Computer target object verification method and device, storage medium and related apparatus

By embedding the processor's public key as a root of trust in the processor, and combining it with the computer's public key and version information for verification, the problem of inconvenient root of trust verification in existing technologies is solved, thus achieving convenience and security in the production of complete computer systems.

CN116244754BActive Publication Date: 2025-11-28HYGON INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211694160.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-28
Publication Date
2025-11-28
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

Existing methods that utilize the root of trust verification program or data set in the processor are inconvenient for computer implementation and pose a risk of the root of trust being tampered with or stolen.

Method used

The processor's public key is used as the root of trust and is fixed in the processor during the processor manufacturing stage. The computer's public key certificate is verified by signing with the processor's private key, and the target signature is verified using the computer's public key. Combined with the processor's identifier and version information, the accuracy and security of the verification are ensured.

Benefits of technology

This approach simplifies the computer manufacturing process by enabling the setting of a root of trust in the processor, improves the security of the root of trust, avoids the risk of the computer's private key being stolen or tampered with, and ensures the reliability and efficiency of verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116244754B_ABST
    Figure CN116244754B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a computer target object verification method, device, storage medium and related device. The computer target object verification method comprises: obtaining a public key signature, wherein the public key signature comprises a signature of a processor private key on a public key certificate, and the public key certificate comprises at least a computer public key; using a processor public key pre-configured in the processor to verify the public key signature; when the processor public key verifies the public key signature successfully, using the computer public key to verify a target signature, wherein the target signature is a signature of a computer private key on a target object; and when the computer public key verifies the target signature successfully, the target object is verified successfully. It can be seen that the computer target object verification method provided by the embodiments of the present application can be implemented by a computer while verifying the trusted root verification program or data in the processor.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of computer, in particular to a computer target object verification method and device, storage medium and related device. BACKGROUND

[0002] In order to ensure the security of the computer, it is necessary to verify whether some programs or data in the computer are maliciously tampered with. In order to achieve fast verification, one existing method is to use the root of trust set in the processor to verify the programs or data. The root of trust refers to the source and basis of trust, and the root of trust cannot and need not be verified.

[0003] However, the existing scheme of using the root of trust set in the processor to verify programs or software is not convenient for computer implementation.

[0004] Therefore, how to verify programs or data using the root of trust set in the processor while facilitating computer implementation has become a technical problem to be solved in the field. SUMMARY

[0005] Therefore, embodiments of the present application provide a computer target object verification method and device, storage medium and related device to facilitate computer implementation while verifying firmware and other programs or data using the root of trust set in the processor.

[0006] To achieve the above object, embodiments of the present application provide the following technical solutions.

[0007] In a first aspect, embodiments of the present application provide a computer target object verification method, comprising:

[0008] Obtaining a public key signature, the public key signature including a signature of a public key certificate by a processor private key, the public key certificate including at least a computer public key;

[0009] Verifying the public key signature using a processor public key pre-set in the processor;

[0010] When the verification of the public key signature by the processor public key is passed, verifying a target signature using the computer public key, the target signature being a signature of a target object by a computer private key;

[0011] When the verification of the target signature by the computer public key is passed, the target object is verified.

[0012] Optionally, the target object includes computer firmware; if the verification of the computer firmware is passed, a computer system corresponding to the computer public key is started.

[0013] Optionally, before the verification of the target signature using the computer public key, the method further comprises:

[0014] determining whether the computer identity corresponding to the computer public key is consistent with a processor identity pre-configured in the processor, the processor identity corresponding to the computer is the same as the computer identity corresponding to the computer public key of the computer;

[0015] when the computer identity is not consistent with the processor identity, the verification of the target object fails.

[0016] Optionally, the public key certificate further comprises the computer identity.

[0017] Optionally, before the verifying the target signature by using the computer public key, the method further comprises:

[0018] determining whether computer version information corresponding to the computer public key is greater than or equal to public key certificate version information pre-configured in the processor, the computer version information is adapted to represent the version of the corresponding computer public key;

[0019] when the computer version information is less than the public key certificate version information, the verification of the target object fails.

[0020] Optionally, the public key certificate further comprises the computer version information.

[0021] Optionally, the processor is configured with a one-time programmable storage circuit, and the one-time programmable storage circuit is used to pre-configure the processor identity and / or the public key certificate version information.

[0022] Optionally, the one-time programmable storage circuit supports bit-by-bit programming, and only the programmed data is read when the one-time programmable storage circuit is read.

[0023] In a second aspect, the embodiment of the present application further provides a computer target object verification device, comprising:

[0024] a public key signature obtaining unit adapted to obtain a public key signature, the public key signature comprising a signature of a processor private key on a public key certificate, the public key certificate comprising at least a computer public key;

[0025] a public key signature verifying unit adapted to verify the public key signature by using a processor public key pre-configured in the processor;

[0026] a target signature verifying unit adapted to verify a target signature by using the computer public key when the processor public key verifies the public key signature, the target signature being a signature of a computer private key on a target object; when the computer public key verifies the target signature, the verification of the target object passes.

[0027] Optionally, the target object comprises computer firmware; if the computer firmware is verified, a computer system corresponding to the computer public key is started.

[0028] Optionally, the method further comprises:

[0029] The identification judging unit is adapted to judge whether the computer identification corresponding to the computer public key is consistent with the processor identification pre-fixed in the processor before the target signature is verified by the target signature verifying unit using the computer public key, the processor identification corresponds to the computer one by one, and the processor identification corresponding to the computer is the same as the computer identification corresponding to the computer public key of the computer; when the computer identification is not consistent with the processor identification, the verification of the target object is not passed.

[0030] Optionally, the method further comprises:

[0031] The version information judging unit is adapted to judge whether the computer version information corresponding to the computer public key is greater than or equal to the public key certificate version information pre-fixed in the processor before the target signature is verified by the target signature verifying unit using the computer public key, the computer version information is adapted to represent the version of the corresponding computer public key; when the computer version information is less than the public key certificate version information, the verification of the target object is not passed.

[0032] In a third aspect, an embodiment of the present application further provides a storage medium, the storage medium stores a program to implement the computer target object verification method in the first aspect.

[0033] In a fourth aspect, an embodiment of the present application further provides a processor, comprising a processor public key hardware circuit, the processor public key hardware circuit is a hardware circuit integrated in the processor, and the processor public key is hard coded in the hardware circuit, and the processor public key hardware circuit is adapted to execute the computer target object verification method in the first aspect.

[0034] In a fifth aspect, an embodiment of the present application further provides an electronic device, comprising a memory, a mainboard and at least one processor on the mainboard, the mainboard stores the target object, the memory stores a program, and the processor calls the program to execute the computer target object verification method in the first aspect to verify the target object.

[0035] The computer target object verification method provided by the embodiment of the present application comprises: obtaining a public key signature, wherein the public key signature comprises a signature of a processor private key on a public key certificate, and the public key certificate comprises at least a computer public key; verifying the public key signature by using a processor public key which is previously fixed in the processor; when the verification of the public key signature by the processor public key is passed, verifying a target signature by using the computer public key, wherein the target signature is a signature of a computer private key on a target object; and when the verification of the target signature by the computer public key is passed, the target object is verified.

[0036] It can be understood that, in the production process of the computer device, the processor producer sets the processor public key as the root of trust in the production process of the processor, which is unchangeably set in the processor, so that different computer whole producers can verify the target object by using the root of trust by means of the public key signature signed by the processor private key without unchangeably writing the root of trust (for example, the computer public key) in the processor after obtaining the processor, thereby facilitating the implementation of the computer target object verification method.

[0037] It can be seen that, the computer target object verification method provided by the embodiment of the present application takes the processor public key as the root of trust, which is set in the processor by the processor producer in the production stage of the processor, and the computer whole producer can verify the target object based on the root of trust without writing the root of trust into the processor by using a specific tool after obtaining the processor, thereby facilitating the computer to implement while verifying the program or data of the root of trust set in the processor, and the processor private key is not stored in the computer, so that the processor private key has no risk of being stolen by malicious software in the running process of the computer, which is more secure, and avoids the dilemma that the computer public key and the computer private key need to be replaced after the computer private key is stolen or tampered, and the computer public key fixed in the processor as the root of trust cannot be replaced. BRIEF DESCRIPTION OF DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only belong to the embodiments of the present application, and for those skilled in the art, other drawings can be obtained without creative labor based on the provided drawings.

[0039] Figure 1 It is a schematic diagram of a computer target object verification method;

[0040] Figure 2 It is an implementation schematic diagram of the computer target object verification method provided by the embodiment of the present application;

[0041] Figure 3 A flow chart of a computer target object verification method provided by an embodiment of the present application;

[0042] Figure 4 Another flow chart of a computer target object verification method provided by an embodiment of the present application;

[0043] Figure 5 Another flow chart of a computer target object verification method provided by an embodiment of the present application;

[0044] Figure 6 A schematic diagram of a computer target object verification device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0045] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0046] For the convenience of understanding, first, a computer target object verification method is provided, please refer to Figure 1 , Figure 1 A schematic diagram of a computer target object verification method.

[0047] As shown in the figure, the processor includes a one-time programmable memory circuit (One Time Programmable Memory; OTP), which is a permanent storage space that can be programmed once but cannot be modified after programming. The computer first programs the computer public key in the one-time programmable memory circuit provided by the processor, and then uses the computer private key to sign the target object, so that the signature of the target object can be verified using the computer public key in the processor. When the verification is passed, it can be judged that the program or data has not been tampered with. In this way, by using the non-modifiability of the one-time programmable memory circuit, it can be ensured that the computer public key in the one-time programmable memory circuit of the processor will not be tampered with by malicious programs during the startup and running of the computer, so that the computer public key in the processor is used as the trust root. Wherein, the target object is a computer program or data verified by the trust root; the computer is the whole machine except the processor.

[0048] It can be seen that the implementation of the above computer target object verification method requires a one-time programmable storage circuit in the processor to provide an unburned state, and the computer writes the computer public key as a trust root into the one-time programmable storage circuit of the processor. The one-time programmable storage circuit needs to be burned by a special burning tool, and the process is complicated. Therefore, the above computer target object verification method is actually inconvenient to implement.

[0049] To solve the above technical problems, the embodiments of the present application provide a computer target object verification method, please refer to Figure 2 and Figure 3 , Figure 2 for the implementation schematic diagram of the computer target object verification method provided by the embodiments of the present application; Figure 3 for the flowchart of the computer target object verification method provided by the embodiments of the present application.

[0050] As Figure 3 shown, the computer target object verification method provided by the embodiments of the present application can include:

[0051] In step S11, a public key signature is obtained, and the public key signature includes a signature of a processor private key on a public key certificate.

[0052] The public key signature includes a signature of a processor private key on a public key certificate, and the public key certificate includes at least a computer public key. The computer public key is a public key belonging to a computer and corresponds to a computer private key also belonging to the computer. A computer has only one pair of computer public key and computer private key. The computer private key can be stored in a special signature server, which has the risk of being tampered with or stolen. Once the computer private key is tampered with or stolen, the computer needs to update the computer private key and the computer public key. The computer public key can be stored in the computer and can be sent to devices outside the computer.

[0053] In some embodiments, a pair of computer public key and computer private key is only owned by one computer, which can prevent the computer private key of other computers from being stolen to leak the computer private key of the computer, thereby improving the security of the computer private key. In other embodiments, a pair of computer public key and computer private key can be shared by multiple computers. Specifically, a pair of computer public key and computer private key can be shared by computers of the same model or computers produced by the same computer manufacturer. In this way, fewer computer private keys and computer public keys can be set to manage a large number of computers, thereby reducing the setting and management cost of computer private keys and computer public keys.

[0054] The processor private key is a private key belonging to the processor, and one processor has only one processor private key and one processor public key corresponding to the processor private key. The processor private key is not stored in the processor, and once the processor private key is tampered with or stolen, the computer needs to update the computer private key and the computer public key. The processor public key can be stored in the processor and cannot be sent to devices other than the processor or parts of the computer other than the processor.

[0055] In some embodiments, the processor private key can be uniquely controlled and kept by the processor producer producing the processor private key.

[0056] It is worth noting that the computer is a computer whole machine that can realize data processing and includes the processor, but because the computer private key cannot be obtained by the processor and the processor public key cannot be stored in the computer part other than the processor in the embodiments of the application, in order to facilitate understanding, it can be considered that the computer in the embodiments of the application is a computer whole machine that does not include the processor.

[0057] In some embodiments, a pair of processor public key and processor private key is only owned by one processor, which can prevent the processor private key from being stolen in other processors, causing the processor private key of the processor to be leaked, thereby improving the security of the processor private key; in other embodiments, a pair of processor public key and processor private key can be shared by multiple processors, specifically, processors of the same model or processors produced by the same processor producer can share a pair of processor public key and processor private key, so that fewer processor private keys and processor public keys can be set to manage a large number of processors, thereby reducing the setting and management cost of the processor private key and the processor public key.

[0058] The public key signature includes the signature of the processor private key on the public key certificate including the computer public key. Since the processor private key is controlled by the processor producer and is not stored in the processor or the computer, the processor producer needs to obtain the public key certificate including the computer public key in advance, so that the processor private key can be used to sign the public key certificate including the computer public key, and the public key certificate is returned to the computer sending the public key certificate after signing.

[0059] The processor private key signs the user public key. In some implementations, the processor private key can be used to perform an encryption operation on the public key certificate to obtain encrypted data, and the encrypted data is the public key signature; in other implementations, the digest of the public key certificate can be calculated by using a hash algorithm first, and then the digest of the public key certificate is encrypted by using the processor private key to obtain encrypted data, and the encrypted data is the public key signature.

[0060] The public key signature is stored in the computer, and specifically, can be stored in a flash chip of a mainboard of the computer.

[0061] In step S12, the public key signature is verified by a processor public key pre-installed in the processor.

[0062] Since the public key signature is a signature by the processor private key, the processor public key corresponding to the processor private key is needed to verify the public key signature. Since the processor public key is pre-installed in the processor and is difficult to be tampered by attackers such as malicious software, the processor public key is considered as a root of trust of the target object verification method provided by the embodiments of the present application. The root of trust refers to the source and basis of trust, and the root of trust cannot and need not be verified.

[0063] The verification can be decryption of the public key signature by the processor public key in the processor to obtain decryption data. In some embodiments, the decryption data can be a public key certificate, and when the decryption data is the same as the public key certificate corresponding to the public key signature, the verification passes. In other embodiments, the decryption data can be a digest of the user public key calculated by a hash algorithm, and then the computer can further calculate a digest of the public key certificate corresponding to the public key signature by the same hash algorithm, and when the digest is the same as the decryption data, the verification passes.

[0064] The public key certificate including the computer public key is stored in the computer and outside the processor, and in some embodiments, can be stored in the flash chip together with the public key signature. In this way, the public key certificate and the public key signature can be automatically read from the flash chip in the start-up phase of the processor.

[0065] It is worth noting that since the processor public key pre-installed in the processor as the root of trust is owned by the processor producer, the processor producer can install the processor public key in the processor when producing the processor. In some embodiments, a one-time programmable storage circuit can be provided in the processor, and the processor public key can be written in the one-time programmable circuit by the processor producer. In this way, the one-time programmable circuit for writing by the computer can not be provided in the processor, but can be provided in the processor by the processor producer in the production phase of the processor, so that the computer manufacturer need not write the root of trust into the processor by a specific tool after obtaining the processor.

[0066] In some embodiments, the processor public key can be directly hard-coded into the hardware circuit of the processor, so that the one-time programmable circuit for the root of trust in the processor can be saved, and the same size of processor public key can occupy less processor area, so that the processor space can be saved; at the same time, the one-time programmable circuit provided for the root of trust can be provided to other data.

[0067] In step S13, when the processor public key signature verification of the public key passes, the target signature is verified by the computer public key, and the target signature is the signature of the target object by the computer private key; when the verification passes, step S14 is executed, and when the verification fails, step S15 is executed.

[0068] The target object is a program or data to be verified, and in some embodiments, the target object can be firmware. Firmware is a program (software) that undertakes the most basic and bottom-level work of a system, such as the operating system of a computer. The importance of firmware makes it a serious computer security problem if the firmware is tampered with, such as core data leakage or computer direct failure to run, so the firmware can be verified before the firmware is started, so as to determine whether the firmware has been tampered with. When the computer firmware verification passes, the computer system corresponding to the computer public key is started.

[0069] When the processor public key signature verification of the public key passes, the computer public key signed by the processor private key can be considered to be safe and not tampered with. Therefore, the target signature can be verified using the computer public key, and when the target signature verification passes, it can be further considered that the target object has not been tampered with; on the contrary, when the target signature verification fails, it can be considered that the target object has been tampered with.

[0070] In step S14, the target object is verified.

[0071] When the target signature verification passes, it is considered that the target object has not been tampered with, so that the target object can be verified, and subsequent other steps can be executed. For example, when the target object is firmware, the target object is verified before the firmware is started, and after the verification passes, the firmware can be started, so that the computer can execute instruction processing data and complete various computer tasks.

[0072] In step S15, the verification of the target object fails.

[0073] When the target object signature verification fails, it can be determined that the target object has been tampered with, so that remedial measures can be taken, and in some embodiments, a termination signal can be sent to the processor to make the processor terminate reading or starting the target object.

[0074] It can be seen that the computer target object verification method provided by the embodiment of the application takes the processor public key as the trust root, and the processor producer sets the trust root in the processor in the production stage of the processor, so that the computer producer can not need to write the trust root into the processor through a specific tool after obtaining the processor, and the computer producer can verify the target object based on the trust root, so that the computer can be implemented conveniently while verifying the program or data of the trust root set in the processor. Meanwhile, since the computer private key is stored in the computer and the processor private key is not stored in the computer, the processor private key has no risk of being stolen by malicious software in the running process of the computer, and the computer is more secure. In addition, after the computer private key is stolen or tampered with, the computer public key and the computer private key need to be replaced, and the computer public key fixed in the processor as the trust root cannot be replaced.

[0075] It should be noted that when the processor public key and the processor private key belong to a plurality of processors, the plurality of processors can be set in a plurality of computers, and the computer public key and the computer private key in each computer can be different, so there is a risk that one computer signs the public key of another computer with its own public key. Since both are signed by the same processor private key, they can also be verified by the processor public key, so that the computer verifies the target object with the wrong computer public key, and thus misjudges that the target object has been tampered with, or makes the wrong target object pass the verification.

[0076] In order to avoid the above situation, in a specific embodiment, please refer to Figure 4 , Figure 4 Another flowchart of the computer target object verification method provided by the embodiment of the application is shown in FIG. 6.

[0077] As shown in the figure, in step S21, a public key signature is obtained, and the public key signature includes a signature of a processor private key on a public key certificate.

[0078] For details of step S21, please refer to the description of step S11 above.

[0079] In step S22, it is judged whether the computer identifier corresponding to the computer public key is consistent with the processor identifier fixed in the processor in advance; when consistent, step S23 is executed, and when inconsistent, step S26 is executed.

[0080] The computer public key is the computer public key corresponding to the public key signature in step S21.

[0081] The processor identifies the computer corresponding to the processor identification. The computer identification corresponding to the computer public key of the computer is the same as the processor identification. When the computer identification corresponding to the computer public key is the same as the processor identification, it can be judged that the computer public key is the computer public key of the computer, rather than the computer public key of other computers encrypted by the same processor private key. When the computer identification corresponding to the computer public key is not the same as the processor identification, it can be judged that the computer public key is not the computer public key of the computer, but the computer public key of other computers encrypted by the same processor private key.

[0082] By pre-installing the processor identification in the processor, the processor identification can be prevented from being tampered by malicious software in the running stage of the computer.

[0083] In some embodiments, the processor identification can be set in the processor in the production stage of the processor, so that the computer manufacturer does not need to write the root of trust into the processor by a specific tool after obtaining the processor, facilitating the implementation of the computer target object verification method provided by the embodiments of the application.

[0084] In order to install the processor identification, in some embodiments, a one-time programmable memory can be built in the processor, so that the processor identification corresponding to the computer corresponding to the processor identification is unchangeably installed in the processor.

[0085] In order to obtain the computer identification corresponding to the computer public key, in some embodiments, the public key certificate includes the computer identification in addition to the computer public key. Thus, the computer identification corresponding to the computer public key recorded in the public key certificate is the computer identification recorded in the same public key certificate.

[0086] Specifically, the computer identification and the computer public key can be calculated by the processor private key, so as to obtain the public key signature which can be used to judge whether the computer identification and the computer public key are tampered.

[0087] In some embodiments, the length of the processor identification can be equal to 8 bits, i.e. 1 byte. Of course, the specific bit number can be set according to the needs.

[0088] In step S23, the public key signature is verified by the processor public key pre-installed in the processor.

[0089] The public key certificate includes the computer identification in addition to the computer public key. The verification of the public key signature of the public key certificate can be used to judge whether the computer identification and the computer public key are tampered.

[0090] In step S24, when the processor public key verifies the public key signature successfully, the target signature is verified by the computer public key, the target signature is the signature of the target object by the computer private key; when the verification is successful, step S25 is executed; when the verification is not successful, step S26 is executed.

[0091] In step S25, the target object is verified successfully.

[0092] In step S26, the target object is not verified successfully.

[0093] When the computer identity is not consistent with the processor identity, the target signature is not allowed to be verified by the computer public key.

[0094] The specific content of steps S23 to S26 can refer to the related description of steps S12 to S15.

[0095] In this way, it can be distinguished whether the public key signature requesting verification corresponds to the computer public key of other computers, when the processor public key and the processor private key belong to multiple processors, the multiple processors can be arranged in multiple computers, and the computer public key and the computer private key in each computer can be different, so that the public key signature tampered by other computers can be prevented from passing the verification.

[0096] It should be noted that when the computer private key is stolen by malicious software, the computer updates the computer private key and the computer public key, although the processor public key fixed in the processor does not need to be updated, the malicious software can use the stolen computer private key to sign the tampered target object, and then use the computer public key before the computer is updated and the public key signature to deceive the processor to make the tampered target object pass the verification.

[0097] In order to distinguish the updated computer private key and the computer public key, and the updated public key signature re-applied according to the updated computer public key, please refer to Figure 5 , Figure 5 Another flowchart of the computer target object verification method provided by the embodiment of the application.

[0098] As Figure 5 shown, the computer target object verification method provided by the embodiment of the application comprises:

[0099] In step S31, a public key signature is obtained, the public key signature comprising a signature of a public key certificate by a processor private key.

[0100] In step S32, it is judged whether the computer version information corresponding to the computer public key is greater than or equal to the public key certificate version information preset in the processor; when greater than or equal to, step S33 is executed, and when less than, step S36 is executed.

[0101] The computer version information is adapted to represent the version of the corresponding computer public key, and when the computer version information is less than the public key certificate version information in the processor, it is considered that the computer public key corresponding to the computer version information is too outdated in version, and thus the target object cannot pass the verification.

[0102] In order to set the computer version information in the processor, in some embodiments, a one-time programmable storage circuit is configured in the processor, and the one-time programmable storage circuit is used to preset the public key certificate version information. Further, in order to allow updating while achieving fixation, in a specific embodiment, the one-time programmable storage circuit also supports bit-by-bit burning, and when the one-time programmable storage circuit is read, only the burned data is read, so that when the public key certificate version information is set in the processor, the data bits of the one-time programmable circuit in the processor are burned bit by bit. Specifically, the provided one-time programmable circuit can have each data bit as “0” before burning, as the public key certificate version information of the computer public key of the first version. After each update of the computer public key and the computer private key, the next data bit in the one-time programmable circuit of the processor is burned as “1” to represent a different version.

[0103] In some embodiments, the one-time programmable circuit can be one byte in size, that is, have eight data bits to be burned, and “00000000” represents the initial version, and the computer version information corresponding to the computer public key of the initial version is also “000000000”. When the computer public key and the computer private key in the computer need to be updated in version due to being stolen and the like, the computer public key and the computer private key after the update can burn one data bit of the one-time programmable circuit by a burning tool to update it to “00000001”, so that when an attacker uses the stolen old version of the computer public key to form a public key signature, since the computer version information of the computer public key of the public key certificate corresponding to the public key signature is “00000000”, which is less than the public key certificate version information “00000001” in the processor, it is judged that the verification fails. When it is necessary to update the public key certificate version information again, the bits are written with “1” in turn, and thus when the one-time programmable circuit is one byte, a total of 8 versions can be updated at most.

[0104] In some embodiments, the computer version information corresponding to the computer public key of the computer can be the same as the public key certificate version information in the processor of the computer. When the computer public key and the computer private key are updated, the public key certificate version information and the computer version information are updated simultaneously, so that the updated public key certificate version information and the computer version information are consistent.

[0105] In some other embodiments, the computer version information corresponding to the computer public key of the computer can be greater than the public key certificate version information. In this way, although the attacker cannot be prevented from using the above-mentioned leaked old version of the computer version information for verification when the public key certificate version information is not updated, the updated computer version information can be prevented from passing the verification.

[0106] When the computer version information corresponding to the computer public key is greater than or equal to the public key certificate version information, it can be determined that the computer public key is the current version of the computer public key, rather than the computer public key of the leaked version. Conversely, it can be determined that the computer public key is not the current version, but the computer public key of the leaked version, and the attack on the computer by the malicious software after stealing the computer private key cannot pass the verification.

[0107] In order to obtain the computer version information corresponding to the computer public key, in some embodiments, the public key certificate further includes the computer version information in addition to the public key signature and the computer public key. In this way, the computer version information corresponding to the computer public key recorded in the public key certificate is the computer version information recorded in the same public key certificate.

[0108] In some embodiments, the public key signature further includes the signature of the processor private key on the computer version information. In this way, when the public key signature is verified, it can also be determined whether the computer version information determined in step S32 is tampered with. Specifically, the entire computer version information and the computer public key can be encrypted by the processor private key to obtain the public key signature, which can be used to determine whether the entire computer version information and the computer public key are tampered with.

[0109] In some embodiments, the length of the public key certificate version information can be less than or equal to 8 bits, i.e. 1 byte. Of course, the specific number of bits can be set as needed.

[0110] In step S33, the processor public key pre-installed in the processor is used to verify the public key signature.

[0111] In step S34, when the processor public key verifies the public key signature successfully, the target signature is verified by the computer public key, the target signature is the signature of the target object by the computer private key; when the verification is successful, step S35 is executed, and when the verification is not successful, step S36 is executed.

[0112] In step S35, the target object is verified successfully.

[0113] In step S36, the target object is not verified successfully.

[0114] The specific content of steps S33 to S36 can refer to the related description of steps S12 to S15.

[0115] In this way, the malicious software can be prevented from signing the tampered target object by the stolen computer private key, and then using the computer public key before the computer is updated and the public key signature to deceive the processor to make the tampered target object pass the verification.

[0116] To solve the above problems, the embodiment of the application further provides a computer target object verification device, which can refer to Figure 6 , Figure 6 The schematic diagram of the computer target object verification device provided by the embodiment of the application.

[0117] As shown in the figure, the computer target object verification device provided by the embodiment of the application comprises:

[0118] The public key signature acquisition unit 1 is adapted to acquire a public key signature, the public key signature comprises a signature of a public key certificate by a processor private key, and the public key certificate comprises at least a computer public key.

[0119] The public key signature verification unit 2 is adapted to verify the public key signature by a processor public key pre-installed in the processor.

[0120] The target signature verification unit 3 is adapted to verify a target signature by the computer public key when the processor public key verifies the public key signature successfully, the target signature is the signature of a target object by a computer private key; when the computer public key verifies the target signature successfully, the target object is verified successfully.

[0121] It can be seen that the computer target object verification device provided by the embodiment of the application takes the processor public key as the trust root, and the processor producer sets the trust root in the processor in the production stage of the processor, so that the computer producer can not need to write the trust root into the processor through specific tools after obtaining the processor, and the computer producer can verify the target object based on the trust root, so that the computer can be implemented conveniently while verifying the program or data of the trust root set in the processor. Meanwhile, the processor private key is not stored in the computer, so that the processor private key has no risk of being stolen by malicious software in the running process of the computer, and the computer is more secure. After the computer private key is stolen or tampered, the computer public key and the computer private key need to be replaced, and the computer public key fixed in the processor as the trust root cannot be replaced.

[0122] In a specific embodiment, the target object includes computer firmware; and if the verification of the computer firmware is passed, a computer system corresponding to the computer public key is started.

[0123] In a specific embodiment, the computer target object verification device provided by the embodiment of the application further includes:

[0124] An identity judgment unit is adapted to judge whether a computer identity corresponding to the computer public key is consistent with a processor identity fixed in the processor in advance before the target signature verification unit verifies the target signature by using the computer public key. The processor identity corresponds to the computer one by one, and the processor identity corresponding to the computer is the same as the computer identity corresponding to the computer public key of the computer. When the computer identity is not consistent with the processor identity, the verification of the target object is not passed.

[0125] In a specific embodiment, the computer target object verification device provided by the embodiment of the application further includes:

[0126] A version information judgment unit is adapted to judge whether computer version information corresponding to the computer public key is greater than or equal to public key certificate version information preset in the processor before the target signature verification unit verifies the target signature by using the computer public key. The computer version information is adapted to indicate the version of the corresponding computer public key. When the computer version information is less than the public key certificate version information, the verification of the target object is not passed.

[0127] In a specific embodiment, the public key certificate further includes the computer identity.

[0128] In a specific embodiment, the public key certificate further includes the computer version information.

[0129] In an embodiment, the processor is configured with a one-time programmable storage circuit, which is used to preset the processor identifier and / or the public key certificate version information.

[0130] In an embodiment, the one-time programmable storage circuit supports bit-by-bit programming, and only the programmed data is read when the one-time programmable storage circuit is read.

[0131] The embodiment of the present application also provides a storage medium, which stores a program to implement the computer target object verification method.

[0132] The embodiment of the present application also provides a processor, which comprises a processor public key hardware circuit, the processor public key hardware circuit is a hardware circuit integrated in the processor, and the processor public key is hard coded in the processor public key hardware circuit, and the processor is adapted to implement the computer target object verification method.

[0133] The embodiment of the present application also provides an electronic device, which comprises a memory, a mainboard and at least one processor on the mainboard, the mainboard stores the target object, the memory stores a program, and the processor calls the program to implement the computer target object verification method to verify the target object.

[0134] It can be seen that the storage medium, the processor and the electronic device provided by the embodiment of the present application take the processor public key as the trust root, the processor producer sets the trust root in the processor in the production stage of the processor, the computer producer does not need to write the trust root into the processor by using a specific tool after obtaining the processor, the computer producer can verify the target object based on the trust root, the computer can be implemented conveniently while verifying the program or the data by using the trust root set in the processor, and the processor private key is not stored in the computer, so the processor private key has no risk of being stolen by malicious software in the computer running process, and the security is higher, and the computer private key is stolen or tampered, so the computer public key and the computer private key need to be replaced, and the computer public key fixed in the processor as the trust root cannot be replaced.

[0135] The above description of disclosed embodiments enables a person skilled in the art to implement or use the invention. Numerous modifications to these embodiments will be apparent to those skilled in the art, and general principles defined herein can be applied to other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention will not be limited to the embodiments shown herein but will be accorded the widest scope consistent with the principles and novel features disclosed herein. The above describes various embodiment schemes provided by the embodiments of the present invention, and each optional mode introduced by each embodiment scheme can be combined with each other and cross-referenced without conflict, thereby extending various possible embodiment schemes, which can all be considered as the embodiment schemes disclosed and disclosed by the embodiments of the present invention.

[0136] Although the embodiments of the present invention are disclosed as above, the present invention is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention, and therefore the protection scope of the present invention should be subject to the scope defined by the claims.

Claims

1. A computer target object verification method, characterized by, The method comprises the following steps: obtaining a public key signature, wherein the public key signature comprises a signature of a processor private key on a public key certificate, and the public key certificate comprises at least a computer public key; wherein the public key certificate comprising the computer public key is stored in a computer, and is located outside the processor, the computer is a whole machine except the processor; the processor private key is not stored in the processor or the computer; the computer public key is a public key belonging to the computer, and corresponds to a computer private key also belonging to the computer; verifying the public key signature by using a processor public key previously fixed in the processor; wherein the processor public key is fixed in the processor when the processor is produced; when the verification of the public key signature by the processor public key is passed, verifying a target signature by using the computer public key, wherein the target signature is a signature of a target object by a computer private key; when the verification of the target signature by the computer public key is passed, the target object is verified to be passed; wherein the target object comprises computer firmware, and if the computer firmware is verified to be passed, a computer system corresponding to the computer public key is started.

2. The computer target object verification method of claim 1, wherein, Before the step of verifying the target signature by using the computer public key, the method further comprises the following steps: judging whether a computer identifier corresponding to the computer public key is consistent with a processor identifier previously fixed in the processor, wherein the processor identifier corresponds to the computer one by one, and the processor identifier corresponding to the computer is the same as the computer identifier corresponding to the computer public key of the computer; when the computer identifier is not consistent with the processor identifier, the verification of the target object is failed.

3. The computer target object verification method of claim 2, wherein, The public key certificate further comprises the computer identifier.

4. The computer target object verification method of claim 2, wherein, Before the step of verifying the target signature by using the computer public key, the method further comprises the following steps: judging whether computer version information corresponding to the computer public key is greater than or equal to public key certificate version information previously fixed in the processor, wherein the computer version information is adapted to represent the version of the corresponding computer public key; when the computer version information is less than the public key certificate version information, the verification of the target object is failed.

5. The computer target object verification method of claim 4, wherein, The public key certificate further comprises the computer version information.

6. The computer target object verification method of claim 4, wherein, The processor is configured with a one-time programmable storage circuit, and the one-time programmable storage circuit is used for previously setting the processor identifier and / or the public key certificate version information.

7. The computer target object verification method of claim 6, wherein, The one-time programmable storage circuit supports bit-by-bit burning, and only the burned data is read when the one-time programmable storage circuit is read.

8. A computer target object verification apparatus, characterized by comprising: The method comprises the following steps: a public key signature obtaining unit is adapted to obtain a public key signature, wherein the public key signature comprises a signature of a processor private key on a public key certificate, and the public key certificate comprises at least a computer public key; wherein the public key certificate comprising the computer public key is stored in a computer, and is located outside the processor, the computer is a whole machine except the processor; the processor private key is not stored in the processor or the computer; the computer public key is a public key belonging to the computer, and corresponds to a computer private key also belonging to the computer; The public key signature verification unit is adapted to verify the public key signature by using a processor public key pre-stored in the processor; wherein the processor public key is stored in the processor when the processor is produced; The target signature verification unit is adapted to verify a target signature by using the computer public key when the processor public key verifies the public key signature successfully, wherein the target signature is a signature of a target object by a computer private key; and the target object is verified successfully when the computer public key verifies the target signature successfully. The target object includes a computer firmware, and the computer system corresponding to the computer public key is started when the computer firmware is verified successfully.

9. The computer target object verification apparatus of claim 8, wherein, Further comprising: The identification judgment unit is adapted to judge whether a computer identification corresponding to the computer public key is consistent with a processor identification pre-stored in the processor before the target signature verification unit verifies the target signature by using the computer public key, wherein the processor identification is one-to-one corresponding to the computer, and the processor identification corresponding to the computer is the same as the computer identification corresponding to the computer public key of the computer; and the target object is verified unsuccessfully when the computer identification is not consistent with the processor identification.

10. The computer target object verification apparatus of claim 9, wherein, Further comprising: The version information judgment unit is adapted to judge whether a computer version information corresponding to the computer public key is greater than or equal to a public key certificate version information pre-stored in the processor before the target signature verification unit verifies the target signature by using the computer public key, wherein the computer version information is adapted to represent the version of the corresponding computer public key; and the target object is verified unsuccessfully when the computer version information is less than the public key certificate version information.

11. A storage medium, characterized by The storage medium stores a program to implement the computer target object verification method according to any one of claims 1-7.

12. A processor, comprising: The processor public key hardware circuit is a hardware circuit in which the processor public key is integrated, and is adapted to implement the computer target object verification method according to any one of claims 1-7.

13. An electronic device, comprising: The mainboard stores the target object, the memory stores a program, and the processor calls the program to verify the target object by using the computer target object verification method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Central processing unit and method for verifying data of main board

    CN104899524A

  • Data interaction method, device, equipment and medium

    CN112487380A

  • Memory burning method and device and to-be-burnt chip

    CN112612486A