Class Distributed UEFI Core Code Anti-Tampering Method and Device
By implanting the Guard network in the UEFI firmware, the integrity verification and repair of UEFI core code is solved, and the problem that the core code of UEFI firmware is easily tampered with is improved, the security protection capability of UEFI is reduced, and the equipment cost is reduced.
Patent Information
- Application Number
- CN202310236672.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-13
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2043-03-13
AI Technical Summary
In the prior art, the core code of UEFI firmware is easily tampered with by attackers, and existing protection mechanisms such as BootGuard have problems such as high cost and fragile trust chain, making it difficult to effectively prevent malicious tampering of UEFI firmware.
The tamper-proof method of distributed UEFI core code is adopted. By implanting a Guard network into the target firmware volume where the UEFI firmware is located, the integrity verification of the UEFI core code is realized and repaired when tampering is detected to ensure the security of the firmware code.
Effectively prevent attackers from attacking by tampering with UEFI core code, improve UEFI's security protection capabilities, eliminate the vulnerability of single trust chain delivery, reduce equipment costs, and provide a safer protection strategy for platforms that do not support BootGuard.
Smart Images

Figure CN116305156B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of firmware security protection, and particularly relates to a method and device for preventing tampering of a distributed UEFI core code-like, and the protection object is UEFI (Unified Extensible Firmware Interface). Background Art
[0002] UEFI is an upgraded solution that replaces the traditional BIOS, and it defines the interface specification between the operating system and the firmware platform. Compared with the traditional BIOS, UEFI has some technical advantages, such as being written in C language, having strict standard specifications, flexible code allocation, processor independence, supporting network connection, etc.
[0003] After the computer is powered on, the system firmware will check the status of components such as the CPU, timing chip, programmable interruptor, and DMA controller, and initialize the chipset, system memory, graphics card, and related peripheral registers, etc. During this process, the system firmware has extremely high privileges. Once there are security vulnerabilities in the firmware or a firmware trojan is implanted, it will pose a serious threat to the security of the platform. In 2017, the world's first UEFI trojan was discovered in the real network environment. This trojan remotely downloads malicious code through a network connection and creates an administrator account, and then remotely steals user data.
[0004] Compared with trojans at the system layer or application layer, system firmware trojans have the characteristics of high destructiveness, high concealment, and being difficult to remove.
[0005] a Strong destructiveness. The firmware needs to complete the initialization of various hardware and the loading of the operating system when the computer starts up, so it can realize the access and control of the computer's underlying hardware. If UEFI is attacked, the attacker can damage the memory data and the system boot program, tamper with the hard disk data, hijack the operating system, etc. In addition, if the firmware's own code or data is tampered with or damaged, the platform can be completely paralyzed.
[0006] b High concealment. The UEFI firmware code is executed before the operating system starts, and is completely transparent to the operating system. While general security software runs in the operating system environment, the operation of the firmware malicious code cannot be detected by general security software. At the same time, the firmware malicious code resides in the Flash chip on the motherboard, and the security software at the system layer cannot access this location and detect it.
[0007] It is difficult to remove. Trojans at the system level can generally be detected and removed by security software, or completely removed by reinstalling the system or replacing the hard drive. However, UEFI firmware trojans are stored in the motherboard Flash / ROM chip. Generally, security software at the system level cannot access this location, so they cannot be removed through the operating system or antivirus software. Even reinstalling the system and replacing the hard drive cannot remove the firmware malicious code.
[0008] In the future, UEFI will not only replace the traditional BIOS on PCs, but also be widely used in smartphones, wearable devices, airport flight control, medical monitoring, and critical infrastructure. In this trend, UEFI firmware security will surely become an extremely important part of computer network and Internet of Things security. For the UEFI firmware of the PC motherboard, the current mainstream protection mechanism is BootGuard to protect it from being maliciously tampered with.
[0009] Under the action of BootGuard, a single-chain trust transfer based on keys and integrity verification is formed throughout the boot process. However, most computer platforms do not support BootGuard. Even some platforms that support BootGuard are not correctly configured, resulting in the exposure of most of the core code of the UEFI firmware on the platform under the attacker's control when the write protection mechanism is bypassed. This poses a huge threat to the security of the computing platform. At the same time, BootGuard requires the support of hardware such as the CPU, chipset, and TPM security chip, which increases the cost of the product and thus affects the competitiveness of the product. In addition, since BootGuard uses a single-chain unidirectional trust transfer, the trust transfer is vulnerable. If the attacker obtains the control right of one link in the trust chain, all subsequent links will be exposed under the attacker's control. Summary of the Invention
[0010] Aiming at the problems existing in the prior art, the present invention proposes a method and device for preventing tampering with UEFI core code in a distributed-like manner, which can effectively prevent attackers from attacking by tampering with the core code of UEFI and restoring the tampered code, thereby improving the security protection ability of UEFI.
[0011] To achieve the above object, the present invention adopts the following technical solutions:
[0012] The present invention provides a method for preventing tampering with UEFI core code in a distributed-like manner, comprising the following steps:
[0013] Plant a Guard network in the target firmware volume where the UEFI firmware is located;
[0014] At startup, before executing the protected firmware file, it first jumps to the corresponding Guard node, and performs integrity verification on the firmware file and other Guard nodes responsible for this Guard node;
[0015] If the detected firmware file and other Guard nodes have not been tampered with or damaged, it jumps to the firmware file and executes the firmware code;
[0016] If the detected firmware file or other Guard nodes have been tampered with or damaged, it aborts the startup process and uses the repair function of this Guard node to repair it;
[0017] If the repair is successful, it continues the startup process; otherwise, it terminates the startup process.
[0018] Furthermore, a Guard network is implanted in the target firmware volume where the UEFI firmware is located, specifically including:
[0019] Step 1: Extract the motherboard firmware from the motherboard and obtain the UEFI firmware from it;
[0020] Step 2: Scan the UEFI firmware, extract the address, size, and GUID information of the firmware volume, and construct a firmware volume list;
[0021] Step 3: Traverse all firmware volumes in the firmware volume list. If the firmware volume is the firmware volume where the UEFI core code is located, go to Step 4; otherwise, skip it;
[0022] Step 4: Scan the firmware volume, identify the firmware file type according to the GUID, record the offset and file size information of the core firmware file, and store them in the firmware file list;
[0023] Step 5: Decompress all firmware files in the firmware file list;
[0024] Step 6: Determine the protection strength coefficient a;
[0025] Step 7: Create a Guard node list;
[0026] Step 8: Traverse the firmware file list, sort the nodes according to the out-degree of each Guard node in the Guard node list, select the first a Guard nodes with the smallest out-degree, and save the integrity information of the current firmware file in these a Guard nodes; construct a Guard protection network with the protected firmware file and Guard nodes as nodes, and make all Guard nodes form a strongly connected graph;
[0027] Step 9: HOOK the original execution path of the firmware to enable the Guard node to verify the integrity of the firmware file before the firmware file is executed;
[0028] Step 10: implant the Guard network into the firmware volume, repackage the modified firmware file and the Guard nodes, and replace the original file with the modified firmware file.
[0029] Further, step 5 decompresses all the firmware files in the firmware file list, including: traversing all the firmware files in the firmware file list, judging the compression algorithm type according to the value of the compression algorithm field and the GUID value feature of the firmware compressed file; decompressing the firmware file by using the decompression algorithm corresponding to the compression algorithm type.
[0030] Further, the protection strength coefficient a represents the ratio of the number of Guard nodes to the number of firmware files to be protected, and is used to determine the number of implanted Guard nodes.
[0031] Further, the Guard protection network is a directed graph, and the directed edge A→B in the graph indicates that node A performs integrity verification on node B. Each node has an in-degree, and the firmware file node only has an in-degree.
[0032] Further, after step 9, it further includes: scanning the free space in the firmware volume, and saving the offset and size information in the free space list.
[0033] Further, in step 10, implant the Guard network into the free space of the firmware volume.
[0034] Further, the process of using the Guard node for repair is as follows:
[0035] The Guard node obtains the GUID of the tampered or damaged firmware file;
[0036] Access the backup BIOS, and scan the corresponding firmware file in the backup BIOS according to the GUID;
[0037] Read the backup firmware file and overwrite the corresponding firmware file part in the main BIOS;
[0038] After repairing the damaged file, it does not directly execute the firmware file, but re-performs integrity verification on it;
[0039] If the integrity verification passes, execute the firmware file, otherwise terminate the startup process.
[0040] The present invention also provides a kind of distributed UEFI core code anti-tampering device, including:
[0041] The Guard network implantation module is used to implant the Guard network into the target firmware volume where the UEFI firmware is located;
[0042] An integrity verification module, which, when starting up, first jumps to the corresponding Guard node before executing the protected firmware file to perform integrity verification on the firmware file and other Guard nodes responsible for by the Guard node;
[0043] A firmware file execution module, which, if the detected firmware file and other Guard nodes have not been tampered with or damaged, jumps to the firmware file and executes the firmware code;
[0044] A damaged file repair module, which, if the detected firmware file or other Guard nodes are tampered with or damaged, aborts the startup process and uses the repair function of the Guard node to repair it;
[0045] A repair result judgment module, which, if the repair is successful, continues the startup process, otherwise terminates the startup process.
[0046] Compared with the prior art, the present invention has the following advantages:
[0047] The method for preventing tampering of the class-distributed UEFI core code of the present invention uses a Guard network to implement the integrity verification of the UEFI core code, eliminating the vulnerability existing in the single trust chain transmission; uses a dual-chip strategy to achieve self-recovery of the tampered UEFI core code, avoiding the situation that the computer executes malicious code after the firmware code is tampered with; cancels the use of modules such as the TPM security chip, reducing the device cost, and providing a more secure UEFI core code protection strategy for platforms that do not support BootGuard. Brief Description of the Drawings
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0049] Figure 1 It is a schematic flowchart of the method for preventing tampering of the class-distributed UEFI core code in the embodiment of the present invention;
[0050] Figure 2 It is a schematic flowchart of implanting the Guard network into the target firmware volume in the embodiment of the present invention;
[0051] Figure 3 It is a schematic flowchart of the Guard node repairing the tampered or damaged firmware file in the embodiment of the present invention;
[0052] Figure 4 It is a schematic diagram of the Guard protection network (the protection strength coefficient a is 1). Specific implementation manner
[0053] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0054] As Figure 1 shown, the method for preventing tampering of the class - distributed UEFI core code in this embodiment, where the core code includes DXE_Core, DXE_Driver, SMM_Core, and SMM_module, is concentrated in the same firmware volume. The method includes the following steps:
[0055] Step S1, implant a Guard network in the target firmware volume where the UEFI firmware is located. A Guard network consists of multiple Guard nodes. The role of a Guard node is to detect whether the firmware file or other Guard nodes it is responsible for are tampered with or damaged during startup.
[0056] Step S2, during startup, before executing a certain protected firmware file, first jump to its corresponding Guard node to perform integrity verification on this firmware file and other Guard nodes responsible for by this Guard node, and determine whether this firmware file and other Guard nodes are tampered with or damaged. The verification methods include but are not limited to hash values; if the detected firmware file and other Guard nodes are not tampered with or damaged, then go to step S3. If the detected firmware file or other Guard nodes are tampered with or damaged, go to step S5.
[0057] Step S3, jump to the firmware file and execute the firmware code.
[0058] Step S4, determine whether there are other firmware files to be executed. If so, go to step S2. If not, the startup process is completed.
[0059] Step S5, abort the startup process and use the repair function of this Guard node to repair it.
[0060] Step S6, determine whether the repair is successful. If the repair is successful, go to step S2 to continue the startup process. If the repair fails, terminate the startup process.
[0061] As Figure 2As shown, step S1 further includes the following steps:
[0062] Step S101, extract the mainboard firmware from the mainboard and obtain the UEFI firmware part therefrom.
[0063] Step S102, scan the UEFI firmware by byte sequence matching, extract information such as the address, size, and GUID of the firmware volume, and construct a firmware volume list.
[0064] Step S103, traverse all the firmware volumes in the firmware volume list, identify the firmware volume where core files such as DXE_Core are located. If the firmware volume is the firmware volume where the UEFI core code is located, go to step S104; otherwise, skip.
[0065] Step S104, scan the firmware volume and identify the firmware file type according to the GUID and byte sequence.
[0066] Step S105, determine whether the firmware file type is a core firmware file such as DXE_Core. If it is a core firmware file, go to step S106; otherwise, skip.
[0067] Step S106, record information such as the offset and file size of the firmware file, and store it in the firmware file list.
[0068] Step S107, traverse all the firmware files in the firmware file list, and determine whether the compression algorithm type is Tiano, LZMA, or the EFI standard compression algorithm, etc., according to the value of the compression algorithm field and the GUID value characteristics of the firmware compressed file.
[0069] Step S108, decompress the firmware file using the decompression algorithm corresponding to the compression algorithm type.
[0070] Step S109, determine the protection strength coefficient a. a represents the ratio of the number of Guard nodes to the number of firmware files to be protected, and can also be understood as each firmware file being integrity-verified by a Guard nodes, which is used to determine the number of implanted Guard nodes. The Guard protection network structure is as Figure 4 shown.
[0071] Step S110, construct the corresponding number of Guard nodes and create a Guard node list.
[0072] Step S111, traverse the firmware file list, select the a Guard nodes with the smallest out-degree from the Guard node list, and save the integrity information of the current firmware file in these a Guard nodes, making them responsible for the integrity verification of the firmware file. The integrity information is the basis for verifying the integrity of the firmware file, such as using the hash value of the firmware file.
[0073] Construct a Guard protection network with the protected firmware file and Guard nodes as nodes, and make all Guard nodes form a strongly connected graph. The Guard protection network is a directed graph, and the directed edge A→B in the graph indicates that node A verifies the integrity of node B. When constructing the directed graph, it is necessary to ensure that each node has an in-degree, and the firmware file node only has an in-degree.
[0074] Step S112, traverse the list of Guard nodes. If the current Guard node has not been incorporated into the strongly connected graph, incorporate it and make it have an in-degree from other Guard nodes and an out-degree pointing to other Guard nodes, with the aim of putting all Guard nodes in a closed loop of integrity verification.
[0075] Step S113, HOOK the original execution path of the firmware to enable the Guard node to verify the integrity of the firmware file before the firmware file is executed.
[0076] Step S114, scan the free space in the firmware volume and save information such as offsets and sizes in the free space list for the next step of implanting the Guard network into the firmware volume.
[0077] Step S115, implant the Guard network into the free space of the firmware volume, repackage the modified firmware file and Guard nodes in the original compression method, and replace the original file with the modified firmware file.
[0078] As Figure 3 shown, the process of using Guard nodes for repair in step S5 is as follows:
[0079] Step S501, the Guard node obtains the GUID of the tampered or damaged firmware file.
[0080] Step S502, the Guard node accesses the backup BIOS and scans the corresponding firmware file in the backup BIOS according to the GUID.
[0081] Step S503, read the backup firmware file and overwrite the corresponding part of the firmware file in the main BIOS.
[0082] Step S504, after repairing the damaged file, do not directly execute the firmware file, but re-verify its integrity.
[0083] Step S505, if the integrity verification passes, execute the firmware file.
[0084] Step S506, if the integrity verification fails, terminate the startup process to prevent the execution of files tampered with by an attacker, thereby preventing the computer platform from being controlled by the attacker.
[0085] Corresponding to the above method for preventing tampering of the class-distributed UEFI core code, this embodiment also proposes a device for preventing tampering of the class-distributed UEFI core code, including:
[0086] The Guard network implantation module is used to implant the Guard network in the target firmware volume where the UEFI firmware is located.
[0087] The integrity verification module is used to, when starting up, first jump to the corresponding Guard node before executing the protected firmware file, and perform integrity verification on the firmware file and other Guard nodes responsible for this Guard node.
[0088] The firmware file execution module is used to, if the detected firmware file and other Guard nodes have not been tampered with or damaged, jump to the firmware file and execute the firmware code.
[0089] The damaged file repair module is used to, if the detected firmware file or other Guard nodes are tampered with or damaged, abort the startup process and use the repair function of this Guard node to repair it.
[0090] The repair result judgment module is used to, if the repair is successful, continue the startup process, otherwise terminate the startup process.
[0091] The present invention uses a class-distributed integrity verification method to eliminate the vulnerability existing in the single trust chain transmission; adopts a dual-chip strategy to achieve self-recovery of the UEFI core code, avoiding the situation where the computer executes malicious code after the firmware code is tampered with; cancels the use of modules such as the TPM security chip, and provides a low-cost and more secure UEFI core code protection strategy for the computer platform.
[0092] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device.
[0093] Finally, it should be noted that the above are only the preferred embodiments of the present invention, which are only used to illustrate the technical solutions of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included within the protection scope of the present invention.
Claims
1. A method for preventing tampering of a kind of distributed UEFI core code, characterized in that The steps include: Plant the Guard network in the target firmware volume where the UEFI firmware is located; At startup, first jump to the corresponding Guard node before executing the protected firmware file, and perform integrity verification on the firmware file and other Guard nodes responsible for this Guard node; If the detected firmware file and other Guard nodes are not tampered with or damaged, jump to the firmware file and execute the firmware code; If the detected firmware file or other Guard nodes are tampered with or damaged, abort the startup process and use the repair function of this Guard node to repair it; If the repair is successful, continue the startup process, otherwise terminate the startup process; Plant the Guard network in the target firmware volume where the UEFI firmware is located, specifically including: Step 1, extract the motherboard firmware from the motherboard and obtain the UEFI firmware from it; Step 2, scan the UEFI firmware, extract the address, size, and GUID information of the firmware volume, and construct a firmware volume list; Step 3, traverse all firmware volumes in the firmware volume list. If the firmware volume is the firmware volume where the UEFI core code is located, go to Step 4, otherwise skip; Step 4, scan the firmware volume, identify the firmware file type according to the GUID, record the offset and file size information of the core firmware file, and store it in the firmware file list; Step 5, decompress all firmware files in the firmware file list; Step 6, determine the protection strength coefficient a; the protection strength coefficient a represents the ratio of the number of Guard nodes to the number of protected firmware files, and is used to determine the number of implanted Guard nodes; Step 7, create a Guard node list; Step 8, traverse the firmware file list, sort the nodes according to the out-degree of each Guard node in the Guard node list, select the m Guard nodes with the smallest out-degree, and save the integrity information of the current firmware file in these m Guard nodes; construct a Guard protection network with the protected firmware files and Guard nodes as nodes, and make all Guard nodes form a strongly connected graph; Step 9, HOOK the original execution path of the firmware to enable the Guard node to verify the integrity of the firmware file before the firmware file is executed; Step 10, implant the Guard network into the firmware volume, repackage the modified firmware file and Guard nodes, and replace the original file with the modified firmware file.
2. The method for preventing tampering of the class-distributed UEFI core code according to claim 1, characterized in that Step 5 decompresses all firmware files in the firmware file list, including: traversing all firmware files in the firmware file list, judging the compression algorithm type according to the compression algorithm field value and the GUID value feature of the firmware compressed file; decompressing the firmware file using the decompression algorithm corresponding to the compression algorithm type.
3. The class distributed UEFI core code anti-tampering method according to claim 1, characterized in that The Guard protection network is a directed graph. The directed edge A→B in the graph means that node A verifies the integrity of node B. Each node has an in-degree, and the firmware file node only has an in-degree.
4. The method for preventing tampering of the class-distributed UEFI core code according to claim 1, wherein After the step 9, it further includes: scanning the free space in the firmware volume and saving the offset and size information in the free space list.
5. The class distributed UEFI core code anti-tampering method according to claim 4, wherein In step 10, the Guard network is implanted into the free space of the firmware volume.
6. The method for preventing tampering of the class-distributed UEFI core code according to claim 1, wherein The process of using the Guard node for repair is as follows: The Guard node obtains the GUID of the tampered or damaged firmware file; Access the backup BIOS and scan the corresponding firmware file in the backup BIOS according to the GUID; Read the backup firmware file and overwrite the corresponding part of the firmware file in the main BIOS; After repairing the damaged file, the firmware file is not directly executed, but its integrity is verified again; If the integrity verification passes, the firmware file is executed, otherwise the startup process is terminated.
7. A kind of distributed UEFI core code anti-tampering device, characterized in that, A device for implementing the class distributed UEFI core code anti-tampering method according to any one of claims 1-6, the device includes: A Guard network implantation module, configured to implant the Guard network into the target firmware volume where the UEFI firmware is located; An integrity verification module, configured to, when starting up, first jump to the corresponding Guard node before executing the protected firmware file to verify the integrity of the firmware file and other Guard nodes responsible for the Guard node; A firmware file execution module, configured to, if the detected firmware file and other Guard nodes are not tampered or damaged, jump to the firmware file and execute the firmware code; A damaged file repair module, configured to, if the detected firmware file or other Guard nodes are tampered or damaged, abort the startup process and use the repair function of the Guard node to repair it; A repair result judgment module, configured to, if the repair is successful, continue the startup process, otherwise terminate the startup process.
Citation Information
Patent Citations
Terminal security precaution method and system based on UEFI (Unified Extensible Firmware Interface) and WinPE (Windows Preinstallation Environment)
CN109120584A
Method and device for verifying security of UEFI-based BIOS
CN110363011A