A security verification method, device, equipment, medium and product when a system starts

By determining the software startup order and performing successive loop verification in the embedded system, the problem of the lack of a hardware root of trust in the embedded system is solved, and the secure startup and trusted verification of the system are realized.

CN119106436BActive Publication Date: 2026-02-03BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411250520.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2026-02-03
Estimated Expiration
2044-09-06

AI Technical Summary

Technical Problem

In embedded systems, without a hardware root of trust, the boot module developed by the device vendor cannot guarantee the trustworthiness of the software boot chain, resulting in unreliable system boot security.

Method used

By determining the startup order of the first type of software and the second type of software, a successive cyclical verification is performed, including security verification, verification by third-party institutions accessing the system, and reverse verification, forming a three-party cyclical verification method to ensure the secure startup of the system.

Benefits of technology

It implements security verification of software during system startup, ensuring reliable system startup and avoiding verification failures caused by factors such as unstable voltage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119106436B_ABST
    Figure CN119106436B_ABST
Patent Text Reader

Abstract

The application discloses a kind of security verification method, device, equipment, medium and product when system starts.The method comprises: in response to power-on reset operation, the software start order of first type software and second type software is determined;According to software start order, successive cyclic verification is carried out, and corresponding verification result is obtained;Wherein, verification at least includes one of the following: security verification between first type software and second type software, third party agency verification of access system, anti-verification;In the case where verification result passes, it is determined that system is safely started.The embodiment of the application determines the software start order of the first type software and the second type software contained in the system starting process, and carries out successive cyclic verification and anti-verification according to the software start order, forms the mode of three-party cyclic verification, and realizes the security start verification of system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, device, medium, and product for security verification during system startup. Background Technology

[0002] In some embedded systems, the kernel system is provided uniformly by the administrator, allowing device providers to select their own components. In this case, the kernel layer and driver layer are separated. The device provider develops its own bootloader and driver, while the administrator provides privileged applications, such as those for application management and security management. Business-related applications are provided by the device provider. Without a hardware root of trust, the first software module during startup is provided by the device provider, which cannot guarantee the trustworthiness of subsequent secure boot chains. Summary of the Invention

[0003] In view of this, the present invention provides a method, apparatus, device, medium and product for security verification during system startup, which can realize security startup verification of the system.

[0004] According to one aspect of the present invention, an embodiment of the present invention provides a security verification method during system startup, the method comprising:

[0005] In response to a power-on reset operation, the software startup order of the first type of software and the second type of software is determined;

[0006] The software startup sequence is used to perform successive loop verifications to obtain corresponding verification results; wherein, the verification includes at least one of the following: security verification between the first type of software and the second type of software, verification by a third-party organization accessing the system, and reverse verification;

[0007] If the verification result passes, the system is confirmed to start securely.

[0008] According to another aspect of the present invention, embodiments of the present invention also provide a security verification device for system startup, the device comprising:

[0009] The sequence determination module is used to determine the software startup order of the first type of software and the second type of software in response to a power-on reset operation;

[0010] The successive verification module is used to perform successive cyclic verification according to the software startup order to obtain the corresponding verification results; wherein, the verification includes at least one of the following: security verification between the first type of software and the second type of software, verification by a third-party organization accessing the system, and reverse verification;

[0011] The startup module is used to determine that the system is safely started if the verification result passes.

[0012] According to another aspect of the present invention, embodiments of the present invention also provide an electronic device, the electronic device comprising:

[0013] At least one processor; and

[0014] A memory communicatively connected to the at least one processor; wherein,

[0015] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the security verification method for system startup as described in any embodiment of the present invention.

[0016] According to another aspect of the present invention, embodiments of the present invention also provide a computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a processor to execute and implement the system startup security verification method described in any embodiment of the present invention.

[0017] According to another aspect of the present invention, an embodiment of the present invention also provides a computer program product, characterized in that the computer program product includes a computer program, which, when executed by a processor, implements the system startup security verification method described in any embodiment of the present invention.

[0018] The technical advantage of this invention lies in the fact that, during the system startup process, the startup order of the included first type of software and second type of software is determined, and successive cyclic verification and reverse verification are performed according to the software startup order to form a three-way cyclic verification method, thereby achieving secure startup verification of the system.

[0019] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 A flowchart illustrating a system startup security verification method according to an embodiment of the present invention;

[0022] Figure 2A flowchart illustrating another system startup security verification method provided in an embodiment of the present invention;

[0023] Figure 3 A power-on startup flowchart for a management software that is not the first software to be started, provided as an embodiment of the present invention;

[0024] Figure 4 This is a flowchart illustrating another system startup security verification method provided in an embodiment of the present invention;

[0025] Figure 5 This is a schematic diagram of the structural framework of a system startup security verification method according to an embodiment of the present invention;

[0026] Figure 6 This is a structural block diagram of a security verification device for system startup provided in an embodiment of the present invention;

[0027] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0028] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0030] In one embodiment, Figure 1This is a flowchart of a system startup security verification method provided in an embodiment of the present invention. This embodiment is applicable to the situation of performing security verification on the startup of the operating system. The method can be executed by a system startup security verification device, which can be implemented in hardware and / or software. The system startup security verification device can be configured in an electronic device. For example, the electronic device in this embodiment can include industrial control equipment, such as smart power equipment such as electricity meters or switches.

[0031] like Figure 1 As shown, the security verification method during system startup in this embodiment includes the following specific steps:

[0032] S110. In response to the power-on reset operation, determine the software startup order of the first type of software and the second type of software.

[0033] The first type of software can be understood as equipment provider software, and the second type of software can be understood as management software. Management software can include multiple management software programs, which can be used for extended applications.

[0034] In one embodiment, the first type of software includes: a first device provider software and a second device provider software; the second type of software includes: a first management software and a second management software; the software startup order is as follows: first device provider software, first management software, second management software, and second device provider software.

[0035] In this embodiment, the device provider software may include a first device provider software and a second device provider software. The first device provider software may be a bootloader, responsible for loading the operating system or other applications when the computer system starts. The second device provider software may be a driver. The management software in this embodiment may include a first management software and a second management software. The first management software may be a kernel / OS operating system software. The second management software may include multiple management software programs. For example, the second management software may include management software 21, which is application management software with functions such as application management, message routing, and module access. It may also include management software 22, which is security management software with security authentication and encryption / decryption functions. Of course, the second management software may also be combined into a single software program, namely the management software; this embodiment does not impose any limitations on this.

[0036] In this embodiment, in response to the power-on reset operation, that is, when the embedded system is powered on or the reset button is pressed, the system will perform a reset operation, clear the system state to zero, and set the processor's program counter to the start address. At this time, the software startup order of the first type of software and the second type of software is determined, and the startup order is: first device provider software, first management software, second management software, and second device provider software.

[0037] S120. Perform sequential verification according to the software startup order to obtain the corresponding verification results; wherein, the verification includes at least one of the following: security verification between the first type of software and the second type of software, verification by a third-party organization accessing the system, and reverse verification.

[0038] Third-party verification refers to the verification process using a connected third-party organization. In this embodiment, third-party verification may include, but is not limited to, third-party certification bodies, third-party testing organizations, and the device installer / mounter / user. Reverse verification can be understood as the process where, after verification reaches the second management software during system startup, the second management software then performs verification on the first device provider.

[0039] In this embodiment, sequential verification is performed according to the software startup order to obtain the corresponding verification results; wherein, the verification includes at least one of the following: security verification between the first type of software and the second type of software, verification by a third-party organization accessing the system, and reverse verification. In some embodiments, following the software startup sequence, the first device provider software is started first. After the first device provider software passes its self-test, a preset secure startup algorithm library package is called to perform a first security check on the first management software to obtain a first verification result. It should be noted that if a third-party organization is required to perform security verification at this time, after obtaining the first verification result, the first management software is verified by a preset third-party organization. After the aforementioned security verification passes, the first management software is used to perform a security verification on the second management software to obtain the corresponding verification result. Similarly, the second management software can be verified by a preset third-party organization, and after the security verification passes, the second management software is used to perform a reverse verification on the first device provider software to obtain the corresponding reverse verification result. Likewise, the first device provider software can be reverse verified by a preset third-party organization, and after the reverse verification passes, the second management software is used to perform a security verification on the second device provider software. If required, the second device provider software is then verified by a preset third-party organization, and after the verification result passes, the second device provider software is launched.

[0040] S130. If the verification result passes, confirm that the system is started securely.

[0041] In this embodiment, if all verification results pass during the system startup process, the system is determined to be able to start safely. It should be noted that the security verification and reverse verification processes described above involve one or more verifications. Only after one or more verifications pass can the system be considered to have passed the verification and be determined to have started safely.

[0042] The technical solution of this invention achieves secure system startup verification by determining the startup order of the first type of software and the second type of software during system startup, and performing successive cyclic verification and reverse verification according to the software startup order to form a three-way cyclic verification method.

[0043] In one embodiment, Figure 2 This is a flowchart of another system startup security verification method provided by an embodiment of the present invention. Based on the above embodiments, this embodiment further refines the method of performing successive cyclic verification according to the software startup order to obtain the corresponding verification results.

[0044] like Figure 2 As shown, the security verification method during system startup in this embodiment may specifically include the following steps:

[0045] S210. In response to the power-on reset operation, determine the software startup order of the first type of software and the second type of software.

[0046] S220. Start the first equipment provider software. After the first equipment provider software passes the self-test, call the preset secure startup algorithm library package to perform the first security check on the first management software and obtain the first check result.

[0047] The preset secure boot algorithm library package may include libraries for integrity verification, signature value verification, and interfaces for application installation and application launch, which are corresponding to security checks.

[0048] In this embodiment, the first security verification may include: integrity verification, confidentiality verification, repudiation verification, and verifiability verification. The first device provider software is started. After the first device provider software passes its self-verification, a preset secure startup algorithm library package is called to perform one or more first security verifications on the first management software to obtain the corresponding first verification result. If the first verification result is successful, the next verification can proceed. Specifically, the software of the first equipment provider is used as the verifier, and the software of the first management party is used as the verifiable party. The verifier performs integrity verification, confidentiality verification, repudiation verification, and verifiability verification on the verifiable party to obtain the corresponding verification results. In this embodiment, integrity verification can use, but is not limited to, Secure Hash Algorithm 1 (SHA1), Secure Hash Algorithm 256-bit (SHA256), and Cryptographic Hash Algorithm SM3; confidentiality verification can use Data Encryption Standard (DES), Triple Data Encryption Algorithm (TDES), Advanced Encryption Standard (AES), or the Chinese national cryptographic algorithm SM1 (SM1 cryptographic algorithm) or the Chinese national cryptographic algorithm SM4 (SM4 block cipher); non-repudiation and verifiability can use RSA encryption algorithm (Rivest Shamir Adleman, RSA) or elliptic curve cryptography. The algorithm (ECC) or the national cryptographic algorithm, the national cryptographic algorithm SM2 (SM2 cryptographic algorithm, SM2) or the national cryptographic algorithm SM9 (SM9 cryptographic algorithm, SM9).

[0049] More specifically, the integrity verification methods include: the verifier obtains the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content. The security verification content includes at least: a signature value, the starting address of the encrypted portion of the original code content, the code encryption length, and a key index; the key index corresponds to the encryption key and decryption key. The verifier performs integrity verification on the original code content and security verification content of the verified party according to a preset integrity verification algorithm. The confidentiality verification methods include: the verifier reads the starting address and encryption length of the encrypted portion of the code from the security verification content of the verified party, selects a key encryption method based on the key index to decrypt the encrypted portion of the code, and fills it into the starting address of the encrypted portion to obtain plaintext. The verifier then performs integrity verification on the plaintext using a preset integrity verification algorithm, and determines the confidentiality verification result based on the integrity verification result. The non-repudiation verification and checkability verification methods both include: the verifier obtains the original code content corresponding to the verified party and the configured security verification content, and performs verification on the original code content and the configured security verification content according to a preset verification algorithm.

[0050] S230. After the first verification result is that the verification is passed, the first management software is used to perform a second security verification on the second management software to obtain a second verification result.

[0051] In this embodiment, the second security verification may include: integrity verification, confidentiality verification, repudiation verification, and verifiability verification. In this embodiment, after the first verification result is passed, the first management software performs a second security verification on the second management software to obtain a second verification result. Specifically, the first management software acts as the verifier, and the second management software acts as the verified party. The verifier performs integrity verification, confidentiality verification, repudiation verification, and verifiability verification on the verified party to obtain the corresponding verification results. Similarly, more specifically, the integrity verification method includes: the verifier obtains the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content, wherein the security verification content includes at least: a signature value, the starting address of the encrypted part of the original code content, the code encryption length, and a key index; wherein the key index corresponds to the encryption key and the decryption key; the integrity of the original code content and the security verification content of the verified party is verified according to a preset integrity verification algorithm; the confidentiality verification method includes: the verifier reads the starting address and code encryption length of the encrypted part of the code from the security verification content of the verified party, selects the key encryption method according to the key index to decrypt the encrypted part of the code, and fills it into the starting address of the encrypted part of the code to obtain the plaintext code, uses the preset integrity verification algorithm to verify the integrity of the plaintext code, and determines the confidentiality verification result based on the integrity verification result; in this embodiment, the non-repudiation verification and the verifiability verification methods both include: the verifier obtains the original code content corresponding to the verified party and the configured security verification content, and verifies the original code content and the configured security verification content according to a preset verification algorithm.

[0052] S240. After the second verification result is that the verification is passed, the second management software is used to perform the first reverse verification on the first equipment provider software to obtain the first reverse verification result.

[0053] The first reverse verification may include: integrity verification, confidentiality verification, repudiation verification, and verifiability verification.

[0054] In this embodiment, after the second verification result is passed, the second management software is used to perform a first reverse verification on the first equipment provider software to obtain a first reverse verification result. Specifically, the second management software is used as the verifier and the first equipment provider software is used as the verifier. The verifier performs integrity verification, confidentiality verification, repudiation verification, and verifiability verification on the verifier to obtain the corresponding verification results. Similarly, more specifically, the integrity verification methods include: the verifier obtains the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content. The security verification content includes at least: a signature value, the starting address of the encrypted portion of the original code content, the code encryption length, and a key index; where the key index corresponds to the encryption key and decryption key. The verifier performs integrity verification on the original code content and security verification content of the verified party according to a preset integrity verification algorithm. The confidentiality verification methods include: the verifier reads the starting address and encryption length of the encrypted portion of the code from the security verification content of the verified party, selects a key encryption method based on the key index to decrypt the encrypted portion of the code, and fills it into the starting address of the encrypted portion to obtain plaintext code. The verifier then performs integrity verification on the plaintext code using a preset integrity verification algorithm, and determines the confidentiality verification result based on the integrity verification result. The non-repudiation verification and checkability verification methods both include: the verifier obtains the original code content corresponding to the verified party and the configured security verification content; and the verifier performs verification on the original code content and the configured security verification content according to a preset verification algorithm.

[0055] S250. After the first reverse verification result is passed, the second management software is used to perform a third security verification on the second equipment provider software to obtain a third verification result. After the third verification result is passed, the second equipment provider software is launched.

[0056] The third security verification may include: integrity verification, confidentiality verification, repudiation verification, and verifiability verification.

[0057] In this embodiment, after the first reverse verification result is passed, the second management software performs a third security verification on the second device provider software to obtain a third verification result. After the third verification result is passed, the second device provider software is launched, and the system is securely started. Specifically, the second management software acts as the verifier, and the second device provider software acts as the verified party. The verifier performs integrity verification, confidentiality verification, repudiation verification, and checkability verification on the verified party to obtain the corresponding verification results. Similarly, more specifically, the integrity verification methods include: the verifier obtains the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content. The security verification content includes at least: a signature value, the starting address of the encrypted portion of the original code content, the code encryption length, and a key index; where the key index corresponds to the encryption key and decryption key. The verifier performs integrity verification on the original code content and security verification content of the verified party according to a preset integrity verification algorithm. The confidentiality verification methods include: the verifier reads the starting address and encryption length of the encrypted portion of the code from the security verification content of the verified party, selects a key encryption method based on the key index to decrypt the encrypted portion of the code, and fills it into the starting address of the encrypted portion to obtain plaintext code. The verifier then performs integrity verification on the plaintext code using a preset integrity verification algorithm, and determines the confidentiality verification result based on the integrity verification result. The non-repudiation verification and checkability verification methods both include: the verifier obtains the original code content corresponding to the verified party and the configured security verification content, and performs verification on the original code content and the configured security verification content according to a preset verification algorithm.

[0058] In one embodiment, the first security check, the second security check, and the third security check all include: integrity check, confidentiality check, repudiation check, and verifiability check; the fourth security check, the fifth security check, and the sixth security check all include: verifiability check; the first reverse check includes: integrity check, confidentiality check, repudiation check, and verifiability check; the second reverse check includes: verifiability check; and the seventh security check and the eighth security check both include: integrity check, confidentiality check, repudiation check, and verifiability check.

[0059] In one embodiment, the verification is performed once, or at least twice. In this embodiment, the verification can be performed cyclically once or multiple times to avoid verification failures caused by unstable voltage in the flash memory, embedded security chip, or security module.

[0060] In one embodiment, the integrity verification method includes: the verifier obtaining the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content. The security verification content includes at least: a signature value, the starting address of the encrypted portion of the original code content, the code encryption length, and a key index; wherein the key index corresponds to the encryption key and the decryption key; and the integrity of the original code content and the security verification content of the verified party is verified according to a preset integrity verification algorithm. The preset integrity verification algorithm is not limited to international algorithms SHA1, SHA256, or Chinese cryptographic algorithm SM3. For example, an integrity verification value, such as a 20-byte hash value HASH_A, is added to the instruction for code download. After the code is fully received, a cryptographic machine or simulation algorithm is called to calculate a 20-byte hash value HASH_B. If HASH_B equals HASH_A, the integrity verification is considered successful; otherwise, it fails.

[0061] In one embodiment, the confidentiality verification method includes: the verifier reads the starting address and encryption length of the encrypted code portion from the security verification content of the verifier; decrypts the encrypted code portion using a key encryption method selected according to the key index; fills the decrypted code portion into the starting address of the encrypted code portion to obtain plaintext code; performs integrity verification on the plaintext code using a preset integrity verification algorithm; and determines the confidentiality verification result based on the integrity verification result. It can be understood that the confidentiality verification method requires performing confidentiality verification first, followed by integrity verification. Confidentiality verification can use international algorithms such as DES, TDES, and AES, or national cryptographic algorithms such as SM1 and SM4. For example, based on the starting address and encryption length of the encrypted code portion, the encrypted code portion is read out; according to the key index, the corresponding algorithm is called to decrypt the encrypted portion; the decrypted code portion is filled into the starting address of the encrypted code portion; and combined with integrity verification, the confidentiality of the code is guaranteed.

[0062] In one embodiment, the non-repudiation verification, verifiability verification, and authenticity verification all include: the verifying party obtaining the original code content corresponding to the verified party, as well as the configured security verification content; and verifying the original code content and the configured security verification content according to a preset verification algorithm. The preset verification algorithm may include, but is not limited to, international algorithms such as RSA and ECC, or national cryptographic algorithms such as SM2 and SM9. For example, a signature value, such as a 128-byte signature value SIGN_A, is appended to the code download instruction or code. After the code is fully received, a cryptographic machine or simulation algorithm is called to calculate a 128-byte signature value SIGN_B. If SIGN_A equals SIGN_B, the signature value verification is considered successful; otherwise, it fails.

[0063] In one embodiment, a first verification interface of a third-party verification agency is pre-configured between the first device provider software and the first management software; a second verification interface of a third-party verification agency is pre-configured between the first management software and the second management software; a third verification interface of a third-party verification agency is pre-configured between the second management software and the first device provider software; and a fourth verification interface of a third-party verification agency is pre-configured between the second management software and the second device provider software. Correspondingly, after obtaining one of the first verification result, the second verification result, the first reverse verification result, and the third verification result, the security verification method further includes:

[0064] The fourth security verification result is obtained by having a pre-set third-party organization perform a fourth security verification on the first management software.

[0065] After the fourth verification result is passed, the second management software is subjected to a fifth security verification by a pre-set third-party organization to obtain the fifth verification result.

[0066] After the fifth verification result is passed, the software of the first equipment provider is subjected to a second reverse verification by a preset third-party organization to obtain the second reverse verification result.

[0067] After the second reverse verification result is passed, the second device provider software is subjected to a sixth security verification by a preset third-party organization to obtain the sixth verification result. After the sixth verification result is passed, the second device provider software is launched.

[0068] The fourth, fifth, and sixth security checks all include a verifiability check. The second reverse check also includes a verifiability check.

[0069] In this embodiment, after performing a first security check on the first management software by calling a preset secure boot algorithm library package, a third-party organization can be introduced for verification as needed. Similarly, after performing a second security check on the second management software using the first management software, performing a first reverse check on the first device provider software using the second management software, and performing a third security check on the second device provider software using the second management software to obtain a third verification result, a third-party verification organization can be added as needed to perform corresponding security checks and reverse checks. Specifically, the third-party verification organization is used as the verification party, and the first management software, second management software, second device provider software, and first device provider software are used as the verifiable entities for checkability verification. More specifically, the checkability verification method includes: the verification party obtains the original code content corresponding to the verifiable entity and the configured security verification content, and verifies the original code content and the configured security verification content according to a preset verification algorithm.

[0070] In one embodiment, the second management software includes: a third management software and a fourth management software, wherein the third management software is started earlier than the fourth management software;

[0071] Accordingly, the second security verification is performed on the second management software using the first management software to obtain the second verification result, including:

[0072] The seventh security check was performed on the third-party software using the first-party management software, and the seventh check result was obtained.

[0073] If the seventh verification result is successful, the first management software performs an eighth security verification on the fourth management software to obtain the eighth verification result, and uses the eighth verification result as the second verification result. If the second verification result is successful, the second management software is launched.

[0074] The seventh and eighth security checks both include: integrity check, confidentiality check, repudiation check, and verifiability check.

[0075] In this embodiment, the first management software performs a seventh security check on the third management software to obtain a seventh check result. If the seventh check result is successful, the first management software performs an eighth security check on the fourth management software to obtain an eighth check result. This eighth check result is used as the second check result. If the second check result is successful, the second management software is launched. Specifically, the first management software acts as the verifier, and the third and fourth management software act as the verifiers, performing integrity checks, confidentiality checks, repudiation checks, and checkability checks. More specifically, the integrity verification methods include: the verifier obtains the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content. The security verification content includes at least: a signature value, the starting address of the encrypted portion of the original code content, the code encryption length, and a key index; the key index corresponds to the encryption key and decryption key. The verifier performs integrity verification on the original code content and security verification content of the verified party according to a preset integrity verification algorithm. The confidentiality verification methods include: the verifier reads the starting address and encryption length of the encrypted portion of the code from the security verification content of the verified party, selects a key encryption method based on the key index to decrypt the encrypted portion of the code, and fills it into the starting address of the encrypted portion to obtain plaintext code. The verifier then performs integrity verification on the plaintext code using a preset integrity verification algorithm, and determines the confidentiality verification result based on the integrity verification result. The non-repudiation verification and checkability verification methods both include: the verifier obtains the original code content corresponding to the verified party and the configured security verification content, and performs verification on the original code content and the configured security verification content according to a preset verification algorithm.

[0076] In one embodiment, the security verification method further includes:

[0077] The third-party management software and the fourth-party management software perform mutual security verification to obtain the corresponding verification results. If each verification result is successful, both the third-party management software and the fourth-party management software are launched.

[0078] Mutual security checks include: integrity checks and verifiability checks.

[0079] In this embodiment, the third-party management software and the fourth-party management software perform mutual security verification to obtain corresponding verification results. If each verification result is successful, both the third-party management software and the fourth-party management software are launched. The mutual security verification includes integrity verification and checkability verification. Specifically, the third-party management software is used as the verifier, and the fourth-party management software is used as the verified party for integrity and checkability verification. Then, the fourth-party management software is used as the verifier, and the third-party management software is used as the verified party for integrity and checkability verification. More specifically, the integrity verification methods include: the verifier obtaining the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content. The security verification content includes at least: a signature value, the starting address of the encrypted portion of the original code content, the code encryption length, and a key index; where the key index corresponds to the encryption key and decryption key. The integrity of the original code content and security verification content of the verified party is verified according to a preset integrity verification algorithm. The verifiability verification methods all include: the verifier obtaining the original code content corresponding to the verified party and the configured security verification content, and verifying the original code content and the configured security verification content according to a preset verification algorithm.

[0080] In one embodiment, the security verification method further includes:

[0081] Self-inspection of the software of the first equipment provider, the software of the second equipment provider, the software of the first management party, and the software of the second management party; wherein, the self-inspection includes: authenticity inspection.

[0082] In this embodiment, the software of the first equipment provider, the software of the second equipment provider, the software of the first management party, and the software of the second management party undergo self-verification; wherein, the self-verification includes: authenticity verification. Specifically, authenticity verification can use international algorithms RSA and ECC or national cryptographic algorithms SM2 and SM9.

[0083] The technical solution of this invention involves starting the first device provider software, and after the first device provider software passes its self-test, calling a preset secure boot algorithm library package to perform a first security check on the first management software to obtain a first check result. If the first check result is successful, the first management software performs a second security check on the second management software to obtain a second check result. If the second check result is successful, the second management software performs a first reverse check on the first device provider software to obtain a first reverse check result. If the first reverse check result is successful, the second management software performs a third security check on the second device provider software to obtain a third check result. The third check result is then considered the final verification result. After successful verification, the second device provider software is launched, and the system securely starts. A fourth security check is performed on the first management software by a pre-set third-party organization, yielding a fourth verification result. If the fourth verification result is successful, a fifth security check is performed on the second management software by the pre-set third-party organization, yielding a fifth verification result. If the fifth verification result is successful, a second reverse verification is performed on the first device provider software by the pre-set third-party organization, yielding a second reverse verification result. If the second reverse verification result is successful, a sixth security check is performed on the second device provider software by the pre-set third-party organization, yielding a sixth verification result. If the sixth verification result is successful, the second device provider software is launched, and the system securely starts. In this embodiment, through the above security checks and the reverse verification method used to perform reverse verification on the first management software, a three-way cyclical verification method is formed between the first management software, the second management software, and the first device provider software to achieve secure startup verification.

[0084] In one embodiment, to facilitate a better understanding of the security verification method during system startup, Figure 3 This invention provides a power-on startup flowchart for a management software that is not the first software to be launched, as provided in one embodiment. Figure 4 This is a flowchart illustrating another system startup security verification method provided in an embodiment of the present invention. Figure 5This is a schematic diagram of the structural framework of a system startup security verification method according to an embodiment of the present invention. In this embodiment, the software startup includes, but is not limited to, device provider software 1, device provider software 2, management software 1, and management software 2; wherein, management software 2 may include management software 21 and management software 22. In this embodiment, the following example is used: device provider software 1 is the bootloader, device provider software 2 is the driver, management software 1 is the kernel / OS operating system, management software 21 is the application software, and management software 22 is the security management software. It should be noted that in this embodiment, device provider software 1 is the first device provider software in the above embodiment, device provider software 2 is the second device provider software in the above embodiment, management software 1 is the first management software in the above embodiment, and management software 2 is the second management software in the above embodiment. Furthermore, management software 21 in management software 2 is the third management software in the above embodiment, and management software 22 is the fourth management software in the above embodiment.

[0085] like Figure 3 , Figure 4 and Figure 5 As shown, the software startup sequence during system startup is as follows: after power-on reset, device provider software 1, management software 1, management software 2, and device provider software 2. Third-party verification is introduced between device provider software 1 and management software 1, between management software 1 and management software 2, and between management software 2 and device provider software 2. Furthermore, when the management software performs reverse verification on device provider software 1, third-party verification is also introduced. Of course, the aforementioned third-party verification can be added or omitted, depending on the requirements. In this embodiment, the addition of third-party verification is used as an example for explanation.

[0086] like Figure 4 and Figure 5 As shown, the device provider software 1, management software 1, and management software 2 form a three-way loop verification. In this embodiment, in the later stages of the startup process, a step-by-step verification method using verification and reverse verification is adopted. After security verification, a reverse verification is performed on the device provider software 1, forming a three-way loop verification method to achieve secure startup verification. In this embodiment, the security verification method during system startup specifically includes the following steps:

[0087] S410, in response to a power-on reset operation, determines the software startup order of the included first type of software and second type of software.

[0088] S420. Start the device provider software 1. After the device provider software 1 passes the self-verification, call the secure startup algorithm library package to perform integrity verification, confidentiality verification, repudiation verification, and checkability verification on the management software 1.

[0089] S430. If it is necessary to pre-set a third-party organization to perform checkability verification on the management software 1, add a third-party organization to perform checkability verification on the management software 1.

[0090] S440. If the verifiability test of the management software 1 is passed, the management software 1 will launch the management software 21 and perform integrity verification, confidentiality verification, repudiation verification, and verifiability verification. If the verification is successful, the management software 21 will be launched.

[0091] S450. If it is necessary to pre-set a third-party organization to perform checkability verification on the management software 21, add a third-party organization to perform checkability verification on the management software 21.

[0092] S460. If the verifiability test of the management software 21 is passed, the management software 1 will start the management software 22 and perform integrity verification, confidentiality verification, repudiation verification, and verifiability verification. If the verification is successful, the management software 22 will be started.

[0093] S470. If it is necessary to preset a third-party organization to perform checkability verification on the management software 22, add a third-party organization to perform checkability verification on the management software 22.

[0094] S480. If the verifiability test of the management software 22 passes, the management software 21 and the management software 22 shall mutually verify each other, including: integrity test and verifiability test.

[0095] S490. If the mutual verification passes, the management software 2 performs a reverse verification of the equipment provider software 1. The first reverse verification includes: integrity verification, confidentiality verification, repudiation verification, and verifiability verification. If the verification fails, the startup fails.

[0096] S4100. In cases where it is necessary to pre-set a third-party organization to perform reverse verification on the equipment provider software 1, a third-party organization is added to perform a second reverse verification on the equipment provider software 1. The second reverse verification includes: checkability verification.

[0097] S4110. If the second reverse verification passes, the management software 2 will perform a security verification on the device provider software 2. If the verification is successful, the device provider software 2 will be launched.

[0098] S4120. If a third-party organization is required to verify the equipment provider software 2, the third-party organization is added to perform integrity verification, confidentiality verification, repudiation verification, and verifiability verification on the equipment provider software 2. After the verification of the equipment provider software 2 is passed, it is launched and the system starts.

[0099] Table 1: Security Verification Table Performed by Verifying Software on Verified Software

[0100]

[0101]

[0102] In this embodiment, the verification can be performed multiple times, for example, 3-5 times, to avoid verification failures caused by unstable device voltage or other reasons.

[0103] In this embodiment, the verification content can be added to the instruction stream and code section of the code download; for example, code integrity verification can be added to the pre-download or download completion instruction, confidentiality verification can be performed by partially or completely encrypting the code, and non-repudiation and verifiability verification can be performed in the application installation instruction. The code is finally filled with a security part, which includes a signature value, the starting address of the encrypted code, the code encryption length, key index, etc.

[0104] In this embodiment, integrity verification can use, but is not limited to, international algorithms SHA1, SHA256 or national cryptographic algorithms SM3; confidentiality verification can use international algorithms DES, TDES, AES or national cryptographic algorithms SM1, SM4; non-repudiation, verifiability and authenticity verification can use international algorithms RSA, ECC or national cryptographic algorithms SM2, SM9.

[0105] In one embodiment, Figure 6 This is a structural block diagram of a system startup security verification device according to an embodiment of the present invention. The device is suitable for performing security verification on the startup of the operating system. The device can be implemented by hardware / software and can be configured in an electronic device to implement a system startup security verification method according to an embodiment of the present invention.

[0106] like Figure 6 As shown, the device includes: a sequence determination module 610, a successive verification module 620, and a startup module 630;

[0107] The sequence determination module 610 is used to determine the software startup order of the first type of software and the second type of software in response to the power-on reset operation.

[0108] The successive verification module 620 is used to perform successive cyclic verification according to the software startup order to obtain the corresponding verification results; wherein, the verification includes at least one of the following: security verification between the first type of software and the second type of software, verification by a third-party organization accessing the system, and reverse verification;

[0109] The startup module 630 is used to determine that the system is safely started if the verification result passes.

[0110] In this embodiment of the invention, the successive verification module determines the software startup order of the first type of software and the second type of software during the system startup process, and performs successive cyclic verification and reverse verification according to the software startup order to form a three-party cyclic verification method, thereby realizing the secure startup verification of the system.

[0111] In one embodiment, the first type of software includes: a first device provider software and a second device provider software; the second type of software includes: a first management software and a second management software.

[0112] The software startup order is as follows: first equipment provider software, first management software, second management software, and second equipment provider software.

[0113] In one embodiment, the successive verification module 620 includes:

[0114] The first verification unit is used to start the software of the first equipment provider. After the software of the first equipment provider passes the self-test, it calls the preset security startup algorithm library package to perform the first security verification on the software of the first management party to obtain the first verification result.

[0115] The second verification unit is used to perform a second security verification on the second management software using the first management software after the first verification result is that the verification is passed, and obtain a second verification result.

[0116] The first reverse verification unit is used to perform a first reverse verification on the first equipment provider software using the second management software after the second verification result is that the verification is passed, and obtain the first reverse verification result.

[0117] The third verification unit is used to perform a third security verification on the second device provider software using the second management software after the first reverse verification result is a successful verification, and to launch the second device provider software after the third verification result is a successful verification.

[0118] In one embodiment, a first verification interface of a third-party verification agency is pre-configured between the first device provider software and the first management software; a second verification interface of a third-party verification agency is pre-configured between the first management software and the second management software; a third verification interface of a third-party verification agency is pre-configured between the second management software and the first device provider software; and a fourth verification interface of a third-party verification agency is pre-configured between the second management software and the second device provider software.

[0119] Accordingly, after obtaining one of the first verification result, the second verification result, the first reverse verification result, and the third verification result, the security verification device further includes:

[0120] The fourth verification module is used to perform a fourth security verification on the first management software through a preset third-party organization to obtain a fourth verification result;

[0121] The fifth verification module is used to perform a fifth security verification on the second management software through a preset third-party organization after the fourth verification result is a successful verification, so as to obtain a fifth verification result.

[0122] The second reverse verification module is used to perform a second reverse verification on the software of the first equipment provider through a preset third-party organization after the fifth verification result is a verification pass to obtain a second reverse verification result.

[0123] The sixth verification module is used to perform a sixth security verification on the second device provider software through a preset third-party organization after the second reverse verification result is a successful verification, and to launch the second device provider software after the sixth verification result is a successful verification.

[0124] In one embodiment, the second management software includes a third management software and a fourth management software, wherein the third management software is started earlier than the fourth management software.

[0125] Correspondingly, the second verification unit includes:

[0126] The first verification subunit is used to perform a seventh security verification on the third management software using the first management software to obtain a seventh verification result.

[0127] The second verification subunit is used to perform an eighth security verification on the fourth management software using the first management software to obtain an eighth verification result when the seventh verification result is a successful verification. The eighth verification result is then used as the second verification result. When the second verification result is a successful verification, the second management software is launched.

[0128] In one embodiment, the security verification device further includes:

[0129] The mutual verification module is used to perform mutual security verification using third-party management software and fourth-party management software to obtain corresponding verification results. If each verification result is a pass, both the third-party management software and the fourth-party management software are launched.

[0130] The mutual security checks include: integrity checks and verifiability checks.

[0131] In one embodiment, the security verification device further includes:

[0132] The self-verification module is used for self-verification of the first equipment provider software, the second equipment provider software, the first management software, and the second management software; wherein, the self-verification includes: authenticity verification.

[0133] In one embodiment, the first security check, the second security check, and the third security check all include: integrity check, confidentiality check, repudiation check, and verifiability check;

[0134] The fourth, fifth, and sixth security checks all include: checkability check;

[0135] The first reverse verification includes: integrity verification, confidentiality verification, repudiation verification, and verifiability verification; the second reverse verification includes: verifiability verification.

[0136] Both the seventh and eighth security checks include: integrity check, confidentiality check, repudiation check, and verifiability check.

[0137] In one embodiment, the verification is performed once, or at least twice.

[0138] In one embodiment, the integrity verification method includes: the verifier obtaining the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content, wherein the security verification content includes at least: a signature value, the starting address of the encrypted part of the original code content, the code encryption length, and a key index; wherein the key index corresponds to the encryption key and the decryption key; and performing integrity verification on the original code content and security verification content of the verified party according to a preset integrity verification algorithm.

[0139] The confidentiality verification method includes: the verifier reads the starting address and encryption length of the encrypted code from the security verification content of the verifier, selects the key encryption method according to the key index to decrypt the encrypted code, and fills it into the starting address of the encrypted code to obtain the plaintext code. The verifier then uses a preset integrity verification algorithm to perform integrity verification on the plaintext code, and determines the confidentiality verification result based on the integrity verification result.

[0140] The methods for non-repudiation verification, verifiability verification, and authenticity verification all include: the verifier obtaining the original code content corresponding to the verifiable party, as well as the configured security verification content; and verifying the original code content and the configured security verification content according to a preset verification algorithm.

[0141] The system startup security verification device provided in the embodiments of the present invention can execute the system startup security verification method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0142] In one embodiment, Figure 7 This is a schematic diagram of an electronic device provided for an embodiment of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0143] like Figure 7 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0144] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0145] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as security verification methods during system startup.

[0146] In some embodiments, the system startup security verification method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the system startup security verification method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the system startup security verification method by any other suitable means (e.g., by means of firmware).

[0147] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0148] Computer programs used to implement the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a security verification device at startup of a general-purpose computer, special-purpose computer, or other programmable system, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0149] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0150] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0151] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0152] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0153] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0154] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A security verification method during system startup, characterized in that, include: In response to a power-on reset operation, the software startup order of the first type of software and the second type of software is determined; The software startup sequence is used to perform successive loop verifications to obtain corresponding verification results; wherein, the verification includes at least one of the following: security verification between the first type of software and the second type of software, verification by a third-party organization accessing the system, and reverse verification; If the verification result passes, the system is confirmed to start securely. The step of performing successive loop checks according to the software startup order to obtain the corresponding check results includes: The software of the first equipment provider is started. After the software of the first equipment provider passes the self-test, the preset security startup algorithm library package is called to perform the first security check on the software of the first management party and obtain the first check result. After the first verification result is passed, the first management software is used to perform a second security verification on the second management software to obtain a second verification result. After the second verification result is passed, the second management software is used to perform a first reverse verification on the first equipment provider software to obtain a first reverse verification result. After the first reverse verification result is passed, the second management software is used to perform a third security verification on the second equipment provider software to obtain a third verification result. After the third verification result is passed, the second equipment provider software is launched. A first verification interface of a third-party verification agency is pre-configured between the first equipment provider software and the first management software; a second verification interface of a third-party verification agency is pre-configured between the first management software and the second management software; a third verification interface of a third-party verification agency is pre-configured between the second management software and the first equipment provider software; and a fourth verification interface of a third-party verification agency is pre-configured between the second management software and the second equipment provider software. Accordingly, after obtaining one of the first verification result, the second verification result, the first reverse verification result, and the third verification result, the security verification method further includes: The fourth security verification result is obtained by having a pre-set third-party organization perform a fourth security verification on the first management software. After the fourth verification result is passed, the second management software is subjected to a fifth security verification by a preset third-party organization to obtain the fifth verification result. After the fifth verification result is passed, the software of the first equipment provider is subjected to a second reverse verification by a preset third-party organization to obtain a second reverse verification result. After the second reverse verification result is passed, the second device provider software is subjected to a sixth security verification by a preset third-party organization to obtain a sixth verification result. After the sixth verification result is passed, the second device provider software is launched. The first reverse verification includes: integrity verification, confidentiality verification, repudiation verification, and verifiability verification; the second reverse verification includes: verifiability verification.

2. The security verification method according to claim 1, characterized in that, The first type of software includes: first equipment provider software and second equipment provider software; the second type of software includes: first management software and second management software. The software startup order is as follows: first equipment provider software, first management software, second management software, and second equipment provider software.

3. The security verification method according to claim 1, characterized in that, The second management software includes: a third management software and a fourth management software, wherein the third management software is started earlier than the fourth management software; Accordingly, the step of using the first management software to perform a second security check on the second management software to obtain a second check result includes: The first management software is used to perform a seventh security check on the third management software to obtain a seventh check result. If the seventh verification result is successful, the first management software is used to perform an eighth security verification on the fourth management software to obtain an eighth verification result, and the eighth verification result is used as the second verification result. If the second verification result is successful, the second management software is launched.

4. The security verification method according to claim 3, characterized in that, The security verification method further includes: The third-party management software and the fourth-party management software perform mutual security verification to obtain corresponding verification results. If each verification result is a pass, the third-party management software and the fourth-party management software are both launched. The mutual security verification includes: integrity verification and verifiability verification.

5. The security verification method according to claim 1, characterized in that, The security verification method further includes: Self-testing of the software of the first equipment provider, the software of the second equipment provider, the software of the first management party, and the software of the second management party; wherein, the self-testing includes: authenticity testing.

6. The security verification method according to claim 3, characterized in that, The first security check, the second security check, and the third security check all include: integrity check, confidentiality check, repudiation check, and verifiability check; The fourth, fifth, and sixth security checks all include: checkability check; The first reverse verification includes: integrity verification, confidentiality verification, repudiation verification, and verifiability verification; the second reverse verification includes: verifiability verification. Both the seventh and eighth security checks include: integrity check, confidentiality check, repudiation check, and verifiability check.

7. The security verification method according to claim 1 or 3, characterized in that, The integrity verification method includes: the verifier obtaining the original code download instruction corresponding to the verified party, the original code content corresponding to the original code download instruction, and the configured security verification content, wherein the security verification content includes at least: a signature value, the starting address of the encrypted part of the original code content, the code encryption length, and a key index; wherein the key index corresponds to the encryption key and the decryption key; and performing integrity verification on the original code content and security verification content of the verified party according to a preset integrity verification algorithm. The confidentiality verification method includes: the verifier reads the starting address and encryption length of the encrypted code from the security verification content of the verifier, selects the key encryption method according to the key index to decrypt the encrypted code, and fills it into the starting address of the encrypted code to obtain the plaintext code. The verifier then uses a preset integrity verification algorithm to perform integrity verification on the plaintext code, and determines the confidentiality verification result based on the integrity verification result. The methods for non-repudiation verification, verifiability verification, and authenticity verification all include: the verifier obtaining the original code content corresponding to the verifiable party, as well as the configured security verification content; and verifying the original code content and the configured security verification content according to a preset verification algorithm.

8. A security verification device for system startup, characterized in that, include: The sequence determination module is used to determine the software startup order of the first type of software and the second type of software in response to a power-on reset operation; The successive verification module is used to perform successive cyclic verification according to the software startup order to obtain the corresponding verification results; wherein, the verification includes at least one of the following: security verification between the first type of software and the second type of software, verification by a third-party organization accessing the system, and reverse verification; The startup module is used to determine that the system is safely started if the verification result passes. The successive verification module includes: The first verification unit is used to start the software of the first equipment provider. After the software of the first equipment provider passes the self-test, it calls the preset security startup algorithm library package to perform the first security verification on the software of the first management party to obtain the first verification result. The second verification unit is used to perform a second security verification on the second management software using the first management software after the first verification result is that the verification is passed, and obtain a second verification result. The first reverse verification unit is used to perform a first reverse verification on the first equipment provider software using the second management software after the second verification result is that the verification is passed, and obtain the first reverse verification result. The third verification unit is used to perform a third security verification on the second device provider software using the second management software after the first reverse verification result is a successful verification, and to launch the second device provider software after the third verification result is a successful verification. A first verification interface of a third-party verification agency is pre-configured between the first equipment provider software and the first management software; a second verification interface of a third-party verification agency is pre-configured between the first management software and the second management software; a third verification interface of a third-party verification agency is pre-configured between the second management software and the first equipment provider software; and a fourth verification interface of a third-party verification agency is pre-configured between the second management software and the second equipment provider software. Accordingly, after obtaining one of the first verification result, the second verification result, the first reverse verification result, and the third verification result, the security verification device further includes: The fourth verification module is used to perform a fourth security verification on the first management software through a preset third-party organization to obtain a fourth verification result; The fifth verification module is used to perform a fifth security verification on the second management software through a preset third-party organization after the fourth verification result is a successful verification, so as to obtain a fifth verification result. The second reverse verification module is used to perform a second reverse verification on the software of the first equipment provider through a preset third-party organization after the fifth verification result is a verification pass to obtain a second reverse verification result. The sixth verification module is used to perform a sixth security verification on the second device provider software through a preset third-party organization after the second reverse verification result is a successful verification, and to launch the second device provider software after the sixth verification result is a successful verification. The first reverse verification includes: integrity verification, confidentiality verification, repudiation verification, and verifiability verification; the second reverse verification includes: verifiability verification.

9. The security verification device according to claim 8, characterized in that, The second management software includes: a third management software and a fourth management software, wherein the third management software is started earlier than the fourth management software; Correspondingly, the second verification unit includes: The first verification subunit is used to perform a seventh security verification on the third management software using the first management software to obtain a seventh verification result. The second verification subunit is used to perform an eighth security verification on the fourth management software using the first management software to obtain an eighth verification result when the seventh verification result is a successful verification. The eighth verification result is then used as the second verification result. When the second verification result is a successful verification, the second management software is launched.

10. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the security verification method for system startup as described in any one of claims 1-7.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement the security verification method for system startup as described in any one of claims 1-7.

12. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the security verification method for system startup according to any one of claims 1-7.

Citation Information

Patent Citations

  • Video Internet of Things equipment key certificate management method, device and system

    CN113037467A

  • Processing method and device for same-type terminal equipment system software

    CN116702221A