Baseboard management controller starting method, device and system, server and medium
By using trusted root information on the server, the programmable logic chip in the server uses trusted root information to verify the substrate management controller layer by layer, the problem of high safety startup cost of the substrate management controller is solved, and a faster and safer startup process is achieved.
Patent Information
- Application Number
- CN202311861743.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
In the prior art, the safe start-up cost of the substrate management controller is relatively high, and it is mainly performed by plugging the ASIC chip to perform safety verification, resulting in an additional cost increase.
The trusted root information built into the programmable logic chip is used to verify the target firmware, operating system and application of the substrate management controller layer by layer, forming a trust chain and achieving secure startup.
It reduces the cost of secure startup, improves startup speed and security, ensures the accuracy and credibility of the startup process, and avoids the process of extrapolation of the security verification chip.
Smart Images

Figure CN120234055A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technologies, and particularly to a method, apparatus, system, server, and medium for starting a baseboard management controller. Background Art
[0002] With the development of communication security technologies, the secure operation of servers has become increasingly important. Among them, as an important component in a server, the security of the baseboard management controller (BMC) is crucial for the secure operation of the entire server. Therefore, during the operation of the server, it is necessary to perform a security check on the startup process of the baseboard management controller to ensure the security after the baseboard management controller is started.
[0003] In related technologies, mainly an application specific integrated circuit (ASIC) chip is used to perform a security check on the startup process of the baseboard management controller. However, using related technologies has the problem of a relatively high cost for the secure startup of the baseboard management controller. Summary of the Invention
[0004] Based on this, it is necessary to provide a method, apparatus, system, device, and medium for starting a baseboard management controller to solve the above technical problems, which can reduce the secure startup cost of the baseboard management controller.
[0005] In a first aspect, an embodiment of the present application provides a method for starting a baseboard management controller, which is applied to a programmable logic chip in a server. The method includes:
[0006] Based on trusted root information, verifying a target firmware corresponding to the baseboard management controller in the server;
[0007] If the target firmware verification passes, verifying the operating system of the server and the application program of the baseboard management controller;
[0008] If both the operating system and the application program pass the verification, controlling the baseboard management controller to start according to the target firmware.
[0009] The technical solution in the embodiment of the present application is applied to a programmable logic chip in a server. Based on the trusted root information, the target firmware corresponding to the baseboard management controller in the server is verified. If the target firmware verification passes, the operating system of the server and the application program of the baseboard management controller are verified. If both the operating system and the application program pass the verification, the baseboard management controller is controlled to start according to the target firmware. The above method does not require an external security verification chip on the server, and the built-in chip in the server can be used to perform security verification on the startup process of the baseboard management controller to securely start the baseboard management controller, thereby saving the cost brought by the external security verification chip and further reducing the security startup cost of the baseboard management controller. At the same time, the above method can automatically perform security verification on the startup process of the baseboard management controller through the built-in chip in the server, avoiding the external plug-in process of the security verification chip, thereby accelerating the security verification speed during the startup process of the baseboard management controller and further improving the security startup speed of the baseboard management controller. In addition, the above method is applied to a programmable logic chip in a server. In the case of updates to the target firmware, operating system, and application program, the verification process can be flexibly changed to improve the accuracy of the verification result before the baseboard management controller starts, thereby improving the security after the baseboard management controller starts. Moreover, the above method can start from the trusted root information and sequentially perform layer-by-layer verification on the target firmware, operating system, and application program corresponding to the baseboard management controller to form a trust chain, thereby greatly improving the security after the baseboard management controller starts.
[0010] In one of the embodiments, before verifying the target firmware corresponding to the baseboard management controller in the server based on the trusted root information, the above method further includes:
[0011] Establish the trusted root information through the trusted root security module in the programmable logic chip.
[0012] The technical solution in the embodiment of the present application can establish the trusted root information through the trusted root security module in the programmable logic chip. Without information transmission, the programmable logic chip can directly use it to implement the subsequent security verification process, thereby avoiding the problem of information tampering during the information transmission process and improving the security of the trusted root information.
[0013] In one of the embodiments, verifying the target firmware corresponding to the baseboard management controller in the server based on the trusted root information includes:
[0014] According to the trusted root information, decrypt the signature value in the target firmware to obtain the first hash value;
[0015] According to the hash algorithm in the target firmware, perform a hash process on the public key value in the target firmware to obtain the second hash value;
[0016] If the first hash value matches the second hash value, the target firmware passes the verification; the target firmware is the startup firmware of the baseboard management controller and the startup firmware of the hardware managed by the baseboard management controller.
[0017] In the technical solution of the embodiment of the present application, according to the trusted root information, the signature value in the target firmware is decrypted to obtain the first hash value, and according to the hash algorithm in the target firmware, the public key value in the target firmware is hashed to obtain the second hash value. When the first hash value matches the second hash value, it is determined that the target firmware passes the verification; the above method can perform security verification on the startup firmware of the baseboard management controller itself and the startup firmware of the hardware managed by the baseboard management controller before the baseboard management controller starts, so as to prepare for the secure startup of the baseboard management controller and improve the security after the baseboard management controller starts.
[0018] In one embodiment, the target firmware includes the startup firmware of the baseboard management controller; verifying the operating system of the server and the application program of the baseboard management controller includes:
[0019] Controlling the execution of the startup firmware of the baseboard management controller to obtain the trusted function firmware corresponding to the trusted module;
[0020] Verifying the trusted function firmware according to the trusted root information;
[0021] If the trusted function firmware passes the verification, then according to the trusted function firmware, the operating system of the server and the application program of the baseboard management controller are verified.
[0022] In the technical solution of the embodiment of the present application, controlling the execution of the startup firmware of the baseboard management controller to obtain the trusted function firmware corresponding to the trusted module, verifying the trusted function firmware according to the trusted root information, and if the trusted function firmware passes the verification, then according to the trusted function firmware, the operating system of the server and the application program of the baseboard management controller are verified; the above method can first verify the trusted function firmware, and then use the verified trusted function firmware to verify the operating system of the server and the application program of the baseboard management controller, thereby improving the accuracy and credibility of the verification results of the operating system and the application program.
[0023] In one embodiment, verifying the trusted function firmware according to the trusted root information includes:
[0024] According to the trusted root information, decrypting the signature value in the trusted function firmware to obtain the third hash value;
[0025] According to the hash algorithm in the trusted function firmware, hashing the public key value in the trusted function firmware to obtain the fourth hash value;
[0026] If the third hash value matches the fourth hash value, the verification of the trusted function firmware passes.
[0027] In the technical solution of the embodiment of the present application, the signature value in the trusted function firmware is decrypted according to the trusted root information to obtain the third hash value, and the public key value in the trusted function firmware is hashed according to the hash algorithm in the trusted function firmware to obtain the fourth hash value. When the third hash value matches the fourth hash value, it is determined that the verification of the trusted function firmware passes; the above method can perform a security verification on the trusted function firmware before the operating system of the server and the application program of the baseboard management controller, so as to prepare for the security verification of the operating system of the server and the application program of the baseboard management controller, and improve the accuracy and credibility of the verification results of the operating system of the server and the application program of the baseboard management controller.
[0028] In one embodiment, verifying the operating system of the server and the application program of the baseboard management controller according to the trusted function firmware includes:
[0029] Performing integrity measurement on the operating system and the application program according to the trusted function firmware to obtain a measurement value;
[0030] If the measurement value matches the standard measurement value, the operating system and the application program pass the verification.
[0031] In the technical solution of the embodiment of the present application, the integrity of the operating system and the application program is measured according to the trusted function firmware to obtain a measurement value. If the measurement value matches the standard measurement value, the operating system and the application program pass the verification. The above method can verify the operating system of the server and the application program of the baseboard management controller based on the trusted function firmware that has passed the security verification, and can improve the accuracy and credibility of the verification results of the operating system and the application program; at the same time, the above method can perform security verification on the operating environment (i.e., the operating system) of the baseboard management controller and the applications on the baseboard management controller before the baseboard management controller starts, so as to improve the security of the baseboard management controller to a greater extent after startup; at the same time, the above method can use the trusted function firmware, that is, the national cryptographic algorithm, to verify the operating system of the server and the application program of the baseboard management controller, so that the verification results of the operating system and the application program are more secure and reliable.
[0032] In a second aspect, the embodiment of the present application further provides a baseboard management controller startup system, and the baseboard management controller startup system includes: a programmable logic chip and a baseboard management controller;
[0033] The programmable logic chip is used to implement the method in any one of the first aspects above and control the startup of the baseboard management controller.
[0034] In one embodiment, the above system further includes: a storage unit;
[0035] The storage unit is configured to store the trusted function firmware for the programmable logic chip to read the trusted function firmware and complete the method of any one of the above embodiments in the first aspect through the trusted function firmware.
[0036] In one embodiment, the above programmable logic chip includes a trusted module;
[0037] Specifically, the programmable logic chip is configured to load the verified trusted function firmware into the trusted module to verify the operating system of the server and the application program of the baseboard management controller through the trusted module.
[0038] In a third aspect, an embodiment of the present application provides a baseboard management controller startup device, and the device includes:
[0039] A first verification module, configured to verify the target firmware corresponding to the baseboard management controller in the server according to the trusted root information;
[0040] A second verification module, configured to verify the operating system of the server and the application program of the baseboard management controller when the target firmware passes the verification;
[0041] An operation module, configured to control the startup of the baseboard management controller according to the target firmware when both the operating system and the application program pass the verification.
[0042] In a fourth aspect, an embodiment of the present application further provides a server, which includes a programmable logic chip, a memory, and a processor. The memory stores a computer program, and when the programmable logic chip executes the computer program, the steps of the method of any one of the above embodiments in the first aspect are implemented.
[0043] In a fifth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the programmable logic chip, the steps of the method of any one of the above embodiments in the first aspect are implemented.
[0044] In a sixth aspect, an embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by the programmable logic chip, the steps of the method of any one of the above embodiments in the first aspect are implemented.
[0045] The above description is only an overview of the technical solutions of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the description. And in order to make the above and other purposes, features, and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically listed below. Description of the Drawings
[0046] Figure 1 It is a schematic flowchart of a method for starting a baseboard management controller in an embodiment;
[0047] Figure 2 It is a schematic flowchart of a method for starting a baseboard management controller in another embodiment;
[0048] Figure 3 It is a schematic flowchart of a method for starting a baseboard management controller in another embodiment;
[0049] Figure 4 It is a schematic flowchart of a method for starting a baseboard management controller in another embodiment;
[0050] Figure 5 It is a schematic flowchart of a method for starting a baseboard management controller in another embodiment;
[0051] Figure 6 It is a schematic structural diagram of a programmable logic chip in an embodiment;
[0052] Figure 7 It is a structural block diagram of a baseboard management controller starting device in an embodiment;
[0053] Figure 8 It is an internal structural diagram of a server in an embodiment. Detailed implementation manners
[0054] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0055] In the field of server security, the baseboard management controller is an important component in the server. The security of the baseboard management controller is crucial for the secure operation of the entire server. Therefore, during the operation of the server, it is necessary to perform a security check on the startup process of the baseboard management controller to ensure the security after the baseboard management controller starts up. In the related art, mainly the trusted module on the integrated circuit chip externally plugged into the server is used to perform a security check on the startup process of the baseboard management controller. However, using the related art will incur additional security check costs, resulting in a relatively high security startup cost for the baseboard management controller. Based on this, the embodiments of the present application provide a method for starting a baseboard management controller, which can perform a security check on the startup process of the baseboard management controller without externally plugging in an integrated circuit chip, reducing the security startup cost of the baseboard management controller.
[0056] The baseboard management controller startup method provided in the embodiment of the present application can be applied to a programmable logic chip built into a server. Optionally, the above-mentioned server can be, but is not limited to, an independent server or a server cluster composed of multiple servers. The specific form of the server is not limited in this embodiment. The following embodiment will introduce the specific process of the baseboard management controller startup method with the programmable logic chip in the server as the execution subject.
[0057] like Figure 1 FIG. 1 is a flow chart of a method for starting a baseboard management controller according to an embodiment of the present application. The method is applied to a programmable logic chip in a server. The method can be implemented by the following steps:
[0058] S100: Based on the trusted root information, verify the target firmware corresponding to the baseboard management controller in the server.
[0059] It should be noted here that the above-mentioned server may include a hardware layer. The hardware layer in the server may include multiple hardware structures, such as an arithmetic unit, a controller, a memory, a motherboard, an input device, and an output device. However, the core hardware structure of the hardware layer in the server is the central processing unit (CPU), that is, the processor.
[0060] Specifically, when the processor in the server is started, the programmable logic chip in the server can obtain the trusted root information, and then based on the trusted root information, use a verification algorithm to perform security verification on the target firmware corresponding to the baseboard management controller in the server.
[0061] In one implementation, the trusted root information can be obtained from a solidified area in the processor. Optionally, the server's hardware layer can store the built-in code of the processor in the hardware layer. The built-in code of the processor is usually stored in the solidified area of the processor. The solidified area can be a storage area that cannot be permanently changed after the information in the processor is written. The information in the solidified area is relatively safe, that is, after the information is written to the solidified area, the information is not easily tampered with or lost. At the same time, the trusted root information can also be stored in the solidified area.
[0062] Among them, since the built-in code written into the hardened area is usually not easy to be tampered with or lost, there is no need to perform security verification on the built-in code of the processor. After the server is powered on, the built-in code of the processor can be automatically run to enable the server's processor to start safely. Optionally, the built-in code of the processor can perform operations such as processor memory initialization, user registration information filling, and pin parameter initialization of the chip in the server.
[0063] Optionally, the above information verification algorithm may be a cyclic redundancy check method, a parity check method, a Hamming code check method, etc., and the embodiments of the present application do not make any limitations in this regard. In addition, the above target firmware may include the startup firmware of the baseboard management controller itself and the startup firmware of the hardware managed by the baseboard management controller. The startup firmware of the hardware managed by the baseboard management controller may be a Programmable System-on-Chip (PSoC) firmware, etc.
[0064] In another implementation, the trusted root information may be obtained from the extended hardware (i.e., USBKEY) in the server. Optionally, the trusted root information may be pre-generated by the extended hardware in the server and the code before the Extensible Firmware Interface Driver Execution Environment (EFI DXE) phase, and stored in the extended hardware.
[0065] S200. If the target firmware verification passes, then verify the operating system of the server and the application program of the baseboard management controller.
[0066] In the embodiments of the present application, when the security verification of the target firmware passes, the programmable logic chip may verify the operating system of the server and the application program of the baseboard management controller.
[0067] Optionally, the operating system of the above server may be an operating system such as Windows, Linux, Unix, etc.; the application programs of the above baseboard management controller may include a health status detection program for each component in the server, a management program for each component in the server, a remote power-on / off function program, a remote Keyboard Video Mouse (KVM) control program, a hardware monitoring program, a user management program, etc., and the embodiments of the present application do not make any limitations in this regard.
[0068] Specifically, the programmable logic chip may adopt a verification algorithm to verify the operating system of the server and the application program of the baseboard management controller respectively.
[0069] In addition, the programmable logic chip may also first pre-construct a verification model, and then input the operating system of the server and the application program of the baseboard management controller into the verification model respectively. The verification model outputs the security verification results of the operating system of the server and the application program of the baseboard management controller in sequence. Optionally, the above verification model may be composed of at least one combination of a convolutional neural network model, a fully connected neural network model, a recurrent neural network model, and a long short-term memory neural network model, etc.
[0070] S300. If both the operating system and the application program pass the verification, then control the baseboard management controller to start according to the target firmware.
[0071] Based on the results of the foregoing steps, when the operating system of the server and the application program of the baseboard management controller both pass the verification, the programmable logic chip can load the startup firmware of the baseboard management controller in the target firmware onto the baseboard management controller to control the safe startup of the baseboard management controller.
[0072] The technical solution in the embodiment of the present application is applied to the programmable logic chip in the server. Based on the trusted root information, the target firmware corresponding to the baseboard management controller in the server is verified. If the target firmware passes the verification, the operating system of the server and the application program of the baseboard management controller are verified. If both the operating system and the application program pass the verification, the baseboard management controller is controlled to start according to the target firmware. The above method does not require an external security verification chip on the server, and the built-in chip in the server can be used to perform a security verification on the startup process of the baseboard management controller to safely start the baseboard management controller, thereby saving the cost brought by the external security verification chip and further reducing the security startup cost of the baseboard management controller; at the same time, the above method can automatically perform a security verification on the startup process of the baseboard management controller through the built-in chip in the server, avoiding the external plug-in process of the security verification chip, thereby accelerating the security verification speed during the startup process of the baseboard management controller and further improving the security startup speed of the baseboard management controller; in addition, the above method is applied to the programmable logic chip in the server, and in the case of updates to the target firmware, the operating system and the application program, the verification process can be flexibly changed to improve the accuracy of the verification result before the baseboard management controller starts, thereby improving the security after the baseboard management controller starts; furthermore, the above method can start from the trusted root information and sequentially perform layer-by-layer verification on the target firmware, the operating system and the application program corresponding to the baseboard management controller to form a trust chain, thereby greatly improving the security after the baseboard management controller starts.
[0073] The process of verifying the target firmware corresponding to the baseboard management controller in the server based on the trusted root information will be described below. In one embodiment, as Figure 2 shown, the steps in S100 above can be implemented in the following manner:
[0074] S110. Decrypt the signature value in the target firmware according to the trusted root information to obtain a first hash value.
[0075] Specifically, the trusted root security module in the programmable logic chip can read the target firmware from the storage unit of the server motherboard through the Serial Peripheral Interface (SPI) controller in the programmable logic chip, and then decrypt the signature value in the target firmware using the asymmetric public key decryption algorithm according to the trusted root information to obtain a first hash value.
[0076] Optionally, the above storage unit may be referred to as a baseboard management controller flash memory. Meanwhile, the above asymmetric public key decryption algorithm may be a decryption algorithm corresponding to an asymmetric public key encryption algorithm, where the above asymmetric public key encryption algorithm may be a public key encryption algorithm (i.e., the RSA algorithm), an elliptic curve cryptography algorithm (i.e., the ECC algorithm), a digital signature algorithm (i.e., the DSA algorithm), etc.
[0077] In an embodiment of the present application, the trusted root security module may have a firmware recovery function. Among them, when at least one of the target firmware, the operating system of the server, and the application program of the baseboard management controller fails the verification, it will cause the baseboard management controller to fail to start. At this time, the trusted root security module may read the startup firmware of the baseboard management controller backed up in the storage unit of the server through the serial peripheral interface controller, and replace the original startup firmware loaded on the baseboard management controller with the read startup firmware, so that the baseboard management controller can start normally, thereby improving the availability and reliability of the server.
[0078] In some scenarios, in order to improve the security of information and avoid the problem of information being tampered with during information transmission, after the programmable logic chip is started, it can establish trusted root information by itself. The process of the programmable logic chip establishing trusted root information will be described below. In one embodiment, before performing the steps in S100 above, the above method may further include: establishing trusted root information through the trusted root security module in the programmable logic chip.
[0079] Specifically, after the server is powered on, the programmable logic chip deployed on the server motherboard is powered on and started. At this time, the trusted root security module (i.e., the Rot module) in the programmable logic chip immediately takes effect and generates trusted root information.
[0080] The embodiment of the present application can establish trusted root information through the trusted root security module in the programmable logic chip. Without information transmission, the programmable logic chip can directly use it to implement the subsequent security verification process, thereby being able to avoid the problem of information being tampered with during information transmission and improving the security of the trusted root information.
[0081] S120. According to the hash algorithm in the target firmware, perform a hash process on the public key value in the target firmware to obtain a second hash value.
[0082] Among them, the programmable logic chip can obtain the hash algorithm in the target firmware, and perform hash processing on the public key value in the target firmware according to the hash algorithm in the target firmware to obtain a second hash value. Optionally, the above hash algorithm can be an irreversible encryption algorithm (such as the MD5 algorithm), a data verification algorithm (such as the CRC algorithm), or a secure hash algorithm (such as the SHA-1 algorithm, the international SHA1 algorithm, the SHA256 algorithm, the SHA284 algorithm, the SHA512 algorithm, the national cryptographic SM3 algorithm), etc.
[0083] S130. If the first hash value matches the second hash value, the target firmware passes the verification. Among them, the target firmware is the startup firmware of the baseboard management controller and the startup firmware of the hardware managed by the baseboard management controller.
[0084] Based on the first hash value and the second hash value obtained in the previous steps, it can be further determined whether the first hash value matches or is equal to the second hash value. If the first hash value matches or is equal to the second hash value, it is determined that the target firmware passes the verification.
[0085] In the embodiment of the present application, the target firmware includes the startup firmware of the baseboard management controller and the startup firmware of the hardware managed by the baseboard management controller. The startup firmware of the hardware managed by the baseboard management controller may include the Basic Input Output System (BIOS) firmware and the Complex Programmable Logic Device (CPLD) firmware.
[0086] Specifically, the trusted root security module in the programmable logic chip can decrypt the signature value in the startup firmware of the baseboard management controller according to the trusted root information to obtain a hash value, perform hash processing on the public key value in the startup firmware according to the hash algorithm in the startup firmware to obtain another hash value, and then determine whether these two hash values match or are equal. If these two hash values match or are equal, it is determined that the startup firmware of the baseboard management controller passes the security verification.
[0087] At the same time, the trusted root security module in the programmable logic chip can decrypt the signature value in the BIOS firmware according to the trusted root information to obtain a hash value, perform hash processing on the public key value in the BIOS firmware according to the hash algorithm in the BIOS firmware to obtain another hash value, and then determine whether these two hash values match or are equal. If these two hash values match or are equal, it is determined that the BIOS firmware passes the security verification.
[0088] In addition, the trusted root security module in the programmable logic chip can also decrypt the signature value in the CPLD firmware according to the trusted root information to obtain a hash value, perform a hash process on the public key value in the CPLD firmware according to the hash algorithm in the CPLD firmware to obtain another hash value, and then determine whether these two hash values match or are equal. If these two hash values match or are equal, it is determined that the CPLD firmware security verification passes.
[0089] It should be noted here that the security verification processes of the startup firmware, BIOS firmware, and CPLD firmware of the baseboard management controller are independent of each other and do not affect each other. Moreover, these three security verification processes can be executed synchronously or asynchronously. The embodiments of this application do not make any limitations in this regard.
[0090] In practical applications, when the security verifications of the startup firmware, BIOS firmware, and CPLD firmware of the baseboard management controller all pass, it is determined that the target firmware security verification passes.
[0091] In the technical solution of the embodiments of this application, according to the trusted root information, the signature value in the target firmware is decrypted to obtain a first hash value, and according to the hash algorithm in the target firmware, the public key value in the target firmware is subjected to a hash process to obtain a second hash value. When the first hash value matches the second hash value, it is determined that the target firmware verification passes; the above method can perform security verification on the startup firmware of the baseboard management controller itself and the startup firmware of the hardware managed by the baseboard management controller before the baseboard management controller starts, so as to prepare for the secure startup of the baseboard management controller and improve the security after the baseboard management controller starts.
[0092] The process of verifying the operating system of the server and the application program of the baseboard management controller will be described below. In one embodiment, the target firmware includes the startup firmware of the baseboard management controller; as Figure 3 shown, the steps of verifying the operating system of the server and the application program of the baseboard management controller in S200 above can be implemented in the following manner:
[0093] S210. Control the execution of the startup firmware of the baseboard management controller to obtain the trusted function firmware corresponding to the trusted module.
[0094] After the target firmware verification passes, the trusted root security module in the programmable logic chip can send the startup firmware in the target firmware to at least one soft core in the programmable logic chip through the bus system. Further, at least one soft core (i.e., CORE) in the programmable logic chip can control the execution of the startup firmware in the target firmware and read the trusted function firmware corresponding to the trusted module from the storage unit of the server.
[0095] It should be noted here that multiple soft cores can be set on the programmable logic chip. In actual applications, the number of soft cores required to control the execution of the startup firmware can be flexibly set according to actual needs. When some soft cores are not used, these soft cores can all be in an idle state. Among them, the more the number of soft cores, the faster the running speed of the startup firmware. Optionally, the above soft core can be understood as a processor soft IP.
[0096] Optionally, the above trusted module can be a Trusted Platform Module (TPM), a Trusted Service Manager (TSM) module, etc. However, in the embodiments of this application, the above trusted module can include a Trusted Platform Control Module (TPCM) and a Trusted Cryptography Module (TCM).
[0097] In actual applications, the above trusted function firmware can include TPCM code and TCM code. In the embodiments of this application, the TCM2.0 code is taken as an example for illustration. It should be noted here that both the TPCM code and the TCM code can be codes written in the Verilog language, so that they can be conveniently and quickly read from the storage unit of the server when in use, and the TPCM code and the TCM code can also be conveniently and flexibly changed.
[0098] Among them, when the trusted module is TPCM, the corresponding trusted function firmware is the TCPM code; when the trusted module is TCM, the corresponding trusted function firmware is the TCM code.
[0099] S220. Verify the trusted function firmware according to the trusted root information.
[0100] Specifically, at least one soft core in the programmable logic chip can perform a security verification on the TCPM code and the TCM code in the trusted function firmware respectively according to the trusted root information by using a verification algorithm through the executed startup firmware.
[0101] In addition, at least one soft core in the programmable logic chip can pre - construct an algorithm model, and then input both the trusted root information and the TCPM code in the trusted function firmware into the algorithm model, and the algorithm model outputs the verification result of the TCPM code. At the same time, the programmable logic chip can also input both the trusted root information and the TCM code in the trusted function firmware into the algorithm model, and the algorithm model outputs the verification result of the TCM code.
[0102] It should be noted here that when the verification results of both the TCPM code and the TCM code pass, it is determined that the security verification of the trusted function firmware passes.
[0103] Among them, the number of soft cores required for verifying the trusted function firmware can be flexibly set according to actual needs; among them, the more the number of soft cores, the faster the verification speed of the trusted function firmware.
[0104] S230. If the verification of the trusted function firmware passes, then based on the trusted function firmware, verify the operating system of the server and the application program of the baseboard management controller.
[0105] Based on the results of the previous steps, when the security verification of the trusted function firmware passes, at least one soft core in the programmable logic chip can control the execution of the startup firmware in the target firmware, read the operating system of the server and the application program of the baseboard management controller from the storage unit of the server, and then load the trusted function firmware into the trusted module, and verify the operating system of the server and the application program of the baseboard management controller through the trusted module respectively.
[0106] Among them, the method of verifying the operating system of the server through the trusted module can be to pre-train a security verification model, and then input both the trusted function firmware on the trusted module and the operating system of the server into the security verification model, and the security verification model outputs the verification result of the operating system. At the same time, the method of verifying the application program of the baseboard management controller through the trusted function firmware can be to input both the trusted function firmware and the application program of the baseboard management controller into the security verification model, and the security verification model outputs the verification result of the application program.
[0107] Optionally, the above security verification model can be composed of at least one combination of a convolutional neural network model, a radial neural network model, a feedforward neural network model, a feedback neural network model, and a graph neural network model, etc.
[0108] In practical applications, the number of soft cores required for verifying the operating system and the application program can be flexibly set according to actual needs; among them, the more the number of soft cores, the faster the verification speed of the operating system and the application program.
[0109] In the technical solution of the embodiment of the present application, the startup firmware of the baseboard management controller is controlled to obtain the trusted function firmware corresponding to the trusted module, and the trusted function firmware is verified according to the trusted root information. If the verification of the trusted function firmware passes, the operating system of the server and the application program of the baseboard management controller are verified according to the trusted function firmware; the above method can first verify the trusted function firmware, and then verify the operating system of the server and the application program of the baseboard management controller through the verified trusted function firmware, thereby improving the accuracy and credibility of the verification results of the operating system and the application program.
[0110] The process of verifying the trusted function firmware according to the trusted root information is described below. In one embodiment, as Figure 4 shown, the steps in S220 above can be implemented in the following manner:
[0111] S221. According to the trusted root information, decrypt the signature value in the trusted function firmware to obtain a third hash value.
[0112] Specifically, at least one soft core in the programmable logic chip can decrypt the signature value in the trusted function firmware according to the trusted root information by using an asymmetric public key decryption algorithm to obtain a third hash value.
[0113] S222. According to the hash algorithm in the trusted function firmware, perform a hash process on the public key value in the trusted function firmware to obtain a fourth hash value.
[0114] Among them, at least one soft core in the programmable logic chip can obtain the hash algorithm in the trusted function firmware and perform a hash process on the public key value in the trusted function firmware according to the hash algorithm in the trusted function firmware to obtain a fourth hash value.
[0115] S223. If the third hash value matches the fourth hash value, the verification of the trusted function firmware passes.
[0116] Based on the third hash value and the fourth hash value obtained in the previous steps, it can be continued to determine whether the third hash value matches or is equal to the fourth hash value. If the third hash value matches or is equal to the fourth hash value, it is determined that the verification of the trusted function firmware passes.
[0117] In the embodiment of the present application, since the trusted function firmware includes TCPM code and TCM code. Specifically, at least one soft core in the programmable logic chip can decrypt the signature value in the TCPM code according to the trusted root information to obtain a hash value, perform a hash process on the public key value in the TCPM code according to the hash algorithm in the TCPM code to obtain another hash value, and then determine whether these two hash values match or are equal. If these two hash values match or are equal, it is determined that the security verification of the TCPM code passes.
[0118] Meanwhile, at least one soft core in the programmable logic chip can decrypt the signature value in the TCM code according to the trusted root information to obtain a hash value, perform a hash process on the public key value in the startup firmware according to the hash algorithm in the TCM code to obtain another hash value, and then determine whether these two hash values match or are equal. If these two hash values match or are equal, it is determined that the security check of the TCM code passes.
[0119] It should be noted here that the security check processes of the TCPM code and the TCM code are independent of each other and do not affect each other. And these two security check processes can be executed synchronously or asynchronously. The embodiments of the present application do not make any limitations in this regard.
[0120] In practical applications, when the security checks of both the TCPM code and the TCM code pass, it is determined that the security check of the trusted function firmware passes.
[0121] In the technical solution of the embodiments of the present application, the signature value in the trusted function firmware is decrypted according to the trusted root information to obtain a third hash value, and the public key value in the trusted function firmware is hashed according to the hash algorithm in the trusted function firmware to obtain a fourth hash value. If the third hash value matches the fourth hash value, it is determined that the verification of the trusted function firmware passes; the above method can perform a security check on the trusted function firmware before the operating system of the server and the application program of the baseboard management controller, so as to prepare for the security checks of the operating system of the server and the application program of the baseboard management controller, and improve the accuracy and credibility of the verification results of the operating system of the server and the application program of the baseboard management controller.
[0122] The process of verifying the operating system of the server and the application program of the baseboard management controller according to the trusted function firmware will be described below. In one embodiment, as Figure 5 shown, the steps of verifying the operating system of the server and the application program of the baseboard management controller according to the trusted function firmware in S230 above may include the following steps:
[0123] S231. Perform integrity measurement on the operating system and the application program according to the trusted function firmware to obtain a measurement value.
[0124] Among them, at least one soft core in the programmable logic chip can load the trusted function firmware TCPM code and / or TCM code into the trusted module on the programmable logic chip, so as to perform integrity measurement on the operating system and the application program through the trusted module to obtain a measurement value.
[0125] When the trusted function firmware is the TCPM code, the TCPM code can be loaded into the TCPM; when the trusted function firmware is the TCM code, the TCM code can be loaded into the TCM. In the embodiments of the present application, when the TPCM runs the TPCM code or the TCM runs the TCM code, the national cryptographic algorithms stored on the programmable logic chip can be called, such as the SM2 algorithm, the SM3 algorithm, the SM4 algorithm, etc.
[0126] At the same time, when running the TPCM code or the TCM code, it is also necessary to call the random number generator (RNG) on the programmable logic chip to generate random numbers, and store the corresponding data through the memory on the programmable logic chip. Optionally, the memory on the programmable logic chip can be a non-volatile random access memory (NVRAM).
[0127] In practical applications, the above integrity measurement process may include: performing integrity measurement on the operating system according to the TCPM code and / or the TCM code in the trusted function firmware to obtain the measurement value of the operating system, and performing integrity measurement on the application program according to the TCPM code and / or the TCM code in the trusted function firmware to obtain the measurement value of the application program.
[0128] It should be noted here that the execution process of performing integrity measurement on the operating system and performing integrity measurement on the application program can be carried out synchronously or asynchronously, and the embodiments of the present application do not make any limitations in this regard.
[0129] S232. If the measurement value matches the standard measurement value, the operating system and the application program pass the verification.
[0130] In the embodiments of the present application, the standard measurement value may include the standard measurement value of the operating system and the standard measurement value of the application program. Optionally, both the standard measurement value of the operating system and the standard measurement value of the application program can be user-defined or determined according to historical experience values.
[0131] Specifically, at least one soft core in the programmable logic chip can determine whether the measurement value of the operating system matches or is equal to the standard measurement value of the operating system. If the measurement value of the operating system matches or is equal to the standard measurement value of the operating system, it is determined that the operating system passes the security verification.
[0132] At the same time, at least one soft core in the programmable logic chip can determine whether the measurement value of the application program matches or is equal to the standard measurement value of the application program. If the measurement value of the application program matches or is equal to the standard measurement value of the application program, it is determined that the application program passes the security verification.
[0133] As Figure 6 shown in the structural diagram of the programmable logic chip, where Figure 6 taking the example of setting four soft cores (i.e., soft core 1, soft core 2, soft core 3, and soft core 4) on the programmable logic chip, in practical applications, the trusted root security module in the programmable logic chip interacts with the storage unit on the server through the serial peripheral interface controller to read the corresponding code and firmware stored in the storage unit on the server.
[0134] Meanwhile, a security transmission module is further provided on the above programmable logic chip. The security transmission module includes a Peripheral Component Interconnect Express (PCIE) controller, an encryption unit, and a storage unit. Among them, the PCIE controller can receive the data transmitted through the bus system and transmit the received data to the encryption unit through a data exchange tool (i.e., DOE) to instruct the encryption unit to encrypt the data, so as to achieve the purpose of securely transmitting the data in subsequent application processes. Further, the encryption unit can transmit the encrypted data back to the PCIE controller, and the PCIE controller then transmits the encrypted data to the storage unit for storage. After that, when the programmable logic chip interacts with the processor in the server, the PCIE controller can read the encrypted data stored in the storage unit and transmit the encrypted data to the processor.
[0135] In the technical solution of the embodiment of the present application, the integrity of the operating system and the application program is measured according to the trusted function firmware to obtain a measurement value. If the measurement value matches the standard measurement value, the operating system and the application program pass the verification. The above method can verify the operating system of the server and the application program of the baseboard management controller based on the trusted function firmware that passes the security verification, which can improve the accuracy and credibility of the verification results of the operating system and the application program. At the same time, the above method can perform security verification on the operating environment (i.e., the operating system) of the baseboard management controller and the applications on the baseboard management controller before the baseboard management controller is started, so as to improve the security of the baseboard management controller to a greater extent after startup. At the same time, the above method can use the trusted function firmware, that is, the national cryptographic algorithm, to verify the operating system of the server and the application program of the baseboard management controller, which can make the verification results of the operating system and the application program more secure and credible.
[0136] In one embodiment, the embodiment of the present application further provides a method for starting a baseboard management controller, which is applied to a programmable logic chip in a server. The method includes the following processes:
[0137] (1) Establish trusted root information through the trusted root security module in the programmable logic chip.
[0138] (2) Decrypt the signature value in the target firmware according to the trusted root information to obtain the first hash value.
[0139] (3) Perform a hash process on the public key value in the target firmware according to the hash algorithm in the target firmware to obtain the second hash value.
[0140] (4) If the first hash value matches the second hash value, the target firmware passes the verification; the target firmware is the startup firmware of the baseboard management controller and the startup firmware of the hardware managed by the baseboard management controller.
[0141] (5) When the target firmware passes the verification, control the execution of the startup firmware of the baseboard management controller to obtain the trusted function firmware corresponding to the trusted module.
[0142] (6) Decrypt the signature value in the trusted function firmware according to the trusted root information to obtain the third hash value.
[0143] (7) Perform a hash process on the public key value in the trusted function firmware according to the hash algorithm in the trusted function firmware to obtain the fourth hash value.
[0144] (8) If the third hash value matches the fourth hash value, the trusted function firmware passes the verification.
[0145] (9) If the trusted function firmware passes the verification, perform an integrity measurement on the operating system and application programs according to the trusted function firmware to obtain a measurement value.
[0146] (10) If the measurement value matches the standard measurement value, the operating system and application programs pass the verification.
[0147] (11) When both the operating system and application programs pass the verification, control the startup of the baseboard management controller according to the target firmware.
[0148] The execution processes of the above (1) to (11) can specifically refer to the description of the above embodiments, and their implementation principles and technical effects are similar, so they will not be elaborated here.
[0149] It should be understood that although the steps in the flowcharts involved in the above embodiments are sequentially shown according to the indications of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0150] In one embodiment, a substrate management controller startup system is further provided, including: a programmable logic chip and a substrate management controller;
[0151] The programmable logic chip is used to implement the steps in the above embodiment of the substrate management controller startup method and control the startup of the substrate management controller.
[0152] In practical applications, the basic management controller startup system can be an independent system outside the server, and the embodiments of this application do not limit this. Among them, during the process of the programmable logic chip executing the substrate management controller startup method, the programmable logic chip can read the trusted function firmware from a storage unit independent of the substrate management controller startup system and complete the substrate management controller startup method through the trusted function firmware.
[0153] In one embodiment, the above system further includes: a storage unit;
[0154] Among them, the storage unit is used to store the trusted function firmware for the programmable logic chip to read the trusted function firmware and complete the substrate management controller startup method through the trusted function firmware.
[0155] In the embodiments of this application, the above substrate management controller startup system may further include a storage unit for storing the trusted function firmware.
[0156] Furthermore, in one embodiment, the above programmable logic chip includes a trusted module;
[0157] Among them, the programmable logic chip is specifically used to load the verified trusted function firmware into the trusted module to verify the operating system of the server and the application program of the substrate management controller through the trusted module.
[0158] Among them, the above programmable logic chip may include a trusted root security module, a serial peripheral interface controller, at least one soft core, a trusted platform control module, a trusted password module, a memory, and a security transmission module. The security transmission module may include a high-speed serial computer extension bus standard controller, an encryption unit, and a storage unit.
[0159] The baseboard management controller startup system provided by the embodiments of the present application can be used to execute the technical solutions in the above embodiments of the baseboard management controller startup method. The implementation principle and technical effects are similar, and will not be elaborated here.
[0160] Based on the same inventive concept, the embodiments of the present application also provide a baseboard management controller startup device for implementing the above-mentioned baseboard management controller startup method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more of the following embodiments of the baseboard management controller startup device can refer to the limitations on the baseboard management controller startup method in the above text, and will not be elaborated here.
[0161] In one embodiment, Figure 7 is a schematic structural diagram of a baseboard management controller startup device in an embodiment of the present application. The baseboard management controller startup device provided by the embodiments of the present application can be applied to a programmable logic chip in a server. As Figure 7 shown, the baseboard management controller startup device of the embodiments of the present application may include: a first verification module 11, a second verification module 12, and an operation module 13, where:
[0162] The first verification module 11 is configured to verify a target firmware corresponding to the baseboard management controller in the server according to trusted root information;
[0163] The second verification module 12 is configured to verify the operating system of the server and the application program of the baseboard management controller when the target firmware passes the verification;
[0164] The operation module 13 is configured to control the startup of the baseboard management controller according to the target firmware when both the operating system and the application program pass the verification.
[0165] The baseboard management controller startup device provided by the embodiments of the present application can be used to execute the technical solutions in the above embodiments of the baseboard management controller startup method. The implementation principle and technical effects are similar, and will not be elaborated here.
[0166] In one of the embodiments, the baseboard management controller startup device further includes: a trust root establishment module, where:
[0167] A root of trust establishment module, configured to establish root of trust information through a trusted root security module in a programmable logic chip.
[0168] The baseboard management controller startup device provided by an embodiment of this application can be used to execute the technical solutions in the above-mentioned embodiment of the baseboard management controller startup method of this application. The implementation principles and technical effects are similar and will not be elaborated here.
[0169] In one embodiment, the first verification module 11 includes: a decryption unit, a hash processing unit, and a determination unit, where:
[0170] The decryption unit is configured to decrypt the signature value in the target firmware according to the root of trust information to obtain a first hash value;
[0171] The hash processing unit is configured to perform hash processing on the public key value in the target firmware according to the hash algorithm in the target firmware to obtain a second hash value;
[0172] The determination unit is configured to, when the first hash value matches the second hash value, pass the verification of the target firmware; the target firmware is the startup firmware of the baseboard management controller and the startup firmware of the hardware managed by the baseboard management controller.
[0173] The baseboard management controller startup device provided by an embodiment of this application can be used to execute the technical solutions in the above-mentioned embodiment of the baseboard management controller startup method of this application. The implementation principles and technical effects are similar and will not be elaborated here.
[0174] In one embodiment, the target firmware includes the startup firmware of the baseboard management controller; the second verification module 12 includes: a function file acquisition unit, a firmware verification unit, and a verification unit, where:
[0175] The function file acquisition unit is configured to control the execution of the startup firmware of the baseboard management controller to obtain the trusted function firmware corresponding to the trusted module;
[0176] The firmware verification unit is configured to verify the trusted function firmware according to the root of trust information;
[0177] The verification unit is configured to, when the trusted function firmware passes the verification, verify the operating system of the server and the application program of the baseboard management controller according to the trusted function firmware.
[0178] The baseboard management controller startup device provided by an embodiment of this application can be used to execute the technical solutions in the above-mentioned embodiment of the baseboard management controller startup method of this application. The implementation principles and technical effects are similar and will not be elaborated here.
[0179] In one embodiment, the firmware verification unit is specifically configured to:
[0180] Decrypt the signature value in the trusted functional firmware according to the trusted root information to obtain the third hash value;
[0181] According to the hash algorithm in the trusted functional firmware, perform a hash process on the public key value in the trusted functional firmware to obtain the fourth hash value;
[0182] If the third hash value matches the fourth hash value, the verification of the trusted functional firmware passes.
[0183] The baseboard management controller startup device provided by the embodiments of the present application can be used to execute the technical solutions in the above-mentioned baseboard management controller startup method embodiments of the present application. The implementation principles and technical effects are similar and will not be elaborated here.
[0184] In one embodiment, the verification unit is specifically used for:
[0185] According to the trusted functional firmware, perform an integrity measurement on the operating system and application programs to obtain a measurement value;
[0186] If the measurement value matches the standard measurement value, the verification of the operating system and application programs passes.
[0187] The baseboard management controller startup device provided by the embodiments of the present application can be used to execute the technical solutions in the above-mentioned baseboard management controller startup method embodiments of the present application. The implementation principles and technical effects are similar and will not be elaborated here.
[0188] For the specific limitations of the baseboard management controller startup device, reference can be made to the limitations on the baseboard management controller startup method in the above text, which will not be elaborated here. Each module in the above baseboard management controller startup device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the programmable logic chip in the server in hardware form or independent of it, or stored in the memory of the server in software form, so that the programmable logic chip can call and execute the operations corresponding to the above modules.
[0189] In one embodiment, a server is further provided. The internal structure diagram of the server can be as Figure 8 shown. The server includes a processor, a programmable logic chip, a memory, and a network interface connected through a system bus. Among them, the processor of the server is used to provide processing capabilities. The memory of the server includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the server is used to store trusted root information. The network interface of the server is used to communicate with an external endpoint through a network connection. When the computer program is executed by the processor, it implements a baseboard management controller startup method.
[0190] Those skilled in the art can understand that Figure 8 the structure shown in Figure 8 is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the server to which the solution of this application is applied. The specific server may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0191] In one embodiment, a server is further provided, which includes the programmable logic chip, memory, and processor in the above embodiments of this application. A computer program is stored in the memory. When the programmable logic chip executes the computer program, the technical solutions in the above embodiments of the substrate management controller startup method of this application are implemented. The implementation principle and technical effects are similar and will not be elaborated here.
[0192] In one embodiment, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by the programmable logic chip, the technical solutions of the above substrate management controller startup method of this application are implemented. The implementation principle and technical effects are similar and will not be elaborated here.
[0193] In one embodiment, a computer program product is further provided, including a computer program. When the computer program is executed by the programmable logic chip, the technical solutions of the above substrate management controller startup method of this application are implemented. The implementation principle and technical effects are similar and will not be elaborated here.
[0194] Those of ordinary skill in the art can understand that all or part of the processes in the above embodiment methods can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it may include the processes of the above method embodiments. Among them, any reference to memory, storage, database, or other media used in the various embodiments provided in this application may include at least one of non-volatile and volatile memories. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0195] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0196] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A method for starting a baseboard management controller, characterized in that A programmable logic chip applied in a server, the method comprising: Based on trusted root information, verifying a target firmware corresponding to a baseboard management controller in the server; If the verification of the target firmware passes, verifying the operating system of the server and the application program of the baseboard management controller; If both the operating system and the application program pass the verification, controlling the baseboard management controller to start according to the target firmware.
2. The method according to claim 1, characterized in that, Before verifying the target firmware corresponding to the baseboard management controller in the server based on the trusted root information, the method further comprises: Establishing the trusted root information through a trusted root security module in the programmable logic chip.
3. The method according to claim 1 or 2, characterized in that, The target firmware includes a startup firmware of the baseboard management controller; verifying the operating system of the server and the application program of the baseboard management controller includes: After controlling the execution of the startup firmware of the baseboard management controller, obtaining a trusted function firmware corresponding to a trusted module; Verifying the trusted function firmware according to the trusted root information; If the verification of the trusted function firmware passes, verifying the operating system of the server and the application program of the baseboard management controller according to the trusted function firmware.
4. The method according to claim 3, characterized in that Verifying the operating system of the server and the application program of the baseboard management controller according to the trusted function firmware includes: Performing integrity measurement on the operating system and the application program according to the trusted function firmware to obtain a measurement value; If the measurement value matches the standard measurement value, the operating system and the application program pass the verification.
5. A substrate management controller startup system, characterized in that, The system comprises: a programmable logic chip and a baseboard management controller; The programmable logic chip is configured to execute the method for starting the baseboard management controller according to any one of claims 1-4, and control the baseboard management controller to start.
6. The system according to claim 5, wherein The system further comprises: a storage unit; The storage unit is configured to store the trusted function firmware for the programmable logic chip to read the trusted function firmware and complete the method for starting the baseboard management controller through the trusted function firmware.
7. The system according to claim 6, characterized in that, The programmable logic chip comprises a trusted module; Wherein, the programmable logic chip is specifically configured to load the verified trusted function firmware into the trusted module to verify the operating system of the server and the application program of the baseboard management controller through the trusted module.
8. A substrate management controller startup device, characterized in that, The device comprises: A first verification module, configured to verify a target firmware corresponding to a baseboard management controller in a server according to trusted root information; A second verification module, configured to verify the operating system of the server and the application program of the baseboard management controller when the verification of the target firmware passes; An operation module, configured to control the baseboard management controller to start according to the target firmware when both the operating system and the application program pass the verification.
9. A server, comprising a programmable logic chip, a memory, and a processor, wherein the memory stores a computer program, characterized in that When the programmable logic chip executes the computer program, the steps of the method according to any one of claims 1-4 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the programmable logic chip, the steps of the method according to any one of claims 1-4 are implemented.
11. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a programmable logic chip, it implements the steps of the method described in any one of claims 1-4.
Citation Information
Cited By
Baseboard management controller, electronic equipment and starting method
CN121188799A
Baseboard management controller, electronic device, and start-up method
CN121188799B