A UEFI BIOS Secure Boot Function Verification and Testing Method

By generating three sets of keys and signing executable files, the complexity and accuracy of UEFI BIOS secure boot function testing is solved, the testing efficiency and reliability are improved, and the installation process of the operating system is simplified.

CN119513928BActive Publication Date: 2025-07-22百信信息技术有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411566440.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-05
Publication Date
2025-07-22
Estimated Expiration
2044-11-05

AI Technical Summary

Technical Problem

The existing UEFI BIOS secure boot function test is complex and time-consuming, the test results are inaccurate and the reliability is low, mainly because the operating system signed by the manufacturer is required to be installed back and forth and the use of fixed encryption algorithms for testing, and the existence of the key and certificate files have not been updated in time.

Method used

By generating three sets of keys and formatting them into public key certificate files that can be imported into the BIOS, using the third private key and public key certificates to sign the target executable file, filtering the target executable file with server security requirements and attribute information, and managing the key validity through encryption algorithms and timestamps to optimize the test process.

Benefits of technology

It realizes fast and accurate verification of the secure boot function of UEFI BIOS, improves testing efficiency and reliability, reduces the number of installations of the operating system, and ensures the accuracy and reliability of test results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119513928B_ABST
    Figure CN119513928B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of security testing, and discloses a verification test method for the secure boot function of UEFI BIOS, including performing the following three groups of key generation and verification steps: generating a first private key and a first public key certificate through a preset tool; then generating a second private key and a second private key certificate request file, and generating a second public key certificate according to the first private key, the first public key certificate, and the second private key certificate request file; then generating a third private key and a third private key certificate request file, and generating a third public key certificate according to the second private key, the second public key certificate, and the third private key certificate request file; converting the three generated public key certificates into three public key certificate files that can be imported into the BIOS; after importing the three public key certificate files into the BIOS, turning on the secure boot option of the BIOS, and signing a target executable file with the third private key and the third public key certificate to obtain a signed executable file. Thus, the verification test of the secure boot function of UEFI BIOS is realized by using the signed executable file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security testing, and particularly to a method for verifying the secure boot function of UEFI BIOS. Background Art

[0002] UEFI (Unified Extensible Firmware Interface) and BIOS (Basic Input Output System) are two firmware interfaces used to initialize hardware and load the operating system when a computer boots up.

[0003] Currently, the BIOS secure boot test mainly involves applying to the OS (Operating System) vendor for an OS with a secure boot signature, and then installing it on the test machine. When the secure boot of the test machine is turned on, only the OS provided by the OS vendor with a signature can enter the system normally, and the OS without a signature will be blocked from entering the system.

[0004] In the existing UEFI BIOS secure boot function test, the following technical problems often exist:

[0005] First, it is necessary to install the operating system with the vendor's signature back and forth on the server to be tested. Only the signed operating system can enter the system normally, and the unsigned operating system will be blocked from entering the system. Testing the UEFI BIOS secure boot function in this way is relatively complex and time-consuming.

[0006] Second, since the existing technology uses fixed executable files to test the UEFI BIOS secure boot function of the server to be tested without discrimination, the test results are inaccurate; due to the inability to quickly and accurately use the required encryption algorithm during the key generation process, the test efficiency is low.

[0007] Third, since the key and certificate files have an expiration date and are not updated in time, the quality of the signed executable files is poor, further resulting in low test reliability. Summary of the Invention

[0008] This part of the summary of the invention is used to briefly introduce the concepts, which will be described in detail in the following detailed implementation part. This part of the summary of the invention is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0009] The present invention proposes a method for verifying the secure boot function of UEFI BIOS to solve one or more of the technical problems mentioned in the above background art part.

[0010] The present invention provides a method for verifying the secure boot function of UEFI BIOS, including performing the following three sets of key generation and verification steps: generating a first private key and a first public key certificate through a preset tool, and converting the first public key certificate into a first public key certificate file that can be imported into the BIOS;

[0011] generating a second private key and a second private key certificate request file through a preset tool, generating a second public key certificate according to the first private key, the first public key certificate and the second private key certificate request file, and converting the second public key certificate into a second public key certificate file that can be imported into the BIOS;

[0012] generating a third private key and a third private key certificate request file through a preset tool, generating a third public key certificate according to the second private key, the second public key certificate and the third private key certificate request file, and converting the third public key certificate into a third public key certificate file that can be imported into the BIOS;

[0013] After importing the first public key certificate file, the second public key certificate file, and the third public key certificate file into the BIOS, turn on the secure boot option of the BIOS, and use the third private key and the third public key certificate to sign the target executable file to obtain a signed executable file, which is used to verify the secure boot function of the UEFI BIOS.

[0014] Optionally, the signed executable file verifies the secure boot function of the UEFI BIOS through the following steps:

[0015] If the signed executable file runs normally and the target executable file is blocked from running, a verification test result indicating that the secure boot function of the UEFI BIOS is effective is generated.

[0016] Optionally, before generating the first private key and the first public key certificate through a preset tool, it further includes:

[0017] Obtaining the server security requirement information and server attribute information of the server to be tested, where the server attribute information includes server model information;

[0018] Parsing the server security requirement information to obtain multiple server security items and the security level of each server security item. If the secure boot item is included in the multiple server security items and the security level of the secure boot item is higher than the preset security level, determine the security level of the secure boot item as the secure boot item security level, and perform the three sets of key generation and verification steps; where the target executable file is generated through the following steps:

[0019] Extract server manufacturer information and server model from the server property information, and obtain a pre-configured executable file library. Each executable file in the executable file library is configured with an applicable security verification level, applicable manufacturer information, applicable server model, and update time;

[0020] According to the server manufacturer information, filter the executable files in the executable file library whose applicable manufacturer information is consistent with the server manufacturer information to obtain a filtered executable file group; according to the security level of the secure boot item, select the executable files in the filtered executable file group whose applicable security verification level is greater than or equal to the security level of the secure boot item to obtain a candidate executable file group; according to the server model, perform a match in the candidate executable file group to determine whether there is an executable file whose applicable server model matches the server model. If there is, determine the matching executable file as the target executable file; if not, sort the executable files in the candidate executable file group according to the update time to obtain a candidate executable file sequence, and determine the executable file with the smallest time difference between the update time and the current time in the candidate executable file sequence as the target executable file.

[0021] Optionally, the first public key certificate file includes a first timestamp and a first expiration time, the second public key certificate file includes a second timestamp and a second expiration time, and the third public key certificate file includes a third timestamp and a third expiration time.

[0022] Optionally, before generating the first private key and the first public key certificate through a preset tool, it further includes:

[0023] Receiving key configuration information input by the user, where the key configuration information includes a first encryption algorithm identifier, a second encryption algorithm identifier, and a third encryption algorithm identifier; and

[0024] Generating the first private key and the first public key certificate through a preset tool includes:

[0025] Generating the first private key and the first public key certificate through the first encryption algorithm corresponding to the first encryption algorithm identifier by the preset tool;

[0026] Generating the second private key and the second private key certificate request file through a preset tool includes:

[0027] Generating the second private key and the second private key certificate request file through the second encryption algorithm corresponding to the second encryption algorithm identifier by the preset tool;

[0028] Generating the third private key and the third private key certificate request file through a preset tool includes:

[0029] Generating the third private key and the third private key certificate request file through the third encryption algorithm corresponding to the third encryption algorithm identifier by the preset tool.

[0030] The present invention has the following beneficial effects:

[0031] 1. It realizes the convenient and rapid verification test of the UEFI BIOS secure boot function. Specifically, three groups of keys are generated through a preset tool, and the public key certificates in each group of keys are formatted into corresponding public key certificate files that can be imported into the BIOS, namely the first public key certificate file, the second public key certificate file, and the third public key certificate file. After importing the first public key certificate file, the second public key certificate file, and the third public key certificate file into the BIOS, the secure boot option of the BIOS is opened, and the target executable file is signed using the third private key and the third public key certificate to obtain a signed executable file, which is used to verify the UEFI BIOS secure boot function. Only need to generate three groups of keys once and execute the verification steps, and the signed executable file and the three groups of keys generated can verify the effectiveness of the UEFI BIOS secure boot function multiple times, so there is no need to install the operating system back and forth, and the UEFI BIOS secure boot function can be verified and tested conveniently and quickly.

[0032] 2. It improves the efficiency of the UEFI BIOS secure boot function test and the accuracy of the test results. Specifically, first, obtain the security requirement information and attribute information of the server to be tested; then, parse the server security requirement information to determine the server security items and their security levels, further determine the security level of the secure boot item, and execute the three - group key generation and verification steps. Among them, determining the target executable file requires: screening out the executable file group that matches the server manufacturer information; then further screening out the candidate executable file group whose security verification level meets the requirements from the executable file group; then matching according to the server model in the candidate executable file group. If a matching executable file is found, it is determined as the target executable file; if no matching one is found, the candidate executable files are sorted according to the update time, and the one with the smallest time difference between the update time and the current time is selected as the target executable file. Screen out the target executable file that matches the server to be tested in a targeted manner, and use the signed executable file to test the UEFI BIOS secure boot function, thereby improving the accuracy of the test results; quickly determine the encryption algorithm used through the encryption algorithm identifier in the key configuration information, thereby improving the test efficiency;

[0033] 3. The reliability of the UEFI BIOS secure boot function test is improved. By calculating the time difference between the current time and the expiration time, if the time difference is less than or equal to the preset time difference threshold, a key update prompt message is generated, and an updated signed executable file is obtained. According to the dependency relationship between keys, the first public key certificate file, the second public key certificate file, and the third public key certificate file are sorted to obtain a public key certificate file sequence. Then, when the time difference reaches the critical time difference, the public key certificate file to be updated is determined. The target executable file is signed using the updated public key certificate file (i.e., the updated public key certificate file) and the reserved public key certificate file, and finally an upgraded signed executable file is obtained. Thus, the signed executable file is optimized, and the reliability of the test is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the embodiments of the present invention will become more apparent. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the elements and elements are not necessarily drawn to scale.

[0035] Figure 1 is a flowchart of a method for verifying and testing the UEFI BIOS secure boot function of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] The present invention will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not intended to limit the scope of protection of the present invention.

[0037] In addition, it should be noted that for the sake of description, only the parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0038] It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules, or units, and are not used to limit the order or mutual dependence relationship of the functions performed by these devices, modules, or units.

[0039] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0040] The names of the messages or information exchanged between multiple devices of the present invention are for illustrative purposes only and are not used to limit the scope of these messages or information.

[0041] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0042] As Figure 1 shown, a method for verifying the UEFI BIOS secure boot function of the present invention is shown, which specifically includes performing the following three groups of key generation and verification steps:

[0043] Step 101, generate a first private key and a first public key certificate through a preset tool, and convert the first public key certificate into a first public key certificate file that can be imported into the BIOS.

[0044] In some embodiments, the execution entity of a method for verifying the UEFI BIOS secure boot function of the present invention can be a client, and the client can be a laptop computer, a desktop computer, etc. A key is a corresponding substitution relationship between a password and a plain code, and is divided into a symmetric key and an asymmetric key, where the asymmetric key includes a public key and a private key. The public key and the private key are a key pair obtained through an algorithm (i.e., a public key and a private key), one of which is publicly disclosed and is called the public key; the other is retained by the client and is called the private key.

[0045] On this basis, the execution entity generates a first private key and a first public key certificate through a preset tool. There are various preset tools for generating the first private key and the first public key. For example, openSSL (Open Secure Sockets Layer), online tools and services, programming languages and libraries, etc. As an example, the preset tool used is openSSL. First, enter the command for generating the first private key and the first public key certificate in openSSL. This command creates a new certificate request file and the first private key. Entering x509 generates an x509 certificate signed by the execution entity. X509 is the format standard for public key certificates in cryptography. Here, the x509 certificate is the first public key certificate, which contains the subject information of the certificate, the name of the generated certificate file, the validity period of the certificate, etc. This command also specifies the length of the key and the name of the generated private key file. The SHA256 algorithm is used, where the SHA256 algorithm is one of the five algorithms in the SHA (Secure Hash Algorithm) family. Finally, the first private key and the first public key certificate are obtained. The first private key is the private key for establishing a trust relationship between the hardware platform and the owner of the hardware platform. The first public key certificate is the certificate containing the first public key. Secondly, enter the command for converting the format of the first public key certificate in openSSL. In this command, the input certificate file is specified as the first public key certificate, the name of the output file is specified as the first public key certificate file, and the output format is specified to convert the format of the first public key certificate into a file format recognizable by the BIOS, obtaining the first public key certificate file.

[0046] Step 102: Generate a second private key and a second private key certificate request file through a preset tool. Generate a second public key certificate based on the first private key, the first public key certificate, and the second private key certificate request file, and convert the second public key certificate into a second public key certificate file that can be imported into the BIOS.

[0047] In some embodiments, the execution entity first inputs, through the above-mentioned preset tool, a command for generating a second private key and a second private key certificate request file. Herein, this command creates a second private key and a certificate request file corresponding to the second private key, specifies the subject information of the certificate request file, the length of the private key, also specifies the names of the generated private key file and the certificate request file, uses the SHA256 algorithm, and obtains the second private key and the second private key certificate request file. The second private key is the private key for establishing a trust relationship between the hardware platform and the operating system, and the second private key certificate request file is the file requesting a signature corresponding to the second private key. The execution entity then inputs, through the above-mentioned preset tool, a command for generating a second public key certificate, and uses the first private key and the first public key certificate to sign the second private key certificate request file. Herein, this command specifies that the input file is the second private key certificate request file, uses the first public key certificate as the CA (Certificate Authority) certificate, the CA certificate is the certificate issuing authority, specifies the first private key as the private key of the CA, specifies that the output file is the second public key certificate, and the second public key certificate contains the second public key; finally, the execution entity inputs, through the above-mentioned preset tool, a command for converting the format of the second public key certificate. Herein, this command specifies that the input file is the second public key certificate, the output file is the second public key certificate file, and specifies the output format, and converts the format of the second public key certificate into a file format recognizable by the BIOS to obtain the second public key certificate file.

[0048] Step 103: Generate a third private key and a third private key certificate request file through the preset tool, generate a third public key certificate according to the second private key, the second public key certificate and the third private key certificate request file, and convert the third public key certificate into a third public key certificate file that can be imported into the BIOS;

[0049] In some embodiments, the executing entity first inputs, through the above-mentioned preset tool, a command for generating a third private key and a third private key certificate request file, and generates the third private key and the third private key certificate request file. Among them, this command creates a third private key and a certificate request file corresponding to the third private key, specifies the subject information of the certificate request file, the length of the private key, also specifies the names of the generated private key file and the certificate request file, uses the SHA256 algorithm, and obtains the third private key and the third private key certificate request file. The third private key is a key used for database encryption, access control, or digital signature. The third private key certificate request file is a file requesting a signature corresponding to the third private key. On this basis, the executing entity inputs, again through the above-mentioned preset tool, a command for generating a third public key certificate, and uses the third private key and the second public key certificate to sign the third private key certificate request file. Among them, this command specifies that the input file is the third private key certificate request file, uses the second public key certificate as the CA (Certificate Authority) certificate, the CA certificate is the issuing authority of the certificate, specifies the second private key as the private key of the CA, and specifies that the output file is the third public key certificate, and the third public key certificate contains the third public key; finally, the executing entity inputs, through the above-mentioned preset tool, a command for converting the format of the third public key certificate. Among them, this command specifies that the input file is the third public key certificate, the output file is the third public key certificate file, and specifies the output format, and converts the format of the third public key certificate into a file format recognizable by the BIOS, and obtains the third public key certificate file.

[0050] Step 104, after importing the first public key certificate file, the second public key certificate file, and the third public key certificate file into the BIOS, open the secure boot option of the BIOS, and use the third private key and the third public key certificate to sign the target executable file to obtain a signed executable file, and the signed executable file is used to verify and test the secure boot function of the UEFI BIOS.

[0051] In some embodiments, the executing entity imports the first public key certificate file, the second public key certificate file, and the third public key certificate file into the BIOS, and opens the secure boot option of the BIOS, and signs the target executable file on a tool providing a signature function through the third private key and the third public key certificate to obtain a signed executable file, and the signed executable file is used to verify and test the secure boot function of the UEFI BIOS. Among them, the target executable file is a file in the.efi (Extensible Firmware Interface) format in the UEFI environment.

[0052] In these embodiments, three sets of keys are generated by a preset tool, and the public key certificates in each set of keys are formatted into corresponding public key certificate files that can be imported into the BIOS, namely the first public key certificate file, the second public key certificate file, and the third public key certificate file. After importing the first public key certificate file, the second public key certificate file, and the third public key certificate file into the BIOS, the secure boot option of the BIOS is turned on, and the target executable file is signed using the third private key and the third public key certificate to obtain a signed executable file, which is used to verify and test the secure boot function of the UEFI BIOS. Thus, it is achieved that only three sets of keys need to be generated once and the verification steps are executed, and the target executable file is signed using the third private key and the third public key certificate. This file and the three sets of keys generated can be used to verify the effectiveness of the secure boot function of the UEFI BIOS multiple times, without the need to install the operating system back and forth, facilitating the quick verification and testing of the secure boot function of the UEFI BIOS.

[0053] In some embodiments, in order to further solve Technical Problem 2 described in the background art section, that is, "Since the prior art uses a fixed executable file to treat the test server for UEFI BIOS secure boot function testing without discrimination, resulting in inaccurate test results; and since the required encryption algorithm cannot be quickly and accurately used during the key generation process, resulting in low test efficiency", in some embodiments of the present invention, the following steps are further included:

[0054] The signed executable file verifies and tests the secure boot function of the UEFI BIOS through the following steps:

[0055] If the signed executable file runs normally and the target executable file is blocked from running, a verification test result indicating that the secure boot function of the UEFI BIOS is effective is generated.

[0056] In some embodiments, when the secure boot function of the UEFI BIOS is enabled, it performs signature verification on the target executable file that attempts to run. If the target executable file has been correctly signed and the signature is trusted by the UEFI, then the target executable file will be allowed to run. On the contrary, if the target executable file is not signed or the signature is not trusted by the UEFI, then the target executable file will be blocked from running.

[0057] Before generating the first private key and the first public key certificate through a preset tool, the following steps are further included:

[0058] Step 1: Obtain the server security requirement information and server attribute information of the server to be tested, where the server attribute information includes server model information;

[0059] In some embodiments, the executing entity may obtain the server security requirement information and server attribute information of the server to be tested through a server management tool, a third-party tool, etc. The server security requirement information has different security requirements for different servers, which may be requirements in terms of system security, network security, data protection, etc. The server attribute information includes server model information, server manufacturer information, etc. The server model information refers to a detailed description of the server hardware configuration, which usually includes key information such as the server's brand, model, processor type, memory size, storage configuration, network interface, etc.

[0060] Step two, parse the server security requirement information to obtain multiple server security items and the security level of each server security item. If the security startup item is included in the multiple server security items and the security level of the security startup item is higher than the preset security level, then determine the security level of the security startup item as the security startup item security level, and execute three groups of key generation and verification steps; among them, the target executable file is generated through the following steps:

[0061] Extract the server manufacturer information and server model from the server attribute information, and obtain the pre-configured executable file library. Each executable file in the executable file library is configured with an applicable security verification level, applicable manufacturer information, applicable server model, and update time;

[0062] According to the server manufacturer information, filter the executable files in the executable file library whose applicable manufacturer information is the same as the server manufacturer information to obtain a filtered executable file group; according to the security startup item security level, select the executable files in the filtered executable file group whose applicable security verification level is greater than or equal to the security startup item security level to obtain a candidate executable file group; according to the server model, perform matching in the candidate executable file group to determine whether there is an executable file whose applicable server model matches the server model. If there is, determine the matching executable file as the target executable file; if not, then sort the executable files in the candidate executable file group according to the update time to obtain a candidate executable file sequence, and determine the executable file with the smallest time difference between the update time and the current time in the candidate executable file sequence as the target executable file.

[0063] In some embodiments, the executing entity first collects server security requirement information, identifies server security items from the information, and each server security item corresponds to a security level. Among them, the server security items include security startup items, user account management, network connection items, etc., and the security level can be set to different levels such as low, medium, high or urgent. If the parsed server security items contain a security startup item and the security level of the security startup item is higher than the preset security level, then the security level of the security startup item is determined as the security startup item security level. Among them, the security startup item security level is a special security level, which reflects the importance of the security startup item in server security and the high requirements for its security. The preset security level is a level set in advance. After determining the security startup item security level, three groups of key generation and verification steps are performed; among them, the target executable file is generated through the following steps:

[0064] The executing entity extracts the server manufacturer information and server model from the server attribute information. The executing entity has already stored a pre-configured executable file library locally. Among them, each executable file in the executable file library is configured with an applicable security verification level, applicable manufacturer information, applicable server model, and update time;

[0065] In practice, as an example, first, the executing entity determines the server manufacturer information, filters the executable files in the executable file library whose applicable manufacturer information is consistent with the server manufacturer information, and collects the filtered consistent executable files into a group to obtain the filtered executable file group A. Among them, the server manufacturer information includes the name of the server manufacturer and its related information. Secondly, the executing entity determines the security startup item security level, and selects the executable files in the filtered executable file group A whose applicable security verification level is greater than or equal to the security startup item security level to obtain the candidate executable file group B. Finally, the executing entity determines the server model and performs a match in the candidate executable file group B to determine whether there is an executable file whose applicable server model matches the server model. If there is, the matching executable file is determined as the target executable file C; if there is no matching executable file, it is necessary to determine the update time of the remaining executable files in the candidate executable file group B and sort them to obtain the candidate executable file sequence D. Calculate the difference between the update time of each executable file in the candidate executable file sequence D and the current time, and determine the executable file with the smallest time difference as the target executable file E. Among them, the update time refers to the last modification time of the executable file, and the current time is the system time when the matching operation is performed or a time point specified manually.

[0066] The first public key certificate file includes a first timestamp and a first expiration time, the second public key certificate file includes a second timestamp and a second expiration time, and the third public key certificate file includes a third timestamp and a third expiration time.

[0067] In some embodiments, each public key certificate file after importing the BIOS contains two key pieces of information: a timestamp and an expiration time. Among them, the timestamp is a complete verifiable piece of data that can indicate that a piece of data has existed at a specific point in time. Its purpose is mainly to provide users with an electronic proof to demonstrate the generation time of certain data of the users. The expiration time refers to the expiration time of the certificate. As an example, the validity period of each certificate is 10 years. If the first timestamp in the first public key certificate file is 2024-10-23 9:00, then the first expiration time is 2034-10-23 9:00; if the second timestamp in the second public key certificate file is 2024-10-24 9:00, then the second expiration time is 2034-10-24 9:00; if the third timestamp in the third public key certificate file is 2024-10-25 9:00, then the third expiration time is 2034-10-25 9:00.

[0068] Before generating the first private key and the first public key certificate through a preset tool, the following steps are further included:

[0069] Receiving key configuration information input by the user, where the key configuration information includes a first encryption algorithm identifier, a second encryption algorithm identifier, and a third encryption algorithm identifier; and

[0070] In some embodiments, the execution entity receives the key configuration information input by the user on the key configuration information input interface. The key configuration information includes a first encryption algorithm identifier, a second encryption algorithm identifier, and a third encryption algorithm identifier. Encryption algorithms are used to encrypt data. The basic process of data encryption is to process the original plaintext file or data according to a certain algorithm to make it an unreadable piece of code, i.e., "ciphertext", so that it can only show its original content after inputting the corresponding key, thereby achieving the purpose of protecting data from being stolen and read by unauthorized persons. Common encryption algorithms include DES (Data Encryption Standard), RSA encryption algorithm, etc. RSA was proposed in 1977 by Ron Rivest, Adi Shamir, and Leonard Adleman together. RSA is formed by concatenating the first letters of their three surnames. An identifier is a mark used for identification. An encryption algorithm identifier refers to a mark for identifying an encryption algorithm, and different encryption algorithms have different identifiers. And

[0071] Generating a first private key and a first public key certificate through a preset tool, including:

[0072] Generating a first private key and a first public key certificate through the preset tool and the first encryption algorithm corresponding to the first encryption algorithm identifier;

[0073] In some embodiments, generating a first private key and a first public key certificate through a preset tool includes: generating a first private key and a first public key certificate through the preset tool and the first encryption algorithm corresponding to the first encryption algorithm identifier; inputting the identifier corresponding to the first encryption algorithm in the key configuration information input interface of the preset tool to determine that the encryption algorithm used is the first encryption algorithm, and using the first encryption algorithm to generate a first private key and a first public key certificate.

[0074] Generating a second private key and a second private key certificate request file through a preset tool, including:

[0075] Generating a second private key and a second private key certificate request file through the preset tool and the second encryption algorithm corresponding to the second encryption algorithm identifier;

[0076] In some embodiments, generating a second private key and a second private key certificate request file through a preset tool includes: generating a second private key and a second private key certificate request file through the preset tool and the second encryption algorithm corresponding to the second encryption algorithm identifier; inputting the identifier corresponding to the second encryption algorithm in the key configuration information input interface of the preset tool to determine that the encryption algorithm used is the second encryption algorithm, and using the second encryption algorithm to generate a second private key and a second public key certificate.

[0077] Generating a third private key and a third private key certificate request file through a preset tool, including:

[0078] Generating a third private key and a third private key certificate request file through the preset tool and the third encryption algorithm corresponding to the third encryption algorithm identifier.

[0079] In some embodiments, generating a third private key and a third private key certificate request file through a preset tool includes: generating a third private key and a third private key certificate request file through the preset tool and the third encryption algorithm corresponding to the third encryption algorithm identifier. Inputting the identifier corresponding to the third encryption algorithm in the key configuration information input interface of the preset tool to determine that the encryption algorithm used is the third encryption algorithm, and using the third encryption algorithm to generate a third private key and a third public key certificate.

[0080] In these embodiments, the efficiency of the UEFI BIOS secure boot function test and the accuracy of the test results are improved. Specifically, first, the security requirement information and attribute information of the server to be tested are obtained; then, the server security requirement information is parsed to determine the server security items and their security levels, and further the security level of the secure boot item is determined, and three groups of key generation and verification steps are executed. Among them, determining the target executable file requires: screening out the group of executable files that match the server manufacturer information; then further screening out the candidate group of executable files whose security verification level meets the requirements from the group of executable files; then matching according to the server model in the candidate group of executable files, if a matching executable file is found, it is determined as the target executable file; if no matching one is found, the candidate executable files are sorted according to the update time, and the one with the smallest time difference between the update time and the current time is selected as the target executable file. The target executable file that matches the server to be tested is screened out in a targeted manner, and the UEFI BIOS secure boot function is tested using the signed executable file, thereby improving the accuracy of the test results; the encryption algorithm used is quickly determined through the encryption algorithm identifier in the key configuration information, thereby improving the efficiency of the test.

[0081] In some embodiments, in order to further solve Technical Problem 3 described in the background art section, that is, "due to the expiration of the validity period of the key and certificate files and the failure to update them in time, the quality of the signed executable file is poor, further resulting in poor test results", some embodiments of the present invention further include the following steps:

[0082] Step 1, for each of the first public key certificate file, the second public key certificate file, and the third public key certificate file, perform the following validity check operations:

[0083] Determine the time difference between the current time and the expiration time, and determine whether the time difference is less than or equal to the preset time difference threshold. If the time difference is less than or equal to the preset time difference threshold, generate a key update prompt message, and add the key update prompt message to the signed executable file to obtain an updated signed executable file; when verifying and testing the UEFI BIOS secure boot function using the updated signed executable file, display the key update prompt message in a pop-up window form;

[0084] In some embodiments, the expiration time refers to the time when the validity period of the key ends. Calculate the difference between the current time and the expiration time. The preset time difference threshold is a pre-set value used to determine whether the key is about to expire. Compare the calculated time difference with the preset time difference threshold. If the time difference is less than or equal to the preset time difference threshold, it means that the executing entity will generate a key update prompt message. Add the key update prompt message to the signed executable file to obtain an updated signed executable file. The key update prompt message informs the executing entity in the form of a pop-up message that the key is about to expire and needs to be updated.

[0085] Step 2: According to the dependency relationship between the keys, sort the first public key certificate file, the second public key certificate file, and the third public key certificate file to obtain a sequence of public key certificate files.

[0086] In some embodiments, the dependency relationship between keys generally refers to the trust chain between different public key certificates. One certificate may depend on another certificate to establish trust, usually because one certificate (referred to as a sub-certificate) is signed by another certificate (referred to as a parent certificate or root certificate). Sort the different public key certificates according to the trust relationship to obtain a sequence of public key certificate files. As an example, if the first public key certificate file is the root certificate, the second public key certificate file is an intermediate certificate signed by the first public key certificate file, and the third public key certificate file is a sub-certificate signed by the second public key certificate file, then the sorting should be the first public key certificate file, the second public key certificate file, and the third public key certificate file, and there is a chronological order among them.

[0087] Step 3: When the time difference reaches the critical time difference, determine the corresponding public key certificate file as the target public key certificate file; determine the public key certificate files after the target public key certificate file in the sequence of public key certificate files as the public key certificate files to be updated, and determine the public key certificate files before the target public key certificate file in the sequence of public key certificate files as the retained public key certificate files; update the target public key certificate file and the public key certificate files to be updated to obtain updated public key certificate files; sign the target executable file based on the updated public key certificate files and the retained public key certificate files to obtain an upgraded signed executable file.

[0088] In some embodiments, reaching the critical time difference means that the public key certificate file is approaching the expiration time. When the time difference of a certain public key certificate file reaches the critical time difference, it is determined as the target public key certificate file, which means that the target public key certificate file needs to be updated. In the sequence of public key certificate files, the certificate files ranked after the target public key certificate file are also regarded as the certificate files that need to be updated because they depend on the target public key certificate file and their validity periods are also approaching expiration. In the sequence of public key certificate files, the certificate files ranked before the target public key certificate file are regarded as reserved public key certificate files. These certificates usually still have sufficient validity periods and do not need to be updated immediately. Update the target public key certificate file and the public key certificate files to be updated, which usually involves generating a new key pair to ensure a sufficiently long validity period. Sign the target executable file with the updated public key certificate file (i.e., the updated public key certificate file) and the reserved public key certificate files, and finally obtain the upgraded signed executable file.

[0089] In these embodiments, the reliability of the UEFI BIOS secure boot function test is improved. Through the time difference between the current time and the expiration time, if the time difference is less than or equal to the preset time difference threshold, key update prompt information is generated to obtain the updated signed executable file. According to the dependency relationship between the keys, sort the first public key certificate file, the second public key certificate file, and the third public key certificate file to obtain the sequence of public key certificate files, and then determine the public key certificate files that need to be updated according to the time difference reaching the critical time difference. Sign the target executable file with the updated public key certificate file (i.e., the updated public key certificate file) and the reserved public key certificate files, and finally obtain the upgraded signed executable file. Thereby, the signed executable file is optimized and the reliability of the test is improved.

[0090] The above description is only some preferred embodiments of the present invention and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present invention is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features having similar functions disclosed in the present invention.

Claims

1. A verification test method for the UEFI BIOS secure boot function, characterized in that, Including, performing the following three groups of key generation and verification steps: Generating three groups of keys through a preset tool, and formatting the public key certificates in each group of keys into corresponding public key certificate files that can be imported into the BIOS, namely the first public key certificate file, the second public key certificate file, and the third public key certificate file; After importing the first public key certificate file, the second public key certificate file, and the third public key certificate file into the BIOS, opening the secure boot option of the BIOS, and using the third private key and the third public key certificate to sign the target executable file to obtain a signed executable file; If the signed executable file runs normally and the target executable file is blocked from running, then generating a verification test result indicating that the secure boot function of the UEFI BIOS is effective; Screening out an executable file group that matches the server manufacturer information; Further screening out a candidate executable file group whose security verification level meets the requirements from the executable file group; matching according to the server model in the candidate executable file group, and if a matching executable file is found, determining it as the target executable file; If no match is found, then sorting the candidate executable files according to the update time, and selecting the one with the smallest time difference between the update time and the current time as the target executable file; For each item in the first public key certificate file, the second public key certificate file, and the third public key certificate file, performing the following validity check operation: Determining the time difference between the current time and the expiration time. If the time difference is less than or equal to a preset time difference threshold, then generating a key update prompt message to obtain an updated signed executable file; When the time difference reaches the critical time difference, determining the public key certificate file that needs to be updated, using the updated public key certificate file and the reserved public key certificate file to sign the target executable file, and finally obtaining an upgraded signed executable file.

2. The UEFI BIOS secure boot function verification test method according to claim 1, wherein Before generating the first private key and the first public key certificate through a preset tool, it further includes: Obtaining the server security requirement information and server attribute information of the server to be tested, where the server attribute information includes server model information; Parsing the server security requirement information to obtain multiple server security items and the security level of each server security item. If the multiple server security items include a secure boot item and the security level of the secure boot item is higher than the preset security level, then determining the security level of the secure boot item as the secure boot item security level, and performing the three groups of key generation and verification steps; where the target executable file is generated through the following steps: Extracting the server manufacturer information and server model from the server attribute information, and obtaining a pre-configured executable file library, where each executable file in the executable file library is configured with an applicable security verification level, applicable manufacturer information, applicable server model, and update time; According to the server manufacturer information, filter the executable files in the executable file library whose applicable manufacturer information is consistent with the server manufacturer information to obtain a filtered executable file group; according to the security level of the secure boot item, select the executable files in the filtered executable file group whose applicable security verification level is greater than or equal to the security level of the secure boot item to obtain a candidate executable file group; according to the server model, perform a match in the candidate executable file group to determine whether there is an executable file whose applicable server model matches the server model. If there is, determine the matching executable file as the target executable file; if not, sort each executable file in the candidate executable file group according to the update time to obtain a candidate executable file sequence, and determine the executable file with the smallest time difference between the update time and the current time in the candidate executable file sequence as the target executable file.

3. The UEFI BIOS secure boot function verification test method according to claim 2, wherein, The first public key certificate file includes a first timestamp and a first expiration time, the second public key certificate file includes a second timestamp and a second expiration time, and the third public key certificate file includes a third timestamp and a third expiration time.

4. The UEFI BIOS secure boot function verification test method according to claim 3, wherein Before generating the first private key and the first public key certificate through the preset tool, it further includes: Receiving key configuration information input by the user, where the key configuration information includes a first encryption algorithm identifier, a second encryption algorithm identifier, and a third encryption algorithm identifier; and Generating the first private key and the first public key certificate through the preset tool includes: Generating the first private key and the first public key certificate through the preset tool and the first encryption algorithm corresponding to the first encryption algorithm identifier; Generating the second private key and the second private key certificate request file through the preset tool includes: Generating the second private key and the second private key certificate request file through the preset tool and the second encryption algorithm corresponding to the second encryption algorithm identifier; Generating the third private key and the third private key certificate request file through the preset tool includes: Generating the third private key and the third private key certificate request file through the preset tool and the third encryption algorithm corresponding to the third encryption algorithm identifier.

Citation Information

Patent Citations

  • System safety starting method, device and system based on national cryptographic algorithm

    CN109598126A