BIOS firmware to be updated will be transferred to the control unit, so as to realize the acquisition of the BIOS firmware to be updated.
[0046] In the embodiment of the present application, the security interface can be an SMC (Secure Monitor Call) interface, so that information interaction is realized between the control unit and the cryptographic engine unit through the SMC interface.
[0047] Optionally, in the embodiment of the present application, the calculation information may be the firmware information of the BIOS firmware to be updated (including the code content of the BIOS firmware to be updated), and the calculation result may be the hash value of the firmware information of the BIOS firmware to be updated. Correspondingly, the preset first result is the hash value of the BIOS firmware carried in the BIOS firmware to be updated. In this way, by judging whether the two hash values match, it can be determined whether the firmware information has been tampered with, so as to realize the security verification of the BIOS firmware to be updated and improve the security of BIOS firmware update.
[0048] To calculate the hash value of the firmware information of the BIOS firmware to be updated, the password engine unit can execute a preset hash algorithm (such as SM3, SHA, MD4, MD5, etc.) to obtain a calculation result and return it to the control unit through a secure interface.
[0049] In the embodiment of the present application, the specific way to determine whether the calculation result matches the preset first result can be: determining whether the calculation result is equal to the preset first result, or whether the deviation between the calculation result and the preset first result is within a pre-set deviation range.
[0050] In the embodiment of the present application, the preset first result can be carried in the BIOS firmware to be updated.
[0051] Optionally, in a feasible implementation manner of the embodiment of the present application, the control unit is further configured to, before sending the calculation information in the BIOS firmware to the password engine unit, send the certificate carried in the BIOS firmware to the password engine unit through a secure interface to instruct the password engine unit to verify the certificate to obtain a verification result, and then, when the verification result matches the preset second result, send the calculation information in the BIOS firmware to the password engine unit.
[0052] In this way, through the dual verification of the certificate and the calculation information, the forgery difficulty of the BIOS firmware can be further increased, thereby further improving the security of the BIOS firmware update. In addition, the algorithms for certificate verification and the algorithms for calculating the calculation information both run in a trusted execution environment, thereby also reducing the risk of the two algorithms being stolen at the same time, further reducing the risk of the algorithms being targeted for cracking, ensuring the security of information verification, and improving the security of the BIOS firmware update.
[0053] It should be noted that the above method for determining whether the verification result matches the preset second result can be: determining whether the verification result is the same as the preset second result.
[0054] In the above feasible implementation manner, the preset second result is a result indicating successful verification.
[0055] In the above feasible implementation manner, the password engine unit can use signature verification algorithms such as SM2 and SHA to verify the signature of the certificate.
[0056] It should be understood that the certificate can be signed with a private key. At this time, the public key corresponding to the private key needs to be used for signature verification during the signature verification process. In an optional embodiment of the above feasible implementation manner, the public key can be pre-stored in the microprocessor, for example, stored in the efuse of the microprocessor (efuse is a one-time programmable memory and information will be written before the microprocessor leaves the factory).
[0057] In an alternative embodiment of the above feasible embodiments, the public key of the certificate may also be carried in the BIOS firmware to be updated. At this time, in order to further improve the security of BIOS firmware update, the control unit may also send the public key of the certificate to the cryptographic engine unit through a secure interface before sending the certificate to the cryptographic engine unit, so as to instruct the cryptographic engine unit to perform a hash calculation on the public key to obtain a unique identifier of the public key, and then send the certificate to the cryptographic engine unit when the unique identifier matches the preset identifier.
[0058] In this way, on the one hand, it can ensure the verification of the certificate based on a legitimate public key; on the other hand, it can also further improve the difficulty of forging the BIOS firmware through triple verification of the public key, certificate and calculation information, thereby further improving the security of BIOS firmware update. In addition, the algorithms for performing hash calculation of the public key, certificate verification, and calculation of calculation information all run in a trusted execution environment, thus also reducing the risk of the three algorithms being stolen simultaneously, further reducing the risk of the algorithms being specifically cracked, ensuring the security of information verification, and improving the security of BIOS firmware update.
[0059] In the above feasible embodiments, the unique identifier of the calculated public key may be the hash value of the public key, and the preset identifier may be a preset public key hash value. In this way, what is pre-saved is the public key hash value rather than the public key, thereby reducing the risk of public key loss on the computer device side.
[0060] In the above feasible embodiments, the cryptographic engine unit may use algorithms such as SM3, SHA, MD4, MD5, etc. to perform hash calculation on the public key.
[0061] It should be noted that the above method for determining whether the unique identifier of the public key matches the preset identifier may be: determining whether the unique identifier of the public key is the same as the preset identifier, or determining whether the deviation between the unique identifier of the public key and the preset identifier is within a pre-set deviation range.
[0062] In the above feasible embodiments, the public key of the certificate and the preset first result may be carried in the certificate. Thus, after the control unit obtains the BIOS firmware to be updated, it can parse the certificate to obtain the public key of the certificate and the preset first result.
[0063] In the embodiments of the present application, the firmware may be divided into three categories: a trusted root, a basic firmware, and a system firmware according to the operations implemented by the firmware. Please refer to Figure 2 as shown Figure 2A system software stack based on the basic firmware is shown, including three layers of firmware: the trusted root, the basic firmware, and the system firmware. Among them, the trusted root can be the trusted boot root built into the microprocessor, which is responsible for verifying the signature of the basic firmware. As other examples, the system software stack may not include this trusted root. The basic firmware is mainly used for the basic initialization of the microprocessor and provides related services. For example, the basic firmware can be used to implement initialization services, power management, recovery (such as image recovery Recover), RAS (Reliability, Availability, and Serviceability) analysis, security platform architecture support, security monitor, secure boot, SPM (Secure Partition Manager) scheduling, etc. In addition, the basic firmware is also responsible for loading the secure operating system running in the secure state, for example, the TEE (Trusted Execution Environment) OS. Depending on the application scenario, the system firmware can have two implementation methods, as Figure 2 shown, the system firmware can be implemented as a unified UEFI (Unified Extensible Firmware Interface) for desktops, servers and other fields, or can be implemented as a U-Boot (Universal Boot) for the embedded field. As Figure 2 shown, the system firmware runs in the normal execution environment. In addition, the basic firmware, the system firmware, and the operating system OS (or VM (Virtual Machine)) can communicate with the out-of-band control system (such as EC (Embedded Controller), BMC (Baseboard Management Controller), etc.). Simply put, the basic firmware is the firmware running in the trusted execution environment, and when the basic firmware is executed, it is used to implement operations related to the microprocessor; the system firmware is the firmware running in the normal execution environment, and when the system firmware is executed, it is used to start the operating system.
[0064] It should be noted that in a certain type of processor architecture, different operating permissions are assigned to different applications. For example Figure 3 shown in a certain type of processor architecture diagram, there are a total of 4 operating permissions from low to high, namely EL0 to EL3. The higher the operating permission, the more operations that can be executed and the more resources that can be called.
[0065] In the embodiment of the present application, considering that the basic firmware implements operations related to the microprocessor, which is equivalent to the "driver program" of the microprocessor. Once it is tampered with, the resulting harm is often greater than that caused by tampering with the system firmware. Therefore, in the embodiment of the present application, the basic firmware can be placed in the trusted execution environment and configured with the highest privilege, so that the general running privilege does not allow the burning of the basic firmware.
[0066] In this way, when the to-be-updated BIOS firmware obtained includes the basic firmware, in order to ensure the smooth burning of the to-be-updated BIOS firmware, the to-be-updated BIOS firmware belonging to the basic firmware can be burned into the storage area corresponding to the trusted execution environment in the BIOS flash memory under the highest running privilege.
[0067] It should be understood that the program for executing the burning of the to-be-updated BIOS firmware can be the basic firmware installed in the microprocessor responsible for firmware burning, and the basic firmware has the highest running privilege.
[0068] In the embodiment of the present application, if the to-be-updated BIOS firmware obtained includes the system firmware, the system firmware can be burned into the storage area corresponding to the normal execution environment in the BIOS flash memory. At this time, the program for executing the burning of the to-be-updated BIOS firmware can also be the basic firmware installed in the microprocessor responsible for firmware burning.
[0069] In the embodiment of the present application, if the to-be-updated BIOS firmware obtained includes both the basic firmware and the system firmware, the basic firmware can be burned into the storage area corresponding to the trusted execution environment in the BIOS flash memory, and the system firmware can be burned into the storage area corresponding to the normal execution environment in the BIOS flash memory, so as to realize the burning and updating of the to-be-updated BIOS firmware.
[0070] It should be understood that considering that in the process of burning the to-be-updated BIOS firmware, the burning may fail due to various factors. In order to improve the burning success rate of the to-be-updated BIOS firmware, in the embodiment of the present application, the control unit can also be used to obtain the calculation result corresponding to the BIOS firmware information currently burned in the BIOS flash memory when the burning of the to-be-updated BIOS firmware ends, and when the calculation result corresponding to the BIOS firmware information does not match the preset first result, re-burn the to-be-updated BIOS firmware into the BIOS flash memory. In this way, when the burning of the to-be-updated BIOS firmware fails, this situation can be captured, so that the burning can be performed again, and the probability of successfully burning the to-be-updated BIOS firmware can be improved.
[0071] It should be noted that in the embodiments of the present application, the threshold of the burn-in times can be preset in advance. If the number of consecutive burn-in failures for the BIOS firmware to be updated exceeds the set threshold of the number of times, it can be considered that there is a hardware problem with the BIOS flash memory (such as the memory being damaged, etc.). At this time, the re-burn-in of the BIOS firmware to be updated is stopped, and information indicating the update failure can also be fed back to prompt the user that there may be a hardware problem with the BIOS flash memory and it needs to be repaired.
[0072] It should be noted that the control unit described in the embodiments of the present application can be the kernel that runs the BIOS system in the microprocessor, and the cryptographic engine unit can be the cryptographic engine in the microprocessor.
[0073] It should be understood that in the embodiments of the present application, since the cryptographic engine unit runs in the trusted execution environment. In order to ensure that the control unit can reliably call the cryptographic engine unit, before the control unit sends the information to be calculated in the BIOS firmware to be updated (such as the calculation information, certificate, public key, etc. described above) to the cryptographic engine unit, the microprocessor can first adjust the running privilege of the control unit to the highest running privilege, so that the control unit runs in the feasible execution environment, and then calls the cryptographic engine unit through the secure interface to calculate the information to be calculated.
[0074] See Figure 4 as shown Figure 4 shows the BIOS firmware update method provided in the embodiments of the present application applied to the aforementioned microprocessor. This BIOS firmware update method is adapted to the functions of the control unit of the microprocessor described above, and includes:
[0075] S401: When the control unit obtains the BIOS firmware to be updated, send the calculation information in the BIOS firmware to the cryptographic engine unit through the secure interface to instruct the cryptographic engine unit to calculate according to the calculation information and obtain the calculation result.
[0076] S402: When it is determined by the control unit that the calculation result matches the preset first result, burn the BIOS firmware into the BIOS flash memory.
[0077] Among them, the calculation information can be the firmware information of the BIOS firmware to be updated; the calculation result can be the hash value of the firmware information of the BIOS firmware to be updated; the preset first result can be the BIOS firmware hash value carried in the BIOS firmware to be updated.
[0078] Optionally, before sending the calculation information in the BIOS firmware to be updated to the password engine unit, the BIOS firmware update method may further include: sending the certificate carried in the BIOS firmware to be updated to the password engine unit through the control unit and the security interface, so as to instruct the password engine unit to verify the certificate and obtain a verification result. Then, when it is determined through the control unit that the verification result matches a preset second result, execute the step of sending the calculation information in the BIOS firmware to be updated to the password engine unit.
[0079] Optionally, before sending the certificate carried in the BIOS firmware to be updated to the password engine unit, the BIOS firmware update method may further include: sending the public key of the certificate to the password engine unit through the control unit and the security interface, so as to instruct the password engine unit to perform a hash calculation on the public key to obtain a unique identifier of the public key. Then, when it is determined through the control unit that the unique identifier matches a preset identifier, execute the step of sending the certificate carried in the BIOS firmware to be updated to the password engine unit.
[0080] Optionally, the BIOS firmware to be updated may be a base firmware and / or a system firmware. The definitions of the base firmware and the system firmware are as described above.
[0081] Optionally, when the BIOS firmware to be updated includes the base firmware, the process of burning the BIOS firmware to be updated into the BIOS flash memory may include: burning the base firmware into the storage area corresponding to the trusted execution environment in the BIOS flash memory through the control unit under the highest operating privilege.
[0082] Optionally, the BIOS firmware update method may further include: when the burning of the BIOS firmware to be updated is completed, obtaining, through the control unit, the calculation result corresponding to the BIOS firmware information currently burned into the BIOS flash memory. Then, when it is determined through the control unit that the calculation result corresponding to the BIOS firmware information does not match a preset first result, burn the BIOS firmware to be updated into the BIOS flash memory again.
[0083] It should be understood that for the sake of brevity of description, some content that has been described in the previous introduction to the microprocessor will not be repeated in the part about the BIOS firmware update method, but the relevant content is equally applicable in the part about the BIOS firmware update method.
[0084] Next, for the convenience of better understanding the solution provided by the embodiments of the present application, taking the control unit as the kernel running the BIOS system in the microprocessor (hereinafter simply referred to as the BIOS kernel), the password engine unit as the password engine configured in the microprocessor, and the password engine can implement the SM2 algorithm and the SM3 algorithm as an example, the present application will be further illustrated by examples.
[0085] See Figure 5 As shown, the password engine is a component in the trusted execution environment, while the BIOS kernel normally runs in the ordinary execution environment and cannot directly access the password engine. However, it should be noted that during firmware update, the BIOS kernel will temporarily adjust the running privilege to EL3 and run in the trusted execution environment, and call the corresponding algorithm interface of the password engine (which belongs to the service in the basic firmware) through the SMC interface to implement the security verification before firmware update. In this example, the password engine adopts the SM2 algorithm and the SM3 algorithm. It should be noted that as Figure 5 shown, there can be two SMC interfaces labeled Hash and Verify in the BIOS kernel, and these two SMC interfaces are respectively used to implement the call to the SM3 algorithm interface and the SM2 algorithm interface of the password engine.
[0086] See Figure 6 As shown, the external firmware management server sends the BIOS firmware to be updated to the local computer device, and the BIOS firmware to be updated carries a certificate.
[0087] The BIOS kernel of the computer device parses the certificate to obtain a public key plaintext contained in the certificate and the hash value of the BIOS firmware to be updated.
[0088] The BIOS kernel passes the public key plaintext to the basic firmware in the trusted execution environment through the Hash interface. The basic firmware will call the SM3 algorithm interface of the password engine to calculate the hash value of the public key, and then pass the hash value back to the BIOS kernel through the SMC interface. The BIOS kernel compares this hash value with the HBK (Hash Of Secure Boot Public Key) in the efuse. If this hash value is equal to the HBK, the BIOS kernel will pass the certificate information to the basic firmware through the Verify interface. The basic firmware will call the SM2 algorithm interface of the password engine to verify the legality of the certificate with the verified public key plaintext, and then return a message indicating whether the verification is successful through the SMC interface.
[0089] If the verification is successful, the BIOS kernel extracts the hash value parsed from the certificate, and then passes the firmware information of the BIOS firmware to be updated to the basic firmware through the Hash interface. The basic firmware calls the SM3 algorithm interface of the password engine to calculate the hash value of the firmware information of the BIOS firmware to be updated, and then passes the hash value to the BIOS kernel through the SMC interface. The BIOS kernel compares whether the hash value in the certificate is equal to the hash value passed by the password engine. If they are equal, it is determined that the BIOS firmware to be updated is legal, and thus the BIOS firmware to be updated is burned into the BIOS flash memory. If any of the above verifications fails, the update is stopped.
[0090] It should be noted that during the process of burning the BIOS firmware to be updated into the BIOS flash memory, data may be incorrect, resulting in a failure in the update. Therefore, in the embodiment of the present application, at the end of each burn of the BIOS firmware to be updated, the BIOS firmware information currently burned into the BIOS flash memory is obtained and passed to the basic firmware in the trusted execution environment through the Hash interface. The basic firmware calls the SM3 algorithm interface of the password engine to calculate the hash value corresponding to the currently burned BIOS firmware information, and passes the hash value to the BIOS kernel through the SMC interface.
[0091] Then the BIOS kernel determines whether the hash value is consistent with the previously calculated hash value (or the hash value parsed from the certificate). If they are consistent, it is determined that the update is successful and the update is exited; if they are inconsistent, the BIOS firmware to be updated is burned into the BIOS flash memory again.
[0092] The above burning process is a process of repeated multiple times. In the embodiment of the present application, a threshold value of the number of times that can be burned is preset. If the number of consecutive burn failures for the BIOS firmware to be updated exceeds the set threshold value, it is determined that there is a hardware problem with the BIOS flash memory.
[0093] In the embodiment of the present application, a computer device is also provided, and the computer device includes the microprocessor described above.
[0094] It should be understood that the computer device may also have other components in addition to the above microprocessor, for example, it may also have components such as a memory, a communication bus, and a communication module. The computer device described in the embodiment of the present application may be a server, a host, a computer, a mobile terminal, etc., but is not limited thereto.
[0095] This embodiment also provides a computer-readable storage medium, such as a floppy disk, an optical disc, a hard disk, a flash memory, a USB flash drive, an SD (Secure Digital Memory Card) card, an MMC (Multimedia Card) card, etc. One or more instructions for implementing the above steps are stored in the computer-readable storage medium. When the one or more instructions are executed by one or more microprocessors, the microprocessors are caused to execute the BIOS firmware update method described above. Details are not described herein again.
[0096] Based on the microprocessor, BIOS firmware update method, computer device, and storage medium provided by the embodiments of the present application, before performing BIOS firmware update, it is possible to first implement security verification of the BIOS firmware, improving the security of BIOS firmware update, and thus improving the security of device startup. In addition, in the embodiments of the present application, the password engine unit performs information calculation and verification in the trusted execution environment, and the algorithms for verifying the BIOS firmware to be updated all run in the trusted execution environment. This reduces the risk of the algorithms being stolen, thereby reducing the risk of the algorithms being targeted for cracking, ensuring the security of information verification, and further improving the security of BIOS firmware update.
[0097] In the embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the communication connections shown or discussed with each other can be implemented through some communication interfaces, and the communication connections between the units can be electrical, mechanical, or other forms.
[0098] In addition, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0099] In this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.
[0100] In this article, "a plurality of" means two or more.
[0101] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A microprocessor, characterized in that, The microprocessor includes a control unit, a cryptographic engine unit, and a BIOS flash memory. The microprocessor is equipped with a normal execution environment and a trusted execution environment, and information interaction between the normal execution environment and the trusted execution environment is carried out through a security interface; the cryptographic engine unit is set in the trusted execution environment, the security interface is a secure monitor call SMC interface, and information interaction between the control unit and the cryptographic engine unit is achieved through the SMC interface; wherein: The control unit is configured to, when obtaining the BIOS firmware to be updated, send the calculation information in the BIOS firmware to the cryptographic engine unit through the SMC interface, so as to instruct the cryptographic engine unit to perform calculations according to the calculation information and obtain a calculation result; The control unit is further configured to, when the calculation result matches a preset first result, write the BIOS firmware to be updated into the BIOS flash memory; Specifically, when the BIOS firmware to be updated obtained by the control unit includes a basic firmware, the control unit writes the BIOS firmware to be updated belonging to the basic firmware into the storage area corresponding to the trusted execution environment in the BIOS flash memory under the highest operating privilege.
2. The microprocessor according to claim 1, characterized in that, The calculation information is the firmware information of the BIOS firmware; the calculation result is the hash value of the firmware information of the BIOS firmware; the preset first result is the hash value of the BIOS firmware carried in the BIOS firmware.
3. The microprocessor according to claim 1, wherein: Before sending the calculation information in the BIOS firmware to the cryptographic engine unit, the control unit further sends the certificate carried in the BIOS firmware to the cryptographic engine unit through the security interface, so as to instruct the cryptographic engine unit to verify the certificate and obtain a verification result; Specifically, when the verification result matches a preset second result, the control unit sends the calculation information in the BIOS firmware to the cryptographic engine unit.
4. The microprocessor according to claim 3, wherein: Before sending the certificate to the cryptographic engine unit, the control unit further sends the public key of the certificate to the cryptographic engine unit through the security interface, so as to instruct the cryptographic engine unit to perform a hash calculation on the public key and obtain a unique identifier of the public key; Specifically, when the unique identifier matches a preset identifier, the control unit sends the certificate to the cryptographic engine unit.
5. The microprocessor according to any one of claims 1 to 4, characterized in that The BIOS firmware to be updated is a basic firmware and / or a system firmware; The basic firmware is a firmware running in the trusted execution environment, and is used to implement operations related to the microprocessor when being executed; The system firmware is a firmware running in the normal execution environment, and is used to start an operating system when being executed.
6. The microprocessor according to any one of claims 1-4, wherein: The control unit is further configured to, when the burning of the BIOS firmware to be updated ends, obtain the calculation result corresponding to the BIOS firmware information currently burned in the BIOS flash memory; The control unit is further configured to, when the calculation result corresponding to the BIOS firmware information does not match the preset first result, re-burn the BIOS firmware to be updated into the BIOS flash memory.
7. A method for updating BIOS firmware, characterized in that, It is applied to a microprocessor; the microprocessor includes a control unit, a cryptographic engine unit, and a BIOS flash memory. The microprocessor is equipped with a normal execution environment and a trusted execution environment, and information interaction between the normal execution environment and the trusted execution environment is carried out through a security interface; The cryptographic engine unit runs in the trusted execution environment; The security interface is a security monitor call SMC interface; the method includes: When the control unit obtains the BIOS firmware to be updated, the calculation information in the BIOS firmware is sent to the cryptographic engine unit through the SMC interface to instruct the cryptographic engine unit to perform calculations based on the calculation information to obtain a calculation result; When the control unit determines that the calculation result matches the preset first result and the BIOS firmware to be updated includes the basic firmware, under the highest operation authority, the BIOS firmware to be updated belonging to the basic firmware is burned into the storage area corresponding to the trusted execution environment in the BIOS flash memory.
8. The BIOS firmware update method according to claim 7, wherein The calculation information is the firmware information of the BIOS firmware; the calculation result is the hash value of the firmware information of the BIOS firmware; the preset first result is the hash value of the BIOS firmware carried in the BIOS firmware.
9. The BIOS firmware update method according to claim 7, wherein Before sending the calculation information in the BIOS firmware to the cryptographic engine unit, the method further includes: The certificate carried in the BIOS firmware is sent to the cryptographic engine unit through the control unit and the security interface to instruct the cryptographic engine unit to verify the certificate to obtain a verification result; When the control unit determines that the verification result matches the preset second result, the step of sending the calculation information in the BIOS firmware to the cryptographic engine unit is executed.
10. The BIOS firmware update method according to claim 9, wherein Before sending the certificate carried in the BIOS firmware to the cryptographic engine unit, the method further includes: The public key of the certificate is sent to the cryptographic engine unit through the control unit and the security interface to instruct the cryptographic engine unit to perform a hash calculation on the public key to obtain the unique identifier of the public key; When the control unit determines that the unique identifier matches the preset identifier, the step of sending the certificate carried in the BIOS firmware to the cryptographic engine unit is executed.
11. The BIOS firmware update method according to any one of claims 7-10, characterized in that, The BIOS firmware to be updated is basic firmware and / or system firmware; The basic firmware is the firmware running in the trusted execution environment, and when the basic firmware is executed, it is used to implement operations related to the microprocessor; The system firmware is the firmware running in the general execution environment, and when executed, the system firmware is used to start the operating system.
12. The BIOS firmware update method according to any one of claims 7 to 10, characterized in that, The method further includes: At the end of the burning of the BIOS firmware to be updated, obtain, by the control unit, the calculation result corresponding to the currently burned BIOS firmware information in the BIOS flash memory; When it is determined by the control unit that the calculation result corresponding to the BIOS firmware information does not match the preset first result, rewrite the BIOS firmware to be updated into the BIOS flash memory again.
13. A computer device, characterized in that, It includes: The microprocessor according to any one of claims 1-6.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores one or more instructions, and when the one or more instructions are executed by one or more microprocessors, the microprocessors are caused to execute the BIOS firmware update method according to any one of claims 7-12.
Citation Information
Patent Citations
Data processing method and electronic equipment
CN104915591A
UEFI BIOS upgrading method and system and related device
CN110018841A
Method and device for quickly and safely starting embedded system and electronic equipment
CN113946375A