BIOS mirror image verification and recovery method and device, equipment and storage medium
By hashing algorithm verification on the BIOS image and recovering when the verification fails, the problem of difficulty in recovery after the BIOS image verification is solved, and the rapid and accurate recovery of the BIOS image is achieved, reducing the system security risks.
Patent Information
- Application Number
- CN202510160405.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-06-27
AI Technical Summary
In the prior art, when the verification fails in BIOS images, it is difficult to recover the verification failed mirror, resulting in increased security risks of the system due to firmware attacks or corruption.
The hashing algorithm is used to verify the main and backup images of the BIOS, and when the verification fails, the successful verification image is used for quick and accurate recovery. This method combines CPLD hardware for timeout detection to improve the accuracy of mirror tamper detection and anti-attack ability.
It effectively reduces the security risks of the system due to firmware attacks or corruption, achieves fast and accurate recovery of BIOS images, reduces the risk of system unavailability and ensures minimized downtime.
Smart Images

Figure CN120217355A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of software protection, and particularly to a method, device, equipment and storage medium for BIOS image verification and recovery. Background Art
[0002] BIOS (Basic Input / Output System) is the first software loaded when a computer starts up, and is responsible for initializing the computer's hardware system and loading the operating system. Due to the special status of the BIOS during the startup process, once it is infected by malicious code, this code will automatically run when the computer starts up, with extremely high concealment and persistence. Attackers may take advantage of vulnerabilities in the BIOS update program to provide users with BIOS update files containing malicious code for download and installation. Once users install these tampered BIOS update files, the malicious code will be implanted into the BIOS. In some cases, attackers may directly write malicious code into the BIOS chip by physically contacting the computer and using special burning equipment. This method requires the attacker to have a relatively high technical level and the opportunity to physically contact the computer. Once the BIOS is infected by malicious code, this code will automatically run when the computer starts up, and can bypass the security protection mechanism of the operating system, steal sensitive information, control the initial settings of hardware devices, misconfigure hardware devices, etc., resulting in serious consequences such as hardware failures or data leaks.
[0003] Attackers embed malicious code into the BIOS image so that it is loaded and executed when the system starts up, thereby obtaining persistent control. This kind of attack is difficult to be detected by conventional security software because the malicious code runs before the operating system is loaded. Attackers may delete or damage the BIOS through physical access or remote vulnerabilities, resulting in the device being unable to start. This kind of attack usually requires high privileges or physical contact, but once successful, the device will not be able to run normally. Modern BIOSs usually use digital signatures to ensure integrity and verify the signature during startup. If the signature is invalid, the loading will be refused. If the signature key is leaked or the attacker bypasses the verification mechanism, malicious code may still be loaded. Summary of the Invention
[0004] The main purpose of this application is to provide a method for BIOS image verification and recovery, aiming to solve the limitation in the existing methods that it is difficult to recover the BIOS image when the verification fails. By using a hash algorithm to verify the primary image and the backup image of the BIOS, and when the verification of the primary image or the backup image of the BIOS fails, quickly and accurately recover the failed image. This method can effectively reduce the security risks caused by firmware attacks or damages. At the same time, this method realizes the cooperation between hardware and firmware, verifies the primary image and the backup image of the BIOS, provides hardware-level timing and status latching through a complex programmable logic device (CPLD), and finally makes an image repair decision through a baseboard management controller (BMC) to form a closed-loop protection chain. The verification of the BIOS image uses the SM3 hash algorithm to verify the integrity of the primary image and the backup image, combines with the CPLD hardware for timeout detection, and improves the accuracy of image tampering detection and anti-attack ability. Selects the repair path according to the verification status of the primary image and the backup image, preferentially uses the backup image to repair the primary image. The redundant design of the primary and backup images and the automatic repair mechanism reduce the risk of system unavailability and ensure the minimization of downtime.
[0005] To achieve the above object, a method for BIOS image verification and recovery provided by this application includes the following steps:
[0006] After the primary image of the BIOS is started, use a preset hash algorithm to verify the current primary image and backup image of the BIOS;
[0007] When one of the primary image or the backup image of the BIOS has a verification failure, use the successfully verified image to recover the failed image.
[0008] In an embodiment, before the step of using a preset hash algorithm to verify the current primary image and backup image of the BIOS after the primary image of the BIOS is started, it further includes:
[0009] Start the primary image of the BIOS and record the start time of the primary image of the BIOS;
[0010] When the start time of the primary image of the BIOS does not exceed the preset value, start the verification of the primary image and the backup image of the BIOS under the condition that the primary image of the BIOS starts normally;
[0011] When the start time of the primary image of the BIOS exceeds the preset value, report that the primary image of the BIOS starts abnormally, and start the verification of the primary image and the backup image of the BIOS under the condition that the primary image of the BIOS starts abnormally.
[0012] In one embodiment, after the main image of the BIOS is started, the step of verifying the main image and the backup image of the current BIOS by using a preset hash algorithm further includes:
[0013] Calculate the hash value of the main image of the BIOS according to the encrypted hash algorithm;
[0014] Compare the calculated hash value of the main image with the pre-stored hash value to obtain the verification result of the main image of the BIOS;
[0015] After the verification of the main image of the BIOS is successful, continue to calculate the hash value of the backup image of the BIOS;
[0016] Compare the calculated hash value of the backup image with the pre-stored hash value to obtain the verification result of the backup image of the BIOS.
[0017] In one embodiment, when one of the main image or the backup image of the BIOS fails the verification, the step of using the successfully verified image to recover the failed verified image includes:
[0018] When the main image of the BIOS starts normally, and the main image of the BIOS is verified successfully and the backup image fails the verification, use the main image to recover the backup image;
[0019] When the main image of the BIOS starts normally, and the main image of the BIOS fails the verification and the backup image is verified successfully, use the backup image to recover the main image;
[0020] When the main image of the BIOS starts abnormally, and the main image of the BIOS fails the verification and the backup image is verified successfully, use the backup image to recover the main image.
[0021] In one embodiment, after the step of using the successfully verified image to recover the failed verified image when one of the main image or the backup image of the BIOS fails the verification, it includes:
[0022] When it is determined that the recovery of the backup image by the main image of the BIOS fails, report the abnormal information of the backup image;
[0023] When it is determined that the recovery of the backup image by the main image of the BIOS is successful, complete the current image verification and recovery work.
[0024] In one embodiment, after the step of using the successfully verified image to recover the failed-verification image when one of the main image or the backup image of the BIOS has a verification failure, the method further includes:
[0025] When it is determined that the recovery of the main image by the backup image of the BIOS fails, report the abnormal information of the backup image;
[0026] When it is determined that the recovery of the main image by the backup image of the BIOS is successful, restart the main image of the BIOS.
[0027] In one embodiment, the BIOS image verification and recovery method further includes:
[0028] Under the condition that the main image of the BIOS fails to start, when the main image of the BIOS is successfully verified and the backup image is failed-verified, do not use the main image to recover the backup image, and report the corresponding BIOS verification failure information;
[0029] Under the condition that the main image of the BIOS fails to start, when the main image of the BIOS is failed-verified and the backup image is failed-verified, do not recover the main image and the backup image of the BIOS;
[0030] Under the condition that the main image of the BIOS fails to start, when the main image of the BIOS is successfully verified and the backup image is successfully verified, report the abnormal information of the main image start of the BIOS;
[0031] Under the condition that the main image of the BIOS starts normally, when the main image of the BIOS is failed-verified and the backup image is failed-verified, do not recover the main image and the backup image of the BIOS, and report the verification failure information of the main image and the backup image of the BIOS;
[0032] Under the condition that the main image of the BIOS starts normally, when the main image of the BIOS is successfully verified and the backup image is successfully verified, complete the current image verification and recovery work.
[0033] In addition, to achieve the above object, the present application further provides a BIOS image verification and recovery device, and the device includes: an image verification module and an image recovery module;
[0034] The image verification module, after the main image of the BIOS starts, uses a preset hash algorithm to verify the current main image and backup image of the BIOS;
[0035] The image recovery module, when one of the main image or the backup image of the BIOS has a verification failure, uses the successfully verified image to recover the failed-verification image.
[0036] In addition, to achieve the above object, the present application further provides a BIOS image verification and recovery device, where the BIOS image verification and recovery device includes: a memory, a processor, and a BIOS image verification and recovery processing program stored on the memory and executable on the processor. When the BIOS image verification and recovery processing program is executed by the processor, the steps of the BIOS image verification and recovery method as described above are implemented.
[0037] In addition, to achieve the above object, the present application further provides a readable storage medium, where a BIOS image verification and recovery program is stored on the readable storage medium. When the BIOS image verification and recovery program is executed by a processor, the steps of the BIOS image verification and recovery method as described above are implemented.
[0038] One or more of the above technical solutions provided by the present application may have the following advantages or at least achieve the following technical effects:
[0039] The present application discloses a BIOS image verification and recovery method, device, equipment, and storage medium, which relates to the field of software protection. The technical method includes the following steps: First, based on a preset security policy, verify the primary image and the backup image of the current BIOS; when the verification of the primary image and / or the backup image of the BIOS fails, start the recovery mechanism corresponding to the primary image or the backup image of the BIOS; according to the recovery status of the primary image or the backup image of the BIOS, output a corresponding result. The present application aims to solve the limitation in the existing method that it is difficult to recover the image with verification failure when the BIOS image has a verification failure. By using a hash algorithm to verify the primary image and the backup image of the BIOS, and when the primary image or the backup image of the BIOS has a verification failure, quickly and accurately recover the image with verification failure. This method can effectively reduce the security risk caused by firmware attacks or damage to the system. At the same time, this method realizes the cooperation between hardware and firmware to verify the BIOS image, provides hardware-level timing and status latching through a complex programmable logic device (CPLD), and finally executes the repair decision through a baseboard management controller (BMC) to form a closed-loop protection chain. The verification of the BIOS image uses the SM3 hash algorithm to verify the integrity of the primary image and the backup image, combines with the CPLD hardware for timeout detection, improves the detection accuracy of image tampering and the anti-attack ability. Select the repair path according to the verification status of the primary image and the backup image, preferentially use the backup image to repair the primary image. The redundant design of the primary and backup images and the automatic repair mechanism reduce the risk of system unavailability and ensure the minimum downtime. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on the structures shown in these drawings.
[0041] Figure 1 It is a schematic flowchart of the first embodiment of the BIOS image verification and recovery method proposed by the embodiments of the present application;
[0042] Figure 2 It is a schematic flowchart of the second embodiment of the BIOS image verification and recovery method proposed by the embodiments of the present application;
[0043] Figure 3 It is a schematic flowchart of the third embodiment of the BIOS image verification and recovery method proposed by the embodiments of the present application.
[0044] The realization of the purpose of the present application, functional features and advantages will be further described in conjunction with the embodiments with reference to the accompanying drawings. Specific Embodiments
[0045] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by the present application.
[0046] It should be noted that if there are directional indications (such as up, down, left, right, front, back...) involved in the embodiments of the present application, the directional indications are only used to explain the relative position relationship and movement conditions between components in a specific posture. If the specific posture changes, the directional indications will also change accordingly.
[0047] In addition, if the embodiments of the present application involve descriptions such as "first" and "second", the descriptions of "first", "second", etc. are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, if "and / or" or "and / or" appears throughout the text, its meaning includes three parallel scenarios. Taking "A and / or B" as an example, it includes scenario A, or scenario B, or the scenario where both A and B are satisfied simultaneously. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0048] This application aims to provide a method for BIOS image verification and recovery. BIOS is the firmware loaded when the computer starts up, responsible for initializing the computer's hardware system and loading the operating system. Firmware is a software program stored in a hardware device and is considered the bridge between computer hardware and software, ensuring that the hardware can work properly and interact smoothly with the operating system. BMC is a management controller responsible for monitoring and controlling the computer's hardware. It can perform operations such as firmware upgrade and device viewing on the machine when the machine is in an off state. BMC has the ability to run independently of BIOS. Therefore, when BIOS is abnormal, BMC can still work properly. BIOS is a program on the computer motherboard, and the BIOS image is the corresponding backup or image file of this program. The BIOS image can be used to restore or update the BIOS program, thus ensuring that the computer can start up and run normally. In this application, the BIOS image is divided into the main image and the backup image of BIOS. Among them, the backup image of BIOS stores the binary code of BIOS, and the content of the backup image is exactly the same as that of the main image. CPLD is mainly responsible for hardware-level timing and monitoring whether the BIOS startup times out (for example, if there is no response within 10 seconds, it is determined as abnormal); CPLD is also responsible for status latching and recording the image startup result through registers (such as "main image startup timeout").
[0049] When the computer starts up normally, the BIOS will first load and execute the Power-On Self-Test (POST) program to ensure that all hardware is working properly. The system verifies the primary and backup images of the BIOS, calculates the checksum (such as MD5, SHA-1, etc.) of the primary and backup images of the BIOS, and compares it with the pre-stored correct checksum to detect whether the primary and backup images of the BIOS have been tampered with or damaged. When the computer starts up normally and both the primary and backup images of the BIOS are normal, the BMC will not perform additional verification or repair operations, thus not increasing the additional boot time. When only the backup image of the BIOS has an abnormal verification, only the primary image of the BIOS is used to repair the backup image, and at the same time, the BMC will not perform additional repair operations on the backup image, and will not increase the additional boot time. This design also ensures that the computer can start up quickly under normal circumstances and can be restored in a timely manner when an abnormality occurs.
[0050] If the BIOS fails to start up properly (such as timeout in loading, error messages, etc.), the BMC will intervene immediately. The BMC will attempt to access the primary and backup images of the BIOS and verify them. If the verification of the primary image is abnormal, the BMC will attempt to verify the backup image. If the verification of the backup image is also abnormal, the BMC will generate corresponding alarms and reports to remind the user that there is a problem with the BIOS image and it needs to be repaired or restored. The BMC usually involves restoring the primary image data from the backup image of the BIOS. The automatic recovery process does not require manual operation by the user and has the characteristics of security, simplicity, and imperceptibility. The user only needs to confirm the recovery operation after receiving the alarms and reports from the BMC. In some cases, the automatic recovery mechanism may not be able to successfully recover the BIOS image. At this time, the user needs to perform a manual recovery operation. Manual recovery usually involves downloading the correct BIOS image file to a storage medium such as a USB flash drive, and then selecting to boot from the USB flash drive and perform the recovery operation from the BIOS setup menu. When performing a manual recovery, the user needs to ensure that the downloaded BIOS image file matches the computer model and follow the manufacturer's guidelines for operation. When the BIOS fails to start up properly, the BMC will generate corresponding alarms and reports and promptly remind the user through system logs, email notifications, or remote management interfaces, etc. The user can understand the status of the BIOS image based on the information in the alarms and reports and take corresponding measures for recovery or repair. The verification and recovery process of the primary and backup images of the BIOS involves the cooperation of the BIOS and the BMC, aiming to enhance the security and stability of the computer system. By using an independent BMC module to verify the BIOS image and automatically or manually perform recovery operations when an abnormality occurs, it can effectively prevent the implantation of malicious code in the normal BIOS in a BIOS-level Trojan attack. At the same time, the good interaction and efficient boot time design ensure the convenience and experience of the user during use.
[0051] The present application proposes a BIOS image verification and recovery method for the first embodiment. Please refer to Figure 1 The BIOS image verification and recovery method includes steps S10 to S20:
[0052] Step S10: After the main image of the BIOS is started, use a pre-set hash algorithm to verify the main image and the backup image of the current BIOS.
[0053] Step S20: When verification fails for one of the main image or the backup image of the BIOS, use the image with successful verification to recover the image with failed verification.
[0054] In this embodiment, when the computer is powered on and started, the main image of the BIOS is first loaded into the memory. The main image contains the basic instructions and configuration information required for the computer to start. It is responsible for initializing the computer's hardware devices, setting the memory address space, loading the operating system and other key tasks. During the process of starting the main image, the system will perform a series of self-check operations to ensure the normal operation of the hardware devices and the integrity of the BIOS image.
[0055] Step S10: When the computer starts, the main image of the BIOS is first loaded and started. The main image is responsible for initializing the computer's hardware devices and loading the operating system. The system uses pre-set hash algorithms such as MD5, SHA-1, SHA-256, etc. These algorithms are all recognized in the industry as methods for verifying file integrity. The system performs a hash operation on the main image and the backup image of the current BIOS to generate corresponding hash values. These hash values are used to compare with the pre-set correct hash values to verify the integrity of the image file. The system compares the calculated hash values with the pre-set or previously stored correct hash values. If the two match, it means that the image file has not been tampered with or damaged, and the verification is successful; if they do not match, it means that the image file may have problems and the verification fails.
[0056] In step S20, if the hash values of the primary image or the backup image do not match, the image is determined to be a failed-verification image. The system selects the successfully-verified image as the recovery source. If the primary image fails verification, the backup image is used for recovery; if the backup image fails verification, the primary image is used for recovery (although in most cases, the primary image has been successfully started, this step is still necessary for integrity considerations). The system reads the successfully-verified image file from the storage medium (such as a hard disk, flash memory, etc.) and writes it to the storage area where the failed-verification image is located. This operation usually involves programming and writing to the BIOS chip, so it is necessary to ensure the accuracy and security of the operation. After the recovery operation is completed, the system restarts the BIOS and verifies whether the recovered image file can be started and run normally. This usually involves re-initializing the computer hardware devices and loading the operating system. If the recovery is successful, the computer will continue to run normally. If the recovery fails, further measures may need to be taken, such as contacting the computer manufacturer or professional technicians for troubleshooting and repair.
[0057] Further, in this embodiment, before the step of verifying the primary image and the backup image of the current BIOS using a preset hash algorithm after the primary image of the BIOS is started, the following steps are also included:
[0058] Start the primary image of the BIOS and record the startup time of the primary image of the BIOS;
[0059] When the startup time of the primary image of the BIOS does not exceed the preset value, start the verification of the primary image and the backup image of the BIOS under the condition that the primary image of the BIOS starts normally;
[0060] When the startup time of the primary image of the BIOS exceeds the preset value, report that the primary image of the BIOS starts abnormally, and start the verification of the primary image and the backup image of the BIOS under the condition that the primary image of the BIOS starts abnormally.
[0061] In this embodiment, in the verification process of the primary image and the backup image of the BIOS, a logic for determining the verification method according to the startup time of the primary image of the BIOS is added. When the computer is powered on or restarted, the BIOS (Basic Input Output System), as a bridge between the hardware and the operating system, is first loaded and executed. In this step, the system attempts to start from the primary image of the BIOS (usually stored in the non-volatile memory on the motherboard, such as EEPROM or Flash memory).
[0062] During the startup process, the system records the time from when the BIOS starts execution until it completes the POST (Power-On Self-Test) and enters the operating system loading phase. This time is commonly referred to as the BIOS startup time or POST time. CPLD hardware timer starts: After the system is powered on, the hardware timer (such as a 32-bit counter) built into the CPLD immediately starts timing. The clock source is the motherboard crystal oscillator (such as 25 MHz), with an accuracy reaching the microsecond level. BIOS startup completed: After the BIOS main image starts normally, it notifies the CPLD to stop timing by writing to a specific register of the CPLD (such as 0x3F8) or triggering a change in the GPIO pin level (such as pulling up GPIO15). Time recording: The CPLD stores the actual startup time (the count value when the timer stops) in the timeout register and converts it to milliseconds (for example, a count value of 250000 corresponds to 10 ms).
[0063] The system internally presets a threshold for the BIOS startup time, which is set based on the time required for the BIOS under normal startup conditions. Once the BIOS startup time is recorded, the system compares this time with the preset threshold. If the startup time does not exceed the preset value: This indicates that the BIOS main image has started normally without obvious delays or errors. In this case, the system proceeds to the next verification process. If the startup time exceeds the preset value: This indicates that the BIOS main image has started abnormally, and there may be hardware failures, software errors, or malicious attacks, etc. In this case, the system immediately reports the abnormal BIOS startup and jumps to the exception handling process.
[0064] When the BIOS main image starts normally, the system verifies the current BIOS main image and backup image according to the pre-set security policy. This verification process includes integrity verification: checking whether the BIOS image has been tampered with or damaged, which is usually achieved by calculating the hash value of the image and comparing it with the known and trusted hash value; version verification: ensuring that the version of the BIOS is consistent with the expected version to prevent incompatible or outdated versions from being loaded; function test: testing the functions of the BIOS to ensure that all necessary hardware initialization and configuration can be correctly executed.
[0065] When the BIOS main image starts abnormally, the system starts a special verification process. This process includes error log analysis: checking the error logs generated during the BIOS startup process to obtain more information about the cause of the startup failure; hardware diagnosis: if the backup image verification fails, the system may enter the hardware diagnosis mode to check for hardware failures; user notification and recovery: the system may display an error message to the user and provide options to recover or repair the BIOS, including using external tools to re-flash the BIOS image or contacting technical support.
[0066] Based on the first embodiment of this application, in the second embodiment of this application, the same or similar content as that in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. Please refer to Figure 2 , in this embodiment, step S10, the step of verifying the current main image and standby image of the BIOS by using a pre-set hash algorithm after the main image of the BIOS is started, further includes:
[0067] Step S11, calculate the hash value of the main image of the BIOS according to the encrypted hash algorithm;
[0068] Step S12, compare the calculated hash value of the main image with the pre-stored hash value to obtain the verification result of the main image of the BIOS;
[0069] Step S13, after the verification of the main image of the BIOS is successful, continue to calculate the hash value of the standby image of the BIOS;
[0070] Step S14, compare the calculated hash value of the standby image with the pre-stored hash value to obtain the verification result of the standby image of the BIOS;
[0071] Specifically, in this embodiment, in order to ensure the stability and security of the system, modern computer systems often adopt a dual-BIOS image design, that is, a main image and a standby image. This design can automatically switch to the standby image when the main image has problems, thus avoiding system crashes. However, how to ensure the integrity and correctness of these two images has become an urgent problem to be solved. Therefore, based on the pre-set security policy, it is particularly important to verify the main image and standby image of the currently running BIOS.
[0072] Step S11, calculate the hash value of the main image of the BIOS according to an encrypted hash algorithm. A hash algorithm is a function that maps data of any length to data of a fixed length. In BIOS image verification, we need to select an encrypted hash algorithm to ensure data integrity and security. Common hash algorithms include SHA-1, SHA-256, MD5, etc. Among them, SHA-256 is widely used in BIOS image verification due to its high security and relatively fast calculation speed. The SHA-256 algorithm is a secure hash algorithm released by NIST (National Institute of Standards and Technology). Its design focuses on providing sufficient security and scalability. It is one of the most widely used hash algorithms globally, and no effective attack method has been found to break its security. The SM3 algorithm is a cryptographic hash function independently developed in China. Its design concept integrates the advantages of the MD5 and SHA series algorithms and incorporates new cryptographic research results. The SM3 algorithm has high security and can resist various attacks, including collision attacks, differential analysis, linear analysis, etc. In the same environment, its security is comparable to that of SHA-256. The SM3 algorithm is mainly applied in the field of information security in China, such as digital signatures, data integrity verification, random number generation, etc. At the same time, it is also used in some specific commercial applications, such as finance, e-commerce, etc. Since SM3 is a hash algorithm completely independently developed in China, it is more suitable for use in various domestic scenarios. After selecting the appropriate hash algorithm, we need to calculate the hash value of the main image of the BIOS. This step is usually implemented through specialized hash calculation tools or libraries. During the calculation process, the file content of the main image of the BIOS needs to be used as input, and a fixed-length hash value is generated through the hash algorithm. This hash value will be used as the unique identifier of the main image of the BIOS for subsequent verification processes. The calculated hash value needs to be securely stored for comparison in subsequent verification processes. Usually, this hash value is stored in the non-volatile memory of the system, such as a hard disk, SSD, or NVRAM, etc. At the same time, to ensure the security of the hash value, it also needs to be encrypted to prevent malicious tampering.
[0073] Step S12: Compare the calculated hash value of the primary image with the pre-stored hash value to obtain the verification result of the primary image of the BIOS. Before performing the hash value comparison, we need to first obtain the pre-stored hash value of the BIOS primary image. This pre-stored hash value is usually generated during the BIOS image production or update process and is stored in the secure area of the system. To ensure its security, the pre-stored hash value also needs to be encrypted. After obtaining the pre-stored hash value, we need to compare it with the calculated hash value. This step is usually implemented through a dedicated verification tool or library. During the comparison process, if the two hash values are exactly the same, it indicates that the integrity and correctness of the primary image of the BIOS have been verified; if the two hash values are different, it indicates that the primary image of the BIOS may have been tampered with or damaged, and corresponding processing is required. Regardless of the verification result, it needs to be recorded. If the verification is successful, information such as the successful time and hash value can be recorded; if the verification fails, the reason for failure, time, etc. need to be recorded, and the corresponding alarm or recovery mechanism is triggered.
[0074] Step S13: After the verification of the primary image of the BIOS is successful, continue to calculate the hash value of the backup image of the BIOS. After the verification of the primary image of the BIOS is successful, we need to obtain the backup image of the BIOS. This backup image is usually stored in the non-volatile memory of another part of the system, such as another partition of the hard disk, another area of the SSD, or another part of the NVRAM, etc. To ensure its availability, the backup image needs to be quickly accessed and loaded when the primary image has problems. After obtaining the backup image, we need to calculate its hash value. This step is the same as the process of calculating the hash value of the primary image. The same hash algorithm needs to be selected and a dedicated hash calculation tool or library is used to implement it. The calculated hash value will be used as the unique identifier of the backup image for subsequent verification processes.
[0075] Step S14: Compare the calculated hash value of the standby image with the pre-stored hash value to obtain the verification result of the standby image of the BIOS. Similar to the verification process of the primary image, before comparing the hash value of the standby image, we need to first obtain the pre-stored hash value of the standby image of the BIOS. This pre-stored hash value is also generated during the BIOS image production or update process and is stored in the secure area of the system. After obtaining the pre-stored hash value, we need to compare it with the calculated hash value of the standby image. This step is also implemented through a dedicated verification tool or library. During the comparison process, if the two hash values are exactly the same, it indicates that the integrity and correctness of the standby image of the BIOS have been verified; if the two hash values are different, it indicates that the standby image of the BIOS may have been tampered with or damaged, and corresponding processing is required. The verification result of the standby image also needs to be recorded. If the verification is successful, information such as the successful time and hash value can be recorded; if the verification fails, the reason for failure, time, etc. need to be recorded, and the corresponding alarm or recovery mechanism is triggered. At the same time, if the standby image verification fails, it is also necessary to consider whether operations such as image recovery or re-production are required.
[0076] Based on the first embodiment and / or the second embodiment of the present application, in the third embodiment of the present application, the same or similar content as in the above-mentioned first and second embodiments can be referred to the above introduction and will not be repeated hereinafter. Please refer to Figure 3 , in this embodiment, step S20, the step of using the successfully verified image to recover the failed-verified image when one of the primary image or the standby image of the BIOS fails verification includes:
[0077] Step S21: When the primary image of the BIOS starts normally, and the primary image of the BIOS is successfully verified and the standby image fails verification, use the primary image to recover the standby image;
[0078] Step S22: When the primary image of the BIOS starts normally, and the primary image of the BIOS fails verification and the standby image is successfully verified, use the standby image to recover the primary image;
[0079] Step S23: When the primary image of the BIOS fails to start, and the primary image of the BIOS fails verification and the standby image is successfully verified, use the standby image to recover the primary image.
[0080] Specifically, in this embodiment, the primary mirror is typically used for normal startup and configuration, while the backup mirror serves as a redundant backup of the primary mirror and provides an alternative solution when the primary mirror has problems. However, due to various reasons (such as hardware failures, software errors, virus attacks, etc.), the BIOS mirror may become corrupted or the verification may fail. When this happens, it is particularly important to use the mirror with successful verification to recover the mirror with failed verification. When the BIOS mirror is written to the storage device, a verification value is usually generated, such as CRC (Cyclic Redundancy Check), MD5, etc. At each startup, the system recalculates the verification value of the current mirror and compares it with the pre-stored verification value. If the two are consistent, it means the mirror is complete and has not been tampered with, and the verification is successful; otherwise, the verification fails. When it is detected that the verification of a certain mirror fails, the system will perform an overwriting write operation using another mirror with successful verification, that is, copy the mirror data with successful verification completely to the mirror storage area with failed verification, so as to achieve the recovery of the faulty mirror.
[0081] Step S21, the BIOS primary mirror starts up normally, the primary mirror verification is successful while the backup mirror verification fails. When the computer starts up, the primary mirror of the BIOS can start up normally, and it is verified that the primary mirror is not damaged or tampered with. However, problems are found with the backup mirror during the verification process, such as being damaged, incomplete, or the verification code not matching. In this case, since the primary mirror is still available and reliable, the system will use the primary mirror to recover or repair the backup mirror. This usually involves copying a copy of the primary mirror to the location of the backup mirror, or regenerating the backup mirror to ensure its integrity and accuracy. This can maintain the effectiveness of the BIOS dual-mirror mechanism so that when the primary mirror has problems, it can quickly switch to the backup mirror, thus avoiding system downtime or failures.
[0082] Step S22, the BIOS primary mirror starts up normally, but the primary mirror verification fails while the backup mirror verification is successful. Although the primary mirror can start the computer, problems are found with the primary mirror during the verification process, such as being damaged or the verification code not matching. At the same time, the backup mirror is verified to be complete and not tampered with. In this case, the system will use the backup mirror to recover or replace the primary mirror. This usually involves copying a copy of the backup mirror to the location of the primary mirror, or regenerating the primary mirror to ensure its integrity and accuracy. This ensures the reliability and stability of the primary mirror so that the computer system can start up and run normally when needed.
[0083] Step S23, the main BIOS image fails to start, and the verification of the main image fails while the verification of the backup image succeeds. When the computer starts up, the main image of the BIOS cannot work properly, resulting in the system being unable to start. At the same time, it is confirmed through verification that there is a problem with the main image. However, the backup image is confirmed to be complete and untampered with through verification. In this case, since the main image cannot start and is damaged, the system will use the backup image to restore or replace the main image. This usually involves loading the backup image to the location of the main image, or reconfiguring the BIOS to use the backup image as the main image. This ensures the availability and reliability of the computer system. Even if there is a problem with the main image, the system can be started and restored through the backup image.
[0084] Further, in this embodiment, after the step S20, the step of using the image with successful verification to restore the image with failed verification when one of the main image or the backup image of the BIOS has a verification failure includes:
[0085] When it is determined that the restoration of the backup image by the main image of the BIOS fails, report the abnormal information of the backup image;
[0086] When it is determined that the restoration of the backup image by the main image of the BIOS is successful, complete the current image verification and restoration work.
[0087] Specifically, in this embodiment, when one of the main image or the backup image of the BIOS has a verification failure and attempts to use the image with successful verification to restore the image with failed verification, some subsequent steps need to be executed to ensure the stability and reliability of the system.
[0088] When the main image of the BIOS attempts to restore the backup image, the restoration may fail due to various reasons (such as hardware failure, storage medium damage, errors during the restoration process, etc.). The system should detect the result of the restoration operation and determine whether the backup image has been successfully restored. If the restoration fails, the system should immediately report the abnormal information of the backup image. This can be achieved through system logs, alarm messages, or specific error codes. The reported abnormal information should contain sufficient details so that technicians can quickly locate the problem and take appropriate solutions. Notify relevant personnel in a timely manner that there is a problem with the backup image so that they can take measures to repair or replace it. Prevent the system from being unable to start or restore from the backup image in the future due to damage to the backup image.
[0089] When the main image of the BIOS successfully restores the backup image, the system needs to confirm the effectiveness of the restoration operation and update the relevant system status information. The system should re-verify the restored backup image to ensure its integrity and accuracy. If the verification is successful, the system should update the BIOS configuration information and mark the restored backup image as available. At the same time, the system should delete any temporary files or log information related to the restoration operation to keep the system clean and efficient. After completing the current image verification and restoration work, the system should continue to monitor the status of the BIOS image and perform verification and update operations regularly to ensure the long-term stability and reliability of the system. If any abnormalities or problems are found during subsequent use, the system should immediately take measures to repair them or report them to relevant personnel.
[0090] Further, after the step of restoring the failed-verification image with the successfully-verified image when one of the main image or the backup image of the BIOS has a verification failure, the method further includes:
[0091] When it is determined that the restoration of the main image using the backup image of the BIOS fails, report the abnormal information of the backup image;
[0092] When it is determined that the restoration of the main image using the backup image of the BIOS is successful, restart the main image of the BIOS.
[0093] Specifically, in this embodiment, different scenarios that may occur during the BIOS image verification and restoration process, as well as the corresponding operations and impacts, are covered.
[0094] During the computer startup process, the BIOS attempts to load the main image for startup but fails. This may be caused by reasons such as a corrupted main image file, incorrect BIOS settings, or hardware failures. Subsequently, the system attempts to restore the main image using the backup image, but the restoration process fails. This may be due to problems with the backup image itself or other errors during the restoration process. The BIOS fails to successfully start the main image, and the system records the startup abnormal information. The system verifies the main image and the backup image and finds that the main image verification fails while the backup image verification is successful. The system attempts to restore the failed-verification main image using the successfully-verified backup image. During the restoration process, the system detects that the restoration fails. This may be due to hidden defects in the backup image, improper restoration tools or methods, hardware failures, etc. The system reports the abnormal information of the backup image, indicating that although the backup image verification is successful, the restoration of the main image fails. At the same time, the system also provides some additional diagnostic information to help technicians further locate the problem.
[0095] During the computer startup process, the BIOS attempts to load the primary image for startup but fails. Subsequently, the system successfully restores the primary image with verification failure using the verified backup image. This means that the backup image not only passes verification but also encounters no problems during the restoration process. When the BIOS fails to successfully start the primary image, the system records the startup exception information. The system verifies the primary image and the backup image and finds that the primary image fails verification while the backup image passes verification. The system attempts to use the verified backup image to restore the primary image with verification failure. During the restoration process, the system detects that the restoration has been successfully completed. This means that the primary image has been successfully restored and both the data integrity and the checksum match. The system attempts to restart the primary image of the BIOS to verify whether the restoration is successful. If the primary image can be successfully started and works properly, it indicates that the restoration process has been successfully completed. The system records the restoration result for subsequent reference and auditing. This helps technicians understand the status and history of the BIOS image for further maintenance and management when needed. For example, a user encounters a problem with abnormal BIOS startup when starting the computer. The technician discovers through verification that the primary image is damaged while the backup image passes verification. Subsequently, the technician successfully restores the primary image using the backup image and restarts the BIOS. The computer starts successfully and works properly, and the user is satisfied. The technician records the restoration result for subsequent reference and auditing.
[0096] Based on the first embodiment and / or the second embodiment and / or the third embodiment of the present application, in the fourth embodiment of the present application, for the same or similar content as in the above-mentioned first embodiment, second embodiment, and third embodiment, reference can be made to the above introduction and will not be elaborated hereinafter. In this embodiment, the BIOS image verification and restoration method further includes:
[0097] Under the condition of abnormal startup of the primary image of the BIOS, when the primary image of the BIOS passes verification and the backup image fails verification, the backup image is not restored using the primary image, and the corresponding BIOS verification failure information is reported;
[0098] Under the condition of abnormal startup of the primary image of the BIOS, when the primary image of the BIOS fails verification and the backup image fails verification, neither the primary image nor the backup image of the BIOS is restored;
[0099] Under the condition of abnormal startup of the primary image of the BIOS, when the primary image of the BIOS passes verification and the backup image passes verification, the abnormal startup information of the primary image of the BIOS is reported;
[0100] When the main image of the BIOS fails the checksum while the main image of the BIOS boots normally and the backup image also fails the checksum, do not recover the main image and the backup image of the BIOS, and report the information that the main image and the backup image of the BIOS fail the checksum;
[0101] When the main image of the BIOS boots normally and the main image of the BIOS passes the checksum and the backup image also passes the checksum, complete the current image checksum and recovery work.
[0102] Specifically, in this embodiment, the steps of using the image that passes the checksum to recover the image that fails the checksum under different conditions and the relevant actual scenarios will be elaborated in detail, and the subsequent processing flow after recovery will be supplemented.
[0103] During the computer startup process, the BIOS attempts to load the main image for startup but fails. This may be caused by various reasons, such as the main image file being corrupted, incorrect BIOS settings, hardware failures, etc. Although the startup fails, the system then checks the main image and finds that its data is not corrupted and the checksum matches. However, when the system attempts to check the backup image, it is found that the data of the backup image is corrupted or the checksum does not match. Detection of startup anomaly: The BIOS fails to successfully start the main image, and the system records the startup anomaly information. The system checks the main image and finds that the data is complete and the checksum matches. The system checks the backup image and finds that the data is corrupted or the checksum does not match. Decision and reporting: Since the main image, although passing the checksum, cannot be started and the backup image fails the checksum, the system decides not to use the main image to recover the backup image. At the same time, the system reports the BIOS checksum failure information, indicating that the backup image is corrupted, and reminds the technician to further check the reason why the main image cannot be started.
[0104] During the computer startup process, the BIOS attempts to load the main image for startup but fails. Subsequently, the system checks the main image and the backup image, and both are found to have corrupted data or mismatched checksums. Detection of startup anomaly: The BIOS fails to successfully start the main image, and the system records the startup anomaly information. The system checks the main image and finds that the data is corrupted or the checksum does not match. The system checks the backup image and also finds that the data is corrupted or the checksum does not match. Since both the main image and the backup image fail the checksum, the system decides not to perform a recovery operation on them. At the same time, the system reports the BIOS checksum failure information, indicating that both the main image and the backup image are corrupted.
[0105] During the computer startup process, the BIOS attempts to load the primary image for startup but fails. However, when the system verifies the primary image and the backup image, it finds that their data is complete and the checksum matches. Detecting a startup anomaly, the BIOS fails to successfully start the primary image, and the system records the startup anomaly information. The system verifies the primary image and finds that the data is complete and the checksum matches. The system verifies the backup image and also finds that the data is complete and the checksum matches. Although the primary image cannot be started, the system reports the startup anomaly information of the BIOS primary image and indicates that the backup image is available and the verification is successful. Although the backup image passes the verification.
[0106] During the computer startup process, the BIOS successfully loads the primary image and starts it. However, during the subsequent verification process, the system finds that the data of both the primary image and the backup image is corrupted or the checksum does not match. The BIOS successfully loads the primary image and starts it, and the system works normally. During the subsequent verification process, the system finds that the data of the primary image is corrupted or the checksum does not match (although it has been successfully started). The system verifies the backup image and also finds that the data is corrupted or the checksum does not match. Although the current system can work normally (because the primary image has been successfully started), the system does not perform a recovery operation on the primary image and the backup image. At the same time, the system reports the BIOS verification failure information, indicating that both the primary image and the backup image are corrupted even though the primary image starts normally. Although the current system can work normally, technicians need to take measures as soon as possible to repair or replace the corrupted images.
[0107] For other embodiments or specific implementation manners of the device of this application, reference may be made to the above method embodiments, which will not be elaborated here.
[0108] The above are only the preferred embodiments of this application, and do not limit the patent scope of this application. Any equivalent structure or equivalent process transformation made using the content of the specification and drawings of this application, or directly or indirectly applied in other related technical fields, is equally included in the patent scope of this application. This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
Claims
1. A BIOS image verification and recovery method, characterized in that: The method comprises the following steps: After the main image of the BIOS is started, the main image and the backup image of the current BIOS are verified using a preset hash algorithm; When one of the primary image or the backup image of the BIOS fails to be verified, the image that has failed to be verified is restored by using the image that has passed the verification.
2. The method according to claim 1, characterized in that Before the step of verifying the primary image and the backup image of the current BIOS by using a preset hash algorithm after the primary image of the BIOS is started, the method further includes: Starting the main image of the BIOS and recording the startup time of the main image of the BIOS; When the startup time of the primary image of the BIOS does not exceed a preset value, start the verification of the primary image and the backup image of the BIOS under normal conditions of the primary image of the BIOS startup; When the startup time of the primary image of the BIOS exceeds a preset value, the primary image startup abnormality of the BIOS is reported, and the primary image and the backup image of the BIOS are checked under the primary image startup abnormality condition of the BIOS.
3. The method according to claim 2, characterized in that The step of verifying the primary image and the backup image of the current BIOS by using a preset hash algorithm after the primary image of the BIOS is started also includes: Calculate the hash value of the master image of the BIOS according to the encrypted hash algorithm; Comparing the calculated hash value of the master image with the pre-stored hash value to obtain a verification result of the master image of the BIOS; After the primary image of the BIOS is successfully verified, continue to calculate the hash value of the backup image of the BIOS; The calculated hash value of the backup image is compared with the pre-stored hash value to obtain a verification result of the backup image of the BIOS.
4. The method according to claim 3, characterized in that When one of the primary image or the backup image of the BIOS fails to be verified, the step of using the image that succeeded in verification to recover the image that failed to be verified includes: Under the condition that the main image of the BIOS is started normally, when the main image verification of the BIOS succeeds and the backup image verification fails, using the main image to restore the backup image; Under the condition that the main image of the BIOS is started normally, when the main image verification of the BIOS fails and the backup image verification succeeds, using the backup image to restore the main image; Under abnormal conditions of the main image startup of the BIOS, when the main image verification of the BIOS fails and the backup image verification succeeds, the backup image is used to restore the main image.
5. The method according to claim 4, characterized in that After the step of restoring the image that failed verification by using the image that succeeded verification when one of the primary image or the backup image of the BIOS fails verification, the method further comprises: When it is determined that the backup image cannot be restored through the primary image of the BIOS, reporting abnormal information of the backup image; When it is determined that the backup image is restored successfully through the primary image of the BIOS, the current image verification and restoration work is completed.
6. The method according to claim 5, characterized in that After the step of restoring the image that failed the verification by using the image that succeeded the verification when one of the primary image or the backup image of the BIOS fails the verification, the method further includes: When it is determined that the restoration of the primary image through the backup image of the BIOS fails, reporting abnormal information of the backup image; When it is determined that the main image is restored successfully through the backup image of the BIOS, the main image of the BIOS is restarted.
7. The method according to claim 1, characterized in that The BIOS image verification and recovery method further includes: Under abnormal conditions of the main image startup of the BIOS, when the main image verification of the BIOS succeeds and the backup image verification fails, the backup image is restored without using the main image, and corresponding BIOS verification failure information is reported; When the primary image of the BIOS fails to be verified and the backup image fails to be verified under the abnormal condition of the primary image startup of the BIOS, the primary image and the backup image of the BIOS are not restored; Under the condition that the primary image startup of the BIOS is abnormal, when the primary image verification of the BIOS succeeds and the backup image verification succeeds, reporting the primary image startup abnormality information of the BIOS; Under the condition that the main image of the BIOS is started normally, when the main image verification of the BIOS fails and the backup image verification fails, the main image and the backup image of the BIOS are not restored, and the main image and the backup image verification failure information of the BIOS is reported; Under the condition that the main image of the BIOS starts normally, when the main image verification and the backup image verification of the BIOS succeed, the current image verification and recovery work is completed.
8. A BIOS image verification and recovery device, characterized in that: The device comprises: an image verification module, an image recovery module and a result output module; An image verification module, after the main image of the BIOS is started, verifies the main image and the backup image of the current BIOS using a preset hash algorithm; The image recovery module uses the image that succeeded in verification to recover the image that failed in verification when one of the primary image or the backup image of the BIOS fails in verification.
9. A BIOS image verification and recovery device, characterized in that: The BIOS image verification and recovery device comprises: a memory, a processor, and a BIOS image verification and recovery processing program stored in the memory and executable on the processor. When the BIOS image verification and recovery processing program is executed by the processor, the steps of the BIOS image verification and recovery method according to any one of claims 1 to 7 are implemented.
10. A readable storage medium, characterized in that: The readable storage medium stores a BIOS image verification and recovery program, and when the BIOS image verification and recovery program is executed by the processor, the steps of the BIOS image verification and recovery method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
BIOS (Basic Input / Output System) double-mirror-image configuration encryption synchronization and credible recovery method and device
CN122285095A