A Trusted Boot Method and System Using an SD Card Based on Domestic Cryptographic Algorithms
By integrating domestic password algorithms and independent processors on the SD card, the security problem of low-end mobile terminal startup process is solved, and integrity and credibility is guaranteed, which is suitable for various mobile terminal platforms.
Patent Information
- Application Number
- CN202110441966.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-23
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-04-23
AI Technical Summary
During the startup process of existing mobile terminals, low-end platforms lack hardware trusted boot devices, which leads to insecure in the startup process. Common algorithms such as SHA-1 and RSA can be cracked, which cannot guarantee the integrity and security of the startup process.
The SD card is used as a trusted startup carrier, and the integrity value of the system image is calculated using the domestic password algorithm SM2 or SM3, and an independent processor is integrated into the SD card. Through the integrity verification module and the storage management module, the legality of the system image is ensured and tampered with avoidance.
It realizes trusted startup on low-end mobile terminals, ensures the integrity and security of system images, improves the credibility of the startup process, and is suitable for various mobile terminal platforms.
Smart Images

Figure CN115238274B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a trusted method and system for secure booting from an SD card based on domestic cryptographic algorithms, and belongs to the field of mobile terminal security. Background Art
[0002] With the rapid development of the mobile Internet and the increasing popularity of mobile terminals, more and more sensitive tasks begin to be executed on mobile terminals, such as mobile payment, data encryption / decryption, sending and receiving sensitive emails, etc. This poses extremely high requirements for the security of mobile devices, and the booting process is the foundation of everything for the mobile terminal operating system. Since any error or omission during the booting process may put the operating system into an unpredictable dangerous state, it is necessary to perform trusted verification during the booting process.
[0003] In order to better protect the booting process of mobile terminals, high-end mobile terminal platforms have integrated hardware trusted boot devices to ensure the security of booting. When the CPU loads the system boot program code, these devices perform trusted measurement on the boot program through algorithms such as SHA-1 or RSA to ensure its integrity, and the boot program gradually performs trusted measurement on the systems loaded later, thereby ensuring the security of the entire system booting. However, algorithms such as SHA-1 and RSA used in the current trusted booting process have been proven to be crackable by Chinese scientists, and at the same time, many relatively low-end mobile terminal platforms do not integrate hardware modules to ensure the security of the booting process. Summary of the Invention
[0004] Aiming at the problems existing in the booting and starting of the operating system on mobile terminal platforms, the present invention provides a trusted booting method and system using an SD card based on domestic cryptographic algorithms. By replacing the currently used algorithms with domestic cryptographic algorithms (such as SM2, SM3), problems that may be caused by signature algorithms can be avoided. At the same time, by using an independent processor with computing power in the SD card, integrity measurement can be performed on the system boot program when it is loaded from the low-end mobile terminal platform to the SD card without relying on dedicated hardware, ensuring the security of its booting process, thereby ensuring the security and trustworthiness of the booting process of the mobile terminal platform operating system, and having characteristics such as strong security and user-friendliness.
[0005] To solve the above technical problems, the present invention adopts the following technical solutions:
[0006] A trusted booting method using an SD card based on domestic cryptographic algorithms, comprising the following steps:
[0007] (1) Modify the BootLoader image according to the device hardware and operating system of the mobile terminal platform to make a system boot module image, which contains code for measuring the integrity of software images required for subsequent startup processes. The software images include the system boot module image and the operating system image; calculate the integrity value of the software image using a domestic cryptographic algorithm, and store the software image and its integrity value in the SD card;
[0008] (2) For a mobile terminal to perform a trusted startup, set the system startup location of the mobile terminal to the SD card;
[0009] (3) When the SD card receives a request from the system processor of the mobile terminal to load the system boot module image, calculate the integrity value of the system boot module image required by the system processor using a domestic cryptographic algorithm, and compare the calculated integrity value of the system boot module image with the integrity value of the system boot module image stored in the SD card to verify the legitimacy of the system boot module image stored in the SD card; if the two integrity values match, the verification passes and loading the system boot module image is allowed, otherwise an error message is returned to interrupt the startup process;
[0010] (4) Configure the environment required to start the system kernel of the mobile terminal through the system boot module image, calculate the integrity value of the operating system image to be loaded using a domestic cryptographic algorithm, and compare the calculated integrity value of the operating system image with the integrity value of the operating system image stored in the SD card to verify the legitimacy of the system image stored in the SD card; if the two integrity values match, the verification passes and loading the operating system image is allowed to complete the trusted startup of the operating system of the mobile terminal.
[0011] Further, the domestic cryptographic algorithm selects the SM2 or SM3 cryptographic algorithm.
[0012] Further, the integrity value of the operating system includes relevant information containing the integrity value at the signature header, and the relevant information includes a certificate containing the integrity value.
[0013] Further, for the ARM TrustZone extended platform, the software image in step 1) also includes a trusted execution environment system image; in step 4), the system boot module image also needs to calculate the integrity value of the trusted execution environment system image to be loaded, and compare the calculated integrity value of the trusted execution environment system image with the integrity value of the trusted execution environment system image stored in the SD card to verify the legitimacy of the trusted execution environment system image stored in the SD card; if the two integrity values match, the verification passes and loading the trusted execution environment system image is allowed, and the trusted execution environment system image takes over the loading of the operating system image to complete the trusted startup of the operating system of the mobile terminal.
[0014] Further, set the system startup location of the mobile terminal to the SD card by moving the jumper switch of the mobile terminal device hardware.
[0015] A trusted startup system using an SD card based on domestic cryptographic algorithms, comprising:
[0016] An integrity verification module, which is responsible for calculating the integrity value of the system boot module image required by the system processor using domestic cryptographic algorithms when the SD card receives a request from the system processor of the mobile terminal to load the system boot module image, and comparing the calculated integrity value of the system boot module image with the integrity value of the system boot module image stored in the SD card to verify the legitimacy of the system boot module image stored in the SD card.
[0017] The SD card storage management module is responsible for receiving a request from the system processor of the mobile terminal to load the system boot module image, judging the content read by the system processor according to the position where the data is read according to the request, responsible for reading the system boot module image and calling the integrity verification module, responsible for loading the system boot module image, and returning an error message and interrupting the startup process.
[0018] The system boot module, based on BootLoader, contains code for measuring the integrity of software images required for subsequent startup processes. The software images include the system boot module image and the operating system image; it is responsible for calculating the integrity value of the software image using domestic cryptographic algorithms and storing the software image and its integrity value in the SD card; it is responsible for configuring the environment required to start the system kernel of the mobile terminal, calculating the integrity value of the operating system image to be loaded using domestic cryptographic algorithms, comparing the calculated integrity value of the operating system image with the integrity value of the operating system image stored in the SD card to verify the legitimacy of the system image stored in the SD card; and it is responsible for loading the operating system image.
[0019] Further, for the ARM TrustZone expansion platform, the system boot module is responsible for calculating the integrity value of the trusted execution environment system image stored in the SD card using domestic cryptographic algorithms, verifying the legitimacy of the integrity value of the trusted execution environment system image stored in the SD card, and is responsible for loading the trusted execution environment system image. The trusted execution environment system image takes over the loading of the operating system image to complete the trusted startup of the operating system of the mobile terminal. Description of the Drawings
[0020] Figure 1 It is a structural block diagram of a trusted startup system using an SD card based on domestic cryptographic algorithms provided by the present invention.
[0021] Figure 2The execution flowchart of a trusted startup using an SD card based on domestic cryptographic algorithms provided by the present invention. Detailed implementation manners
[0022] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the following takes examples with reference to the attached drawings to further elaborate on the present invention in detail. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of the present invention, several changes and improvements can be made, and these all fall within the protection scope of the present invention.
[0023] This embodiment provides a trusted startup system using an SD card based on domestic cryptographic algorithms, as Figure 1 shown, including a cryptographic algorithm module, an SD card storage management module, and a system boot module. Among them:
[0024] An integrity verification module, when the SD card receives a system processor of a mobile terminal's request to load the system boot module image, is responsible for using domestic cryptographic algorithms SM2 and SM3 to calculate the integrity value of the system boot module image required by the system processor, and comparing the calculated integrity value of the system boot module image with the integrity value of the system boot module image stored in the SD card to verify the legality of the system boot module image stored in the SD card. In this example, the integrity verification module utilizes the computing power of the SD card's FTL to perform integrity measurement on the system boot module image.
[0025] The SD card storage management module is responsible for receiving the request from the system processor to load the system boot module image. When receiving a read request from the system processor, it determines the content read by the system processor according to the position of the requested data. If it is the system boot module image, it calls the integrity verification module to calculate and compare the integrity value of the system boot module image, and then returns corresponding information to the system processor according to the returned result. If the integrity value verification passes, it allows the system processor to read the system boot module image, thereby starting the system. If the verification fails, it returns an error message, rejects the system processor from reading the tampered system boot module image, and interrupts the system startup process.
[0026] The system boot module, which is based on BootLoader, is responsible for completing all the basic functions of BootLoader after being loaded. It is responsible for using domestic cryptographic algorithms SM2 and SM3 to calculate the integrity value of the software image stored in the corresponding location, and comparing it with the integrity value stored in the system to verify the integrity of the loaded software image, so as to protect the software image required for system startup from being tampered with and protect the integrity of its code. The software images required for system startup include the system boot module image and the operating system image. For the ARM TrustZone extended platform, it also includes the trusted execution environment system image. When all the preparations for loading the next system image are completed and the next image is called, the system boot module verifies the integrity of the next image, or verifies the trusted execution environment system image on the platform extended with ARM TrustZone, that is, compares it with the integrity value stored in the image information header. If the verification passes, the subsequent kernel image is loaded. If the verification fails, an error message is returned to terminate the device startup, and the user is prompted that the operating system image has been tampered with. In this way, it can be ensured that the loaded image has not been tampered with and the security and trustworthiness of the started system are ensured.
[0027] This embodiment also provides a trusted startup method using an SD card based on domestic cryptographic algorithms, as Figure 2 shown, including the following steps:
[0028] (1) The device manufacturer or developer modifies the BootLoader image according to the system, adds code for measuring the integrity of the software images required for the subsequent startup process, makes the system boot module image, and calculates the integrity value of the image using the SM2 and SM3 cryptographic algorithms. The integrity values of the system boot module image and the operating system image are stored in specific locations on the used SD card according to the specific requirements of the specific platform for the subsequently loaded images.
[0029] (2) Set the system startup location to the manufactured SD card by adjusting the device hardware attributes (such as jumper switches, etc.).
[0030] (3) When the SD card receives a system processor read request, the SD card storage management module will determine whether the read location is the system boot module image. If so, it will call the integrity verification module to calculate the integrity value of the system boot module image required by the system processor and compare it with the integrity value stored in the SD card to verify the legality of the image.
[0031] (4) If the verification passes, the normal read process is executed, allowing the system processor to load the verified system boot module image. Otherwise, an error message is returned to interrupt the startup process.
[0032] After the system boot module is loaded, it is responsible for completing all the functions of the BootLoader, such as the environment configuration required to start the system kernel. Then, it measures the integrity of the system image to be loaded next, compares it with the signature header information of the image, and verifies the legitimacy of the image. In this example, the image to be loaded next can be the system kernel image, and its integrity value is signed by the developer's private key and attached to the image header.
[0033] (6) If the verification passes, the corresponding system kernel image is loaded to complete the system startup process and ensure the security and trustworthiness of the system startup.
[0034] The above is only one embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A trusted boot method using an SD card based on domestic cryptographic algorithms, characterized in that, Including the following steps: (1) Modify the BootLoader image according to the device hardware and operating system of the mobile terminal platform to make a system boot module image, which contains code for measuring the integrity of software images required for subsequent startup processes. The software images include the system boot module image and the operating system image; calculate the integrity value of the software image using a domestic cryptographic algorithm, and store the software image and its integrity value in the SD card; (2) For a mobile terminal to perform a trusted startup, set the system startup location of the mobile terminal to the SD card; (3) When the SD card receives a request from the system processor of the mobile terminal to load the system boot module image, calculate the integrity value of the system boot module image required by the system processor using a domestic cryptographic algorithm, and compare the calculated integrity value of the system boot module image with the integrity value of the system boot module image stored in the SD card to verify the legitimacy of the system boot module image stored in the SD card; if the two integrity values match, the verification passes and the system boot module image is allowed to be loaded, otherwise an error message is returned to interrupt the startup process; (4) Configure the environment required to start the system kernel of the mobile terminal through the system boot module image, calculate the integrity value of the operating system image to be loaded using a domestic cryptographic algorithm, and compare the calculated integrity value of the operating system image with the integrity value of the operating system image stored in the SD card to verify the legitimacy of the system image stored in the SD card; if the two integrity values match, the verification passes and the operating system image is allowed to be loaded to complete the trusted startup of the operating system of the mobile terminal.
2. The method according to claim 1, wherein The domestic cryptographic algorithm selects the SM2 or SM3 cryptographic algorithm.
3. The method according to claim 1, characterized in that The integrity value of the operating system includes relevant information containing the integrity value at the signature header, and this relevant information includes a certificate containing the integrity value.
4. The method according to claim 1, wherein For the ARM TrustZone extended platform, the software image described in step 1) also includes a trusted execution environment system image; in step 4), the system boot module image also needs to calculate the integrity value of the trusted execution environment system image to be loaded, and compare the calculated integrity value of the trusted execution environment system image with the integrity value of the trusted execution environment system image stored in the SD card to verify the legitimacy of the trusted execution environment system image stored in the SD card; if the two integrity values match, the verification passes and the trusted execution environment system image is allowed to be loaded, and the trusted execution environment system image takes over the loading of the operating system image to complete the trusted startup of the operating system of the mobile terminal.
5. The method according to claim 1, wherein Set the system startup location of the mobile terminal to the SD card through the jumper switch of the mobile terminal device hardware.
6. A trusted boot system using an SD card based on domestic cryptographic algorithms for implementing the method according to any one of claims 1-5, characterized in that, Including: An integrity verification module, which is responsible for calculating the integrity value of the system boot module image required by the system processor using a domestic cryptographic algorithm and comparing the calculated integrity value of the system boot module image with the integrity value of the system boot module image stored in the SD card to verify the legitimacy of the system boot module image stored in the SD card when the SD card receives a request from the system processor of the mobile terminal to load the system boot module image; The SD card storage management module is responsible for receiving the system processor's request in the mobile terminal to load the system boot module image, determining the content read by the system processor based on the requested data location, reading the system boot module image, invoking the integrity verification module, loading the system boot module image, and returning error messages and interrupting the startup process; The system boot module, based on BootLoader, contains code for integrity measurement of software images required for subsequent startup processes. The software images include the system boot module image and the operating system image; it is responsible for calculating the integrity value of the software image using domestic cryptographic algorithms and storing the software image and its integrity value in the SD card; it is responsible for configuring the environment required to start the system kernel of the mobile terminal, calculating the integrity value of the operating system image to be loaded using domestic cryptographic algorithms, comparing the calculated integrity value of the operating system image with the integrity value of the operating system image stored in the SD card to verify the legitimacy of the system image stored in the SD card; and it is responsible for loading the operating system image.
7. The system according to claim 6, wherein The integrity verification module utilizes the computing power of the SD card FTL to perform integrity calculation and legitimacy verification on the system boot module image.
8. The method according to claim 6, wherein For the ARM TrustZone extended platform, the system boot module is responsible for calculating the integrity value of the trusted execution environment system image stored in the SD card using domestic cryptographic algorithms, verifying the legitimacy of the integrity value of the trusted execution environment system image stored in the SD card, and loading the trusted execution environment system image. The trusted execution environment system image takes over the loading of the operating system image to complete the trusted startup of the operating system of the mobile terminal.
Citation Information
Patent Citations
Universal safe intelligent terminal starting method
CN104298913A
Manufacturing method of embedded Linux operating system starting SD card
CN105468425A