Security verification method and device, computer equipment and storage medium

Through the two-way measurement verification mechanism between the security unit and the storage unit of the trusted computing platform, the problem of inaccurate measurement and verification in the prior art is solved, and the accuracy of security verification and the security of the trusted platform are improved.

CN120217366APending Publication Date: 2025-06-27NETTRIX INFORMATION IND CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202311801020.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-25
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing trusted computing platform realizes a trusted chain through step-by-step measurement and verification technology, but there are inaccuracies, which affects the accuracy of security verification and the security of trusted platforms.

Method used

By measuring the verification mechanism between the security unit and the storage unit, the signal transmission between the security unit and the storage unit is not tampered with, and two-factor verification is achieved.

Benefits of technology

Improves the accuracy of security verification, enhances the security and reliability of trusted platforms, and reduces the risk of malicious attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217366A_ABST
    Figure CN120217366A_ABST
Patent Text Reader

Abstract

The invention relates to a security verification method and device, computer equipment and a storage medium, and the method comprises the steps: forwarding a first measurement signal sent by a security unit to a first storage unit, and then forwarding a first configuration file returned by the first storage unit to the security unit, and carrying out the security verification of the first storage unit. And verifying the security unit to obtain a first verification result under the condition that the first verification result shows that verification is passed, and verifying the security unit to obtain a second verification result. According to the method, through a verification mechanism of bidirectional measurement of the security unit and the first storage unit, the accuracy of security verification can be improved, the security and reliability of the trusted platform are further improved, and the risk that the trusted platform is subjected to hostile attacks is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technologies, and particularly to a security verification method, apparatus, computer device, and storage medium. Background Art

[0002] With the rapid development of society, network technologies have penetrated all aspects of our lives, covering production, life, commercial finance, and so on. Therefore, the phenomenon of network attacks cannot be underestimated, especially for the cloud servers and terminal servers in some important fields, which pose potential security threats. The trusted computing platform thus emerges. Trusted computing (TC, Trusted Computing) is a technology initiated and promoted by the Trusted Computing Group (TCG, Trusted Computing Group).

[0003] In related technologies, trusted computing is mainly achieved through the technology of step-by-step measurement and verification. The previous-level program measures the next-level program. Only when the measurement and verification are successful can the current program continue to transfer the trusted chain to the next-level program and extend the trusted chain to achieve the purpose of creating a trusted computing environment.

[0004] However, the above measurement and verification method has the problem of inaccuracy. Summary of the Invention

[0005] Based on this, it is necessary to provide a security verification method, apparatus, computer device, and storage medium that can improve accuracy for the above technical problems.

[0006] In a first aspect, the present application provides a security verification method, which includes:

[0007] Forward the first measurement signal sent by the security unit to the first storage unit;

[0008] Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit to obtain a first verification result;

[0009] When the first verification result indicates that the verification is passed, verify the security unit to obtain a second verification result.

[0010] The security verification method provided by the embodiment of the present application forwards the first measurement signal sent by the security unit to the first storage unit, and then forwards the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, obtaining a first verification result. And when the first verification result indicates that the verification is passed, the security unit is verified to obtain a second verification result. The above method can improve the accuracy of security verification through the verification mechanism of two-way measurement between the security unit and the first storage unit, further improve the security and reliability of the trusted platform, and greatly reduce the risk of the trusted platform being maliciously attacked.

[0011] In one embodiment, when the first verification result indicates that the verification is passed, verifying the security unit to obtain a second verification result includes:

[0012] Forwarding the second measurement signal sent by the first storage unit to the security unit;

[0013] Forwarding the second configuration file returned by the security unit to the first storage unit for security verification of the security unit, obtaining a second verification result.

[0014] The method described in the embodiment of the present application can improve the accuracy of security verification by performing reverse verification on the security unit, further improve the security and reliability of the trusted platform, and greatly reduce the risk of the trusted platform being maliciously attacked.

[0015] In one embodiment, the method further includes:

[0016] Sending a verification request to the security unit;

[0017] Receiving a third configuration file returned by the security unit based on the verification request, and performing security verification on the security unit according to the third configuration file, obtaining a third verification result;

[0018] When the third verification result indicates that the security unit passes the verification, receiving the first measurement signal sent by the security unit.

[0019] The method described in the embodiment of the present application can avoid the irrecoverable problem caused by the first storage unit being maliciously tampered with or attacked before the protection mechanism of the trusted platform starts by performing trusted verification of the security unit immediately after power-on.

[0020] In one embodiment, forwarding the first measurement signal sent by the security unit to the first storage unit includes:

[0021] When receiving the first measurement signal, sending the first measurement signal to the first storage unit through the first interface on the logic control unit;

[0022] Forwarding the second measurement signal sent by the first storage unit to the security unit includes:

[0023] When receiving the second measurement signal, send the second measurement signal to the security unit through the second interface on the logic control unit.

[0024] In the method described in the embodiments of the present application, by transmitting the measurement signal through the interface on the logic control unit, it can be ensured that the measurement signal will not be tampered with or modified during the transmission process, the accuracy and reliability of the measurement result can be ensured, and security vulnerabilities and attacks can be prevented.

[0025] In one of the embodiments, the method further includes:

[0026] In the case where the first verification result indicates that the verification fails, use the second storage unit as the new first storage unit, and return to execute the step of forwarding the first measurement signal sent by the security unit to the first storage unit.

[0027] In the method described in the embodiments of the present application, by using the backup storage unit, the fault tolerance and redundancy of the system can be increased. When the verification of the first storage unit fails, the system can automatically switch to the second storage unit to ensure that the system can be normally initialized and operate.

[0028] In one of the embodiments, the method further includes:

[0029] In the case where the second verification result indicates that the verification passes, use the third storage unit as the new first storage unit, and return to execute the step of forwarding the first measurement signal sent by the security unit to the first storage unit.

[0030] In the method described in the embodiments of the present application, by performing double measurement and verification on the third storage unit under the condition of double measurement and verification of the first storage unit and the security unit, the security and reliability of the trusted platform can be improved.

[0031] In a second aspect, the present application further provides a security verification device, which includes: a security unit, at least one storage unit, and a logic control unit; the logic control unit is respectively connected to the security unit and the storage unit;

[0032] The logic control unit is configured to execute the steps of the method in any one of the above first aspects.

[0033] The security verification device described in the embodiments of the present application can improve the accuracy of security verification through the verification mechanism of two-way measurement between the security unit and the first storage unit, further improve the security and reliability of the trusted platform, and greatly reduce the risk of the trusted platform being maliciously attacked.

[0034] In a third aspect, the present application further provides a security verification device, which includes: a system module and a storage module. The system module includes a security unit, a logic control unit, and a basic input / output storage unit; the storage module includes a baseboard management control storage unit; the system module and the storage module are connected;

[0035] The logic control unit is configured to execute the steps of the method according to any one of the embodiments in the first aspect above.

[0036] For the security verification device described in the embodiments of the present application, by performing double measurement and verification on the baseboard management control storage unit and the security unit, and then performing double measurement and verification on the basic input / output storage unit, the security and reliability of the trusted platform can be improved.

[0037] In a fourth aspect, the present application further provides a security verification device, which includes:

[0038] A forwarding module that forwards the first measurement signal sent by the security unit to the first storage unit;

[0039] A first verification module, configured to forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, and obtain a first verification result;

[0040] A second verification module, configured to verify the security unit and obtain a second verification result when the first verification result indicates that the verification is passed.

[0041] In a fifth aspect, the present application further provides a computer device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0042] Forward the first measurement signal sent by the security unit to the first storage unit;

[0043] Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, and obtain a first verification result;

[0044] Verify the security unit and obtain a second verification result when the first verification result indicates that the verification is passed.

[0045] In a sixth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0046] Forward the first measurement signal sent by the security unit to the first storage unit;

[0047] Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, and obtain a first verification result;

[0048] When the first verification result indicates that the verification is passed, verify the security unit to obtain a second verification result.

[0049] In a seventh aspect, the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0050] Forward the first measurement signal sent by the security unit to the first storage unit;

[0051] Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, and obtain a first verification result;

[0052] When the first verification result indicates that the verification is passed, verify the security unit to obtain a second verification result.

[0053] In the above security verification method, device, computer device, and storage medium, the method forwards the first measurement signal sent by the security unit to the first storage unit, then forwards the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit to obtain a first verification result, and when the first verification result indicates that the verification is passed, verifies the security unit to obtain a second verification result. Through the verification mechanism of two-way measurement between the security unit and the first storage unit, the above method can improve the accuracy of security verification, further improve the security and reliability of the trusted platform, and greatly reduce the risk of the trusted platform being maliciously attacked. Description of the Drawings

[0054] Figure 1 It is a structural block diagram of a security verification device in an embodiment;

[0055] Figure 2 It is a schematic flowchart of a security verification method in an embodiment;

[0056] Figure 3 It is a schematic flowchart of a security verification method in another embodiment;

[0057] Figure 4 It is a schematic flowchart of a security verification method in another embodiment;

[0058] Figure 5 It is a schematic flowchart of a security verification method in another embodiment;

[0059] Figure 6 It is a schematic flowchart of a security verification method in another embodiment;

[0060] Figure 7 is a schematic flowchart of a security verification method in another embodiment;

[0061] Figure 8 is a structural block diagram of a security verification device in another embodiment;

[0062] Figure 9 is an interface block diagram of a security verification device in another embodiment;

[0063] Figure 10 is a schematic flowchart of a security verification method in another embodiment;

[0064] Figure 11 is a schematic flowchart of a security verification method in another embodiment;

[0065] Figure 12 is a structural block diagram of a security verification device in another embodiment;

[0066] Figure 13 is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0067] In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0068] With the rapid development of society, network technology has penetrated into all aspects of our lives, covering production, life, commercial finance, and other levels. Therefore, the phenomenon of network attacks cannot be underestimated, especially for the cloud servers and terminal servers in some important fields, which pose potential security threats. The trusted computing platform comes into being. Trusted computing (TC) is a technology initiated and promoted by the Trusted Computing Group (TCG). In related technologies, trusted computing is mainly realized through the technology of step-by-step measurement and verification. The previous program measures the next program. Only when the measurement and verification are successful can the current program continue to transmit the trusted chain to the next program and extend the trusted chain to achieve the purpose of creating a trusted computing environment. However, the above measurement and verification methods have the problem of inaccuracy. The present application provides a security verification method aimed at solving the above technical problems. The following embodiments will specifically illustrate the security verification method described in the present application.

[0069] The security verification method provided by the embodiments of the present application can be applied to such as Figure 1In the security verification device shown, the device includes a security unit 101, at least one storage unit 102, and a logic control unit 103. The logic control unit 103 is respectively connected to the security unit 101 and the storage unit 102. Among them, the security unit 101 is used to measure and verify at least one storage unit 102, and at least one storage unit 102 is used to measure and verify the security chip 101, so as to implement double measurement and verification between the security unit 101 and at least one storage unit 102. The logic control unit 103 forwards the measurement signal and verification result between the security unit 101 and at least one storage unit 102, and measures and verifies the security chip 101. The above-mentioned security unit 101 can be, but is not limited to, security chips or cryptographic chips such as a Trusted Platform Module (TPM for short), a Trusted Cryptography Module (TCM for short), and a Trusted Platform Control Module (TPCM for short). The above-mentioned security verification device can specifically be a trusted platform. The above-mentioned storage unit 102 can be, but is not limited to, at least one of a baseboard management control storage unit and a basic input / output storage unit. The baseboard management control storage unit can be a Baseboard Management Controller (BMC for short), and the basic input / output storage unit can be a Basic Input Output System (BIOS for short). The above-mentioned logic control unit 103 can be a Logic Control Unit (LCU for short).

[0070] Those skilled in the art can understand that Figure 1 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the security verification device to which the solution of this application is applied. The specific security verification device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0071] In one embodiment, as Figure 2 shown, a security verification method is provided. Taking the logic control unit (LCU) in Figure 1 as an example for illustration, the method includes the following steps:

[0072] S201, forward the first measurement signal sent by the security unit to the first storage unit.

[0073] Among them, the first measurement signal is the signal for the security unit to measure the first storage unit. The first storage unit can be the baseboard management control storage unit, the basic input / output storage unit, or both the baseboard management control storage unit and the basic input / output storage unit.

[0074] In the embodiment of the present application, after the system power is turned on, the logic control unit can perform initialization operations. Specifically, the enable signal of the logic control unit is activated and the reset signal is released. For example, LCU EN is activated and LCU RST is released. After the initialization operation of the logic control unit is completed, the security unit can perform a security verification on the first storage unit. During the verification process, the security unit can send the first measurement signal to the logic control unit, and after receiving the first measurement signal, the logic control unit can forward the first measurement signal to the first storage unit. Optionally, after receiving the first measurement signal, the logic control unit can process the first measurement signal and then forward the processed first measurement signal to the first storage unit.

[0075] S202: Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit to obtain a first verification result.

[0076] Among them, the first configuration file is a firmware file, including at least one of the firmware file of the baseboard management control storage unit (for example, BMC ROM file) and the firmware file of the basic input / output storage unit (for example, BIOS ROM). The first verification result is used to indicate whether the first storage unit passes or fails the verification.

[0077] In an embodiment of the present application, after the logic control unit forwards the first metric signal to the first storage unit, the first storage unit can receive the first metric signal. Then, the first storage unit can return the first configuration file to the logic control unit according to the indication of the first metric signal. For example, the first configuration file is a firmware program. After receiving the first configuration file, the logic control unit forwards the first configuration file to the security unit. After receiving the first configuration file, the security unit can measure the first configuration file to obtain a measurement result. Specifically, the measurement value corresponding to the first configuration file can be calculated. For example, the hash value corresponding to the first configuration file is calculated using a hash function. After obtaining the measurement result, the security unit can verify whether the first storage unit passes the verification and obtain a first verification result by comparing the measurement result with the expected measurement result. Specifically, if the measurement result is consistent with the expected measurement result, the first verification result indicates that the first storage unit passes the verification, that is, the first storage unit is trusted. If the measurement result is inconsistent with the expected measurement result, the second verification result indicates that the first storage unit fails the verification, that is, the first storage unit is not trusted. Optionally, the security unit directly obtains the first configuration file from the first storage unit based on the indication of the first metric signal.

[0078] S203. When the first verification result indicates that the verification is passed, verify the security unit to obtain a second verification result.

[0079] Wherein, the second verification result is used to indicate whether the security unit passes the verification or fails the verification.

[0080] In the embodiment of the present application, when the first verification result indicates that the verification is passed, it means that the security unit has passed the verification of the first storage unit. Then, it is necessary to measure and verify the security unit in turn to implement a dual-verification mechanism. Specifically, the security unit can be verified for security by the first storage unit to obtain a second verification result. Optionally, the security unit can be verified for security by the logic control unit to obtain a second verification result. It should be noted that when the first storage unit is the baseboard management control storage unit and the basic input / output storage unit, the security unit can first verify the baseboard management control storage unit through the above steps S201 and S202. Then, when the verification of the baseboard management control storage unit is passed, the logic control unit can verify the security unit through the above step S203. Specifically, the security unit can be verified by the basic baseboard management control storage unit or the logic control unit. Then, when the verification of the security unit is passed, the security unit can verify the basic input / output storage unit again through the above steps S201 and S202. Then, when the verification of the basic input / output storage unit is passed, the basic input / output storage unit can verify the security unit through the above step S203. Specifically, the security unit can be verified by the basic input / output storage unit or the logic control unit to complete the dual-verification process between the security unit and the baseboard management control storage unit, and between the security unit and the basic input / output storage unit.

[0081] The security verification method provided by the embodiment of the present application forwards the first measurement signal sent by the security unit to the first storage unit, and then forwards the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit to obtain a first verification result. When the first verification result indicates that the verification is passed, the security unit is verified to obtain a second verification result. Through the verification mechanism of two-way measurement between the security unit and the first storage unit, the above method can improve the accuracy of security verification, further improve the security and reliability of the trusted platform, and greatly reduce the risk of the trusted platform being maliciously attacked.

[0082] In one embodiment, a specific implementation manner for verifying the security unit to obtain a second verification result is also provided, as Figure 3 shown. The "when the first verification result indicates that the verification is passed, verify the security unit to obtain a second verification result" in the above step S203 includes:

[0083] S301, forward the second measurement signal sent by the first storage unit to the security unit.

[0084] Among them, the second measurement signal is a signal for the first storage unit to measure the security unit.

[0085] In the embodiment of the present application, when the first verification result indicates that the verification is passed, it means that the security unit has passed the verification of the first storage unit. Then, it is necessary for the first storage unit to measure and verify the security unit in turn to implement a dual verification mechanism. Specifically, the first storage unit can send a second measurement signal to the logic control unit. After receiving the second measurement signal, the logic control unit can forward the second measurement signal to the security unit. Optionally, after receiving the second measurement signal, the logic control unit can process the second measurement signal and then forward the processed second measurement signal to the security unit.

[0086] S302: Forward the second configuration file returned by the security unit to the first storage unit for security verification of the security unit to obtain a second verification result.

[0087] Among them, the second configuration file is the firmware file of the security unit. The second verification result is used to indicate whether the security unit passes the verification or fails the verification.

[0088] In the embodiment of the present application, after the logic control unit forwards the second measurement signal to the security unit, the security unit can receive the second measurement signal. Then, the security unit can return the second configuration file to the logic control unit according to the indication of the second measurement signal. For example, the second configuration file is the firmware program of the security unit. After receiving the second configuration file, the logic control unit forwards the second configuration file to the first storage unit. After receiving the second configuration file, the first storage unit can measure the second configuration file to obtain a measurement result. Specifically, the measurement value corresponding to the second configuration file can be calculated. For example, the hash value corresponding to the second configuration file is calculated using a hash function. After obtaining the measurement result, the second storage unit can verify whether the security unit passes the verification by comparing the measurement result with the expected measurement result and obtain a second verification result. Specifically, if the measurement result is consistent with the expected measurement result, the second verification result indicates that the security unit passes the verification, that is, the security unit is trustworthy. If the measurement result is inconsistent with the expected measurement result, the second verification result indicates that the security unit fails the verification, that is, the security unit is untrustworthy. Optionally, the first storage unit directly obtains the second configuration file from the security unit based on the indication of the second measurement signal.

[0089] The method described in the embodiment of the present application can improve the accuracy of security verification by performing reverse verification on the security unit, further improve the security and reliability of the trusted platform, and greatly reduce the risk of the trusted platform being maliciously attacked.

[0090] In one embodiment, in one embodiment, a security verification method is further provided, as Figure 4As shown, before forwarding the first metric signal sent by the security unit to the first storage unit, Figure 2 The method described in the embodiment further includes:

[0091] S204, sending a verification request to the security unit.

[0092] Among them, the verification request is a request for the logic control unit to measure and verify the security unit.

[0093] In the embodiment of the present application, after the system power is turned on, the logic control unit can perform initialization operations. Specifically, the enable signal of the logic control unit is activated, and the reset signal is released. For example, LCU EN is activated and LCU RST is released. After the initialization operation of the logic control unit is completed, a verification request can be sent to the security unit to verify whether the security unit is trustworthy.

[0094] S205, receiving the third configuration file returned by the security unit based on the verification request, and performing security verification on the security unit according to the third configuration file to obtain a third verification result.

[0095] Among them, the third configuration file is the firmware file of the security unit, which can be the same as the second configuration file or different from the second configuration file. The third verification result is used to indicate whether the security unit passes the verification or fails the verification.

[0096] In the embodiment of the present application, after the security chip receives the verification request sent by the logic control unit, it can send the third configuration file to the logic control unit based on the indication of the verification request. After the logic control unit receives the third configuration file, it can measure the third configuration file to obtain a measurement result. Specifically, the measurement value corresponding to the third configuration file can be calculated. For example, the hash value corresponding to the third configuration file is calculated using a hash function. After the logic control unit obtains the measurement result, it can verify whether the security unit passes the verification by comparing the measurement result with the expected measurement result, and obtain the third verification result. Specifically, if the measurement result is consistent with the expected measurement result, then the third verification result indicates that the security unit passes the verification, that is, the security unit is trustworthy. If the measurement result is inconsistent with the expected measurement result, then the third verification result indicates that the security unit fails the verification, that is, the security unit is untrustworthy.

[0097] S206, when the third verification result indicates that the security unit passes the verification, receiving the first metric signal sent by the security unit.

[0098] In an embodiment of the present application, when the logic control unit determines that the third verification result indicates that the security unit has passed the verification based on the above steps, that is, when it determines that the security unit is trusted, it can then receive the first measurement signal sent by the security unit, forward the first measurement signal sent by the security unit to the first storage unit, and forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit to obtain a first verification result. And when the first verification result indicates that the verification has passed, verify the security unit to obtain a second verification result.

[0099] In the method described in the embodiment of the present application, by immediately performing the trust verification of the security unit after power-on, it is possible to avoid the irrecoverable problem caused by the first storage unit being maliciously tampered with or attacked before the protection mechanism of the trusted platform starts.

[0100] In one embodiment, a specific implementation manner of forwarding the first measurement signal and the second measurement signal is further provided. The "forwarding the first measurement signal sent by the security unit to the first storage unit" in the above step S201 includes: when receiving the first measurement signal, sending the first measurement signal to the first storage unit through the first interface on the logic control unit.

[0101] Among them, the first interface is used to transmit the first measurement signal.

[0102] In the embodiment of the present application, during the process of the security unit performing security verification on the first storage unit, the security unit can send a first measurement request to the logic control unit. The first measurement request is used to instruct the logic control unit to open the channel between the logic control unit and the first storage unit, that is, the first interface. After receiving the first measurement request, the logic control unit can open the channel between the logic control unit and the first storage unit, and then the security unit can send the first measurement signal to the first storage unit through the first interface on the logic control unit.

[0103] Further, the "forwarding the second measurement signal sent by the first storage unit to the security unit" in the above step S301 includes: when receiving the second measurement signal, sending the second measurement signal to the security unit through the second interface on the logic control unit.

[0104] Among them, the second interface is used to transmit the second measurement signal.

[0105] In the embodiment of the present application, during the process of the first storage unit performing security verification on the security unit, the first storage unit may send a second measurement request to the logic control unit. The second measurement request is used to instruct the logic control unit to open a channel between the logic control unit and the security unit, that is, the second interface. After receiving the second measurement request, the logic control unit may open the channel between the logic control unit and the security unit. Then, the first storage unit may send the second measurement signal to the security unit through the second interface on the logic control unit.

[0106] For the method described in the embodiment of the present application, by transmitting the measurement signal through the interface on the logic control unit, it can be ensured that the measurement signal will not be tampered with or modified during the transmission process, and the accuracy and reliability of the measurement result can be ensured, preventing security vulnerabilities and attacks.

[0107] In one embodiment, there is also provided a security verification method. As Figure 5 shown, after obtaining the first verification result, Figure 2 the method described in the embodiment further includes:

[0108] S207, in the case where the first verification result indicates that the verification fails, use the second storage unit as the new first storage unit, and return to execute the step of S201.

[0109] Among them, the second storage unit is a backup storage unit of the first storage unit. The second storage unit may be a baseboard management control storage unit, or a basic input / output storage unit, or both a baseboard management control storage unit and a basic input / output storage unit. When the first storage unit is BMC ROM1, the second storage unit is BMC ROM2. When the first storage unit is BIOS ROM1, the second storage unit is BIOS ROM2.

[0110] In the embodiment of the present application, in the case where the first verification result of the first storage unit indicates that the verification fails, the second storage unit may be used as the new first storage unit, and the security unit performs security verification on the second storage unit. Specifically, the step of S201 may be executed in a loop. For example, when the measurement of BMC ROM1 fails, start the measurement of the backup BMC ROM2. After the measurement of BMC ROM2 passes, BMC can be normally initialized. Another example is that when the measurement of BIOS ROM1 fails, start the measurement of the backup BIOS ROM2. After the measurement of BIOS ROM2 passes, BIOS is normally initialized.

[0111] For the method described in the embodiment of the present application, by using the backup storage unit, the fault tolerance and redundancy of the system can be increased. When the verification of the first storage unit fails, the system can automatically switch to the second storage unit to ensure that the system can be normally initialized and operate.

[0112] In one embodiment, there is also provided a security verification method. As Figure 6 shown, after obtaining the second verification result, Figure 2 the method described in the embodiment further includes:

[0113] S208, when the second verification result indicates that the verification is passed, use the third storage unit as the new first storage unit, and return to execute step S201.

[0114] Wherein, the third storage unit is a basic input / output storage unit.

[0115] In the embodiment of the present application, when the second verification result indicates that the verification is passed, it means that the dual measurement and verification of the first storage unit and the security unit are passed. Further, it is necessary to perform dual measurement and verification between the third storage unit and the security unit. Specifically, the third storage unit can be used as the new first storage unit, and the security unit performs security verification on the third storage unit. Specifically, step S201 can be executed cyclically. It should be noted that before verifying the third storage unit, Device enumeration detection can be performed. For example, detect the connection status of the interfaces corresponding to all basic input / output units corresponding to the third storage unit.

[0116] Further, after the dual verification between the security unit and the baseboard management control storage unit, and between the security unit and the basic input / output storage unit are both passed, the security unit or the logic control unit can also measure and verify the boot loader of the CPU or the boot loader of other components. Specifically, the boot loader can be measured to obtain a measurement result. Specifically, the measurement value corresponding to the boot loader can be calculated. For example, use a hash function to calculate the hash value corresponding to the boot loader. After the security unit or the logic control unit obtains the measurement result, it can verify whether the boot loader passes the verification by comparing the measurement result with the expected measurement result, and enter the operating system when the boot loader passes the verification. For example, enter the OS system.

[0117] As Figure 7As shown in the figure, the verification flowchart of the trusted platform is as follows: After the power supply AC of the system corresponding to the trusted platform is powered on, the logic control unit LCU starts the power-on initialization operation, that is, the security unit TPCM can be started by enabling instruction 1, and then the security unit TPCM is verified through authentication instruction 1. In the case of failed verification, another security unit can be verified or the security unit can be repaired until the verification passes. Then, the security unit TPCM measures and verifies the BMC ROM1 (corresponding to the above-mentioned first storage unit). If the measurement or verification of BMC ROM1 by TPCM fails, the BMC ROM2 (corresponding to the above-mentioned second storage unit) is measured and verified, and after the security unit TPCM successfully verifies the BMC ROM2, the security unit TPCM is reversely measured and verified through the BMC ROM2 to implement a two-way measurement mechanism. If the measurement and verification of BMC ROM1 by TPCM are successful, after the security unit TPCM successfully verifies the BMC ROM1, the security unit TPCM is reversely measured and verified through the BMC ROM1 to implement a two-way measurement mechanism, and after the two-way measurement between the security unit and the BMC ROM is successful, the BMC initialization is controlled. After the BMC initialization is completed, Device enumeration detection is performed. For example, it is detected whether the interfaces corresponding to the basic input / output units are normally connected. After that, the security unit TPCM can measure and verify the BIOS ROM1 (corresponding to the above-mentioned third storage unit). If the measurement or verification of BIOS ROM1 by TPCM fails, the BIOS ROM2 (corresponding to the above-mentioned second storage unit) is measured and verified, and after the security unit TPCM successfully verifies the BIOS ROM2, the security unit TPCM is reversely measured and verified through the BIOS ROM2 to implement a two-way measurement mechanism. If the measurement and verification of BIOS ROM1 by TPCM are successful, after the security unit TPCM successfully verifies the BIOS ROM1, the security unit TPCM is reversely measured and verified through the BIOS ROM1 to implement a two-way measurement mechanism, and after the two-way measurement between the security unit and the BIOS ROM is successful, the BIOS initialization is controlled. After the BIOS initialization is completed, the TPCM measures and verifies the boot loader, and after the measurement and verification of the boot loader by the TPCM are successful, it enters the operating system OS, and then the system running System Running is performed.

[0118] In the method described in the embodiment of the present application, by performing double measurement and verification on the third storage unit under the condition of double measurement and verification of the first storage unit and the security unit, the security and reliability of the trusted platform can be improved.

[0119] In one embodiment, asFigure 1 As shown, a security verification device is provided, which includes: a security unit 101, at least one storage unit 102, and a logic control unit 103; the logic control unit 103 is respectively connected to the security unit 101 and the storage unit 102;

[0120] Among them, the logic control unit 103 is configured to execute the steps of the method in any of the above embodiments.

[0121] The methods described in the above steps have been described in the foregoing embodiments. For detailed content, please refer to the foregoing description and will not be elaborated here.

[0122] The security verification device described in the embodiments of the present application can improve the accuracy of security verification through the verification mechanism of bidirectional measurement of the security unit and the first storage unit, further improve the security and reliability of the trusted platform, and greatly reduce the risk of the trusted platform being maliciously attacked.

[0123] In one embodiment, as Figure 8 shown, a security verification device is provided, which includes: a system module 10 and a storage module 11. The system module 10 includes a security unit 101, a logic control unit 103, and a basic input / output storage unit 104; the storage module 11 includes a baseboard management control storage unit 110; the system module and the storage module are connected through a data transmission interface 12;

[0124] Among them, the logic control unit 103 is configured to execute the steps of the method in any of the above embodiments.

[0125] The above system module 10 includes a security unit 101, a logic control unit 102, and a basic input / output storage unit 104; the storage module 11 includes a baseboard management control storage unit 110. The above system module 10 may be the main board of a trusted platform. The security unit 101 may be, but is not limited to, a security chip or a cryptographic chip such as a Trusted Platform Module (TPM for short), a Trusted Cryptography Module (TCM for short), or a Trusted Platform Control Module (TPCM for short). The logic control unit 102 may be a Logic Control Unit (LCU for short), and the basic input / output storage unit 104 may be a Basic Input Output System (BIOS for short). The above storage module 11 may be a Datacenter Secure Control Module (DC-SCM for short), and the baseboard management control storage unit 110 may be a Baseboard Management Controller (BMC for short).

[0126] As Figure 9 shown, the above data transmission interfaces include SPD I3C, BP I2C, SGPIO, GPIO, USB, and so on. The above storage module 11 further includes input / output interfaces (see Manage Interfaces in Figure 9 for details), which are used to connect to other components.

[0127] Optionally, as Figure 8 shown, the above system module 10 further includes a central processing unit 105, which is used to process data after entering the operating system. The central processing unit may specifically be a CPU chip. Optionally, the above storage module 11 further includes a logic unit 111, which is used to process the first measurement signal and the second measurement signal. Specifically, the first measurement signal can be converted into a signal that the BMC can process, and the second measurement signal can be converted into a signal that the TPCM can process. The logic unit may specifically be a CPLD chip.

[0128] The methods described in each of the above steps have been described in the foregoing embodiments. For detailed content, please refer to the foregoing description and will not be elaborated here.

[0129] As Figure 10As shown in the figure, the process of two-way measurement of TPCM, ROM, and LCU is as follows: After the power supply AC is powered on, the LCU is initialized, the RST is released, and the EN signal is activated. Then, the LCU measures the TPCM. When the TPCM verification is passed, the TPCM sends the BI-IO0 signal to the LCU. The LCU can then enable EN0 to start, that is, open the channel to the ROM. The TPCM can then send the TPCM_SPI protocol signal (i.e., the first measurement signal) to the LCU. The LCU sends this signal to the BMC ROM. Then, the TPCM enables the main measurement mode, and the BMC ROM enables the slave measurement mode. Compared with the TPCM, the LCU is in the slave measurement mode. Compared with the BMC ROM, the LCU is in the main measurement mode. When the verification is passed, the BMC ROM enables the main measurement mode, and the BMC ROM sends the BI-IO1 signal to the LCU. The LCU can then enable EN1 to start, that is, open the channel to the TPCM. The BMC ROM can then send the ROM_SPI protocol signal (i.e., the third measurement signal) to the LCU. The LCU sends this signal to the TPCM. Then, the BMC ROM enables the main measurement mode, and the TPCM enables the slave measurement mode. Compared with the TPCM, the LCU is in the main measurement mode. Compared with the BMC ROM, the LCU is in the slave measurement mode. When the verification is passed, the above steps are cycled to measure and verify the BIOS ROM.

[0130] The methods described in each of the above steps have been described in the foregoing embodiments. For detailed content, please refer to the foregoing description and will not be elaborated here.

[0131] The security verification device described in the embodiments of the present application can improve the security and reliability of the trusted platform by performing double measurement and verification on the basic input / output storage unit after double measurement and verification of the baseboard management control storage unit and the security unit.

[0132] Combining all the above embodiments, a security verification method is further provided, as Figure 11 shown. The method includes:

[0133] S401, sending a verification request to the security unit.

[0134] S402, receiving the third configuration file returned by the security unit based on the verification request, and performing security verification on the security unit according to the third configuration file to obtain a third verification result.

[0135] S403, when the third verification result indicates that the security unit passes the verification, receiving the first measurement signal sent by the security unit.

[0136] S404, when the first measurement signal is received, sending the first measurement signal to the first storage unit through the first interface on the logic control unit.

[0137] S405. Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, and obtain a first verification result.

[0138] S406. In the case where the first verification result indicates that the verification fails, use the second storage unit as the new first storage unit, and return to execute step S401.

[0139] S407. In the case where the first verification result indicates that the verification passes, when receiving the second measurement signal, send the second measurement signal to the security unit through the second interface on the logic control unit.

[0140] S408. Forward the second configuration file returned by the security unit to the first storage unit for security verification of the security unit, and obtain a second verification result.

[0141] S409. In the case where the second verification result indicates that the verification passes, use the third storage unit as the new first storage unit, and return to execute step S401.

[0142] The methods described in the above steps have all been described in the foregoing embodiments. For detailed content, please refer to the foregoing description and will not be elaborated here.

[0143] In the method described in the embodiments of the present application, the LCU and the DC-SCM are independently arranged, which can realize the flexible signal interaction function between the main board and the DC-SCM. Compared with the design structure of traditional main boards, which integrates the main management and access platforms (such as BMC, etc.) into one, when it is necessary to meet the upgrade requirements of the market and customers, the entire board needs to be updated and iterated. From the hardware circuit design to the PCB layout and wiring, to the board making and board returning tests, etc., the required human and financial costs are relatively high, and unknown BUGs are likely to be generated and increased during the system test process, increasing the design complexity. However, this structure can achieve cross-generation upgrades, reduce the design complexity and costs, and maintain and enhance the reliability of trusted measurement. Moreover, the DC-SCM card can be highly adapted to different main boards, meet different configuration requirements, and support independent iteration of single boards (cards). When the AC is powered on, the LCU module first performs a uniqueness authentication on the TPCM. Only after the authentication is passed can it access the ROM module to implement an active measurement mechanism for the ROM, curbing malicious attacks from the outside before the boot process and preventing the ROM from starting up and waking up internal malicious programs. By using the LCU logic block as the main (slave) measurement block, two-way measurement between the TPCM and the BMC ROM and two-way measurement between the TPCM and the BIOS ROM are realized. The dual encryption mechanism strengthens the security and reliability of the trusted platform. It supports the two-way measurement protection mechanism between the TPCM and the ROM, performs dual measurement on the chip kernel data, realizes the security protection before chip initialization, further improves the security of the trusted platform against external malicious attacks. At the same time, the DC-SCM integration supports external data and management interfaces to implement the measurement mechanism when the TPCM accesses the external data interface of the DC-SCM card.

[0144] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0145] Based on the same inventive concept, the embodiments of the present application also provide a security verification device for implementing the above-mentioned security verification method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the security verification device provided below can refer to the limitations on the security verification method in the above text and will not be elaborated here.

[0146] In one embodiment, as Figure 12 shown, a security verification device is provided, including:

[0147] A forwarding module 20, configured to forward a first metric signal sent by a security unit to a first storage unit.

[0148] A first verification module 21, configured to forward a first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, and obtain a first verification result.

[0149] A second verification module 22, configured to verify the security unit to obtain a second verification result when the first verification result indicates that the verification is passed.

[0150] In one embodiment, the above-mentioned second verification module 22 includes:

[0151] A first forwarding unit, configured to forward a second metric signal sent by the first storage unit to the security unit.

[0152] A second forwarding unit, configured to forward a second configuration file returned by the security unit to the first storage unit for security verification of the security unit, and obtain a second verification result.

[0153] In one embodiment, the above-mentioned security verification device further includes:

[0154] A sending module, configured to send a verification request to the security unit.

[0155] A third verification module, configured to receive a third configuration file returned by the security unit based on the verification request, and perform security verification on the security unit according to the third configuration file, and obtain a third verification result.

[0156] A receiving module, configured to receive the first metric signal sent by the security unit when the third verification result indicates that the security unit passes the verification.

[0157] In one embodiment, the above-mentioned forwarding module 20 is specifically configured to, when receiving the first metric signal, send the first metric signal to the first storage unit through a first interface on the logic control unit.

[0158] In one embodiment, the above-mentioned first forwarding unit is specifically configured to, when receiving the second metric signal, send the second metric signal to the security unit through a second interface on the logic control unit.

[0159] In one embodiment, the above-mentioned security verification device further includes:

[0160] A first loop module, configured to, when a first verification result indicates that the verification fails, use a second storage unit as a new first storage unit, and return to execute the step of forwarding a first metric signal sent by a security unit to the first storage unit.

[0161] In one embodiment, the above security verification device further includes:

[0162] A first loop module, configured to, when a second verification result indicates that the verification passes, use a third storage unit as a new first storage unit, and return to execute the step of forwarding a first metric signal sent by a security unit to the first storage unit.

[0163] Each module in the above security verification device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in a processor in a computer device in hardware form or be independent of the processor, or can be stored in a memory in the computer device in software form, so that the processor can call and execute operations corresponding to the above respective modules.

[0164] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structural diagram can be as Figure 13 shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for communicating with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. The computer program, when executed by the processor, implements a security verification method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or can also be an external keyboard, a touchpad, or a mouse, etc.

[0165] Those skilled in the art can understand, Figure 13The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0166] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:

[0167] Forward the first metric signal sent by the security unit to the first storage unit;

[0168] Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, and obtain a first verification result;

[0169] When the first verification result indicates that the verification is passed, verify the security unit to obtain a second verification result.

[0170] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0171] Forward the second metric signal sent by the first storage unit to the security unit;

[0172] Forward the second configuration file returned by the security unit to the first storage unit for security verification of the security unit, and obtain a second verification result.

[0173] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0174] Send a verification request to the security unit;

[0175] Receive the third configuration file returned by the security unit based on the verification request, and perform security verification on the security unit according to the third configuration file to obtain a third verification result;

[0176] When the third verification result indicates that the security unit passes the verification, receive the first metric signal sent by the security unit.

[0177] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0178] When the first verification result indicates that the verification fails, use the second storage unit as the new first storage unit, and return to execute the step of forwarding the first metric signal sent by the security unit to the first storage unit.

[0179] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0180] In the case where the first verification result indicates that the verification fails, use the second storage unit as the new first storage unit, and return to execute the step of forwarding the first metric signal sent by the security unit to the first storage unit.

[0181] In one embodiment, when the processor executes the computer program, the following steps are further implemented:

[0182] In the case where the second verification result indicates that the verification passes, use the third storage unit as the new first storage unit, and return to execute the step of forwarding the first metric signal sent by the security unit to the first storage unit.

[0183] For a computer device provided in the above embodiment, its implementation principle and technical effects are similar to those of the above method embodiment, and will not be elaborated here.

[0184] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0185] Forward the first metric signal sent by the security unit to the first storage unit;

[0186] Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit, and obtain a first verification result;

[0187] In the case where the first verification result indicates that the verification passes, verify the security unit to obtain a second verification result.

[0188] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0189] Forward the second metric signal sent by the first storage unit to the security unit;

[0190] Forward the second configuration file returned by the security unit to the first storage unit for security verification of the security unit, and obtain a second verification result.

[0191] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0192] Send a verification request to the security unit;

[0193] Receive the third configuration file returned by the security unit based on the verification request, and perform security verification on the security unit according to the third configuration file to obtain a third verification result;

[0194] In the case where the third verification result indicates that the security unit passes the verification, receive the first metric signal sent by the security unit.

[0195] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0196] In the case where the first verification result indicates that the verification fails, the second storage unit is used as the new first storage unit, and the step of forwarding the first metric signal sent by the security unit to the first storage unit is returned for execution.

[0197] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0198] In the case where the first verification result indicates that the verification fails, the second storage unit is used as the new first storage unit, and the step of forwarding the first metric signal sent by the security unit to the first storage unit is returned for execution.

[0199] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0200] In the case where the second verification result indicates that the verification passes, the third storage unit is used as the new first storage unit, and the step of forwarding the first metric signal sent by the security unit to the first storage unit is returned for execution.

[0201] For the computer-readable storage medium provided in the above embodiment, its implementation principle and technical effects are similar to those of the above method embodiment, and will not be elaborated here.

[0202] In one embodiment, a computer program product is provided, including a computer program, which when executed by a processor, implements the following steps:

[0203] Forward the first metric signal sent by the security unit to the first storage unit;

[0204] Forward the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit to obtain a first verification result;

[0205] In the case where the first verification result indicates that the verification passes, verify the security unit to obtain a second verification result.

[0206] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0207] Forward the second metric signal sent by the first storage unit to the security unit;

[0208] Forward the second configuration file returned by the security unit to the first storage unit for security verification of the security unit to obtain a second verification result.

[0209] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0210] Send a verification request to the security unit;

[0211] Receive the third configuration file returned by the security unit based on the verification request, and perform a security verification on the security unit according to the third configuration file to obtain a third verification result;

[0212] When the third verification result indicates that the security unit passes the verification, receive the first metric signal sent by the security unit.

[0213] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0214] When the first verification result indicates that the verification fails, use the second storage unit as the new first storage unit, and return to execute the step of forwarding the first metric signal sent by the security unit to the first storage unit.

[0215] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0216] When the first verification result indicates that the verification fails, use the second storage unit as the new first storage unit, and return to execute the step of forwarding the first metric signal sent by the security unit to the first storage unit.

[0217] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0218] When the second verification result indicates that the verification passes, use the third storage unit as the new first storage unit, and return to execute the step of forwarding the first metric signal sent by the security unit to the first storage unit.

[0219] For the computer program product provided in the above embodiment, its implementation principle and technical effects are similar to those of the above method embodiment, and will not be elaborated here.

[0220] Those of ordinary skill in the art can understand that all or part of the processes in the above-described method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the method embodiments as described above. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.

[0221] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0222] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A security verification method, characterized in that, The method includes: Forwarding the first metric signal sent by the security unit to the first storage unit; Forwarding the first configuration file returned by the first storage unit to the security unit for security verification of the first storage unit to obtain a first verification result; When the first verification result indicates that the verification is passed, verifying the security unit to obtain a second verification result.

2. The method according to claim 1, wherein The step of, when the first verification result indicates that the verification is passed, verifying the security unit to obtain a second verification result includes: Forwarding the second metric signal sent by the first storage unit to the security unit; Forwarding the second configuration file returned by the security unit to the first storage unit for security verification of the security unit to obtain the second verification result.

3. The method according to claim 1 or 2, characterized in that, The method further includes: Sending a verification request to the security unit; Receiving a third configuration file returned by the security unit based on the verification request and performing security verification on the security unit according to the third configuration file to obtain a third verification result; When the third verification result indicates that the security unit passes the verification, receiving the first metric signal sent by the security unit.

4. The method according to claim 1, wherein The step of forwarding the first metric signal sent by the security unit to the first storage unit includes: When the first metric signal is received, sending the first metric signal to the first storage unit through a first interface on the logic control unit; The step of forwarding the second metric signal sent by the first storage unit to the security unit includes: When the second metric signal is received, sending the second metric signal to the security unit through a second interface on the logic control unit.

5. The method according to claim 1, characterized in that, The method further includes: When the first verification result indicates that the verification fails, using the second storage unit as the new first storage unit and returning to execute the step of forwarding the first metric signal sent by the security unit to the first storage unit.

6. The method according to claim 1, characterized in that, The method further includes: When the second verification result indicates that the verification is passed, using the third storage unit as the new first storage unit and returning to execute the step of forwarding the first metric signal sent by the security unit to the first storage unit.

7. A security verification device, characterized in that, The device includes: a security unit, at least one storage unit, and a logic control unit; the logic control unit is respectively connected to the security unit and the storage unit; The logic control unit is configured to execute the steps of the method according to any one of claims 1 to 6.

8. A security verification device, characterized in that, The device includes: a system module and a storage module, the system module includes a security unit, a logic control unit, and a basic input / output storage unit; the storage module includes a baseboard management control storage unit; the system module and the storage module are connected; The logic control unit is configured to execute the steps of the method according to any one of claims 1 to 6.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • A Trusted Boot Method for Operating Systems Based on Reverse Integrity Verification

    CN102270288A

  • Trusted security measurement method and device

    CN111625831A

  • Bidirectional authentication trusted starting system and method based on TPCM chip

    CN114077740A