System, protection method, BIOS and computer protected by hybrid algorithm
Through the hybrid algorithm protection strategy, strong collision-resistant encryption signatures and RSA digital signatures combined with symmetric encryption are adopted for the core code, and lightweight algorithms are used for non-core codes, which solves the problem of insufficient system code integrity and credibility and achieves high security and high performance of the system.
Patent Information
- Application Number
- CN202510408317.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-02
AI Technical Summary
The prior art has shortcomings in protecting system code integrity and credibility, and cannot effectively prevent tampering or corruption, and digital signatures and hash verifications have computational complexity and hash collision attack risks.
The hybrid algorithm protection strategy is adopted to use the first collision-resistant encryption signature algorithm and RSA digital signature combined with symmetric encryption algorithm for multi-level protection. A lightweight encryption signature algorithm is used for non-core codes, and a dynamic selection algorithm is used according to the code, partition storage and verification is used according to the frequency.
Enhanced system security, prevent core code tampering, reduce the complexity of non-core code verification calculation, take into account system performance and security, and achieve a balance between security and performance.
Smart Images

Figure CN119918081B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer science and technology, and in particular to a system, a protection method, a BIOS and a computer protected by a hybrid algorithm. Background Art
[0002] In modern computer systems, the integrity of system code is an important link to ensure system security. With the rapid development of computer technology and the diversification of application scenarios, the attack methods faced by the system are becoming increasingly complex and diverse. In particular, the attack means against low-level systems such as BIOS (Basic Input / Output System) and firmware are constantly evolving. If an attacker successfully tampers with the system code, it will not only cause abnormal system operation, but may even be used as an entry point for malware propagation, data theft or deeper attacks.
[0003] Especially on the X86 platform, the security of system startup directly depends on the code integrity of the BIOS. As the interface between the system and the hardware, the core function of the BIOS is to complete system hardware initialization and boot the operating system. If the BIOS code is tampered with, an attacker can insert malicious code in the startup chain, which not only endangers the security of the operating system, but may also lead to uncontrollable risks for the entire system.
[0004] To ensure the integrity and security of system code, the prior art mainly uses the following methods to encrypt system code: (1) Symmetric encryption (such as AES): Protects the confidentiality of the code, but cannot prevent the code from being tampered with; (2) Digital signature (such as RSA): Verifies the source and integrity of the code, but the signature and verification processes are computationally complex and may affect system performance; (3) Hash check (such as SHA-256): Generates a code digest for integrity verification, but using the hash algorithm alone has the risk of being replaced by a legitimate hash value or suffering from a hash collision attack.
[0005] Although there are various system code encryption and protection methods listed above, there are still some problems and limitations in the prior art for protecting system code. First, the existing encryption technologies are mainly used to protect the confidentiality of code, but using encryption technology alone cannot effectively prevent the code from being tampered with or damaged during storage and operation. Second, although the existing digital signature technologies can verify the source and integrity of code, their signature and verification processes involve complex calculations, which may affect the performance of the system in systems with limited resources or high performance requirements. In addition, although the existing hash functions can generate a fixed-length message digest of the code, relying solely on hash functions for verification has deficiencies. Attackers may cause threats to the integrity and credibility of the code by replacing legitimate hash values or exploiting hash collisions. Therefore, there are still certain deficiencies in the prior art for protecting the integrity and credibility of system code.
[0006] The disclosure of the above background technical content is only for assisting in understanding the inventive concept and technical solution of the present invention, and it does not necessarily belong to the prior art of this application, nor will it necessarily provide technical guidance; in the case where there is no clear evidence indicating that the above content was publicly available before the filing date of this application, the above background technology should not be used to evaluate the novelty and inventiveness of this application. Summary of the Invention
[0007] The object of the present invention is to provide a system, protection method, BIOS and computer protected by a hybrid algorithm, which can improve the security of the system.
[0008] To achieve the above object, the technical solution adopted by the present invention is as follows:
[0009] A system protected by a hybrid algorithm, including a core code module, the core code module being configured to store and / or load the core code of the system, the core code being the code with relatively high security requirements in the system. For some systems with very high security requirements, it can be determined that all of its code is the core code;
[0010] The core code is protected by a first protection strategy, and the first protection strategy includes:
[0011] Calculating an encrypted signature value of the core code using a first encryption signature algorithm to obtain an original first encrypted signature value;
[0012] Performing a digital signature on the original first encrypted signature value using an RSA private key to generate original signature data;
[0013] Encrypting the original signature data using a first symmetric encryption algorithm to generate an encrypted original check code;
[0014] Store the original first encrypted signature value and the original check code in a first storage area, which is a secure storage area.
[0015] Further, based on any one of the above technical solutions or a combination of multiple technical solutions, it further includes a dynamic loading module, which is configured to store and / or load non-core code of the system, and the security level of the non-core code is lower than that of the core code;
[0016] Protect the non-core code by using a second protection strategy, and the second protection strategy includes:
[0017] Calculate the encrypted signature value of the non-core code by using a second encryption signature algorithm to obtain an original second encrypted signature value. Both the first encryption signature algorithm and the second encryption signature algorithm preferably adopt a hash algorithm based on a hash function. The collision resistance of the first encryption signature algorithm is stronger than that of the second encryption signature algorithm. The collision resistance of the hash algorithm refers to the difficulty of finding two different input data such that the hash values generated by them through the hash function are the same. And the second encryption signature algorithm is a lightweight encryption algorithm, and its calculation efficiency is higher than that of the first encryption signature algorithm;
[0018] Store the original second encrypted signature value in a second storage area, and the security level of the first storage area is higher than that of the second storage area.
[0019] Further, based on any one of the above technical solutions or a combination of multiple technical solutions, the second protection strategy further includes:
[0020] Divide the non-core code into multiple consecutive sub-codes;
[0021] For each segment of the sub-code, calculate the encrypted signature value of the sub-code by using the second encryption signature algorithm to obtain a sub-original encrypted signature value;
[0022] Store the sub-original encrypted signature value in the second storage area.
[0023] Further, based on any one of the above technical solutions or a combination of multiple technical solutions, the second protection strategy further includes: for two adjacent segments of the sub-code, calculate the encrypted signature value of the sub-code by using two different second encryption signature algorithms.
[0024] Further, based on any one of the above technical solutions or a combination of multiple technical solutions, if the usage frequency of the non-core code is not lower than a preset first frequency value, then the second encryption signature algorithm adopts the FNV-1 algorithm;
[0025] If the usage frequency of the non-core code is lower than a preset first frequency value, the second encryption signature algorithm adopts the CRC-32 algorithm.
[0026] Further, based on any one of the foregoing technical solutions or a combination of multiple technical solutions, the second encryption signature algorithm includes the CRC-32 algorithm and the FNV-1 algorithm.
[0027] Further, based on any one of the foregoing technical solutions or a combination of multiple technical solutions, the second protection strategy further includes verifying the security of the non-core code in the following manner:
[0028] Each time the non-core code is loaded or periodically, the second encryption signature algorithm is used to recalculate the encryption signature value of the non-core code to obtain the current second encryption signature value;
[0029] Verify the consistency between the current second encryption signature value and the original second encryption signature value. If they are consistent, it is determined that the non-core code is secure; if not, it is determined that the non-core code is insecure.
[0030] Further, based on any one of the foregoing technical solutions or a combination of multiple technical solutions, the second storage area includes RAM, flash memory, HDD, and SSD; and / or,
[0031] The dynamic loading module includes multiple sub-modules, each sub-module is configured to store and / or load different non-core codes, and the second encryption signature algorithms adopted by each sub-module are the same or different.
[0032] Further, based on any one of the foregoing technical solutions or a combination of multiple technical solutions, the first protection strategy further includes verifying the security of the core code in the following manner:
[0033] Use the first symmetric encryption algorithm to decrypt the original verification code to obtain the decrypted signature data;
[0034] Use the first encryption signature algorithm to calculate the encryption signature value of the current core code to obtain the current first encryption signature value;
[0035] Use the RSA public key to verify the decrypted signature data, and verify the consistency between the current first encryption signature value and the original first encryption signature value. If both verifications pass, it is determined that the current core code is secure; otherwise, it is determined that the current core code is insecure.
[0036] Further, based on any one of the foregoing technical solutions or a combination of multiple technical solutions, the first storage area includes ROM, HSM, and TPM chips; and / or,
[0037] The first encryption signature algorithm includes the SHA-256 algorithm, the SHA-3 algorithm, the SM3 algorithm, and the BLAKE2 algorithm; and / or,
[0038] The first symmetric encryption algorithm includes the AES-256 algorithm, the SM4-128 algorithm, the Camellia-256 algorithm, and the Serpent-256 algorithm.
[0039] According to another aspect of the present invention, the present invention provides a method for protecting system code based on a hybrid algorithm, including the following steps:
[0040] Determine the core code in the system code, and protect the core code using a first protection strategy, including:
[0041] Calculate the encrypted signature value of the core code using the first encryption signature algorithm to obtain the original first encrypted signature value;
[0042] Perform a digital signature on the original first encrypted signature value using the RSA private key to generate the original signature data;
[0043] Encrypt the original signature data using the first symmetric encryption algorithm to generate an encrypted original check code;
[0044] Store the original check code in a first storage area, and the first storage area is a secure storage area.
[0045] Further, based on any one of the foregoing technical solutions or a combination of multiple technical solutions, the method for protecting system code based on a hybrid algorithm further includes the following steps:
[0046] Determine the non-core code in the system code, the security level of the core code is higher than that of the non-core code, and protect the non-core code using a second protection strategy, including:
[0047] Calculate the encrypted signature value of the non-core code using a second encryption signature algorithm to obtain the original second encrypted signature value, and the collision resistance of the first encryption signature algorithm is stronger than that of the second encryption signature algorithm;
[0048] Store the original second encrypted signature value in a second storage area, and the security level of the first storage area is higher than that of the second storage area.
[0049] Further, based on any one of the foregoing technical solutions or a combination of multiple technical solutions, the second protection strategy further includes verifying the security of the non-core code in the following manner:
[0050] Each time the non-core code is loaded, the second encryption signature algorithm is used to calculate the encryption signature value of the non-core code to obtain the second encryption signature value;
[0051] Verify the consistency between the second encryption signature value and the original second encryption signature value. If they are consistent, it is determined that the non-core code is secure; if not, it is determined that the non-core code is insecure.
[0052] Further, based on any one of the foregoing technical solutions or a combination of multiple technical solutions, the first protection strategy further includes verifying the security of the core code in the following manner:
[0053] Use the first symmetric encryption algorithm to decrypt the original verification code to obtain the decrypted signature data;
[0054] Use the first encryption signature algorithm to calculate the encryption signature value of the current core code to obtain the current first encryption signature value;
[0055] Use the RSA public key to verify the decrypted signature data, and verify the consistency between the current first encryption signature value and the original first encryption signature value. If both verifications pass, it is determined that the current core code is secure; otherwise, it is determined that the current core code is insecure.
[0056] According to another aspect of the present invention, there is provided a BIOS, which is configured to be based on the system protected by the hybrid algorithm as described in any one of the foregoing technical solutions or a combination of multiple technical solutions.
[0057] According to another aspect of the present invention, there is provided a computer, including the system protected by the hybrid algorithm as described in any one of the foregoing technical solutions or a combination of multiple technical solutions.
[0058] The beneficial effects brought by the technical solutions provided by the present invention are as follows:
[0059] a. The system protected by the hybrid algorithm provided by the present invention calculates the encryption signature value of the core code of the system by using the first encryption signature algorithm with strong collision resistance, and combines the RSA digital signature and the first symmetric encryption algorithm to form a multi-level protection mechanism for the core code, which can enhance the collision resistance of the encryption signature verification, effectively prevent the threat of encryption signature collision attacks or replacement of legitimate encryption signature values, and thus avoid the core code being tampered with or replaced during storage and loading, significantly enhancing the security of the system;
[0060] b. By dividing the system code into core code and non-core code, the present invention adopts a second encryption signature algorithm with lower computational complexity for the non-core code, and dynamically selects a suitable second encryption signature algorithm according to the code usage frequency, reducing the computational complexity of the signature verification process for the non-core code and lowering the computational overhead of its verification process, which is particularly suitable for systems sensitive to startup time;
[0061] c. By adopting different second encryption signature algorithms for multiple sub-codes of the non-core code and using different lightweight encryption algorithms for adjacent sub-codes for encryption, the present invention can further improve the overall security of the system while ensuring system efficiency, and can also reduce the diffusion range and diffusion speed of the attacked object even if some non-core code is attacked;
[0062] d. Through the division of core code and non-core code and the adoption of protection strategies with different security levels for different codes, the present invention takes into account system performance while ensuring system security. In particular, a lightweight verification mechanism is adopted for non-core code with high usage frequency, improving the overall efficiency of the system and achieving a balance between system security and performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0064] Figure 1 A flowchart of the encryption protection process for core code provided by an exemplary embodiment of the present invention;
[0065] Figure 2 A flowchart of the verification process for core code provided by an exemplary embodiment of the present invention;
[0066] Figure 3 A schematic diagram of the partition of system code provided by an exemplary embodiment of the present invention;
[0067] Figure 4 A flowchart of the encryption protection process for non-core code provided by an exemplary embodiment of the present invention;
[0068] Figure 5 A flowchart of the encryption protection process for non-core code based on usage frequency provided by an exemplary embodiment of the present invention;
[0069] Figure 6Flowchart of the encryption protection process for non-core code that takes into account lightweight and high security provided for an exemplary embodiment of the present invention;
[0070] Figure 7 Flowchart of the verification process for non-core code provided for an exemplary embodiment of the present invention. Detailed implementation manners
[0071] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0072] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment comprising a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.
[0073] In an embodiment of the present invention, a system protected by a hybrid algorithm is provided, which includes a core code module, and the core code module is configured to store and / or load the core code of the system;
[0074] See Figure 1 , and a first protection strategy is adopted to protect the core code, and the first protection strategy includes:
[0075] Calculate the encrypted signature value of the core code using a first encryption signature algorithm to obtain the original first encrypted signature value;
[0076] Perform a digital signature on the original first encrypted signature value using an RSA private key to generate the original signature data;
[0077] Encrypt the original signature data using a first symmetric encryption algorithm to generate an encrypted original verification code;
[0078] Store the original first encrypted signature value and the original check code in a first storage area, which is a secure storage area.
[0079] Among them, the first encryption signature algorithm is an encryption signature algorithm with strong collision resistance, such as algorithms like SHA-256, SHA-3, SM3, and BLAKE2. Preferably, the first encryption signature algorithm uses SHA-256, and calculates the encrypted signature value of the core code using SHA-256 to generate a unique code digest set, which is the original first encrypted signature value.
[0080] SHA-256 is currently a generally recognized encryption signature algorithm with strong collision resistance, which can effectively prevent the code from being maliciously tampered with. Because the encrypted signature value it generates is unique, and the probability of collision (that is, two different inputs generate the same encrypted signature value) is extremely low. Calculate the encrypted signature value of the core code using SHA-256 to generate a unique code digest, so that the core code can be verified in subsequent steps. If any tampering occurs to the core code, its encrypted signature value will change, which is convenient for detection.
[0081] RSA is an asymmetric encryption algorithm, which uses a public-private key pair for encryption and decryption. The private key is used to generate a signature, and the public key is used to verify the authenticity of the signature. Select the RSA private key to perform a digital signature on the original signature data to generate a digital signature data, which is the original signature data. The integrity and source of the core code can be verified through the original signature data. During the verification process, use the public key to decrypt the signature data to confirm that the code has not been tampered with and is indeed signed by the legitimate private key holder, thereby ensuring that the code has not been tampered with by a third party.
[0082] The first symmetric encryption algorithm uses algorithms with high security levels such as AES-256, SM4-128, Camellia-256, and Serpent-256. Preferably, AES-256 is used to encrypt the original signature data to generate the original check code.
[0083] AES (Advanced Encryption Standard) is a symmetric encryption algorithm, where the 256-bit key provides extremely high encryption strength. Using the AES-256 encryption algorithm to encrypt the original signature data can prevent the encrypted signature data from being accessed or tampered with by unauthorized third parties. The encrypted signature data, which is the original check code, can provide higher security during storage. Even if an attacker obtains the stored content, they cannot directly use or modify the signature.
[0084] Specifically, the original first encrypted signature value and the original check code are stored in a secure storage area. In the computer field, the secure storage area refers to a storage area protected by hardware. The encrypted original check code (i.e., the encrypted signature data) and the original first encrypted signature value are stored in a hardware-protected area. For example, a dedicated hardware security module (HSM), read-only memory (ROM), or TPM chip or other protected storage area is used. These areas can prevent unauthorized access and can only be read and verified by the system at startup. The encrypted check code stored in the hardware-protected area ensures that even if an attacker obtains the storage device through physical access, it is impossible to easily tamper with or modify the signature data of the code.
[0085] In this embodiment, the first protection policy further includes verifying the security of the core code in the following manner:
[0086] Decrypt the original check code using the first symmetric encryption algorithm to obtain the decrypted signature data;
[0087] Calculate the encrypted signature value of the current core code using the first encrypted signature algorithm to obtain the current first encrypted signature value;
[0088] Verify the decrypted signature data using the RSA public key, and verify the consistency between the current first encrypted signature value and the original first encrypted signature value. If both verifications pass, it is determined that the current core code is secure; otherwise, it is determined that the current core code is insecure.
[0089] See Figure 2 , the verification process for the core code is as follows: When the system starts up, first, the encrypted signature data, that is, the original check code, is read from the hardware-protected area, i.e., the first storage area, and decrypted using AES. Subsequently, the system verifies the decrypted signature data using the RSA public key and verifies the consistency between the encrypted signature value of the current core code and the original first encrypted signature value. If both double verifications pass, it proves that the core code has not been tampered with, and the system continues to start up; if they are inconsistent, the system interrupts the startup and gives a security warning.
[0090] For example, for a server, its BIOS core code is responsible for initializing the hardware and loading the operating system. The specific protection implementation process for the core code in this system is as follows.
[0091] Core code (such as hardware initialization code): This part of the code will perform system hardware initialization operations, including the detection and configuration of devices such as the CPU, memory, hard disk, and graphics card. In order to ensure that this part of the code has not been tampered with at startup, the SHA-256 algorithm is first used to calculate the SHA-256 encrypted signature value of the code. The calculated SHA-256 encrypted signature value is digitally signed with the RSA private key to generate a digital signature data. At this time, the RSA signature data guarantees the source and integrity of the code, and any unauthorized modification will cause the signature verification to fail. The generated digital signature data is encrypted using the AES-256 algorithm. The encrypted signature data is stored in a protected storage area, such as a hardware security module (HSM). This storage area can only be accessed by authorized operating systems or hardware to prevent illegal access.
[0092] During the verification process, after the system loads the core code, it will use a strong anti-collision encryption signature algorithm (such as SHA-256) to recalculate the encryption signature value of the currently loaded code. When recalculating the encryption signature value, the SHA-256 encryption signature algorithm ensures that the generated encryption signature value is unique, and any minor modification will result in a huge change in the encryption signature value, which is easy to detect.
[0093] The decrypted digital signature is verified by the RSA public key. The digital signature is generated by the private key, and the public key is used to verify the validity of the signature. Check whether the original first digital signature value matches the recalculated encrypted signature value. If they match, it means that the source of the core code is reliable and has not been tampered with. If the digital signature cannot be verified, it means that the integrity of the core code is threatened, the system will stop starting and trigger a security warning. Through digital signature and public key verification, the system can confirm whether the loaded code comes from a trusted source and ensure that its content has not been tampered with during storage. Digital signature verification can effectively prevent malware from compromising system security by replacing core code and ensure startup security.
[0094] Countermeasures for verification failure: (1) System interruption startup. If the integrity check of the core code fails, the system will immediately interrupt the startup process; at this time, the system will not continue to load the operating system or other modules to prevent the execution of any malicious code or damaged code. (2) Security warning The system will trigger a security warning to inform the user or administrator that the code integrity check has failed. The warning content usually describes in detail the reason for the verification failure (such as signature mismatch, inconsistent encryption signature value, etc.) and requires the administrator to take further security measures. (3) Prevent damaged code from running. By interrupting the startup and displaying warnings, the system effectively prevents damaged or tampered core code from running. At this time, the administrator can check the system log, perform repair operations, or reinstall the system (such as BIOS) code to ensure system security.
[0095] In one embodiment of the present invention, the system protected by the hybrid algorithm further includes a dynamic loading module, which is configured to store and / or load non-core code of the system, and the security level of the non-core code is lower than that of the core code.
[0096] Protect the non-core code using a second protection strategy, see Figure 4 , and the second protection strategy includes:
[0097] Calculate the encrypted signature value of the non-core code using a second encrypted signature algorithm to obtain the original second encrypted signature value. The collision resistance of the first encrypted signature algorithm is stronger than that of the second encrypted signature algorithm; the second encrypted signature algorithm is a lightweight encryption algorithm, and specifically, CRC-32 or FNV-1 can be used, etc.;
[0098] Store the original second encrypted signature value in a second storage area. The security level of the first storage area is higher than that of the second storage area. The second storage area can use a non-read-only storage unit, and RAM, flash memory, HDD, SSD, etc. can be used.
[0099] See Figure 7 , and the second protection strategy further includes verifying the security of the non-core code in the following way: each time the non-core code is loaded or periodically, recalculate the encrypted signature value of the non-core code using the second encrypted signature algorithm to obtain the current second encrypted signature value. Verify the consistency between the current second encrypted signature value and the original second encrypted signature value. If they are consistent, determine that the non-core code is secure; if they are inconsistent, determine that the non-core code is insecure.
[0100] The dynamic loading module is usually a driver, an extended function module, etc. in the system, and is required to be loaded and executed in the later stage of startup. If a computationally complex encrypted signature algorithm is used, it may cause the module loading speed to be too slow and affect the system performance. Therefore, selecting lightweight algorithms such as CRC-32 and FNV-1 can provide fast and effective integrity verification. These algorithms can provide fast integrity verification without significantly affecting the system performance, and are suitable for dynamically loaded modules that are frequently loaded and updated. Some embedded systems or low-power devices have limited computing resources, and using complex encryption algorithms will cause the system to be overloaded. Therefore, using lightweight algorithms such as CRC-32 and FNV-1 can ensure the security of the module while maintaining reasonable computing efficiency.
[0101] The following uses a specific embodiment to illustrate the protection and verification process of dynamically loaded modules. Assume that a server runs on an operating system, which contains multiple dynamically loaded modules, such as network card drivers, graphics card drivers, and other peripheral driver programs. These modules are dynamically loaded when the operating system starts and perform corresponding hardware initialization and resource configuration tasks later.
[0102] Load a dynamically loaded module for the first time and calculate the second encrypted signature value of its corresponding non-core code: When the system first loads the network card driver program net_driver.dll, use the CRC-32 algorithm to calculate the encrypted signature value of the driver program code. For example, the calculated encrypted signature value is C1F9B01F. This encrypted signature value is stored in the persistent storage of the system as the unique identifier of the driver program.
[0103] Perform encrypted signature verification when dynamically loading a module: When the operating system loads the network card driver program again, the system calculates the CRC-32 encrypted signature value of the net_driver.dll file and compares it with the original encrypted signature value. Assume that the calculated encrypted signature value is the same as the original value (C1F9B01F), which proves that the driver program has not been tampered with, and the system continues to load the driver program.
[0104] Assume that net_driver.dll is tampered with during a certain loading, and the recalculated encrypted signature value is D2A8C041, which does not match the original encrypted signature value (C1F9B01F). Then the system detects that the encrypted signature values are inconsistent, triggers a security warning, and refuses to load the module to prevent potential security threats to the system.
[0105] Legally update the module and update the encrypted signature value: The system administrator updates the version of the network card driver program, and the updated driver file net_driver_v2.dll is loaded. The system recalculates the encrypted signature value of this file and updates the stored encrypted signature value to ensure that the new version of the driver program can pass the integrity check.
[0106] In this embodiment, according to the different security requirement levels of the code in the system, the system code is divided into core code and non-core code, and two different protection strategies are adopted.
[0107] Such as Figure 3As shown, taking the BIOS as an example, the BIOS code is classified. According to its importance and functional characteristics, the BIOS code is divided into core code and non-core code. The core code includes the key parts of system startup and hardware initialization, which requires the highest level of security protection; the non-core code is the functional extension part of the system, and a balance needs to be achieved between security and performance. According to different code regions, corresponding security policies are formulated. Strong security measures are adopted for the core code, and a lightweight verification mechanism is adopted for the non-core code in the dynamically loaded modules.
[0108] The core code module refers to the key part that needs to ensure the normal startup of the system and provide a stable operating environment for the operating system in the early stage of system startup. Specifically, the functions of the core code in the core code module usually include:
[0109] Hardware initialization: Responsible for the initialization of computer hardware, including the detection and configuration of hardware such as CPU, memory, hard disk, graphics card, input and output devices, etc. This is the basis for ensuring the normal operation of the computer;
[0110] Boot the operating system: The core code is responsible for booting the operating system. It will load the startup image of the operating system through the boot manager to ensure that the system can smoothly enter the operating system environment;
[0111] BIOS configuration management: Includes managing user-defined BIOS settings, such as date and time, startup order, etc., to ensure that the user-defined configuration information can be correctly applied;
[0112] These functions are crucial for the security of the computer system. If an attacker tampers with any core code, it may implant malicious code during startup or prevent the loading of the operating system, resulting in the system being unable to work properly. Therefore, this part of the code must be strictly protected to ensure that it is not tampered with during the entire system operation process.
[0113] The dynamically loaded module refers to those auxiliary function code modules that are loaded in the later stage of system startup and executed as needed. Specifically, the functions of the dynamically loaded module usually include:
[0114] Driver: Some hardware drivers, such as network card drivers, graphics card drivers, etc. These drivers are usually loaded after the operating system starts and are dynamically loaded as needed;
[0115] System extension functions: Some non-core system function extensions, such as debugging tools, log collection modules, security check tools, etc. These function modules may be dynamically loaded during operation;
[0116] Firmware update and configuration tools: Some BIOS support function modules for updating firmware or modifying configurations after the operating system starts.
[0117] Compared with the core code module, the dynamically loaded module has less impact on the system security. Although these modules need to ensure the integrity of data and prevent being tampered with, their security requirements are not as high as those of the core code, and they mainly focus on performance and flexibility. Therefore, a lightweight verification mechanism is usually adopted for this part of the modules to ensure that the system performance is not overly affected.
[0118] CRC-32 has great advantages in terms of performance and computational efficiency. CRC-32 is a widely used cyclic redundancy check algorithm that can quickly calculate the encrypted signature value of data. Although its collision resistance is weak, for dynamically loaded modules, the calculation speed and efficiency are more critical indicators. Therefore, CRC-32 is suitable for verifying the integrity of these modules. For example, when the system loads a dynamic module (such as a hardware driver or a system extension module), it is necessary to verify a network card driver net_driver.dll. The system will calculate the CRC-32 encrypted signature value for this file to generate a 32-bit encrypted signature value as the "fingerprint" of this module.
[0119] Each time a dynamically loaded module is loaded, the system will recalculate the encrypted signature value of this module. The recalculated encrypted signature value will be compared with the stored original CRC-32 encrypted signature value. If the two encrypted signature values are the same, it indicates that this module has not been tampered with, and the system continues to load the module.
[0120] FNV-1 is another lightweight encrypted signature algorithm. It is simpler than CRC-32, can provide fast encrypted signature calculation, and performs well when dealing with smaller modules. FNV-1 can achieve efficient encrypted signature calculation in a memory-constrained environment and is suitable for small modules that require quick verification. For smaller modules with a relatively high usage frequency (such as the driver of a certain device), the FNV-1 algorithm can be used to calculate the encrypted signature value of this module. Similarly, the encrypted signature value recalculated using the FNV-1 algorithm will be compared with the stored encrypted signature value to ensure the integrity of the module.
[0121] If the recalculated encrypted signature value does not match the stored encrypted signature value, the system will consider that the module may have been tampered with, and then trigger an alarm or refuse to load this module to prevent the running of malicious code. If the module is legally updated, the new version will recalculate the encrypted signature value and update the stored encrypted signature value. In this way, the system can always verify the integrity of the module.
[0122] Therefore, in an embodiment of the present invention, refer to Figure 5If the usage frequency of the non-core code is not lower than the preset first frequency value, the second encryption signature algorithm adopts the FNV-1 algorithm. If the usage frequency of the non-core code is lower than the preset first frequency value, the second encryption signature algorithm adopts the CRC-32 algorithm. The present invention divides the system code into core code and non-core code, adopts a second encryption signature algorithm with lower computational complexity for the non-core code, and dynamically selects a suitable algorithm according to the frequency of code usage, thereby reducing the computational complexity of the signature verification process, reducing the computational overhead of the verification process, and improving the verification efficiency. It is particularly suitable for systems that are sensitive to startup time.
[0123] In one embodiment of the present invention, see Figure 6 , the second protection strategy also includes: dividing the non-core code into multiple continuous sub-codes; for each sub-code, using the second encryption signature algorithm to calculate the encryption signature value of the sub-code to obtain the sub-original encryption signature value; storing the sub-original encryption signature value in the second storage area. More preferably, for two adjacent sub-codes, two different second encryption signature algorithms are used to calculate the encryption signature value of the sub-code. For example, for two adjacent sub-codes, one sub-code uses the CRC-32 algorithm and the other sub-code uses the FNV-1 algorithm. Based on this approach, while achieving lightweight protection for the dynamically loaded module, the security of the dynamically loaded module can be further improved, and a balance between system security and performance can be achieved.
[0124] In one embodiment of the present invention, a system code protection method based on a hybrid algorithm is provided. Figure 1 , Figure 2 , Figure 4 and Figure 7 , the method comprises the following steps.
[0125] The core code and non-core code in the system code are determined, the security level of the core code is higher than the security level of the non-core code, and the non-core code is protected by adopting a second protection strategy.
[0126] The core code is protected by a first protection strategy, including: using a first encryption signature algorithm to calculate the encryption signature value of the core code to obtain an original first encryption signature value; using an RSA private key to digitally sign the original first encryption signature value to generate original signature data; using a first symmetric encryption algorithm to encrypt the original signature data to generate an encrypted original verification code; and storing the original verification code in a first storage area, which is a secure storage area.
[0127] Verify the security of the core code in the following manner: decrypt the original verification code using the first symmetric encryption algorithm to obtain the decrypted signature data; calculate the encrypted signature value of the current core code using the first encryption signature algorithm to obtain the current first encrypted signature value; verify the decrypted signature data using the RSA public key, and verify the consistency between the current first encrypted signature value and the original first encrypted signature value. If both verifications pass, determine that the current core code is secure; otherwise, determine that the current core code is insecure.
[0128] Calculate the encrypted signature value of the non-core code using the second encryption signature algorithm to obtain the original second encrypted signature value. The first encryption signature algorithm has stronger collision resistance than the second encryption signature algorithm. Store the original second encrypted signature value in the second storage area. The security level of the first storage area is higher than that of the second storage area.
[0129] Protect the non-core code using the second protection strategy, further including: each time the non-core code is loaded, calculate the encrypted signature value of the non-core code using the second encryption signature algorithm to obtain the second encrypted signature value; verify the consistency between the second encrypted signature value and the original second encrypted signature value. If they are consistent, determine that the non-core code is secure; if they are inconsistent, determine that the non-core code is insecure.
[0130] In an embodiment of the present invention, a BIOS is provided. The BIOS is configured to be based on the system protected by the hybrid algorithm as described in any one or more combinations of the above embodiments.
[0131] In an embodiment of the present invention, a computer is provided, including the system protected by the hybrid algorithm as described in any one or more combinations of the above embodiments.
[0132] It should be noted that the system code protection method, BIOS, and computer embodiments provided by the present invention based on the hybrid algorithm have the same inventive concept as the system code protection method embodiments based on the hybrid algorithm. The entire content of the system code protection method embodiments based on the hybrid algorithm is incorporated into the system code protection method, BIOS, and computer embodiments based on the hybrid algorithm by introduction.
[0133] The BIOS code integrity protection method based on the hybrid algorithm proposed in this technical solution has significant security and performance advantages and has broad application prospects in multiple fields. First, in the field of computer system security, this solution can effectively prevent the BIOS code from being tampered with or replaced, improving the security of the system startup process. With the increasing threats of hardware-level attacks and firmware malware, protecting the integrity of low-level system codes such as BIOS has become crucial. This technical solution provides a solution that balances security and performance and is applicable to computing environments that require high security, such as personal computers, servers, and large data centers.
[0134] Secondly, in the fields of industrial control and critical infrastructure, such as industries like power, transportation, and energy, the reliability and security of the system are of utmost importance. This technical solution can be used to protect the firmware codes of industrial control systems, prevent security accidents caused by code tampering, and ensure the stable operation of the system. In addition, in fields with extremely high security requirements, such as finance, healthcare, and government agencies, this solution can provide a high level of system code integrity protection, prevent potential security vulnerabilities from being exploited, and protect the security of sensitive data and critical services. Finally, with the popularization of cloud computing and virtualization technologies, the security of the hypervisor and firmware layer in virtualization environments has also received increasing attention. This technical solution can be applied to the protection of firmware and system codes in virtualized environments, enhancing the security of cloud environments.
[0135] In summary, while ensuring high security, this technical solution takes into account system performance, solving the problems of large computational overhead and insufficient anti-attack ability in existing technologies. It has broad application prospects, can meet the needs of various industries for system code integrity protection, and has significant market value and promotional significance.
[0136] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0137] The above are only specific embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A system protected by a hybrid algorithm, characterized in that, It includes a core code module and a dynamic loading module. The core code module is configured to store and / or load the core code of the system. The dynamic loading module is configured to store and / or load the non-core code of the system, and the security level of the non-core code is lower than that of the core code; The core code is protected by a first protection strategy, and the first protection strategy includes: Using a first encryption signature algorithm to calculate the encryption signature value of the core code to obtain the original first encryption signature value; Using an RSA private key to digitally sign the original first encryption signature value to generate original signature data; Using a first symmetric encryption algorithm to encrypt the original signature data to generate an encrypted original check code; Storing the original first encryption signature value and the original check code in a first storage area, and the first storage area is a secure storage area; The non-core code is protected by a second protection strategy, and the second protection strategy includes: Using a second encryption signature algorithm to calculate the encryption signature value of the non-core code to obtain the original second encryption signature value. The collision resistance of the first encryption signature algorithm is stronger than that of the second encryption signature algorithm; if the usage frequency of the non-core code is not lower than a preset first frequency value, the second encryption signature algorithm uses the FNV-1 algorithm; if the usage frequency of the non-core code is lower than the preset first frequency value, the second encryption signature algorithm uses the CRC-32 algorithm; Storing the original second encryption signature value in a second storage area, and the security level of the first storage area is higher than that of the second storage area.
2. The system protected based on the hybrid algorithm according to claim 1, wherein The second protection strategy further includes: Dividing the non-core code into multiple consecutive sub-codes; For each segment of the sub-code, using a second encryption signature algorithm to calculate the encryption signature value of the sub-code to obtain a sub-original encryption signature value; Storing the sub-original encryption signature value in the second storage area.
3. The system protected based on the hybrid algorithm according to claim 2, wherein The second protection strategy further includes: for two adjacent segments of the sub-code, using two different second encryption signature algorithms to calculate the encryption signature value of the sub-code.
4. The system protected based on the hybrid algorithm according to claim 1, wherein The second protection strategy further includes verifying the security of the non-core code in the following manner: Each time the non-core code is loaded or periodically, using the second encryption signature algorithm to recalculate the encryption signature value of the non-core code to obtain the current second encryption signature value; Verifying the consistency between the current second encryption signature value and the original second encryption signature value. If they are consistent, it is determined that the non-core code is secure; If they are inconsistent, it is determined that the non-core code is insecure.
5. The system protected based on the hybrid algorithm according to claim 1, wherein The second storage area includes RAM, flash memory, HDD, and SSD; and / or, The dynamic loading module includes multiple sub-modules. Each sub-module is configured to store and / or load different non-core codes, and the second encryption signature algorithms used by each of the sub-modules are the same or different.
6. The system protected based on the hybrid algorithm according to claim 1, wherein The first protection strategy further includes verifying the security of the core code in the following manner: Using the first symmetric encryption algorithm to decrypt the original check code to obtain the decrypted signature data; Calculate the encrypted signature value of the current core code using the first encryption signature algorithm to obtain the current first encrypted signature value; Verify the decrypted signature data using the RSA public key, and verify the consistency between the current first encrypted signature value and the original first encrypted signature value. If both verifications pass, determine that the current core code is secure; Otherwise, determine that the current core code is insecure.
7. The system protected based on the hybrid algorithm according to claim 1, wherein, The first storage area includes a ROM, an HSM, and a TPM chip; and / or, The first encryption signature algorithm includes the SHA-256 algorithm, the SHA-3 algorithm, the SM3 algorithm, and the BLAKE2 algorithm; and / or, The first symmetric encryption algorithm includes the AES-256 algorithm, the SM4-128 algorithm, the Camellia-256 algorithm, and the Serpent-256 algorithm.
8. A system code protection method based on a hybrid algorithm, characterized in that Include the following steps: Determine the core code in the system code, and protect the core code using a first protection strategy, including: Calculate the encrypted signature value of the core code using the first encryption signature algorithm to obtain the original first encrypted signature value; Perform a digital signature on the original first encrypted signature value using the RSA private key to generate original signature data; Encrypt the original signature data using the first symmetric encryption algorithm to generate an encrypted original check code; Store the original check code in the first storage area, and the first storage area is a secure storage area; Determine the non-core code in the system code. The security level of the core code is higher than that of the non-core code, and protect the non-core code using a second protection strategy, including: Calculate the encrypted signature value of the non-core code using the second encryption signature algorithm to obtain the original second encrypted signature value. The collision resistance of the first encryption signature algorithm is stronger than that of the second encryption signature algorithm; if the usage frequency of the non-core code is not lower than a preset first frequency value, the second encryption signature algorithm uses the FNV-1 algorithm; if the usage frequency of the non-core code is lower than the preset first frequency value, the second encryption signature algorithm uses the CRC-32 algorithm; Store the original second encrypted signature value in the second storage area, and the security level of the first storage area is higher than that of the second storage area.
9. The method for protecting system code based on a hybrid algorithm according to claim 8, wherein The second protection strategy also includes verifying the security of the non-core code in the following way: Each time the non-core code is loaded, calculate the encrypted signature value of the non-core code using the second encryption signature algorithm to obtain the second encrypted signature value; Verify the consistency between the second encrypted signature value and the original second encrypted signature value. If they are consistent, determine that the non-core code is secure; If they are inconsistent, determine that the non-core code is insecure.
10. The method for protecting system code based on a hybrid algorithm according to claim 8, characterized in that, The first protection strategy also includes verifying the security of the core code in the following way: Decrypt the original check code using the first symmetric encryption algorithm to obtain the decrypted signature data; Calculate the encrypted signature value of the current core code using the first encryption signature algorithm to obtain the current first encrypted signature value; Verify the decrypted signature data using the RSA public key, and verify the consistency between the current first encrypted signature value and the original first encrypted signature value. If both verifications pass, determine that the current core code is secure; Otherwise, determine that the current core code is insecure.
11. A BIOS, characterized in that, The BIOS is configured to be a system protected based on the hybrid algorithm according to any one of claims 1 to 7.
12. A computer, characterized in that, Includes a system protected based on the hybrid algorithm according to any one of claims 1 to 7.
Citation Information
Patent Citations
Signature and verification method based on hybrid encryption algorithm in cloud storage
CN107070948A
A method and apparatus for protecting codes using a random password
CN109145533A
Android platform message-driven core code integrity detection system and Android platform message-driven core code integrity detection method
CN109981283A
Data fingerprint generation method and device based on block chain and storage medium
CN114880697A