System firmware file initialization method, device, equipment, medium and product
Through the automated detection and initialization method of the system firmware file initialization device, the problems of inefficient production efficiency and cost increase caused by manual loading of system firmware files are solved, and efficient and secure system firmware file initialization is achieved.
Patent Information
- Application Number
- CN202510388967.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-03-31
AI Technical Summary
In the prior art, manually loading system firmware files leads to problems of inefficient production efficiency and increased costs.
The system firmware file initialization device is used to detect the module through automated means and send the target password file and the system firmware file to realize the automatic initialization of the module, including integrity and legality verification and lock permissions.
Improve production efficiency, reduce production costs, and ensure the rationality and security of system firmware files.
Smart Images

Figure CN119902820B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a method, apparatus, device, medium, and product for initializing system firmware files. Background Art
[0002] When facing equipment production, it is necessary to load the system firmware file into the main board of the equipment to complete the production of the equipment.
[0003] In related technologies, during the production of equipment equipped with a computing processing platform, R & D personnel load the system firmware file on-site to complete the initialization of the system firmware, and then the detection program can be put on the line. However, the method of manually loading the system firmware file reduces production efficiency and increases production costs. Summary of the Invention
[0004] This application provides a method, apparatus, device, medium, and product for initializing system firmware files to at least solve the problems of reduced production efficiency and increased production costs in related technologies.
[0005] In a first aspect, this application provides a method for initializing a system firmware file, including:
[0006] In response to detecting that the system is in an offline state, obtain an initialization command; the detection system is located in a module;
[0007] Detect the module based on the initialization command to obtain a detection result;
[0008] If the detection result is not passed, send a target password file to the module; the target password file corresponds to the module; the module is used to produce a target device; the target device is equipped with a computing processing platform; the target password file is used to verify the integrity and legality of the target system firmware file during initialization and the first normal startup of the module, and is used to lock the permissions of the module;
[0009] Send the target system firmware file bound to the target password file to the module so that the module can be initialized based on the target system firmware file; the target system firmware file is the system firmware file corresponding to the module.
[0010] In a second aspect, this application also provides a device for initializing a system firmware file, including:
[0011] An acquisition module, configured to obtain an initialization command in response to detecting that the system is in an offline state; the detection system is located in a module;
[0012] A detection module, configured to detect the module based on the initialization command to obtain a detection result;
[0013] A sending module, configured to send a target password file to a module if the detection result is not passed; the target password file corresponds to the module; the module is used to produce a target device; the target device is equipped with a computing processing platform; the target password file is used for the module to verify the integrity and legality of the target system firmware file during initialization and the first normal startup, and is used for the module to lock permissions;
[0014] The sending module is further configured to send a target system firmware file bound to the target password file to the module, so that the module can be initialized based on the target system firmware file; the target system firmware file is the system firmware file corresponding to the module.
[0015] In a third aspect, the present application further provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of any of the above system firmware file initialization methods when executing the computer program.
[0016] In a fourth aspect, the present application further provides a computer-readable storage medium, in which a computer program is stored, and wherein the computer program implements the steps of any of the above system firmware file initialization methods when executed by a processor.
[0017] In a fifth aspect, the present application further provides a computer program product, including a computer program, and the computer program implements the steps of any of the above system firmware file initialization methods when executed by a processor.
[0018] Through a system firmware file initialization method, device, equipment, medium and product provided by the present application, in the present application, the system firmware file initialization device (hereinafter referred to as the initialization device) first responds to the detection system being in an offline state, obtains an initialization command, and then detects the module. If the detection result is not passed, the target password file is sent to the module. Further, the initialization device sends the target system firmware file bound to the target password file to the module, so that the module can be initialized. Thus, it can be seen that the initialization device in the present application realizes the automatic sending of the target system firmware file to the module, rather than manually loading the target system firmware file into the module. Therefore, the automatic method can improve production efficiency and reduce production costs; in addition, the initialization device in the present application also sends the target password file to the module, and then the module can verify the integrity and legality of the target password file during initialization, so as to ensure that the target system firmware file is reasonable and normal in the module; in addition, the module also locks permissions with the target password file, so as to ensure the security of the target device during production; thus, it can be seen that the present application not only improves the initialization efficiency of the target system firmware file by an automatic method, thereby improving production efficiency and reducing production costs, but also can ensure that the target system firmware file is reasonable, normal and secure. Description of the Drawings
[0019] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0020] Figure 1 A schematic diagram of an application scenario provided by the present application;
[0021] Figure 2 A schematic flow diagram of a method for initializing a system firmware file provided for Embodiment 1;
[0022] Figure 3 A schematic flow diagram of a method for initializing a system firmware file provided for Embodiment 2;
[0023] Figure 4 A schematic diagram of a target device provided by the present application;
[0024] Figure 5 A schematic diagram of an interaction provided for an example of the present application;
[0025] Figure 6 A schematic diagram of initializing system hardware provided by the present application;
[0026] Figure 7 A schematic diagram of the structure of a device for initializing a system firmware file provided by the present application;
[0027] Figure 8 A schematic diagram of the structure of an electronic device provided by the present application. Detailed implementation manners
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.
[0029] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variation thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0030] In the related art, during the production of devices equipped with a computing processing platform, R & D personnel load the system firmware file on-site to complete the initialization of the system firmware, so that the detection program can be put on line. However, the method of manually loading the system firmware file reduces production efficiency and increases production costs.
[0031] To solve the defects included in the related art, this solution has undergone a series of improvements and proposes a method for initializing a system firmware file. To solve the problems of reduced production efficiency and increased production costs in the related art, this solution uses a system firmware file initialization device (hereinafter referred to as the initialization device) to automatically send the target system firmware file to the module, and the module initializes based on the target system firmware file. Specifically: the initialization device detects the module based on the initialization command. If the detection result is non-ventilated, it sends the target password file to the module and at the same time sends the target system firmware file bound to the target password file to the module. Therefore, in this solution, the initialization device can automatically send the target system firmware file to the module based on the initialization command, thus avoiding the method of manually loading the target system firmware file in the related art, thereby improving production efficiency and reducing production costs; at the same time, in this solution, the initialization device also sends the target password file to the module. The target password file can be used by the module to verify the integrity and legality of the target system firmware file during initialization, and can also be used by the module to lock permissions, avoiding the loading of other system firmware files into the module, thus ensuring that the module initializes with the target system firmware file bound to the target password file, realizing the locking of the target system firmware file and the target device permissions, and improving security.
[0032] To enable those skilled in the art of this technology to better understand the solution of this application, the following further elaborates on this application in conjunction with the accompanying drawings and specific implementation manners.
[0033] Combined with the specific application environment architecture or specific hardware architecture on which the execution of the system firmware file initialization method depends, the specific application environment architecture or specific hardware architecture is described herein. Refer to Figure 1 , Figure 1 This is a schematic diagram of an application scenario provided by this application. As Figure 1 shown, it includes an electronic device 101 and a module 102.
[0034] Among them, the electronic device 101 can be any control device. For example, the electronic device 101 can be a Baseboard Management Controller (BMC), or others, which are not limited here.
[0035] Among them, the module 102 includes a corresponding central processing unit, memory, and electronic storage chip, etc., which will not be elaborated here. The electronic device 101 and the module 102 are mounted on a computing processing platform, and the computing processing platform is deployed in the target device.
[0036] In this application scenario, the user can achieve one-key initialization (i.e., trigger a one-key operation) through the electronic device 101, and then initiate an initialization command. Thus, the electronic device 101 obtains the initialization command.
[0037] Furthermore, the electronic device 101 detects the module based on the initialization command and obtains a detection result. If the detection result fails, the target password file is sent to the module 102. Furthermore, the electronic device 101 sends the target system firmware file bound to the target password file to the module 102. It should be noted that the module 102 can send the target system firmware file to the electronic storage chip therein to achieve the loading and refreshing of the target system firmware file to complete the initialization.
[0038] Furthermore, the module 102 verifies the target system firmware file based on the target password file to achieve the initialization of the target system firmware file. In this scenario, the electronic device 101 can send the target system file to the module in an automated manner. In addition, the electronic device 101 also sends the target password file bound to the target system firmware file to the module, and the target password file can enable the module to verify the integrity and legality of the target system firmware file during initialization and the first normal startup, ensuring the reasonableness and normality of the target system firmware file; in addition, the target password file can also be used for the module to lock permissions, ensuring that the target system firmware file is not tampered with, and preventing the loading of other system firmware files (i.e., system firmware files not bound to the target password file) into the module, thereby locking the permissions of the target system firmware file. Furthermore, the permissions of the target device produced based on the target system firmware file are locked, that is, it is ensured that the target device does not include other target system firmware.
[0039] It should be noted that after obtaining the module, the system firmware file initialization method in this application needs to first initialize the system firmware file of the module, and then the detection system loaded in the module can be started normally. Therefore, for the convenience of subsequent production of the target device, the detection system needs to be started normally in this application so that the detection system can detect abnormalities during the production process. Therefore, the urgent task is to initialize the system firmware file of the module. It should be noted that the normal startup of the detection system depends on the system firmware file.
[0040] It should be noted that in the related art, when the device to be produced is a computing processing platform, due to the integrated design of the module, the electronic device cannot directly access it through the hardware interface, so the system firmware file of the module is initialized manually.
[0041] Embodiment 1
[0042] In Embodiment 1 to Embodiment 16 of this application, the execution subject is a system firmware file initialization device (hereinafter referred to as the initialization device), which is located in the electronic device. The electronic device can be a control device, and the electronic device is located in the target device to be produced.
[0043] Figure 2 FIG. is a schematic flow chart of a method for initializing a system firmware file provided for Embodiment 1. As Figure 2 shown, it includes:
[0044] S201, in response to detecting that the system is in an offline state, obtain an initialization command; the detection system is located in the module.
[0045] Among them, detecting that the system is in an offline state means that the detection system cannot be suspended when powered on, that is, it cannot start working normally.
[0046] Among them, the initialization command is a command indicating to enter the system firmware file initialization process.
[0047] In one way, the initialization device can receive the detection system status information sent by the user, and determine whether the detection system is in an offline state based on the detection system status information.
[0048] In one way, the user can issue an initialization command through a one-key operation. Specifically, the user can trigger a one-key operation on the user side or on the electronic device (that is, press a preset one-key operation button to trigger the one-key operation). This one-key operation is used to indicate that the detection system in the module is in an offline state and send the initialization command to the electronic device. In this way, the initialization command is generated by triggering the one-key operation or sent by the user side, so the electronic device obtains the initialization command. In this way, only by triggering the one-key operation, the initialization device can automatically send the target system firmware file to the module, so that the module is initialized based on the target system firmware file. Therefore, this application can implement the one-key initialization method of the system firmware file.
[0049] Alternatively, in this application, when it is determined that the detection system is in an offline state, the electronic device can be triggered directly to perform S202 to implement the detection of the module.
[0050] S202, detect the module based on the initialization command to obtain a detection result.
[0051] Among them, the detection result refers to the result of whether the system firmware file is initialized in the detection module.
[0052] In one way, the initialization device detects the external trusted root in the module based on the initialization command, so as to obtain the detection result.
[0053] Specifically, the module may include at least one external trusted root. In Way 1, specifically: the initialization device may detect any one of the external trusted roots, obtain the detection result corresponding to the external trusted root, and use this detection result as the detection result of each external trusted root.
[0054] In Way 2, specifically: the initialization device detects each external trusted root based on the initialization command to obtain the final detection result. It should be noted that detecting each external trusted root can ensure the accuracy of the detection result and avoid missing the detection of any external trusted root.
[0055] Among them, the external trusted root may be External Root of Trust, abbreviated as EROT.
[0056] S203, if the detection result is not passed, send the target password file to the module; the target password file corresponds to the module; the module is used to produce the target device; the target device is equipped with a computing processing platform; the target password file is used for the module to verify the integrity and legality of the target system firmware file during initialization and the first normal startup, and is used for the module to lock permissions.
[0057] Among them, if the detection result is not passed, it means that the target system firmware file is not initialized in the module.
[0058] It should be noted that during the production process of the target device, the module needs to be installed in the computing processing platform. Different merchants correspond to different modules, and each module corresponds to a bound target password file and a target system firmware file. The module in this application corresponds to the target password file, which ensures the security of the module and the target password file. When initializing the module, instead of using other password files for initialization, so after initializing with the target password file, the obtained target device is the one expected to be produced.
[0059] Among them, verifying the integrity and legality of the target system firmware file during initialization and the first normal startup means that the module verifies the integrity of the target system firmware using the target password file during the loading stage (or the refreshing stage) of initialization to ensure that the target system firmware file is a complete system firmware file. In addition, the module verifies the legality of the target system firmware file using the target password file during the startup stage of initialization to ensure that the target system firmware is a legal system firmware file, and it can also verify that the target system firmware is the system firmware expected in the target device generated this time, avoiding the illegal loading of the module by other system firmware files instead of the target system firmware file.
[0060] S204. Send the target system firmware file bound to the target password file to the module so that the module can be initialized based on the target system firmware file; the target system firmware file is the system firmware file corresponding to the module.
[0061] Among them, the target system firmware file bound to the target password file is pre-set. The target password file and the target system firmware file are associated with the supplier. The target password file and the target system firmware file in this application belong to the target supplier, and the target supplier can provide the module in this application. Furthermore, the module is bound to the target password file and the target system firmware file is in a bound relationship. Under normal circumstances, the target password file and the bound target system firmware file need to be loaded into the module.
[0062] Among them, the target system firmware file is a basic input / output system firmware, which is the first program to start after the target device is powered on, and is used to configure the basic functions of the target device and overall configure the basic information of the target device. Among them, the basic input / output system firmware can be BIOS Firmware.
[0063] It should be noted that in this application, initialization is achieved during the production of the target device. The target device in this application is different from the devices in other related technologies. The target device in this application is equipped with a computing processing platform. What this application realizes is that when the target device is equipped with a computing processing platform and the detection system is in an offline state, this application can achieve offline and automatic initialization. In related technologies, when the target device is equipped with a computing processing platform, offline initialization cannot be performed, but manual initialization is achieved through manual means.
[0064] Among them, the computing processing platform can be a central processing unit designed for large-scale artificial intelligence and high-performance computing platforms. The computing processing platform can be a system for training giant artificial intelligence models, or other large-scale computing platforms, and there is no limitation here.
[0065] This embodiment provides a method for initializing a system firmware file. In this embodiment, first, in response to detecting that the system is in an offline state, an initialization command is obtained, and then the module is detected. If the detection result is not passed, a target password file is sent to the module. Further, the initialization device sends the target system firmware file bound to the target password file to the module, so that the module is initialized. It can be seen that in this embodiment, the initialization device realizes the automatic sending of the target system firmware file to the module, rather than manually loading the target system firmware file into the module. Therefore, the automatic method can improve production efficiency and reduce production costs. In addition, in this embodiment, the initialization device realizes the automatic detection of the module, which also improves production efficiency. In addition, in this embodiment, the initialization device also sends the target password file to the module, so that the module can verify the integrity and legality of the target password file during initialization, thus ensuring that the target system firmware file is reasonable and normal in the module. In addition, the module locks the permissions with the target password file, so as to ensure the security of the target device during production. It can be seen that in this embodiment, not only the initialization efficiency of the target system firmware file is improved by an automatic method, thereby improving production efficiency and reducing production costs, but also the target system firmware file can be ensured to be reasonable, normal and safe.
[0066] Embodiment 2
[0067] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional way to detect the module based on the initialization command to obtain the detection result.
[0068] Figure 3 A schematic flow chart of a method for initializing a system firmware file provided for Embodiment 2 is as follows Figure 3 shown, including:
[0069] S301, detecting the initialization status information of the module through a preset security protocol.
[0070] Among them, the preset security protocol can be any security protocol. For example, it can be the SPDM (Security Protocol and Data Model) protocol. Among them, the SPDM protocol can protect the security and integrity of data transmission between devices.
[0071] Among them, the initialization status information refers to the status information of whether the module is initialized.
[0072] Among them, the initialization status information includes uninitialized or initialized.
[0073] S302, if the initialization status information is uninitialized, it is determined that the detection result is not passed.
[0074] Among them, the initialization status information being uninitialized means that the module does not include the target system file or the target password file.
[0075] S303, if the initialization status information is initialized, then determine that the detection result is passed.
[0076] Among them, being initialized means that the module includes the target system file or the target password file.
[0077] It should be noted that before the electronic device in this application detects the module, the firmware partition therein already includes the target system firmware file. The electronic device can detect the module based on the automatic detection function of the target system firmware file stored in itself, and can detect whether the module includes the target password file or the target system firmware file, or can also detect whether the module is in a normal startup state. If it is detected that the module does not include the target password file or the target system firmware file, or it is detected that the module is in an abnormal startup state, then the electronic device can automatically implement the initialization of the target system firmware.
[0078] In this application, before detecting the module, the electronic device can control the module to start. If the module fails to start within the specified time, the user can trigger a one-key operation through the user terminal or the electronic device. The electronic device obtains the initialization command, and then performs detection based on the initialization command, and automatically determines whether initialization is required according to the detection result. It should be noted that it is possible to directly perform the initialization of the target system firmware file without detection after obtaining the initialization command. However, in this application, considering the accidental factor that the initialized module fails to start within the specified time, in order to ensure accuracy, detection can be performed after obtaining the initialization command. The detection can more accurately determine whether the module is initialized. If the detection result is not passed, the electronic device automatically performs the subsequent initialization process.
[0079] In one way, if the detection result is passed, the electronic device does not perform initialization. At this time, it means that the module is already initialized, but due to an accident in the early stage, the module failed to start within the specified time. Therefore, the initialization process is not performed at this time. The electronic device can control the module to start again to achieve the first normal startup of the module.
[0080] It should be noted that this embodiment realizes that the electronic device automatically detects whether the module is initialized, that is, in the case where the newly incoming module cannot start normally, automatic initialization can be performed, so that the newly incoming module is initialized and can start normally for the first time, further realizing the way of automatic production on the production line.
[0081] It should be noted that the reason why the newly incoming module cannot start normally is that the newly incoming module does not include the target system firmware file.
[0082] This embodiment provides a method for initializing system firmware files. In this embodiment, the initialization status information of the module is detected through a preset security protocol. Since a security protocol is adopted, the security of data transmission between the electronic device and the module is ensured, and the intrusion of malicious data is avoided; at the same time, the integrity of the data is also ensured.
[0083] Embodiment III
[0084] This embodiment is a further refinement of any of the above embodiments. In this embodiment, the initialization status information includes password initialization information.
[0085] Among them, the initialization status information includes firmware initialization information and password initialization information.
[0086] Among them, the firmware initialization information includes that the target system firmware file is not initialized or has been initialized. Among them, the firmware initialization information being not initialized indicates that the target system firmware file is not initialized, that is, the module does not include the target system file.
[0087] Among them, the password initialization information includes that the target password file is not initialized or has been initialized. Among them, the password initialization information being not initialized indicates that the target password file is not initialized, that is, it indicates that the module does not include the target password file. It can be understood that since the target password file and the target system firmware file are in a binding relationship, when the target password file is not initialized (that is, the target password file is not included in the module), it means that the target system firmware file is not initialized.
[0088] This embodiment is an optional way to detect the initialization status information of the module through a preset security protocol, including:
[0089] Detect the password initialization information of at least one externally trusted root in the module through a preset security protocol.
[0090] In one way, an externally trusted root can be deployed on each side of a module, and the electronic device can detect the password initialization information of at least one externally trusted root included in the module through a preset security protocol.
[0091] Among them, the externally trusted root can be used to store the target password file.
[0092] Among them, the password initialization information refers to the information on whether the target password file is initialized. If the target password file is included in the externally trusted root, the password initialization information is initialized; if the target password file is not included in the externally trusted root, the password initialization information is not initialized.
[0093] This embodiment provides a method for initializing system firmware files. In this embodiment, only the password initialization information needs to be detected to determine whether the initialization status information is initialized.
[0094] Example 4
[0095] This example is a further refinement of any of the above examples. In this example, the initialization status information includes password initialization information.
[0096] This example is an optional way to determine that the detection result fails if the initialization status information is uninitialized, including:
[0097] If the password initialization information is uninitialized, determine that the detection result fails.
[0098] Among them, the password initialization information being uninitialized means that the target password file is not included in the external trusted root.
[0099] This example is an optional way to determine that the detection result passes if the initialization status information is initialized, including:
[0100] If the password initialization information is initialized, determine that the detection result passes.
[0101] Among them, the password initialization information being initialized means that the target password file is included in the external trusted root.
[0102] This example provides a method for initializing the system firmware file. In this example, the detection result is accurately determined according to whether the password initialization information is initialized.
[0103] Example 5
[0104] This example is a further refinement of any of the above examples. This example is an optional way to determine the password initialization information, including:
[0105] If it is detected that the target password file is not included in any of the external trusted roots, determine that the password initialization information is uninitialized; the external trusted root is located in the module.
[0106] It should be noted that for multiple external trusted roots, if it is detected that the target password file is not included in any one of them, determine that the password initialization information is uninitialized.
[0107] If it is detected that the target password file is included in each of the external trusted roots, determine that the password initialization information is initialized.
[0108] It should be noted that for multiple external trusted roots, if it is detected that the target password file is included in each of the external trusted roots, determine that the password initialization information is initialized.
[0109] It should be noted that the external trusted roots are interconnected, and the statuses of the external trusted roots are basically the same. That is, if one of the external trusted roots includes the target password file, the other external trusted roots will also include the target password file; or, if one of the external trusted roots does not include the target password file, the other external trusted roots will also not include the target password file.
[0110] In practical applications, in order to save computing time and computing resources, the initialization device can detect only any one of the external trusted roots.
[0111] Specifically, the initialization device can randomly detect any one of the external trusted roots.
[0112] Alternatively, the initialization device can detect a predetermined external trusted root among them.
[0113] Alternatively, the initialization device can detect an external trusted root with a shorter communication distance among them. Here, the communication distance refers to the distance between the electronic device and the external trusted root.
[0114] This embodiment provides a method for initializing a system firmware file. In this embodiment, as long as it is detected that any one of the external trusted roots does not include the target password file, it is determined that the password initialization information is not initialized, so there is no need to continue detecting the other external trusted roots; in addition, in this embodiment, only when it is detected that all the external trusted roots include the target password file, will it be determined that the password initialization information is initialized, so the accuracy of the password initialization information is improved, and the situation where one of the external trusted roots does not include the target password file while the other external trusted roots all include the target password file due to abnormal conditions is avoided, so the accuracy is improved to prevent abnormal situations.
[0115] Embodiment Six
[0116] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional method before sending the target password file to the module, including:
[0117] Obtain the target password file from its own preset storage space.
[0118] Among them, the initialization device includes a preset storage space.
[0119] Among them, the preset storage space can be an embedded memory card (Embedded Multi Media Card, abbreviated as EMMC) using the storage technology of NAND Flash, and EMMC is mainly used in embedded devices.
[0120] Specifically, the initialization device obtains the target password file from the embedded memory card.
[0121] It should be noted that the target password file can be pre-stored in a preset storage space.
[0122] This embodiment also includes an optional method for sending the target password file to the module, specifically:
[0123] Send the target password file to the module through a preset security protocol.
[0124] This embodiment provides a method for initializing a system firmware file. In this embodiment, to ensure the security and integrity of data, the initialization device sends the target password file to the module through a preset security protocol.
[0125] Embodiment Seven
[0126] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional method for sending the target password file to the module through a preset security protocol, including:
[0127] Send the target password file to at least one external trusted root in the module through a preset security protocol.
[0128] This embodiment provides a method for initializing a system firmware file. In this embodiment, to ensure that each external trusted root includes the target password file, the target password file needs to be sent to at least one external trusted root.
[0129] Embodiment Eight
[0130] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional method for obtaining the target password file from its own preset storage space, including:
[0131] Obtain the target password file from the password partition; the password partition is located in the preset storage space.
[0132] It should be noted that for an electronic device, it can be partitioned in advance, and the preset storage space therein is partitioned into a password partition and a firmware partition.
[0133] Among them, the password partition is used to pre-store the target password file.
[0134] Among them, the firmware partition is used to pre-store the target system firmware file.
[0135] This embodiment provides a method for initializing a system firmware file. In this embodiment, the password partition is located in a preset storage space. It can be further refined that the target password file is obtained from the password partition, which is more orderly, rather than obtaining the target password file in the preset storage space as a unit. Because the preset storage space may include a large amount of data, if the target password file is directly obtained in the preset storage space, it may take more time to obtain the target password file; and the way to obtain the target password file is also messy.
[0136] Embodiment Nine
[0137] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional way to send the target system firmware file bound to the target password file to the module so that the module can be initialized based on the target system firmware file, including:
[0138] Obtain the target system firmware file bound to the target password file from its own preset storage space;
[0139] This embodiment also includes an optional way to send the target system firmware file bound to the target password file to the module so that the module can be initialized based on the target system firmware file. Specifically:
[0140] Send the target system firmware file to the module through a preset management protocol so that the module can be initialized based on the target system firmware file.
[0141] Among them, the preset management protocol can be a set of standards developed by the Distributed Management Task Force, which can be the PLDM protocol (full name Platform Level Data Model). This protocol mainly aims to standardize the data exchange between system management components.
[0142] This embodiment provides a method for initializing a system firmware file. In this embodiment, the target system firmware file is sent through a preset management protocol. Using the preset management protocol can systematically implement the sending of the target system firmware file.
[0143] Embodiment Ten
[0144] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional way to obtain the target system firmware file bound to the target password file from its own preset storage space, including:
[0145] Obtain the target system firmware file bound to the target password file from the firmware partition; the firmware partition is located in the preset storage space.
[0146] This embodiment provides a method for initializing a system firmware file. In this embodiment, the firmware partition is located in a preset storage space. It can be further refined that the target system firmware file is obtained from the firmware partition, which is more orderly, rather than obtaining the target system firmware file in the preset storage space as a unit. Because the preset storage space may include a large amount of data, if the target system firmware file is directly obtained in the preset storage space, it may take more time to obtain the target system firmware file; and the way to obtain the target system firmware file is also messy.
[0147] Embodiment XI
[0148] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional way of sending the target system firmware file bound to the target password file to the module so that the module can be initialized based on the target system firmware file, including:
[0149] When the module has initialized the target system firmware file, control the module to start normally for the first time so that the detection system in the module goes online. The detection system is used to detect abnormalities in the production process of the target device.
[0150] It should be noted that whether the detection system can go online (i.e., start normally) depends on the existence of the target system firmware file. Because the target system firmware is the basic program in the module, after the module is obtained for the first time, the target system firmware file needs to be initialized in the module before the detection system can go online.
[0151] Among them, the detection system is located in the module and can be used to detect abnormalities in the production process of the target device. The detection system is an essential system during the production process of the target device.
[0152] This embodiment provides a method for initializing a system firmware file. In this embodiment, the detection system goes online, so abnormalities in the production process can be detected, and thus the production process can be ensured to proceed smoothly.
[0153] Embodiment XII
[0154] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional way before obtaining the initialization command in response to the detection system being in an offline state, including:
[0155] Step 1: Generate a target password file.
[0156] It should be noted that the target password file is generated before the system firmware is initialized and stored in the storage partition.
[0157] In one way, a preset asymmetric encryption algorithm can be used to generate the target password file.
[0158] Step 2: Partition the preset storage space of itself to obtain storage partitions.
[0159] The preset storage space in this application can be an electronic storage device.
[0160] It should be noted that the initialization device can randomly partition its own preset storage space to obtain storage partitions.
[0161] Alternatively, the initialization device partitions the preset storage space based on the pre-received partition address information. The partition address information refers to the address information included in the preset storage space. The storage partitions in this application can be multiple partitions. Among them, by way of example, it is assumed that the preset storage space includes three address information, namely the first address information, the second address information, and the third address information. Among them, the partition address information is the first address information and the second address information. Then the initialization device partitions the first address information and the second address information according to the partition address information to obtain storage partitions, where the partition address information includes the first address information and the second address information. Based on the above description, the storage partitions in this application can be multiple partitions. Among them, the address information can include the corresponding storage space capacity information.
[0162] In one way, the storage partition in this application can be one partition, that is, only one address information is included in the partition address information, that is, a space is divided from the preset storage space as the storage partition.
[0163] Step 3: Store the target password file in the storage partition.
[0164] This embodiment provides a method for initializing a system firmware file. In this embodiment, storing the target password file in the storage partition facilitates subsequent acquisition from a more refined storage partition, rather than directly acquiring the target password file in units of the preset storage partition.
[0165] Embodiment Thirteen
[0166] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional way to generate the target password file, including:
[0167] Generate a local authorization password and its corresponding component authorization password using a preset asymmetric encryption algorithm; the component authorization password includes a component public key and a component private key; the target password file includes the local authorization password and the component authorization password; the component authorization password is used for the module to verify the integrity and legality of the target system firmware file during initialization and the first normal startup; the local authorization password is used for the module to lock the component authorization password to lock the permissions.
[0168] Among them, the component authorization password can be expressed as Component Authorization Key, abbreviated as CAK Key.
[0169] Among them, the local access password can be expressed as Local Access Key, abbreviated as LAK Key.
[0170] Among them, the component authorization password is used to verify the integrity of the target system firmware file during the refresh phase when the module is initialized. Also, after the refresh is completed, when the control model starts normally for the first time and enters the startup phase, the component authorization password is also used to verify the legality of the target system firmware file.
[0171] Among them, the local access password is used to lock the component authorization password to prevent the component authorization password from being invaded, tampered with, or replaced during the entire production process, thus realizing the locking of the permissions of the target device.
[0172] It should be noted that in actual applications, the component authorization password is the password corresponding to the target supplier, and the local access password is the password corresponding to the target producer. There is a cooperation relationship between the target supplier and the target producer. Due to this cooperation relationship, two target password files corresponding to the two merchants are generated. This indicates the cooperation between the above two merchants during this production. The system firmware files of any other merchants cannot be initialized into the module in this application. Therefore, the target device produced carries the target system firmware file of the target supplier and other components of the target producer, and it is not allowed to load the system firmware files of other suppliers into the module in this application to avoid confusing the produced devices and failing to achieve the expected target device.
[0173] In this application, the preset asymmetric encryption algorithm can be generated by the RSA-3072 asymmetric encryption algorithm.
[0174] This embodiment provides a method for initializing a system firmware file. In this embodiment, the local access password and the component authorization password are in a corresponding relationship, which can also be said to be a binding relationship. First, the component authorization password ensures the integrity and legality of the target system firmware file; the local access password locks the permissions to ensure that the target device is the device within the expected production permissions.
[0175] Embodiment Fourteen
[0176] This embodiment is a further refinement of any of the above embodiments. This is an optional way to partition the preset storage space of itself to obtain storage partitions, including:
[0177] Partition the preset storage space of itself to obtain a password partition and a firmware partition respectively; the storage partition includes a password partition and a firmware partition.
[0178] According to the description of the storage partition being multiple partitions in Embodiment Twelve, further, the partition address information further includes the function information corresponding to each address information. Exemplarily, if the function information corresponding to the first address information is that the address corresponding to the first address information is the address for storing the target password file, then when initializing the partition, the initialization device partitions the address corresponding to the first address information into a password partition.
[0179] Similarly, the partition address information further includes: the function information corresponding to the second address information is that the address corresponding to the second address information is the address for storing the target system firmware file, then when initializing the partition, the initialization device partitions the address corresponding to the second address information into a firmware partition.
[0180] This embodiment provides a method for initializing a system firmware file. In this embodiment, the storage partition is further refined into a password partition and a firmware partition, which is more beneficial and faster to obtain data from each partition.
[0181] It should be noted that in this application, the preset storage space is pre-partitioned to obtain a storage partition. Among them, the storage partition may include a password partition and a firmware partition, and different partitions have different functions. Among them, the password partition can store the target password file, and the firmware partition can store the target system firmware file. Thus, different files are stored in different partitions, which is convenient for obtaining different files from different partitions. The pre-partitioning method in this application has obvious advantages.
[0182] Embodiment Fifteen
[0183] This embodiment is a further refinement of any of the above embodiments. In this embodiment, the storage partition includes a password partition and a firmware partition.
[0184] This embodiment is an optional way to store the target password file in the storage partition, including:
[0185] Storing the target password file into the password partition through a preset programmer.
[0186] This embodiment further includes:
[0187] Receiving the target system firmware file bound to the target password file; storing the target system firmware file into the firmware partition through a preset programmer.
[0188] Among them, the target system firmware file can be provided by the target vendor, can be sent from the user side to the electronic device, and the electronic device receives the target system firmware file.
[0189] It should be noted that during the production stage of the target device in this application, the electronic device can preset the target password file and the target system firmware file at a relatively low cost through the system firmware image preset function. In this embodiment, the preset programmer plays a role when using the system firmware image preset function.
[0190] This embodiment provides a method for initializing a system firmware file. In this embodiment, the preset programmer is used to store the target password file and the target system firmware file into the corresponding partitions, so that each partition stores its corresponding file, which is convenient for subsequent file acquisition. Herein, the file refers to the target password file and the target system firmware file.
[0191] Embodiment XVI
[0192] This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional method before obtaining the initialization command in response to detecting that the system is in an offline state, and includes:
[0193] Start the control module. In response to the module failing to start normally, determine that the detection system in the module is not suspended and determine that the detection system is in an offline state.
[0194] This embodiment also includes another method, specifically:
[0195] Receive the detection system status information of the module. In response to the system status information being in an offline state, determine that the detection system is in an offline state.
[0196] Herein, the system status information refers to the status information of the detection system.
[0197] Herein, the system status information includes an offline state or an online state.
[0198] Herein, the offline state means that the detection system cannot be suspended and cannot be used normally.
[0199] Herein, the online state means that the detection system can be suspended and can be used normally.
[0200] This embodiment also includes another method, specifically:
[0201] In response to triggering a one-key operation, determine that the detection system is in an offline state and obtain an initialization command; the initialization command can be generated by the user terminal when triggering a one-key operation on the user terminal and sent to the electronic device. It can also be generated by the electronic device when triggering a one-key operation on the electronic device, and then the initialization command is obtained.
[0202] Herein, triggering a one-key operation can be a one-key operation triggered by the user on the user terminal or on the electronic device, and there is no limitation here.
[0203] It can be understood that in this method, a one-key initialization method for the system firmware file can be implemented, that is, only by triggering a one-key operation, the automatic initialization of the target system firmware file can be achieved.
[0204] It should be noted that in this application, when the user triggers a one-key operation and determines that the detection system is in an offline state, it may also be caused accidentally. Therefore, after obtaining the initialization command, in case the detection system is in an offline state accidentally, the electronic device can detect the module based on the initialization command, and determine whether to automatically send the target password file and the target system firmware file to the module based on the final detection result, so that the module completes the initialization of the target system firmware file.
[0205] It should be noted that when the detection result is not passed, it means that the detection system is finally in an offline state, and it also means that the module fails to start normally (i.e., an abnormal startup state), and the module does not include the target password file or the target system file.
[0206] Figure 4 A schematic diagram of a target device provided by this application. As Figure 4 shown, the target device 400 includes an electronic device 101, a module 102, a main board 401, and a computing processing platform 402.
[0207] Among them, both the electronic device 101 and the module 102 are deployed on the main board 401.
[0208] Among them, the main board 401 is mounted on the computing processing platform 402.
[0209] Among them, the module 102 is communicatively connected to the electronic device 101, and the connection method can be a wired connection or a wireless connection.
[0210] Figure 5 An interaction schematic diagram provided by this application. As Figure 5 shown, the execution entities include BMC and the module.
[0211] S501, BMC generates a target password file and stores it in the password partition.
[0212] S502, BMC receives the target system firmware file bound to the target password file and stores it in the firmware partition.
[0213] S503, BMC obtains an initialization command in response to the detection system being in an offline state.
[0214] S504, BMC detects the module based on the initialization command to obtain a detection result; if the detection result is not passed, then execute S505; if the detection result is passed, then execute S509.
[0215] S505, the BMC sends the target password file to the module.
[0216] S506, the module stores the target password file in its own external trusted root.
[0217] S507, the BMC sends the target system firmware file bound to the target password file to the module.
[0218] S508, the module loads the target system firmware file into the electronic storage chip based on the external trusted root, and initializes the target system firmware file based on the target password file.
[0219] S509, the BMC controls the first normal startup.
[0220] S510, the module normally starts up when the target system firmware file has been initialized, and brings the detection system online.
[0221] Among them, the electronic storage chip can be a Flash chip, or other storage devices, etc., which is not limited here.
[0222] In this application, the BMC sends the target system firmware file to the external trusted root, then the external trusted root sends the target system firmware file to the electronic storage chip, and then uses the target password file to perform integrity verification on the target system firmware file. If the integrity verification passes, it supports loading the target system firmware file into the electronic storage chip, and then the module loads the target system firmware into the electronic storage chip. Further, when the module receives the control startup request from the BMC, that is, the BMC requests to control the module to start up normally for the first time, then before the first normal startup, the module uses the target password file to perform legality verification on the target system firmware file. If the legality verification passes, the module starts up normally for the first time under the control of the BMC. After the module starts up normally, the detection system included therein operates normally, that is, the detection system is online. In this application, the BMC uses the method of presetting the target password file and the target system firmware file to automatically send the target password file and the target system firmware file to the module during the production process, enabling the detection system in the module to operate normally, thereby realizing the automatic compatibility of the detection system. This application can improve production efficiency and reduce production costs. Among them, the module in this application has the function of changing the device owner, and thus can perform two verifications based on the target password file and lock the permissions.
[0223] In this application, the detection system can realize the diagnosis of production anomalies during the entire production process, providing strong support for production.
[0224] Among them, the integrity verification of the target system firmware file is performed using the target password file. Specifically, the module receives integrity signature information, which is generated by signing with the component private key in the component authorization password. Further, the module verifies the integrity signature information based on the component public key. If the component public key matches the integrity signature information, the integrity verification passes.
[0225] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0226] Figure 6 It is a schematic diagram of the initialization system hardware provided by this application. As Figure 6 shown, the board-level management control device 600 includes an EMMC memory 601, an embedded processor 602, and an integrated circuit 603.
[0227] Among them, the embedded processor 602 includes a communication controller 6021.
[0228] Among them, the EMMC memory 601 includes a password partition 6011 and a firmware partition 6012.
[0229] Among them, Figure 6 It further includes a module 102. Among them, the module 102 includes a Field-Programmable Gate Array (FPGA) 6041, a security controller 6042, and an electronic storage chip 6043.
[0230] Among them, the embedded processor 602 can communicate with the FPGA 6041 in the module according to a preset protocol through the communication controller 6021, realizing the communication between the board-level management control device (BMC) 600 and the FPGA 6041 in the module 102 according to a preset protocol. Among them, the preset protocol can be a preset security protocol and / or a preset management protocol.
[0231] Specifically, when the board-level management control device 600 is powered on, in response to the detection system in the module 102 being in an offline state, an initialization command is obtained. The initialization command is used to trigger detection and initialization actions. The embedded processor 602 is used to control the integrated circuit 603 to detect the module 102 to obtain a detection result.
[0232] Further, if the detection result fails, the embedded processor 602 obtains the target password file from the password partition 6011 in the EMMC memory 601, and sends the target password file to the FPGA 6041 in the module 102 according to the corresponding preset protocol through the communication controller 6021. The FPGA 6041 sends and stores the target password file to the security controller 6042. Among them, Figure 6 the security controller 6042 in
[0233] Further, the embedded processor 602 obtains the target system firmware file from the firmware partition 6012, and sends the target system firmware file to the FPGA 6041 in the module 102 according to the corresponding preset protocol through the communication controller 6021. The module 102 sends and stores the target system firmware file to the electronic storage chip 6043 through the FPGA 6041.
[0234] In Figure 6 , the FPGA 6041 can be communicatively connected through a Serial Peripheral Interface (SPI). The embedded processor 602 and the integrated circuit 603 can also be communicatively connected through SPI. The embedded processor 602 can be communicatively connected through an EMMC (Embedded Multimedia Card), which can provide high-speed data transmission and storage functions.
[0235] The embodiment of the present application also provides a system firmware file initialization device. Figure 7 The following is a schematic structural diagram of a system firmware file initialization device provided by the present application. As Figure 7 shown, the system firmware file initialization device 700 includes the following modules:
[0236] An acquisition module 701, configured to obtain an initialization command in response to detecting that the system is in an offline state; the detection system is located in the module;
[0237] A detection module 702, configured to detect the module based on the initialization command to obtain a detection result;
[0238] A sending module 703, configured to send a target password file to the module if the detection result fails; the target password file corresponds to the module; the module is used to produce the target device; the target device is equipped with a computing processing platform; the target password file is used to verify the integrity and legality of the target system firmware file during the initialization and the first normal startup of the module, and is used to lock the permissions of the module;
[0239] The sending module 703 is further configured to send the target system firmware file bound to the target password file to the module, so that the module is initialized based on the target system firmware file; the target system firmware file is the system firmware file corresponding to the module.
[0240] Optionally, when the detection module 702 detects the module based on the initialization command to obtain a detection result, it is specifically used for:
[0241] Detect the initialization status information of the module through a preset security protocol;
[0242] If the initialization status information is uninitialized, determine that the detection result fails;
[0243] If the initialization status information is initialized, determine that the detection result passes.
[0244] Optionally, the initialization status information includes password initialization information;
[0245] When the detection module 702 detects the initialization status information of the module through a preset security protocol, it is specifically used for:
[0246] Detect the password initialization information of at least one externally trusted root in the module through a preset security protocol.
[0247] Optionally, the initialization status information includes password initialization information;
[0248] When the detection module 702 determines that the detection result fails if the initialization status information is uninitialized, it is specifically used for:
[0249] If the password initialization information is uninitialized, determine that the detection result fails;
[0250] If the initialization status information is initialized, determining that the detection result passes includes:
[0251] If the password initialization information is initialized, determine that the detection result passes.
[0252] Optionally, this embodiment provides a system firmware file initialization device, further including: a determination module;
[0253] When the determination module determines the password initialization information, it is specifically used for:
[0254] If it is detected that any externally trusted root does not include the target password file, determine that the password initialization information is uninitialized; the externally trusted root is located in the module;
[0255] If it is detected that each externally trusted root includes the target password file, determine that the password initialization information is initialized.
[0256] Optionally, before the acquisition module 701 sends the target password file to the module, it is further used for:
[0257] Obtain the target password file from its own preset storage space;
[0258] The sending module 703, when sending the target password file to the module, is specifically used for:
[0259] Send the target password file to the module through a preset security protocol.
[0260] Optionally, the sending module 703, when sending the target password file to the module through a preset security protocol, is specifically used for:
[0261] Send the target password file to at least one external trusted root in the module through a preset security protocol.
[0262] Optionally, when the obtaining module 701 obtains the target password file from its own preset storage space, it is specifically used for:
[0263] Obtain the target password file from the password partition; the password partition is located in the preset storage space.
[0264] Optionally, before sending the target system firmware file bound to the target password file to the module so that the module is initialized based on the target system firmware file, the obtaining module 701 is further used for:
[0265] Obtain the target system firmware file bound to the target password file from its own preset storage space;
[0266] The sending module 703, when sending the target system firmware file bound to the target password file to the module so that the module is initialized based on the target system firmware file, is specifically used for:
[0267] Send the target system firmware file to the module through a preset management protocol so that the module is initialized based on the target system firmware file.
[0268] Optionally, when the obtaining module 701 obtains the target system firmware file bound to the target password file from its own preset storage space, it is specifically used for:
[0269] Obtain the target system firmware file bound to the target password file from the firmware partition; the firmware partition is located in the preset storage space.
[0270] Optionally, this embodiment provides a system firmware file initialization device, further including: a control module;
[0271] After sending the target system firmware file bound to the target password file to the module so that the module is initialized based on the target system firmware file, the control module is used for:
[0272] When the module has initialized the target system firmware file, control the module to start normally for the first time, so that the detection system in the module goes online. The detection system is used to detect anomalies during the production process of the target device.
[0273] Optionally, this embodiment provides a system firmware file initialization device, further including: a generation module, a partitioning module, and a storage module;
[0274] Before obtaining the initialization command in response to the detection system being in an offline state, where the generation module is used to generate a target password file; the partitioning module is used to partition its own preset storage space to obtain a storage partition; the storage module is used to store the target password file in the storage partition.
[0275] Optionally, when generating the target password file, the generation module is specifically used for:
[0276] Generate a local authorization password and its corresponding component authorization password using a preset asymmetric encryption algorithm; the component authorization password includes a component public key and a component private key; the target password file includes the local authorization password and the component authorization password; the component authorization password is used for the module to verify the integrity and legality of the target system firmware file during initialization and the first normal startup; the local authorization password is used for the module to lock the component authorization password to lock permissions.
[0277] Optionally, when partitioning its own preset storage space to obtain a storage partition, the partitioning module is specifically used for:
[0278] Partition its own preset storage space to respectively obtain a password partition and a firmware partition; the storage partition includes a password partition and a firmware partition.
[0279] Optionally, the storage partition includes a password partition and a firmware partition;
[0280] When storing the target password file in the storage partition, the storage module is specifically used for:
[0281] Store the target password file in the password partition through a preset programmer;
[0282] This application provides a system firmware initialization device, further including: a receiving module, used for: receiving the target system firmware file bound to the target password file;
[0283] The storage module is further used to store the target system firmware file in the firmware partition through a preset programmer.
[0284] Optionally, before obtaining the initialization command in response to the detection system being in an offline state, the control module is further used for:
[0285] The control module is started to determine the module, and is further configured to: in response to the failure of the module to start normally, determine that the detection system in the module is not suspended, and determine that the detection system is in an offline state;
[0286] The receiving module is further configured to receive the detection system status information of the module, and the determining module is further configured to: in response to the system status information being in an offline state, determine that the detection system is in an offline state.
[0287] For the description of the features in the embodiment corresponding to the system firmware file initialization device, reference may be made to the relevant description in the embodiment corresponding to the system firmware file initialization method, which will not be elaborated here one by one.
[0288] Figure 8 This is a schematic structural diagram of the electronic device provided by this application. As Figure 8 shown, the electronic device 101 provided in this embodiment includes: at least one processor 801 and a memory 802. Optionally, the electronic device 101 further includes a communication component 803. Among them, the processor 801, the memory 802, and the communication component 803 are connected through a bus 804.
[0289] In the specific implementation process, at least one processor 801 executes the computer execution instructions stored in the memory 802, so that at least one processor 801 executes the above-mentioned embodiment of the system firmware file initialization method.
[0290] For the specific implementation process of the processor 801, reference may be made to the above method embodiment, and its implementation principle and technical effects are similar, which will not be elaborated here in this embodiment.
[0291] In the above embodiment, it should be understood that the processor may be a central processing unit (Central Processing Unit, abbreviated as: CPU), or other general-purpose processors, digital signal processors (Digital Signal Processor, abbreviated as: DSP), application specific integrated circuits (Application Specific Integrated Circuit, abbreviated as: ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the application can be directly implemented by the execution of the hardware processor, or implemented by the combination of the hardware and software modules in the processor.
[0292] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0293] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the buses in the drawings of the present application are not limited to only one bus or one type of bus.
[0294] An embodiment of the present application also provides a computer-readable storage medium storing a computer program, where the computer program is configured to execute the steps in any of the above-mentioned system firmware file initialization method embodiments when running.
[0295] In an exemplary embodiment, the above-mentioned computer-readable storage medium may include, but is not limited to: various media that can store computer programs such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc.
[0296] An embodiment of the present application also provides a computer program product. The above-mentioned computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-mentioned system firmware file initialization method embodiments.
[0297] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-mentioned system firmware file initialization method embodiments.
[0298] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.
[0299] The above has introduced in detail a method for initializing a system firmware file provided by this application. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method of this application and its core idea. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A method for initializing a system firmware file, characterized in that, Including: Upon detecting that the detection system is in an offline state, obtain an initialization command; The detection system is located in the module; Based on the initialization command, detect at least one external trusted root in the module to obtain a detection result; If the detection result fails, send a target password file to the module; the target password file corresponds to the module; The module is used to produce a target device; the target device is equipped with a computing processing platform; the target password file is used for the module to verify the integrity and legality of the target system firmware file during initialization and the first normal startup, and is used for the module to lock permissions; Send the target system firmware file bound to the target password file to the module, so that the module initializes based on the target system firmware file; The target system firmware file is the system firmware file corresponding to the module.
2. The method according to claim 1, wherein The detecting at least one external trusted root in the module based on the initialization command to obtain a detection result includes: Detect the initialization status information of the module through a preset security protocol; If the initialization status information is uninitialized, determine that the detection result fails; If the initialization status information is initialized, determine that the detection result passes.
3. The method according to claim 2, characterized in that, The initialization status information includes password initialization information; The detecting the initialization status information of the module through a preset security protocol includes: Detect the password initialization information of at least one external trusted root in the module through a preset security protocol.
4. The method according to claim 2, wherein The initialization status information includes password initialization information; The if the initialization status information is uninitialized, determining that the detection result fails includes: If the password initialization information is uninitialized, determine that the detection result fails; The if the initialization status information is initialized, determining that the detection result passes includes: If the password initialization information is initialized, determine that the detection result passes.
5. The method according to claim 4, characterized in that Determining the password initialization information includes: If it is detected that any of the external trusted roots does not include the target password file, determine that the password initialization information is uninitialized; the external trusted root is located in the module; If it is detected that all of the external trusted roots include the target password file, determine that the password initialization information is initialized.
6. The method according to claim 1, wherein Before sending the target password file to the module, it further includes: Obtain the target password file from its own preset storage space; The sending the target password file to the module includes: Send the target password file to the module through a preset security protocol.
7. The method according to claim 6, wherein The sending the target password file to the module through a preset security protocol includes: Send the target password file to at least one external trusted root in the module through a preset security protocol.
8. The method according to claim 6, wherein The obtaining the target password file from its own preset storage space includes: Obtain the target password file from the password partition; the password partition is located in the preset storage space.
9. The method according to claim 1, characterized in that, Before sending the target system firmware file bound to the target password file to the module to enable the module to be initialized based on the target system firmware file, the method further includes: Obtaining the target system firmware file bound to the target password file from its own preset storage space; The step of sending the target system firmware file bound to the target password file to the module to enable the module to be initialized based on the target system firmware file includes: Sending the target system firmware file to the module through a preset management protocol to enable the module to be initialized based on the target system firmware file.
10. The method according to claim 9, wherein The step of obtaining the target system firmware file bound to the target password file from its own preset storage space includes: Obtaining the target system firmware file bound to the target password file from a firmware partition; the firmware partition is located in the preset storage space.
11. The method according to claim 1, wherein After sending the target system firmware file bound to the target password file to the module to enable the module to be initialized based on the target system firmware file, the method further includes: When the module has initialized the target system firmware file, controlling the module to start normally for the first time to enable the detection system in the module to go online, where the detection system is used to detect anomalies during the production process of the target device.
12. The method according to claim 1, wherein Before responding to the offline state of the detection system and obtaining the initialization command, the method further includes: Generating a target password file; Partitioning its own preset storage space to obtain a storage partition; Storing the target password file in the storage partition.
13. The method according to claim 12, characterized in that, The step of generating the target password file includes: Generating a local authorization password and its corresponding component authorization password using a preset asymmetric encryption algorithm; the component authorization password includes a component public key and a component private key; the target password file includes the local authorization password and the component authorization password; the component authorization password is used for the module to verify the integrity and legality of the target system firmware file during initialization and the first normal startup; the local authorization password is used for the module to lock the component authorization password to lock the permissions.
14. The method according to claim 12, wherein The step of partitioning its own preset storage space to obtain a storage partition includes: Partitioning its own preset storage space to respectively obtain a password partition and a firmware partition; the storage partition includes the password partition and the firmware partition.
15. The method according to claim 12, wherein The storage partition includes a password partition and a firmware partition; The step of storing the target password file in the storage partition includes: Storing the target password file in the password partition through a preset programmer; The method further includes: Receiving the target system firmware file bound to the target password file; Storing the target system firmware file in the firmware partition through a preset programmer.
16. The method according to claim 1, characterized in that, Before responding to the offline state of the detection system and obtaining the initialization command, the method further includes: Controlling the module to start, and in response to the module failing to start normally, determining that the detection system in the module is not suspended and determining that the detection system is in an offline state; Alternatively, receive the detection system status information of the module, and in response to the system status information being in an offline state, determine that the detection system is in an offline state.
17. A system firmware file initialization device, characterized in that, It includes: An acquisition module, configured to acquire an initialization command in response to the detection system being in an offline state; The detection system is located in the module; A detection module, configured to detect at least one external trusted root in the module based on the initialization command to obtain a detection result; A sending module, configured to send a target password file to the module if the detection result is not passed; the target password file corresponds to the module; The module is used to produce a target device; the target device is equipped with a computing processing platform; the target password file is used for the module to verify the integrity and legality of the target system firmware file during initialization and the first normal startup, and is used for the module to lock permissions; The sending module is further configured to send a target system firmware file bound to the target password file to the module, so that the module is initialized based on the target system firmware file; The target system firmware file is the system firmware file corresponding to the module.
18. An electronic device, characterized in that, It includes: A memory, configured to store a computer program; A processor, configured to implement the steps of the system firmware file initialization method according to any one of claims 1 to 16 when executing the computer program.
19. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the system firmware file initialization method according to any one of claims 1 to 16 when executed by a processor.
20. A computer program product, comprising a computer program, characterized in that, The computer program implements the steps of the system firmware file initialization method according to any one of claims 1 to 16 when executed by a processor.
Citation Information
Patent Citations
Server component firmware updating method
CN111625263A
Component authentication method and device
CN116702114A