基于BMC启动的代码安全更新方法、装置、设备及介质
By obtaining backup firmware code during the BMC boot process and using TCM to clear and update the baseline value of the target firmware code, the low security of existing firmware code update schemes is solved, realizing the security of the system boot process and the restoration of the trusted chain, and improving the maintainability and reusability of firmware code.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING UNIV OF TECH
- Filing Date
- 2023-11-22
- Publication Date
- 2026-07-17
AI Technical Summary
Existing firmware code update schemes cannot guarantee the security of the system boot process, especially when the firmware code is tampered with, and cannot maintain the integrity of the chain of trust.
When the motherboard management controller (BMC) is in an insecure state, the backup firmware code is obtained from the first flash memory, the first reference value of the target firmware code is cleared using the embedded memory chip (TCM), and a second metric value is determined based on the TCM and the target firmware code. This second metric value is then stored in the TCM as the second reference value, thereby achieving a secure update of the target firmware code.
This achieves the security and trust chain recovery of the target firmware code during system startup, improves the maintainability and reusability of the firmware code, and ensures the secure startup of the system.
Smart Images

Figure CN117592055B_ABST