A verification method, device, computer, and computer configuration system
By performing two-way verification of BIOS code and hardware on the local processor of the computer, the security and reliability issues of remote verification are solved, ensuring the security and reliability of the computer when powered on and on.
Patent Information
- Application Number
- CN202310511593.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-08
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-05-08
AI Technical Summary
In the prior art, BIOS code verification when the computer is powered on and powered on depends on a remote server, which has problems such as difficulty in ensuring security and reliability, and the legality verification of BIOS code and hardware is not comprehensive enough.
BIOS code security verification is carried out in the local processor of the computer. By burning the unique identification and digital certificate information of the computer hardware in the BIOS chip, two-way verification is achieved, including the legality and integrity verification of the BIOS code, as well as the legality verification of the hardware.
It improves the verification reliability during the power-on and boot stage of the computer, prevents BIOS code and hardware from being compromised or tampered by attacks, reduces the security risks and costs of remote verification, and enhances the security of the computer.
Smart Images

Figure CN116561734B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computer technologies, and particularly to a verification method, apparatus, computer, and computer configuration system. Background Art
[0002] To ensure the normal and stable operation of a computer, when the computer is powered on and booted, it is necessary to verify the computer so that after the computer verification passes, the startup of the computer operating system is allowed. As an important means to ensure the normal and stable operation of a computer, how to provide technical means to support the improvement of the reliability of computer verification has become a technical problem that those skilled in the art urgently need to solve. Summary of the Invention
[0003] In view of this, the embodiments of the present application provide a verification method, apparatus, computer, and computer configuration system to verify the security of the BIOS code before verifying the computer using the BIOS code, and add a verification of the legality of the computer hardware when verifying the computer, so as to ensure the reliability of computer verification through two-way verification (BIOS code security verification and computer hardware legality verification).
[0004] To achieve the above object, the embodiments of the present application provide the following technical solutions.
[0005] In a first aspect, the embodiments of the present application provide a verification method, including:
[0006] Respond to a computer power-on and boot instruction, and read the BIOS code and BIOS verification information from the BIOS chip of the computer, where the BIOS code pre-saves the unique identifier of the computer hardware of the computer;
[0007] Perform BIOS code security verification according to the BIOS code and the BIOS verification information;
[0008] If the BIOS code security verification passes, run the BIOS code to start the work of computer power-on initialization, and the work includes verifying the computer hardware;
[0009] During the process of verifying the computer hardware, verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-saved in the BIOS code.
[0010] In a second aspect, the embodiments of the present application provide a verification apparatus, including:
[0011] An information reading module, configured to respond to a computer power-on boot instruction, and read BIOS code and BIOS verification information from the BIOS chip of the computer, wherein the unique identifier of the computer hardware of the computer is pre-stored in the BIOS code;
[0012] A BIOS verification module, configured to perform BIOS code security verification according to the BIOS code and the BIOS verification information;
[0013] A code running module, configured to run the BIOS code to start the computer power-on initialization work if the BIOS code security verification passes, and the work includes verifying the computer hardware;
[0014] A hardware verification module, configured to verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code during the process of verifying the computer hardware.
[0015] In a third aspect, an embodiment of the present application provides a computer, including: a processor and a BIOS chip; wherein, the processor is configured to execute the verification method described in the first aspect above, and the BIOS chip has BIOS code and BIOS verification information, wherein the unique identifier of the computer hardware of the computer is pre-stored in the BIOS code.
[0016] In a fourth aspect, an embodiment of the present application provides a computer configuration system, including: a BIOS configuration device system and a digital certificate device system; wherein, the BIOS configuration device system configures information for the BIOS chip to be configured by the computer, and the digital certificate device system configures information for the processor and the BIOS chip to be configured by the computer, and the computer is the computer described in the third aspect above.
[0017] The verification method provided by the embodiments of the present application can, when the computer is powered on and booted, perform security verification on the BIOS code by the processor in the computer. Thus, the processor can respond to the computer power-on and boot instruction, read the BIOS code and BIOS verification information from the BIOS chip of the computer, where the unique identifier of the computer hardware of the computer is pre-stored in the BIOS code; furthermore, the processor can perform BIOS code security verification according to the BIOS code and the BIOS verification information; after the BIOS code security verification passes, the processor can run the read BIOS code to start the work of computer power-on initialization, and the work includes verifying the computer hardware; during the process of verifying the computer hardware, the processor can verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code to perform the legality verification of the computer hardware. Therefore, the verification method provided by the embodiments of the present application can, in the computer power-on and boot stage, achieve the security verification of the BIOS code by the processor and the legality verification of the computer hardware after the BIOS code runs.
[0018] It can be seen that the embodiments of the present application can, in the computer power-on and boot stage, ensure the reliability of computer verification through two-way verification of BIOS code security verification and computer hardware legality verification, so as to comprehensively detect whether the computer has been attacked, damaged, or tampered with (including the situation where the BIOS code has been attacked, damaged, or tampered with, and the situation where the computer hardware has been attacked, damaged, or tampered with), avoid the security risks of the computer running in the case of being attacked, damaged, or tampered with, and improve the security of the computer. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0020] Figure 1 It is a block diagram of the computer configuration system provided by the embodiments of the present application.
[0021] Figure 2 It is a flowchart of the computer configuration method provided by the embodiments of the present application.
[0022] Figure 3 It is an example diagram of the information burned into the processor and the BIOS chip in the embodiments of the present application.
[0023] Figure 4 It is a flowchart of the verification method provided by the embodiments of the present application.
[0024] Figure 5 Another flowchart of the verification method provided in an embodiment of the present application.
[0025] Figure 6 A block diagram of a verification device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0026] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0027] When the computer is powered on, the processor in the computer can load and run the BIOS (Basic Input Output System) code to perform functional tests on the computer hardware such as the processor, memory, graphics card, hard disk, and motherboard through the BIOS power-on self-test program, so as to verify the computer when the computer is powered on by detecting whether the functions of the computer hardware are normal. Among them, BIOS is a set of programs that are fixed to the BIOS chip (such as a Flash chip), which stores the computer's basic input and output programs, system setting information, power-on self-test programs, and system self-starting programs; the BIOS chip can be set on the computer motherboard. As software that runs when the computer starts, BIOS can provide the computer with low-level, direct hardware settings and controls, and is a bridge connecting the underlying hardware system and software system.
[0028] Due to the importance of BIOS, if there is a problem with BIOS, the computer may not start normally, or even be manipulated and information in the computer may be stolen because the BIOS is embedded with a virus by hackers. BIOS has the function of verifying the computer when the computer is powered on. In order to ensure the reliability of computer verification, the security of the BIOS code (BIOS code security, such as the legitimacy and integrity of the BIOS code) can be verified before using the BIOS code to verify the computer.
[0029] The inventor of this application has considered using a remote server to perform security verification on the computer's BIOS code when the computer is powered on, and then using the BIOS code to verify the computer after the security verification of the BIOS code passes, so as to implement computer verification when the computer is powered on.
[0030] The above method for security verification of BIOS code is a remote verification method, that is, the remote server as the verifier is remotely set relative to the computer, which may lead to security risks in the security verification of BIOS code, and thus it is difficult to guarantee the reliability of computer verification based on BIOS.
[0031] Specifically, it is difficult to guarantee the trustworthiness of the remote server, which makes it difficult to guarantee the reliability of the security verification result of the computer's BIOS code, and thus it is difficult to guarantee the reliability of the computer verification result based on BIOS. For example, key components such as the processor and hard disk in the remote server may be replaced, but this does not affect the verification result of the security verification of the computer's BIOS code by the remote server. However, if the replaced processor in the remote server is implanted with a Trojan horse and the replaced hard disk is installed with illegal software, then when the key components such as the processor and hard disk in the remote server are not secure themselves, it is also difficult to guarantee the accuracy of the result of the security verification of BIOS code performed using the remote server, and further it is difficult to guarantee the reliability of the result of the computer verification based on BIOS.
[0032] In addition, when using a remote server to verify the BIOS, it is necessary to remotely transmit the BIOS-related data in the computer to the remote server, which increases the risk of the computer data being stolen or intercepted during the transmission process.
[0033] Based on this, the embodiments of the present application consider performing a security verification of the BIOS code using the processor (such as the CPU) in the computer when the computer is powered on and turned on. Thus, after the security verification of the BIOS code passes, the processor can run the BIOS code to verify the computer using the BIOS code. That is to say, the verifier of the BIOS code is changed from the remote server to the processor local to the computer, reducing the security risks existing in the remote verification of the BIOS code. At the same time, considering the possibility that computer hardware such as the processor and hard disk in the computer may be illegally replaced or tampered with, when the embodiments of the present application use the BIOS code to verify the computer, in addition to performing a functional detection of the computer hardware, a legitimacy verification of the computer hardware such as the processor and hard disk in the computer is also added (such as detecting whether the computer hardware such as the processor and hard disk in the computer has been illegally replaced or tampered with), so as to guarantee the reliability of the computer verification through a two-way verification method (the security verification of the BIOS code local to the computer and the legitimacy verification of the computer hardware based on the BIOS code).
[0034] Based on the above ideas, as an optional implementation, taking the BIOS code security verification including BIOS code legitimacy verification and BIOS code integrity verification as an example, the embodiment of the present application can burn the unique identifier of the computer hardware in the BIOS code of the BIOS chip to be configured by the computer when configuring the computer, and burn the BIOS verification information used for BIOS code security verification in the BIOS chip. In the optional implementation, the BIOS verification information can at least include: digital signature information, the digital signature information is the result of encrypting the BIOS summary corresponding to the BIOS code by the BIOS private key; in a further optional implementation, the BIOS verification information can also include: digital certificate information, the digital certificate information is the result of encrypting the BIOS public key by the digital certificate private key, and the BIOS public key corresponds to the BIOS private key.
[0035] As an optional implementation, when configuring a computer, the embodiment of the present application can also burn a digital certificate public key corresponding to a digital certificate private key in a processor (such as a CPU) to be configured in the computer. Thus, when the computer is configured and powered on, the processor in the computer can decrypt the digital certificate information of the BIOS chip through the pre-burned digital certificate public key to obtain the BIOS public key; and then the processor can use the BIOS public key to decrypt the digital signature information of the BIOS chip, so as to achieve secondary BIOS code legitimacy verification through the decryption of the digital certificate information by the digital certificate public key and the decryption of the digital signature information by the BIOS public key.
[0036] After the BIOS code legitimacy verification passes, the processor can verify whether the BIOS code is complete based on the BIOS digest obtained from the digital signature information to implement BIOS code integrity verification. After both the BIOS code legitimacy verification and the BIOS code integrity verification pass, the processor can confirm that the BIOS code security verification passes, so that the processor can run the BIOS code to start the computer power-on initialization work. During the computer power-on initialization work, the processor can use the BIOS code to verify the computer hardware (for example, based on the BIOS code power-on self-test program, verify the computer hardware), and in the process of verifying the computer hardware, the unique identification of the computer hardware pre-saved in the BIOS code is used to verify the legitimacy of the computer hardware, thereby combining the BIOS code security verification before the BIOS code runs, and the computer hardware legitimacy verification during the BIOS code running process, to achieve two-way verification in the computer power-on stage, to provide support for improving the reliability of computer verification.
[0037] As an optional implementation, Figure 1 An optional block diagram of a computer configuration system provided by an embodiment of the present application is shown exemplarily.Figure 1 The computer configuration system shown can, during the stage of configuring a computer (such as the assembly and manufacturing stage of the computer), configure relevant information and relevant keys for the BIOS chip and the processor to be configured in the computer, so as to provide a basis for the two-way verification in the embodiments of the present application (the security verification of the BIOS code locally in the computer and the legality verification of the computer hardware based on the BIOS).
[0038] As Figure 1 shown, the computer configuration system may include: a BIOS configuration device system 110 and a digital certificate device system 120. For the BIOS chip and the processor whose configurations in the computer have been determined, the BIOS configuration device system 110 can configure information for the BIOS chip to be configured in the computer, and the digital certificate device system 120 can configure information for the processor and the BIOS chip to be configured in the computer.
[0039] When the configuration of the computer is determined, the computer may include a BIOS chip with a determined configuration and multiple computer hardware components. The computer hardware includes a processor (CPU) and other computer hardware components, such as hardware devices like hard disks and memories. In one example, during the production process of the BIOS chip, the processor, and other computer hardware components, it can be determined which computer the produced BIOS chip, processor, and other computer hardware components are to be configured and assembled into, thereby enabling the computer to determine its configuration. For example, the BIOS chip, the processor, and other computer hardware components have determined their association relationships during the production process and are subsequently configured into the same computer based on these association relationships (for example, assembled into the same computer based on the association relationships).
[0040] The BIOS configuration device system 110 can be a device system responsible for configuring information for the BIOS chip to be configured in the computer, and the device system can be composed of one or more devices. Optionally, the BIOS configuration device system 110 can generate a BIOS public key and a BIOS private key, and save the unique identifier of the computer hardware to be configured in the computer in the BIOS code; thus, the BIOS configuration device system 110 can use the BIOS private key to encrypt the BIOS digest corresponding to the BIOS code to obtain digital signature information; and the BIOS configuration device system 110 can obtain digital certificate information from the digital certificate device system 120; furthermore, the BIOS configuration device system 110 can burn the BIOS code, the digital signature information, and the digital certificate information into the BIOS chip to be configured in the computer.
[0041] The BIOS configuration device system has information configuration and control authority for the BIOS chip. In some embodiments, the BIOS configuration device system may be a device system used by a provider of the BIOS chip, such as a BIOS manufacturer device system (such as a service device system such as a server of a BIOS manufacturer), a motherboard manufacturer device system (such as a service device system such as a server of a motherboard manufacturer), etc.
[0042] The digital certificate device system 120 can be a trusted CA (Certificate Authority) device system, or it can be implemented by a processor manufacturer device system when the processor manufacturer can be trusted. Optionally, the digital certificate device system 120 can generate a digital certificate private key and a digital certificate public key, wherein the digital certificate private key can be used to encrypt the BIOS public key to generate digital certificate information, and the digital certificate public key can be burned into the processor (CPU) to be configured by the computer, for example, the digital certificate public key can be burned into the internal ROM (Read Only Memory) of the processor and solidified.
[0043] Optionally, the digital certificate device system can implement the following functions: issuing digital certificate information, the digital certificate information mainly proves the legitimacy of the user's public key, for example, the digital certificate information can list the user and the user's public key, and prove that the user legally owns the listed public key; in addition, the digital certificate device system is also responsible for the legitimacy verification of the public key in the public key system. In some embodiments, the digital certificate device system can be a CA device system used by CA, such as a service device system such as a CA server. As a third-party digital certificate issuing agency, CA needs to be trusted by processor manufacturers and BIOS manufacturers. In other embodiments, if the processor manufacturer and the BIOS manufacturer trust each other, the digital certificate device system can be implemented by the processor manufacturer's device system, such as a service device system such as a processor manufacturer's server.
[0044] based on Figure 1 The computer configuration system shown in the embodiment of the present application can burn the BIOS code (including the unique identification of the computer hardware), digital signature information, and digital certificate information into the BIOS chip and solidify it during the computer configuration stage (for example, the computer assembly or device manufacturing stage), and burn the digital certificate public key into the processor (such as the ROM of the processor) and solidify it, so as to provide a basis for the two-way verification of the embodiment of the present application.
[0045] As an optional implementation, Figure 2 The optional flow chart of the computer configuration method provided in the embodiment of the present application is shown as an example. Figure 2As shown, this process can be implemented by the BIOS configuration device system and the digital certificate device system. In an alternative implementation, the BIOS configuration device system, such as the BIOS vendor device system, the motherboard vendor device system, etc., is a device system that has information configuration and control permissions for the BIOS chip during the computer configuration phase; the digital certificate device system can be a trusted device system with the authority to issue digital certificate information, such as the CA device system, the processor vendor device system, etc. Referring to Figure 2 , the method process may include the following steps.
[0046] In step S210, the BIOS configuration device system generates a BIOS public key and a BIOS private key.
[0047] In the embodiment of the present application, the BIOS private key is used to encrypt the BIOS code of the BIOS chip, and the BIOS public key is the decryption key corresponding to the BIOS private key.
[0048] In an alternative implementation, the BIOS configuration device system can use a key generation tool to call a key algorithm to generate a pair of signature public and private key pairs including the BIOS public key and the BIOS private key. The key algorithms used by the key generation tool include, but are not limited to, asymmetric encryption algorithms. Among them, the asymmetric encryption algorithms such as the large integer factorization algorithm or the discrete logarithm algorithm, the large integer factorization algorithm includes, but is not limited to, RSA, DSA, ECDSA, Rabin, etc.; the discrete logarithm algorithm includes, but is not limited to, DH, DSA, ECC, ECDH, SM2, SM9, etc.
[0049] In an implementation example, taking the BIOS configuration device system as the BIOS vendor device system and using the SM2 algorithm as an example, the BIOS vendor can run the SM2 algorithm key generation tool in the BIOS vendor device system, so as to use the SM2 algorithm key generation tool to generate a pair of signature public and private key pairs: the BIOS vendor public key and the BIOS vendor private key. In the case of using the BIOS vendor device system as the BIOS configuration device system, the BIOS vendor public key is an alternative form of the BIOS public key, and the BIOS vendor private key is an alternative form of the BIOS private key. Of course, the BIOS configuration device system may also be the motherboard vendor device system, and the corresponding generated BIOS public key is, for example, the motherboard vendor public key, and the BIOS private key is, for example, the motherboard vendor private key. It should be noted that the SM2 algorithm is an asymmetric algorithm, a public key cryptography algorithm based on elliptic curve cryptography. The SM2 algorithm includes digital signature algorithms, key agreement protocols, public key encryption algorithms, etc.
[0050] In step S211, the BIOS configuration device system sends the BIOS public key to the digital certificate device system.
[0051] After the BIOS configuration device system generates the BIOS public key and the BIOS private key, it can send the BIOS public key to the digital certificate device system so that the digital certificate device system can authenticate the legality of the BIOS public key. In a further optional implementation, the BIOS configuration device system can protect the BIOS private key. For example, in the security server corresponding to the BIOS configuration device system, the BIOS private key is saved. As an implementation example, taking the BIOS configuration device system as the BIOS manufacturer device system, the BIOS manufacturer private key (an example of the BIOS private key) can be saved in the security server of the BIOS manufacturer to securely save the BIOS manufacturer private key, while the BIOS manufacturer public key (an example of the BIOS public key) can be sent to the digital certificate device system.
[0052] In step S212, the digital certificate device system generates a digital certificate public key and a digital certificate private key; among them, the digital certificate public key is burned into the processor to be configured by the computer.
[0053] In an optional implementation, the digital certificate device system can use a key generation tool to call a key algorithm to generate a pair of signature public and private key pairs including the digital certificate public key and the digital certificate private key. The type of key algorithm used by the key generation tool can refer to the corresponding description in the previous text.
[0054] In an implementation example, taking the digital certificate device system as the CA device system and using the SM2 algorithm as an example, the CA device system can run the SM2 algorithm key generation tool, so as to use the SM2 algorithm key generation tool to generate a pair of signature public and private key pairs: the CA center public key and the CA center private key. When using the CA device system as the digital certificate device system, the CA center public key is an optional form of the digital certificate public key, and the CA center private key is an optional form of the digital certificate private key.
[0055] In another implementation example, taking the digital certificate device system as the processor manufacturer device system and using the SM2 algorithm as an example, the processor manufacturer can run the SM2 algorithm key generation tool in the processor manufacturer device system, so as to use the SM2 algorithm key generation tool to generate a pair of signature public and private key pairs: the processor manufacturer public key and the processor manufacturer private key. When using the processor manufacturer device system as the digital certificate device system, the processor manufacturer public key is an optional form of the digital certificate public key, and the processor manufacturer private key is an optional form of the digital certificate private key.
[0056] For the digital certificate public key and digital certificate private key generated by the digital certificate device system, the digital certificate private key can be used to encrypt the BIOS public key to authenticate the legality of the BIOS public key, thereby indicating that the provider of the BIOS chip (such as the BIOS manufacturer or the motherboard manufacturer) legally owns the BIOS public key; the digital certificate public key can be burned into the ROM of the processor to be configured in the computer and solidified. After the processor chip is produced, the data in the ROM of the processor is solidified and cannot be modified, which can ensure the security of the digital certificate public key burned in the processor.
[0057] In an alternative implementation example, if the digital certificate device system is a CA device system, the CA device system can send the CA center public key to the processor manufacturer device system. Thus, based on the CA center public key obtained by the processor manufacturer device system, the processor manufacturer can burn the CA center public key into the ROM of the processor to be configured in the computer and solidify it during the processor production line. In an alternative implementation example, if the digital certificate device system is a processor manufacturer device system, the processor manufacturer can burn the processor manufacturer public key generated by the processor manufacturer device system into the ROM of the processor to be configured in the computer and solidify it during the processor production line.
[0058] In step S213, the digital certificate device system encrypts the BIOS public key according to the digital certificate private key to generate digital certificate information.
[0059] After the digital certificate device system generates the digital certificate public key and digital certificate private key and obtains the BIOS public key transmitted by the BIOS configuration device system, it can authenticate the legality of the BIOS public key. In the embodiments of the present application, the digital certificate device system can encrypt the BIOS public key according to the digital certificate private key to generate digital certificate information, so as to express the legality authentication result of the BIOS public key through the digital certificate information. In an alternative implementation, the digital certificate device system can call a key algorithm such as the SM2 algorithm and use the digital certificate private key to encrypt the BIOS public key to generate digital certificate information.
[0060] In one implementation example, taking the digital certificate device system as a CA device system and the BIOS configuration device system as a BIOS manufacturer device system as an example, the CA device system can call a key algorithm such as the SM2 algorithm and use the CA center private key (an example of the digital certificate private key) to encrypt the BIOS manufacturer public key (an example of the BIOS public key) to generate the digital certificate information of the BIOS manufacturer, thereby expressing that the BIOS manufacturer legally owns the BIOS manufacturer public key through the digital certificate information.
[0061] In another implementation example, taking the digital certificate device system as the device system of the processor manufacturer and the BIOS configuration device system as the device system of the BIOS manufacturer as an example, the device system of the processor manufacturer can call key algorithms such as the SM2 algorithm and use the private key of the processor manufacturer (an example of the private key of the digital certificate) to encrypt the public key of the BIOS manufacturer (an example of the public key of the BIOS) to generate the digital certificate information of the BIOS manufacturer.
[0062] In step S214, the digital certificate device system sends the digital certificate information to the BIOS configuration device system.
[0063] After generating the digital certificate information, the digital certificate device system can send the digital certificate information to the BIOS configuration device system so that the BIOS configuration device system can burn the digital certificate information into the BIOS chip to be configured in the computer. For example, in the case where the digital certificate device system is the CA device system, the CA device system can send the digital certificate of the BIOS manufacturer to the device system of the BIOS manufacturer so that the BIOS manufacturer can burn the digital certificate obtained by the device system of the BIOS manufacturer into the BIOS chip to be configured in the computer. Another example is that in the case where the digital certificate device system is the device system of the processor manufacturer, the device system of the processor manufacturer can send the digital certificate of the BIOS manufacturer to the device system of the BIOS manufacturer so that the BIOS manufacturer can burn the digital certificate obtained by the device system of the BIOS manufacturer into the BIOS chip to be configured in the computer.
[0064] In step S215, the BIOS configuration device system saves the unique identifier of the computer hardware to be configured in the computer in the BIOS code.
[0065] The provider of the BIOS chip (such as the BIOS manufacturer or the motherboard manufacturer, etc.) can collect the unique identifier of all or part of the computer hardware to be configured in the computer when the BIOS chip of the computer, as well as the computer hardware such as the processor and hard disk, has been configured, and use the BIOS configuration device system (the device system of the BIOS manufacturer or the device system of the motherboard manufacturer) to save the collected unique identifier of the computer hardware in the BIOS code. In an alternative implementation, the unique identifier of the computer hardware can be the unique ID of the computer hardware. For example, the product serial number of the computer hardware is used to uniquely identify the computer hardware. In one example, the unique ID of the processor (such as the product serial number of the processor) is used to uniquely identify the processor, and the unique ID of the hard disk (such as the product serial number of the hard disk) is used to uniquely identify the hard disk.
[0066] In the embodiments of the present application, in addition to saving the basic code information for implementing the basic functions of the BIOS, the BIOS code also saves the unique identifier of the computer hardware of the computer, so as to provide a data basis for the subsequent legal verification of the computer hardware. Optionally, the basic code information for implementing the basic functions of the BIOS includes, for example, basic input / output program information, system setting information, power-on self-test program information, and system self-start program information, etc. In an alternative implementation, the BIOS configuration device system can save the unique identifiers (such as product serial numbers) of computer hardware such as the processor and hard disk to be configured by the computer into the BIOS code to generate a BIOS image, thereby realizing the generation of the BIOS code that saves the unique identifier of the computer hardware.
[0067] In step S216, the BIOS configuration device system generates a BIOS digest corresponding to the BIOS code.
[0068] Based on the fact that the BIOS code saves the basic code information for implementing the basic functions of the BIOS and the unique identifier of the computer hardware, the BIOS configuration device system can generate a BIOS digest corresponding to the BIOS code. The BIOS digest can be used to verify the integrity of the BIOS code during the security verification phase of the BIOS code, such as verifying whether the BIOS code has been tampered with, etc.
[0069] In an alternative implementation, the BIOS configuration device system can call a digest generation algorithm to generate a BIOS digest corresponding to the BIOS code. Digest generation algorithms include, for example, algorithms with the ability to generate information digests such as hash algorithms and hashing algorithms. Optionally, hashing algorithms or hash algorithms include, for example, MD5, SHA-1, SHA-2, SM3, etc. In an exemplary implementation, the BIOS configuration device system can call the SM3 algorithm to calculate the hash value of the BIOS image to generate a BIOS digest. It should be noted that the SM3 algorithm is a hashing algorithm, which is applicable to digital signature and verification, generation and verification of message authentication codes, and can meet the application requirements of electronic authentication service systems and other applications in combination with other cryptographic algorithms.
[0070] In step S217, the BIOS configuration device system encrypts the BIOS digest according to the BIOS private key to generate digital signature information.
[0071] After the BIOS configuration device system generates the BIOS digest of the BIOS code, it can further encrypt the BIOS digest according to the previously generated BIOS private key to obtain digital signature information. In the embodiments of the present application, the digital signature information is used to verify the legality of the BIOS code during the security verification phase of the BIOS code.
[0072] It should be noted that since the BIOS private key corresponds to the BIOS public key, and the digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key, after proving the legality of the digital certificate information (the legality of the digital certificate information can be proved by whether the digital certificate public key pre-stored in the processor can successfully decrypt the digital certificate information), if the BIOS private key used to encrypt the BIOS digest corresponds to the BIOS public key in the digital certificate information, it can prove the legality and correctness of the BIOS private key, that is, it can prove that the BIOS private key in the BIOS chip belongs to a legal and correct provider; if the BIOS private key used to encrypt the BIOS digest does not correspond to the BIOS public key in the digital certificate information, it means that the BIOS private key is incorrect, that is, it cannot prove that the BIOS private key in the BIOS chip belongs to a legal and correct provider.
[0073] In an optional implementation, the BIOS configuration device system can call key algorithms such as the SM2 algorithm to encrypt the BIOS digest with the BIOS private key to generate digital signature information. For example, the BIOS manufacturer's device system can call key algorithms such as the SM2 algorithm to encrypt the BIOS digest with the BIOS manufacturer's private key to generate a digital signature.
[0074] In the embodiment of the present application, the BIOS code, digital signature information, and digital certificate information recorded by the BIOS configuration device system can be burned into the BIOS chip to be configured by the computer.
[0075] Optionally, based on the BIOS code, digital signature information generated by the BIOS configuration device system, and the digital certificate information obtained from the digital certificate device system, the BIOS chip provider (such as the BIOS manufacturer) can burn the BIOS code, digital signature information, and digital certificate information into the BIOS chip to be configured by the computer to solidify the BIOS code, digital signature information, and digital certificate information in the BIOS chip. In an implementation example, the BIOS manufacturer can, based on the BIOS code, digital signature information, and digital certificate information recorded in the BIOS configuration device system, burn the BIOS code, digital signature information, and digital certificate information into the BIOS chip to be configured by the computer on the BIOS chip production line.
[0076] Based on the computer configuration method provided by the embodiments of the present application, in the configuration stages such as the assembly and manufacturing of a computer, through the interaction between a digital certificate device system (such as a CA device system, a processor manufacturer device system, etc.) and a BIOS configuration device system (such as a BIOS manufacturer device system, a motherboard manufacturer device system, etc.), the processor manufacturer can burn and solidify relevant information and relevant keys in the ROM of the processor, and the BIOS chip provider can burn relevant information and relevant keys in the BIOS chip. In one example, Figure 3 An exemplary diagram showing the information burned in the processor and the BIOS chip in the embodiments of the present application is provided for reference.
[0077] As Figure 3 shown, the BIOS chip is burned with BIOS code, digital signature information, and digital certificate information. Among them, in addition to the basic code information for implementing the basic functions of the BIOS, the BIOS code also has a unique identifier of the computer hardware, which is used to verify the legality of the computer hardware. The digital signature information is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS private key; among them, the BIOS digest is used to verify the integrity of the BIOS code in the security verification stage of the BIOS code; the encrypted digital signature information is used to verify the legality of the BIOS code (such as verifying whether the BIOS private key belongs to the correct and legal provider) in combination with the BIOS public key in the digital certificate information (when the digital certificate information can be successfully decrypted) in the security verification stage of the BIOS code. The digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key, and the digital certificate public key is burned and solidified in the ROM of the processor, which is used to verify the legality of the BIOS code (such as verifying whether the digital certificate private key belongs to the correct and legal provider) by whether the digital certificate public key can correctly decrypt the digital certificate information in the BIOS chip in the security verification stage of the BIOS code.
[0078] Based on the relevant information and keys burned in the processor and the BIOS chip of the computer, the embodiments of the present application can, when the computer is powered on and turned on, have the processor verify the security of the BIOS code (such as verifying the legality and integrity of the BIOS code). Thus, after the security verification of the BIOS code passes, the processor can run the BIOS code to start the power-on initialization work of the computer, and then verify the computer hardware during the power-on initialization work of the computer, and add the verification of the legality of the computer hardware during the verification process of the computer hardware.
[0079] As an optional implementation, Figure 4An optional flowchart of the verification method provided by the embodiments of the present application is exemplarily shown. This method flow can be implemented by a processor (CPU). Referring to Figure 4 , the method flow may include the following steps.
[0080] In step S410, in response to a computer power-on startup instruction, read the BIOS code, digital signature information, and digital certificate information from the BIOS chip.
[0081] In the embodiments of the present application, when the computer is powered on and starts up, the BIOS code is not directly loaded and run by the computer's processor to perform the computer power-on initialization work. Instead, the processor first reads the BIOS code, digital signature information, and digital certificate information to perform security verification on the BIOS code. Therefore, when the computer is powered on and starts up, the processor can detect the computer power-on startup instruction and run; when the processor runs, it can read the BIOS code, digital signature information, and digital certificate information from the BIOS chip. As described above, the digital signature information is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS private key; the digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key; the BIOS private key corresponds to the BIOS public key.
[0082] In step S411, verify whether the digital certificate information is legal according to the pre-saved digital certificate public key. If not, execute step S412; if so, execute step S413.
[0083] The digital certificate public key is pre-burned and solidified in the ROM of the processor. After the processor reads the digital certificate information from the BIOS chip, the processor can use the pre-saved digital certificate public key to verify whether the digital certificate information is legal to implement the first-level legality verification of the BIOS code; if the digital certificate information is illegal, enter step S412; if the digital certificate information is legal, enter step S413. In an optional implementation, the processor can decrypt the digital certificate information according to the pre-saved digital certificate public key and verify whether the digital certificate information is legal based on whether the decryption process is successful; if the decryption process is successful (that is, the digital certificate information can be successfully decrypted using the digital certificate public key), it is confirmed that the digital certificate information is legal; if the decryption process fails (that is, the digital certificate information cannot be decrypted using the digital certificate public key), it is confirmed that the digital certificate information is illegal.
[0084] It should be noted that the digital certificate public key and the digital certificate private key are a one-to-one public-private key pair generated by the digital certificate device system and have a unique correspondence. When the digital certificate information is encrypted with the BIOS public key using a legitimate digital certificate private key, it can be successfully decrypted by the corresponding legitimate digital certificate public key. If the processor fails to successfully decrypt the digital certificate information when using the corresponding legitimate digital certificate public key to decrypt the digital certificate information, it means that the digital certificate information may not be encrypted using a legitimate digital certificate private key and there is a possibility that the digital certificate information has been illegally tampered with.
[0085] In an optional implementation, the processor can call a key algorithm such as the SM2 cryptographic algorithm, and use the pre-saved digital certificate public key (the digital certificate public key solidified in the ROM) to decrypt the digital certificate information, so as to verify whether the digital certificate information is legal by checking whether the decryption process is successful. In one example, taking the digital certificate public key as the CA center public key as an example, the processor can call a key algorithm such as the SM2 cryptographic algorithm, and use the CA center public key pre-solidified in the ROM to decrypt the digital certificate information, so as to verify whether the digital certificate information is legal by checking whether the decryption process is successful. In another example, taking the digital certificate public key as the processor manufacturer public key as an example, the processor can call a key algorithm such as the SM2 cryptographic algorithm, and use the processor manufacturer public key pre-solidified in the ROM to decrypt the digital certificate information, so as to verify whether the digital certificate information is legal by checking whether the decryption process is successful.
[0086] In step S412, the computer is stopped and a prompt is given.
[0087] In the case of verifying that the digital certificate information is illegal, the digital certificate information of the BIOS chip may be illegally tampered with, so if the computer continues to run, there may be a security risk. At this time, the processor can stop the computer and give a prompt. Optionally, the prompt method may be outputting a warning sound, displaying a prompt pop-up window, etc. For example, the pop-up window content may prompt that the reason why the computer stopped running is that the digital certificate information of the BIOS chip is illegal.
[0088] In step S413, the BIOS public key decrypted from the digital certificate information is obtained, and the digital signature information is verified to be legal based on the BIOS public key. If not, step S412 is executed; if yes, step S414 is executed.
[0089] Based on the fact that the digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key, when the digital certificate information is verified to be legal, the processor can successfully decrypt the BIOS public key from the digital certificate information according to the digital certificate public key. Therefore, the processor can obtain the BIOS public key. After the processor obtains the BIOS public key, based on the legality of the BIOS public key, it can be shown that the BIOS public key is the key legally owned by the provider of the BIOS chip for this BIOS chip. Therefore, the processor can verify whether the digital signature information is legal based on the BIOS public key to achieve the second-level legality verification of the BIOS code.
[0090] In an alternative implementation, the processor can decrypt the digital signature information according to the BIOS public key and verify whether the digital signature information is legal based on whether the decryption process is successful. If the decryption process is successful (i.e., the digital signature information can be successfully decrypted using the BIOS public key), it is confirmed that the digital signature information is legal, that is, the digital signature information is encrypted using the BIOS private key corresponding to the legal BIOS public key, which can prove the legality of the BIOS code (for example, the BIOS private key belongs to the correct BIOS manufacturer). If the decryption process is not successful (i.e., the digital signature information cannot be decrypted using the BIOS public key), it is confirmed that the digital signature information is illegal, that is, the private key used to encrypt the digital signature information does not correspond to the legal BIOS public key and cannot prove the legality of the BIOS code.
[0091] In an alternative implementation, the processor can call key algorithms such as the SM2 cryptographic algorithm, use the BIOS public key, and decrypt the digital signature information to verify whether the digital signature information is legal based on whether the decryption process is successful. In one example, taking the BIOS public key as the BIOS manufacturer's public key, correspondingly, the digital signature information is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS manufacturer's private key. Then the processor can call key algorithms such as the SM2 cryptographic algorithm, use the BIOS manufacturer's public key, and decrypt the digital signature information to verify whether the digital signature information is legal based on whether the decryption process is successful.
[0092] When the digital signature information is verified to be illegal, the processor can stop the computer from running and give a prompt. Optionally, the prompt method can be, for example, outputting a prompt warning sound, displaying a prompt pop-up window, etc. By way of example, the content of the pop-up window can prompt that the reason for the computer to stop running is that the digital signature information of the BIOS chip is illegal, etc.
[0093] In step S414, obtain the BIOS digest decrypted from the digital signature information and regenerate the BIOS digest corresponding to the BIOS code.
[0094] Based on the fact that the digital signature information is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS private key, when the digital signature information is verified to be legal, the processor can successfully decrypt the BIOS digest from the digital signature information according to the BIOS public key. Therefore, the processor can obtain the BIOS digest. After the processor obtains the BIOS digest, the processor can regenerate the BIOS digest for the BIOS code to verify whether the BIOS code is complete by comparing the BIOS digests, so as to realize the verification of the integrity of the BIOS code.
[0095] In an alternative implementation, the processor can call a digest generation algorithm such as the SM3 algorithm to calculate the hash value of the BIOS code to obtain the regenerated BIOS digest.
[0096] In step S415, according to the BIOS digest decrypted from the digital signature information and the regenerated BIOS digest, verify whether the BIOS code is complete. If not, execute step S412. If so, execute step S416.
[0097] After the processor regenerates the BIOS digest corresponding to the BIOS code, it can compare the BIOS digest decrypted from the digital signature information with the regenerated BIOS digest, so as to verify whether the BIOS code is complete through the comparison result; if the comparison result of the BIOS digest decrypted from the digital signature information and the regenerated BIOS digest is consistent, it means that the BIOS code has not been tampered with, the BIOS code is complete, and the integrity verification of the BIOS code passes; if the comparison result is inconsistent, it means that the BIOS code has been tampered with, the BIOS code is incomplete, and the integrity verification of the BIOS code fails.
[0098] When it is verified that the BIOS code is incomplete, the processor can stop the computer from running and give a prompt. Optionally, the prompt method can be, for example, outputting a prompt warning sound, displaying a prompt pop-up window, etc. By way of example, the content of the pop-up window can prompt that the reason for the computer to stop running is that the BIOS code is incomplete, etc.
[0099] In step S416, run the BIOS code to start the power-on initialization work of the computer, and the work includes verifying the computer hardware.
[0100] When the processor verifies that the BIOS code is complete, the processor can confirm that the BIOS code passes the legality verification and integrity verification, so that the processor can load and run the BIOS code to start the power-on initialization of the computer by running the BIOS code. The power-on initialization of the computer started by the processor running the BIOS code can be, for example, system settings, power-on self-test, etc. Among them, the power-on self-test can implement computer hardware verification (for example, through the power-on self-test program, computer hardware verification is performed). During the computer hardware verification process, the processor can verify the legality of the computer hardware based on the unique identifier of the computer hardware pre-stored in the BIOS code.
[0101] In step S417, during the process of verifying the computer hardware, according to the unique identifier of the computer hardware pre-stored in the BIOS code, verify whether the computer hardware of the computer is legal. If not, execute step S412. If so, execute step S418.
[0102] Optionally, the processor can verify the computer hardware by running the power-on self-test program of the BIOS code, and add the legality verification of the computer hardware when verifying the computer hardware. For example, the embodiment of the present application can add the legality verification logic of the computer hardware to the power-on self-test program of the BIOS code, so that the processor can verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code during the process of running the BIOS code and verifying the computer hardware.
[0103] In an alternative implementation, the processor can read the identifier of the computer hardware, compare the read identifier of the computer hardware with the unique identifier of the corresponding computer hardware pre-stored in the BIOS code. If the comparison result is consistent, the computer hardware is verified to be legal. If the comparison result is inconsistent, the computer hardware is verified to be illegal (for example, there is a situation of tampering or replacement of the computer hardware in the computer). Optionally, the BIOS code can store the unique identifiers of all or part of the computer hardware in the computer, so that based on the type of computer hardware for which the unique identifier is pre-stored in the BIOS code, the processor can read the identifier of the corresponding type of computer hardware; and then compare the read identifiers of each type of computer hardware with the unique identifiers of the corresponding type of computer hardware stored in the BIOS code; if all comparison results are consistent, the computer hardware is verified to be legal. If any comparison result is inconsistent, the computer hardware is verified to be illegal.
[0104] In an implementation example, taking the BIOS code that stores the IDs of the CPU, hard disk, and other devices as an example, the processor can read the ID of the CPU, the ID of the hard disk, and the IDs of each other device; thus, the processor can compare the read ID of the CPU with the ID of the CPU stored in the BIOS code, compare the read ID of the hard disk with the ID of the hard disk stored in the BIOS code, and compare the read IDs of each other device with the IDs of the corresponding devices stored in the BIOS code respectively; if all comparison results are consistent, the computer hardware is verified as legal, and if any of the comparison results is inconsistent, the computer hardware is verified as illegal.
[0105] In an alternative implementation, the computer hardware verification process involves a functional test of the computer hardware. During the process of running the BIOS code, the processor can read the identification of the computer hardware either before performing the functional test of the computer hardware, so as to verify whether the computer hardware of the computer is legal based on the unique identification of the computer hardware stored in the BIOS code and the read identification of the computer hardware. In an alternative implementation, during the process of running the BIOS code, the processor can also read the identification of the computer hardware after performing the functional test of the computer hardware, and verify whether the computer hardware of the computer is legal based on the unique identification of the computer hardware stored in the BIOS code and the read identification of the computer hardware. In an alternative implementation, during the process of running the BIOS code, the processor can also read the identification of the computer hardware in real time. For example, for the currently tested computer hardware, the BIOS chip can read the identification of the currently tested computer hardware in real time, so as to verify whether the identification of the currently tested computer hardware is consistent with the corresponding unique identification stored in the BIOS code based on the unique identification of the computer hardware stored in the BIOS code and the identification of the currently tested computer hardware. It should be noted that the present application embodiment does not limit the verification timing of the legality verification of the computer hardware, and it can be set at any node during the computer verification process.
[0106] In step S418, continue to run the computer.
[0107] If the computer hardware in the computer is verified as illegal, it indicates that there may be an illegal replacement of the computer hardware in the computer. To reduce the risk of computer operation, the BIOS chip can stop the computer from running and give a prompt. Optionally, the prompt method can be, for example, outputting a prompt warning sound, displaying a prompt pop-up window, etc. By way of example, the content of the pop-up window can prompt the reason for the computer to stop running, such as the illegal replacement of the computer hardware (such as the type of the illegally replaced computer hardware can be prompted).
[0108] If the computer hardware in the verification computer is legal, the computer can continue to run; for example, after other verifications of the computer pass, the operating system boot record can be read in, and the operating system is started by the operating system boot record.
[0109] The verification method provided by the embodiments of this application can, when the computer is powered on and booted, perform a security verification on the BIOS code by the processor in the computer, and the security verification of the BIOS code includes a two-level BIOS code legality verification (legality verification based on digital certificate information and legality verification based on digital signature information), and BIOS code integrity verification. Thus, the processor can respond to the computer power-on and boot instruction, read the BIOS code, digital signature information, and digital certificate information from the BIOS chip; wherein, the BIOS code stores the unique identifier of the computer hardware of the computer, and the digital signature information is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS private key, and the digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key, and the BIOS private key corresponds to the BIOS public key; furthermore, the processor can verify whether the digital certificate information is legal according to the pre-stored digital certificate public key. If the digital certificate information is legal, the processor can obtain the BIOS public key decrypted from the digital certificate information, and verify whether the digital signature information is legal according to the BIOS public key; if the digital signature information is legal, the processor can obtain the BIOS digest decrypted from the digital signature information, and regenerate the BIOS digest corresponding to the BIOS code; according to the BIOS digest decrypted from the digital signature information and the regenerated BIOS digest, the processor can verify whether the BIOS code is complete; if the BIOS code is complete, the processor can run the BIOS code to start the work of computer power-on initialization, and the work includes verifying the computer hardware; during the process of verifying the computer hardware, the processor can verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code, so as to verify the legality of the computer hardware. Therefore, the embodiments of this application can, at the computer power-on and boot stage, implement the security verification of the BIOS code by the processor and the legality verification of the computer hardware during the process of the processor running the BIOS code.
[0110] It can be seen that the embodiments of this application can, at the computer power-on and boot stage, through the two-way verification of the BIOS code security verification and the computer hardware legality verification, ensure the reliability of the computer verification, so as to comprehensively detect whether the computer has been attacked, damaged, or tampered with (including the situation where the BIOS code has been attacked, damaged, or tampered with, and the situation where the computer hardware has been attacked, damaged, or tampered with), avoid the security risks of the computer running in the case of being attacked, damaged, or tampered with, and improve the security of the computer.
[0111] Furthermore, in the embodiments of the present application, the verification party of the BIOS is set to the processor on the local computer, and a key (such as the public key of a digital certificate) for verifying the security of the BIOS is solidified in the ROM of the processor, which can at least avoid the following problems brought by the remote server for verifying the BIOS: it can avoid the situation of remotely transmitting BIOS-related data to the remote server, reduce the setup cost of the remote server, and reduce the risk of the computer data being stolen or intercepted during remote transmission.
[0112] It should be noted that Figure 2 and Figure 4 are the optional configuration processes of the computer and the optional processes of computer verification when the BIOS code security verification includes two-level BIOS code legality verification (legality verification based on digital certificate information and legality verification based on digital signature information) and BIOS code integrity verification. Under the idea of two-way verification of BIOS code security verification and computer hardware legality verification, the embodiments of the present application do not limit the specific manner of BIOS code security verification.
[0113] In other possible implementation manners, the BIOS code security verification may include first-level BIOS code legality verification (legality verification based on digital signature information) and BIOS code integrity verification; correspondingly, in the configuration stage of the computer, the embodiments of the present application may support not configuring the public key of the digital certificate and the certificate key. For example, when trusting the BIOS manufacturer and not requiring a third party to authenticate the BIOS public key, the processor manufacturer can directly obtain the BIOS public key from the BIOS manufacturer and burn the BIOS public key into the ROM of the processor for solidification; thus, when the computer is powered on and booted, the processor can obtain the BIOS code and digital signature information, and directly verify whether the digital signature information is legal according to the pre-saved BIOS public key; when the processor verifies that the digital signature information is legal, the processor can obtain the BIOS digest decrypted from the digital signature information and regenerate the BIOS digest corresponding to the BIOS code to verify whether the BIOS code is complete through the comparison of the BIOS digests; when the BIOS code is verified to be complete, the processor can run the BIOS code to start the power-on initialization work of the computer, and then verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-saved in the BIOS code.
[0114] It should be noted that the specific methods and forms of BIOS code security verification can be selected and determined according to the actual situation. When the BIOS code in the BIOS chip stores the unique identifier of the computer hardware, in the embodiments of the present application, after the BIOS code security verification passes, during the computer hardware verification based on the BIOS, the legitimacy verification of the computer hardware can be added, so as to ensure the reliability of computer verification through two-way verification and improve the security of the computer.
[0115] As an optional implementation, Figure 5 Another optional flowchart of the verification method provided by the embodiments of the present application is exemplarily shown. This method flow can be implemented by a processor. Referring to Figure 5 , this method flow may include the following steps.
[0116] In step S510, in response to a computer power-on boot instruction, read the BIOS code and BIOS verification information from the computer's BIOS chip, where the BIOS code stores the unique identifier of the computer hardware.
[0117] In step S511, perform BIOS code security verification according to the BIOS code and the BIOS verification information.
[0118] In some embodiments, the BIOS code security verification includes BIOS code legitimacy verification and BIOS code integrity verification. Among them, the BIOS code legitimacy verification can be implemented based on the BIOS verification information, and the BIOS code integrity verification can be implemented based on the BIOS code. That is to say, the BIOS code security verification includes BIOS code legitimacy verification based on the BIOS verification information and BIOS code integrity verification based on the BIOS code.
[0119] In an optional implementation, the BIOS verification information may at least include digital signature information, and the digital signature information is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS private key. Thus, when the processor performs BIOS code security verification, it can obtain the BIOS public key corresponding to the BIOS private key (the BIOS public key can be decrypted by the processor from the digital certificate information or can be pre-saved by the processor); according to the BIOS public key, verify whether the digital signature information is legal; if the digital signature information is legal, obtain the BIOS digest decrypted from the digital signature information and regenerate the BIOS digest corresponding to the BIOS code; furthermore, according to the BIOS digest decrypted from the digital signature information and the regenerated BIOS digest, verify whether the BIOS code is complete; where if the BIOS code is verified to be complete, the BIOS code security verification passes.
[0120] In an implementation example, if the BIOS code security verification includes two - level BIOS code legality verification (legality verification based on digital certificate information and legality verification based on digital signature information), and BIOS code integrity verification, the BIOS verification information read by the processor from the BIOS chip may include digital certificate information and digital signature information. Correspondingly, the optional process for the processor to perform BIOS code security verification may refer to Figure 4 the process shown, which will not be elaborated here.
[0121] In other optional implementations, if the BIOS code security verification includes one - level BIOS code legality verification (legality verification based on digital signature information), and BIOS code integrity verification, the BIOS verification information read by the processor from the BIOS chip may include digital signature information. Correspondingly, when the processor performs BIOS code security verification, it can verify whether the digital signature information is legal according to the pre - saved BIOS public key; when the digital signature information is legal, obtain the BIOS digest decrypted from the digital signature information, and regenerate the BIOS digest corresponding to the BIOS code; furthermore, compare the BIOS digest decrypted from the digital signature information with the regenerated BIOS digest to verify whether the BIOS code is complete.
[0122] In step S512, if the BIOS code security verification passes, run the BIOS code to start the power - on initialization work of the computer, and the work includes verifying the computer hardware.
[0123] In step S513, during the process of verifying the computer hardware, verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre - saved in the BIOS code.
[0124] Optionally, during the process of verifying the computer hardware, the processor can read the identifier of the computer hardware, compare the read identifier of the computer hardware with the unique identifier of the corresponding computer hardware pre - saved in the BIOS code. If the comparison result is consistent, the computer hardware is verified as legal; if the comparison result is inconsistent, the computer hardware is verified as illegal; if the computer hardware is verified as illegal, the processor can stop the computer from running and give a prompt; if the computer hardware is verified as legal, the processor can continue to run the computer.
[0125] The verification method provided by the embodiments of the present application can, when the computer is powered on and booted, perform security verification on the BIOS code by the processor in the computer. Thus, the processor can respond to the computer power-on and boot instruction, read the BIOS code and BIOS verification information from the BIOS chip of the computer, wherein the unique identifier of the computer hardware of the computer is pre-stored in the BIOS code; furthermore, the processor can perform BIOS code security verification according to the BIOS code and the BIOS verification information; after the BIOS code security verification passes, the processor can run the read BIOS code to start the work of computer power-on initialization, and the work includes verifying the computer hardware; during the process of verifying the computer hardware, the processor can verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code, so as to perform the legality verification of the computer hardware. Therefore, the verification method provided by the embodiments of the present application can, at the computer power-on and boot stage, implement the security verification of the BIOS code by the processor and the legality verification of the computer hardware after the BIOS code runs.
[0126] It can be seen that the embodiments of the present application can, at the computer power-on and boot stage, ensure the reliability of computer verification through two-way verification of BIOS code security verification and computer hardware legality verification, so as to comprehensively detect whether the computer has been attacked, damaged, or tampered with (including the situation where the BIOS code has been attacked, damaged, or tampered with, and the situation where the computer hardware has been attacked, damaged, or tampered with), avoid the security risks of the computer running in the case of being attacked, damaged, or tampered with, and improve the security of the computer.
[0127] It should be noted that in the prior art, before the computer starts, the processor does not know the number of computer hardware existing in the computer, but when the processor runs the BIOS code, it determines the number of computer hardware in the computer by reading the register information related to the computer hardware information. For example, taking the hard disk as an example, the working mechanism of the BIOS is to determine the number of hard disks in the computer by reading the register that shows the number of hard disks in place after initializing the hard disk controller. Therefore, from the BIOS working mechanism of the prior art, in the prior art, the BIOS chip does not pre-store the unique identifiers such as the ID of the computer hardware in advance. However, the solution provided by the embodiments of the present application can solidify the IDs of computer hardware such as the CPU and hard disk configured in the computer into the BIOS code, and perform the legality verification of the computer hardware during computer verification, so that the computer hardware of the computer cannot be randomly deleted and replaced. Thus, when the BIOS code uniquely identifies the computer hardware of the computer, the security of the computer can be enhanced.
[0128] For example, the BIOS code is run by a processor to reverse-verify the legality of computer hardware through the ID of the computer hardware, which can prevent the computer hardware from being illegally replaced with different models of computer hardware from the same manufacturer and avoid problems that may arise from simply verifying the computer hardware through manufacturer information. In one example, taking the CPU (an example of a processor) as an example, the performance of CPUs of the same manufacturer but different models may vary. Then, replacing the high-performance CPU in the computer with a low-performance CPU of the same manufacturer (i.e., the performance of the replaced CPU is lower than that of the original CPU and they are CPUs of the same manufacturer but different models), or even cloning a low-performance CPU into a high-performance CPU of the same manufacturer, cannot be identified by verifying the manufacturer information of the CPU. Based on this, after the security verification of the BIOS passes, the embodiments of the present application use the ID of the CPU saved in the BIOS code to reverse-verify the legality of the ID of the current CPU in the computer, which can enhance the CPU security when the legal CPU of the computer is uniquely determined, reduce the occurrence of the situation where the CPU is replaced with a low-performance CPU of the same manufacturer, and avoid the situation where the configured CPU of the computer is illegally replaced and cannot be identified. In another example, taking the hard disk as an example, the embodiments of the present application do not verify the hard disk at the computer operating system level, and the verification basis is not the manufacturer information of the hard disk, but at the BIOS level (the startup source point of the computer). Based on the ID of the legal hard disk pre-saved in the BIOS code, the legality of the current hard disk in the computer is verified, which can reduce the occurrence of the situation where the hard disk is replaced with a low-performance hard disk of the same manufacturer and improve the hard disk security. The legality verification of other computer hardware devices can be similarly referred to and will not be elaborated here.
[0129] In a further optional implementation, when the user needs to replace computer hardware such as the CPU and hard disk in the computer configuration, the embodiments of the present application allow, through the process in the computer configuration stage (such as Figure 2 the process shown), a trusted device system with BIOS code configuration and control permissions (such as the BIOS manufacturer device system, the motherboard manufacturer device system, etc.) to rewrite the unique identifier of the replaced computer hardware into the BIOS code in the BIOS chip, so as to update the unique identifier of the computer hardware in the BIOS code and ensure that the legally replaced computer hardware can pass the legality verification by controlling the writing permission of the BIOS code while allowing the computer to legally replace computer hardware such as the CPU and hard disk.
[0130] The embodiment of the present application utilizes the security verification of BIOS and the legality verification of computer hardware, and can improve the reliability of computer verification through two-way verification, avoid running the computer when the BIOS is unsafe and the computer hardware is illegally replaced, and improve the security of the computer. In addition, by solidifying the key used for the security verification of BIOS code in the local processor of the computer, the security verification of BIOS is implemented by the local processor of the computer, which can avoid the cost problem caused by the remote verification of BIOS and the risk of computer data being stolen and intercepted during remote transmission, thereby reducing the cost of BIOS verification and improving the security of computer data.
[0131] The verification device provided in the embodiment of the present application is introduced below. The verification device described below can be regarded as a functional module required for the processor to implement the verification method provided in the embodiment of the present application. The content of the device described below can be referenced to the content described above.
[0132] As an optional implementation, Figure 6 An optional block diagram of a verification device provided in an embodiment of the present application is exemplarily shown. The verification device can be applied to a processor, referring to Figure 6 , the verification device may include:
[0133] The information reading module 610 is used to respond to the computer power-on instruction and read the BIOS code and BIOS verification information from the BIOS chip of the computer, wherein the BIOS code pre-stores the unique identification of the computer hardware of the computer;
[0134] A BIOS verification module 611, configured to perform BIOS code security verification according to the BIOS code and the BIOS verification information;
[0135] A code running module 612 is used to run the BIOS code if the BIOS code security verification passes, so as to start the computer power-on initialization work, which includes verifying the computer hardware;
[0136] The hardware verification module 613 is used to verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code during the process of verifying the computer hardware.
[0137] Optionally, the BIOS code security verification includes BIOS code legitimacy verification based on BIOS verification information, and BIOS code integrity verification based on the BIOS code.
[0138] Optionally, the BIOS verification information at least includes digital signature information, which is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS private key;
[0139] Correspondingly, the BIOS verification module 611 for performing BIOS code security verification based on the BIOS code and the BIOS verification information includes:
[0140] Obtain the BIOS public key corresponding to the BIOS private key; verify whether the digital signature information is legal according to the BIOS public key; if the digital signature information is legal, obtain the BIOS digest decrypted from the digital signature information and regenerate the BIOS digest corresponding to the BIOS code; verify whether the BIOS code is complete according to the BIOS digest decrypted from the digital signature information and the regenerated BIOS digest; wherein, if the BIOS code is complete, the BIOS code security verification passes.
[0141] Optionally, on the one hand, the BIOS verification information further includes digital certificate information, which is the result of encrypting the BIOS public key with the digital certificate private key;
[0142] Correspondingly, the BIOS verification module 611 for obtaining the BIOS public key corresponding to the BIOS private key includes:
[0143] Verify whether the digital certificate information is legal according to the pre-stored digital certificate public key; if the verification of the digital certificate information is legal, obtain the BIOS public key decrypted from the digital certificate information.
[0144] Optionally, on the other hand, the BIOS public key corresponding to the BIOS private key can be pre-stored in the processor, for example, the BIOS public key is pre-cured in the ROM of the processor.
[0145] Optionally, the verification device can also be used for:
[0146] If the verification of the digital certificate information is illegal, or the verification of the digital signature information is illegal, or the verification of the BIOS code is incomplete, it is confirmed that the BIOS code security verification fails, and the computer operation is stopped and a prompt is given.
[0147] Optionally, the hardware verification module 613 for verifying whether the computer hardware is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code during the verification of the computer hardware includes:
[0148] During the verification of the computer hardware, read the identifier of the computer hardware;
[0149] Compare the identified computer hardware read with the unique identifier of the corresponding computer hardware saved in the BIOS code; wherein, if the comparison result is consistent, the computer hardware is verified as legal, and if the comparison result is inconsistent, the computer hardware is verified as illegal.
[0150] Optionally, the verification device can also be used for:
[0151] If the computer hardware is verified as illegal, stop the computer from running and give a prompt;
[0152] If the computer hardware is verified as legal, continue to run the computer.
[0153] Optionally, the hardware verification module 613, when verifying the computer hardware, reads the identifier of the computer hardware including:
[0154] Read the identifier of the computer hardware before or after performing a function test on the computer hardware;
[0155] Or, for the currently detected computer hardware, read the identifier of the currently detected computer hardware.
[0156] Optionally, the BIOS public key is the BIOS manufacturer's public key or the motherboard manufacturer's public key; the BIOS private key is the BIOS manufacturer's private key corresponding to the BIOS manufacturer's public key, or the motherboard manufacturer's private key corresponding to the motherboard manufacturer's public key; the digital certificate public key is the CA center public key or the processor manufacturer's public key; the digital certificate private key is the CA center private key corresponding to the CA center public key, or the processor manufacturer's private key corresponding to the processor manufacturer's public key.
[0157] The embodiment of the present application also provides a computer, which can have data processing capabilities (such as a data processing computer). In one example, the computer is, for example, a server device (such as a cloud service device), or can also be a terminal (such as a personal computer). The computer can include a processor and a BIOS chip, wherein the processor is configured to execute the verification method provided by the embodiment of the present application. Further, the BIOS chip is configured with BIOS code and BIOS verification information, wherein the BIOS code pre-saves the unique identifier of the computer hardware of the computer.
[0158] In an alternative implementation, the processor can implement the verification method executed by the processor provided by the embodiment of the present application by setting a verification device as Figure 6 illustrated.
[0159] The embodiment of the present application also provides a computer configuration system, in combination with Figure 1As shown, the computer configuration system may include a BIOS configuration device system and a digital certificate device system; wherein, the BIOS configuration device system configures information for the BIOS chip to be configured by the computer, and the digital certificate device system configures information for the processor and the BIOS chip to be configured by the computer, and the computer is the computer provided in the embodiments of the present application.
[0160] Optionally, the BIOS configuration device system is a device system that has information configuration and control authority over the BIOS chip of the computer; the digital certificate device system is a trusted device system that has the authority to issue digital certificate information.
[0161] Optionally, the BIOS configuration device system is used for: generating a BIOS public key and a BIOS private key; sending the BIOS public key to the digital certificate device system, and obtaining the digital certificate information sent by the digital certificate device system, where the digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key generated by the digital certificate device system; saving the unique identifier of the computer hardware to be configured by the computer in the BIOS code; generating a BIOS digest corresponding to the BIOS code; encrypting the BIOS digest with the BIOS private key to generate digital signature information; wherein, the BIOS code, the digital signature information, and the digital certificate information are burned into the BIOS chip to be configured by the computer.
[0162] Optionally, the digital certificate device system is used for: generating a digital certificate public key and a digital certificate private key; encrypting the BIOS public key sent by the BIOS configuration device system with the digital certificate private key to generate digital certificate information, and sending the digital certificate information to the BIOS configuration device system; wherein, the digital certificate public key is burned into the processor to be configured by the computer.
[0163] Optionally, the digital certificate public key is burned into the internal ROM of the processor to be configured by the computer, so that after the processor chip is produced, the data in the ROM of the processor is solidified and cannot be modified, which can ensure the security of the digital certificate public key burned into the processor.
[0164] Optionally, the BIOS configuration device system is a BIOS manufacturer device system or a motherboard manufacturer device system; the BIOS public key is a BIOS manufacturer public key or a motherboard manufacturer public key; the BIOS private key is a BIOS manufacturer private key corresponding to the BIOS manufacturer public key, or a motherboard manufacturer private key corresponding to the motherboard manufacturer public key.
[0165] Optionally, the digital certificate device system is a CA device system or a processor manufacturer device system; the digital certificate public key is a CA center public key or a processor manufacturer public key; the digital certificate private key is a CA center private key corresponding to the CA center public key, or a processor manufacturer private key corresponding to the processor manufacturer public key.
[0166] The above describes multiple embodiment solutions provided by the embodiments of the present application. The various optional methods described in each embodiment solution can be combined and cross-referenced with each other without conflict, thereby extending a variety of possible embodiment solutions, all of which can be considered as the embodiment solutions disclosed and made public by the embodiments of the present application.
[0167] Although the embodiments of the present application are disclosed as above, the present application is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application should be subject to the scope defined by the claims.
Claims
1. A verification method, characterized in that, A processor applied to a computer, comprising: Responding to a computer power-on instruction, reading BIOS code and BIOS verification information from the computer's BIOS chip, wherein the BIOS chip is burned with BIOS code and BIOS verification information; the BIOS code pre-stores a unique identifier of the computer hardware of the computer; Performing BIOS code security verification according to the BIOS code and the BIOS verification information, the BIOS code security verification including BIOS code legality verification based on the BIOS verification information and BIOS code integrity verification based on the BIOS code; If the BIOS code security verification passes, running the BIOS code to start the work of computer power-on initialization, the work including verifying computer hardware; During the process of verifying computer hardware, verifying whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code; Wherein, the BIOS verification information at least includes digital signature information, and the digital signature information is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS private key; the internal ROM of the processor is burned with a digital certificate public key, and the BIOS verification information further includes digital certificate information, and the digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key; The performing BIOS code security verification according to the BIOS code and the BIOS verification information includes: Obtaining a BIOS public key corresponding to the BIOS private key, including: verifying whether the digital certificate information is legal according to the pre-stored digital certificate public key; if the digital certificate information is verified to be legal, obtaining the BIOS public key decrypted from the digital certificate information; Verifying whether the digital signature information is legal according to the BIOS public key; If the digital signature information is legal, obtaining the BIOS digest decrypted from the digital signature information and regenerating the BIOS digest corresponding to the BIOS code; Verifying whether the BIOS code is complete according to the BIOS digest decrypted from the digital signature information and the regenerated BIOS digest; wherein, if the BIOS code is complete, the BIOS code security verification passes.
2. The verification method according to claim 1, wherein The verification method further includes: If the digital certificate information is verified to be illegal, or the digital signature information is verified to be illegal, or the BIOS code is verified to be incomplete, it is confirmed that the BIOS code security verification fails, the computer operation is stopped and a prompt is given.
3. The verification method according to any one of claims 1-2, characterized in that, The during the process of verifying computer hardware, verifying whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code includes: During the process of verifying computer hardware, reading the identifier of the computer hardware; Compare the identified computer hardware read with the unique identifier of the corresponding computer hardware stored in the BIOS code; wherein, if the comparison result is consistent, the computer hardware is verified as legal, and if the comparison result is inconsistent, the computer hardware is verified as illegal.
4. The verification method according to claim 2, characterized in that, It further includes: If the computer hardware is verified as illegal, stop the computer from running and give a prompt. If the computer hardware is verified as legal, continue to run the computer.
5. The verification method according to claim 2, wherein During the process of verifying the computer hardware, reading the identifier of the computer hardware includes: Read the identifier of the computer hardware before or after performing a functional test on the computer hardware. Alternatively, for the currently detected computer hardware, read the identifier of the currently detected computer hardware.
6. The verification method according to claim 1 or 2, characterized in that The BIOS public key is the BIOS manufacturer's public key or the motherboard manufacturer's public key; the BIOS private key is the BIOS manufacturer's private key corresponding to the BIOS manufacturer's public key, or the motherboard manufacturer's private key corresponding to the motherboard manufacturer's public key; the digital certificate public key is the CA center public key or the processor manufacturer's public key; the digital certificate private key is the CA center private key corresponding to the CA center public key, or the processor manufacturer's private key corresponding to the processor manufacturer's public key.
7. A verification device, characterized in that, Applied to the processor in a computer, it includes: An information reading module, configured to respond to a computer power-on and boot instruction, and read the BIOS code and BIOS verification information from the computer's BIOS chip, wherein the BIOS chip is burned with the BIOS code and BIOS verification information; the BIOS code pre-stores the unique identifier of the computer hardware of the computer. A BIOS verification module, configured to perform BIOS code security verification according to the BIOS code and the BIOS verification information, and the BIOS code security verification includes BIOS code legality verification based on the BIOS verification information and BIOS code integrity verification based on the BIOS code. A code running module, configured to, if the BIOS code security verification passes, run the BIOS code to start the work of computer power-on initialization, and the work includes verifying the computer hardware. A hardware verification module, configured to, during the process of verifying the computer hardware, verify whether the computer hardware of the computer is legal according to the unique identifier of the computer hardware pre-stored in the BIOS code. Wherein, the BIOS verification information at least includes digital signature information, and the digital signature information is the result of encrypting the BIOS digest corresponding to the BIOS code with the BIOS private key; the digital certificate public key is burned in the internal ROM of the processor, and the BIOS verification information further includes digital certificate information, and the digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key. The BIOS verification module, configured to perform BIOS code security verification according to the BIOS code and the BIOS verification information, includes: Obtaining the BIOS public key corresponding to the BIOS private key includes: verifying whether the digital certificate information is legal according to the pre - saved digital certificate public key; if the verification of the digital certificate information is legal, obtaining the BIOS public key decrypted from the digital certificate information; Verifying whether the digital signature information is legal according to the BIOS public key; If the digital signature information is legal, obtaining the BIOS digest decrypted from the digital signature information and regenerating the BIOS digest corresponding to the BIOS code; Verifying whether the BIOS code is complete according to the BIOS digest decrypted from the digital signature information and the regenerated BIOS digest; wherein, if the BIOS code is complete, the security verification of the BIOS code passes.
8. A computer, characterized in that, Including: A processor and a BIOS chip; wherein, the processor is configured to execute the verification method according to any one of claims 1 - 6, and the BIOS chip is configured with BIOS code and BIOS verification information, and the unique identifier of the computer hardware of the computer is pre - saved in the BIOS code.
9. A computer configuration system, characterized in that, Including: A BIOS configuration device system and a digital certificate device system; wherein, the BIOS configuration device system configures information for the BIOS chip to be configured by the computer, and the digital certificate device system configures information for the processor and the BIOS chip to be configured by the computer, and the computer is the computer according to claim 8.
10. The computer configuration system according to claim 9, characterized in that, The BIOS configuration device system is used for: generating a BIOS public key and a BIOS private key; sending the BIOS public key to the digital certificate device system, and obtaining the digital certificate information sent by the digital certificate device system, where the digital certificate information is the result of encrypting the BIOS public key with the digital certificate private key generated by the digital certificate device system; Saving the unique identifier of the computer hardware to be configured by the computer in the BIOS code; Generating a BIOS digest corresponding to the BIOS code; encrypting the BIOS digest with the BIOS private key to generate digital signature information; wherein, the BIOS code, the digital signature information, and the digital certificate information are burned into the BIOS chip to be configured by the computer; The digital certificate device system is used for: generating a digital certificate public key and a digital certificate private key; encrypting the BIOS public key sent by the BIOS configuration device system with the digital certificate private key to generate digital certificate information, and sending the digital certificate information to the BIOS configuration device system; wherein, the digital certificate public key is burned into the processor to be configured by the computer.
11. The computer configuration system according to claim 10, wherein The digital certificate public key is burned into the internal ROM of the processor to be configured by the computer.
12. The computer configuration system according to claim 10, wherein The BIOS configuration device system is a BIOS manufacturer device system or a motherboard manufacturer device system; the BIOS public key is a BIOS manufacturer public key or a motherboard manufacturer public key; the BIOS private key is a BIOS manufacturer private key corresponding to the BIOS manufacturer public key, or a motherboard manufacturer private key corresponding to the motherboard manufacturer public key; The digital certificate device system is a CA device system or a processor manufacturer device system; the digital certificate public key is a CA center public key or a processor manufacturer public key; the digital certificate private key is a CA center private key corresponding to the CA center public key, or a processor manufacturer private key corresponding to the processor manufacturer public key.
Citation Information
Patent Citations
A method and a device for controlling computer startup and an electronic device
CN109214187A
A BIOS starting method and a data processing method
CN109714303A
Rapid peripheral component interconnection equipment starting method and device, and storage medium
CN114077739A