Computer system starting method and device, computer system, medium and product
By verifying the information in the solidified area in the computer system, the information integrity of the firmware layer and the trusted password module firmware is ensured, and the startup process of the computer system is controlled based on this information, the complex problem of the computer system's secure startup process is solved, and higher information verification accuracy and security after the computer system is started is achieved.
Patent Information
- Application Number
- CN202311771222.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-24
AI Technical Summary
In the prior art, the secure startup process of a computer system is relatively complex and it is difficult to effectively reduce this complexity.
By verifying the information in the solidified area in the computer system, the information integrity of the firmware layer and the trusted password module firmware is ensured, and the startup process of the computer system is controlled based on this information.
This method can improve the accuracy of information verification and the security after startup of the computer system, while reducing the complexity of the secure startup process, without requiring external auxiliary circuits, and simplifying the startup process.
Smart Images

Figure CN120197170A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a computer system startup method, device, computer system, medium and product. Background Art
[0002] With the development of communication security technology, the security of computer system operation is becoming more and more important. In order to ensure the security of computer system startup, it is particularly important to perform security verification on the computer system startup process.
[0003] In the related art, a dedicated circuit is mainly used to perform security verification on the startup process of a computer system to ensure the safe startup of the computer system. However, the use of the related art will result in a more complicated safe startup process of the computer system. Summary of the invention
[0004] Based on this, it is necessary to provide a computer system startup method, device, computer system, medium and product to address the above technical problems, which can reduce the complexity of the computer system security startup process.
[0005] In a first aspect, an embodiment of the present application provides a computer system startup method, the method comprising:
[0006] Verifying information in a firmware layer of a computer system based on information in a solidified area of the computer system;
[0007] If the information verification passes, the trusted cryptographic module firmware in the processor in the computer system is verified according to the information in the firmware layer;
[0008] If the trusted cryptographic module firmware passes the verification, the computer system is started up according to the trusted cryptographic module firmware.
[0009] The technical solution in the embodiment of the present application verifies the information in the firmware layer of the computer system according to the information in the solidified area of the computer system. If the information verification passes, the trusted cryptographic module firmware in the processor in the computer system is verified according to the information in the firmware layer. If the trusted cryptographic module firmware verification passes, the computer system startup is controlled according to the trusted cryptographic module firmware. The above method can use the information solidified in the computer system that is not easy to be tampered with or lost as a trusted basis to implement the information verification process before the computer system is started, which can improve the accuracy of information verification, thereby improving the security of the computer system after startup, and the above method can realize the safe startup of the computer system through the solidified information built into the computer system, and the method does not require the participation of other auxiliary circuits outside the computer system, thereby making the computer system The secure boot process becomes simpler, reducing the complexity of the secure boot process of the computer system; in addition, the above method can realize the information verification process before the secure boot of the computer system through the solidified information stored in the computer system, so that the information verification process is simplified, thereby speeding up the information verification speed and further speeding up the secure boot of the computer system; in addition, the above method does not require human participation, which can not only save the secure boot cost of the computer system, but also improve the accuracy of the information verification before the secure boot of the computer system. On this basis, the security of the computer system after startup can be further improved; furthermore, the above method can use the solidified information in the computer system to perform layer-by-layer verification on the entire link from the power-on of the computer system to the startup of the computer system, thereby greatly improving the security of the computer system after startup.
[0010] In one embodiment, the information in the hardened area includes the root public key information of the processor, and the information in the firmware layer includes the secure processor startup program and the firmware startup file; based on the information in the hardened area of the computer system, the information in the firmware layer of the computer system is verified, including:
[0011] Verify the security processor startup program through the processor's root public key information;
[0012] If the security processor startup program passes the verification, the firmware startup file is verified through the security processor startup program.
[0013] The technical solution in the embodiment of the present application verifies the security processor startup program through the root public key information of the processor. If the security processor startup program passes the verification, the firmware startup file is verified through the security processor startup program. The above method can use the information that is not easily tampered with or lost solidified in the computer system as a trusted basis to verify the information in the solidified layer layer by layer, which can improve the accuracy of the information verification results in the solidified layer. On this basis, the solidified layer of the computer system can be guaranteed to start securely.
[0014] In one embodiment, the firmware startup file includes a public key certificate chain and an initialization program in the firmware startup program; and the firmware startup file is verified by the security processor startup program, including:
[0015] Control the execution of the security processor startup program and verify the public key certificate chain;
[0016] If the public key certificate chain passes the verification, the initialization program is verified using the public key in the public key certificate chain.
[0017] The technical solution in the embodiment of the present application controls the execution of the security processor startup program and verifies the public key certificate chain. If the public key certificate chain verification passes, the initialization program in the firmware startup program is verified by the public key in the public key certificate chain; the above method can adopt an interlocking chain verification method to verify the content of the firmware startup file layer by layer, which can improve the accuracy of the firmware startup file security verification.
[0018] In one embodiment, verifying the public key certificate chain includes:
[0019] Decrypting the signature value in the public key certificate chain according to the root public key information of the processor to obtain a first hash value;
[0020] Performing hash processing on the public key value in the public key certificate chain according to the hash algorithm in the public key certificate chain to obtain a second hash value;
[0021] If the first hash value is equal to the second hash value, the public key certificate chain verification passes.
[0022] The technical solution in the embodiment of the present application is to decrypt the signature value in the public key certificate chain according to the root public key information of the processor to obtain a first hash value, and to hash the public key value in the public key certificate chain according to the hash algorithm in the public key certificate chain to obtain a second hash value. If the first hash value is equal to the second hash value, the public key certificate chain verification passes. The above method can perform security verification on the public key certificate chain to provide an effective basis for the next step of accurate and secure verification of the initialization program in the firmware startup program, and can further improve the accuracy of the verification result of the initialization program in the firmware startup program.
[0023] In one embodiment, the information in the firmware layer includes the initialization program in the firmware boot program; verifying the trusted password module firmware in the processor within the computer system according to the information in the firmware layer includes:
[0024] Controlling the execution of the initialization program in the firmware boot program, and verifying the trusted certificate in the trusted password module firmware according to the root public key information of the processor.
[0025] In the technical solution of the embodiment of the present application, controlling the execution of the initialization program in the firmware boot program, and verifying the trusted certificate in the trusted password module firmware according to the root public key information of the processor; the above method can control the execution of the initialization program that passes the verification to verify the trusted certificate, which can make the security of the trusted certificate verification process higher. At the same time, the above method can use the information that is solidified in the computer system and is not easily tampered with or lost as a trusted basis to verify the trusted certificate in the trusted password module firmware, which can improve the accuracy of the verification result of the trusted certificate.
[0026] In one embodiment, verifying the trusted certificate in the trusted password module firmware according to the root public key information of the processor includes:
[0027] Decrypting the signature value in the trusted certificate according to the root public key information to obtain a third hash value;
[0028] Performing a hash process on the public key value in the trusted certificate according to the hash algorithm in the trusted certificate to obtain a fourth hash value;
[0029] If the third hash value is equal to the fourth hash value, the verification of the trusted certificate passes.
[0030] In the technical solution of the embodiment of the present application, decrypting the signature value in the trusted certificate according to the root public key information to obtain a third hash value, performing a hash process on the public key value in the trusted certificate according to the hash algorithm in the trusted certificate to obtain a fourth hash value, and if the third hash value is equal to the fourth hash value, the verification of the trusted certificate in the trusted password module firmware passes; the above method can perform a security verification on the trusted certificate in the trusted password module firmware to prepare for the next secure startup of the computer system, making the security of the computer system higher after startup.
[0031] In one embodiment, controlling the startup of the computer system according to the trusted password module firmware includes:
[0032] Controlling the execution of the trusted password module firmware, performing trusted computing on the target firmware startup file to obtain a trusted root;
[0033] Determining the trusted state of the target firmware startup file according to the trusted root;
[0034] If the trusted state is trusted, the target firmware startup file is controlled to run to complete the startup of the computer system.
[0035] The technical solution in the embodiment of the present application controls the execution of the trusted cryptographic module firmware, performs trusted calculation on the target firmware startup file to obtain a trusted root, determines the trusted state of the target firmware startup file based on the trusted root, and if the trusted state is trusted, controls the running of the target firmware startup file to complete the startup of the computer system; the above method can verify the trusted cryptographic module firmware to perform trust measurement on other firmware startup files required in the computer system startup process, that is, the target firmware startup file, so as to prepare for the safe startup of the computer system, and finally ensure the security of the entire computer system after startup.
[0036] In a second aspect, an embodiment of the present application provides a computer system startup device, the device comprising:
[0037] A first verification module, used to verify information in the firmware layer of the computer system according to information in the solidified area of the computer system;
[0038] A second verification module is used to verify the trusted cryptographic module firmware in the processor in the computer system according to the information in the firmware layer when the information verification passes;
[0039] The startup module is used to control the startup of the computer system according to the trusted cryptographic module firmware when the trusted cryptographic module firmware passes the verification.
[0040] In a third aspect, an embodiment of the present application further provides a computer system, the computer system comprising a memory and a processor, the memory storing a computer program, and the processor implementing the steps of the method of any embodiment of the first aspect when executing the computer program.
[0041] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method of any embodiment in the above-mentioned first aspect are implemented.
[0042] In a fifth aspect, an embodiment of the present application further provides a computer program product, the computer program product comprising a computer program, which, when executed by a processor, implements the steps of the method of any embodiment of the first aspect above.
[0043] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 is the internal structure diagram of a computer device in one embodiment;
[0045] Figure 2 is the schematic flowchart of a computer system startup method in one embodiment;
[0046] Figure 3 is the schematic flowchart of a computer system startup method in another embodiment;
[0047] Figure 4 is the schematic flowchart of a computer system startup method in another embodiment;
[0048] Figure 5 is the schematic flowchart of a computer system startup method in another embodiment;
[0049] Figure 6 is the schematic flowchart of a computer system startup method in another embodiment;
[0050] Figure 7 is the schematic flowchart of a computer system startup method in another embodiment;
[0051] Figure 8 is the structural block diagram of a computer system startup device in one embodiment. Detailed implementation manners
[0052] In order to make the objectives, technical solutions and advantages of this application more clear and understandable, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.
[0053] In the field of computers, the security of computer system operation is becoming increasingly important. In order to ensure the security of computer system startup, it is particularly important to perform security verification on the startup process of the computer system.
[0054] In the related art, mainly through an externally plugged dedicated circuit of the computer system to perform security verification on the startup process of the computer system to ensure the safe startup of the computer system. However, using the related art will have the problem that the safe startup process of the computer system is relatively complex. Based on this, the embodiments of this application provide a computer system startup method, which can reduce the complexity of the computer system safe startup process.
[0055] The computer system startup method provided by the embodiments of this application can be applicable to Figure 1The computer system shown. Optionally, the computer system includes a central processing unit, i.e., a processor; the computer system may be a computer device or a server, etc., wherein the computer device may be, but not limited to, various personal computers, laptops, smart phones, tablet computers, etc.; the server may be, but not limited to, an independent server or a server cluster composed of multiple servers. This embodiment does not limit the specific form of the computer system. The following embodiment will take the processor in the computer system as the execution subject to introduce the specific process of the computer system startup method.
[0056] Figure 2 FIG. 1 is a flow chart of a method for starting a computer system according to an embodiment of the present application, and the method can be implemented by the following steps:
[0057] S100: Verify information in a firmware layer of a computer system according to information in a solidified area of the computer system.
[0058] Among them, the solidified area in the computer system can be understood as a storage area in the processor of the computer system that cannot be changed permanently after the information is written, that is, the solidified area in the processor of the computer system. The information in the solidified area is relatively safe, that is, after the information is written to the solidified area, the information is not easy to be tampered with or lost. Optionally, the information written to the solidified area may include the built-in code of the processor in the computer system and related information of other hardware structures, etc., which is not limited in the embodiments of the present application. In the embodiments of the present application, the information in the solidified area can be understood as solidified information.
[0059] Specifically, after the computer system is powered on, the processor in the computer system can obtain information in a fixed area in the processor in the computer system, and then verify information in the firmware layer of the computer system based on the information in the fixed area in the processor.
[0060] In one embodiment, the method for verifying information in the firmware layer of a computer system based on information in a solid-state area in a processor can be to pre-train an algorithm model, and then input both the information in the solid-state area and the information in the firmware layer of the computer system into the algorithm model, and the algorithm model outputs the verification result of the information in the firmware layer.
[0061] In another embodiment, the method for verifying the information in the firmware layer of the computer system based on the information in the solidified area of the processor can also be to decrypt the information in the firmware layer separately according to the information in the solidified area, and compare the obtained decryption processing result with the preset decryption value. If the decryption processing result is equal to the preset decryption value, it is determined that the information in the firmware layer has passed the verification; if the decryption processing result is not equal to the preset decryption value, the information in the firmware layer has failed the verification.
[0062] Optionally, the above computer system may include a hardware layer, a firmware layer, and a system layer; the information in the firmware layer may include the underlying code that connects the hardware layer and the system layer when the computer system starts up.
[0063] S200. If the information verification passes, then verify the trusted cryptographic module firmware in the processor within the computer system according to the information in the firmware layer.
[0064] In practical applications, when the information in the firmware layer passes the verification, the processor in the computer system can obtain the trusted cryptographic module (TCM) firmware from the flash memory of the processor, and according to the information in the firmware layer, use the information verification algorithm to perform a security verification on the trusted cryptographic module firmware in the processor within the computer system.
[0065] Among them, the above information verification algorithm can be a cyclic redundancy check method, a parity check method, a Hamming code check method, etc., and the embodiments of the present application do not make limitations in this regard.
[0066] It should be noted here that in the embodiments of the present application, the above trusted cryptographic module firmware may be the firmware of the trusted cryptographic module version 2.0.
[0067] S300. If the trusted cryptographic module firmware verification passes, then control the startup of the computer system according to the trusted cryptographic module firmware.
[0068] Based on the results obtained in the previous steps, when the security verification of the trusted cryptographic module firmware passes, the processor in the computer system can detect whether the computer system meets the secure startup conditions through the trusted cryptographic module firmware. If it meets the conditions, then control the computer system to start up securely. Optionally, the startup conditions may be determined according to empirical values, and the startup conditions may include information such as the minimum interval duration from the power-on moment of the computer system to the secure startup moment of the computer system, the maximum temperature of the computer system, and the minimum remaining memory space of the computer system.
[0069] The technical solution in the embodiment of the present application verifies the information in the firmware layer of the computer system according to the information in the solidified area of the computer system. If the information verification passes, the trusted cryptographic module firmware in the processor in the computer system is verified according to the information in the firmware layer. If the trusted cryptographic module firmware verification passes, the computer system startup is controlled according to the trusted cryptographic module firmware. The above method can use the information solidified in the computer system that is not easy to be tampered with or lost as a trusted basis to implement the information verification process before the computer system is started, which can improve the accuracy of information verification, thereby improving the security of the computer system after startup, and the above method can realize the safe startup of the computer system through the solidified information built into the computer system, and the method does not require the participation of other auxiliary circuits outside the computer system, thereby making the computer system The secure boot process becomes simpler, reducing the complexity of the secure boot process of the computer system; in addition, the above method can realize the information verification process before the secure boot of the computer system through the solidified information stored in the computer system, so that the information verification process is simplified, thereby speeding up the information verification speed and further speeding up the secure boot of the computer system; in addition, the above method does not require human participation, which can not only save the secure boot cost of the computer system, but also improve the accuracy of the information verification before the secure boot of the computer system. On this basis, the security of the computer system after startup can be further improved; furthermore, the above method can use the solidified information in the computer system to perform layer-by-layer verification on the entire link from the power-on of the computer system to the startup of the computer system, thereby greatly improving the security of the computer system after startup.
[0070] In some scenarios, in order to improve the accuracy of information verification in the firmware layer of a computer system, the solidified information in the computer system can be used to perform security verification. The following describes the process of verifying the information in the firmware layer of the computer system based on the information in the solidified area of the computer system. In one embodiment, the information in the solidified area includes the root public key information of the processor, and the information in the firmware layer includes the security processor startup program and the firmware startup file; Figure 3 As shown, the steps in S100 above can be implemented in the following manner:
[0071] S110 , verifying the security processor startup program through the root public key information of the processor.
[0072] In an embodiment of the present application, the information in the above-mentioned solidified area may include the root public key (ie, RootPubkey) information of the processor; the information in the above-mentioned firmware layer includes the security processor startup program and the firmware startup file.
[0073] Among them, the security processor in the computer system can be understood as a security coprocessor. In practical applications, at the initial moment, the security processor startup program is not loaded into the security processor, that is, the security processor cannot run at the initial moment. Naturally, the security processor needs to be loaded with the security processor startup program before it can start running. Therefore, in order to make the security processor run securely, before loading the security processor startup program into the security processor, the security processor startup program can be subjected to a security check first.
[0074] Among them, the processor in the computer system can perform a security check on the security processor startup program by using the root public key information of the processor and an information verification algorithm. In the embodiment of the present application, the security processor startup program is also the security processor startup loader (Platform Security Processor Boot Loader, PSP BootLoader).
[0075] In the embodiment of the present application, the processor in the computer system can decrypt the signature value in the security processor startup program through the root public key information of the processor to obtain a hash value, and then use the hash algorithm in the security processor startup program to perform a hash calculation on the public key in the security processor startup program to obtain another hash value. After that, these two hash values are compared. If these two hash values are equal, it is determined that the security check of the security processor startup program passes.
[0076] S120: If the security check of the security processor startup program passes, the firmware startup file is checked through the security processor startup program.
[0077] After it is determined that the security check of the security processor startup program passes, the processor in the computer system can use an information verification algorithm to check the firmware startup file of the computer system.
[0078] In practical applications, the startup firmware in the computer system can include an Extensible Firmware Interface (EFI) and a Unified Extensible Firmware Interface (UEFI), etc. However, in the embodiment of the present application, the startup firmware is the Basic Input Output System (BIOS) for illustration.
[0079] In the technical solution of the embodiment of the present application, the security processor startup program is verified by the root public key information of the processor. If the security processor startup program passes the verification, the firmware startup file is verified by the security processor startup program; the above method can use the information that is solidified in the computer system and is not easily tampered with or lost as a trusted basis to layer by layer verify the information in the solidified layer, which can improve the accuracy of the information verification result in the solidified layer. On this basis, the secure startup of the solidified layer of the computer system can be ensured.
[0080] The process of verifying the firmware startup file by the security processor startup program described above will be described below. In one embodiment, the above firmware startup file includes a public key certificate chain and an initialization program in the firmware startup program; as Figure 4 shown, the steps of verifying the firmware startup file by the security processor startup program in S120 above can be implemented in the following manner:
[0081] S121. Control the execution of the security processor startup program to verify the public key certificate chain.
[0082] After it is determined that the security processor startup program passes the verification, the processor in the computer system can load the security processor startup program into the security processor to control the execution of the security processor startup program to start the security processor. Further, the public key certificate chain is obtained from the flash memory of the processor in the computer system by the securely started security processor, and then the public key certificate chain in the firmware startup file is verified using an information verification algorithm.
[0083] At the same time, the computer system can also process the public key certificate chain in the firmware startup file to obtain a first verification value, and then compare the first verification value with a preset first verification threshold, and determine whether the public key certificate chain passes the verification according to the comparison result.
[0084] Among them, if the first verification value is equal to the preset first verification threshold, it is determined that the public key certificate chain passes the verification; if the first verification value is equal to the preset first verification threshold, it is determined that the public key certificate chain fails the verification. Optionally, the preset first verification threshold can be determined customarily or determined according to historical experience values, and the embodiments of the present application do not make any limitations in this regard.
[0085] In the embodiment of the present application, the firmware startup file is a signed BIOS file, that is, a bin file generated by compiling BIOS code, that is, a BIOS ROM file. Among them, the BIOS ROM file may include a public key certificate chain, a BIOS public key, a signature value of the BIOS public key, a signature algorithm, a hash value, a hash algorithm, manufacturer information, the valid time of certificate issuance, and so on.
[0086] It should be noted here that the firmware startup file can be generated by the BIOS manufacturer's server without the participation of developers. Therefore, when the firmware startup file includes a public key certificate chain, during the generation process of the firmware startup file, the contact between developers and the public key certificate chain can be reduced, thereby reducing the possibility of the public key certificate chain being tampered with or lost.
[0087] Optionally, the BIOS manufacturer's server can generate a BIOS public key (i.e., the BIOS manufacturer's public key, OEM_Pubkey) and a private key through a signature tool, and send the BIOS public key and the user information of the BIOS to the CPU manufacturer's server. The CPU manufacturer's server authenticates through the user information of the BIOS to determine whether the BIOS manufacturer's server is in its own supplier list. If it exists, it determines that the identity verification is passed. Further, the CPU manufacturer's server generates a public key certificate chain based on the BIOS public key, and then sends the public key certificate chain to the corresponding BIOS manufacturer's server according to the user information of the BIOS.
[0088] Correspondingly, the BIOS manufacturer's server can read the compiled BIOS code file through a signature tool, parse the compiled BIOS code file to obtain the key information of the BIOS in the compiled BIOS code file, then calculate the hash value of the compiled BIOS code file according to the key information of the BIOS, and then perform signature processing on the hash value of the compiled BIOS code file through the private key to obtain a signature value, and then write the signature value and the public key certificate chain into the compiled BIOS code file to obtain a signed BIOS file. Optionally, the compiled BIOS code file can be understood as the BIOS file to be signed.
[0089] Among them, the storage module of the above-mentioned BIOS manufacturer can include the file identification information of the compiled BIOS code file, the corresponding public key certificate chain, the private key, and the corresponding relationship among the three.
[0090] In the embodiment of the present application, the above public key certificate chain can be understood as a BIOS public key certificate chain, and the public key certificate chain can include information such as the public key of the BIOS, the public key length, the signature algorithm, the hash algorithm, and the signature value. Among them, the signature value in the public key certificate chain can be generated by signing the public key in the public key certificate chain using the root public key information of the processor, and the signature algorithm here corresponds to the signature algorithm in the public key certificate chain. Among them, the signature value in the above public key certificate chain can be understood as an encrypted signature value.
[0091] In addition, the computer system can also pre-train an algorithm model, and then input the root public key information of the processor, the public keys in the public key certificate chain, and the signature values in the public key certificate chain into the algorithm model to verify the public key certificate chain, and the algorithm model outputs the verification result of the public key certificate chain.
[0092] Optionally, the computer system can also verify the public key certificate chain by using an asymmetric decryption algorithm based on the root public key information of the processor, the public keys in the public key certificate chain, and the signature values in the public key certificate chain. Optionally, the asymmetric decryption algorithm can be the decryption algorithm corresponding to the asymmetric encryption algorithm, where the above asymmetric encryption algorithm can be a public key cryptography algorithm (i.e., RSA algorithm), a national standard digital signature algorithm (i.e., DSA algorithm), an elliptic curve encryption algorithm (i.e., ECC algorithm), or a key exchange algorithm (i.e., DH algorithm), etc.
[0093] S122. If the public key certificate chain passes the verification, the initialization program in the firmware startup program is verified by using the public key in the public key certificate chain.
[0094] Based on the results of the previous steps, when it is determined that the public key certificate chain passes the verification, the processor in the computer system can use the public key in the public key certificate chain and adopt an information verification algorithm to verify the initialization program in the firmware startup program.
[0095] Alternatively, when it is determined that the public key certificate chain passes the verification, the computer system can also use the public key in the public key certificate chain to process the initialization program in the firmware startup program to obtain a second verification value, and then compare the second verification value with a preset second verification threshold, and determine whether the initialization program in the firmware startup program passes the verification according to the comparison result.
[0096] Among them, if the second verification value is equal to the preset second verification threshold, it is determined that the initialization program in the firmware startup program passes the verification; if the second verification value is equal to the preset second verification threshold, it is determined that the initialization program in the firmware startup program fails the verification.
[0097] In the embodiments of the present application, the firmware startup program can be a BIOS startup code, and the BIOS startup code includes information such as the signature value, hash value, hash algorithm, and public key of the BIOS startup code. Among them, the signature value in the BIOS startup code can be obtained by performing signature calculation on the BIOS startup code according to the private key information of the BIOS.
[0098] It should be noted here that the firmware startup program can include the initialization program (i.e., FV_BB segment code) and the driver program (i.e., FV_MAIN segment code) in the BIOS startup code. Correspondingly, the signature value in the firmware startup program can include the signature value of the FV_BB segment code and the signature value of the FV_MAIN segment code.
[0099] Optionally, the signature value of the FV_BB segment code can be obtained by performing signature calculation on the FV_BB segment code according to the private key information of the BIOS; the signature value of the FV_MAIN segment code can be obtained by performing signature calculation on the FV_MAIN segment code according to the private key information of the BIOS.
[0100] In addition, the computer system can also decrypt the signature value of the initialization program in the firmware startup program according to the public key in the public key certificate chain to obtain a hash value, then perform a hash operation on the initialization program in the firmware startup program through the hash algorithm in the firmware startup program to obtain another hash value, and then compare these two hash values. If these two hash values are equal, it is determined that the initialization program in the firmware startup program passes the verification; otherwise, it is determined that the initialization program in the firmware startup program fails the verification.
[0101] In the technical solution of the embodiment of the present application, the security processor startup program is controlled to execute, and the public key certificate chain is verified. If the public key certificate chain passes the verification, the initialization program in the firmware startup program is verified by the public key in the public key certificate chain; the above method can adopt a chain-like verification method with interlocking links to layer-by-layer verify the content in the firmware startup file, which can improve the accuracy of the security verification of the firmware startup file.
[0102] In some scenarios, the public key certificate chain can be verified by using the asymmetric decryption algorithm corresponding to the RSA algorithm. The process of verifying the public key certificate chain above will be described below. In one embodiment, as Figure 5 shown, the steps of verifying the public key certificate chain in S121 can be implemented in the following manner:
[0103] S1211: Decrypt the signature value in the public key certificate chain according to the root public key information of the processor to obtain a first hash value.
[0104] In the embodiment of the present application, the processor in the computer system can decrypt the signature value in the public key certificate chain according to the root public key information of the processor by using the asymmetric public key decryption algorithm to obtain a first hash value.
[0105] S1212: Perform a hash process on the public key value in the public key certificate chain according to the hash algorithm in the public key certificate chain to obtain a second hash value.
[0106] Among them, the hash algorithm in the public key certificate chain can be obtained, and the public key value in the public key certificate chain is hashed according to the hash algorithm in the public key certificate chain to obtain a second hash value.
[0107] Optionally, the hash algorithm in the above public key certificate chain may be an irreversible encryption algorithm (such as the MD5 algorithm), a data verification algorithm (such as the CRC algorithm), or a secure hash algorithm (such as the SHA-1 algorithm, the international SHA1 algorithm, the SHA256 algorithm, the SHA284 algorithm, the SHA512 algorithm, the national cryptographic SM3 algorithm), etc., and the embodiments of the present application do not limit this.
[0108] S1213. If the first hash value is equal to the second hash value, the public key certificate chain passes the verification.
[0109] Based on the first hash value and the second hash value obtained in the previous steps, it can be further determined whether the first hash value is equal to the second hash value. If the first hash value is equal to the second hash value, it is determined that the public key certificate chain passes the verification.
[0110] In the technical solution of the embodiments of the present application, according to the root public key information of the processor, the signature value in the public key certificate chain is decrypted to obtain the first hash value. According to the hash algorithm in the public key certificate chain, the public key value in the public key certificate chain is hashed to obtain the second hash value. If the first hash value is equal to the second hash value, the public key certificate chain passes the verification. The above method can perform a security verification on the public key certificate chain to provide an effective basis for accurately and securely verifying the initialization program in the firmware startup program in the next step, and can further improve the accuracy of the verification result of the initialization program in the firmware startup program.
[0111] The process of verifying the trusted password module firmware in the processor in the computer system according to the information in the firmware layer is described below. In one embodiment, the information in the firmware layer includes the initialization program in the firmware startup program. The step of verifying the trusted password module firmware in the processor in the computer system according to the information in the firmware layer in S200 may include: controlling the execution of the initialization program in the firmware startup program, and verifying the trusted certificate in the trusted password module firmware according to the root public key information of the processor.
[0112] Specifically, the processor in the computer system may control the execution of the initialization program in the firmware startup program that has passed the verification, obtain the trusted password module firmware from the flash memory of the processor in the computer system, and then verify the trusted certificate in the trusted password module firmware according to the root public key information of the processor.
[0113] In one implementation manner, the method of verifying the trusted certificate in the trusted password module firmware according to the root public key information of the processor may be to verify the trusted certificate in the trusted password module firmware using an information verification algorithm according to the root public key information of the processor.
[0114] In another implementation manner, the method for verifying the trusted certificate in the trusted password module firmware based on the root public key information of the processor may also be to process the trusted certificate in the trusted password module firmware based on the root public key information of the processor to obtain a verification value, and then compare the verification value with the standard verification value of the trusted certificate. If the verification value is equal to the standard verification value of the trusted certificate, it is determined that the verification of the trusted certificate passes.
[0115] In the technical solution of the embodiment of the present application, the initialization program in the firmware startup program is controlled to execute, and the trusted certificate in the trusted password module firmware is verified according to the root public key information of the processor; the above method can control the initialization program that passes the verification to verify the trusted certificate, which can make the security of the trusted certificate verification process higher. At the same time, the above method can use the information that is solidified in the computer system and is not easily tampered with or lost as a trusted basis to verify the trusted certificate in the trusted password module firmware, which can improve the accuracy of the verification result of the trusted certificate.
[0116] In one embodiment, as Figure 6 shown, the steps of verifying the trusted certificate in the trusted password module firmware based on the root public key information of the processor can be implemented in the following manner:
[0117] S210. Decrypt the signature value in the trusted certificate according to the root public key information to obtain a third hash value.
[0118] Among them, the trusted certificate may include information such as the signature value, hash algorithm, and public key value of the trusted certificate.
[0119] In the embodiment of the present application, the processor in the computer system may decrypt the signature value in the trusted certificate according to the root public key information of the processor by using an asymmetric public key decryption algorithm to obtain a third hash value.
[0120] S220. Perform a hash process on the public key value in the trusted certificate according to the hash algorithm in the trusted certificate to obtain a fourth hash value.
[0121] Among them, the hash algorithm in the trusted certificate can be obtained, and the public key value in the trusted certificate is hashed according to the hash algorithm in the trusted certificate to obtain a fourth hash value.
[0122] Optionally, the hash algorithm in the above-mentioned trusted certificate may be an irreversible encryption algorithm (such as the MD5 algorithm), a data verification algorithm (such as the CRC algorithm), or a secure hash algorithm (such as the SHA-1 algorithm, the international SHA1 algorithm, the SHA256 algorithm, the SHA284 algorithm, the SHA512 algorithm, the national secret SM3 algorithm), etc. The embodiment of the present application does not make any limitations in this regard.
[0123] S230. If the third hash value is equal to the fourth hash value, the verification of the trusted certificate passes.
[0124] Based on the third hash value and the fourth hash value obtained in the previous steps, it can be further determined whether the third hash value is equal to the fourth hash value. If the third hash value is equal to the fourth hash value, it is determined that the verification of the trusted certificate passes.
[0125] In the technical solution of this application embodiment, according to the root public key information, the signature value in the trusted certificate is decrypted to obtain the third hash value. According to the hash algorithm in the trusted certificate, the public key value in the trusted certificate is hashed to obtain the fourth hash value. If the third hash value is equal to the fourth hash value, the verification of the trusted certificate in the trusted password module firmware passes. The above method can perform a security check on the trusted certificate in the trusted password module firmware to prepare for the next secure startup of the computer system, making the computer system more secure after startup.
[0126] The following describes the process of controlling the startup of the computer system according to the trusted password module firmware. In one embodiment, as Figure 7 shown, the steps of controlling the startup of the computer system according to the trusted password module firmware in S300 above can be implemented in the following manner:
[0127] S310. Control the execution of the trusted password module firmware to perform trusted computing on the target firmware startup file to obtain a trusted root.
[0128] The trusted password module is built into the processor of the computer system. In practical applications, the processor in the computer system can load the verified trusted password module firmware into the trusted password module, control the execution of the trusted password module firmware to start the trusted password module. Further, the trusted password module performs trusted computing on the target firmware startup file through a secure channel to obtain a trusted root.
[0129] Optionally, the above target firmware startup file may include, but is not limited to, the driver in the firmware startup program (i.e., the FV_MAIN segment code), the startup file of the operating system in the computer system, the initialization program of each hardware device in the computer system, and the kernel startup program of the operating system in the computer system.
[0130] S320. Determine the trusted state of the target firmware startup file according to the trusted root.
[0131] Specifically, the trusted password module in the computer system can compare the trusted root of the target firmware startup file obtained in the previous steps with the standard trusted root, and determine the trusted state of the target firmware startup file according to the comparison result.
[0132] When the trusted root of the above target firmware startup file is equal to the standard trusted root, the trusted state of the target firmware startup file can be determined to be trusted; when the trusted root of the target firmware startup file is not equal to the standard trusted root, the trusted state of the target firmware startup file can be determined to be untrusted.
[0133] In the embodiments of the present application, for the driver in the target firmware startup file, the startup file of the operating system, the initialization programs of each hardware device in the computer system, and the kernel startup program of the operating system, there can be respective corresponding standard trusted roots. At the same time, in practical applications, the above trusted roots can include the trusted measurement root, the trusted reporting root, and the trusted storage root. Correspondingly, the standard trusted roots can include the standard trusted measurement root, the standard trusted reporting root, and the standard trusted storage root.
[0134] Taking the driver in the target firmware startup file as an example, trusted computing can be performed on the driver to obtain the trusted measurement root, the trusted reporting root, and the trusted storage root of the driver, and compare the trusted measurement root of the driver with the standard trusted measurement root of the driver, compare the trusted reporting root of the driver with the standard trusted reporting root of the driver, and compare the trusted storage root of the driver with the standard trusted storage root of the driver. When the trusted measurement root of the driver is equal to the standard trusted measurement root of the driver, the trusted reporting root of the driver is equal to the standard trusted reporting root of the driver, and the trusted storage root of the driver is equal to the standard trusted storage root of the driver, determine that the trusted state of the driver is trusted; otherwise, determine that the trusted state of the driver is untrusted.
[0135] At the same time, trusted computing can be respectively performed on the startup file of the operating system, the initialization programs of each hardware device in the computer system, and the kernel startup program of the operating system in the target firmware startup file, and their respective corresponding trusted states can be determined. When the trusted states of the driver, the startup file of the operating system, the initialization programs of each hardware device in the computer system, and the kernel startup program in the target firmware startup file are all trusted, determine that the trusted state of the target firmware startup file is trusted; otherwise, determine that the trusted state of the target firmware startup file is untrusted.
[0136] It should be noted here that the method of performing trusted computing on the startup file of the operating system, the initialization programs of each hardware device in the computer system, and the kernel startup program is similar to the method of performing trusted computing on the driver, and the embodiments of the present application will not elaborate on this; at the same time, the method of determining the trusted states of the startup file of the operating system, the initialization programs of each hardware device in the computer system, and the kernel startup program is similar to the method of determining the trusted state of the driver, and the embodiments of the present application will not elaborate on this either.
[0137] S330: If the trusted state is trusted, control the execution of the target firmware startup file to complete the startup of the computer system.
[0138] Based on the results obtained in the previous steps, when it is determined that the trust status of the target firmware startup file is trustworthy, the processor in the computer system can control the execution of the target firmware startup file to complete the startup of the computer system.
[0139] The technical solution in the embodiment of the present application controls the execution of the trusted cryptographic module firmware, performs trusted calculation on the target firmware startup file to obtain a trusted root, determines the trusted state of the target firmware startup file based on the trusted root, and if the trusted state is trusted, controls the running of the target firmware startup file to complete the startup of the computer system; the above method can verify the trusted cryptographic module firmware to perform trust measurement on other firmware startup files required in the computer system startup process, that is, the target firmware startup file, to prepare for the safe startup of the computer system, and ultimately ensure the security of the entire computer system after startup; furthermore, the above method can perform layer-by-layer verification on the entire link from the power-on of the computer system to the startup of the computer system through the solidified information in the computer system, thereby greatly improving the security of the computer system after startup.
[0140] In one embodiment, the present application also provides a computer system startup method, which includes the following process:
[0141] (1) Verify the security processor startup program in the firmware layer of the computer system based on the root public key information of the processor in the hardened area of the computer system.
[0142] (2) When the security processor startup program passes the verification, the security processor startup program is controlled to be executed, and the signature value in the public key certificate chain is decrypted according to the root public key information of the processor to obtain a first hash value.
[0143] (3) According to the hash algorithm in the public key certificate chain, the public key value in the public key certificate chain is hashed to obtain a second hash value.
[0144] (4) If the first hash value is equal to the second hash value, the public key certificate chain verification passes.
[0145] (5) If the public key certificate chain is verified, the firmware boot program is verified using the public key in the public key certificate chain.
[0146] (6) When the information verification passes, the firmware startup program is controlled to execute, and the signature value in the trusted certificate is decrypted according to the root public key information to obtain a third hash value.
[0147] (7) Perform hash processing on the public key value in the trusted certificate according to the hash algorithm in the trusted certificate to obtain a fourth hash value.
[0148] (8) If the third hash value is equal to the fourth hash value, the trusted certificate verification passes.
[0149] (9) When the trusted cryptographic module firmware passes the verification, the computer system startup is controlled according to the trusted cryptographic module firmware.
[0150] The execution process of the above (1) to (9) can be specifically referred to the description of the above embodiment. The implementation principle and technical effect are similar and will not be repeated here.
[0151] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0152] Based on the same inventive concept, the embodiment of the present application also provides a computer system startup device for implementing the computer system startup method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more computer system startup device embodiments provided below can refer to the limitations on the computer system startup method above, and will not be repeated here.
[0153] In one embodiment, Figure 8 This is a schematic diagram of the structure of a computer system startup device in one embodiment of the present application. The computer system startup device provided in the embodiment of the present application can be applied to a computer system. Figure 8 As shown, the computer system startup device of the embodiment of the present application may include: a first verification module 11, a second verification module 12 and a startup module 13, wherein:
[0154] A first verification module 11 is used to verify information in the firmware layer of the computer system according to information in the solidified area of the computer system;
[0155] The second verification module 12 is used to verify the trusted cryptographic module firmware in the processor in the computer system according to the information in the firmware layer when the information verification passes;
[0156] The startup module 13 is used to control the startup of the computer system according to the trusted cryptographic module firmware when the trusted cryptographic module firmware passes the verification.
[0157] The computer system startup device provided in the embodiment of the present application can be used to execute the technical solution in the above-mentioned computer system startup method embodiment of the present application. Its implementation principle and technical effect are similar and will not be repeated here.
[0158] In one embodiment, the information in the solidified area includes the root public key information of the processor, and the information in the firmware layer includes the security processor startup program and the firmware startup file; the first verification module 11 includes: a first verification unit and a second verification unit, wherein:
[0159] A first verification unit, used to verify the security processor startup program through the root public key information of the processor;
[0160] The second verification unit is used to verify the firmware startup file through the security processor startup program when the security processor startup program is verified.
[0161] The computer system startup device provided in the embodiment of the present application can be used to execute the technical solution in the above-mentioned computer system startup method embodiment of the present application. Its implementation principle and technical effect are similar and will not be repeated here.
[0162] In one embodiment, the firmware startup file includes a public key certificate chain and an initialization program in the firmware startup program; the second verification unit includes: a certificate chain verification subunit and a program verification subunit, wherein:
[0163] The certificate chain verification subunit is used to control the execution of the security processor startup program and verify the public key certificate chain;
[0164] The program verification subunit is used to verify the initialization program through the public key in the public key certificate chain when the public key certificate chain verification passes.
[0165] The computer system startup device provided in the embodiment of the present application can be used to execute the technical solution in the above-mentioned computer system startup method embodiment of the present application. Its implementation principle and technical effect are similar and will not be repeated here.
[0166] In one embodiment, the certificate chain verification subunit is specifically used to:
[0167] Decrypting the signature value in the public key certificate chain according to the root public key information of the processor to obtain a first hash value;
[0168] Perform a hash process on the public key value in the public key certificate chain according to the hash algorithm in the public key certificate chain to obtain a second hash value;
[0169] If the first hash value is equal to the second hash value, the public key certificate chain passes the verification.
[0170] The computer system startup device provided by the embodiments of the present application can be used to execute the technical solutions in the above-mentioned computer system startup method embodiments of the present application. The implementation principles and technical effects are similar and will not be elaborated here.
[0171] In one embodiment, the information in the firmware layer includes the initialization program in the firmware startup program; the second verification module 12 includes: a trusted certificate verification unit, where:
[0172] The trusted certificate verification unit is used to control the execution of the initialization program in the firmware startup program and verify the trusted certificate in the trusted password module firmware according to the root public key information of the processor.
[0173] The computer system startup device provided by the embodiments of the present application can be used to execute the technical solutions in the above-mentioned computer system startup method embodiments of the present application. The implementation principles and technical effects are similar and will not be elaborated here.
[0174] In one embodiment, the trusted certificate verification unit is specifically used for:
[0175] Decrypt the signature value in the trusted certificate according to the root public key information to obtain a third hash value;
[0176] Perform a hash process on the public key value in the trusted certificate according to the hash algorithm in the trusted certificate to obtain a fourth hash value;
[0177] If the third hash value is equal to the fourth hash value, the trusted certificate passes the verification.
[0178] The computer system startup device provided by the embodiments of the present application can be used to execute the technical solutions in the above-mentioned computer system startup method embodiments of the present application. The implementation principles and technical effects are similar and will not be elaborated here.
[0179] In one embodiment, the startup module 13 is specifically used for:
[0180] Control the execution of the trusted password module firmware to perform trusted computing on the target firmware startup file to obtain a trusted root;
[0181] Determine the trusted state of the target firmware startup file according to the trusted root;
[0182] If the trusted state is trusted, control the operation of the target firmware startup file to complete the startup of the computer system.
[0183] The computer system startup device provided by the embodiments of this application can be used to execute the technical solutions in the above-mentioned embodiments of the computer system startup method of this application. The implementation principles and technical effects are similar and will not be elaborated here.
[0184] For the specific limitations of the computer system startup device, reference can be made to the limitations on the computer system startup method in the above text, which will not be elaborated here. Each module in the above computer system startup device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer system in hardware form or be independent of it, or be stored in the memory in the computer system in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0185] In one embodiment, a computer system is provided. The computer system can be a server, and its internal structure diagram can be seen Figure 1 as shown. The computer system includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer system is used to provide processing capabilities. The memory of the computer system includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer system is used to store the trusted password module firmware and the information in the firmware layer. The network interface of the computer system is used to communicate with an external endpoint through a network connection. When the computer program is executed by the processor, it implements a computer system startup method.
[0186] Those skilled in the art can understand that Figure 1 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer system to which the solution of this application is applied. The specific computer system may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0187] In one embodiment, a computer system is further provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, it implements the technical solutions in the above-mentioned embodiments of the computer system startup method of this application. The implementation principles and technical effects are similar and will not be elaborated here.
[0188] In one embodiment, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by the processor, it implements the technical solutions of the above-mentioned computer system startup method of this application. The implementation principles and technical effects are similar and will not be elaborated here.
[0189] In one embodiment, a computer program product is further provided, including a computer program which, when executed by a processor, implements the technical solution of the above-mentioned computer system startup method of the present application. The implementation principle and technical effects are similar and will not be elaborated here.
[0190] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided by the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0191] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0192] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A method for starting a computer system, characterized in that, The method comprises: Verifying information in a firmware layer of the computer system based on information in a solidified area of the computer system; If the information verification passes, verifying the trusted cryptographic module firmware in the processor in the computer system according to the information in the firmware layer; If the trusted cryptographic module firmware passes the verification, the computer system is controlled to start according to the trusted cryptographic module firmware.
2. The method according to claim 1, wherein The information in the solidified area includes the root public key information of the processor, and the information in the firmware layer includes the security processor startup program and the firmware startup file; and verifying the information in the firmware layer of the computer system according to the information in the solidified area of the computer system includes: Verifying the security processor startup program using the root public key information of the processor; If the security processor startup program passes the verification, the firmware startup file is verified by the security processor startup program.
3. The method according to claim 2, wherein The firmware startup file includes a public key certificate chain and an initialization program in the firmware startup program; The verifying the firmware startup file by the security processor startup program includes: Controlling the execution of the security processor startup program to verify the public key certificate chain; If the public key certificate chain passes the verification, the initialization program is verified using the public key in the public key certificate chain.
4. The method according to claim 3, characterized in that, The verifying the public key certificate chain includes: Decrypting the signature value in the public key certificate chain according to the root public key information of the processor to obtain a first hash value; Performing hash processing on the public key value in the public key certificate chain according to the hash algorithm in the public key certificate chain to obtain a second hash value; If the first hash value is equal to the second hash value, the public key certificate chain verification passes.
5. The method according to any one of claims 1-4, characterized in that, The information in the firmware layer includes an initialization program in a firmware startup program; and verifying the trusted cryptographic module firmware in the processor in the computer system according to the information in the firmware layer includes: The initialization program in the firmware startup program is controlled to execute, and the trusted certificate in the trusted cryptographic module firmware is verified according to the root public key information of the processor.
6. The method according to claim 5, wherein The verifying the trusted certificate in the trusted cryptographic module firmware according to the root public key information of the processor includes: Decrypting the signature value in the trusted certificate according to the root public key information to obtain a third hash value; Performing hash processing on the public key value in the trusted certificate according to the hash algorithm in the trusted certificate to obtain a fourth hash value; If the third Hash value is equal to the fourth Hash value, the trusted certificate verification passes.
7. The method according to any one of claims 1 to 4, characterized in that The step of controlling the computer system to start up according to the trusted cryptographic module firmware includes: Controlling the execution of the trusted cryptographic module firmware, performing trusted calculation on the target firmware startup file, and obtaining a trusted root; Determining the trusted state of the target firmware startup file according to the trusted root; If the trusted state is trusted, the target firmware startup file is controlled to run to complete the startup of the computer system.
8. A computer system startup device, characterized in that, The device comprises: The first verification module is used to verify the information in the firmware layer of the computer system according to the information in the solidified area of the computer system; The second verification module is used to verify the trusted password module firmware in the processor in the computer system according to the information in the firmware layer when the information verification is passed; The startup module is used to control the startup of the computer system according to the trusted password module firmware when the verification of the trusted password module firmware is passed.
9. A computer system, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method described in any one of claims 1-7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method described in any one of claims 1-7 are implemented.
Citation Information
Patent Citations
Firmware security detection method of electronic equipment and related equipment
CN111008379A
Safe starting method and device, electronic equipment and storage medium
CN114880048A
BIOS firmware verification method and device, server, storage medium and program product
CN115514492A
Firmware Verified Boot
US20110087872A1
Secure booting method, apparatus and system
WO2023051262A1