Trusted adjustment module, trusted adjustment method and terminal
Patent Information
- Application Number
- CN202211306973.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-25
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2042-10-25
AI Technical Summary
[0030] The trusted adjustment module, trusted adjustment method, and terminal provided in this invention embodiment include at least a main control board, a key unit, an external connection unit, an interface adjustment unit, and a light-emitting unit. The key unit is connected to the main control board through the external connection unit, and is also connected to the light-emitting unit and the interface adjustment unit. The interface adjustment unit is used to determine different link connection methods according to different types of motherboard devices. The light-emitting unit is used to illuminate an indicator light when the type of motherboard device matches the link connection method of the interface adjustment unit. For different designed motherboards, the link connection method of the trusted adjustment module can be changed by changing the jumper cap to suit different motherboards.
Smart Images

Figure CN115720139B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of circuit technology, and in particular to a reliable adjustment module, a reliable adjustment method, and a terminal. Background Technology
[0002] A Trusted Platform Module (TPM) is a device that can independently generate, encrypt, and decrypt keys for a computer's (PC's) hard drive, files, and external storage. It has its own independent processor and storage unit, capable of storing keys and signature data, and providing encryption and security authentication for the PC. The TPM security chip is both a key generator and a key management device, and also provides a unified programming interface. The key is the unique key to unlocking encrypted files. A key function of the TPM security chip is to strengthen key management. The chip generates, stores, and manages keys in hardware. The TPM security chip can store keys in non-volatile memory protected by the TPM controller. The hardware functions of the TPM include several features, including:
[0003] First, the keys for the TPM security chip are randomly generated in hardware and used for encryption and decryption within the system to securely store and transmit confidential information. Because the computation is centralized within the TPM security chip, it simultaneously improves both system performance and encryption capabilities compared to software-generated keys.
[0004] Secondly, the TPM security chip employs a special algorithm to verify the trustworthiness of the system's hardware and software. It monitors any changes to the computer's hardware and software, thereby preventing various hardware and software attacks.
[0005] Third, the TPM security chip also provides management and initialization functions, allowing authorized users to enable or disable the chip, reinitialize the chip, and perform other functions.
[0006] How to make the Trusted Platform Module applicable to different computers is an urgent problem to be solved. Summary of the Invention
[0007] In view of the above problems, embodiments of the present invention are proposed to provide a reliable adjustment module and reliable adjustment method that overcome or at least partially solve the above problems.
[0008] In a first aspect, embodiments of the present invention provide a trusted adjustment module, the trusted adjustment module including at least a main control board, a key unit, an external connection unit, an interface adjustment unit, and a light-emitting unit, the key unit being connected to the main control board through the external connection unit, and the key unit being connected to the light-emitting unit and the interface adjustment unit respectively;
[0009] The interface adjustment unit is used to determine different link connection methods according to different types of motherboard devices;
[0010] The light-emitting unit is used to illuminate the indicator light when the type of the motherboard device matches the link connection method of the interface adjustment unit.
[0011] Optionally, the interface adjustment unit includes at least a connecting plate and a jumper cap, the connecting plate including multiple pins.
[0012] Optionally, the sixth pin of the key unit is connected to the TPM_PWRDWN signal terminal of the main control board via a jumper cap.
[0013] Optionally, when the jumper cap is connected to the first and second pins of the connection board, the sixth pin of the key unit is connected to the first end of the first resistor, the second end of the first resistor is connected to the second pin of the connection board, and the first pin of the connection board is connected to the 3.3V power supply terminal.
[0014] When the jumper cap is connected to the second and third pins, the sixth pin of the key unit is connected to the first end of the first resistor, the second end of the first resistor is connected to the second pin of the connection board, and the third pin of the connection board is connected to ground through the second resistor.
[0015] Optionally, the seventh pin of the key unit can be connected to the TPM_PWRDWN signal terminal of the main control board via a jumper cap.
[0016] Optionally, when the jumper cap is connected to the second and third pins of the connection board, the seventh pin of the key unit is connected to the second pin of the connection board, and the third pin of the connection board is connected to the 3.3V power supply terminal through a third resistor;
[0017] When the jumper cap is connected to the first and second pins of the connection board, the seventh pin of the key unit is connected to the second pin of the connection board, and the first pin of the connection board is connected to ground through the fourth resistor.
[0018] Optionally, the key unit is an SLB 9665 TPM2.0 chip.
[0019] Secondly, embodiments of the present invention provide a reliable adjustment method, applied to the reliable adjustment module of the first aspect, the method comprising:
[0020] With the trusted adjustment module connected to the main control board device, verify the integrity of the current underlying firmware;
[0021] If the current underlying firmware is complete, then the integrity of the BIOS and operating system will be verified sequentially by the underlying firmware.
[0022] By changing the way the jump cap is connected, different keys can be generated to encrypt and decrypt the application module.
[0023] Optionally, when the jumper cap is connected to the first and second pins of the connection board, the pin of the reliable adjustment module is at a high level; when the jumper cap is connected to the second and third pins, the pin of the reliable adjustment module is at a low level.
[0024] Optionally, the step of generating different keys by changing the connection method of the jump cap to encrypt and decrypt the application module includes:
[0025] When version compatibility issues occur, adjustments are made through the jump cap of the trusted adjustment module;
[0026] When the jumper cap is connected to the second and third pins, the trusted adjustment module is used for TPM2.0 encryption;
[0027] When the jumper cap is connected to the first and second pins of the connection board, the trusted adjustment module is used for TPM1.2 encryption.
[0028] Thirdly, embodiments of the present invention provide a trusted adjustment terminal, including the trusted adjustment device described in the first aspect.
[0029] The embodiments of the present invention have the following advantages:
[0030] The trusted adjustment module, trusted adjustment method, and terminal provided in this invention embodiment include at least a main control board, a key unit, an external connection unit, an interface adjustment unit, and a light-emitting unit. The key unit is connected to the main control board through the external connection unit, and is also connected to the light-emitting unit and the interface adjustment unit. The interface adjustment unit is used to determine different link connection methods according to different types of motherboard devices. The light-emitting unit is used to illuminate an indicator light when the type of motherboard device matches the link connection method of the interface adjustment unit. For different designed motherboards, the link connection method of the trusted adjustment module can be changed by changing the jumper cap to suit different motherboards. Attached Figure Description
[0031] Figure 1 This is a structural block diagram of a reliable adjustment module embodiment of the present invention;
[0032] Figure 2 This is a connection diagram of the SLB 9665 TPM2.0 chip of the present invention;
[0033] Figure 3 This is a circuit diagram of the busbar of the present invention;
[0034] Figure 4 This is a front view of the jump cap and pin header of the present invention;
[0035] Figure 5 These are three views of the jump cap and pin header of the present invention;
[0036] Figure 6 This is a perspective view of the jump cap and pin header of the present invention. Detailed Implementation
[0037] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0038] One embodiment of the present invention provides a reliable adjustment module for adapting to different types of main control boards. (See reference...) Figure 1 The diagram shows a structural block diagram of a trusted adjustment module embodiment of the present invention. The trusted adjustment module includes at least a main control board 103, a key unit 101, an external connection unit 104, an interface adjustment unit 102, and a light-emitting unit 105. The key unit 101 is connected to the main control board 103 through the external connection unit 104, and the key unit 101 is connected to the light-emitting unit 105 and the interface adjustment unit 102 respectively.
[0039] The interface adjustment unit 102 is used to determine different link connection methods according to different types of motherboard devices;
[0040] The light-emitting unit 105 is used to illuminate the indicator light when the type of the motherboard device matches the link connection method of the interface adjustment unit.
[0041] Key unit 101 is used to generate keys to encrypt various applications.
[0042] The light-emitting unit can be an LED display light or other light-emitting object.
[0043] Main control board 103 is the main control board inside each computer.
[0044] Figure 4 This is a front view of the jump cap and pin header of the present invention, as shown below. Figure 4 As shown, optionally, the interface adjustment unit includes at least a connecting plate and a jumper cap, the connecting plate including multiple pins. The jumper cap is a device that allows switching between different states at different positions, for example... Figure 4 You can switch between left and right. Figure 5 These are three views of the jump cap and pin header of the present invention; Figure 6 This is a perspective view of the jump cap and pin header of the present invention.
[0045] like Figures 2-3As shown, optionally, the sixth pin of the key unit is connected to the TPM_PWRDWN signal terminal of the main control board via a jumper cap.
[0046] Optionally, when the jumper cap is connected to the first and second pins of the connection board, the sixth pin of the key unit is connected to the first end of the first resistor UR29, the second end of the first resistor is connected to the second pin of the connection board, and the first pin of the connection board is connected to the 3.3V power supply terminal through the resistor RL53.
[0047] When the jumper cap connects the second and third pins, the sixth pin of the key unit is connected to the first end of the first resistor UR29, the second end of the first resistor UR29 is connected to the second pin of the connection board, and the third pin of the connection board is connected to ground through the second resistor RL54.
[0048] Optionally, the seventh pin of the key unit can be connected to the signal terminal of the main control board via a jumper cap.
[0049] Optionally, when the jumper cap is connected to the second and third pins of the connection board, the seventh pin of the key unit is connected to the second pin of the connection board, and the third pin of the connection board is connected to the 3.3V power supply terminal through the third resistor RL51.
[0050] When the jump cap is connected to the first and second pins of the connection board, the seventh pin of the key unit is connected to the second pin of the connection board, and the first pin of the connection board is connected to ground through the fourth resistor RL52.
[0051] Specifically, TPM 1.2 has only one endorsement key, EK, which is pre-installed in the chip by the manufacturer at the factory. After takingowner, a unique storage root key SRK can be generated, thereby enabling the construction of a key storage system.
[0052] In TPM 2.0, the EK belongs to the privacy domain, and there can be multiple EKs that support different asymmetric algorithms; the SRK belongs to the security domain, and there can also be multiple SRKs that support different algorithms. In fact, all three control domains of TPM 2.0 support multiple keys and multiple algorithms.
[0053] Optionally, the key unit is an SLB 9665 TPM2.0 chip.
[0054] Specifically, the Trusted Platform Module (TPM) effectively protects the PC and prevents unauthorized access. Connecting to the TPM female connector on the PCB motherboard and confirming the LED lights up confirms successful connection. The SLB 9665 TPM2.0 chip's pin 6 GPIO is connected to the interface TPM_PWRDWN signal via a jumper. When the jumper is set to pins 1-2, the GPIO is high; conversely, pins 2-3 are low, allowing for different motherboard designs to meet specific requirements. For version compatibility issues, the external jumper on pin 7 of the SLB 9665 TPM2.0 chip can be used for adjustment. Setting it to pins 2-3 satisfies TPM2.0; otherwise, adjusting pins 1-2 downgrades to TPM1.2. This module can be enabled or disabled in the BIOS (by selecting SecurityChip in the Security tab).
[0055] Specifically, the SLB 9665 TPM2.0 chip's GPIO pin 6 is connected to the interface TPM_PWRDWN signal via a jumper. Pins 1-2 are externally pulled high because they are connected to +3.3VS. Pins 2-3 are externally pulled low because they are connected to ground. The GPIO can also be pulled high or low via BIOS modifications. However, because different motherboards have different GPIO states, the TPM_PWRDWN signal state (pins 1-2 high / pins 2-3 low) can only be confirmed through external hardware intervention.
[0056] This invention provides a reliable adjustment method applied to the aforementioned reliable adjustment module. The method includes:
[0057] With the trusted adjustment module connected to the main control board, verify the integrity of the current underlying firmware;
[0058] If the current underlying firmware is complete, then the underlying firmware will verify the integrity of the BIOS (Basic Input Output System) and the operating system in turn.
[0059] By changing the way the jump cap is connected, different keys can be generated to encrypt and decrypt the application module.
[0060] Optionally, when the jumper cap is connected to the first and second pins of the connection board, the pin of the reliable adjustment module is at a high level; when the jumper cap is connected to the second and third pins, the pin of the reliable adjustment module is at a low level.
[0061] Optionally, by changing the connection method of the jump cap, different keys can be generated to encrypt and decrypt the application module, including:
[0062] When version compatibility issues occur, adjustments are made through the jump cap of the trusted adjustment module;
[0063] When the jumper cap is connected to the second and third pins, the trusted adjustment module is used for TPM2.0 encryption;
[0064] When the jumper cap is connected to the first and second pins of the connection board, the trusted adjustment module is used for TPM1.2 encryption.
[0065] Specifically, the Trusted Platform Module first verifies the integrity of the current underlying firmware. It determines whether the bottom firmware, motherboard, and external modules are working properly by checking if the LEDs on the Trusted Platform Module light up.
[0066] If correct, the normal system initialization is completed, and then the underlying firmware verifies the integrity of the BIOS and the operating system in sequence. The verification of the integrity of the BIOS and the operating system is specifically as follows:
[0067] After entering the BIOS setup interface, click "Advanced," then click the "SETTINGS" option on the left, then select the "Security" option on the right, and then select the "Trusted Computing" option. Next, set "Security Device Support" to "Enabled" and save. Verify whether the motherboard BIOS has TPM functionality.
[0068] If correct, the operating system will run normally; otherwise, it will stop running. The TPM security chip's built-in encryption module generates various keys for the system, encrypting and decrypting application modules, and providing a secure communication interface to ensure the security of upper-layer application modules. By changing different pins using jumper caps, it achieves compatibility with different platforms.
[0069] Different platforms handle the (6) pin signal (TPM_PWRDWN) differently, with three different scenarios: 1. No device connected; 2. Grounded through a resistor; 3. Pulled up by voltage through a resistor. This design can achieve these three states using jumpers: no jumper means floating, pins 1-2 are pulled up, and pins 2-3 are grounded. These three state options offer different adaptability to different platforms.
[0070] The embodiments of the present invention have the following advantages:
[0071] The trusted adjustment module, trusted adjustment method, and terminal provided in this invention embodiment include at least a main control board, a key unit, an external connection unit, an interface adjustment unit, and a light-emitting unit. The key unit is connected to the main control board through the external connection unit, and is also connected to the light-emitting unit and the interface adjustment unit. The interface adjustment unit is used to determine different link connection methods according to different types of motherboard devices. The light-emitting unit is used to illuminate an indicator light when the type of motherboard device matches the link connection method of the interface adjustment unit. For different designed motherboards, the link connection method of the trusted adjustment module can be changed by changing the jumper cap to suit different motherboards.
[0072] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0073] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0074] Embodiments of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, electronic devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing electronic device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing electronic device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0075] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing electronic device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0076] These computer program instructions can also be loaded onto a computer or other programmable data processing electronic device to cause a series of operational steps to be performed on the computer or other programmable electronic device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable electronic device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0077] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.
[0078] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or electronic device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or electronic device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or electronic device that includes the element.
[0079] The above provides a detailed description of the reliable adjustment module and the reliable adjustment method provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A reliable adjustment module, characterized in that, The trusted adjustment module includes at least a main control board, a key unit, an external connection unit, an interface adjustment unit, and a light-emitting unit. The key unit is connected to the main control board through the external connection unit, and the key unit is connected to the light-emitting unit and the interface adjustment unit respectively. The interface adjustment unit is used to determine different link connection methods according to different types of motherboard devices; The light-emitting unit is used to illuminate the indicator light when the type of the motherboard device matches the link connection method of the interface adjustment unit; The interface adjustment unit includes at least a connecting plate and a jumper cap, and the connecting plate includes multiple pins; When the sixth pin of the key unit is connected to the TPM_PWRDWN signal terminal of the main control board via a jumper cap. When the jumper cap is connected to the first and second pins of the connection board, the sixth pin of the key unit is connected to the first end of the first resistor, the second end of the first resistor is connected to the second pin of the connection board, and the first pin of the connection board is connected to the 3.3V power supply terminal. When the jumper cap connects the second and third pins, the sixth pin of the key unit is connected to the first end of the first resistor, the second end of the first resistor is connected to the second pin of the connection board, and the third pin of the connection board is connected to ground through the second resistor.
2. The reliable adjustment module according to claim 1, characterized in that, The seventh pin of the key unit is connected to the TPM_PWRDWN signal terminal of the main control board via a jumper cap.
3. The reliable adjustment module according to claim 2, characterized in that, When the jumper cap is connected to the second and third pins of the connection board, the seventh pin of the key unit is connected to the second pin of the connection board, and the third pin of the connection board is connected to the 3.3V power supply terminal through the third resistor; When the jumper cap is connected to the first and second pins of the connection board, the seventh pin of the key unit is connected to the second pin of the connection board, and the first pin of the connection board is connected to ground through the fourth resistor.
4. A reliable adjustment method, characterized in that, Applied to the reliable adjustment module as described in any one of claims 1-3, the method includes: With the trusted adjustment module connected to the main control board device, verify the integrity of the current underlying firmware; If the current underlying firmware is complete, then the integrity of the BIOS and operating system will be verified sequentially by the underlying firmware. By changing the way the jump cap is connected, different keys can be generated to encrypt and decrypt the application module.
5. The reliable adjustment method according to claim 4, characterized in that, When the jumper cap is connected to the first and second pins of the connection board, the pin of the reliable adjustment module is at a high level; when the jumper cap is connected to the second and third pins, the pin of the reliable adjustment module is at a low level.
6. The reliable adjustment method according to claim 4, characterized in that, The method of generating different keys by changing the connection method of the jump cap to encrypt and decrypt the application module includes: When version compatibility issues occur, adjustments are made through the jump cap of the trusted adjustment module; When the jumper cap is connected to the second and third pins, the trusted adjustment module is used for TPM2.0 encryption; When the jumper cap is connected to the first and second pins of the connection board, the trusted adjustment module is used for TPM1.2 encryption.
7. A reliable adjustment terminal, characterized in that, Includes the trusted adjustment module as described in any one of claims 1-3.
Citation Information
Patent Citations
Compatible method, equipment of credible chip and usage method for equipment
CN103034812A
A system and method for secure boot of server
CN110109715A