Baseboard management controller firmware encryption system based on FPGA (Field Programmable Gate Array)

By adopting an FPGA-based encryption system in the substrate management controller, the FPGA sequence number is used to generate the encryption algorithm key, encrypt and decrypt the firmware data, and through integrity verification, the problem of vulnerability to the existing substrate management controller firmware encryption methods is solved, achieving higher security and efficiency.

CN119989428AActive Publication Date: 2025-05-13709TH RESEARCH INSTITUTE CHINA STATE SHIPBUILDING CORP LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510056480.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-05-13
Estimated Expiration
2045-01-14

AI Technical Summary

Technical Problem

The existing substrate management controller firmware encryption methods are vulnerable to attacks and are difficult to effectively prevent unauthorized access and modification.

Method used

The encryption system based on FPGA is adopted, including an encryption module, a decryption module and a firmware storage module. The FPGA serial number is used to generate the encryption algorithm key, and the firmware data is encrypted and decrypted in combination with the preset encryption algorithm, and the data security is ensured through integrity verification.

Benefits of technology

By isolating and encrypting firmware data at the physical level, the security of the firmware of the substrate management controller is improved, the risk of being cracked and attacked is reduced, while ensuring the efficiency and flexibility of firmware upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989428A_ABST
    Figure CN119989428A_ABST
Patent Text Reader

Abstract

The invention discloses a substrate management controller firmware encryption system based on an FPGA, and belongs to the technical field of circuit encryption. The device comprises an FPGA which is in communication connection with a substrate management controller. The FPGA comprises an encryption module, a decryption module and a firmware storage module, and the encryption module is used for reading firmware data and encrypting the firmware data by using a preset encryption algorithm in combination with a serial number of the FPGA; the firmware storage module is used for storing encrypted firmware data; and the decryption module is used for decrypting the encrypted firmware data by adopting a preset decryption algorithm. According to the scheme, the technical problem that an existing software-level encryption method is easily attacked is solved in a hardware isolation encryption mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of circuit encryption technology, and more specifically, relates to a baseboard management controller firmware encryption system based on FPGA. Background Art

[0002] In modern computer systems, baseboard management controllers are widely used for server status monitoring. Baseboard management controllers usually contain a firmware that handles server system management tasks, reads sensor data such as temperature in real time, and performs remote control functions. Therefore, the security and integrity of the baseboard management controller firmware are very important for the stable and safe operation of the server system.

[0003] Traditionally, the security of baseboard management controller firmware is mainly achieved through software-level encryption, signature technology, etc. However, these methods are vulnerable to malicious attacks and tampering, so a higher level of security protection is required to prevent unauthorized access and modification of the baseboard management controller firmware. Summary of the invention

[0004] In view of the above defects or improvement needs of the prior art, the present application provides a baseboard management controller firmware encryption system based on FPGA, which aims to solve the technical problem that the existing baseboard management controller firmware encryption method is vulnerable to attack.

[0005] To achieve the above objectives, in a first aspect, the present application provides a baseboard management controller firmware encryption system based on FPGA, including an FPGA that is communicatively connected to the baseboard management controller; the FPGA includes an encryption module, a decryption module and a firmware storage module, wherein:

[0006] An encryption module, used to encrypt firmware data using a preset encryption algorithm combined with the serial number of the FPGA;

[0007] A firmware storage module, used for storing encrypted firmware data;

[0008] The decryption module is used to read the encrypted firmware data from the firmware storage module and decrypt the encrypted firmware data using a preset decryption algorithm.

[0009] Preferably, in the encryption module, a preset encryption algorithm is used in combination with the serial number of the FPGA to encrypt the firmware data, specifically: a key of the encryption algorithm is generated based on the serial number, and the firmware data is encrypted using the key and the preset encryption algorithm.

[0010] Preferably, in the encryption module, a preset encryption algorithm is used in combination with the serial number of the FPGA to encrypt the firmware data, specifically: parameters or initial vectors of the preset encryption algorithm are generated based on the serial number, and the preset encryption algorithm is used to encrypt the firmware data.

[0011] Preferably, in the encryption module, the firmware data is encrypted using a preset encryption algorithm in combination with the serial number of the FPGA, specifically: the firmware data is encrypted using a preset encryption algorithm, and the serial number is attached to the encrypted firmware data.

[0012] Preferably, in the encryption module, the firmware data is encrypted using symmetric encryption technology, and the key in the symmetric encryption technology is encrypted using asymmetric encryption technology.

[0013] Preferably, the encryption module includes an encryption algorithm unit and a key management unit; the key management unit is used to generate and manage keys; the encryption algorithm unit is used to obtain keys from the key management unit and encrypt firmware data using a preset encryption algorithm.

[0014] Preferably, it also includes an integrity check module, which is used to perform integrity check on the firmware data before and after encryption. If the integrity check fails, the system's security response mechanism is triggered.

[0015] Preferably, the integrity check module is specifically used to: generate a first check value by combining the firmware data and serial number before encryption, generate a second check value by combining the firmware data and serial number after decryption, compare the first check value and the second check value, and trigger the system's security response mechanism if they are not equal.

[0016] Preferably, it also includes a status monitoring module, which is used to monitor the upload encryption and decryption operations in real time.

[0017] In a second aspect, the present application provides a method for encrypting firmware of a baseboard management controller based on FPGA, the method being applied to any system described in the first aspect, and specifically comprising the following steps:

[0018] Generate two symmetric keys of the symmetric encryption algorithm based on the FPGA serial number, and encrypt one of the symmetric keys using the public key of the asymmetric encryption algorithm;

[0019] After receiving the firmware update instruction, the FPGA reads the firmware data in the baseboard management controller, uses the integrity check technology to generate a first check value for the firmware data; and uses an unencrypted symmetric key to encrypt the firmware data;

[0020] Before the baseboard management controller is started, the FPGA uses the private key of the asymmetric encryption algorithm to decrypt the encrypted symmetric key, and then uses the decrypted symmetric key to decrypt the encrypted firmware data; the decrypted firmware data is subjected to integrity verification technology to generate a second verification value; the first verification value and the second verification value are compared, and if they are the same, the decrypted firmware data is written into the baseboard management controller and started; if they are different, the system's security response mechanism is triggered.

[0021] In general, the above technical solutions conceived by this application have the following beneficial effects compared with the prior art:

[0022] (1) In traditional methods, the security protection of baseboard management controller firmware is mainly achieved through software-level encryption and signature technology. This application encrypts the baseboard management controller firmware through FPGA and isolates the firmware data that needs to be protected at the physical level. Therefore, the encryption scheme of this application is more difficult to be cracked and attacked. At the same time, the programmability and high-speed processing capabilities of FPGA are used to ensure the efficiency and flexibility of firmware upgrades.

[0023] (2) The present application integrates the unique serial number of the FPGA into the encryption algorithm, thereby further reducing the impact of software on encryption, increasing the difficulty of cracking the encryption algorithm, and improving the security of firmware encryption.

[0024] (3) This application integrates encryption algorithm and integrity verification to further ensure that firmware data will not be maliciously tampered with. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 It is a structural diagram of a baseboard management controller firmware encryption system based on FPGA provided in an embodiment of the present application.

[0026] Figure 2 This is a flowchart of a baseboard management controller firmware encryption method based on FPGA provided in an embodiment of the present application. DETAILED DESCRIPTION

[0027] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0028] The terms "first" and "second" in the specification and claims herein are used to distinguish different objects rather than to describe a specific order of objects. For example, a first check value and a second check value are used to distinguish different check values ​​rather than to describe a specific order of check values.

[0029] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0030] In the description of the embodiments of the present application, unless otherwise specified, "multiple" means two or more than two. For example, multiple processing units refer to two or more processing units, etc.; multiple elements refer to two or more elements, etc.

[0031] like Figure 1 As shown, a baseboard management controller firmware encryption system based on FPGA is provided in an embodiment of the present application. The baseboard management controller firmware encryption system includes an FPGA that is communicatively connected to the baseboard management controller.

[0032] The FPGA serves as the core of the baseboard management controller firmware data encryption system. The encryption and decryption of the firmware data are all completed in the FPGA, thereby isolating the firmware data that needs to be protected at the physical level, making the firmware data difficult to crack and attack.

[0033] The FPGA includes an encryption module, a decryption module, a firmware storage module, an integrity check module and a status monitoring module. In this embodiment, the FPGA is an FPGA.

[0034] After receiving the firmware update instruction, the integrity check module is started to directly read the firmware data from the firmware memory of the baseboard management controller, and the first check value is generated by combining the firmware data and the serial number of the FPGA.

[0035] The encryption module is then started, and the firmware data is encrypted using a preset encryption algorithm combined with the FPGA serial number.

[0036] In this embodiment, a symmetric encryption algorithm combined with an asymmetric encryption algorithm is selected as the preset encryption algorithm. Specifically, a symmetric encryption algorithm is selected to encrypt firmware data, and an asymmetric encryption algorithm is selected to encrypt the key of the symmetric encryption algorithm.

[0037] The firmware data may also be encrypted using a hash algorithm, a message authentication code algorithm, a digital signature algorithm, or a combination of one or more of the above as a preset encryption algorithm.

[0038] In this embodiment, the firmware data is encrypted using the unique serial number of the FPGA in combination with an encryption algorithm. Specifically, the key of the encryption algorithm is generated based on the unique serial number of the FPGA, and then the firmware data is encrypted using the key, so that the hardware serial number is integrated into the encryption algorithm, thereby further reducing the impact of software on encryption, increasing the difficulty of cracking the encryption algorithm, and improving the security of firmware encryption.

[0039] In this embodiment, a key is first randomly generated, and then the serial number is embedded in the key to generate a new key, and then the new key is used to encrypt the firmware data.

[0040] In this embodiment, it is also optional to input the serial number into a key derivation function to generate a key.

[0041] In this embodiment, it is also optional to generate parameters of a preset encryption algorithm based on the serial number, and use the preset encryption algorithm to encrypt the firmware data.

[0042] In this embodiment, it is also optional to use a preset encryption algorithm to encrypt the firmware data, and append the serial number to the encrypted firmware data. The appending method can be specifically in the form of splicing or insertion, so that new encrypted firmware data is formed.

[0043] In this application, the generated new key is used as the symmetric key of the symmetric encryption algorithm to encrypt the firmware data. At the same time, the public key of the asymmetric encryption algorithm is used to encrypt the symmetric key.

[0044] The encryption module includes an encryption algorithm unit and a key management unit, wherein the key management unit is used to generate and manage keys; in this embodiment, it is used to generate and manage symmetric keys of symmetric encryption algorithms, and public keys and private keys of asymmetric encryption algorithms. All keys are stored in the non-volatile storage area of ​​FPGA to ensure that the keys will not be lost after the FPGA is powered off. The symmetric key before encryption is distributed to the encryption algorithm unit, and the encrypted symmetric key and the private key of the asymmetric key are distributed to the decryption module.

[0045] The encryption algorithm unit is used to obtain a symmetric key from the key management unit and encrypt the firmware data using a preset encryption algorithm.

[0046] The encrypted firmware data is stored in a firmware storage module, which is located in a memory in the FPGA, specifically NAND Flash or NOR Flash.

[0047] The decryption module is used to obtain the encrypted firmware data from the firmware storage module and decrypt the encrypted firmware data using a preset decryption algorithm.

[0048] In this embodiment, the decryption module obtains the private key and the encrypted symmetric key in the asymmetric encryption algorithm from the key management unit, first uses the private key to decrypt the symmetric key, and then uses the decrypted symmetric key to decrypt the encrypted firmware data, and finally obtains the decrypted firmware data.

[0049] The integrity check module generates a second check value by combining the decrypted firmware data and the serial number, and compares the first check value with the second check value. If they are not equal, the system's security response mechanism is triggered. Otherwise, the decrypted firmware data is written to the baseboard management controller.

[0050] After receiving the firmware update instruction, the integrity check module, the encryption module and the firmware storage module are called to encrypt the firmware data in the baseboard management controller memory.

[0051] Each time the baseboard management controller is started, the firmware storage module, decryption module and integrity check module are called to decrypt the encrypted firmware data. After decryption, the firmware data is sent to the baseboard management controller for execution. Thus, the firmware data sent to the baseboard management controller can ensure normal operation and no tampering every time it runs.

[0052] like Figure 2 As shown, the embodiment of the present application also implements a baseboard management controller firmware encryption method based on FPGA, comprising the following steps:

[0053] Before encrypting and decrypting firmware data, the FPGA generates two symmetric keys based on the FPGA serial number in advance, and encrypts one of the symmetric keys using the public key of the asymmetric encryption algorithm.

[0054] After receiving the firmware update instruction, the FPGA reads the firmware data in the baseboard management controller, uses the integrity check technology to generate a first check value for the firmware data; and uses an unencrypted symmetric key to encrypt the firmware data.

[0055] Before starting the baseboard management controller, the FPGA uses the private key of the asymmetric encryption algorithm to decrypt the encrypted symmetric key, and then uses the decrypted symmetric key to decrypt the encrypted firmware data; the decrypted firmware data uses integrity verification technology to generate a second verification value; the first verification value and the second verification value are compared, and if they are the same, the decrypted firmware data is written to the baseboard management controller and the baseboard management controller is started; otherwise, the system's security response mechanism is triggered.

[0056] It should be understood that the various numerical numbers involved in the embodiments of the present application are only used for the convenience of description and are not used to limit the scope of the embodiments of the present application.

[0057] The above content is easily understood by those skilled in the art. The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present application should be included in the protection scope of the present application.

Claims

1. A baseboard management controller firmware encryption system based on FPGA, characterized in that: An FPGA is included which is in communication with a baseboard management controller; the FPGA includes an encryption module, a decryption module and a firmware storage module, wherein: An encryption module, used to encrypt firmware data using a preset encryption algorithm combined with the serial number of the FPGA; A firmware storage module, used for storing encrypted firmware data; The decryption module is used to read the encrypted firmware data from the firmware storage module and decrypt the encrypted firmware data using a preset decryption algorithm.

2. The baseboard management controller firmware encryption system according to claim 1, characterized in that: In the encryption module, the firmware data is encrypted using a preset encryption algorithm in combination with the serial number of the FPGA, specifically: a key of the encryption algorithm is generated based on the serial number, and the firmware data is encrypted using the key and the preset encryption algorithm.

3. The baseboard management controller firmware encryption system according to claim 1, characterized in that: In the encryption module, the firmware data is encrypted using a preset encryption algorithm combined with the serial number of the FPGA, specifically: the parameters or initial vector of the preset encryption algorithm are generated based on the serial number, and the firmware data is encrypted using the preset encryption algorithm.

4. The baseboard management controller firmware encryption system according to claim 1, characterized in that: In the encryption module, the firmware data is encrypted using a preset encryption algorithm in combination with the serial number of the FPGA, specifically: the firmware data is encrypted using a preset encryption algorithm, and the serial number is attached to the encrypted firmware data.

5. The baseboard management controller firmware encryption system according to claim 1, characterized in that: In the encryption module, the firmware data is encrypted using the symmetric encryption technology, and the key in the symmetric encryption technology is encrypted using the asymmetric encryption technology.

6. The baseboard management controller firmware encryption system according to claim 1, characterized in that: The encryption module includes an encryption algorithm unit and a key management unit; the key management unit is used to generate and manage keys; the encryption algorithm unit is used to obtain keys from the key management unit and encrypt firmware data using a preset encryption algorithm.

7. The baseboard management controller firmware encryption system according to claim 1, characterized in that: It also includes an integrity check module, which is used to perform integrity check on the firmware data before and after encryption. If the integrity check fails, the system's security response mechanism is triggered.

8. The baseboard management controller firmware encryption system according to claim 7, characterized in that: The integrity check module is specifically used to: generate a first check value by combining the firmware data and the serial number before encryption, generate a second check value by combining the firmware data and the serial number after decryption, compare the first check value and the second check value, and trigger the system's security response mechanism if they are not equal.

9. The baseboard management controller firmware encryption system according to claim 1, characterized in that: It also includes a status monitoring module, which is used to monitor the upload encryption and decryption operations in real time.

10. A method for encrypting firmware of a baseboard management controller based on FPGA, characterized in that: The method is applied to the system described in any one of claims 1 to 9, and specifically comprises the following steps: Generate two symmetric keys of the symmetric encryption algorithm based on the FPGA serial number, and encrypt one of the symmetric keys using the public key of the asymmetric encryption algorithm; After receiving the firmware update instruction, the FPGA reads the firmware data in the baseboard management controller, uses the integrity check technology to generate a first check value for the firmware data; and uses an unencrypted symmetric key to encrypt the firmware data; Before the baseboard management controller is started, the FPGA uses the private key of the asymmetric encryption algorithm to decrypt the encrypted symmetric key, and then uses the decrypted symmetric key to decrypt the encrypted firmware data; the decrypted firmware data is subjected to integrity verification technology to generate a second verification value; the first verification value and the second verification value are compared, and if they are the same, the decrypted firmware data is written into the baseboard management controller and started; if they are different, the system's security response mechanism is triggered.

Citation Information

Patent Citations

  • Encryption and decryption method for realizing hardware and software binding

    CN101149775A

  • Methods for encrypting and protecting system by combining software and field-programmable gate array (FPGA)

    CN102523088A

  • Partial reconfiguration file encryption method and system, FPGA and readable storage medium

    CN109829325A

  • Data isolation system based on FPGA + ARM

    CN110941862A

  • Mobile medium encryption method and device, equipment and storage medium

    CN116684075A