A control circuit and electronic device

Through the control circuit of the master-slave controller architecture, efficient booting of BMC and BIOS is achieved, solving the problem of low boot efficiency caused by complex encryption and decryption operations of TPM and TCM, and ensuring the security and integrity of firmware.

CN119356744BActive Publication Date: 2026-04-07INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-29
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

In existing technologies, the complex encryption and decryption operations performed by TPM and TCM when verifying BMC firmware and BIOS firmware increase the complexity of the boot process, slow down the boot efficiency, and some server motherboards do not support TPM and TCM.

Method used

The system adopts a master-slave controller architecture. The master controller controls the BMC and BIOS controller to reset after the circuit is powered on, and the slave controller wakes up the corresponding communication link to load the firmware after the firmware verification is passed, thus avoiding complex encryption and decryption operations.

Benefits of technology

It reduces the complexity of the boot process for BMC and BIOS, improves boot efficiency, and ensures the security and integrity of the firmware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119356744B_ABST
    Figure CN119356744B_ABST
Patent Text Reader

Abstract

This application discloses a control circuit and electronic device in the field of computer technology. The control circuit provided in this application utilizes two controllers, master and slave, to verify the BMC firmware and BIOS firmware. After the BMC firmware and BIOS firmware verification is successful, a first communication link is established between the baseboard management controller and the first flash memory device, and a second communication link is established between the basic input / output system controller and the second flash memory device. Thus, the baseboard management controller can complete the boot process via the first communication link, and the basic input / output system controller can complete the BIOS boot process via the second communication link. This eliminates complex encryption and decryption operations in the boot process, reducing its complexity and improving boot efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computers, and particularly relates to a control circuit and electronic equipment. BACKGROUND

[0002] At present, TPM (Trusted Platform Module) or TCM (Trusted Cryptography Module) is often used to check the BMC firmware and BIOS firmware, so as to complete the start of the BMC and BIOS. However, in the process of checking the BMC firmware and BIOS firmware by the TPM and TCM, the complex encryption and decryption operations involved will occupy certain computer resources, which will increase the complexity of the start process and slow down the start efficiency of the BMC and BIOS; and some server motherboards do not support the TPM and TCM.

[0003] Therefore, how to reduce the complexity of the start process of the BMC and BIOS and improve the start efficiency is a problem to be solved by those skilled in the art. SUMMARY

[0004] Therefore, the present application aims to provide a control circuit and electronic equipment to reduce the complexity of the start process of the BMC and BIOS and improve the start efficiency. The specific scheme is as follows:

[0005] In a first aspect, the present application provides a control circuit, a baseboard management controller, a basic input / output system controller and a main controller are interconnected two by two, and the main controller is further connected to a slave controller;

[0006] The slave controller, the baseboard management controller and a first control switch are interconnected two by two; the first control switch is further connected to a first flash memory device, and the first flash memory device stores the firmware of the baseboard management controller;

[0007] The slave controller, the basic input / output system controller and a second control switch are interconnected two by two; the second control switch is further connected to a second flash memory device, and the second flash memory device stores the firmware of the basic input / output system;

[0008] The main controller is configured to control the baseboard management controller and the basic input / output system controller to be in a reset state after the control circuit is powered on;

[0009] The slave controller is configured to wake up the baseboard management controller by the host controller after the firmware check of the baseboard management controller is passed, and control the first control switch to connect the first communication link between the baseboard management controller and the first flash memory device; wake up the basic input output system controller by the host controller after the firmware check of the basic input output system is passed, and control the second control switch to connect the second communication link between the basic input output system controller and the second flash memory device.

[0010] Optionally, the first flash memory device comprises a master flash memory and a slave flash memory; the master flash memory and the slave flash memory both store the firmware of the baseboard management controller.

[0011] Correspondingly, the slave controller is configured to check the firmware of the baseboard management controller stored in the master flash memory and / or the firmware of the baseboard management controller stored in the slave flash memory; if the firmware of the baseboard management controller stored in the master flash memory and / or the firmware of the baseboard management controller stored in the slave flash memory is passed, it is confirmed that the firmware check of the baseboard management controller is passed.

[0012] Optionally, the slave controller is configured to wake up the master flash memory and not wake up the slave flash memory if only the firmware of the baseboard management controller stored in the master flash memory is passed.

[0013] Correspondingly, the baseboard management controller is configured to read the firmware of the baseboard management controller in the master flash memory passed by the first communication link, and load the read firmware of the baseboard management controller for starting; after the starting is completed, a baseboard management controller starting completion signal is sent to the host controller.

[0014] Correspondingly, the host controller is configured to send the baseboard management controller starting completion signal to the slave controller after receiving the baseboard management controller starting completion signal.

[0015] Correspondingly, the slave controller is configured to wake up the slave flash memory and restore the firmware of the baseboard management controller in the slave flash memory by the firmware of the baseboard management controller in the master flash memory if it is confirmed that the baseboard management controller has completed starting and it is confirmed that the slave flash memory is in an un-woken state.

[0016] Optionally, the slave controller is configured to wake up the slave flash memory and not wake up the master flash memory if only the firmware of the baseboard management controller stored in the slave flash memory is passed.

[0017] Correspondingly, the baseboard management controller is configured to read the firmware of the baseboard management controller in the slave flash memory that passes the verification through the first communication link, and load the read firmware of the baseboard management controller for starting up; after the starting up is completed, send a baseboard management controller startup completion signal to the host controller.

[0018] Correspondingly, the host controller is configured to, after receiving the baseboard management controller startup completion signal, send the baseboard management controller startup completion signal to the slave controller.

[0019] Correspondingly, the slave controller is configured to, in a case where it is confirmed that the baseboard management controller has completed the startup and it is confirmed that the host flash memory is in an un-wakeup state, wake up the host flash memory, and restore the firmware of the baseboard management controller in the host flash memory by using the firmware of the baseboard management controller in the slave flash memory.

[0020] Optionally, the slave controller is configured to, in a case where the firmware of the baseboard management controller stored in the host flash memory and the firmware of the baseboard management controller stored in the slave flash memory both pass the verification, wake up the slave flash memory and the host flash memory.

[0021] Correspondingly, the baseboard management controller is configured to read the firmware of the baseboard management controller in the slave flash memory that passes the verification through the first communication link, and load the read firmware of the baseboard management controller for starting up;

[0022] The slave controller is configured to, in a case where the firmware of the baseboard management controller stored in the host flash memory and the firmware of the baseboard management controller stored in the slave flash memory both fail the verification, confirm that the firmware of the baseboard management controller fails the verification, and not wake up the slave flash memory and the host flash memory.

[0023] Optionally, the slave controller is configured to, after the firmware of the baseboard management controller fails the verification, cause the host controller to keep a reset state of the baseboard management controller, and control the first control switch to disconnect the first communication link to prohibit the baseboard management controller from starting up; and after the firmware of the basic input / output system fails the verification, cause the host controller to keep a reset state of the basic input / output system controller, and control the second control switch to disconnect the second communication link to prohibit the basic input / output system from starting up.

[0024] Optionally, the baseboard management controller is configured to, after the baseboard management controller itself completes the startup, write a baseboard management controller startup completion signal to a register in the host controller through a target bus.

[0025] Optionally, the baseboard management controller is configured to: if a signal indicating that the firmware of the basic input / output system fails to pass the verification is received from the slave controller, control the second control switch to connect a communication link between the baseboard management controller and the second flash memory device, mount the second flash memory device through the communication link, and restore the firmware of the basic input / output system in the second flash memory device; and after the restoration is completed, send a signal indicating that the firmware of the basic input / output system is restored to the master controller.

[0026] Correspondingly, the master controller is configured to: after receiving the signal indicating that the firmware of the basic input / output system is restored, send the signal indicating that the firmware of the basic input / output system is restored to the slave controller.

[0027] Correspondingly, the slave controller is configured to: in the case where it is confirmed that the firmware of the basic input / output system is restored, re-verify the firmware of the basic input / output system in the second flash memory device.

[0028] Optionally, the slave controller is configured to: after the baseboard management controller and / or the basic input / output system is started, prohibit modification operation on the firmware of the baseboard management controller and / or the firmware of the basic input / output system.

[0029] In a second aspect, the present application provides an electronic device, comprising the control circuit according to any one of the preceding aspects.

[0030] According to the above scheme, the present application provides a control circuit, in which the baseboard management controller, the basic input / output system controller and the master controller are interconnected in pairs, and the master controller is further connected to the slave controller; the slave controller, the baseboard management controller and the first control switch are interconnected in pairs; the first control switch is further connected to the first flash memory device, and the first flash memory device stores the firmware of the baseboard management controller; the slave controller, the basic input / output system controller and the second control switch are interconnected in pairs; the second control switch is further connected to the second flash memory device, and the second flash memory device stores the firmware of the basic input / output system; the master controller is configured to: after the control circuit is powered on, control the baseboard management controller and the basic input / output system controller to be in a reset state; the slave controller is configured to: after the firmware of the baseboard management controller passes the verification, control the master controller to wake up the baseboard management controller, and control the first control switch to connect a first communication link between the baseboard management controller and the first flash memory device; and after the firmware of the basic input / output system passes the verification, control the master controller to wake up the basic input / output system controller, and control the second control switch to connect a second communication link between the basic input / output system controller and the second flash memory device.

[0031] It can be seen that the control circuit provided in the application realizes the verification of the BMC firmware and the BIOS firmware by using two controllers, i.e., a master controller and a slave controller. After the control circuit is powered on, the master controller can control the baseboard management controller and the basic input / output system controller to be in a reset state. After the firmware verification of the baseboard management controller is passed, the slave controller wakes up the baseboard management controller by the master controller, and controls the first control switch to connect the first communication link between the baseboard management controller and the first flash memory device. After the firmware verification of the basic input / output system is passed, the slave controller wakes up the basic input / output system controller by the master controller, and controls the second control switch to connect the second communication link between the basic input / output system controller and the second flash memory device. In this way, the baseboard management controller can complete the startup through the first communication link, and the basic input / output system controller can complete the BIOS startup through the second communication link. The scheme does not involve complex encryption and decryption operations, reduces the complexity of the startup process, and improves the startup efficiency.

[0032] Correspondingly, the electronic device provided in the application also has the above technical effects. BRIEF DESCRIPTION OF DRAWINGS

[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only constitute a part of the embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.

[0034] Figure 1 A control circuit schematic diagram disclosed in the application;

[0035] Figure 2 A second control circuit schematic diagram disclosed in the application;

[0036] Figure 3 A startup process schematic diagram disclosed in the application. DETAILED DESCRIPTION

[0037] The technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments only constitute a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other examples obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0038] Currently, TPM or TCM is often used to check the BMC firmware and BIOS firmware to complete the start of the BMC and BIOS. However, in the process of checking the BMC firmware and BIOS firmware by TPM and TCM, the complex encryption and decryption operations involved will occupy certain computer resources, which will increase the complexity of the start process and slow down the start efficiency of the BMC and BIOS; and some server motherboards do not support TPM and TCM. Therefore, the application provides a control scheme, which can reduce the complexity of the start process of the BMC and BIOS and improve the start efficiency.

[0039] Referring to Figure 1 As shown in the figure, the embodiment of the application discloses a control circuit, a baseboard management controller (BMC), a basic input output system (BIOS) controller and a main controller are interconnected two by two, and the main controller is also connected to a slave controller.

[0040] The slave controller, the baseboard management controller and the first control switch are interconnected two by two; the first control switch is also connected to a first flash memory device, and the first flash memory device stores the firmware of the baseboard management controller.

[0041] The slave controller, the basic input output system controller and the second control switch are interconnected two by two; the second control switch is also connected to a second flash memory device, and the second flash memory device stores the firmware of the basic input output system.

[0042] The main controller is used to: after the control circuit is powered on, the baseboard management controller and the basic input output system controller are in a reset state.

[0043] The slave controller is used to: after the firmware of the baseboard management controller is checked, the main controller is woken up, and the first control switch is controlled to connect the first communication link between the baseboard management controller and the first flash memory device, so that the baseboard management controller reads and loads the firmware of the baseboard management controller in the first flash memory device through the first communication link to start the baseboard management controller.

[0044] After the firmware of the basic input output system is checked, the main controller is woken up, and the second control switch is controlled to connect the second communication link between the basic input output system controller and the second flash memory device, so that the basic input output system controller reads and loads the firmware of the BIOS in the second flash memory device through the second communication link to start the BIOS.

[0045] In this embodiment, during the verification process of the firmware of the baseboard management controller and the firmware of the BIOS, the baseboard management controller is not connected to the first flash memory device, and the basic input / output system controller is not connected to the second flash memory device. Therefore, the security of the firmware of the baseboard management controller and the firmware of the BIOS during the verification process can be guaranteed. Furthermore, after the controller starts the baseboard management controller and / or the basic input / output system, modification operations on the firmware of the baseboard management controller and / or the firmware of the basic input / output system are prohibited, thus ensuring the security of the firmware of the baseboard management controller and the firmware of the BIOS during operation.

[0046] In one embodiment, the first flash memory device includes a master flash memory and a slave flash memory; both the master flash memory and the slave flash memory store firmware of a substrate management controller; correspondingly, the slave controller is used to: verify the firmware of the substrate management controller stored in the master flash memory and / or the firmware of the substrate management controller stored in the slave flash memory; if the firmware of the substrate management controller stored in the master flash memory and / or the firmware of the substrate management controller stored in the slave flash memory pass the verification, then the firmware verification of the substrate management controller is confirmed to be successful.

[0047] In one embodiment, the slave controller is configured to: wake up the main flash memory without waking up the slave flash memory if only the firmware of the baseboard management controller stored in the main flash memory passes verification; correspondingly, the baseboard management controller is configured to: read the firmware of the baseboard management controller in the verified main flash memory via a first communication link and load the read firmware of the baseboard management controller for startup; after startup is completed, send a baseboard management controller startup completion signal to the main controller; correspondingly, the main controller is configured to: send a baseboard management controller startup completion signal to the slave controller after receiving the baseboard management controller startup completion signal; correspondingly, the slave controller is configured to: wake up the slave flash memory and restore the firmware of the baseboard management controller in the slave flash memory using the firmware of the baseboard management controller in the main flash memory if it is confirmed that the baseboard management controller has completed startup and the slave flash memory is in a non-wake-up state.

[0048] In one embodiment, the slave controller is configured to: wake up the slave flash memory without waking up the master flash memory if only the firmware of the baseboard management controller stored in the flash memory passes verification; correspondingly, the baseboard management controller is configured to: read the firmware of the baseboard management controller in the verified slave flash memory via a first communication link and load the read firmware of the baseboard management controller for startup; after startup is completed, send a baseboard management controller startup completion signal to the master controller; correspondingly, the master controller is configured to: send a baseboard management controller startup completion signal to the slave controller after receiving the baseboard management controller startup completion signal; correspondingly, the slave controller is configured to: wake up the master flash memory and restore the firmware of the baseboard management controller in the master flash memory using the firmware of the baseboard management controller in the slave flash memory if it is confirmed that the baseboard management controller has completed startup and the master flash memory is in a non-wake-up state.

[0049] In one embodiment, the slave controller is configured to: wake up the slave flash memory and the main flash memory if both the firmware of the baseboard management controller stored in the main flash memory and the firmware of the baseboard management controller stored in the slave flash memory pass verification; correspondingly, the baseboard management controller is configured to: read the firmware of the baseboard management controller in the main flash memory or the firmware of the baseboard management controller in the slave flash memory that has passed verification through a first communication link, and load the read firmware of the baseboard management controller for startup; the slave controller is configured to: confirm that the firmware verification of the baseboard management controller has failed if both the firmware of the baseboard management controller stored in the main flash memory and the firmware of the baseboard management controller stored in the slave flash memory fail verification, and not wake up the slave flash memory and the main flash memory.

[0050] In one embodiment, the slave controller is configured to: after the firmware verification of the baseboard management controller fails, keep the baseboard management controller in a reset state and control a first control switch to disconnect the first communication link to prevent the baseboard management controller from starting; and after the firmware verification of the basic input / output system fails, keep the basic input / output system controller in a reset state and control a second control switch to disconnect the second communication link to prevent the basic input / output system from starting.

[0051] In one implementation, the baseboard management controller is used to: after its own startup is completed, write a baseboard management controller startup completion signal to a register in the main controller via a target bus.

[0052] In one embodiment, the baseboard management controller is configured to: if it receives a signal from the slave controller indicating that the firmware verification of the basic input / output system has failed, control a second control switch to connect the communication link between the baseboard management controller and the second flash memory device, connect the second flash memory device through the communication link, and restore the firmware of the basic input / output system in the second flash memory device; after the restoration is completed, send a firmware restoration signal of the basic input / output system to the master controller; correspondingly, the master controller is configured to: after receiving the firmware restoration signal of the basic input / output system, send a firmware restoration signal of the basic input / output system to the slave controller; correspondingly, the slave controller is configured to: if it confirms that the firmware of the basic input / output system has been restored, re-verify the firmware of the basic input / output system in the second flash memory device.

[0053] In one implementation, the controller is configured to: disable modifications to the firmware of the baseboard management controller and / or the basic input / output system after the baseboard management controller and / or basic input / output system are started.

[0054] As can be seen, in this embodiment, the control circuit utilizes two controllers, master and slave, to verify the BMC firmware and BIOS firmware. After the control circuit is powered on, the master controller can control the baseboard management controller and the basic input / output system controller to be in a reset state. After the slave controller passes the firmware verification of the baseboard management controller, it causes the master controller to wake up the baseboard management controller and controls the first control switch to connect the first communication link between the baseboard management controller and the first flash memory device. After passing the firmware verification of the basic input / output system, the master controller wakes up the basic input / output system controller and controls the second control switch to connect the second communication link between the basic input / output system controller and the second flash memory device. Thus, the baseboard management controller can complete the boot process via the first communication link, and the basic input / output system controller can complete the BIOS boot process via the second communication link. This scheme does not involve complex encryption / decryption operations, reducing the complexity of the boot process and improving boot efficiency.

[0055] In one example, the connections between the components in the control circuit can be referenced. Figure 2 . Figure 2 The circuit components included are: BMC, BIOS controller, master CPLD (master controller), slave CPLD (slave controller), and first control switch. Figure 2 The first SPI switch and the second control switch (in the middle) Figure 2 The second SPI switch in the middle), BMC master-slave flash memory ( Figure 2 The BMCFlash Main+Secondary in the text corresponds to the first flash memory device mentioned earlier, and the flash memory of the BIOS ( Figure 2The BIOS Flash in this context corresponds to the second flash memory device mentioned earlier. These devices are connected via relevant buses; see [link to bus type details] for more information. Figure 2 As shown.

[0056] It's important to note that the controller can detect the legitimacy and integrity of BMC firmware and BIOS firmware. Specifically, BMC firmware typically includes a digital signature, generated by encrypting specific parts of the firmware (such as header information and critical data blocks) using a private key. The controller can verify this digital signature using the corresponding public key. The public and private keys are an asymmetric encryption pair; the private key is used for signing, and the public key is used for verification. If the signature can be successfully verified using the correct public key, the BMC firmware is considered legitimate. BIOS firmware detection follows a similar process. Assuming the RSA asymmetric encryption algorithm is used, the firmware provider encrypts the firmware's hash value (e.g., a SHA-256 hash value) using their private key to generate a signature. The controller, possessing the public key issued by the firmware provider, first calculates the SHA-256 hash value of the BMC firmware, then decrypts the signature using the public key to obtain the original hash value. If these two hash values ​​match, the signature is verified, thus proving the legitimacy of the BMC firmware.

[0057] Reference Figure 2 As shown, the BMC accesses the CPLD (Complex Programmable Logic Device) through a hardware path, enabling status detection and CPLD certificate management. Specifically, a CPLD certificate is a digital certificate used to verify the legitimacy and trustworthiness of the CPLD itself or CPLD-based devices in scenarios such as secure communication and authentication. The specific certificate verification process includes:

[0058] (1) Establishing a communication connection: BMC and CPLD need to establish a connection through a predefined communication interface and protocol. Mailbox can be used as a communication mechanism for data interaction between the two.

[0059] (2) BMC sends a certificate detection request: BMC sends a certificate detection request message to CPLD, which is delivered to CPLD via mailbox. The request message may contain some necessary parameters, such as the type of operation requested (in this case, certificate detection), possible certificate identification information (if there are multiple certificates, it is necessary to specify which one to detect), etc.

[0060] (3) CPLD prepares certificate data: After receiving the detection request from the BMC, the CPLD reads the certificate data to be detected from its storage area (such as internal non-volatile memory or externally connected storage devices). The CPLD needs to organize the certificate data according to the pre-agreed format for subsequent transmission to the BMC.

[0061] (4) CPLD sends certificate data back via mailbox: The CPLD sends the prepared certificate data back to the BMC via mailbox. The data transmission process needs to ensure accuracy and integrity to avoid data loss or damage.

[0062] (5) BMC receives and parses certificate data: After receiving the certificate data sent back by CPLD, BMC parses the certificate. The parsing process includes extracting key information from the certificate, such as the certificate version number, serial number, signature algorithm identifier, issuer information, validity period, user information, and public key information.

[0063] (6) Certificate Verification: BMC verifies the parsed certificate data according to the set certificate verification rules. For example, it checks whether the certificate format conforms to the standard specifications, uses the pre-stored public key of the certificate authority to verify whether the certificate signature is correct, and confirms whether the certificate's validity period is within the current time range.

[0064] (7) Result Feedback: Based on the certificate verification results, BMC sends the test results to CPLD via mailbox. If the certificate test passes, BMC can send a confirmation message to CPLD; if the certificate test fails, BMC can send an error message to inform CPLD of the problem with the certificate. At the same time, BMC can also record the test results in the local log as needed for subsequent querying and analysis.

[0065] If the CPLD certificate verification is successful, the subsequent process will continue. If the certificate verification fails, the BMC will be set to a reset state and will not be able to start normally.

[0066] In this embodiment, BMC can complete the verification of the primary CPLD certificate and the secondary CPLD certificate by referring to the above process. After the verification of both the primary and secondary CPLD certificates is successful, it proceeds according to... Figure 2 The circuit shown verifies the BMC firmware and BIOS firmware, as well as the subsequent boot process.

[0067] Please see Figure 3 The boot process is divided into two stages: pre-boot (pre-boot stage) and boot (boot stage).

[0068] The pre-boot phase includes: After power-on, the master CPLD and slave CPLD are powered on first, at which point the BMC and BIOS controllers are both in a reset state. Then, the slave CPLD accesses the BMC flash and BIOS flash to read the BMC firmware and BIOS firmware, and verifies them. If the verification is successful, it notifies the master CPLD to release the reset signals of the BMC and BIOS controllers, allowing the BMC and BIOS to boot normally; if the verification fails, it may prevent the BMC and BIOS from booting, depending on the circumstances.

[0069] Specifically, the BMC flash uses a master-slave dual-flash configuration, therefore it is necessary to verify the BMC firmware stored in each flash. The master flash stores the main BMC firmware, and the slave flash stores the backup BMC firmware. The verification results of the relevant firmware and their relationship to whether the BMC and BIOS can be booted are shown in Table 1.

[0070] Table 1

[0071]

[0072] As can be seen in this embodiment, the CPLD first verifies the firmware. When the verification fails, it will prevent the BMC and / or BIOS from starting, i.e., it will hold down their reset signal. When the verification passes, the CPLD will open the path for the BMC and / or BIOS to access the BMC flash and / or BIOS flash, and at the same time, it will release its reset signal, so that the BMC or BIOS can start normally.

[0073] In this example, the BMC needs to access the master CPLD's I2C path through the slave CPLD. There are three sets of GPIO pins between the slave CPLD and the master CPLD: TM_DONE, REBOOT, and BOOT_DONE.

[0074] Among them, TM_DONE: The reset signal of BMC and BIOS is controlled by the main CPLD. The main CPLD determines whether to release the reset signal of BMC / BIOS based on the TM_DONE signal passed from the CPLD.

[0075] REBOOT: This is the BMC restart signal. The BMC uses this signal to tell the CPLD that the BMC image needs to be re-verified.

[0076] BOOT_DONE: After the BMC starts up, it will notify the master CPLD by writing to the register. After receiving the register modification, the master CPLD will notify the slave CPLD through the boot_done gpio channel. After receiving the boot_done signal, the slave CPLD will stop destroying the chip select signal of the untrusted flash, that is, wake up the relevant untrusted flash.

[0077] In this embodiment, the verification process for any firmware includes: when storing the firmware, generating a checksum by performing arithmetic operations (such as summation, bitwise XOR, etc.) on all bytes of the data block in the firmware, and storing it together with the firmware; after reading the firmware from the CPLD, recalculating the checksum according to the same algorithm, and then comparing the newly calculated checksum with the pre-stored checksum; if they match, the verification passes; otherwise, the verification fails.

[0078] For example, when the BMC firmware is written to a storage device (such as Flash), a calculation tool (which could be a dedicated programming tool or a calculation module within the BMC) performs a checksum calculation on the BMC firmware. For instance, it uses a byte summation method, adding the values ​​of all bytes in the BMC firmware to obtain a checksum value, which is then stored in a specific location, such as another area of ​​the Flash or a configuration register associated with the BMC firmware. When verification is performed from the CPLD, it reads the contents of the BMC firmware via the SPI interface, then recalculates the checksum using the same byte summation method, and compares the newly calculated checksum with the previously stored checksum. If they are equal, the BMC firmware is considered complete, i.e., the verification passes; if they are not equal, it indicates that the BMC firmware is damaged or tampered with, i.e., the verification fails.

[0079] Furthermore, the main actions during the boot phase include: the reset signal of the BMC and / or BIOS controller is controlled by the master CPLD, which releases the reset signal of the BMC and / or BIOS controller based on the TM_DONE signal (wake-up signal) transmitted from the CPLD. After the reset signal of the BMC and / or BIOS controller is released, the BMC and / or BIOS boot normally.

[0080] Specifically, during the pre-boot phase, the release of the BMC and / or BIOS controller's reset signal is controlled based on different verification results. For the BIOS, if the firmware verification passes, the BIOS controller's reset signal is released; if the verification fails, the BIOS controller's reset signal is held. For the BMC, the release logic of the BMC's reset signal needs to be adjusted accordingly due to the existence of its dual flash memory. If the BMC firmware verification in either the primary or backup flash memory passes, the BMC's reset signal can be released.

[0081] Specifically, when both the BMC main firmware and the BMC backup firmware pass verification, the CPLD releases flash control back to the BMC, and the BMC chip will first attempt to boot from the BMC main flash. If the BMC main firmware fails verification while the BMC backup firmware passes verification, and the CPLD does not restrict access to the BMC main flash, the BMC will still attempt to boot from the BMC main flash first after the BMC reset pin is released, leading to BMC boot failure. To solve this problem, the CPLD needs a mechanism to prevent the BMC chip from being unable to access the BMC flash chip that failed verification after the reset pin is released. Since the BMC accesses flash memory via the SPI interface, the BMC chip's ability to access the flash memory requires compliance with the SPI protocol. Conversely, if the SPI timing requirements are not met, the BMC chip cannot access the flash memory. The CPLD can prevent the BMC chip from accessing the unverified flash memory by holding down the CS signal of the unverified flash. After the watchdog timeout, the BMC chip switches to the verified flash for startup. Once startup is complete, the BMC sends a Boot Done signal. Upon receiving the Boot Done signal, the CPLD releases the SPI signal of the unverified flash. Furthermore, verified trusted BMC firmware can be used to analyze and restore the unverified BMC firmware.

[0082] Correspondingly, if the BMC main firmware passes verification but the BMC backup firmware fails verification, the same method will be used to restrict access to the BMC backup firmware. If both the BMC main firmware and the BMC backup firmware fail verification, the BMC's startup will be restricted.

[0083] After the BMC boots, it notifies the master CPLD by writing to registers. Specifically, the BMC modifies the master CPLD's registers via I2C to indicate that it has booted successfully. The information written to the registers includes: which firmware in the BMC flash memory passed verification, which failed, and which flash memory the BMC booted from successfully. Upon receiving the register modifications, the master CPLD notifies the slave CPLD via the BOOT_DONE GPIO channel. Upon receiving the boot_done signal, the slave CPLD stops corrupting the chip select signal of untrusted flash memory (i.e., the flash memory containing the BMC firmware that failed verification).

[0084] Furthermore, the BIOS boot and recovery process includes: verifying the BIOS firmware from the CPLD; if the BIOS verification fails, the CPLD holds the BIOS TM_DONE signal and releases control of the BIOS flash. After the BMC boots, if the main CPLD does not receive the BIOS TM_DONE signal, it will prevent the BIOS controller from powering on and prevent the BIOS from booting.

[0085] Using Valar (a tool for obtaining CPLD status), after the CPLD detects a BIOS verification failure, it attempts to restore the BIOS firmware via the BIOS firmware upgrade interface provided by the BMC. The BMC checks the main CPLD power supply; if the 1V8 Power Good signal is 0, the BMC skips the communication steps with CPU-related components and directly loads the BIOS flash driver, mounts the BIOS flash partition to the BMC, and then updates the BIOS firmware in the BIOS flash. After the BIOS update is complete, the BMC notifies the main CPLD that the BIOS verification is complete, and the main CPLD instructs the secondary CPLD to re-verify the BIOS firmware.

[0086] As can be seen, this embodiment can detect the legality and integrity of BMC firmware and BIOS firmware; furthermore, if the BMC firmware is tampered with during its operation, the CPLD will detect and prevent the tampering, thereby protecting the BMC firmware from attacks during the BMC operation and ensuring that at least one secure firmware is available for the BMC during upgrades.

[0087] The following describes an electronic device provided by an embodiment of this application. The electronic device described below can be referred to in conjunction with other embodiments described herein.

[0088] This application discloses an electronic device, including the control circuit described in any of the preceding embodiments. In this control circuit, a baseboard management controller, a basic input / output system controller, and a master controller are interconnected in pairs; the master controller is also connected to a slave controller; the slave controller, the baseboard management controller, and a first control switch are interconnected in pairs; the first control switch is also connected to a first flash memory device, which stores the firmware of the baseboard management controller; the slave controller, the basic input / output system controller, and a second control switch are interconnected in pairs; the second control switch is also connected to a second flash memory device, which stores the firmware of the basic input / output system; the master controller is used to: after the control circuit is powered on, control the baseboard management controller and the basic input / output system controller to be in a reset state; the slave controller is used to: after the firmware verification of the baseboard management controller passes, cause the master controller to wake up the baseboard management controller and control the first control switch to connect the first communication link between the baseboard management controller and the first flash memory device; after the firmware verification of the basic input / output system passes, cause the master controller to wake up the basic input / output system controller and control the second control switch to connect the second communication link between the basic input / output system controller and the second flash memory device.

[0089] In one embodiment, the first flash memory device includes a master flash memory and a slave flash memory; both the master flash memory and the slave flash memory store firmware of a baseboard management controller.

[0090] Accordingly, the controller is used to: verify the firmware of the baseboard management controller stored in the main flash memory and / or the firmware of the baseboard management controller stored in the flash memory; if the firmware of the baseboard management controller stored in the main flash memory and / or the firmware of the baseboard management controller stored in the flash memory passes the verification, then the firmware verification of the baseboard management controller is confirmed to be successful.

[0091] In one implementation, the slave controller is configured to: wake up the main flash memory without waking up the slave flash memory if only the firmware verification of the substrate management controller stored in the main flash memory passes;

[0092] Accordingly, the baseboard management controller is used to: read the firmware of the baseboard management controller in the main flash memory that has passed verification through the first communication link, and load the read firmware of the baseboard management controller to start up; after the start-up is completed, send the baseboard management controller start-up completion signal to the main controller;

[0093] Accordingly, the main controller is configured to: after receiving the board management controller start-up completion signal, send the board management controller start-up completion signal to the slave controller;

[0094] Accordingly, the slave controller is used to: wake up the slave flash memory after confirming that the baseboard management controller has completed startup and that the slave flash memory is in a non-wake-up state, and restore the firmware of the baseboard management controller in the slave flash memory using the firmware of the baseboard management controller in the master flash memory.

[0095] In one implementation, the slave controller is used to: wake up the slave flash memory without waking up the master flash memory if the firmware verification of the baseboard management controller stored only in the flash memory passes;

[0096] Accordingly, the baseboard management controller is used to: read the verified firmware of the baseboard management controller from the flash memory through the first communication link, and load the read firmware of the baseboard management controller to start up; after the start-up is completed, send a baseboard management controller start-up completion signal to the main controller.

[0097] Accordingly, the main controller is configured to: after receiving the board management controller start-up completion signal, send the board management controller start-up completion signal to the slave controller;

[0098] Accordingly, the slave controller is used to: wake up the main flash memory after confirming that the baseboard management controller has completed startup and that the main flash memory is in a non-wake-up state, and restore the firmware of the baseboard management controller in the main flash memory using the firmware of the baseboard management controller in the slave flash memory.

[0099] In one implementation, the slave controller is used to wake up the slave flash memory and the main flash memory if both the firmware of the baseboard management controller stored in the main flash memory and the firmware of the baseboard management controller stored in the slave flash memory pass the verification.

[0100] Accordingly, the baseboard management controller is used to: read the firmware of the baseboard management controller in the main flash memory that has passed verification through the first communication link, or to read the firmware of the baseboard management controller in the flash memory, and load the read firmware of the baseboard management controller to start up;

[0101] The slave controller is used to: confirm that the firmware verification of the baseboard management controller has failed if both the firmware of the baseboard management controller stored in the main flash memory and the firmware of the baseboard management controller stored in the slave flash memory fail to pass verification, and not to wake up the slave flash memory and the main flash memory.

[0102] In one embodiment, the slave controller is configured to: after the firmware verification of the baseboard management controller fails, keep the baseboard management controller in a reset state and control a first control switch to disconnect the first communication link to prevent the baseboard management controller from starting; and after the firmware verification of the basic input / output system fails, keep the basic input / output system controller in a reset state and control a second control switch to disconnect the second communication link to prevent the basic input / output system from starting.

[0103] In one implementation, the baseboard management controller is used to: after its own startup is completed, write a baseboard management controller startup completion signal to a register in the main controller via a target bus.

[0104] In one embodiment, the baseboard management controller is configured to: if it receives a signal from the controller indicating that the firmware verification of the basic input / output system has failed, control a second control switch to connect the communication link between the baseboard management controller and the second flash memory device, connect the second flash memory device through the communication link, and restore the firmware of the basic input / output system in the second flash memory device; after the restoration is completed, send a firmware restoration signal of the basic input / output system to the main controller.

[0105] Accordingly, the master controller is configured to: after receiving the firmware recovery signal of the basic input / output system, send the firmware recovery signal of the basic input / output system to the slave controller;

[0106] Accordingly, the controller is used to: re-verify the firmware of the basic input / output system in the second flash memory device if it is confirmed that the firmware of the basic input / output system has been restored.

[0107] In one implementation, the controller is configured to: disable modifications to the firmware of the baseboard management controller and / or the basic input / output system after the baseboard management controller and / or basic input / output system are started.

[0108] For more detailed information on the operation of each device in this embodiment, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.

[0109] As can be seen, the control circuit provided in this embodiment utilizes two controllers, master and slave, to verify the BMC firmware and BIOS firmware. After the BMC firmware and BIOS firmware verification is successful, a first communication link is established between the baseboard management controller and the first flash memory device, and a second communication link is established between the basic input / output system controller and the second flash memory device. Thus, the baseboard management controller can complete the boot process via the first communication link, and the basic input / output system controller can complete the BIOS boot process via the second communication link. This eliminates the need for complex encryption / decryption operations during the boot process, reducing its complexity and improving boot efficiency.

[0110] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0111] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of non-volatile storage medium known in the art.

[0112] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A control circuit, characterized in that, The baseboard management controller, the basic input / output system controller, and the main controller are interconnected in pairs, and the main controller is also connected to the slave controller; The slave controller, the substrate management controller, and the first control switch are interconnected in pairs; the first control switch is also connected to a first flash memory device, which stores the firmware of the substrate management controller. The controller, the basic input / output system controller, and the second control switch are interconnected in pairs; the second control switch is also connected to a second flash memory device, which stores the firmware of the basic input / output system. The main controller is used to: after the control circuit is powered on, control the baseboard management controller and the basic input / output system controller to be in a reset state; The slave controller is configured to: after the firmware verification of the baseboard management controller passes, cause the master controller to wake up the baseboard management controller and control the first control switch to connect the first communication link between the baseboard management controller and the first flash memory device; after the firmware verification of the basic input / output system passes, cause the master controller to wake up the basic input / output system controller and control the second control switch to connect the second communication link between the basic input / output system controller and the second flash memory device.

2. The control circuit according to claim 1, characterized in that, The first flash memory device includes a master flash memory and a slave flash memory; both the master flash memory and the slave flash memory store firmware of the baseboard management controller. Accordingly, the slave controller is configured to: verify the firmware of the baseboard management controller stored in the master flash memory and / or the firmware of the baseboard management controller stored in the slave flash memory; if the firmware of the baseboard management controller stored in the master flash memory and / or the firmware of the baseboard management controller stored in the slave flash memory passes the verification, then the firmware verification of the baseboard management controller is confirmed to be successful.

3. The control circuit according to claim 2, characterized in that, The slave controller is configured to: wake up the main flash memory if only the firmware verification of the baseboard management controller stored in the main flash memory passes, but not wake up the slave flash memory; Accordingly, the baseboard management controller is configured to: read the firmware of the baseboard management controller in the main flash memory that has passed verification through the first communication link, and load the read firmware of the baseboard management controller to start up; after the start-up is completed, send a baseboard management controller start-up completion signal to the main controller; Accordingly, the main controller is configured to: after receiving the baseboard management controller start-up completion signal, send the baseboard management controller start-up completion signal to the slave controller; Accordingly, the slave controller is configured to: wake up the slave flash memory after confirming that the baseboard management controller has completed startup and that the slave flash memory is in a non-wake-up state, and restore the firmware of the baseboard management controller in the slave flash memory using the firmware of the baseboard management controller in the master flash memory.

4. The control circuit according to claim 2, characterized in that, The slave controller is configured to: wake up the slave flash memory without waking up the master flash memory if only the firmware verification of the baseboard management controller stored in the slave flash memory passes; Accordingly, the baseboard management controller is configured to: read the firmware of the baseboard management controller that has passed verification in the flash memory through the first communication link, and load the read firmware of the baseboard management controller to start up; after the start-up is completed, send a baseboard management controller start-up completion signal to the main controller; Accordingly, the main controller is configured to: after receiving the baseboard management controller start-up completion signal, send the baseboard management controller start-up completion signal to the slave controller; Accordingly, the slave controller is configured to: wake up the main flash memory when it is confirmed that the baseboard management controller has completed startup and the main flash memory is in a non-wake-up state, and restore the firmware of the baseboard management controller in the main flash memory using the firmware of the baseboard management controller in the slave flash memory.

5. The control circuit according to claim 2, characterized in that, The slave controller is used to wake up the slave flash memory and the main flash memory if both the firmware of the baseboard management controller stored in the main flash memory and the firmware of the baseboard management controller stored in the slave flash memory pass the verification. Accordingly, the baseboard management controller is configured to: read the firmware of the baseboard management controller in the main flash memory or the firmware of the baseboard management controller in the slave flash memory that has passed verification through the first communication link, and load the read firmware of the baseboard management controller to start up; The slave controller is configured to: confirm that the firmware verification of the baseboard management controller has failed if both the firmware of the baseboard management controller stored in the master flash memory and the firmware of the baseboard management controller stored in the slave flash memory fail verification, and not wake up the slave flash memory and the master flash memory.

6. The control circuit according to claim 1, characterized in that, The slave controller is configured to: after the firmware verification of the baseboard management controller fails, keep the baseboard management controller in a reset state and control the first control switch to disconnect the first communication link to prevent the baseboard management controller from starting; after the firmware verification of the basic input / output system fails, keep the basic input / output system controller in a reset state and control the second control switch to disconnect the second communication link to prevent the basic input / output system from starting.

7. The control circuit according to any one of claims 1 to 6, characterized in that, The baseboard management controller is used to: after its own startup is completed, write the baseboard management controller startup completion signal to the register in the main controller via the target bus.

8. The control circuit according to claim 1, characterized in that, The baseboard management controller is configured to: if it receives a signal from the controller indicating that the firmware verification of the basic input / output system has failed, control the second control switch to connect the communication link between the baseboard management controller and the second flash memory device, connect the second flash memory device through the communication link, and restore the firmware of the basic input / output system in the second flash memory device; after the restoration is completed, send a firmware restoration signal of the basic input / output system to the main controller. Accordingly, the master controller is configured to: after receiving the firmware recovery signal of the basic input / output system, send the firmware recovery signal of the basic input / output system to the slave controller; Accordingly, the slave controller is configured to: re-verify the firmware of the basic input / output system in the second flash memory device if it is confirmed that the firmware of the basic input / output system has been restored.

9. The control circuit according to claim 1, characterized in that, The slave controller is configured to: after the baseboard management controller and / or basic input / output system are started, prohibit modification operations on the firmware of the baseboard management controller and / or the firmware of the basic input / output system.

10. An electronic device, characterized in that, include: The control circuit as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Server starting method and system, electronic equipment and storage medium

    CN111399919A

  • Method and Apparatus for Providing a Root of Trust using a Baseboard Management Controller

    US20200042710A1