Trusted boot methods, systems, computer devices and storage media

By performing trust measurement on the extended unit when the root of trust is powered on, the boot loading unit is determined, and the central processing unit is controlled to boot and load the target boot firmware, the problem of the computing node being unable to boot in a trustworthy manner is solved, and trust measurement and secure boot are achieved across the entire link.

CN119848857BActive Publication Date: 2026-05-05BEIJING KEXIN HUATAI INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING KEXIN HUATAI INFORMATION TECH
Filing Date
2024-11-14
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing computing nodes cannot achieve trusted boot and establish a complete trusted chain after adding a root of trust, which poses a security risk if the boot firmware is damaged or destroyed.

Method used

When the root of trust is powered on, the extended unit is trusted, the boot loading unit is determined, and the central processing unit is controlled to boot using the logic control unit. The target boot firmware is loaded and trusted, ensuring that the trusted measurement result of the preset measurement object is trusted.

Benefits of technology

It implements end-to-end trust measurement of computing nodes, ensures the security and trustworthiness of the startup process, establishes a complete trust chain, and solves the problem of untrustworthy startup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119848857B_ABST
    Figure CN119848857B_ABST
Patent Text Reader

Abstract

This application relates to a trusted boot method, system, computer device, and storage medium. The method includes: first, performing a trusted measurement on the extended units within the improved trusted root when it is powered on; if the trusted measurement result of the extended units is trusted, determining a boot loading unit according to the deployment method between the improved trusted root and the computing node; using a logic control unit to control the central processing unit in the computing node to boot and load the target boot firmware from the boot loading unit into the central processing unit for boot execution, thereby completing the trusted measurement of the boot firmware and secure boot; then, performing a trusted measurement on a preset measurement object during the boot phase; if the trusted measurement result of the preset measurement object is trusted, determining that the trusted boot process of the computing node is complete, thereby achieving end-to-end trusted measurement during the boot process of the computing node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a trusted boot method, system, computer device, and storage medium. Background Technology

[0002] Trusted computing begins with the boot firmware, measuring and establishing a chain of trust layer by layer. Due to the relatively late development and limited application of trusted computing in China, most existing computing nodes lack trusted computing security mechanisms. Therefore, to provide these mechanisms, trust modifications are necessary. While some such modifications involve adding roots of trust to build a trusted mechanism, the inherent structural limitations of the motherboard prevent changes to the boot order of components. This hinders initial measurement of the boot firmware, preventing the establishment of a complete chain of trust and ultimately failing to create a truly secure and trusted computing environment. Since the boot firmware is the starting point for a computing node's boot process, damage to storage units or corruption of internal firmware can prevent the node from booting, posing a significant security risk. Summary of the Invention

[0003] This application provides a trusted boot method, system, computer device, and storage medium to solve the problem that existing computing nodes cannot be trusted to boot and establish a complete trusted chain after adding a trusted root.

[0004] In a first aspect, this application provides a trusted boot method, the method comprising:

[0005] When the improved root of trust on the computing node is powered on, a trust measurement is performed on the extended unit in the improved root of trust to obtain the trust measurement result of the extended unit, wherein the extended unit includes a logic control unit and a first storage unit;

[0006] When the trust measurement result of the extended unit is trustworthy, the startup loading unit is determined according to the deployment method between the computing node and the improved root of trust, wherein the startup loading unit is the first storage unit or the second storage unit that has been successfully measured, and the second storage unit is the storage unit in the computing node;

[0007] The logic control unit controls the central processing unit in the computing node to power on and start up, and loads the target boot firmware in the boot loading unit into the central processing unit for startup and operation. The target boot firmware is either the first boot firmware in the first storage unit or the boot firmware in the second storage unit.

[0008] When the target boot firmware completes booting, a trust measurement is performed on the preset measurement object to obtain the trust measurement result corresponding to the preset measurement object;

[0009] When the trusted measurement result of the preset measurement object is trusted, it is determined that the trusted startup process of the computing node has been completed.

[0010] Optionally, when the trust measurement result of the extended unit is trustworthy, determining the startup loading unit based on the deployment method between the computing node and the improved root of trust includes:

[0011] When the trust measurement result of the extended unit is trustworthy, it is determined whether there is a second storage unit in the computing node according to the deployment method between the computing node and the improved root of trust.

[0012] When the second storage unit is not present in the computing node, the first storage unit is used as the boot loading unit.

[0013] Optionally, determining whether a second storage unit exists in the computing node based on the deployment method between the computing node and the improved root of trust includes:

[0014] If the improved root of trust is connected to the motherboard interface of the second storage unit in the compute node, it is determined that the second storage unit does not exist in the compute node, wherein the first storage unit in the improved root of trust has replaced the first storage unit through the interface connection; or,

[0015] If the improved root of trust is not connected to the motherboard interface of the second storage unit, it is determined that the second storage unit exists in the computing node.

[0016] Optionally, after determining whether a second storage unit exists in the computing node based on the deployment method between the computing node and the improved root of trust when the trust measurement result of the extended unit is trustworthy, the method further includes:

[0017] When the second storage unit exists in the computing node, the logic control unit is used to control the second storage unit to power on and start up, and the improved root of trust is used to perform a trust measurement on the second startup firmware in the second storage unit to obtain the trust measurement result of the second startup firmware.

[0018] When the trust measurement result of the second boot firmware is trustworthy, the second storage unit is used as the boot loading unit.

[0019] Optionally, after obtaining the trust measurement result of the second boot firmware, the method further includes:

[0020] When the trust measurement result of the second boot firmware is untrustworthy, the number of consecutive measurements of the boot firmware in the second storage unit is accumulated and determined;

[0021] When the number of consecutive measurements of the firmware in the second storage unit is less than a preset number, the second boot firmware in the second storage unit is updated using the first boot firmware in the first storage unit.

[0022] Determine the firmware update status of the second storage unit and accumulate the number of synchronization updates;

[0023] When the firmware update status is "update successful", a trust measurement is performed on the updated third boot firmware in the second storage unit to obtain the trust measurement result of the third boot firmware.

[0024] When the trust measurement result of the third boot firmware is trustworthy, the second storage unit is used as the boot loading unit.

[0025] Optionally, when the trust measurement result of the second boot firmware is untrustworthy, after accumulating and determining the number of consecutive measurements of the second boot firmware, the method further includes:

[0026] If the number of consecutive measurements of firmware startup in the second storage unit is greater than or equal to a preset number, or if the firmware update status is "update failed", the first storage unit is used as the startup loading unit.

[0027] Optionally, when the target boot firmware completes booting, a trust measurement is performed on a preset measurement object to obtain a trust measurement result corresponding to the preset measurement object, including:

[0028] When the target boot firmware completes booting, a trust measurement is performed on the operating system bootloader to obtain the trust measurement result of the operating system bootloader.

[0029] When the trust measurement result of the measured operating system boot program is trustworthy, the measured operating system boot program is loaded, and a trust measurement is performed on the measured operating system program to obtain the trust measurement result of the measured operating system program.

[0030] When the trust measurement result of the measured operating system program is trustworthy, the measured operating system program is loaded, and a trust measurement is performed on the preset application to obtain the trust measurement result of the preset application.

[0031] When the trusted measurement result of the preset application is trusted, a trusted measurement result of the successful measurement of the preset measurement object is obtained, wherein the preset measurement object includes the measured operating system bootloader, the measured operating system program, and the preset application.

[0032] Secondly, this application provides a trusted boot system, which includes a computing node and an improved root of trust. The improved root of trust is deployed in different locations on the motherboard of the computing node, corresponding to different deployment methods. The computing node with the root of trust deployed is used to implement the trusted boot method as described in any of the above.

[0033] Thirdly, this application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the aforementioned trusted boot method.

[0034] Fourthly, this application also provides a computer storage medium storing computer-executable instructions for executing the aforementioned trusted boot method.

[0035] The method provided in this application embodiment involves performing a trust measurement on an extended unit within the improved root of trust on a computing node when the improved root of trust is powered on, obtaining a trust measurement result for the extended unit. The extended unit includes a logic control unit and a first storage unit. When the trust measurement result of the extended unit is trustworthy, a startup loading unit is determined based on the deployment method between the computing node and the improved root of trust. The startup loading unit is either the first storage unit or the second storage unit that has successfully undergone measurement, and the second storage unit is a storage unit within the computing node. The logic control unit controls the power-on startup of the central processing unit (CPU) in the computing node, and the target startup firmware from the startup loading unit is loaded into the CPU for startup and execution. The target startup firmware is either the first startup firmware in the first storage unit or the startup firmware in the second storage unit. When the target startup firmware has finished starting, a trust measurement is performed on a preset measurement object, obtaining a trust measurement result corresponding to the preset measurement object. When the trust measurement result of the preset measurement object is trustworthy, the trust startup process of the computing node is determined to be complete.

[0036] Based on the above method, when the improved root of trust is powered on, the extended units in the improved root of trust are first subjected to trust measurement. If the trust measurement result of the extended unit is trustworthy, the boot loading unit is determined according to the deployment method between the improved root of trust and the computing node. The boot loading unit can be the first storage unit in the extended unit, or the second storage unit located in the computing node but not on the improved root of trust. Since the boot loading unit is a unit that has undergone trust measurement and the trust measurement result is trustworthy, the logic control unit is used to control the central processing unit in the computing node to start and load the target boot firmware in the boot loading unit into the central processing unit for startup and operation. This completes the trust measurement of the boot firmware and secure startup. Then, the preset measurement object in the startup phase is subjected to trust measurement. If the trust measurement result of the preset measurement object is trustworthy, it is determined that the trusted startup process of the computing node has been completed. This realizes the full-link trust measurement during the startup process of the computing node, determines that the computing node can start trustworthy and establish a complete trusted chain, and solves the problem that existing computing nodes cannot start trustworthy and establish a complete trusted chain after adding a root of trust. Attached Figure Description

[0037] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0039] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.

[0040] Figure 1 This is a schematic diagram of the structure of a trusted boot system provided in an embodiment of this application;

[0041] Figure 2 This is a schematic diagram of an improved trusted root structure provided in an embodiment of this application;

[0042] Figure 3 This is a schematic diagram of an improved trusted root structure provided in an embodiment of this application;

[0043] Figure 4 This application provides a schematic diagram of the structure of a computing node.

[0044] Figure 5 This application provides a schematic diagram of the structure of a computing node.

[0045] Figure 6 A flowchart illustrating a trusted startup method provided in an embodiment of this application;

[0046] Figure 7 A flowchart illustrating a trusted startup method provided in an embodiment of this application;

[0047] Figure 8 A flowchart illustrating a trusted startup method provided in an embodiment of this application;

[0048] Figure 9 A flowchart illustrating a trusted startup method provided in an embodiment of this application;

[0049] Figure 10 A flowchart illustrating a trusted startup method provided in an embodiment of this application;

[0050] Figure 11 This is a schematic diagram of the internal structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0051] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0052] The following disclosure provides numerous different embodiments or examples for implementing various structures of the invention. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the scope of the invention. Furthermore, reference numerals and / or letters may be repeated in different examples. Such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed.

[0053] Figure 1 This is a schematic diagram of the trusted boot system in one embodiment. (Refer to...) Figure 1This trusted boot method is applied to a trusted boot system. The trusted boot system includes a compute node 110 and an improved root of trust 120. The improved root of trust 120 is deployed in different locations on the motherboard of the compute node 110, corresponding to different deployment methods. The compute node 110, with the root of trust deployed thereon, is used to implement the trusted boot method. The compute node 110 includes a motherboard power supply, logic switches, a central processing unit, a second memory unit, motherboard circuitry, and other components.

[0054] like Figure 2 and Figure 3 As shown, the improved root of trust 120 (improved TPCM) adds an extension unit to the original initial root of trust (original TPCM). The initial root of trust includes a microprocessor, volatile memory, non-volatile memory, timers, input / output units, a cryptographic module management unit, a key generator, and a random number generator. The extension unit specifically includes a first storage unit and a logic control unit. The first storage unit is a BIOS / Uboot storage unit, used to store the basic firmware required for CPU startup, specifically including boot firmware, basic configuration files, basic function code, driver modules, peripheral function modules, and system boot measurement control, etc. The logic control unit configures the internals of the improved TPCM to protect the boot firmware (BIOS / Uboot firmware) within the root of trust, ensuring the security and trustworthiness of the boot firmware in the computing node 110. The logic control unit is also used to control the power-on timing and data access logic of various components within the computing node 110, and can manage and control the external output ports of the improved root of trust 120.

[0055] There are two ways to improve the deployment between the root of trust 120 and the compute node 110, as described in the following references. Figure 4 The first approach involves optimizing the interface of the improved TPCM. Without altering the original motherboard, the improved TPCM is deployed directly using the existing BIOS / Uboot storage unit's interface on the motherboard. This involves replacing the original second storage unit on compute node 110 with the improved root of trust 120, thereby simplifying the trust transformation of compute node 110 and improving the adaptability of trusted applications. (Refer to...) Figure 5 The second method is to retain the original BIOS / Uboot storage unit components and modify the motherboard circuit design or utilize other motherboard interfaces to perform a reliable modification of the computing node 110. This method stores two BIOS / Uboot storage units, which can achieve a complete backup of the boot firmware and increase the security and reliability of the boot firmware.

[0056] In one embodiment, Figure 6 This is a flowchart illustrating a trusted boot method in one embodiment, with reference to... Figure 6This provides a trusted boot method. This embodiment mainly applies this method to the above-mentioned... Figure 1 Taking compute node 110 as an example, the trusted boot method specifically includes the following steps:

[0057] Step S210: When the improved root of trust 120 on the computing node 110 is powered on, a trust measurement is performed on the extended unit in the improved root of trust 120 to obtain the trust measurement result of the extended unit, wherein the extended unit includes a logic control unit and a first storage unit.

[0058] Specifically, when the improved root of trust 120 is powered on, the extended units in the improved root of trust 120 are first subjected to trust measurement to ensure the trust status of the logic control unit and the first storage unit, so as to enable the trusted startup of the computing node 110 by using the startup firmware that comes with the improved TPCM.

[0059] Step S220: When the trust measurement result of the extended unit is trustworthy, the startup loading unit is determined according to the deployment method between the computing node 110 and the improved trust root 120, wherein the startup loading unit is the first storage unit or the second storage unit that has been successfully measured, and the second storage unit is the storage unit in the computing node 110.

[0060] Specifically, if the trust measurement result of the extended unit is trustworthy, the boot loading unit needs to be determined based on the deployment method between compute node 110 and improved root of trust 120. This is because the existence status of the second storage unit in compute node 110 differs under different deployment methods. The second storage unit is a storage unit that exists only in compute node 110 but not in improved root of trust 120. The first and second storage units are BIOS / Uboot storage units deployed in different locations. The boot loading unit is selected from the first and second storage units. Therefore, the different existence status of the second storage unit will affect the selection of the boot loading unit. The boot loading unit is a storage unit that has undergone trust measurement, i.e., a trustworthy first storage unit or a trustworthy second storage unit.

[0061] Step S230: The logic control unit controls the central processing unit in the computing node 110 to power on and start up, and loads the target boot firmware in the boot loading unit into the central processing unit for startup and operation, wherein the target boot firmware is the first boot firmware in the first storage unit or the boot firmware in the second storage unit.

[0062] Specifically, the central processing unit in compute node 110 is referred to as CPU. If a trustworthy boot loading unit is identified, the CPU in compute node 110 can be powered on and started, and the target boot firmware in the boot loading unit can be loaded into the CPU for startup and execution, so as to ensure the safe and trustworthy startup of the boot firmware.

[0063] Step S240: When the target boot firmware completes booting, a trust measurement is performed on the preset measurement object to obtain the trust measurement result corresponding to the preset measurement object.

[0064] Specifically, the preset measurement objects refer to the objects that need to be trusted during the startup process of compute node 110, excluding the startup firmware. After the target startup firmware has started, the other preset measurement objects are trusted to detect their trust status.

[0065] Step S250: When the trusted measurement result of the preset measurement object is trusted, it is determined that the trusted startup process of the computing node 110 has been completed.

[0066] Specifically, if the trusted measurement result of the preset measurement object is trusted, it means that the entire link is trusted during the startup process of computing node 110. This determines that the trusted startup process of computing node 110 has been completed, ensuring the trusted startup of the entire link during the startup process. This achieves trusted measurement of the entire link during the startup process of computing node 110, confirming that computing node 110 can start trusted and establish a complete trusted chain, thereby solving the problem that existing computing node 110 cannot start trusted and establish a complete trusted chain after adding a trusted root.

[0067] In one embodiment, when the trust metric result of the extended unit is trustworthy, determining the startup loading unit based on the deployment method between the computing node 110 and the improved root of trust 120 includes:

[0068] When the trust measurement result of the extended unit is trustworthy, it is determined whether there is a second storage unit in the computing node 110 according to the deployment method between the computing node 110 and the improved root of trust 120.

[0069] When the second storage unit is not present in the computing node 110, the first storage unit is used as the boot loading unit.

[0070] Specifically, if the trust measurement result of the extension unit is trustworthy, it means that the trust measurement results of both the first storage unit and the logic control unit are trustworthy. The presence of a second storage unit in computing node 110 is determined based on the deployment method between computing node 110 and the improved root of trust 120. If the deployment method between computing node 110 and the improved root of trust 120 indicates that there is no second storage unit in computing node 110, it means that only one BIOS / Uboot storage unit exists on computing node 110, which is the first storage unit in the improved root of trust 120. Therefore, the first storage unit with a trust measurement result of trustworthiness is used as the boot loading unit, so that a secure and trustworthy boot firmware can be subsequently obtained from the first storage unit and loaded into the central processing unit, thereby ensuring the secure and trustworthy state of the boot firmware.

[0071] In one embodiment, determining whether a second storage unit exists in the computing node 110 based on the deployment method between the computing node 110 and the improved root of trust 120 includes:

[0072] If the improved root of trust 120 is connected to the motherboard interface of the second storage unit in the compute node 110, it is determined that the second storage unit does not exist in the compute node 110, wherein the first storage unit in the improved root of trust 120 has replaced the first storage unit through the interface connection; or,

[0073] If the improved root of trust 120 is not connected to the motherboard interface of the second storage unit, it is determined that the second storage unit exists in the computing node 110.

[0074] Specifically, by improving the motherboard interface connection between the root of trust 120 and the second storage unit, and determining the deployment location of the root of trust 120 on the compute node 110 corresponding to the second storage unit, interface matching with the original BIOS / Uboot storage unit can be achieved. The trusted transformation of compute node 110 is realized by replacing the original BIOS / Uboot storage unit on the motherboard. That is, the first storage unit in the improved root of trust 120 replaces the second storage unit. At this point, compute node 110 only has one BIOS / Uboot storage unit; the second storage unit is absent. This deployment method allows for the rapid construction of a complete trust chain of trusted nodes without altering the motherboard circuit design, improving the efficiency and applicability of trusted computing transformation. Optimizing the external interface output of the improved root of trust 120 ensures that the output interface matches the original boot storage unit interface on the motherboard as closely as possible, reducing modifications to the motherboard during trusted adaptation and enhancing the applicability of the improved root of trust 120 on different motherboards, thus completing the establishment of the trusted chain.

[0075] However, if no matching connection is detected between the improved root of trust 120 and the motherboard interface of the second storage unit, it indicates that the deployment method between the improved root of trust 120 and the compute node 110 is to retain the original second storage unit in the compute node 110. This is achieved by modifying the corresponding motherboard circuitry and boot logic of the compute node 110, deploying the improved root of trust 120 on the motherboard using other interfaces or by adding it, enabling it to boot from the improved root of trust 120 and establish a complete trusted chain. In this deployment method, the compute node 110 retains the second storage unit; therefore, it can be determined that the compute node 110 contains a second storage unit based on this deployment method. By modifying the boot logic and circuit design, the deployment of the root of trust is completed, ensuring that the compute node 110 boots from the root of trust, realizing the trusted transformation and upgrade of the node. This method is suitable for external, surface-mount, and other root of trust applications. In this deployment method, the compute node 110 has two BIOS / Uboot storage units, which can achieve complete backup of the boot firmware, increasing the security and trustworthiness of the boot firmware.

[0076] In one embodiment, refer to Figure 8 When the trust measurement result of the extended unit is trustworthy, after determining whether there is a second storage unit in the computing node 110 based on the deployment method between the computing node 110 and the improved root of trust 120, the method further includes:

[0077] When the second storage unit exists in the computing node 110, the logic control unit is used to control the second storage unit to power on and start up, and the improved root of trust 120 is used to perform a trust measurement on the second startup firmware in the second storage unit to obtain the trust measurement result of the second startup firmware.

[0078] When the trust measurement result of the second boot firmware is trustworthy, the second storage unit is used as the boot loading unit.

[0079] Specifically, when a second storage unit exists in computing node 110, the logic control unit is first used to control the second storage unit to power on and start. Then, the improved root of trust 120 is used to perform a trust measurement on the second boot firmware in the second storage unit to obtain the trust measurement result of the second boot firmware, which is used to indicate the trust status of the second boot firmware. When the trust measurement result of the second boot firmware is trustworthy, the trustworthy second storage unit is used as the boot loading unit, that is, the local second storage unit of computing node 110 is preferentially selected as the boot loading unit, and the second boot firmware in the second storage unit is used as the target boot firmware.

[0080] Reference Figure 9The second deployment method enables the dual BIOS / Uboot storage units to operate. The first storage unit (BIOS / Uboot1) of the improved TPCM (i.e., the improved root of trust 120) is the secure source of the boot firmware on the local node, and the second boot firmware in the second storage unit (BIOS / Uboot2) must be consistent with the first boot firmware in the first storage unit.

[0081] In this method, both the first and second deployment methods can utilize local maintenance tools and a remote trusted security management center to load or update the boot firmware of the BIOS / Uboot1 storage unit within the improved TPCM. The boot firmware loaded or updated using either method must be secure and trustworthy to ensure that the boot firmware loaded into the CPU memory is also secure and trustworthy.

[0082] After the boot firmware is stored in the BIOS / Uboot1 storage unit, the improved TPCM calculates the baseline value for boot firmware measurement and stores it in the trusted baseline library. The improved TPCM synchronizes the boot firmware loaded or updated in the BIOS / Uboot1 storage unit to the BIOS / Uboot2 storage unit through the interface. After the BIOS / Uboot2 storage unit is powered on, the improved TPCM measures the boot firmware stored inside it and verifies it with the baseline value in the trusted baseline library. After the verification is successful, the CPU is powered on to perform the CPU boot measurement process.

[0083] In one embodiment, after obtaining the trust measurement result of the second boot firmware, the method further includes:

[0084] When the trust measurement result of the second boot firmware is untrustworthy, the number of consecutive measurements of the boot firmware in the second storage unit is accumulated and determined;

[0085] When the number of consecutive measurements of the firmware in the second storage unit is less than a preset number, the second boot firmware in the second storage unit is updated using the first boot firmware in the first storage unit.

[0086] Determine the firmware update status of the second storage unit and accumulate the number of synchronization updates;

[0087] When the firmware update status is "update successful", a trust measurement is performed on the updated third boot firmware in the second storage unit to obtain the trust measurement result of the third boot firmware.

[0088] When the trust measurement result of the third boot firmware is trustworthy, the second storage unit is used as the boot loading unit.

[0089] Specifically, refer to Figure 10If the trust measurement result of the second boot firmware is untrustworthy, the second boot firmware cannot be used to start the computing node 110. The number of consecutive measurements n of the boot firmware in the second storage unit is accumulated and determined. The number of consecutive measurements is the number of times the trust measurement result is untrustworthy. If the number of consecutive measurements n is less than the preset number N, the first boot firmware in the first storage unit is used to update the second boot firmware in the second storage unit. The firmware update status of the second storage unit is used to determine whether the boot firmware has been updated successfully. The accumulated number of synchronization updates is used to record the number of times the firmware of the first storage unit synchronizes with the second storage unit.

[0090] When the firmware update status is "update successful," a trust measurement is performed again on the updated third boot firmware in the second storage unit to obtain the trust measurement result of the third boot firmware. If the trust measurement result of the third boot firmware is trustworthy, the second storage unit is used as the boot loading unit, and the third boot firmware in the second storage unit is used as the target boot firmware. That is, if the boot firmware in the second storage unit is untrustworthy, the boot firmware is synchronously transferred from the first storage unit to the second storage unit to update the boot firmware in the second storage unit. At this time, the first storage unit acts as a boot firmware backup to ensure that a trustworthy boot firmware can be provided to the second storage unit.

[0091] In one embodiment, after accumulating and determining the number of consecutive measurements of the second boot firmware when the trust measurement result of the second boot firmware is untrustworthy, the method further includes:

[0092] If the number of consecutive measurements of firmware startup in the second storage unit is greater than or equal to a preset number, or if the firmware update status is "update failed", the first storage unit is used as the startup loading unit.

[0093] Specifically, refer to Figure 10 If the number of consecutive measurements of the boot firmware in the second storage unit is greater than or equal to a preset number, it indicates that the multiple trust measurement results of the boot firmware in the second storage unit are unreliable, and synchronous updates of the boot firmware in the second storage unit cannot continue. If the firmware update status of using the first boot firmware in the first storage unit to synchronously update the boot firmware of the second storage unit is "update failed," it indicates that the first storage unit cannot successfully synchronize a trustworthy boot firmware for the second storage unit. In either of the above two cases, the first storage unit is used as the boot loading unit, and the first boot firmware is loaded from the first storage unit into the central processing unit to ensure the trustworthiness of the boot firmware.

[0094] In one embodiment, when the target boot firmware completes booting, a trust measurement is performed on a preset measurement object to obtain a trust measurement result corresponding to the preset measurement object, including:

[0095] When the target boot firmware completes booting, a trust measurement is performed on the operating system bootloader to obtain the trust measurement result of the operating system bootloader.

[0096] When the trust measurement result of the measured operating system boot program is trustworthy, the measured operating system boot program is loaded, and a trust measurement is performed on the measured operating system program to obtain the trust measurement result of the measured operating system program.

[0097] When the trust measurement result of the measured operating system program is trustworthy, the measured operating system program is loaded, and a trust measurement is performed on the preset application to obtain the trust measurement result of the preset application.

[0098] When the trusted measurement result of the preset application is trusted, a trusted measurement result of the successful measurement of the preset measurement object is obtained, wherein the preset measurement object includes the measured operating system bootloader, the measured operating system program, and the preset application.

[0099] Specifically, after the target boot firmware has booted, a trust measurement is performed on the operating system bootloader. If the trust measurement result for the operating system bootloader is trustworthy, the bootloader is loaded. Then, a trust measurement is performed on the operating system program itself, and if the trust measurement result for the operating system program is trustworthy, the bootloader is loaded. Finally, a trust measurement is performed on a preset application, and if the trust measurement result for the preset application is trustworthy, the preset application is loaded, thus completing the trust measurement process for the boot process.

[0100] In one specific embodiment, refer to Figure 4 The improved root of trust 120 replaces the original second storage unit in compute node 110, and the startup of compute node 110 begins from the improved root of trust 120. Figure 7 As shown, the specific process is as follows:

[0101] (1) The motherboard power supply powers the improved root of trust 120 and the improved root of trust 120 starts up. At this time, the CPU of compute node 110 is not powered on.

[0102] (2) Improve the internal initialization of the root of trust 120 by first performing a trust measurement on the firmware in the logic control unit;

[0103] (3) After the firmware measurement of the logic control unit is passed, the BIOS / Uboot boot firmware in the first storage unit is subjected to a trust measurement.

[0104] (4) After the BIOS / Uboot firmware in the first storage unit passes the measurement, the control logic switch is turned on, the CPU is powered on, and the CPU starts up.

[0105] (5) Load the BIOS / Uboot boot firmware in the first storage unit into the CPU memory and run the BIOS / Uboot boot firmware;

[0106] (6) After the BIOS / Uboot boot firmware is completed, the operating system boot program is measured. If the measurement passes, the program is loaded.

[0107] (7) After the operating system boot program finishes starting, it measures the operating system program and loads the program after the measurement is complete.

[0108] (8) After the operating system program starts up, the preset application is measured. After the measurement passes, the preset application is loaded to complete the reliable measurement of the startup process.

[0109] In one specific embodiment, refer to Figure 5 While retaining the original second storage unit, the motherboard circuitry and boot logic were modified. By utilizing other interfaces or adding an improved root of trust 120 deployed on the motherboard, it was given the capability to boot from the improved root of trust 120 and establish a complete chain of trust. The boot of compute node 110 begins with the improved root of trust 120, such as... Figure 10 As shown, the specific process is as follows:

[0110] (1) The system is powered on, the improved root of trust 120 is started, and initialization is performed;

[0111] (2) Measure the first boot firmware inside the improved root of trust 120 and the firmware in the logic control unit.

[0112] (3) The metric failed. Restart the improved root of trust 120.

[0113] (4) After the measurement is passed, set the preset number of times (BIOS / Uboot2 firmware measurement number) corresponding to the second storage unit on the motherboard corresponding to computing node 110;

[0114] (5) Control the logic switch to power on the second storage unit (BIOS / Uboot2) and measure the second boot firmware in the second storage unit;

[0115] (6) After the measurement is passed, the second storage unit is used as the startup loading unit;

[0116] (7) If the measurement fails, determine the number of consecutive measurements of the boot firmware in the second storage unit;

[0117] (8) If the number of consecutive measurements does not exceed the preset number, the firmware in the second storage unit is synchronously updated from the improved root of trust 120, and the number of synchronous updates is accumulated; after successful synchronization, return to step (5) to measure the startup firmware.

[0118] (9) If the number of consecutive measurements exceeds the preset number or the BIOS / Uboot firmware fails to synchronize successfully, the first storage unit (BIOS / Uboot1) within the improved root of trust 120 will be used as the boot loading unit.

[0119] (10) After the loading unit selection is completed, the control logic switch powers on the CPU and starts the CPU;

[0120] (11) The subsequent startup process is the same as steps ⑤, ⑥, ⑦ and ⑧ in the previous specific embodiment.

[0121] Figures 6 to 10 This is a flowchart illustrating a trusted startup method in one embodiment. It should be understood that, although... Figures 6 to 10 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figures 6 to 10 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0122] like Figure 11 As shown, this application provides a computer device including a processor 711, a communication interface 712, a memory 713, and a communication bus 714, wherein the processor 711, the communication interface 712, and the memory 713 communicate with each other through the communication bus 714.

[0123] Memory 713 is used to store computer programs;

[0124] When the processor 711 executes the program stored in the memory 713, it implements the trusted startup method provided in any of the foregoing method embodiments.

[0125] Those skilled in the art will understand that Figure 11The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0126] In one embodiment, the trusted boot system provided in this application can be implemented as a computer program, which can be implemented in, for example... Figure 11 The system runs on the computer device shown. The computer device's memory can store the various program modules that make up the trusted boot system. The computer program, composed of the various program modules, causes the processor to execute the trusted boot methods of the various embodiments of this application described in this specification.

[0127] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the trusted boot method as provided in any of the foregoing method embodiments.

[0128] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0129] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented using software plus a general-purpose hardware platform, or of course, using hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the related technology, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0130] It should be understood that the terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” as used herein may also mean including the plural forms. The terms “comprising,” “including,” “containing,” and “having” are inclusive and therefore indicate the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not construed as requiring them to be performed in a particular order described or illustrated unless the order of performance is explicitly indicated. It should also be understood that alternatives or substitutions may be used.

[0131] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A trusted boot method, characterized in that, The method includes: When the improved root of trust on the computing node is powered on, a trust measurement is performed on the extended unit in the improved root of trust to obtain the trust measurement result of the extended unit, wherein the extended unit includes a logic control unit and a first storage unit; When the trust measurement result of the extended unit is trustworthy, the startup loading unit is determined according to the deployment method between the computing node and the improved root of trust, wherein the startup loading unit is the first storage unit or the second storage unit that has been successfully measured, and the second storage unit is the storage unit in the computing node; The logic control unit controls the central processing unit in the computing node to power on and start up, and loads the target boot firmware in the boot loading unit into the central processing unit for startup and operation. The target boot firmware is either the first boot firmware in the first storage unit or the boot firmware in the second storage unit. When the target boot firmware completes booting, a trust measurement is performed on the preset measurement object to obtain the trust measurement result corresponding to the preset measurement object; When the trusted measurement result of the preset measurement object is trusted, it is determined that the trusted startup process of the computing node has been completed; Wherein, when the trust measurement result of the extended unit is trustworthy, determining the startup loading unit based on the deployment method between the computing node and the improved root of trust includes: When the trust measurement result of the extended unit is trustworthy, it is determined whether there is a second storage unit in the computing node according to the deployment method between the computing node and the improved root of trust. When the second storage unit is not present in the computing node, the first storage unit is used as the boot loading unit; The determination of whether a second storage unit exists in the computing node based on the deployment method between the computing node and the improved root of trust includes: If the improved root of trust is connected to the motherboard interface of the second storage unit in the compute node, it is determined that the second storage unit does not exist in the compute node, wherein the first storage unit in the improved root of trust has replaced the first storage unit through the interface connection; or, If the improved root of trust is not connected to the motherboard interface of the second storage unit, it is determined that the second storage unit exists in the computing node.

2. The method according to claim 1, characterized in that, When the trust measurement result of the extended unit is trustworthy, after determining whether a second storage unit exists in the computing node based on the deployment method between the computing node and the improved root of trust, the method further includes: When the second storage unit exists in the computing node, the logic control unit is used to control the second storage unit to power on and start up, and the improved root of trust is used to perform a trust measurement on the second boot firmware in the second storage unit to obtain the trust measurement result of the second boot firmware. When the trust measurement result of the second boot firmware is trustworthy, the second storage unit is used as the boot loading unit.

3. The method according to claim 2, characterized in that, After obtaining the trust measurement result of the second boot firmware, the method further includes: When the trust measurement result of the second boot firmware is untrustworthy, the number of consecutive measurements of the boot firmware in the second storage unit is accumulated and determined; When the number of consecutive measurements of the firmware in the second storage unit is less than a preset number, the second boot firmware in the second storage unit is updated using the first boot firmware in the first storage unit. Determine the firmware update status of the second storage unit and accumulate the number of synchronization updates; When the firmware update status is "update successful", a trust measurement is performed on the updated third boot firmware in the second storage unit to obtain the trust measurement result of the third boot firmware. When the trust measurement result of the third boot firmware is trustworthy, the second storage unit is used as the boot loading unit.

4. The method according to claim 3, characterized in that, When the trust measurement result of the second boot firmware is untrustworthy, after accumulating and determining the number of consecutive measurements of the second boot firmware, the method further includes: If the number of consecutive measurements of firmware startup in the second storage unit is greater than or equal to a preset number, or if the firmware update status is "update failed", the first storage unit is used as the startup loading unit.

5. The method according to claim 1, characterized in that, When the target boot firmware completes booting, a trust measurement is performed on a preset measurement object to obtain the trust measurement result corresponding to the preset measurement object, including: When the target boot firmware completes booting, a trust measurement is performed on the operating system bootloader to obtain the trust measurement result of the operating system bootloader. When the trust measurement result of the measured operating system boot program is trustworthy, the measured operating system boot program is loaded, and a trust measurement is performed on the measured operating system program to obtain the trust measurement result of the measured operating system program. When the trust measurement result of the measured operating system program is trustworthy, the measured operating system program is loaded, and a trust measurement is performed on the preset application to obtain the trust measurement result of the preset application. When the trusted measurement result of the preset application is trusted, a trusted measurement result of the successful measurement of the preset measurement object is obtained, wherein the preset measurement object includes the measured operating system bootloader, the measured operating system program, and the preset application.

6. A trusted boot system, characterized in that, The trusted boot system includes a compute node and an improved root of trust. The improved root of trust is deployed in different locations on the motherboard of the compute node, corresponding to different deployment methods. The compute node with the root of trust is used to implement the trusted boot method as described in any one of claims 1-5.

7. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 5.

Citation Information

Patent Citations

  • Trusted computing platform of a computing and protection parallel double-system structure

    CN109871695A

  • Trusted measurement method and device and processor

    CN110321715A