Domestic server starting method, server, computer device and storage medium

By introducing a trusted root of trust into the trusted platform control module in domestic servers for multiple measurement and verification, a dual-system protection architecture is constructed, which solves the security threat caused by the mixing of security modules and functional code in the trusted transformation of the BMC of domestic servers, and realizes trusted startup and secure control of the server.

CN117785308BActive Publication Date: 2026-07-31EVOC INTELLIGENT TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
EVOC INTELLIGENT TECH
Filing Date
2023-12-29
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

In the current trusted transformation of domestic server BMC, the security module is mixed with the BMC functional code, which threatens the server security and lacks an effective dual-system protection architecture.

Method used

In domestically produced servers, a trusted platform control module is introduced as a trusted root, serving as a trusted core. Through multiple measurements and verifications of the baseboard management controller functional core, basic input/output system, operating system loader, and operating system kernel, a dual-system protection architecture is constructed to ensure the separation of security functions from business functions.

Benefits of technology

It enables trusted measurement and control of critical components during server startup, preventing code tampering, ensuring server security and trustworthiness, and avoiding the risks associated with the integration of security and business functions in traditional BMC trusted core construction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117785308B_ABST
    Figure CN117785308B_ABST
Patent Text Reader

Abstract

This application provides a domestic server startup method, server, computer equipment, and storage medium. After the trusted root of the trusted platform control module (TPC) in the protection component is powered on and running, it sequentially measures the baseboard management controller (BMC) functional core, basic input / output system (BIS), operating system loader, and operating system kernel based on the TPC's TMC ...
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of server technology, and in particular to domestic server boot methods, servers, computer equipment and storage media. Background Technology

[0002] The Baseboard Management Controller (BMC) is an important unit of the server. It provides remote management functions for the server using virtual keyboard, interface, mouse, power supply, etc. Users can log in to the BMC's web management interface to monitor the physical characteristics of the server, such as the temperature, voltage, power supply of various components of the motherboard, and chassis intrusion.

[0003] The BMC (Browser Control Unit) is a control unit with independent power supply and independent I / O interfaces (i.e., input / output interfaces). Regardless of whether the server has an operating system installed or is powered on, the BMC can monitor the server's operating status as long as it is powered on. Therefore, using a trusted BMC with self-protection mechanisms is a viable solution for high-security servers.

[0004] In recent years, due to the continuous improvement in the performance of domestically produced chips, more and more domestically produced servers have been used for security reasons. However, the current method of trusting the BMC (Browser Control Center) of domestically produced servers involves adding trust-related modules to the original BMC functional code, while the security module code is mixed with the BMC functional code. Once a problem occurs in the BMC code, it will threaten the security module, leading to server security issues. Summary of the Invention

[0005] This application provides a domestic server startup method, server, computer equipment, and storage medium. When building a trusted root of trust for a trusted platform control module, it can be used as a trusted core. Then, a metric agent is added on the host side to achieve a dual-system protection architecture. At the same time, it overcomes the risks brought about by the integration of security functions and business functions in the traditional BMC trusted core construction.

[0006] In a first aspect, embodiments of this application provide a method for booting a domestically produced server, applied to a server, the server including a computing component and a protection component; the protection component including a baseboard management controller functional core and a baseboard management controller trusted core; the computing component including a basic input / output system, an operating system loader, and an operating system kernel; the baseboard management controller trusted core including a trusted root of trust for a trusted platform control module; the method for booting the domestically produced server includes:

[0007] The trusted platform control module's trusted root is powered on and running.

[0008] The trusted platform control module reads the U-BOOT image from the functional core of the baseboard management controller and performs the first measurement verification to obtain the first measurement result.

[0009] If the root of trust of the trusted platform control module determines that the first measurement result is a measurement pass result, then the basic input-output system is subjected to a second measurement verification to obtain a second measurement result.

[0010] If the trusted root of the trusted platform control module determines that the second measurement result is a measurement pass result, then it performs a third measurement verification on the operating system loader to obtain the third measurement result.

[0011] If the trusted root of the trusted platform control module determines that the third measurement result is a measurement pass result, then it performs a fourth measurement verification on the operating system kernel to obtain the fourth measurement result.

[0012] The computing unit powers on and starts up once it determines that the fourth measurement result is a measurement pass result.

[0013] Secondly, embodiments of this application provide a server, which includes a computing component and a protection component; the protection component includes a baseboard management controller functional core and a baseboard management controller trusted core; the computing component includes a basic input / output system, an operating system loader, and an operating system kernel; the baseboard management controller trusted core includes a trusted root of trusted platform control module; the server is used to execute the domestic server startup method of the first aspect described above.

[0014] Thirdly, embodiments of this application provide a computer device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the domestic server startup method described in the first aspect.

[0015] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to execute the domestic server startup method described in the first aspect.

[0016] This application provides a method for booting a domestically produced server, a server, a computer device, and a storage medium. The method includes: powering on and running the trusted root of the trusted platform control module; the trusted root of the trusted platform control module reads the U-BOOT image in the baseboard management controller functional core and performs a first measurement verification to obtain a first measurement result; if the trusted root of the trusted platform control module determines that the first measurement result is a pass result, it performs a second measurement verification on the basic input / output system to obtain a second measurement result; if the trusted root of the trusted platform control module determines that the second measurement result is a pass result, it performs a third measurement verification on the operating system loader to obtain a third measurement result; if the trusted root of the trusted platform control module determines that the third measurement result is a pass result, it performs a fourth measurement verification on the operating system kernel to obtain a fourth measurement result; and if the computing unit determines that the fourth measurement result is a pass result, it powers on and starts up. In constructing the trusted root of the trusted platform control module, this application treats it as a trusted core and then adds a measurement agent on the host side. Compared with the existing technology where the security module code and BMC functional code are mixed, this achieves a dual-system protection architecture and overcomes the risks brought about by the integration of security functions and business functions in the traditional BMC trusted core construction. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a schematic diagram illustrating an application scenario of the domestic server startup method provided in the embodiments of this application;

[0019] Figure 2 A flowchart illustrating the domestic server startup method provided in this application embodiment;

[0020] Figure 3 A schematic diagram of the BMC firmware architecture in the domestic server startup method provided in this application embodiment;

[0021] Figure 4 A schematic diagram of a sub-process of the domestic server startup method provided in the embodiments of this application;

[0022] Figure 5 This is a schematic diagram of another sub-process of the domestic server startup method provided in the embodiments of this application;

[0023] Figure 6 This is a schematic diagram of another sub-process of the domestic server startup method provided in the embodiments of this application;

[0024] Figure 7 This is a schematic diagram of another sub-process of the domestic server startup method provided in the embodiments of this application;

[0025] Figure 8 A schematic diagram illustrating the complete trust chain model construction in the domestic server startup method provided in this application embodiment;

[0026] Figure 9 A schematic block diagram of a computer device provided in an embodiment of this application. Detailed Implementation

[0027] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0028] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0029] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the scope of the application. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0030] It should also be further understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0031] Please also refer to Figure 1 , Figure 1 This is a schematic diagram illustrating an application scenario of the domestic server startup method provided in the embodiments of this application. Figure 2 This is a flowchart illustrating the domestic server startup method provided in an embodiment of this application. Figure 1As shown, this domestically developed server startup method is applied to server 10, which includes a computing component 11 and a protection component 12. The protection component 12 includes a baseboard management controller functional core 121 and a baseboard management controller trusted core 122. The computing component 11 includes a basic input / output system 111, an operating system loader 112, and an operating system kernel 113. The baseboard management controller trusted core 122 includes a trusted platform control module trusted root 1221. Figure 2 As shown, the startup method of this domestic server specifically includes the following steps S110-S160.

[0032] S110, the trusted root of the trusted platform control module is powered on and running.

[0033] In this embodiment, the Trusted Platform Control Module (TPCM) root of trust 1221 can be considered as a TPCM root of trust jointly constructed by a Baseboard Management Controller (BMC) and a Trusted Cryptography Module (TCM). Specifically, the Trusted Cryptography Module is added to the bootstrap layer of the BMC firmware corresponding to the Baseboard Management Controller. The architecture of the BMC firmware is as follows: Figure 3 As shown.

[0034] The BMC firmware architecture includes a boot layer, a kernel layer, kernel middleware, and a software layer. The details of each layer are as follows:

[0035] A1) Guiding Layer

[0036] The boot layer is the U-BOOT boot program of the BMC firmware. The U-BOOT boot program is the first piece of code that runs when the BMC powers on. The trusted modules added to the U-BOOT boot program include the trusted cryptographic module driver (i.e., TCM driver), the measurement program, and the measurement value storage interface.

[0037] The TCM driver is used to enable communication between the U-BOOT boot program and the trusted cryptographic module; the measurement program is used by the trusted cryptographic module to measure the Linux Kernel (i.e., the Linux kernel) when the BMC starts up; the measurement value storage interface is used to save various measurement values ​​to the PCR register of the trusted cryptographic module (PCR stands for Platform Configuration Register).

[0038] A2) Kernel layer

[0039] The kernel layer is a trimmed-down ARM Linux kernel, and I / O drivers (i.e., input / output drivers) have been added to enable trusted computing functionality. These drivers include the hardware interface functions of LPC (Lowpin Count Bus, used to connect low-bandwidth devices and "older" devices to the CPU chip), SPI (SPI is a full-duplex synchronous serial bus), and IIC (Inter-Integrated Circuit, representing an integrated circuit bus). They also handle the timing of the hardware interface and configure the relevant registers to enable normal communication between the BMC and external modules.

[0040] A3) Kernel Middleware

[0041] Kernel middleware is located between the kernel layer and the software layer. It provides trusted proxy programs, metric storage interfaces, command interfaces for BMC to control CPLDs, and various trusted function APIs (API stands for Application Programming Interface).

[0042] The trusted proxy program is used to schedule the trusted cryptographic module to measure the BIOS Boot Block (the boot block of the Basic Input / Output System) and the BMC application. The measurement value storage interface is used to save various measurement values ​​to the PCR register of the trusted cryptographic module. In the command interface for controlling the CPLD by the BMC, the BMC controls the power-on sequence of the motherboard (CPLD stands for Complex Programmable Logic Device) through the CPLD. Specifically, when the BMC powers on, it does not initially power on the motherboard's CPU chip; only after measuring the BMC and BIOS Boot Block and ensuring their trustworthiness is achieved does it control the CPU chip to power on through the CPLD, thus ensuring the integrity of the program during operation. Various trusted function APIs, including trusted function enable API, baseline value API, measurement value API, log API, privilege code API, and configuration interface, provide an operation interface for the BMC Web management interface to implement trusted computing functions.

[0043] A4) Software Layer

[0044] The software layer includes the BMC Web application and the BMC application. The trusted state is presented in the BMC Web application by calling the API interface of the kernel middleware, such as enabling trusted functions, baseline value management, log presentation, privileged startup, whitelist management, etc.

[0045] To ensure secure server startup, the computing components in the server are not powered on initially. Instead, the trusted core of the baseboard management controller in the protection components is powered on and running. After measuring and ensuring the trustworthiness of the BMC, basic input / output system, operating system loader, and operating system kernel, the CPU chip is powered on via the CPLD, thereby ensuring the integrity of the program during operation.

[0046] S120, the trusted root of the trusted platform control module reads the U-BOOT image in the functional core of the baseboard management controller and performs the first measurement verification to obtain the first measurement result.

[0047] In this embodiment, after the trusted root of trust of the trusted platform control module is powered on and running, it does not immediately measure the computing part of the server. Instead, it first measures and verifies the U-BOOT image in the baseboard management controller functional core. Specifically, it performs trusted measurement, trusted verification, and trusted control on the U-BOOT image in the baseboard management controller functional core. After completing the first measurement and verification of the U-BOOT image and obtaining the first measurement result, it further determines whether to measure the computing part based on whether the measurement passed or failed.

[0048] In one embodiment, such as Figure 1 As shown, the trusted platform control module trusted root 1221 includes a trusted cryptographic module 1221A; as Figure 4 As shown, step S120 includes:

[0049] S121. The trusted platform control module reads the U-BOOT image from the baseboard management controller function core and calls the trusted cryptography module to obtain the U-BOOT image metric value corresponding to the U-BOOT image.

[0050] S122. The trusted root of the trusted platform control module reads the U-BOOT baseline value from the trusted cryptographic module.

[0051] S123. The trusted root of the trusted platform control module determines the first measurement result based on the comparison between the U-BOOT image measurement value and the U-BOOT baseline value.

[0052] In this embodiment, after the trusted root of the trusted platform control module performs a power-on self-test, it enters the running phase, and the measurement program in the BMC firmware begins to run. First, the measurement program reads the U-BOOT image from the baseboard management controller functional core and calculates the relevant measurement values ​​of the U-BOOT image by calling the SM3 function of the trusted cryptographic module to obtain the U-BOOT image measurement value. Next, the trusted root of the trusted platform control module reads the U-BOOT baseline value stored in the non-volatile memory of the trusted cryptographic module. Finally, the trusted root of the trusted platform control module compares the U-BOOT image measurement value with the U-BOOT baseline value. If they are the same, the first measurement result is a pass; if they are different, the first measurement result is a fail (i.e., the BMC firmware may have been tampered with or attacked). Through the above process, trusted measurement, trusted verification, and trusted control of the baseboard management controller functional core can be achieved.

[0053] S130. Once the trusted root of the trusted platform control module determines that the first measurement result is a measurement pass result, it performs a second measurement verification on the basic input-output system to obtain the second measurement result.

[0054] In this embodiment, when the trusted platform control module's root of trust determines that the first measurement result is a measurement pass result, it indicates that the baseboard management controller functional core has passed the measurement verification and can continue to measure the basic input / output system (i.e., BIOS). After completing the second measurement verification of the basic input / output system to obtain the second measurement result, based on whether the measurement passes or fails according to the second measurement result, it is further determined whether to measure the remaining part of the calculation section.

[0055] In one embodiment, such as Figure 1 As shown, the basic input / output system 111 includes a first metric agent communication module 111A; as Figure 5 As shown, step S130 includes:

[0056] S131, The trusted root of the trusted platform control module reads the BIOS initial value sent by the first metric agent communication module in the basic input / output system, and calls the trusted cryptographic module to obtain the BIOS metric value corresponding to the BIOS initial value;

[0057] S132, The trusted root of the trusted platform control module reads the BIOS baseline value from the trusted cryptographic module;

[0058] S133, The Trusted Root of the Trusted Platform Control Module determines the second measurement result based on the comparison between the BIOS measurement value and the BIOS baseline value.

[0059] In this embodiment, after the trusted root of the trusted platform control module powers on and performs a self-test, and completes the measurement of the baseboard management controller's functional core, the trusted root of the trusted platform control module first reads the BIOS initial value sent by the first measurement agent communication module in the basic input / output system, and then calls the SM3 function of the trusted cryptographic module to calculate the measurement value related to the BIOS initial value to obtain the BIOS measurement value. Afterwards, the trusted root of the trusted platform control module directly reads the BIOS measurement value corresponding to the BIOS initial value from the non-volatile memory stored in the trusted cryptographic module. Finally, the trusted root of the trusted platform control module compares the BIOS measurement value with the BIOS benchmark value. If they are the same, the second measurement result is a pass; if they are different, the second measurement result is a fail. Through the above process, trusted measurement, trusted verification, and trusted control of the basic input / output system can be achieved.

[0060] To better understand the above measurement process, the interaction mechanism between the Trusted Platform Control Module's Trusted Root and the server's computing components is described below. In this application, there is extensive data interaction between the Trusted Platform Control Module's Trusted Root and the server's computing components. When the Trusted Platform Control Module's Trusted Root performs measurements on the computing components' Basic Input / Output System (BIOS), Operating System Loader (OS Loader), Operating System Kernel, and applications, it relies on measurement proxy communication modules deployed in these components to achieve the corresponding measurements and control. For example, a first measurement proxy communication module is deployed in the BIOS, a second measurement proxy communication module is deployed in the OS Loader, and a third measurement proxy communication module is deployed in the OS Kernel.

[0061] For example, when measuring the operating system loader, the first measurement agent communication module located in the basic input / output system transmits the relevant data read from the operating system loader to the trusted root of the trusted platform control module. The trusted root of the trusted platform control module then verifies the relevant data to obtain a second measurement result and returns a control signal to the second measurement agent communication module of the operating system loader. Upon receiving the control signal, the second measurement agent communication module decides whether to start the operating system loader. Subsequent measurements of the operating system kernel, etc., follow the same process. Dynamic measurements of applications after the server's computing components start are also implemented in this way. Through this method, a complete trusted system can be constructed.

[0062] Meanwhile, to prevent unauthorized programs from accessing the communication link and ensure communication security, access control mechanisms can be added to multiple metric proxy communication modules on the server's computing component side (i.e., the host side). Related encryption functions are provided for the communication between the server's computing component and the trusted root of the trusted platform control module to prevent attacks during the interaction process and ensure communication security.

[0063] S140. If the Trusted Root of Trust in the Trusted Platform Control Module determines that the second measurement result is a measurement pass result, then it performs a third measurement verification on the operating system loader to obtain the third measurement result.

[0064] In this embodiment, when the trusted platform control module's root of trust determines that the second measurement result is a measurement pass result, it indicates that the basic input / output system has passed the measurement verification, and the operating system loader (i.e., OS Loader) can continue to be measured. After completing the third measurement verification of the operating system loader and obtaining the third measurement result, based on whether the measurement passed result corresponds to the third measurement result, it is further determined whether to measure the remaining part of the computation part.

[0065] In one embodiment, such as Figure 1 As shown, the operating system loader 112 includes a second measurement agent communication module 112A; as Figure 6 As shown, step S140 includes:

[0066] S141, The trusted root of the trusted platform control module reads the OSLoader metric value sent by the second metric agent communication module in the operating system loader;

[0067] S142. The trusted root of the trusted platform control module reads the OSLoader baseline value in the trusted cryptographic module.

[0068] S143. The trusted root of the trusted platform control module determines the third measurement result based on the comparison between the OSLoader measurement value and the OSLoader baseline value.

[0069] In this embodiment, after the trusted root of the trusted platform control module completes the measurement of the basic input / output system, it first reads the OSLoader measurement value sent by the second measurement agent communication module in the operating system loader. Then, the trusted root directly reads the OSLoader baseline value, corresponding to the OSLoader measurement value, stored in the non-volatile memory of the trusted cryptographic module. Finally, the trusted root compares the OSLoader measurement value with the OSLoader baseline value; if they are the same, the third measurement result is a pass; otherwise, it is a fail. Through this process, trusted measurement, trusted verification, and trusted control of the operating system loader can be achieved.

[0070] S150. If the Trusted Root of Trust in the Trusted Platform Control Module determines that the third measurement result is a measurement pass result, then it performs a fourth measurement verification on the operating system kernel to obtain the fourth measurement result.

[0071] In this embodiment, when the trusted platform control module's root of trust determines that the third measurement result is a passed result, it indicates that the operating system loader has passed the measurement verification and can continue to measure the operating system kernel. After completing the fourth measurement verification of the operating system kernel and obtaining the fourth measurement result, based on the result corresponding to whether the fourth measurement result passed, it is further determined whether to power on and start the computing unit.

[0072] In one embodiment, such as Figure 1 As shown, the operating system kernel 113 includes a third metric agent communication module 113A; as Figure 7 As shown, step S150 includes:

[0073] S151, The trusted root of the trusted platform control module reads the operating system kernel metric value sent by the third metric agent communication module in the operating system kernel;

[0074] S152. The trusted root of the trusted platform control module reads the operating system kernel baseline value from the trusted cryptographic module.

[0075] S153. The trusted root of the trusted platform control module determines the fourth metric result based on the comparison between the operating system kernel metric value and the operating system kernel baseline value.

[0076] In this embodiment, after the trusted root of the trusted platform control module completes the measurement of the operating system loader, it first reads the operating system kernel measurement value sent by the third measurement proxy communication module in the operating system kernel. Then, the trusted root directly reads the operating system kernel baseline value, corresponding to the operating system kernel measurement value, stored in the non-volatile memory of the trusted cryptographic module. Finally, the trusted root compares the operating system kernel measurement value with the operating system kernel baseline value; if they are the same, the fourth measurement result is a pass; if they are different, the fourth measurement result is a fail. Through this process, trusted measurement, trusted verification, and trusted control of the operating system kernel can be achieved.

[0077] In one embodiment, such as Figure 1 As shown, the trusted root 1221 of the trusted platform control module includes a metric storage interface 1221B and a PCR register 1221C.

[0078] Following step S120, the trusted root of the trusted platform control module stores the first measurement result into the PCR register through the measurement value storage interface;

[0079] Following step S130, the following is also included: the trusted root of the trusted platform control module stores the second measurement result into the PCR register through the measurement value storage interface;

[0080] Following step S140, the following is also included: the trusted root of the trusted platform control module stores the third measurement result into the PCR register through the measurement value storage interface;

[0081] The process after step S150 also includes: the trusted root of the trusted platform control module stores the fourth measurement result into the PCR register through the measurement value storage interface.

[0082] In this embodiment, in order to implement log recording of the entire measurement process in the trusted root of the trusted platform control module, after each measurement result is obtained, the trusted root of the trusted platform control module can store the fourth measurement result in the PCR register through the measurement value storage interface for use in subsequent trusted auditing.

[0083] S160. The calculation unit starts the power-on process after determining that the fourth measurement result is a measurement pass result.

[0084] In this embodiment, once the trusted root of trust of the trusted platform control module has completed the measurement of the operating system kernel and determined that the measurement has passed, the computing component side of the server (i.e., the host side) can be powered on and started, thereby completing the secure startup of the server.

[0085] In one embodiment, the method further includes the following after step S160:

[0086] The startup block in the basic input / output system measures the main block and obtains the fifth measurement result.

[0087] If the main block in the basic input / output system determines that the fifth measurement result is a measurement pass result, it will measure the motherboard peripherals connected to the computing unit to obtain the sixth measurement result.

[0088] Once the operating system loader determines that the sixth measurement result is a pass result, it will measure the operating system loading configuration file and the operating system kernel to obtain the seventh measurement result.

[0089] Once the operating system kernel determines that the seventh metric result is a passed result, it obtains the constructed trust chain.

[0090] In this embodiment, to achieve trusted boot of the server, in addition to establishing a trust chain before powering on the server's computing component side (i.e., the host side), it is also necessary to continue perfecting the trust chain establishment after powering on the server's computing component side. The following section combines... Figure 8 The complete model construction diagram of the trust chain in the middle is used to illustrate this in detail.

[0091] B1) The Baseboard Management Controller (BMC) and the Trusted Cryptographic Module are powered on and started before the computing components of the server. Specifically, the Trusted Cryptographic Module measures the U-BOOT image in the functional core of the Baseboard Management Controller. If the U-BOOT has been tampered with, the startup process is paused.

[0092] B2) During the boot loading process of the BMC based on the U-BOOT image, the measurement program in the U-BOOT image calls the SM3 algorithm of the trusted cryptographic module to measure the Linux kernel and trusted proxy program. The first measurement result is extended and stored in PCR0 of the PCR register of the trusted cryptographic module. If the kernel file or trusted proxy program in the Linux kernel of the baseboard management controller functional core is tampered with, the boot process is stopped; otherwise, the Linux kernel is started, and system control is transferred from the U-BOOT image to the Linux kernel.

[0093] B3) The trusted agent program in the Linux system located in the baseboard management controller functional core reads the boot block (i.e., BIOS Boot Block) code in the basic input / output system for measurement, and then measures the BMC application. The measurement value is extended and stored in PCR0 of the trusted cryptographic module's PCR register. If the BIOS Boot Block or the BMC application is tampered with, the boot process is stopped; otherwise, system control is transferred from the Linux system to the BIOS Boot Block, and then the server powers on and boots.

[0094] B4) After the server is powered on, the BIOS completes the establishment of the subsequent trust chain (that is, the steps executed after step S160 correspond to step B4 and the steps thereafter). The BIOS BootBlock measures the BIOS version information and the BIOS Main Block (i.e. the main block in the basic input / output system), and stores the corresponding measurement results in PCR0 of the PCR register of the trusted cryptographic module.

[0095] B5) The main block of the basic input / output system first measures the motherboard peripherals such as graphics cards, hard drives, network cards, and PCI-E cards on the computing component side of the server, and stores the corresponding measurement results in PCR2 of the PCR register of the trusted cryptographic module; then it measures the operating system bootloader in the operating system loader, i.e. the code of each stage of Bootloader Grub, and stores the corresponding measurement results in PCR4 of the PCR register of the trusted cryptographic module.

[0096] B6) After Bootloader Grub gains control, it performs the loading of the operating system. Grub first measures the operating system loading configuration file (i.e., the configuration file grub.conf) and extends it to PCR5 of the PCR register of the trusted cryptographic module; then it measures the operating system kernel (i.e., the OS Kernel) to be loaded and verifies the integrity of the operating system kernel.

[0097] B7) After Bootloader Grub hands over control to the OS Kernel, the operating system begins the boot process, thus establishing a complete chain of trust.

[0098] This method first powers on the Trusted Platform Control Module (TPC) root of trust in the server. Then, based on the TPC root of trust, it sequentially measures the Baseboard Management Controller (BMC) functional core, Basic Input / Output System (BIS), Operating System loader, and Operating System kernel. Only after all measurements are successful is the computing component in the server powered on and started. This method treats the TPC root of trust as a trusted core during its construction and adds a measurement agent on the host side. Compared to existing technologies that mix security module code with BMC functional code, this method achieves a dual-system protection architecture while overcoming the risks associated with the fusion of security and business functions in traditional BMC trusted core construction.

[0099] This application also provides a server for executing any of the aforementioned embodiments of the domestic server startup method. For example... Figure 1As shown, server 10 includes a computing component 11 and a protection component 12; the protection component 12 includes a baseboard management controller functional core 121 and a baseboard management controller trusted core 122; the computing component 11 includes a basic input / output system 111, an operating system loader 112, and an operating system kernel 113; the baseboard management controller trusted core 122 includes a trusted platform control module trusted root 1221; the server is used to perform the following steps:

[0100] The trusted platform control module's trusted root is powered on and running.

[0101] The trusted platform control module reads the U-BOOT image from the functional core of the baseboard management controller and performs the first measurement verification to obtain the first measurement result.

[0102] If the root of trust of the trusted platform control module determines that the first measurement result is a measurement pass result, then the basic input-output system is subjected to a second measurement verification to obtain a second measurement result.

[0103] If the trusted root of the trusted platform control module determines that the second measurement result is a measurement pass result, then it performs a third measurement verification on the operating system loader to obtain the third measurement result.

[0104] If the trusted root of the trusted platform control module determines that the third measurement result is a measurement pass result, then it performs a fourth measurement verification on the operating system kernel to obtain the fourth measurement result.

[0105] The computing unit powers on and starts up once it determines that the fourth measurement result is a measurement pass result.

[0106] It should be noted that those skilled in the art can clearly understand that the specific implementation process of the above-mentioned server and each module can be referred to the corresponding description in the foregoing method embodiments. For the sake of convenience and brevity, it will not be repeated here.

[0107] This server operates by powering on the Trusted Platform Control Module (TPC) root of trust within the protection component. Based on the TPC root of trust, it sequentially measures the Baseboard Management Controller (BMC) functional core, Basic Input / Output System (BIS), Operating System loader, and Operating System kernel. Only after all measurements are successful does the server's computing component power on and start. This method treats the TPC root of trust as a trusted core during its construction and adds a measurement agent on the host side. Compared to existing technologies that mix security module code with BMC functional code, this approach achieves a dual-system protection architecture while overcoming the risks associated with the fusion of security and business functions in traditional BMC trusted core construction.

[0108] The aforementioned secure server boot device can be implemented as a computer program, which can, for example... Figure 9 It runs on the computer device shown.

[0109] Please see Figure 9 , Figure 9 This is a schematic block diagram of a computer device provided in an embodiment of this application. The computer device 800 can be a terminal device such as a smartphone, tablet computer, personal computer (PC), learning machine, or smart wearable device. See also... Figure 9 The computer device 800 includes a processor 802, a memory, and a network interface 805 connected via a device bus 801, wherein the memory may include a storage medium 803 and internal memory 804.

[0110] The storage medium 803 can store the operating system 8031 ​​and the computer program 8032. When the computer program 8032 is executed, it enables the processor 802 to execute the domestic server boot method.

[0111] The processor 802 provides computing and control capabilities to support the operation of the entire computer device 800.

[0112] The internal memory 804 provides an environment for the computer program 8032 in the storage medium 803 to run. When the computer program 8032 is executed by the processor 802, the processor 802 can execute the domestic server startup method.

[0113] This network interface 805 is used for network communication, such as providing data transmission. Those skilled in the art will understand that... Figure 9 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device 800 to which the present application is applied. The specific computer device 800 may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0114] The processor 802 is used to run the computer program 8032 stored in the memory to implement the domestic server startup method disclosed in the embodiments of this application.

[0115] Those skilled in the art will understand that Figure 9 The embodiments of the computer device shown do not constitute a limitation on the specific configuration of the computer device. In other embodiments, the computer device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. For example, in some embodiments, the computer device may include only memory and a processor. In such embodiments, the structure and function of the memory and processor are different from those shown. Figure 9 The embodiments shown are consistent and will not be repeated here.

[0116] It should be understood that in the embodiments of this application, the processor 802 may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0117] In another embodiment of this application, a computer-readable storage medium is provided. This computer-readable storage medium can be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. The computer-readable storage medium stores a computer program, wherein when executed by a processor, the computer program implements the domestic server startup method disclosed in the embodiments of this application.

[0118] Those skilled in the art will readily understand that, for the sake of convenience and brevity, the specific working processes of the devices, apparatuses, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0119] In the embodiments provided in this application, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Units with the same function may be grouped into one unit. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, or it may be an electrical, mechanical, or other form of connection.

[0120] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.

[0121] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0122] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a backend server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks.

[0123] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A domestically developed server startup method, applied to a server, characterized in that, The server includes a computing component and a protection component; the protection component includes a baseboard management controller functional core and a baseboard management controller trusted core; the computing component includes a basic input / output system, an operating system loader, and an operating system kernel; The trusted core of the baseboard management controller includes a trusted root of the trusted platform control module; The method for starting up the domestically produced server includes: The trusted platform control module's trusted root is powered on and running. The trusted platform control module reads the U-BOOT image from the functional core of the baseboard management controller and performs the first measurement verification to obtain the first measurement result. If the root of trust of the trusted platform control module determines that the first measurement result is a measurement pass result, then the basic input-output system is subjected to a second measurement verification to obtain a second measurement result. If the trusted root of the trusted platform control module determines that the second measurement result is a measurement pass result, then it performs a third measurement verification on the operating system loader to obtain the third measurement result. If the trusted root of the trusted platform control module determines that the third measurement result is a measurement pass result, then it performs a fourth measurement verification on the operating system kernel to obtain the fourth measurement result. The computing unit powers on and starts up once it determines that the fourth measurement result is a measurement pass result. The trusted root of the trusted platform control module includes a trusted cryptographic module; The trusted platform control module's trusted root reads the U-BOOT image from the baseboard management controller's functional core and performs a first measurement verification to obtain a first measurement result, including: The trusted platform control module's trusted root reads the U-BOOT image from the baseboard management controller's functional core and calls the trusted cryptographic module to obtain the U-BOOT image metric value corresponding to the U-BOOT image; The trusted platform control module's trusted root reads the U-BOOT baseline value from the trusted cryptographic module; The trusted root of the trusted platform control module determines the first measurement result based on the comparison between the U-BOOT mirror measurement value and the U-BOOT baseline value. The basic input / output system includes a first metric proxy communication module; The second measurement verification of the basic input / output system, to obtain the second measurement result, includes: The trusted platform control module's trusted root reads the BIOS initial value sent by the first metric proxy communication module in the basic input / output system, and calls the trusted cryptographic module to obtain the BIOS metric value corresponding to the BIOS initial value; The trusted platform control module's trusted root reads the BIOS baseline value from the trusted cryptographic module; The Trusted Platform Control Module determines the second metric result based on the comparison between the BIOS metric value and the BIOS baseline value.

2. The method according to claim 1, characterized in that, The operating system loader includes a second metric proxy communication module; The third measurement and verification of the operating system loader, to obtain the third measurement result, includes: The trusted platform control module's trusted root reads the OSLoader metric value sent by the second metric proxy communication module in the operating system loader; The trusted platform control module's trusted root reads the OSLoader baseline value from the trusted cryptographic module; The trusted platform control module determines the third metric result based on the comparison between the OSLoader metric value and the OSLoader baseline value.

3. The method according to claim 1, characterized in that, The operating system kernel includes a third-level measurement proxy communication module; The fourth measurement verification of the operating system kernel, to obtain the fourth measurement result, includes: The trusted platform control module's trusted root reads the operating system kernel metric value sent by the third metric proxy communication module in the operating system kernel; The trusted platform control module's trusted root reads the operating system kernel baseline value from the trusted cryptographic module; The trusted root of the trusted platform control module determines the fourth metric result based on the comparison between the operating system kernel metric value and the operating system kernel baseline value.

4. The method according to claim 1, characterized in that, The trusted root of the trusted platform control module includes a metric value storage interface and a PCR register; After the trusted root of the trusted platform control module reads the U-BOOT image in the functional core of the baseboard management controller and performs the first measurement verification to obtain the first measurement result, the method further includes: The trusted root of the trusted platform control module stores the first measurement result into the PCR register through the measurement value storage interface; After the trusted root of trust in the trusted platform control module determines that the first measurement result is a measurement pass result, and then performs a second measurement verification on the basic input / output system to obtain a second measurement result, the method further includes: The trusted root of the trusted platform control module stores the second measurement result into the PCR register through the measurement value storage interface; After the trusted root of the trusted platform control module determines that the second measurement result is a measurement pass result, and then performs a third measurement verification on the operating system loader to obtain the third measurement result, the method further includes: The trusted root of the trusted platform control module stores the third measurement result into the PCR register through the measurement value storage interface; After the trusted root of the trusted platform control module determines that the third measurement result is a measurement pass result, and then performs a fourth measurement verification on the operating system kernel to obtain the fourth measurement result, the method further includes: The trusted root of the trusted platform control module stores the fourth metric result into the PCR register through the metric storage interface.

5. The method according to claim 1, characterized in that, After the calculation unit determines that the fourth measurement result is a measurement pass result and then powers on, the process further includes: The startup block in the basic input / output system measures the main block to obtain the fifth measurement result. In the basic input / output system, if the main block determines that the fifth measurement result is a measurement pass result, it performs measurement on the motherboard peripherals connected to the computing unit to obtain the sixth measurement result. If the operating system loader determines that the sixth measurement result is a measurement pass result, it will measure the operating system loading configuration file and the operating system kernel to obtain the seventh measurement result. The operating system kernel determines that the seventh metric result is a metric pass result, and then obtains the constructed trust chain.

6. A server, characterized in that, The server includes a computing component and a protection component; the protection component includes a baseboard management controller functional core and a baseboard management controller trusted core; the computing component includes a basic input / output system, an operating system loader, and an operating system kernel; The trusted core of the baseboard management controller includes a trusted root of the trusted platform control module; The server is used to execute computer programs to implement the method as described in any one of claims 1 to 5.

7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 5.

8. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 5.