Identity security authentication method and device
By sending the password and password verification identification code entered by the user to the security chip for verification, the security risks existing in BIOS when verifying the user's identity are solved, and higher security and accuracy are achieved.
Patent Information
- Application Number
- CN202311727176.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-13
- Publication Date
- 2025-06-13
AI Technical Summary
In the prior art, BIOS has security risks when verifying user identity. Attackers can obtain passwords and ciphertexts by monitoring memory changes, resulting in illegal acquisition of BIOS permissions.
By sending the password and password verification identification code entered by the user to the security chip for verification, the password is verified using the high security performance value of the security chip, and the verification result is returned to the BIOS to determine the user's identity security authentication result.
It improves the security of the user identity security authentication process, ensures the accuracy of password verification results, and reduces the risk of BIOS being maliciously attacked.
Smart Images

Figure CN120145348A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer security technologies, and particularly to an identity security authentication method and device. Background Art
[0002] As the basic boot system of a computer, the Basic Input Output System (BIOS) provides the most fundamental and direct hardware settings and controls for the computer.
[0003] The identity authentication function in the BIOS is one of the important security functions of the BIOS. In related technologies, when accessing the BIOS, it is usually necessary to authenticate the user's identity to grant the user corresponding BIOS permissions.
[0004] However, in related technologies, the method of authenticating the user's identity still poses security risks to the BIOS. Summary of the Invention
[0005] Based on this, in view of the above technical problems, it is necessary to provide an identity security authentication method and device to enhance the security of the user identity authentication process.
[0006] In a first aspect, this application provides an identity security authentication method applied to the BIOS. The method includes:
[0007] In response to a password input by a user, send the password and a password verification identification code to a security chip. The password verification identification code is used to instruct the security chip to verify the password; the security performance value of the security chip is higher than that of the BIOS;
[0008] Determine the user's identity security authentication result according to the password verification result sent by the security chip.
[0009] In the technical solution provided by the embodiments of the present application, the BIOS sends the password and the password verification identification code to the security chip in response to the password input by the user, so as to instruct the security chip to verify the password, and then determines the user's identity security authentication result according to the password verification result sent by the security chip. Among them, the security performance value of the security chip is higher than that of the BIOS. In this method, on the basis of obtaining the password input by the user, the BIOS verifies the password through the security chip to obtain the password verification result, and further determines the identity security authentication result. It is equivalent to that in the embodiments of the present application, the password verification process is executed by the security chip. And, the security performance value of the security chip is higher than that of the BIOS. Then, compared with the method of verifying the password through the BIOS, in the embodiments of the present application, the method of verifying the password through the security chip is more secure, and the password verification result obtained by the security chip is also more accurate. On this basis, through the interaction between the BIOS and the security chip, the identity security authentication result determined by the BIOS according to the password verification result is also more accurate.
[0010] In one embodiment, determining the user's identity security authentication result according to the password verification result sent by the security chip includes:
[0011] If the password verification result includes the verification passed identification code, it is determined that the user's identity security authentication result is passed;
[0012] If the password verification result includes the verification failed identification code, it is determined that the user's identity security authentication result is not passed.
[0013] In the technical solution provided by the embodiments of the present application, the verification passed identification code and the verification failed identification code are fixed identification information set based on the security chip interface. During the identity security authentication process, the verification passed identification code and the verification failed identification code remain unchanged. Based on this, the BIOS can quickly and accurately obtain the user's identity security authentication result according to the verification passed identification code or the verification failed identification code in the password verification result.
[0014] In one embodiment, the user's identity security authentication result is passed; the method further includes:
[0015] In response to the password modification instruction, obtain the modified password input by the user;
[0016] Send the modified password and the password modification identification code to the security chip; the password modification identification code is used to instruct the security chip to perform password overwrite based on the modified password;
[0017] Receive the password setting result sent by the security chip.
[0018] In the technical solution provided by the embodiment of the present application, based on the BIOS obtaining the modified password input by the user, the password overwrite process is executed through the security chip. Since the security performance value of the security chip is higher than that of the BIOS, compared with the conventional method of overwriting the password through the BIOS, in the embodiment of the present application, the security of the method of overwriting the password through the security chip is higher, and the password setting result is also more accurate.
[0019] In one embodiment, the method further includes:
[0020] If the password setting result includes a success identification code for setting, display a password modification success prompt message;
[0021] If the password setting result includes a failure identification code for setting, instruct to re-enter the modified password.
[0022] In the technical solution provided by the embodiment of the present application, the BIOS executes an action corresponding to the password setting result according to different password setting results, and displays the overwrite result to the user, so as to facilitate the user to timely perceive the password modification progress, and instruct the user to re-enter the modified password in case of failure, improving the password modification efficiency and enhancing the user experience to a certain extent.
[0023] In one embodiment, the method further includes:
[0024] Obtain the output times of the password error prompt message; the password error prompt message is output when the user's identity security authentication result fails;
[0025] If the output times are greater than a preset threshold, stop accessing the BIOS;
[0026] If the output times are less than or equal to the preset threshold, instruct to re-enter the BIOS password.
[0027] In the technical solution provided by the embodiment of the present application, when the output times of the password error prompt message are less than or equal to the preset threshold, instruct to re-enter the BIOS password to improve the fault tolerance of the BIOS access mechanism; when the output times of the password error prompt message are greater than the preset threshold, stop accessing the BIOS to avoid malicious attacks on the BIOS.
[0028] In a second aspect, the present application provides an identity security authentication method, which is applied to a security chip. The method includes:
[0029] Receive the password input by the user and the password verification identification code sent by the BIOS;
[0030] Verify the password according to the password verification identification code to obtain a password verification result;
[0031] Send the password verification result to the BIOS; the password verification result is used by the BIOS to determine the result of the user's identity security authentication.
[0032] In the technical solution provided by the embodiments of the present application, the security chip verifies the password based on the password input by the user and the password verification identification code sent by the BIOS, and sends the password verification result to the BIOS. Among them, the password verification result is used by the BIOS to determine the result of the user's identity security authentication. In the embodiments of the present application, the password verification process is executed by the security chip. Then, in the case where the security performance value of the security chip is higher than the security performance value of the BIOS, compared with the method of verifying the password through the BIOS, the security of the method of verifying the password through the security chip is higher.
[0033] In one of the embodiments, verifying the password to obtain the password verification result includes:
[0034] Encrypt the password to obtain the password ciphertext and the standard ciphertext corresponding to the password;
[0035] If the standard ciphertext is the same as the password ciphertext, determine that the password verification result is the verification passed identification code;
[0036] If the standard ciphertext is different from the password ciphertext, determine that the password verification result is the verification failed identification code.
[0037] In the technical solution provided by the embodiments of the present application, on the basis of obtaining the password, the password is encrypted, and the verification result of the password is determined by comparing the standard ciphertext with the password ciphertext. Compared with the method of directly comparing the password with the standard password, the verification dimension of the embodiments of the present application is more complex and diversified, and the determined password verification result is more accurate.
[0038] In one of the embodiments, the method further includes:
[0039] Receive the modified password of the password sent by the BIOS;
[0040] Encrypt the modified password to obtain the modified password ciphertext, and overwrite the standard ciphertext corresponding to the password with the modified password ciphertext;
[0041] If the overwrite is successful, send the setting successful identification code to the BIOS; otherwise, send the setting failed identification code to the BIOS.
[0042] In the technical solution provided by the embodiments of the present application, in the case where the user identity security authentication is passed, the modified password ciphertext is generated based on the modified password input by the user, and the modified password ciphertext is used to overwrite the original standard ciphertext, so as to realize the synchronous update of the standard ciphertext corresponding to the password, so as to facilitate subsequent access to the BIOS through the new modified password.
[0043] In a third aspect, the present application further provides an identity security authentication device, including:
[0044] A password sending module, configured to send a password and a password verification identification code to a security chip in response to a password input by a user, where the password verification identification code is used to instruct the security chip to verify the password; the security performance value of the security chip is higher than that of the BIOS;
[0045] A result determination module, configured to determine the identity security authentication result of the user according to the password verification result sent by the security chip.
[0046] In a fourth aspect, the present application further provides an identity security authentication device, including:
[0047] A password receiving module, configured to receive the password input by the user and the password verification identification code sent by the BIOS; the security performance value of the security chip is higher than that of the BIOS;
[0048] A password verification module, configured to verify the password according to the password verification identification code to obtain a password verification result;
[0049] A result sending module, configured to send the password verification result to the BIOS; the password verification result is used by the BIOS to determine the identity security authentication result of the user.
[0050] In a fifth aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the method in any one of the first aspect and the second aspect are implemented.
[0051] In a sixth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method in any one of the first aspect and the second aspect are implemented.
[0052] In a seventh aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the method in any one of the first aspect and the second aspect are implemented. Description of the Drawings
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0054] Figure 1It is an application environment diagram of the identity security authentication method in an embodiment;
[0055] Figure 2 It is a schematic flowchart of the identity security authentication method in an embodiment;
[0056] Figure 3 It is a schematic flowchart of the step for determining the identity security authentication result in an embodiment;
[0057] Figure 4 It is a schematic flowchart of the password modification step in an embodiment;
[0058] Figure 5 It is a schematic flowchart of the password modification step in another embodiment;
[0059] Figure 6 It is a schematic flowchart of the password modification step in another embodiment;
[0060] Figure 7 It is a schematic flowchart of the step for obtaining the verification result in an embodiment;
[0061] Figure 8 It is a schematic flowchart of the step for obtaining the verification result in another embodiment;
[0062] Figure 9 It is a schematic flowchart of the step for obtaining the setting result in an embodiment;
[0063] Figure 10 It is a schematic flowchart of the identity security authentication method in another embodiment;
[0064] Figure 11 It is a schematic flowchart of the identity security authentication method in another embodiment;
[0065] Figure 12 It is a structural block diagram of the identity security authentication device in an embodiment;
[0066] Figure 13 It is a structural block diagram of the identity security authentication device in an embodiment;
[0067] Figure 14 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0068] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0069] The identity security authentication method provided by the embodiments of the present application can be applied to, for exampleFigure 1 in the application environment shown. Among them, the basic input / output system 102 communicates with the security chip 104 through the network. Information can be transmitted between the basic input / output system 102 and the security chip 104 through an interaction interface. For example, an identification code is generated by the interaction interface specification of the security chip, and its size is not limited. The purpose is to enable the basic input / output system 102 and the security chip 104 to perceive each other's intentions.
[0070] The identity security authentication function in the basic input / output system is one of the important security functions of the basic input / output system. This function mainly identifies the operator's identity through the recognized password (BIOS password) and then gives corresponding permissions. If an attacker obtains relevant data such as the password through technical means, they will illegally obtain the BIOS system permissions, resulting in security risks. Therefore, improving the security of the identity security authentication mechanism has important practical significance.
[0071] In the related art, when accessing the BIOS, usually the BIOS stores the password ciphertext in the chip where the firmware program is located, and authenticates the user's identity through the method of running the calculation of the password ciphertext in the memory by the BIOS firmware program to grant the user corresponding BIOS permissions. However, there are the following risks in the related art:
[0072] (1) The process of calculating the ciphertext from the password is determined by the BIOS firmware program. The program runs in the memory, and a large number of intermediate calculation values will inevitably be generated during the calculation process. An attacker can obtain sensitive information such as the password and ciphertext by monitoring the memory changes.
[0073] (2) The pre-set ciphertext is generally stored in a storage medium such as the chip of the BIOS program. An attacker can use a tool to read all the data in the chip and find the ciphertext. Then, by some means, this ciphertext is directly used for ciphertext comparison to achieve a replay attack.
[0074] Considering the above factors, the embodiment of the present application provides an identity security authentication method. The BIOS sends the password and the password verification identification code to a security chip with a higher security performance value than itself. The security chip verifies the password to generate a password verification result to improve the security of the password verification process and obtain a more accurate password verification result. Finally, the BIOS determines a more accurate identity security authentication result according to the password verification result.
[0075] The following uses specific embodiments to elaborate in detail on the technical solution of the present application and how the technical solution of the present application solves the above technical problems. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0076] In an exemplary embodiment, as Figure 2 shown, an identity security authentication method is provided. Taking the BIOS in Figure 1 as an example, it includes:
[0077] S201, in response to the password input by the user, send the password and the password verification identification code to the security chip. The password verification identification code is used to instruct the security chip to verify the password; the security performance value of the security chip is higher than that of the BIOS.
[0078] As the computer's boot system, the BIOS provides the most basic and direct hardware settings and controls for the computer. Users can modify the configuration information of the computer system by accessing and entering the BIOS to improve the computer's performance.
[0079] To ensure the security of the BIOS, if a user needs to access the BIOS, the BIOS needs to authenticate the user's identity and allow the user to access only when the user's identity security authentication passes.
[0080] In the embodiment of the present application, the user's identity is verified through the plaintext password input by the user, that is, the password. Specifically, the BIOS waits for the user to input the password on the access request interface. The user can input the password through various interfaces, such as a mouse, a keyboard, a communication signal, etc.
[0081] Further, the BIOS sends the received password and the password verification identification code to the security chip to instruct the security chip to operate on the password based on the password verification identification code. Among them, the password verification identification code is determined based on the security chip, used to instruct the security chip to perform the verification action, and during the entire identity security authentication process, the password verification identification code remains unchanged. For example, the password verification identification code can be 0xFF000001.
[0082] After receiving the password and the password verification identification code sent by the BIOS, the security chip first determines the verification action according to the password verification identification code, then takes the password as the execution object, verifies the password, and returns the password verification result to the BIOS.
[0083] It should be noted that the BIOS firmware code is generally stored in the Flash chip. The BIOS firmware code on the Flash chip can be directly read through a burner. Such a data reading and writing method has a relatively high risk of data theft or leakage. In contrast, the security chip in the embodiment of the present application has necessary protection operations, which avoids the risk of data leakage to a certain extent, that is to say, the security performance value of the security chip is higher than that of the BIOS.
[0084] Among them, the security performance value can be characterized by quantitative indicators such as the chip's cracking difficulty coefficient, manufacturing precision level, or security level. The above indicators can be obtained from the chip's corresponding certification certificate, or can be obtained by testing the chip's hardware architecture through dynamic or static testing methods.
[0085] Taking the reading difficulty coefficient as the security performance value as an example, the number of cores can be read from the chip's certification certificate, and then based on the mapping relationship between the number of cores and the reading difficulty, the reading difficulty of the chip can be determined. Among them, the more cores there are, the stronger the chip's data processing ability, the larger the amount of data processed, and the greater the cracking difficulty of the chip. For example, when the Flash chip to which the BIOS belongs has 4 cores, an 8-core central processing unit (CPU) or a 16-core CPU can be determined as a security chip.
[0086] Taking the security level as the security performance value as an example, an emulator or a debugging tool can be used to simulate the chip's attack environment, evaluate whether the chip has security vulnerabilities and the number of security vulnerabilities, and then determine the security level of the chip according to the number of security vulnerabilities of the chip. Among them, the fewer security vulnerabilities the chip has, the higher the security level.
[0087] Based on this, in the embodiments of the present application, the security performance value of the security chip is higher than that of the BIOS, which means that the process of password verification through the security chip is less likely to be monitored or attacked by an attacker compared to the method of password verification through the BIOS. The security level of password verification by the security chip is higher, and the obtained password verification result is more accurate.
[0088] In an actual scenario, when the BIOS sends the password and the password verification identification code to the security chip, it will also automatically clear the cached password to prevent the password entered by the user from being leaked.
[0089] S202. Determine the user's identity security authentication result according to the password verification result sent by the security chip.
[0090] The security chip can carry the identity security authentication result information in the password verification result and send it to the BIOS. Correspondingly, the BIOS extracts the user's identity security authentication result from the password verification result.
[0091] In the embodiments of the present application, there are no restrictions on the size and form of the password verification result. In addition to carrying the identity security authentication result, the password verification result can also include other information that can characterize the identity security authentication result, such as an identification code, a string, a machine code, etc.
[0092] In another scenario, the password verification result sent by the security chip is a verification result identification code, and the BIOS determines the identity security authentication result corresponding to the verification result identification code according to the mapping table of the verification result identification code and the identity security authentication result.
[0093] In the embodiment of the present application, in response to the password input by the user, the BIOS sends the password and the password verification identification code to the security chip to instruct the security chip to verify the password, and then determines the identity security authentication result of the user according to the password verification result sent by the security chip. Among them, the security performance value of the security chip is higher than that of the BIOS. In this method, based on obtaining the password input by the user, the BIOS verifies the password through the security chip to obtain the password verification result, and further determines the identity security authentication result. That is to say, in the embodiment of the present application, the password verification process is executed by the security chip. And, the security performance value of the security chip is higher than that of the BIOS. Then, compared with the method of verifying the password through the BIOS, in the embodiment of the present application, the method of verifying the password through the security chip is more secure, and the password verification result obtained by the security chip is also more accurate. On this basis, through the interaction between the BIOS and the security chip, the identity security authentication result determined by the BIOS according to the password verification result is also more accurate.
[0094] As can be seen from the foregoing embodiments, in the process of identity security authentication, the BIOS determines the identity security authentication result based on the password verification result sent by the security chip. In this case, the BIOS can determine the identity security authentication result from various dimensions such as the type, form, and content of the information in the password verification result. The following uses an embodiment to illustrate a feasible way for the BIOS to determine the identity security authentication result according to the password verification result.
[0095] In an exemplary embodiment, determining the identity security authentication result of the user according to the password verification result sent by the security chip includes:
[0096] S301, if the password verification result includes a verification passed identification code, determine that the identity security authentication result of the user is passed.
[0097] If the password verification result includes a verification passed identification code, it means that the password input by the user is the same as the standard password preset by the BIOS, and the user has the permission to access the BIOS, then determine that the identity security authentication result of the user is passed.
[0098] In practical applications, the BIOS can also correspond to users with different access privilege levels, such as administrative users and ordinary users. In this case, the verification pass identification code can also include a first pass identification code and a second pass identification code. If the password verification result includes the first pass identification code, it is determined that the user's identity security authentication result is passed, and the user's identity is determined to be an administrative user; if the password verification result includes the second pass identification code, it is determined that the user's identity security authentication result is passed, and the user's identity is determined to be an ordinary user.
[0099] S302, if the password verification result includes a verification failure identification code, it is determined that the user's identity security authentication result is not passed.
[0100] If the password verification result includes a verification failure identification code, it means that the password entered by the user is different from the standard password preset in the BIOS, and the user does not have the permission to access the BIOS. Then it is determined that the user's identity security authentication result is not passed.
[0101] It should be noted that in practical applications, the password verification result is to select and determine either a verification success identification code or a verification failure identification code. In other words, when the password verification result includes a verification pass identification code, it does not include a verification failure identification code, and vice versa. When the password verification result includes a verification failure identification code, it does not include a verification pass identification code.
[0102] Moreover, the verification pass identification code, the verification failure identification code are similar to the password verification identification code in the foregoing embodiments, and all have high reusability, respectively representing the corresponding identification information. During the identity security authentication process, the specific contents of the verification pass identification code, the verification failure identification code, and the password verification identification code remain unchanged.
[0103] In the embodiments of the present application, the verification pass identification code and the verification failure identification code are fixed identification information set based on the security chip interface. During the identity security authentication process, the verification pass identification code and the verification failure identification code remain unchanged. Based on this, the BIOS can quickly and accurately obtain the user's identity security authentication result according to the verification pass identification code or the verification failure identification code in the password verification result.
[0104] In the case where the user's identity security authentication is passed, the user can control the computer's hardware in the BIOS based on the access privilege granted by the BIOS, such as virtual disk partitioning, etc., and can also modify the password of the BIOS to improve the security of the password. Hereinafter, through an embodiment, an implementation manner of modifying the BIOS password will be described.
[0105] In an exemplary embodiment, as Figure 4 shown, the user's identity security authentication result is passed; the method further includes:
[0106] S401, in response to the password modification instruction, obtain the modified password entered by the user.
[0107] The BIOS provides a password modification interface, and the user inputs the modified password on the password modification interface through various interfaces such as a mouse, a keyboard, and a communication signal.
[0108] S402, send the modified password and the password modification identification code to the security chip; the password modification identification code is used to instruct the security chip to perform password overwrite based on the modified password.
[0109] Among them, the password modification identification code is determined based on the security chip and is used to instruct the security chip to replace the current password, replace relevant information such as the ciphertext of the current password, etc. It should be noted that, similar to the password verification identification code, the password modification identification code remains unchanged throughout the identity security authentication process.
[0110] The BIOS sends the received password and the password modification identification code to the security chip to instruct the security chip to overwrite the information of the current password based on the information of the modified password.
[0111] S403, receive the password setting result sent by the security chip.
[0112] When the security chip performs password overwrite, there will be two situations: overwrite success and overwrite failure. Different overwrite situations correspond to different password setting results. In the embodiments of the present application, regardless of which password setting result, the security chip will send it to the BIOS.
[0113] In the embodiments of the present application, based on obtaining the modified password input by the user, the BIOS executes the password overwrite process through the security chip. Since the security performance value of the security chip is higher than that of the BIOS, compared with the traditional method of password overwrite through the BIOS, in the embodiments of the present application, the method of password overwrite through the security chip has higher security and more accurate password setting results.
[0114] After the BIOS receives the password setting result sent by the security chip, it can further display it to the user to timely inform the user of the password setting progress and result. Then in an exemplary embodiment, as Figure 5 shown, the method further includes:
[0115] S501, if the password setting result includes a setting success identification code, display a password modification success prompt message.
[0116] If the password setting result includes a successful setting identification code, it means that the security chip has completed the process of modifying the password to overwrite the password. At this time, the BIOS will display a prompt message indicating that the password has been successfully modified, informing the user that the password has been successfully modified. In this case, the user needs to enter the modified password subsequently to access the BIOS.
[0117] S502, if the password setting result includes a failure setting identification code, it indicates to re-enter the modified password.
[0118] If the password setting result includes a failure setting identification code, it means that the modified password entered by the user does not meet the preset password modification standard, and the security chip cannot complete the process of modifying the password to overwrite the password. At this time, the BIOS can display the password modification interface again, instructing the user to re-enter the new modified password.
[0119] It should be noted that in practical applications, the password setting result is either a successful setting identification code or a failure setting identification code. In other words, when the password setting result includes a successful setting identification code, it does not include a failure setting identification code. Conversely, when the password verification result includes a failure setting identification code, it does not include a passed verification identification code.
[0120] Moreover, the successful setting identification code and the failure setting identification code are similar in function to the passed verification identification code, the failed verification identification code, and the password verification identification code in the foregoing embodiments, and all have high reusability, respectively representing the corresponding identification information. In the process of identity security authentication, the specific contents of the successful setting identification code, the failure setting identification code, the passed verification identification code, the failed verification identification code, and the password verification identification code remain unchanged.
[0121] In the embodiments of the present application, the BIOS performs actions corresponding to the password setting result according to different password setting results, and displays the overwrite result to the user, so as to facilitate the user to timely perceive the progress of password modification, and instructs the user to re-enter the modified password in case of failure, improving the efficiency of password modification and enhancing the user experience to a certain extent.
[0122] Based on the password entered by the user, there are two corresponding situations: identity security authentication passed and identity security authentication not passed. The foregoing embodiments have described the situation where the user's identity security authentication result is passed. Next, through an embodiment, the situation where the user's identity security authentication is not passed will be described.
[0123] In an exemplary embodiment, as Figure 6 shown, the method further includes:
[0124] S601, obtain the output times of the password error prompt message; the password error prompt message is output when the user's identity security authentication result is not passed.
[0125] When the security chip verifies the password input by the user and the verification fails, it sends a verification failure identification code to the BIOS.
[0126] When the BIOS first determines that the user identity security authentication result fails, it outputs a password error prompt. Then, every time the user identity security authentication result fails, it outputs a password error prompt once. At the same time, the BIOS continuously monitors the number of consecutive password error prompts output.
[0127] S602, if the output times are greater than the preset threshold, stop accessing the BIOS.
[0128] The preset threshold is set by developers according to empirical values, which is the maximum number of times that allows the user to continuously enter incorrect passwords, and also the maximum value of the number of times that allows the continuous output of password error prompt messages.
[0129] If the number of times the password error prompt message is output is greater than the preset threshold, it means that the user has continuously entered incorrect passwords multiple times. At this time, to prevent the user from occupying computer resources for a long time, stop the user from accessing the BIOS.
[0130] S603, if the output times are less than or equal to the preset threshold, indicate to re-enter the BIOS password.
[0131] If the output times are less than or equal to the preset threshold, the BIOS confirms that the password currently entered by the user is incorrect and returns to the password input interface to indicate to the user to re-enter the BIOS password.
[0132] In the embodiments of the present application, when the number of times the password error prompt message is output is less than or equal to the preset threshold, it indicates to re-enter the BIOS password, improving the fault tolerance of the BIOS access mechanism; when the number of times the password error prompt message is output is greater than the preset threshold, stop accessing the BIOS to prevent the BIOS from being maliciously attacked.
[0133] The above is the description of the relevant embodiments on the side with the BIOS as the execution subject. On this basis, the embodiments of the present application also provide corresponding embodiments of the above process with the security chip as the execution subject. Since all the implementation principles, detailed processes, and achievable technical effects of the embodiments with the security chip as the execution subject below are the same as those of the embodiments on the side with the BIOS as the execution subject, for the sake of simplicity and clarity, the following embodiments will not be described in detail one by one. The implementation process and implementation effects of each embodiment can be referred to the description of the foregoing embodiments.
[0134] Then as Figure 7 shown, a method for user identity security authentication is provided, which is applied to a security chip. The method includes:
[0135] S701. Receive the password and password verification identification code input by the user sent by the BIOS. The security performance value of the security chip is higher than that of the BIOS.
[0136] Among them, the password is input by the user based on different interfaces, such as interfaces of a mouse, a keyboard, a communication signal, etc. The password verification identification code is determined based on the security chip, used to instruct the security chip to perform a verification action, and during the entire identity security authentication process, the password verification identification code remains unchanged.
[0137] S702. Verify the password according to the password verification identification code to obtain a password verification result.
[0138] The security chip determines a verification action according to the password verification identification code sent by the BIOS, then uses the password as the execution object to verify the password, and returns the password verification result to the BIOS. In the embodiments of the present application, the method for verifying the password is not limited.
[0139] For example, the security chip compares the password input by the user with a preset standard password, and then determines the password verification result according to the comparison result.
[0140] S703. Send the password verification result to the BIOS; the password verification result is used for the BIOS to determine the user's identity security authentication result.
[0141] Among them, the password verification result includes a verification passed identification code, used for the BIOS to determine that the user's identity security authentication result is passed. Or, the password verification result can include a verification failed identification code, used for the BIOS to determine that the user's identity security authentication result is not passed.
[0142] It should be noted that the verification passed identification code, the verification failed identification code and the password verification identification code have similar functions, all have high reusability, respectively represent the corresponding identification information, and during the identity security authentication process, the specific contents of the verification passed identification code, the verification failed identification code and the password verification identification code remain unchanged.
[0143] In the embodiments of the present application, the security chip verifies the password based on the password and password verification identification code input by the user sent by the BIOS, and sends the password verification result to the BIOS. Among them, the password verification result is used for the BIOS to determine the user's identity security authentication result. In the embodiments of the present application, the password verification process is executed by the security chip. Then, in the case where the security performance value of the security chip is higher than that of the BIOS, compared with the method of verifying the password through the BIOS, the method of verifying the password through the security chip is more secure.
[0144] After obtaining the password, the security chip can verify the password in various ways, such as the matching method, the similarity calculation method, etc., to obtain an accurate password verification result. Based on this, the following uses an embodiment to illustrate an implementable way for the security chip to verify the password.
[0145] In an exemplary embodiment, as Figure 8 shown, verifying the password to obtain a password verification result includes:
[0146] S801, encrypt the password to obtain the password ciphertext and the standard ciphertext corresponding to the password.
[0147] Among them, the standard ciphertext is the ciphertext calculated in advance by the security chip based on the standard password using an encryption algorithm, and the standard ciphertext is stored in the security chip or a third storage medium in advance.
[0148] After the security chip obtains the password input by the user, it uses the encryption algorithm of the standard password to perform an encryption calculation on the password input by the user to obtain the password ciphertext.
[0149] S802, if the standard ciphertext is the same as the password ciphertext, determine that the password verification result is the verification passed identification code.
[0150] If the standard ciphertext is the same as the password ciphertext, it means that the password input by the user exactly matches the standard password corresponding to the standard ciphertext, then determine that the password verification result is the verification passed identification code.
[0151] S803, if the standard ciphertext is different from the password ciphertext, determine that the password verification result is the verification failed identification code.
[0152] If the standard ciphertext is different from the password ciphertext, it means that the password input by the user does not match the standard password corresponding to the standard ciphertext, that is, the password verification fails, then determine that the password verification result is the verification failed identification code.
[0153] In the embodiment of the present application, on the basis of obtaining the password, the password is encrypted, and the verification result of the password is determined by comparing the standard ciphertext with the password ciphertext. Compared with the method of directly comparing the password with the standard password, the verification dimension of the embodiment of the present application is more complex and diversified, and the determined password verification result is more accurate.
[0154] In the case where the user identity security authentication is passed, the user can also update the password to increase the cracking difficulty of the password, thereby improving the security level of the BIOS. Then in an exemplary embodiment, as Figure 9 shown, the method further includes:
[0155] S901, receive the modified password of the password sent by the BIOS.
[0156] S902 encrypts the modified password to obtain the encrypted modified password ciphertext, and overwrites the standard ciphertext corresponding to the password with the encrypted modified password ciphertext.
[0157] Encrypt the modified password entered by the user through a preset encryption algorithm to obtain the encrypted modified password ciphertext corresponding to the modified password. Among them, the encryption algorithm for encrypting the modified password can be the same as or different from the algorithm for encrypting the password entered by the user in the foregoing embodiments.
[0158] After obtaining the encrypted modified password ciphertext, replace the original standard ciphertext with the encrypted modified password ciphertext. In one scenario, if the security chip stores the standard password, replace the original standard password with the modified password.
[0159] S903, if the overwrite is successful, send a setup success identification code to the BIOS; otherwise, send a setup failure identification code to the BIOS.
[0160] When the security chip performs password overwrite, there are two situations: overwrite success and overwrite failure. Overwrite success corresponds to a setup success identification code, and overwrite failure corresponds to a setup failure identification code. In the embodiments of the present application, regardless of which identification code, the security chip will send it to the BIOS.
[0161] If the security chip overwrites the standard ciphertext with the encrypted modified password ciphertext and the overwrite is successful, it can send a setup success identification code to the BIOS, or carry the setup success identification code in the password setup result and send it to the BIOS.
[0162] If the security chip overwrites the standard ciphertext with the encrypted modified password ciphertext, but the overwrite fails, it can send a setup failure identification code to the BIOS, or carry the setup failure identification code in the password setup result and send it to the BIOS.
[0163] In the embodiments of the present application, in the case where the user identity security authentication passes, an encrypted modified password ciphertext is generated based on the modified password entered by the user, and the encrypted modified password ciphertext is used to overwrite the original standard ciphertext, so as to synchronously update the standard ciphertext corresponding to the password, so as to facilitate subsequent access to the BIOS through the new modified password.
[0164] In a specific embodiment, taking the security chip as the CPU as an example, as Figure 10 shown, the identity security authentication method is described, including:
[0165] S1001, the BIOS receives the password entered by the user.
[0166] Among them, the way to enter the password can be multiple interfaces, including but not limited to a mouse, a keyboard, a communication signal, etc.
[0167] S1002, the BIOS sends the password and the password verification identification code to the CPU and clears the password cache.
[0168] Among them, the password verification identification code represents the identification code for setting a new password and is used to instruct the CPU to verify the password.
[0169] S1003, the CPU calculates the password ciphertext corresponding to the password using the built-in encryption algorithm according to the password verification identification code.
[0170] Among them, the encryption algorithm includes but is not limited to encryption algorithms such as SM2 and RSA.
[0171] S1004, the CPU compares the standard ciphertext with the password ciphertext.
[0172] Among them, the standard ciphertext is the ciphertext stored before retrieving the non-volatile storage area internally.
[0173] S1005, if they are not the same, the CPU sends a verification failure identification code to the BIOS.
[0174] S1006, if they are the same, the CPU sends a verification passed identification code to the BIOS.
[0175] S1007, when the BIOS receives the verification failure identification code, it determines that the identity security authentication fails and outputs a password error prompt message.
[0176] S1008, the BIOS determines whether the output times of the password error prompt message are greater than the preset threshold.
[0177] S1009, if so, stop the access to the BIOS.
[0178] The way for the BIOS to stop accessing can be to instruct the CPU to lock up, making it impossible for the user to power on the machine.
[0179] S1009, if not, then instruct to re-enter the password of the BIOS.
[0180] S1010, when the BIOS receives the verification passed identification code, it determines that the identity security authentication passes and grants the user corresponding permissions.
[0181] In the embodiments of the present application, the algorithm for calculating the password ciphertext and the standard ciphertext of the password set by the user are set inside the CPU, and the BIOS only calls the interface of the CPU to verify the password and calculate and store the ciphertext, which greatly improves the security, specifically reflected in the following aspects:
[0182] (1) Compared with the method of running the calculation of the password ciphertext in the memory through the BIOS firmware program, in the embodiment of the present application, the password is directly handed over to the CPU interface, and the internal CPU directly performs calculation processing, and the entire processing process of the ciphertext is inside the CPU. Attackers cannot obtain the intermediate value of the ciphertext calculation by monitoring the memory, greatly reducing the security risk.
[0183] (2) Compared with the practice of storing the password ciphertext in the chip where the firmware program is located, in the embodiment of the present application, the ciphertext is directly stored inside the CPU. Due to its precision, the CPU is different from other common storage chips, and it is more difficult for attackers to read the stored content therein, thereby reducing the risk of ciphertext leakage and preventing attackers from performing replay attacks by stealing the ciphertext. At the same time, it is also possible to avoid introducing other secure computing or storage devices for the security of storage and calculation when designing the motherboard, saving costs.
[0184] (3) Compared with preventing unauthorized personnel from intercepting at the BIOS firmware level, in the embodiment of the present application, program execution is blocked at the CPU level. Unless the identity security authentication is verified through the CPU interface, even if the attacker breaks the BIOS password program, they cannot skip the identity security authentication process, increasing security.
[0185] In a specific embodiment, continuing to take the CPU as the security chip as an example, as Figure 11 shown, the identity security authentication method is described, including:
[0186] S1101, the BIOS responds to the user's password modification instruction and prompts for the input of the password.
[0187] S1102, the BIOS sends the password and the password verification identification code to the CPU and clears the password cache.
[0188] S1103, the CPU calculates the password ciphertext using the built-in encryption algorithm based on the password verification identification code sent by the BIOS.
[0189] S1104, the CPU compares the standard ciphertext with the password ciphertext. If they are the same, the CPU sends an authentication passed identification code to the BIOS. If they are different, the CPU sends an authentication failed identification code to the BIOS.
[0190] Among them, the standard ciphertext is the ciphertext stored previously retrieved from the non-volatile storage area internally.
[0191] S1105, if the BIOS receives the authentication passed identification code, it prompts for the input of the modified password, otherwise it returns to S1101.
[0192] S1106, the BIOS sends the modified password and the password modification identification code to the CPU and clears the password cache.
[0193] Among them, the password modification identification code represents the identification code that has passed verification and is to set a new password, and is used to instruct the CPU to overwrite the password based on the modified password.
[0194] S1107, the CPU receives the password modification identification code sent by the BIOS, and uses the built-in encryption algorithm to calculate the modified password ciphertext corresponding to the modified password.
[0195] S1108, the CPU overwrites the standard ciphertext according to the modified password ciphertext.
[0196] If the overwrite is successful, send a setting success identification code to the BIOS; otherwise, send a setting failure identification code to the BIOS.
[0197] S1109, the BIOS receives the setting failure identification code, instructs to re-enter the modified password, and returns to S1106.
[0198] S1110, the BIOS receives the setting success identification code and displays a password modification success prompt message.
[0199] In the embodiments of the present application, the CPU interface is used to calculate the password ciphertext to implement the functions of verifying the operator's password and setting a new password. The calculation process is carried out inside the CPU instead of using a firmware program to calculate in the memory, avoiding the risk of leakage of intermediate values during calculation and increasing the security of identity authentication. At the same time, in the embodiments of the present application, the password ciphertext is stored inside the CPU. Due to its precision, the CPU is more secure than other storage chips. At the same time, it is also possible to not introduce other secure calculation or storage devices for the security of storage and calculation when designing the motherboard, saving costs.
[0200] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.
[0201] Based on the same inventive concept, an embodiment of the present application further provides an identity security authentication device for implementing the identity security authentication method involved above. The solution provided by this device for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the identity security authentication device provided below can refer to the limitations on the identity security authentication method in the above text, and will not be repeated here.
[0202] In an exemplary embodiment, as Figure 12 shown, an identity security authentication device is provided, including: a password sending module 1201 and a result determination module 1202, where:
[0203] The password sending module 1201 is configured to send a password and a password verification identification code to the security chip in response to a password input by a user. The password verification identification code is used to instruct the security chip to verify the password; the security performance value of the security chip is higher than the security performance value of the BIOS.
[0204] The result determination module 1202 is configured to determine the identity security authentication result of the user according to the password verification result sent by the security chip.
[0205] In an exemplary embodiment, the result determination module 1202 includes a first determination unit and a second determination unit, where:
[0206] The first determination unit is configured to determine that the identity security authentication result of the user is passed if the password verification result includes a verification passed identification code;
[0207] The second determination unit is configured to determine that the identity security authentication result of the user is not passed if the password verification result includes a verification failed identification code.
[0208] In an exemplary embodiment, the identity security authentication device further includes: an instruction response module, a password modification module, and a result receiving module, where:
[0209] The instruction response module is configured to obtain the modified password input by the user in response to a password modification instruction;
[0210] The password modification module is configured to send the modified password and a password modification identification code to the security chip; the password modification identification code is used to instruct the security chip to perform password overwrite based on the modified password;
[0211] The result receiving module is configured to receive the password setting result sent by the security chip.
[0212] In an exemplary embodiment, the identity security authentication device further includes: an information display module and a modification indication module, where:
[0213] An information display module, configured to display a password modification success prompt message when the password setting result includes a setting success identification code;
[0214] A modification indication module, configured to indicate re - entering the modified password when the password setting result includes a setting failure identification code.
[0215] In an exemplary embodiment, the identity security authentication device further includes: a times acquisition module, an access termination module, and an input indication module, where:
[0216] The times acquisition module is configured to acquire the output times of the password error prompt message; the password error prompt message is output when the user's identity security authentication result fails.
[0217] The access termination module is configured to stop accessing the BIOS if the output times are greater than a preset threshold.
[0218] The input indication module is configured to indicate re - entering the BIOS password if the output times are less than or equal to the preset threshold.
[0219] In an exemplary embodiment, as Figure 13 shown, there is provided an identity security authentication device, including: a password receiving module 1301, a password verification module 1302, and a result sending module 1303, where:
[0220] The password receiving module 1301 is configured to receive the password input by the user sent by the BIOS and a password verification identification code; the security performance value of the security chip is higher than that of the BIOS.
[0221] The password verification module 1302 is configured to verify the password according to the password verification identification code to obtain a password verification result.
[0222] The result sending module 1303 is configured to send the password verification result to the BIOS; the password verification result is used by the BIOS to determine the user's identity security authentication result.
[0223] In an exemplary embodiment, the password verification module 1302 includes: a first encryption unit, a verification passed unit, and a verification failed unit, where:
[0224] The first encryption unit is configured to encrypt the password to obtain a password ciphertext and a standard ciphertext corresponding to the password.
[0225] The verification passed unit is configured to determine that the password verification result is a verification passed identification code when the standard ciphertext is the same as the password ciphertext.
[0226] A verification failure unit is used to determine that the password verification result is a verification failure identification code when the standard ciphertext is different from the password ciphertext.
[0227] In an exemplary embodiment, the identity security authentication device further includes: a second encryption module, a ciphertext overwrite module, and an identification code sending module, where:
[0228] The second encryption module is used to receive the modified password of the password sent by the BIOS.
[0229] The ciphertext overwrite module is used to encrypt the modified password to obtain a modified password ciphertext, and overwrite the standard ciphertext corresponding to the password with the modified password ciphertext.
[0230] The identification code sending module is used to send a setting success identification code to the BIOS in the case of successful overwrite; otherwise, send a setting failure identification code to the BIOS.
[0231] Each module in the above identity security authentication device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a memory in a computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0232] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 14 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store identity security authentication data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. The computer program, when executed by the processor, implements an identity security authentication method.
[0233] Those skilled in the art can understand, Figure 14The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0234] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0235] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0236] In an embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0237] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0238] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0239] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0240] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. An identity security authentication method, characterized in that, applied to the Basic Input Output System (BIOS), the method includes: In response to a password input by the user, sending the password and a password verification identification code to the security chip, where the password verification identification code is used to instruct the security chip to verify the password; the security performance value of the security chip is higher than that of the BIOS; Determining the identity security authentication result of the user according to the password verification result sent by the security chip.
2. The method according to claim 1, characterized in that, the determining the identity security authentication result of the user according to the password verification result sent by the security chip includes: If the password verification result includes a verification passed identification code, determining that the identity security authentication result of the user is passed; If the password verification result includes a verification failed identification code, determining that the identity security authentication result of the user is not passed.
3. The method according to claim 1 or 2, characterized in that, the identity security authentication result of the user is passed; the method further includes: In response to a password modification instruction, obtaining the modified password input by the user; Sending the modified password and a password modification identification code to the security chip; the password modification identification code is used to instruct the security chip to overwrite the password based on the modified password; Receiving the password setting result sent by the security chip.
4. The method according to claim 3, characterized in that, the method further includes: If the password setting result includes a setting success identification code, displaying a password modification success prompt message; If the password setting result includes a setting failed identification code, instructing to re-enter the modified password.
5. The method according to claim 1 or 2, characterized in that, the method further includes: Obtaining the output times of the password error prompt message; the password error prompt message is output when the identity security authentication result of the user is not passed; If the output times are greater than a preset threshold, stopping the access to the BIOS; If the output times are less than or equal to the preset threshold, instructing to re-enter the password of the BIOS.
6. An identity security authentication method, characterized in that, applied to the security chip, the method includes: Receiving the password input by the user and the password verification identification code sent by the BIOS; the security performance value of the security chip is higher than that of the BIOS; Verifying the password according to the password verification identification code to obtain a password verification result; Sending the password verification result to the BIOS; the password verification result is used for the BIOS to determine the identity security authentication result of the user.
7. The method according to claim 6, characterized in that, the verifying the password to obtain a password verification result includes: Encrypting the password to obtain a password ciphertext and the standard ciphertext corresponding to the password; If the standard ciphertext is the same as the password ciphertext, determining that the password verification result is a verification passed identification code; If the standard ciphertext is different from the password ciphertext, determine that the password verification result is a verification failure identification code.
8. The method according to claim 6 or 7, wherein, the method further includes: receiving a modified password of the password sent by the BIOS; encrypting the modified password to obtain a modified password ciphertext, and overwriting the standard ciphertext corresponding to the password with the modified password ciphertext; if the overwrite is successful, send a setting success identification code to the BIOS; otherwise, send a setting failure identification code to the BIOS.
9. An identity security authentication device, wherein, the device includes: a password sending module, configured to send the password and a password verification identification code to a security chip in response to a password input by a user, where the password verification identification code is used to instruct the security chip to verify the password; the security performance value of the security chip is higher than that of the BIOS; a result determination module, configured to determine an identity security authentication result of the user according to a password verification result sent by the security chip.
10. An identity security authentication device, wherein, the device includes: a password receiving module, configured to receive a password input by a user and a password verification identification code sent by the BIOS; the security performance value of the security chip is higher than that of the BIOS; a password verification module, configured to verify the password according to the password verification identification code to obtain a password verification result; a result sending module, configured to send the password verification result to the BIOS; the password verification result is used by the BIOS to determine an identity security authentication result of the user.