A security check method for a BIOS firmware and a server
By switching memory access permissions using the BMC and verifying the BIOS firmware using the OTP storage area and root public key, the BIOS firmware security issue during server operation is resolved, achieving the effect that security verification does not affect the normal operation of the server.
Patent Information
- Application Number
- CN202410397044.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-02
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2044-04-02
AI Technical Summary
The security and integrity of BIOS firmware are crucial to the stability and security of servers, but existing technologies cannot effectively perform security checks during server operation, which may lead to the server failing to start normally or being injected with malicious code.
The system receives verification commands through the Baseboard Management Controller (BMC), switches the memory access permissions to the BMC, establishes a trust chain using the OTP storage area and the root public key, performs security verification on the BIOS firmware, and controls the business functions of the in-band processor during the verification process to ensure that the normal operation of the server is not affected.
This system enables secure verification of the BIOS firmware during server operation, preventing malicious tampering, improving server security and stability, and ensuring the integrity and reliability of the BIOS firmware.
Smart Images

Figure CN118627076B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of servers, and particularly relates to a BIOS firmware security verification method and a server. BACKGROUND
[0002] With the rapid development of networks and data centers, as the core equipment of the data center, servers are facing various security risks from the inside or outside. As the underlying basis for the startup and operation of the server, the security and integrity of the BIOS firmware are crucial to the stability and security of the server operating system. If the BIOS firmware is maliciously tampered with or damaged, it may cause the server to fail to start normally, or even be injected with malicious code, thereby threatening the security of the entire operating system.
[0003] Therefore, it is necessary to provide a BIOS firmware security verification method to provide protection for the safe operation of the server and the operating system. SUMMARY
[0004] Therefore, the embodiments of the present application provide a BIOS firmware security verification method and a server.
[0005] In a first aspect, the present application provides a BIOS firmware security verification method, which comprises the following steps:
[0006] The baseboard management controller (BMC) receives a BIOS verification command, wherein the BIOS verification command is used to instruct to verify the BIOS firmware.
[0007] The BMC switches the accessible object of the memory from an in-band processor to the BMC, wherein the memory is used to store the BIOS firmware, and the in-band processor is used to access the memory to realize the BIOS service function.
[0008] The BMC verifies the BIOS firmware in the memory through accessing the memory.
[0009] The embodiments of the present application provide a BIOS firmware security verification method. When the BIOS firmware verification is needed, the BMC transfers the access right of the memory storing the BIOS firmware from the in-band processor to the detection device, and isolates the memory from the in-band processor. During the BIOS firmware verification, the in-band processor can normally run the operating system and realize other functions, and the detection device can verify the BIOS firmware in the memory through accessing the memory, so that the BIOS firmware is detected during the running of the operating system of the in-band processor. The security verification of the BIOS firmware is realized, and the normal running of the server and the in-band processor is not affected, and the security of the server running is improved.
[0010] In a possible implementation, the BMC switches the accessible object of the memory from the in-band processor to the BMC, including:
[0011] The BMC switches the accessible object of the memory to the BMC by controlling a general input-output pin of the memory.
[0012] In the embodiments of the present application, the BMC can directly control the accessible object of the memory through the general input-output pin, without modifying through the in-band processor, reducing the interaction between hardware devices, and improving the security of the system.
[0013] In a possible implementation, the BMC performs security verification on the BIOS firmware in the memory by accessing the memory, including:
[0014] The BMC accesses the memory and performs security verification on the BIOS firmware by using an one-time programmable (OTP) storage area.
[0015] In the embodiments of the present application, the security verification on the BIOS firmware by using the OTP storage area can ensure the one-time writing of the verification data, prevent malicious tampering or unauthorized access, and thus improve the security of the system.
[0016] In a possible implementation, the BMC performs security verification on the BIOS firmware by using the OTP storage area, including:
[0017] The BMC reads a root public key in the OTP storage area;
[0018] The BMC verifies a secondary key certificate of the BIOS firmware by using the root public key;
[0019] After the verification of the secondary key certificate is passed, the BMC obtains a public key from the secondary key certificate and performs security verification on the BIOS firmware by using the public key.
[0020] In the embodiments of the present application, in this way, the BMC establishes a trust chain by using the root public key in the OTP storage area, verifies the secondary key certificate of the BIOS firmware, and performs security verification on the BIOS firmware by using the extracted public key, thereby ensuring the security and integrity of the BIOS firmware.
[0021] In a possible implementation, before the BMC performs security verification on the BIOS firmware in the memory by accessing the memory, the method further includes:
[0022] The BMC sends a first control instruction to the in-band processor, where the first control instruction is used to instruct the in-band processor to stop performing a service function that needs to access the memory or the BIOS firmware;
[0023] The method further includes:
[0024] The BMC sends a second control instruction to the in-band processor in response to the BIOS firmware passing the verification, where the second control instruction is used to instruct the in-band processor to resume performing the service function that needs to access the memory or the BIOS firmware.
[0025] In the embodiments of the present application, the BMC sends a first control instruction to the in-band processor to make the in-band processor stop performing a service function that needs to access the memory or the BIOS firmware, and to pause other service functions that may conflict with the verification operation when performing the BIOS firmware security verification. After the BIOS firmware passes the verification, the BMC sends a second control instruction to the in-band processor to make the in-band processor resume performing the service function that needs to access the memory or the BIOS firmware, so as to ensure that the system can normally continue to perform other service functions after the security verification is completed. In this way, the BMC ensures the coordination between the verification operation and other service functions when performing the BIOS firmware security verification, thereby improving the security and stability of the system.
[0026] In a possible implementation, the memory includes a first memory and a second memory, and the first memory and the second memory respectively store the BIOS firmware, and the BIOS verification command is used to instruct to perform security verification on the BIOS firmware in the first memory;
[0027] The BMC receives a BIOS verification command and switches the accessible object of the memory to the BMC, including:
[0028] The BMC switches the accessible object of the first memory to the BMC and switches the accessible object of the second memory to the in-band processor.
[0029] The BMC performs security verification on the BIOS firmware in the memory by accessing the memory, including:
[0030] The BMC accesses the first memory to perform security verification on the BIOS firmware in the first memory.
[0031] In the embodiment of the present application, the BMC switches the accessible object of the first memory to itself, so as to perform security check on the BIOS firmware in the first memory. Meanwhile, the BMC switches the accessible object of the second memory to the in-band processor, so as to ensure normal access of other system functions. By switching the first memory access object to the BMC, it can be ensured that the BIOS firmware in the first memory is not disturbed by other system functions when the security check continues.
[0032] In a possible implementation, the memory includes a first memory and a second memory, and the first memory and the second memory respectively store the BIOS firmware; the BIOS check command is used to indicate that the BIOS firmware in the first memory is checked first, and then the BIOS firmware in the second memory is checked;
[0033] The BMC receives a BIOS check command and switches the accessible object of the memory to the BMC, including:
[0034] The BMC switches the accessible object of the first memory to the BMC and switches the accessible object of the second memory to the in-band processor;
[0035] After the BIOS firmware in the first memory passes the check, the BMC switches the accessible object of the second memory to the BMC and switches the accessible object of the first memory to the in-band processor;
[0036] The BMC performs security check on the BIOS firmware in the memory by accessing the memory, including:
[0037] The BMC accesses the first memory to perform security check on the BIOS firmware in the first memory;
[0038] After the BMC switches the accessible object of the second memory to the BMC, the BMC accesses the second memory to perform security check on the BIOS firmware in the second memory.
[0039] In the embodiment of the present application, the BMC can perform security check on the BIOS firmware in the two memories in stages, and switches the accessible object of the memory after the check passes, so as to ensure smooth performance of the check operation and guarantee the security and stability of the system.
[0040] In a possible implementation, the BMC includes a security core and a business core; the BMC receives a BIOS check command and switches the accessible object of the memory to the BMC, including:
[0041] The service core receives the BIOS verification command and sends the BIOS verification command to the security core;
[0042] The security core switches the accessible object of the memory to the security core according to the BIOS verification command;
[0043] The BMC performs security verification on the BIOS firmware in the memory by accessing the memory, including:
[0044] The security core performs security verification on the BIOS firmware in the memory by accessing the memory.
[0045] In the embodiments of the present application, the service core and the security core each assume different roles: the service core is responsible for receiving and delivering commands, and the security core is responsible for actual BIOS firmware security verification, which isolates BIOS firmware verification from other services, thereby ensuring the security and effectiveness when performing verification operations.
[0046] In a possible implementation, the method further includes:
[0047] The security core switches the accessible object of the memory to the in-band processor in response to a BIOS verification result indicating that the BIOS firmware in the memory passes security verification.
[0048] In the embodiments of the present application, the security core can transfer the access right of the memory that has just passed BIOS firmware security verification to the in-band processor, so that the in-band processor accesses the memory with higher security to implement related services, thereby improving the stability of the system.
[0049] In a second aspect, the present application provides a BIOS firmware security verification device, which includes:
[0050] A receiving module is configured to receive a BIOS verification command, the BIOS verification command being used to instruct to verify the BIOS firmware;
[0051] A switching module is configured to switch the accessible object of the memory from the in-band processor to the BMC, the memory being used to store the BIOS firmware, and the in-band processor being used to access the memory to implement BIOS service functions;
[0052] A verification module is configured to perform security verification on the BIOS firmware in the memory by accessing the memory.
[0053] In a possible implementation, the switching module is specifically configured to switch the accessible object of the memory to the BMC by controlling a general input-output pin of the memory.
[0054] In a possible implementation, the checking module is specifically configured to access the memory and perform security checking on the BIOS firmware by using an one-time programmable (OTP) storage area.
[0055] In a possible implementation, the checking module is specifically configured to read a root public key in the OTP storage area, perform checking on a secondary key certificate of the BIOS firmware by using the root public key, and after the checking on the secondary key certificate passes, obtain a public key from the secondary key certificate and perform security checking on the BIOS firmware by using the public key.
[0056] In a possible implementation, the apparatus further includes a start-stop module, which is configured to send a first control instruction to the in-band processor before performing security checking on the BIOS firmware in the memory by accessing the memory, where the first control instruction is used to instruct the in-band processor to stop performing a service function that needs to access the memory or the BIOS firmware, and send a second control instruction to the in-band processor in response to the BIOS firmware passing the checking, where the second control instruction is used to instruct the in-band processor to resume performing the service function that needs to access the memory or the BIOS firmware.
[0057] In a possible implementation, the memory includes a first memory and a second memory, and the first memory and the second memory respectively store the BIOS firmware, and the BIOS checking command is used to instruct to perform security checking on the BIOS firmware in the first memory.
[0058] The switching module is specifically configured to switch an accessible object of the first memory to the BMC and switch an accessible object of the second memory to the in-band processor.
[0059] The checking module is specifically configured to perform security checking on the BIOS firmware in the first memory by the BMC accessing the first memory.
[0060] In a possible implementation, the memory includes a first memory and a second memory, and the first memory and the second memory respectively store the BIOS firmware, and the BIOS checking command is used to instruct to perform security checking on the BIOS firmware in the first memory.
[0061] The switching module is specifically configured to switch the accessible object of the first memory to the BMC, switch the accessible object of the second memory to the in-band processor, and after the BIOS firmware in the first memory passes the verification, switch the accessible object of the second memory to the BMC and switch the accessible object of the first memory to the in-band processor.
[0062] The verification module is specifically configured to access the first memory to perform security verification on the BIOS firmware in the first memory, and after the BMC switches the accessible object of the second memory to the BMC, access the second memory to perform security verification on the BIOS firmware in the second memory.
[0063] In a possible implementation, the BMC includes a security core and a business core, and the switching module is specifically configured to receive the BIOS verification command, send the BIOS verification command to the security core through the business core, and switch the accessible object of the memory to the security core according to the BIOS verification command through the security core.
[0064] The verification module is specifically configured to access the memory through the security core to perform security verification on the BIOS firmware in the memory.
[0065] In a possible implementation, the switching module is further configured to switch the accessible object of the memory to the in-band processor through the security core in response to a BIOS verification result representing that the BIOS firmware in the memory passes the security verification.
[0066] In a third aspect, an embodiment of the present application provides a server, including a processor, and a memory connected with the processor in communication;
[0067] The memory is configured to store computer execution instructions.
[0068] The processor is configured to execute the computer execution instructions stored in the memory, so as to implement the security verification method of the BIOS firmware according to any one of the embodiments of the first aspect.
[0069] In a fourth aspect, an embodiment of the present application provides a computer storage medium, which stores codes, and when the codes are executed, a device executing the codes implements the security verification method of the BIOS firmware according to any one of the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0070] In order to more clearly illustrate the technical solutions in the embodiments or the prior art, the accompanying drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the accompanying drawings in the following description only represent some embodiments of the present application, and for those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0071] Figure 1 A flowchart of a security verification method of a BIOS firmware provided by the related art;
[0072] Figure 2 A flowchart of a security verification method of a BIOS firmware provided by the embodiments of the present application;
[0073] Figure 3 A flowchart of a security verification method of a BIOS firmware provided by the embodiments of the present application;
[0074] Figure 4 A flowchart of a security verification method of a BIOS firmware provided by the embodiments of the present application;
[0075] Figure 5 A flowchart of a security verification method of a BIOS firmware provided by the embodiments of the present application;
[0076] Figure 6 A flowchart of a security verification method of a BIOS firmware provided by the embodiments of the present application;
[0077] Figure 7 A structural schematic diagram of a server provided by the embodiments of the present application. DETAILED DESCRIPTION
[0078] It should be noted that the embodiments described in the present application are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort are within the scope of protection of the present application.
[0079] In order to make the following embodiments clear, the technical terms involved in the present application will be introduced first.
[0080] The basic input / output system (BIOS) is an initialization program required to be run when a computer (such as a server) is started, responsible for initializing and configuring computer hardware, and starting the operating system. The BIOS firmware refers to the initialization program (including the basic input / output program) solidified into the storage chip of the computer mainboard. The computer realizes the initialization and configuration of the computer hardware by running the BIOS firmware, and loads the operating system of the computer. The BIOS firmware is the firmware program actually existing on the mainboard, while the BIOS is an abstract concept of this firmware program. The BIOS can be regarded as an interface for input and output in the computer system, and the BIOS firmware is the software actually realizing this interface function. In the general sense, checking the BIOS means checking the BIOS firmware.
[0081] Flash storage is a non-volatile memory (Non-Volatile Memory) widely used in computers and other electronic devices. Flash storage is known for its fast access speed, low power consumption, and high data density. Flash storage has many advantages. First, Flash storage is non-volatile, meaning that even if power is cut off, the data in the Flash storage can still be maintained. Second, Flash storage has fast read and write speed and low power consumption, making it widely used in mobile devices and embedded systems. In addition, Flash storage also has high data density, capable of storing a large amount of data in a relatively small space. In the embodiments of the present application, the BIOS firmware can be stored in the Flash storage.
[0082] The baseboard management controller (BMC) is a small operating system independent of the server system, which can perform firmware upgrade, view electronic devices and other operations on electronic devices (such as servers) in the state of not being started. The BMC is usually an independent chip or module, which can be called a BMC chip. The BMC chip is a chip integrated on the mainboard or connected to the mainboard through various forms such as peripheral component interconnect express (PCIE). The BMC chip has an independent IP address and network port, and is mainly used for out-of-band management of servers, which can remotely access and manage servers through the network.
[0083] In-band management typically refers to performing operational and management actions through the server's main operating system (such as the operating system running on the server's processor). This method relies on the server's normal operation and the availability of the operating system. If the server experiences problems or the operating system fails to boot, in-band management may be limited or unusable.
[0084] Out-of-band management is a management method independent of the server's main operating system. Taking the BMC (Browser Control Center) as an example, the BMC is a small operating system integrated on the motherboard. It allows for remote management, monitoring, installation, and restarting of the server before startup or when the operating system malfunctions. This management method does not depend on the state of the server's main operating system; therefore, even if the server encounters problems, troubleshooting and repair can be performed through out-of-band management.
[0085] The following description, in conjunction with the accompanying drawings, illustrates the scenarios in which the embodiments of this application are applied.
[0086] like Figure 1 As shown, in one possible implementation, most servers can use the BMC chip to perform security verification on the BIOS firmware before BIOS startup. After successful verification, the BIOS boots normally, allowing the server to complete hardware initialization and configuration, as well as load the operating system. However, during server operation (i.e., while the server's in-band processor is running), if a BIOS verification instruction is triggered, the server needs to restart, interrupting the operation of the operating system on the in-band processor, thus preventing the security verification of the BIOS firmware. In other words, security verification of the BIOS firmware cannot be achieved while the server's in-band operating system is running.
[0087] In response, this application provides a BIOS firmware security verification method and server. The entity executing this method can be called a detection device, specifically a BMC chip, or other chips or devices capable of out-of-band management.
[0088] Before the server starts, the BMC chip can directly perform security verification on the BIOS firmware. After the server starts (i.e., during the operation of the server's in-band processor), in response to the BIOS firmware verification command, the BMC chip first disables the in-band processor's access to the memory storing the BIOS firmware (hereinafter referred to as memory), and switches the object that can access the memory from the in-band processor to the BMC chip. Then, the BMC chip performs security verification on the BIOS firmware in the memory by accessing the memory. After the verification is successful, the BMC chip enables the in-band processor's access to the memory, and switches the object that can access the memory from the BMC chip to the in-band processor. Through the above method, by controlling the business functions of the in-band processor and the object that can access the memory, the BMC chip can isolate the impact of BIOS firmware security verification on the in-band processor during the BIOS firmware verification process. The in-band processor can run the operating system normally and implement other business functions without affecting the continuity of other in-band business functions, thus achieving security verification of the BIOS firmware during server operation.
[0089] The security verification method for BIOS firmware provided in this application will now be described in conjunction with the accompanying drawings.
[0090] like Figure 2 As shown, Figure 2 This is a flowchart illustrating a security verification method for BIOS firmware provided in an embodiment of this application. Figure 2 The process shown only includes the implementation process of verifying the BIOS firmware during server operation. This application embodiment does not limit the process of verifying the BIOS firmware before server startup. Figure 2 The BMC chip and in-band processor shown can be integrated or installed on the same server motherboard. The BMC chip and the in-band processor can communicate via integrated circuits on the motherboard or via other wireless communication methods. This application does not specifically limit the type of in-band processor; it can be a central processing unit (CPU) within the server.
[0091] S201: The BMC chip receives BIOS verification commands.
[0092] In a possible implementation, the BIOS verification command is used to instruct to perform security verification on the BIOS firmware in the memory. The BIOS firmware is usually verified in the following situations: in addition to the need to verify the BIOS firmware when the server starts, the BIOS firmware also needs to be verified during the server operation. For example: when the BIOS firmware is updated or upgraded, the BIOS firmware needs to be verified to ensure that the new BIOS firmware is correctly installed and no damage occurs. Or, when the server performs operating system maintenance, the BIOS firmware needs to be verified to troubleshoot whether the BIOS firmware has a problem.
[0093] The BIOS verification command can be automatically generated and sent to the BMC chip by other devices (such as an in-band processor) in the server, for example: the server is set to perform periodic verification of the BIOS firmware, and the in-band processor generates a BIOS verification command and sends the BIOS verification command to the BMC chip every predetermined time. The BIOS verification command can also be automatically generated and sent to the BMC chip by other devices (such as an in-band processor) in the server, for example: the in-band processor generates a BIOS verification command and sends the BIOS verification command to the BMC chip in response to an administrator or technician triggering a BIOS firmware verification operation.
[0094] In a possible implementation, the BIOS verification command is generated by the BMC chip, and in this case, the BMC chip does not need to receive the BIOS verification command. For example, the BMC chip generates a BIOS verification command in response to conditions for triggering BIOS firmware verification (such as BIOS periodic verification or an administrator triggering a BIOS firmware verification operation).
[0095] In another possible implementation, the BMC chip can also directly execute step S202 in response to conditions for triggering BIOS firmware verification, that is, the BMC chip does not need to execute step S201 and does not generate a BIOS verification command.
[0096] S202: The BMC chip sends a first control instruction to the in-band processor.
[0097] The first control instruction is used to instruct the in-band processor to stop performing a service function (hereinafter referred to as a BIOS service function) that needs to access the memory or access the BIOS firmware in the memory. The BMC chip controls the BIOS service function of the in-band processor, and before verifying the BIOS firmware, the BIOS service function of the in-band controller is suspended to avoid the in-band controller performing the BIOS service function to access the BIOS firmware during the verification of the BIOS firmware by the BMC chip, which causes the BIOS service function to be unable to be implemented or affects the accuracy of the BIOS firmware verification.
[0098] In a possible implementation, a BIOS service function variable is set in a controller driver of the memory. The controller driver is in the in-band processor, and the BIOS service function variable is used to identify whether the in-band processor can perform the BIOS service function. The BMC chip controls the in-band memory by sending a first control instruction to the in-band controller, and then setting the BIOS service function variable of the in-band processor. As an example, the first control instruction can be an Intelligent Platform Management Interface (IPMI) command.
[0099] The IPMI command is a set of commands and tools for remotely managing and monitoring server hardware. Through the IPMI command, a user can remotely monitor, diagnose, and manage a server without being limited by an operating system. In the embodiment of the present application, the BMC chip can control whether the in-band processor performs the BIOS service function through the IPMI command.
[0100] S203: The BMC chip switches the object that can access the memory to the BMC chip.
[0101] The memory is used to store the BIOS firmware, and in the embodiment of the present application, the memory can be a Flash memory. The BIOS firmware is stored by using the Flash memory, which can prevent unauthorized write operations, so that the BIOS firmware is not easily tampered with, thereby improving the security of the BIOS firmware.
[0102] The object that can access the memory refers to a hardware device that can access the memory (hereinafter referred to as an accessible object), and can also be understood as a hardware device that has access rights to the memory. The BMC chip can switch the access object from the in-band processor to the BMC chip, transfer the access rights of the memory from the in-band processor to the BMC chip, and then cut off the interaction between the in-band processor and the memory, thereby avoiding the influence of the BIOS firmware check by the BMC chip on the normal operation of the in-band processor.
[0103] In a possible implementation, the BMC chip can control the accessible object of the memory by controlling a General Purpose Input-Output (GPIO) pin of the memory, thereby controlling the accessible object of the memory. When it is necessary to switch the accessible object, the BMC chip controls the GPIO pin of the memory to change the access path of the memory, so that the access rights are switched from the in-band processor to the BMC chip.
[0104] The BMC chip can dynamically adjust the access permission of the memory according to the requirement of BIOS firmware verification, to ensure that the in-band processor can normally operate. Moreover, the BMC chip can autonomously switch the accessible object of the memory through the GPIO pin to realize the verification of the BIOS firmware, without accessing the in-band processor of the server, thereby improving the manageability and security of the system.
[0105] S204: The BMC chip accesses the memory and performs security verification on the BIOS firmware.
[0106] After the accessible object of the memory is successfully switched to the BMC chip, the BMC chip can access the memory and then verify the BIOS firmware.
[0107] In a possible implementation, the BMC chip can use an One Time Programmable (OTP) storage area to realize the security verification on the BIOS firmware.
[0108] The OTP storage area is different from the general memory. The general memory can be restored to the factory state through an erase command, and then data can be written again. The biggest feature of the OTP storage area is that the data is one-time programmable. Once the data is written, it cannot be restored to the factory state through the erase command. That is, for each bit, it can only be changed from “1” to “0”, but cannot be changed from “0” to “1”, that is, the data in the OTP storage area is not modifiable. Therefore, the OTP storage area is very suitable for storing critical data that should not be easily changed, such as device identification, key, encryption parameter and the like.
[0109] The process in which the BMC chip uses the OTP storage area to perform security verification on the BIOS firmware is as shown in Figure 3
[0110] S2041: The BMC chip reads the root public key of the OTP storage area.
[0111] The root public key refers to the topmost public key in a group of public keys, and is usually the highest-level public key in the digital certificate system. As the root of the entire trust chain, the root public key is used to verify the authenticity and credibility of other digital certificates. The BMC chip takes the root public key as a feasible root, and constructs a trust chain system by extending downward to the subordinate certificate authority. The trust chain is used to verify the validity of the digital certificate, to ensure the security and trust between the two communication parties.
[0112] In the embodiment of the present application, the root public key is stored in the OTP storage area, and the security of the root public key is ensured by using the non-modifiable feature of the OTP storage area.
[0113] S2042: The BMC chip verifies the secondary key certificate of the BIOS firmware.
[0114] The BMC chip obtains a secondary key certificate in the BIOS firmware. The secondary key certificate of the BIOS firmware is usually generated in the production manufacturing process. The secondary key certificate includes a public key and other related information. In the scenario of checking the BIOS firmware, this public key is usually used to verify the integrity and authenticity of the firmware to ensure that the firmware is signed by a legitimate manufacturer. Therefore, the public key in the secondary key certificate is a public key corresponding to a private key, which is used for digital signature verification and other operations. The BMC chip verifies the authenticity of the secondary key certificate by using the root public key. When the secondary key certificate can be traced back to a trusted root public key, it can be considered as a trusted certificate.
[0115] The BMC chip extracts the signature from the secondary key certificate. The BMC chip decrypts the signature using the root public key to obtain a first digest. The BMC chip calculates a second digest of the secondary key certificate and compares whether the first digest decrypted and the second digest calculated are consistent to determine whether the signature of the secondary key certificate is valid. If the secondary key certificate passes the verification, that is, the first digest and the second digest are the same, it means that the secondary key certificate is issued by a trusted entity, that is, the secondary key certificate passes the verification.
[0116] S2043: The BMC chip obtains a public key from the secondary key certificate.
[0117] The BMC chip extracts the public key from the secondary key certificate. In the subsequent security check process of the BIOS firmware, the public key will be used to verify the digital signature of the firmware or perform other security operations. The BMC chip can obtain the public key in the secondary key certificate by parsing the secondary key certificate.
[0118] S2044: The BMC chip performs security check on the BIOS firmware by using the public key.
[0119] The BMC chip uses the extracted public key to perform signature verification on the BIOS firmware, such as digital signature verification, hash value comparison, and other operations. If the verification passes, it means that the BIOS firmware is complete and has not been tampered with.
[0120] In this way, the BMC chip uses the root public key information stored in the OTP area as a trusted root to check the secondary key certificate of the BIOS, and uses the public key in the certificate to perform security check on the BIOS firmware, thereby ensuring the security of the BIOS firmware. Preventing the BIOS firmware from being maliciously tampered with or replaced, improving the security and stability of the server.
[0121] S205: The BMC chip switches the object of the accessible memory to an in-band processor.
[0122] After the BIOS firmware verification passes, the BMC chip switches the accessible object of the memory from the BMC chip to the in-band processor, and transfers the access right of the memory from the BMC chip to the in-band processor. The specific switching manner can refer to step S203.
[0123] S206: The BMC chip sends a second control instruction to the in-band processor.
[0124] The second control instruction is used to instruct the in-band processor to continue the service function that needs to access the memory or access the BIOS firmware in the memory, that is, to restore the BIOS service function of the in-band processor. When the BMC chip completes the verification of the BIOS firmware and transfers the access right of the memory to the in-band processor, the in-band processor can continue to access the BIOS firmware in the memory, and then implement the corresponding BIOS service function.
[0125] S207: The BMC chip feeds back the BIOS verification result.
[0126] The BIOS verification result can include the verification result of the digital signature of the BIOS firmware (such as whether the signature is valid, whether it matches the public key in the second key certificate), the verification result of the validity period of the second key certificate (such as whether the second key certificate is expired or valid), and the verification result of other security information (such as whether the extension information in the second key certificate meets the expectation, whether the second key certificate meets a specific security policy).
[0127] The BMC chip can provide comprehensive information about the security of the BIOS firmware to the administrator or technician by feeding back the BIOS verification result, so that the administrator or technician can understand the security status of the BIOS firmware and take necessary measures.
[0128] It should be noted that in the above S201-S207, the execution order of S202 and S203 is not limited, and step S203 can be executed first and then step S202; the execution order of S205 and S206 is also not limited, and step S206 can be executed first and then step S205. In addition, steps S202 and S206 are optional steps. When the BMC chip switches the accessible object to the BMC chip, the in-band processor can automatically suspend the BIOS service function; when the BMC chip switches the accessible object to the in-band processor, the in-band processor can automatically start the BIOS service function.
[0129] The BIOS firmware security verification method provided by the embodiment of the present application can switch the accessible object of the memory to the BMC chip in the verification process of the BIOS firmware by controlling the access authority of the memory, isolate the access of the in-band processor to the BIOS firmware, and then perform the security verification of the BIOS firmware in the running process of the server. The process can not only realize the security verification of the BIOS firmware, but also will not affect the normal operation of the server and the in-band processor.
[0130] In a possible implementation, the embodiment of the present application provides a BMC chip, which includes a business core and a security core.
[0131] The business core is responsible for performing various management tasks, such as hardware state monitoring, fault detection, and system configuration. The business core interacts with other hardware and software components to achieve comprehensive management of the server. In the embodiment of the present application, the business core is also used to receive and forward the BIOS verification command, and send the control instruction to the in-band processor.
[0132] The security core can perform encryption and decryption operations to protect sensitive data from being illegally accessed, and can also provide access control functions to limit only authorized users to manage and operate the BMC chip and the server. In this way, the security core can greatly improve the security and reliability of the server. In the embodiment of the present application, the security core is also used to control the access authority of the memory, switch the accessible object of the memory, and perform the security verification of the BIOS firmware by using the OTP storage area.
[0133] As shown in Figure 4 , Fig. 2 is a flowchart of another BIOS firmware security verification method provided by the embodiment of the present application. The method includes the following steps. Figure 4
[0134] S401: The business core receives the BIOS verification command.
[0135] In a possible implementation, the BIOS verification command is used to instruct to perform the security verification of the BIOS firmware in the memory.
[0136] In the BMC chip, the business core is used to receive the BIOS verification command, and issue other commands or instructions according to the BIOS verification command.
[0137] S402: The business core sends the first control instruction to the in-band processor.
[0138] The first control instruction is used to instruct the in-band processor to stop performing the BIOS service function. When the service core receives the BIOS verification command, the first control instruction is sent to the in-band processor to control the in-band processor to suspend processing the BIOS service function. This avoids the BIOS service function being unable to be implemented during the BIOS firmware verification process, or the in-band processor accessing the BIOS firmware affecting the accuracy of the BIOS firmware verification.
[0139] S403: The service core sends a BIOS verification command to the security core.
[0140] The security core is used to implement security verification of the BIOS firmware. The service core sends the BIOS verification command to the security core, and then the security core performs security verification of the BIOS firmware in the memory according to the BIOS verification command.
[0141] S404: The security core switches the accessible object of the memory to the security core.
[0142] After receiving the BIOS verification command, the security core switches the accessible object of the memory from the in-band processor to the security core, that is, the access right of the memory is transferred from the in-band processor to the security core. In the embodiment of the application, only the security core can control the accessible object of the memory. The security core can switch the accessible object of the memory by modifying the GPIO pin of the memory.
[0143] By switching the accessible object of the memory, the in-band processor can suspend accessing the memory and the BIOS firmware during the security core verifying the BIOS firmware, while the in-band processor can normally run and implement other service functions, thereby realizing security verification of the BIOS firmware during running of the in-band processor.
[0144] S405: The security core accesses the memory and verifies the BIOS firmware.
[0145] After the accessible object of the memory is successfully switched to the security core, the security core can access the memory and then verify the BIOS firmware. In the embodiment of the application, the security core can use the OTP storage area to verify the BIOS firmware. The specific implementation process can be referred to steps S204 and S2041-S2044.
[0146] S406: The security core switches the accessible object of the memory to the in-band processor.
[0147] After the BIOS firmware is verified, the security core switches the accessible object of the memory from the security core to the in-band processor, and transfers the access right of the memory from the security core to the in-band processor. The specific switching method can be referred to step S404.
[0148] S407: The security core sends the BIOS verification result to the service core.
[0149] After obtaining the BIOS verification result through BIOS firmware verification, the security core can send the BIOS verification result to the service core, and the service core performs subsequent processing according to the BIOS verification result.
[0150] S408: The service core sends a second control instruction to the in-band processor.
[0151] The second control instruction is used to instruct the in-band processor to continue the service function that needs to access the memory or access the BIOS firmware in the memory, that is, to restore the BIOS service function of the in-band processor. The service core receiving the BIOS verification result sent by the security core means that the security core has completed the verification of the BIOS firmware. At this time, the service core restores the BIOS service function of the in-band processor by sending the second control instruction to the in-band processor.
[0152] S409: The service core feeds back the BIOS verification result.
[0153] The service core can display the BIOS verification result to the administrator in a visual manner, so that the administrator can intuitively understand the current state of the BIOS firmware. As an example, if the BIOS verification result indicates that the BIOS firmware verification fails, the service core can also perform BIOS firmware exception alarm.
[0154] It should be noted that in the above S401-S409, the execution order of S402 and S403 is not limited, and S403 can be executed first and then S402 can be executed; the execution order of S406 and S407 is also not limited, and S407 can be executed first and then S406 can be executed. In addition, steps S402 and S408 are optional steps. When the security core switches the accessible object to the security core, the in-band processor can automatically suspend the BIOS service function; when the security core switches the accessible object to the in-band processor, the in-band processor can automatically restore the BIOS service function.
[0155] The method is implemented by the BMC chip including the business core and the security core, the BIOS security check process and the message interaction process (such as receiving the BIOS check command and sending the control command to the in-band processor) are respectively implemented by using two cores (the business core and the security core), the isolation of different processes is achieved, and the mutual influence of the two processes by a single core is avoided. Moreover, the modification of the memory access permission and other business implementations are isolated, that is, the security core can change the memory accessible object, the business core can implement information interaction, the BIOS security check and the BIOS firmware security can be improved, and the malicious modification of the memory access permission by the business core directly attacked by the outside world and the malicious access of the memory and the BIOS firmware by the outside world are avoided.
[0156] In a possible implementation, two memories (the first memory and the second memory) can be arranged to store the BIOS firmware, and the redundancy reliability of the BIOS firmware is increased. The BIOS firmware in the first memory is the same as the BIOS firmware in the second memory, and it can be understood that the BIOS firmware in the first memory and the BIOS firmware in the second memory are backups of each other. Of course, the number of memories is not limited in the embodiment of the application, and two memories are only taken as an example for illustration, and the method is also applicable to more memory application scenarios.
[0157] As shown in Figure 5 , Fig. 4 is a flowchart of another BIOS firmware security check method provided by the embodiment of the application. The method comprises the following steps: Figure 5 S401: The business core receives a BIOS check command.
[0158] S501: The business core receives a BIOS check command.
[0159] In a possible implementation, the BIOS check command is used to instruct to check the BIOS firmware in the first memory. The BIOS check command can be used to instruct to check only the BIOS firmware in a certain memory, such as checking only the BIOS firmware in the first memory or checking only the BIOS firmware in the second memory.
[0160] S502: The business core sends the BIOS check command to the security core.
[0161] S503: The security core switches the object accessible to the first memory to the security core, and switches the object accessible to the second memory to the in-band processor.
[0162] The secure core switches the accessible object of the memory indicated by the BIOS verification command to the secure core and switches the accessible object of another memory to the in-band processor after receiving the BIOS verification command. In the embodiment of the application, the BIOS verification command is used to indicate to verify the BIOS firmware in the first memory, so the access right of the first memory is transferred to the secure core, and the access right of the second memory is transferred to the in-band processor. As an example, the in-band processor has the access right of the second memory, so the secure core does not need to adjust the access right of the second memory, and only needs to ensure that the in-band processor cannot access the first memory, and the secure core has the access right of the first memory and can correctly access the first memory to verify the BIOS firmware.
[0163] In the application scenario of storing the BIOS firmware in multiple memories at the same time, if the BIOS firmware is not verified, the in-band memory can have the access right of multiple memories at the same time, or can have the access right of only one memory.
[0164] S504: The secure core accesses the first memory and verifies the BIOS firmware.
[0165] After the accessible object of the first memory is successfully switched to the secure core, the secure core can access the first memory and further verify the BIOS firmware in the first memory. In the embodiment of the application, the secure core can verify the BIOS firmware by using the OTP storage area, and the specific implementation process can refer to steps S204 and S2041-S2044.
[0166] S505: The secure core sends the BIOS verification result to the business core.
[0167] The BIOS verification result is the result obtained by verifying the BIOS firmware in the first memory. After the secure core verifies the BIOS firmware in the first memory and obtains the BIOS verification result, the secure core can send the BIOS verification result to the business core, and the business core can further process according to the BIOS verification result.
[0168] S506: The business core feeds back the BIOS verification result.
[0169] The business core can display the BIOS verification result to the administrator in a visual manner, so that the administrator can intuitively understand the current state of the BIOS firmware.
[0170] In the embodiment of the present application, by setting at least two memories to store the BIOS firmware, when the BIOS firmware in a certain memory is verified, the in-band processor can access the BIOS firmware in the other memory to implement the BIOS service function, that is, during the verification of the BIOS firmware by the BMC chip, the BMC chip does not need to suspend the BIOS service function of the in-band processor, and the in-band processor can still implement the BIOS service function, further realizing the security verification of the BIOS firmware during the running of the server and the in-band processor.
[0171] In a possible implementation, when the security core verifies that the BIOS firmware in the first memory passes the verification, the security core can transfer the access right of the first memory to the in-band processor, and temporarily remove the access right of the second memory from the in-band processor, so that the in-band memory implements the BIOS service function by using the BIOS firmware that has just passed the security verification, further improving the security of the operating system.
[0172] In another possible implementation, the BMC chip can perform security verification on the BIOS firmware in multiple memories in sequence. For example, the BMC chip verifies the BIOS firmware in the first memory and the second memory in sequence, as shown in FIG. 6. Figure 6 Figure 6 FIG. 7 is another flowchart of a method for security verification of BIOS firmware provided in the embodiment of the present application. The method comprises the following steps:
[0173] S601: The service core receives a BIOS verification command.
[0174] In a possible implementation, the BIOS verification command is used to indicate that the BIOS firmware in the first memory is verified first, and then the BIOS firmware in the second memory is verified.
[0175] S602: The service core sends the BIOS verification command to the security core.
[0176] S603: The security core switches the object that can access the first memory to the security core, and switches the object that can access the second memory to the in-band processor.
[0177] According to the indication of the BIOS verification command, the security core verifies the BIOS firmware in the first memory first, switches the accessible object of the first memory to the security core, that is, transfers the access right of the first memory to the security core, and switches the accessible object of the second memory to the in-band processor, to ensure that the in-band processor can access the BIOS firmware in the second memory to implement the corresponding BIOS service function during the verification of the BIOS firmware in the first memory by the security core.
[0178] S604: The security core accesses the first memory and checks the BIOS firmware.
[0179] After the accessible object of the first memory is successfully switched to the security core, the security core can access the first memory and check the BIOS firmware in the first memory. In the embodiment of the present application, the security core can use the OTP storage area to securely check the BIOS firmware, and the specific implementation process can refer to steps S204 and S2041-S2044.
[0180] S605: The security core sends the first BIOS check result to the service core.
[0181] The first BIOS check result is the result of checking the BIOS firmware in the first memory. After the security core checks the BIOS firmware in the first memory and obtains the first BIOS check result, the security core can send the first BIOS check result to the service core.
[0182] S606: The security core switches the accessible object of the second memory to the security core and switches the accessible object of the first memory to the in-band processor.
[0183] After the checking of the BIOS firmware in the first memory is completed, if the first BIOS check result indicates that the BIOS firmware in the first memory passes the check, the security core continues to check the BIOS firmware in the second memory. The security core switches the accessible object of the first memory to the in-band processor, that is, the security core transfers the access right of the first memory to the in-band processor, so that the in-band processor accesses the BIOS firmware in the first memory that passes the security check to implement the BIOS service function. Moreover, the security core switches the accessible object of the second memory to the security core, that is, the security core transfers the access right of the second memory to the security core, so that the security core accesses the BIOS firmware in the second memory for security check.
[0184] In another possible implementation, if the first BIOS check result indicates that the BIOS firmware in the first memory does not pass the check, the security core only switches the accessible object of the second memory to the security core, and the service core sends a first control instruction to the in-band processor according to the first BIOS check result to stop the BIOS service function of the in-band processor, and at the same time, the service core performs BIOS firmware exception alarm. When the BIOS firmware in the second memory passes the check and the security core transfers the access right of the second memory to the in-band processor, the service core sends a second control instruction to the in-band processor to restore the BIOS service function of the in-band processor.
[0185] S607: The security core accesses the second memory and checks the BIOS firmware.
[0186] After the accessible objects of the second memory are successfully switched to the secure core, the secure core can access the second memory, and then verify the BIOS firmware in the second memory. In the embodiment of the present application, the secure core can use the OTP storage area to securely verify the BIOS firmware, and the specific implementation process can refer to steps S204 and S2041-S2044.
[0187] S608: The secure core sends the second BIOS verification result to the business core.
[0188] The second BIOS verification result is the result obtained by verifying the BIOS firmware in the second memory. After the secure core verifies the BIOS firmware in the second memory and obtains the second BIOS verification result, the secure core can send the second BIOS verification result to the business core.
[0189] S609: The business core feeds back the first BIOS verification result and the second BIOS verification result.
[0190] After the business core receives the first BIOS verification result and the second BIOS verification result, the business core can display the first BIOS verification result and the second BIOS verification result to the administrator in a visual manner, so that the administrator can intuitively understand the current state of the BIOS firmware in each memory.
[0191] Through the above steps S601-S609, the BMC chip can verify the BIOS firmware in multiple memories in sequence, and enable the in-band processor to access the BIOS firmware in other memories to implement the BIOS business function during the BIOS verification process, thereby realizing the secure verification of the BIOS firmware during the running of the server and the in-band processor, and improving the stability of the operating system running.
[0192] In another possible implementation, if the first BIOS verification result indicates that the BIOS firmware in the first memory passes the verification, and the second BIOS verification result indicates that the BIOS firmware in the second memory passes the verification, the secure core can transfer the access right of at least one memory to the in-band processor. If only the BIOS firmware in the first memory passes the verification or only the BIOS firmware in the second memory passes the verification, the secure core transfers the access right of the memory that passes the BIOS firmware verification to the in-band processor, and ensures that the in-band processor cannot access the memory that does not pass the BIOS firmware verification. If the BIOS firmware in the first memory and the second memory does not pass the verification, the business core needs to send a first control instruction to the in-band processor to stop the BIOS business function of the in-band processor, and the secure core needs to ensure that the in-band processor cannot access the first memory and the second memory.
[0193] Through the above process, the BMC chip can control the in-band processor to access the memory verified by the BIOS firmware to implement the BIOS service function, and suspend the BIOS service function of the in-band processor when the BIOS firmware in the memory is not verified, so as to avoid the case that the in-band processor causes operation abnormality due to accessing the memory not verified by the BIOS firmware, and further improve the stability of the in-band processor running the operating system.
[0194] Based on the same inventive concept, the embodiment of the present application further provides a BIOS firmware security verification device. The device provides a solution to the problem similar to the implementation scheme described in the above method, and the same technical effects can be achieved. Here, it is not repeated. The device includes:
[0195] The receiving module is configured to receive a BIOS verification command, wherein the BIOS verification command is used to instruct to verify the BIOS firmware;
[0196] The switching module is configured to switch the accessible object of the memory from the in-band processor to the BMC, wherein the memory is used to store the BIOS firmware, and the in-band processor is used to access the memory to implement the BIOS service function;
[0197] The verification module is configured to verify the BIOS firmware in the memory by accessing the memory.
[0198] In a possible implementation, the switching module is specifically configured to switch the accessible object of the memory to the BMC by controlling the general input and output pin of the memory.
[0199] In a possible implementation, the verification module is specifically configured to access the memory and verify the BIOS firmware by using the one-time programmable (OTP) storage area.
[0200] In a possible implementation, the verification module is specifically configured to read the root public key in the OTP storage area, verify the secondary key certificate of the BIOS firmware by using the root public key, obtain the public key from the secondary key certificate after the secondary key certificate is verified, and verify the BIOS firmware by using the public key.
[0201] In a possible implementation, the apparatus further includes a start-stop module, configured to send a first control instruction to the in-band processor before the BIOS firmware in the memory is verified by accessing the memory, where the first control instruction is used to instruct the in-band processor to stop performing a service function that needs to access the memory or the BIOS firmware; and send a second control instruction to the in-band processor in response to the BIOS firmware passing the verification, where the second control instruction is used to instruct the in-band processor to resume performing the service function that needs to access the memory or the BIOS firmware.
[0202] In a possible implementation, the memory includes a first memory and a second memory, and the first memory and the second memory respectively store the BIOS firmware, and the BIOS verification command is used to instruct to verify the BIOS firmware in the first memory;
[0203] The switching module is specifically configured to switch the accessible object of the first memory to the BMC and switch the accessible object of the second memory to the in-band processor.
[0204] The verification module is specifically configured to verify the BIOS firmware in the first memory by the BMC accessing the first memory.
[0205] In a possible implementation, the memory includes a first memory and a second memory, and the first memory and the second memory respectively store the BIOS firmware, and the BIOS verification command is used to instruct to verify the BIOS firmware in the first memory;
[0206] The switching module is specifically configured to switch the accessible object of the first memory to the BMC and switch the accessible object of the second memory to the in-band processor, and switch the accessible object of the second memory to the BMC and switch the accessible object of the first memory to the in-band processor after the BIOS firmware in the first memory passes the verification.
[0207] The verification module is specifically configured to verify the BIOS firmware in the first memory by accessing the first memory, and verify the BIOS firmware in the second memory by accessing the second memory after the BMC switches the accessible object of the second memory to the BMC.
[0208] In a possible implementation, the BMC includes a security core and a business core, and the switching module is specifically configured to receive the BIOS verification command, send the BIOS verification command to the security core through the business core, and switch the accessible object of the memory to the security core according to the BIOS verification command through the security core.
[0209] The verification module is specifically configured to perform security verification on the BIOS firmware in the memory through the security core.
[0210] In a possible implementation, the switching module is further configured to switch the accessible object of the memory to the in-band processor through the security core in response to a BIOS verification result indicating that the BIOS firmware in the memory passes the security verification.
[0211] The embodiments of the present application also provide a corresponding server, as shown in the figure, the server 700 includes: a detection device 701 and a memory 702; Figure 7
[0212] The detection device 701 is configured to perform the security verification method of the BIOS firmware according to any of the embodiments of the present application, and the memory 702 is configured to store the BIOS firmware.
[0213] The embodiments of the present application also provide a corresponding device and a computer storage medium, which are used to implement the schemes provided by the embodiments of the present application.
[0214] The device includes a memory and a processor, the memory is configured to store instructions or codes, and the processor is configured to execute the instructions or codes, so that the device performs the security verification method of the BIOS firmware according to any of the embodiments of the present application.
[0215] The computer storage medium stores codes, and when the codes are executed, the device executing the codes implements the security verification method of the BIOS firmware according to any of the embodiments of the present application.
[0216] The "first", "second" (if any) in the names mentioned in the embodiments of the present application are only used for name identification, and do not represent the first and second in order.
[0217] Those skilled in the art can clearly understand the above-mentioned method of the embodiment, all or part of the steps in the above-mentioned method can be realized by means of software and a general hardware platform. Based on this understanding, the technical solutions of the present application can be embodied in the form of a software product. The computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the method described in each embodiment or some parts of the embodiments of the present application.
[0218] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, it is described relatively simply, and the relevant part can be referred to the part of the method embodiment. According to the actual needs, part or all of the modules can be selected to achieve the purpose of the embodiment. Those skilled in the art can understand and implement without creative labor.
[0219] The above-mentioned is only an exemplary embodiment of the present application, and is not used to limit the protection scope of the present application.
Claims
1. A method for security verification of a BIOS firmware, characterized in that, The method comprises the following steps: A baseboard management controller (BMC) receives a BIOS verification command, the BIOS verification command being used to instruct to perform security verification on BIOS firmware in a first memory; The BMC switches an accessible object of the memory used to store the BIOS firmware from an in-band processor to the BMC, the in-band processor being used to access the memory to implement a BIOS service function; the memory comprises the first memory and a second memory, and the first memory and the second memory respectively store the BIOS firmware; The BMC performs security verification on the BIOS firmware in the memory by accessing the memory; The BMC receives a BIOS verification command and switches an accessible object of the memory to the BMC, comprising the following steps: The BMC switches an accessible object of the first memory to the BMC and switches an accessible object of the second memory to the in-band processor; The BMC performs security verification on the BIOS firmware in the memory by accessing the memory, comprising the following steps: The BMC accesses the first memory to perform security verification on the BIOS firmware in the first memory.
2. The method of claim 1, wherein, The BMC switches an accessible object of the memory from the in-band processor to the BMC, comprising the following steps: The BMC switches the accessible object of the memory to the BMC by controlling a general input / output pin of the memory.
3. The method of claim 1, wherein, The BMC performs security verification on the BIOS firmware in the memory by accessing the memory, comprising the following steps: The BMC accesses the memory and performs security verification on the BIOS firmware by using an one-time programmable (OTP) storage area.
4. The method of claim 3, wherein, The BMC performs security verification on the BIOS firmware by using the OTP storage area, comprising the following steps: The BMC reads a root public key in the OTP storage area; The BMC verifies a second-level key certificate of the BIOS firmware by using the root public key; After the second-level key certificate verification passes, the BMC obtains a public key from the second-level key certificate and performs security verification on the BIOS firmware by using the public key.
5. The method of claim 1, wherein, Before the BMC performs security verification on the BIOS firmware in the memory by accessing the memory, the method further comprises the following steps: The BMC sends a first control instruction to the in-band processor, the first control instruction being used to instruct the in-band processor to stop performing a service function that needs to access the memory or the BIOS firmware; The method further comprises the following steps: The BMC sends a second control instruction to the in-band processor in response to the BIOS firmware passing the verification, the second control instruction being used to instruct the in-band processor to resume performing the service function that needs to access the memory or the BIOS firmware.
6. The method of claim 1, wherein, The memory comprises a first memory and a second memory, and the first memory and the second memory respectively store the BIOS firmware, and the BIOS verification command is used to indicate that the BIOS firmware in the first memory is verified first, and then the BIOS firmware in the second memory is verified; The BMC receives the BIOS verification command and switches the accessible object of the memory to the BMC, comprising: The BMC switches the accessible object of the first memory to the BMC and switches the accessible object of the second memory to the in-band processor; After the BIOS firmware in the first memory is verified, the BMC switches the accessible object of the second memory to the BMC and switches the accessible object of the first memory to the in-band processor; The BMC verifies the BIOS firmware in the memory by accessing the memory, comprising: The BMC accesses the first memory to verify the BIOS firmware in the first memory; After the BMC switches the accessible object of the second memory to the BMC, the BMC accesses the second memory to verify the BIOS firmware in the second memory.
7. The method of claim 1, wherein, The BMC comprises a security core and a business core; the BMC receives the BIOS verification command and switches the accessible object of the memory to the BMC, comprising: The business core receives the BIOS verification command and sends the BIOS verification command to the security core; The security core switches the accessible object of the memory to the security core according to the BIOS verification command; The BMC verifies the BIOS firmware in the memory by accessing the memory, comprising: The security core verifies the BIOS firmware in the memory by accessing the memory.
8. The method of claim 7, wherein, The method further comprises: The security core switches the accessible object of the memory to the in-band processor in response to a BIOS verification result indicating that the BIOS firmware in the memory is verified.
9. A server, characterized by The server comprises a detection device, and the detection device is used to implement the BIOS firmware verification method according to any one of claims 1-8.
Citation Information
Patent Citations
Security detection system, method and device and storage medium
CN113868667A
Baseboard management controller firmware security system
US20220245222A1