A Mobile Terminal Secure Boot Method with an Updatable Trust Root

By storing security startup code on writable media and using write protection, the method addresses inflexible trust root changes, ensuring secure and adaptable security updates with minimal performance impact.

CN115828252BActive Publication Date: 2025-07-15INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211235146.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-10
Publication Date
2025-07-15
Estimated Expiration
2042-10-10

AI Technical Summary

Technical Problem

The existing mobile terminal secure boot solution cannot flexibly update the algorithms and mirror verification logic used for secure boot, and the trust root is configured as a one-time operation, which cannot meet the flexible configuration needs of different owners.

Method used

Store the code of the secure boot system into the boot partition of the read-write storage medium. Using the Power-on write protection function of the storage device, configure the secure boot partition to read-only before starting to achieve protection of itself, and flexibly replace the trust root through the delivery update mechanism to ensure trusted updates of the secure boot system.

Benefits of technology

It realizes flexible updates of secure startup-related password algorithms and trust root data, ensuring that the mobile terminal safely starts its own published operating system between different owners, prevents attackers from tampering with it, and meets flexible configuration requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115828252B_ABST
    Figure CN115828252B_ABST
Patent Text Reader

Abstract

The present invention discloses a mobile terminal secure boot method with an updatable trust root. The steps include: 1) storing the code of the secure boot system in the boot partition that is first started in the readable and writable storage medium of the mobile terminal, and storing the boot loader in other boot partitions of the readable and writable storage medium; setting a system partition for storing the operating system image and a secure boot auxiliary partition for storing control information in the data area of the medium; 2) by configuring the boot options of the mobile terminal, enabling the mobile terminal to read the relevant code of the secure boot system from the medium and execute it; the secure boot system determines whether to update the trust root of the mobile terminal according to the control information; if an update is required, after completing the trust root update, proceed to step 3); if an update is not required, directly proceed to step 3); 3) setting the partition where the secure boot system is located to read-only, performing integrity verification on the operating system image to be started, and starting the boot loader to complete system startup.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a mobile terminal security startup method capable of updating a trusted root, and belongs to the technical field of mobile terminal security. Background Art

[0002] With the development of the Internet of Things and smart devices, mobile terminals are becoming more and more popular. Many sensitive businesses are running on mobile terminals, such as mobile payment, personal health data collection, sensitive file processing, etc., involving a large amount of sensitive data. If the mobile terminal does not properly protect the above data, it will lead to data leakage, resulting in economic losses and other adverse consequences.

[0003] To protect the security of sensitive data, the mobile terminal must first ensure the security of its own operating system. If an attacker destroys the integrity of the operating system and obtains administrator privileges, the security of the sensitive data carried by the operating system will naturally be out of the question. Secure boot is one of the common operating system integrity protection schemes. The key of the secure boot system usually consists of a public-private key pair, in which the private key is held by the device manufacturer and the public key is stored on the mobile terminal as a trust root. When releasing the operating system image, the device manufacturer will use the private key it holds to sign the hash value of the image file and publish the signature value together with the operating system image. Before the mobile terminal loads and starts the operating system, the secure boot system will use the trust root stored in the terminal to verify the signature value of the operating system image to be loaded. Only when the signature verification passes, the operating system is allowed to start.

[0004] Existing secure boot solutions are usually provided by processor chip manufacturers of mobile terminals, in which the code part is usually solidified in the read-only storage area of the processor, and the trusted root data used is usually stored in the electronic fuse (eFuse). Although the above combination has good security, it has many inconveniences for mobile terminal manufacturers and users. First, after the processor manufacturer completes chip manufacturing, the mobile terminal manufacturer and user cannot make any modifications to the cryptographic algorithm and image verification logic implemented by it; secondly, although the mobile terminal manufacturer and user can configure the trusted root by burning the eFuse, because the eFuse can only be written once, the configuration of the trusted root is a one-time operation, which cannot meet the needs of flexible configuration. Summary of the invention

[0005] Aiming at the technical problems existing in the prior art, the purpose of the present invention is to provide a mobile terminal secure boot method with an updatable trust root, which can realize the upgrade of the algorithms and mirror verification logics used in secure boot, and can flexibly replace data such as trust roots required for mirror verification according to different users of the mobile terminal. The secure boot solution implemented based on the writable storage medium in the present invention can obtain better flexibility; through the verification of the written data and a controllable upgrade, it is possible to prevent attackers from tampering with the content in the writable storage medium, achieving security similar to that based on read-only storage.

[0006] Secure boot can ensure that the system started by the intelligent terminal is trustworthy. To achieve this goal, two functions need to be completed:

[0007] 1. Ensure that secure boot runs first after the intelligent terminal is powered on, so that secure boot can verify other system images.

[0008] 2. Ensure that the secure boot system cannot be tampered with. After the secure boot completes the verification of the system image, it will exit by itself. At this time, it is necessary to ensure that the relevant code data of the secure boot is not tampered with, otherwise the secure boot will fail due to being tampered with during the next startup.

[0009] In the system on chip (SoC) of a mobile phone, there is usually a read-only storage area. After the SoC is powered on, it will default to read the code from this area and execute it. The area storing this code is called BootROM. Traditional secure boot solutions are usually implemented based on BootROM, that is, by placing the code in BootROM, the above two functions can be satisfied. BootROM will select the next storage device correspondingly through a dip switch or other configurations. After the selection is completed, BootROM will read the code data from the agreed position (usually the startup partition) of the selected storage device and execute it.

[0010] The main idea of this patent is to abandon the manufacturer-built-in secure boot mechanism in BootROM and move it to the storage device. Because after the storage device is configured, the mobile terminal will execute the code from the agreed position of the storage device. Just place the secure boot code at this position to achieve that the secure boot code is started first.

[0011] At the same time, existing storage devices usually have a write protection function to protect a part of the data from being tampered with. Specifically, storage devices usually have a Power-on write protection function, that is, during a single power-on startup process of a mobile terminal, a certain data area can be set to read-only once, and before the device is restarted, the read-only state of this area cannot be modified again. After restarting, the write protection of this area will be lifted. With this feature, the secure boot system implemented in this patent will start the write protection of itself before exiting the operation to prevent itself from being tampered with.

[0012] Traditional secure boot systems are implemented based on read-only BootROMs and cannot be updated. In this invention, the write protection of the secure boot system is implemented based on Power-on write protection. Before the secure boot system enables write protection, it will update itself. How to perform trusted updates in an orderly manner is another important part of this invention.

[0013] The technical solution of this invention:

[0014] On the one hand, this invention provides a method for secure boot of a mobile terminal with an updatable trust root, including:

[0015] 1) Store the code of the secure boot system in the startup partition that is first started in the readable and writable storage medium in the mobile terminal, which is called the secure boot partition; store the boot loader BootLoader in other startup partitions of the readable and writable storage medium; set a secure boot auxiliary partition and a system partition in the data area of the readable and writable storage medium, where the secure boot auxiliary partition is used to store control information sent by users, and the system partition is used to store the operating system image of the mobile terminal.

[0016] 2) Configure the startup options of the mobile terminal through a DIP switch or the like, so as to ensure that the mobile terminal will read the relevant code of the secure boot system of the mobile terminal from the specified readable and writable storage medium and execute it; the DIP switch is usually directly connected to the pins of the SoC. It can be configured which storage device the SoC reads the system image from and starts. Usually, the DIP switch can configure the storage device, and the SoC will read the system image from a fixed partition (such as the startup partition) of the specified storage device.

[0017] 3) After the secure boot system is executed, it will load the operating system image from the readable and writable storage medium into the memory and perform integrity verification on the operating system image to be started.

[0018] 4) In order to protect itself, the secure boot system needs to configure the storage device and set the storage partition where it is located to read-only before starting the operating system.

[0019] Further, step 2) includes:

[0020] 2.1) Loading the secure boot system: After the mobile terminal is powered on, the processor loads data such as the code to be executed from the fixed storage partition location of the storage device into the memory and executes it. By storing the code related to the secure boot system in the above storage partition, it is possible to execute the secure boot system first after the mobile terminal is started;

[0021] 2.2) Loading the operating system image: The secure boot system will perform a preliminary initialization of the peripherals of the mobile terminal, and then load the operating system image from the storage device into the memory;

[0022] 2.3) Verifying the integrity of the operating system image: The secure boot system uses a hash algorithm to calculate the hash value of the operating system image located in the memory, and further uses the root of trust to verify the integrity of the image. The root of trust is a public key, and the public-private key pair is generated by the device manufacturer and the public key is written into the mobile terminal as the root of trust.

[0023] On the other hand, the present invention provides a transfer update and upgrade mechanism for a trusted secure boot algorithm and data such as the root of trust. The secure boot system first determines whether to update the root of trust of the mobile terminal according to the control information of the secure boot auxiliary partition; if an update is required, step 3) is performed after the root of trust is updated; if no update is required, step 3) is directly performed.

[0024] The method for updating the root of trust is as follows: The secure boot system uses the root of trust to verify the signature of the system image to be started. The root of trust determines that the mobile terminal can only start the system image signed by the holder of the private key of the root of trust. Therefore, after the owner of the mobile terminal changes, the root of trust needs to be changed at the same time. In order to achieve controllable change of the root of trust and prevent attackers from launching attacks during the root of trust change process, the present invention uses a transfer update and upgrade mechanism. That is, the current owner of the mobile terminal endorses the next owner. When the ownership of the mobile terminal is transferred, the owner needs to use the private key of the root of trust he holds to sign the root of trust of the next owner, so that the mobile terminal can verify that the root of trust to be updated is trustworthy. After the verification passes, the data such as the algorithm and the root of trust currently stored will be updated. Through the transfer update method, the transfer of the control right of the mobile terminal is realized. That is, different owners can deploy their own algorithms and roots of trust, so as to securely start the operating systems they release.

[0025] The present invention also provides a mobile terminal, which is characterized in that it includes a readable and writable storage medium, and a boot partition and a data area are provided on the readable and writable storage medium; the partition that is first started in the boot partition is called the secure boot partition, which is used to store the code of the secure boot system, and the other partitions in the boot partition are used to store the boot loader BootLoader; the data area is provided with a system boot partition and a secure boot auxiliary partition, the secure boot auxiliary partition is used to store control information sent by the user, and the system boot partition is used to store the operating system image of the mobile terminal; by configuring the boot options of the mobile terminal, the mobile terminal reads the relevant code of the secure boot system from the readable and writable storage medium and executes it; the secure boot system first determines whether to update the trust root of the mobile terminal according to the control information in the secure boot auxiliary partition. If an update is required, after completing the trust root update, the secure boot partition is set to read-only, and then the integrity verification of the operating system image to be started is performed; if no update is required, the secure boot partition is directly set to read-only, and then the integrity verification of the operating system image to be started is performed.

[0026] Compared with the prior art, the beneficial effects of the present invention are:

[0027] While realizing the functions of the traditional solution, the updatable secure boot solution and system of the present invention realize the flexible update of data such as relevant cryptographic algorithms and trust roots for secure boot. When the owner of the mobile terminal changes, a secure boot solution and data held by the new owner can be deployed, solving the problem of trust root change when the mobile terminal is held by different owners. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 It is a general architecture diagram of a secure boot solution with an updatable trust root provided by the present invention.

[0029] Figure 2 It is a storage partition diagram of a secure boot solution with an updatable trust root provided by the present invention;

[0030] (a) eMMC storage partition without deploying the secure boot system,

[0031] (b) eMMC storage partition after deploying the secure boot system.

[0032] Figure 3 It is a flowchart of the execution of a secure boot solution with an updatable trust root provided by the present invention.

[0033] Figure 4 It is a schematic diagram of a transfer update mechanism provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0034] To make the objectives, technical solutions and advantages of the present invention more clearly understood, the following examples are provided with reference to the accompanying drawings for further detailed description of the present invention. It should be understood that the specific examples described herein are only used to explain the present invention and are not used to limit the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several changes and improvements can still be made, and these all fall within the protection scope of the present invention.

[0035] Please refer to Figure 1 , an embodiment of the present invention provides an updatable secure boot system, which realizes the updatable secure boot system by virtue of the write protection feature of an embedded multimedia card (eMMC) storage device. Among them:

[0036] According to whether the storage partition where the secure boot system is located is configured with write protection after the mobile terminal is started, the device is defined as locked and unlocked states. In the locked state, the operating system of the mobile terminal cannot modify the configuration of the secure boot system. At this time, the device can only start the operating system image verified by the secure boot system.

[0037] In the present invention, the operating system image run by the mobile terminal is provided by the device owner and signed with the private key held by the owner. Subsequently, the device owner writes a lock command, a trust root file used for secure boot system verification, etc. and the signatures of the above files to the secure boot auxiliary partition through the operating system of the mobile terminal. The secure boot system will verify the above files and configure its own implementation located in the write protection partition according to the relevant information. After the configuration is completed, the write protection of the secure boot system will be started, and the device will be in the locked state. Before the owner of the device unlocks the device with the private key, other commands attempting to change the locked state of the device will be rejected.

[0038] Please refer to Figure 2 , the present invention adjusts the original eMMC device partition and adds a partition for storing the secure boot system. Among them, the secure boot system is located in the eMMC boot partition and is write-protected; the secure boot auxiliary partition is located in the eMMC data partition and can be read and written arbitrarily. The secure boot system implements the verification logic, related algorithms and data required for secure boot of the mobile terminal, such as RSA, SHA-256, SM2, SM3, etc. The secure boot auxiliary partition stores the control information sent by the owner, and its credibility and integrity are signed by the owner.

[0039] Please refer to Figure 3 and Figure 4 , an embodiment of the present invention provides a method for implementing an updatable secure boot system, which is characterized by including the following steps:

[0040] (1) Read the control command sent by the owner from the secure boot auxiliary partition: To reduce the trusted computing base of the secure boot system, which does not include components required for network communication, etc., but instead the operating system communicates with the remote administrator on its behalf and uses the secure boot auxiliary partition to transfer to the secure boot system.

[0041] (2) Perform different processing according to different states and commands of the device: To record the current state of the mobile terminal, the secure boot system maintains a total of 4 variables, namely whether it is locked, the root key, the encryption algorithm library, and the unlock random number. Among them, "whether it is locked" records whether the current mobile terminal is in a locked state; "the root key" stores the trust root used by the current mobile terminal; "the encryption algorithm library" stores the cryptographic algorithm used by the current mobile terminal to verify the system image; "the unlock random number" is mainly used to prevent replay attacks during unlocking.

[0042] The secure boot system will first attempt to read the remote control command from the secure boot auxiliary partition. If there is no control command, it will determine whether to verify the operating system image to be started according to the locked state of the current system, that is, the value of the "whether it is locked" variable; if there is a control command, it will verify the control command using the trust root stored in the "root key" and perform corresponding locking / unlocking operations on the device according to the command. In the locked state, before each time the secure boot system starts the operating system image, it will configure the write protection of the partition where the secure boot system is located, so as to ensure that the secure boot system cannot be tampered with.

[0043] In the case of the present invention, loading the secure boot system and verifying and signing the operating system image may cause performance loss. The experimental content is to test the loading and execution performance of the secure boot system in the above two scenarios. To reduce experimental errors, each test experiment will be iterated 500 times and then the average value will be taken as the final experimental result.

[0044] (1) Secure boot system loading time test experiment: The experimental content is the time consumed by the secure boot system during initialization by the processor chip, and the test results are shown in Table 1.

[0045] Table 1 Test results of secure boot system loading time

[0046]

[0047]

[0048] (2) Operating system image verification time test experiment: The experimental content is the time consumed by the secure boot system to verify the operating system image, and the test results are shown in Table 2.

[0049] Table 2 Test results of operating system image verification time

[0050] Operating system image size 128KB 256KB 512KB 1MB 2MB 4MB Time 1.75ms 3.41ms 6.74ms 13.40ms 26.70ms 53.33ms

[0051] The above experiments show that the present invention only brings a very small performance overhead to the loading and execution of the operating system, and the above overhead is only generated once when the mobile terminal starts, and will not affect the execution of the mobile terminal after startup.

[0052] The above is only one embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the scope of protection of the present invention.

Claims

1. A method for secure boot of a mobile terminal with an updatable trust root, the steps of which include: 1) Store the code of the secure boot system in the boot partition that is first started in the readable and writable storage medium of the mobile terminal, which is called the secure boot partition; Store the boot loader BootLoader in other boot partitions of the readable and writable storage medium; Set up a system boot partition and a secure boot auxiliary partition in the data area of the readable and writable storage medium. The secure boot auxiliary partition is used to store control information sent by the user, and the system boot partition is used to store the operating system image of the mobile terminal; 2) By configuring the boot options of the mobile terminal, make the mobile terminal read and execute the relevant code of the secure boot system from the readable and writable storage medium; the secure boot system determines whether to update the trust root of the mobile terminal according to the control information in the secure boot auxiliary partition; If an update is required, proceed to step 3) after completing the trust root update; If no update is required, directly proceed to step 3); 3) The secure boot system sets the secure boot partition to read-only and then starts the boot loader BootLoader, and loads the operating system image from the system boot partition into the memory; Then the secure boot system performs an integrity verification on the operating system image to be started; 4) When the ownership of the mobile terminal is transferred, the original owner of the mobile terminal signs the new trust root set by the new owner using the trust root private key, and the new owner sends this new trust root to the secure boot auxiliary partition; after the mobile terminal verifies that the signature of the new trust root passes, update the algorithm and trust root currently stored in the secure boot system.

2. The method according to claim 1, wherein The secure boot system includes the verification logic, relevant algorithms, and data required for the secure boot of the mobile terminal.

3. The method according to claim 1, wherein The secure boot system uses the trust root to verify the signature of the system image to be started in order to verify the integrity of the image.

4. The method according to claim 1, characterized in that, Configure the boot options of the mobile terminal through the DIP switch on the mobile terminal.

5. The method according to claim 1, wherein The readable and writable storage medium is a readable and writable storage device with a write protection function.

6. A mobile terminal, characterized in that, It includes a readable and writable storage medium, and there are boot partitions and a data area on the readable and writable storage medium; the partition that is first started in the boot partitions is called the secure boot partition, which is used to store the code of the secure boot system; Another partition in the boot partitions is used to store the boot loader BootLoader; the data area sets up a system boot partition and a secure boot auxiliary partition. The secure boot auxiliary partition is used to store control information sent by the user, and the system boot partition is used to store the operating system image of the mobile terminal; By configuring the boot options of the mobile terminal, make the mobile terminal read and execute the relevant code of the secure boot system from the readable and writable storage medium; the secure boot system first determines whether to update the trust root of the mobile terminal according to the control information in the secure boot auxiliary partition. If an update is required, after completing the trust root update, set the secure boot partition to read-only, and then perform an integrity verification on the operating system image to be started; If no update is required, directly set the security boot partition to read-only, and then perform an integrity verification on the operating system image to be booted; when the ownership of the mobile terminal is transferred, the original owner of the mobile terminal signs the new trust root set by the new owner using the trust root private key, and the new owner sends the new trust root to the security boot auxiliary partition; after the mobile terminal verifies that the signature verification of the new trust root passes, update the algorithm and trust root currently stored in the security boot system.

Citation Information

Patent Citations

  • Method and system for verifying BIOS (basic input / output system) credibility

    CN107392032A

  • Trusted starting method and device for operating system, mobile terminal and storage medium

    CN112445537A