Safe starting processing method and device of application program and storage medium

CN120234807AActive Publication Date: 2025-07-01CHENGDU TD TECH LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311870685.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01
Estimated Expiration
2043-12-29

Smart Images

  • Figure CN120234807A_ABST
    Figure CN120234807A_ABST
Patent Text Reader

Abstract

The invention provides a safe starting processing method and device for an application program and a storage medium, and relates to the technical field of chips. The method comprises the following steps: in response to a system power-on signal, calling a secure startup program so as to check whether Uboot is credible or not according to the secure startup program; if the verification result of the security startup program to the Uboot is credible, calling a security chip to verify the system to be loaded and a security verification program based on the Uboot; if the verification results of the to-be-loaded system and the security verification program are credible, calling a security chip to verify a key component of each to-be-loaded application based on the security verification program; and if the verification result of the key component of the to-be-loaded application is credible, starting an application program based on the key component. According to the method, reliable and effective transmission of the trust chain is realized, the transmission of the trust chain in the whole starting process has no breakpoint, the starting safety of the system is ensured, and meanwhile, the safe starting of the system is ensured to meet the power industry standard.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of chip technology, and in particular to a method, device, and storage medium for secure startup processing of application programs. Background Art

[0002] A System-on-a-Chip (SoC) is a highly integrated electronic system that integrates multiple functional modules onto a single chip, thereby improving system performance, reducing power consumption, and decreasing physical size.

[0003] When an SoC is used, it first needs to perform a security check through a security chip. The existing security check process mainly includes: after the system is powered on, the security chip calls Uboot in the SPI Flash to perform firmware verification, and after the verification passes, the SPISwitch is used to switch the path between the SPI Flash and the SoC, so that the SoC can load Uboot in the SPI Flash, and the kernel and file system are loaded and verified according to Uboot to complete the startup of the system.

[0004] In the above SoC structure, if Uboot in the SPI Flash is tampered with or the security chip is short-circuited, the verification of the security chip will fail. At the same time, it will also cause the loaded kernel to be an unexpected kernel, resulting in the system being unable to reverse-check Uboot, making the startup process untrustworthy. Summary of the Invention

[0005] This application provides a method, device, and storage medium for secure startup processing of application programs to solve the problem that when Uboot in the SPI Flash is tampered with or the security chip is short-circuited before the existing chip starts up, the verification of the security chip will fail, and at the same time, it will also cause the loaded kernel to be an unexpected kernel, resulting in the system being unable to reverse-check Uboot, making the startup process untrustworthy.

[0006] In a first aspect, this application provides a method for secure startup processing of application programs, including:

[0007] In response to a system power-on signal, call a secure startup program to verify whether Uboot is trustworthy according to the secure startup program; wherein, the secure startup program includes calling a security chip to verify Uboot.

[0008] If the verification result of the secure startup program for Uboot is trustworthy, then call a security chip based on Uboot to verify the system and security verification program to be loaded; wherein, the system to be loaded includes a kernel and an initialization process.

[0009] If the verification results of the system to be loaded and the security verification program are both trustworthy, then call the security chip based on the security verification program to verify each key component of the application to be loaded;

[0010] If the verification result of the key component of the application to be loaded is trustworthy, then start the application program based on the key component.

[0011] In a possible design, the calling the security startup program to verify whether Uboot is trustworthy according to the security startup program includes:

[0012] Trigger the security core to call the built-in trusted root certificate, and verify the bootloader according to the trusted root certificate; wherein, the bootloader is used to guide the security chip to verify Uboot;

[0013] If the bootloader is trustworthy, then call the security chip based on the bootloader to verify Uboot.

[0014] In a possible design, it further includes:

[0015] If the verification result of Uboot is not trustworthy, or the verification results of the system to be loaded and the security verification program are not trustworthy, or the verification result of the key component of the application to be loaded is not trustworthy, then restart the system.

[0016] In a possible design, the starting the application program based on the key component includes:

[0017] Call the security chip based on the key component to verify the application program corresponding to the key component;

[0018] If the verification result of the application program corresponding to the key component is trustworthy, then start the application program.

[0019] In a second aspect, the present application provides a system-on-chip, including:

[0020] A security module, configured to respond to a system power-on signal, call a security startup program to verify whether Uboot is trustworthy according to the security startup program; wherein, the security startup program includes calling a security chip to verify Uboot;

[0021] A service module, configured to, if the verification result of Uboot by the security startup program is trustworthy, call a security chip based on Uboot to verify the system to be loaded and the security verification program; wherein, the system to be loaded includes a kernel and an initialization process;

[0022] The service module is further configured to, if the verification results of the system to be loaded and the security verification program are both trustworthy, call a security chip based on the security verification program to verify each key component of the application to be loaded;

[0023] The service module is further configured to start an application program based on the key component if the verification result of the key component of the application to be loaded is trustworthy.

[0024] Optionally, the service module is specifically configured to call a secure startup program to verify whether Uboot is trustworthy according to the secure startup program, including:

[0025] Trigger the secure core to call the built-in trusted root certificate, and verify the bootloader according to the trusted root certificate; wherein, the bootloader is used to guide the secure chip to verify Uboot;

[0026] If the bootloader is trustworthy, call the secure chip to verify Uboot based on the bootloader.

[0027] Optionally, the service module is specifically configured to start an application program based on the key component, including:

[0028] Call the secure chip to verify the application program corresponding to the key component based on the key component;

[0029] If the verification result of the application program corresponding to the key component is trustworthy, start the application program.

[0030] Furthermore, it further includes:

[0031] A restart module, configured to restart the system if the verification result of Uboot is untrustworthy, or the verification results of the system and the security verification program to be loaded are untrustworthy, or the verification result of the key component of the application to be loaded is untrustworthy.

[0032] In a third aspect, the present application provides a secure startup system, including:

[0033] An embedded multimedia card, a secure chip, and a system-on-chip, the embedded multimedia card and the secure chip are respectively connected to the system-on-chip; wherein, the system-on-chip includes a secure core and a service core, the secure core is used to verify Uboot according to the built-in trusted root certificate of the secure core, and the service core is used to verify the service to be loaded in the embedded multimedia card according to the Uboot verified by the secure core.

[0034] In a fourth aspect, the present application provides an electronic device, including:

[0035] A processor, and a memory communicatively connected to the processor;

[0036] The memory stores computer-executable instructions;

[0037] The processor executes the computer-executable instructions stored in the memory to implement a secure boot processing method for an application program.

[0038] In a fifth aspect, the present application provides a computer-readable storage medium storing computer-executable instructions, which are used to implement a secure boot processing method for an application program when executed by a processor.

[0039] In a sixth aspect, the present application provides a computer program product, including:

[0040] A computer program, which implements a secure boot processing method for an application program when executed by a processor.

[0041] The secure boot processing method, device, and storage medium provided by the present application respond to a system power-on signal, call a secure boot program, and verify whether Uboot is trustworthy according to the secure boot program; if the verification result of Uboot by the secure boot program is trustworthy, then call a security chip based on Uboot to verify the system to be loaded and the security verification program; if the verification results of the system to be loaded and the security verification program are both trustworthy, then call a security chip based on the security verification program to verify the key components of each application to be loaded; if the verification result of the key components of the application to be loaded is trustworthy, then start the application program based on the key components. Compared with the prior art, when Uboot in the SPI Flash is tampered with or the security chip is short-circuited before the chip starts, the verification of the security chip will fail, and at the same time, it will also cause the loaded kernel to be an unexpected kernel, resulting in the system being unable to reverse-verify Uboot, making the startup process untrustworthy. The present application realizes the reliable and effective transmission of the trust chain, and there is no breakpoint in the transmission of the trust chain during the entire startup process, ensuring the security of the system startup and at the same time ensuring that the secure startup of the system meets the power industry standards. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0043] Figure 1 It is a schematic diagram of the secure boot processing process of an application program provided by the prior art of the present application;

[0044] Figure 2 It is a flowchart of the secure boot processing method for an application program provided by an embodiment of the present application Figure 1 ;

[0045] Figure 3 Schematic flow chart of the secure startup processing method for the application program provided by the embodiment of the present application Figure 2 ;

[0046] Figure 4 Schematic structural diagram of the secure startup processing device for the application program provided by the embodiment of the present application;

[0047] Figure 5 Schematic structural diagram of the secure startup system provided by the embodiment of the present application;

[0048] Figure 6 Schematic hardware structure diagram of the electronic device provided by the embodiment of the present application;

[0049] Figure 7 Schematic flow chart of the secure startup processing method for the application program provided by the embodiment of the present application Figure 3 。

[0050] Description of reference numerals:

[0051] 101, security chip; 102, SPI Flash; 103, SPI Switch; 104, system-on-chip; 105, embedded multimedia card;

[0052] 401, security module; 402, service module; 403, restart module;

[0053] 501, embedded multimedia card; 502, security chip; 503, system-on-chip;

[0054] 601, processor; 602, memory; 603, communication component; 604, bus. Detailed implementation manners

[0055] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are only examples of devices and methods consistent with some aspects of the present application, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the protection scope of the present invention.

[0056] First, the relevant concepts or terms involved in the present application are explained:

[0057] System-on-a-Chip (SoC): It refers to a highly integrated electronic system that integrates multiple functional modules onto a single chip, thereby improving system performance, reducing power consumption, and decreasing physical size.

[0058] Uboot: It refers to a general CPU bootloader, mainly applied to the bootloader module of embedded terminals.

[0059] Kernel: It refers to an operating system kernel.

[0060] Init: It refers to the initialization process required for system startup.

[0061] Security chip: It refers to a device that can independently generate keys, encrypt and decrypt. It has an independent processor and storage unit inside, can store keys and feature data, and provides encryption and security authentication services for the computer.

[0062] Serial Peripheral Interface (SPI): It refers to a synchronous peripheral interface that enables a microcontroller to communicate with various peripheral devices in a serial manner to exchange information. Peripheral devices include Flash RAM, network controllers, LCD display drivers, A / D converters, and MCUs, etc.

[0063] Embedded Multi Media Card (eMMC): It refers to a standard for flash memory cards that defines the physical architecture, access interface, and protocol of a storage system based on the embedded multi-media card.

[0064] Flash: It refers to a non-volatile storage device, similar to a hard disk or solid-state drive, but with faster read and write speeds, more durable, and more portable. It is commonly used to store data in devices such as mobile phones, cameras, and MP3 players.

[0065] Switch: It refers to a switch that uses hardware to perform the tasks of filtering, learning, and forwarding processes that were previously done by software in a bridge.

[0066] Figure 1 Schematic diagram of the security startup processing procedure of the application program provided by the prior art of this application. As Figure 1As shown in the figure, after the existing system is powered on, the security chip 101 calls Uboot in the SPI Flash 102 to perform firmware verification. After the verification passes, the SPI Switch 103 is used to switch the path between the SPI Flash 102 and the system-level chip 104, so that the system-level chip 104 loads Uboot in the SPI Flash 102, and the kernel and file system in the embedded multimedia card 105 are loaded and verified according to the boot of Uboot, thus completing the startup of the system. Since Uboot in the SPI Flash is public and has no security protection measures, it is easily retrieved and tampered with. Moreover, according to the structural layout of the startup processing schematic diagram, if the security chip 101 is short-circuited, that is, when the security chip 101 is directly connected to the system-level chip 104, the verification of the security chip 101 will fail. At the same time, because the loaded kernel is not the kernel expected by the original Uboot, the system cannot perform reverse verification on Uboot, that is, the reverse verification process also fails, resulting in no security verification operation during the entire startup process, making the entire startup process untrustworthy.

[0067] Based on the above technical problems, the inventive concept of the present application lies in: by setting a root certificate in the SoC that cannot be changed after factory settings, the security core in the SoC verifies the legitimacy of Uboot. After the verification passes, the security core pulls up Uboot on the service core, and Uboot sends verification information such as the system startup program and the security verification program to the security core for further verification. After the verification passes, the verification of the remaining key service programs is performed to achieve the secure startup of the application program, aiming to solve the above technical problems of the prior art.

[0068] The following uses specific embodiments to elaborate in detail on the technical solution of the present application and how the technical solution of the present application solves the above technical problems. These several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0069] Figure 2 Schematic flow of the secure startup processing method for the application program provided by the embodiment of the present application Figure 1 As Figure 2 shown, the method includes:

[0070] S201. In response to the system power-on signal, call the secure startup program to verify whether Uboot is trustworthy according to the secure startup program.

[0071] Among them, the secure startup program includes calling the security chip to verify Uboot.

[0072] Specifically, after the system is powered on, the secure boot program is first called to verify whether Uboot is trustworthy, rather than directly calling Uboot to perform the system security verification in the prior art after power-on. Therefore, the situation where Uboot is tampered with can be avoided. The secure boot program is set as a built-in program that cannot be changed after leaving the factory, which can ensure that the secure boot program is not tampered with, thus realizing the trust chain transfer from the secure boot program to Uboot after the system is powered on, avoiding the situation where the subsequent service security cannot be guaranteed due to Uboot being tampered with, and ensuring the security of the startup process.

[0073] S202. If the verification result of the secure boot program for Uboot is trustworthy, then based on Uboot, call the security chip to verify the system to be loaded and the security verification program.

[0074] Among them, the system to be loaded includes a kernel and an initialization process.

[0075] Specifically, as an independent security verification module, the security chip verifies the legality of all programs in the system. Since Uboot is a bootloader, after determining that Uboot is trustworthy, Uboot can only boot the system when the system to be loaded and the security verification program are required for the security chip verification. If Uboot is not trustworthy, the bootloader that triggers the security chip verification will not be launched, and the system will be directly restarted to determine the trustworthiness of Uboot again, avoiding the situation where the Uboot verification fails due to factors such as program bugs.

[0076] S203. If the verification results of both the system to be loaded and the security verification program are trustworthy, then based on the security verification program, call the security chip to verify the key components of each application to be loaded.

[0077] Specifically, after determining that both the system to be loaded and the security verification program are trustworthy, the system is started based on the kernel and initialization process in the system to be loaded. After the system is started, application programs need to be loaded. Therefore, it is necessary to verify the application programs to be loaded. Similarly, the verification needs to be performed on the security chip. The security verification program is a program used to guide the security chip to perform reverse verification of the system and verification of the key components of the application program on the service core. Therefore, based on the security verification program, the security chip is started to perform reverse verification of Uboot and the kernel, further ensuring the reliability of the previous trust chain transfer, and also verifying the key components of the service management application program related to the service core to be loaded with the service application program on the security chip, thereby extending the transfer of the trust chain to the service management application program.

[0078] S204. If the verification result of the key components of the application to be loaded is trustworthy, then start the application program based on the key components.

[0079] Specifically, since the business management application uniformly manages the legitimacy and startup sequence of business applications, after determining that the key components of the application to be loaded are trustworthy, the corresponding business application can be launched according to the business management application, realizing the transfer of the trust chain from the business management application to the business application, and ultimately realizing the complete transfer of the trust chain in the overall process from system power-on to application startup completion.

[0080] The method provided in this embodiment calls the secure startup program in response to the system power-on signal to verify whether Uboot is trustworthy according to the secure startup program; if the verification result of Uboot by the secure startup program is trustworthy, the secure chip is called based on Uboot to verify the system to be loaded and the security verification program; if the verification results of the system to be loaded and the security verification program are both trustworthy, the secure chip is called based on the security verification program to verify the key components of each application to be loaded; if the verification result of the key components of the application to be loaded is trustworthy, the application program is started based on the key components, realizing the reliable and effective transfer of the trust chain. There is no breakpoint in the trust chain transfer during the entire startup process, ensuring the security of system startup and at the same time ensuring that the secure startup of the system meets the power industry standards.

[0081] Next, a specific embodiment is used to elaborate in detail on the secure startup processing method of the application program of the present application.

[0082] Figure 3 Schematic flow of the secure startup processing method of the application program provided for the embodiment of the present application Figure 2 As Figure 3 shown, the method includes:

[0083] S301. In response to the system power-on signal, trigger the secure core to call the built-in trusted root certificate, and verify the bootloader according to the trusted root certificate.

[0084] Among them, the bootloader is used to guide the secure chip to verify Uboot.

[0085] Specifically, the built-in trusted root certificate is a root certificate that cannot be changed after the factory settings of the SoC are set. The secure core in the SoC verifies the legitimacy of the bootloader L1.

[0086] S302. Determine whether the bootloader is trustworthy. If so, execute S303; if not, execute S313.

[0087] S303. Call the secure chip to verify Uboot based on the bootloader.

[0088] Specifically, after determining that the bootloader L1 is trustworthy, the bootloader L1 further verifies the legality of Uboot through the security chip, implementing the two trust chain transfer processes from system power-on to Uboot.

[0089] S304. Determine whether the verification result of the security startup program for Uboot is trustworthy. If it is, execute S305; if not, execute S313.

[0090] S305. Based on Uboot, call the security chip to verify the system to be loaded and the security verification program.

[0091] Among them, the system to be loaded includes a kernel and an initialization process.

[0092] Specifically, after Uboot passes the verification, the security core starts Uboot on the service core. Uboot sends the verification information of files such as the system's kernel, init, and the security verification program to the security chip and receives the return value sent by the security chip, implementing the breakpoint-free trust chain transfer from the security core to the service core.

[0093] S306. Determine whether the verification results of the system to be loaded and the security verification program are both trustworthy. If they are, execute S307; if not, execute S313.

[0094] S307. Based on the security verification program, call the security chip to verify the key components of each application to be loaded.

[0095] Specifically, analyze the return value of the security chip. When the verification passes, continue to start the verified kernel and enter the system, ensuring that the program starting the system is the expected program and ensuring that the security verification program is the expected one, implementing the trust chain transfer of the system and the security verification program within the service core.

[0096] The specific implementation method of S307 is similar to that of S203, and will not be elaborated here in this embodiment.

[0097] S308. Determine whether the verification result of the key components of the application to be loaded is trustworthy. If it is, execute S309; if not, execute S313.

[0098] S309. Based on the key components, call the security chip to verify the application program corresponding to the key components.

[0099] Specifically, the security verification program verifies the remaining other key programs through the security chip, such as the business management application program, etc., ensuring that the key programs running the system are the expected ones, implementing the trust chain transfer from the security verification program to the key programs.

[0100] S310. Determine whether the verification result of each application corresponding to the key component is trustworthy. If so, execute S311; if not, execute S312.

[0101] S311. Start the application.

[0102] S312. Skip the application.

[0103] Specifically, the key component is used to manage the legality and startup timing of applications. After the key component passes the verification, the corresponding applications are verified in sequence according to the startup timing configured by the key component, and the application is started after the business application passes the verification. Also, since there may be more than one application in the system, if it is determined that the current application fails the verification, the application is skipped and the next application is continued to be judged whether it passes the verification.

[0104] S313. Restart the system.

[0105] Specifically, restarting the system is used to prevent the opening of applications. At the same time, by restarting, the transmission process of the trust chain can be re-executed to avoid the situation where the trust chain is interrupted due to some programs not being normally started during the startup process.

[0106] Figure 7 It is a flowchart of the secure startup processing method for the application provided by the embodiment of the present application. Figure 3 . As Figure 7 shown, the method includes the following processes:

[0107] After the system is powered on, the secure core first runs the trusted root certificate in the read-only memory, verifies and loads the bootloader L1. L1 verifies Uboot through the security chip. If Uboot passes the verification, then the business core pulls up Uboot to complete the trust chain transmission process of the secure core part; if Uboot fails the verification, the system is restarted until Uboot passes the verification or the user actively shuts down the power to stop power-on.

[0108] After the business core pulls up Uboot, Uboot verifies kernel + init + security verification program through the security chip. If all verifications pass, then the verified kernel + init + security verification program is loaded, and the kernel + init startup program is used. The security verification program verifies the key program through the security chip. If the key program passes the verification, the system allows the login process. The key program continues to verify the applications of each service through the security chip and executes the application when it passes the verification to complete the trust chain transmission process of the business core part.

[0109] If any one of the kernel + init + security verification program or critical programs fails the verification, the system will be restarted until all verifications pass;

[0110] If any application fails the verification, it will be skipped and not executed, but this does not affect the execution of other applications that have passed the verification.

[0111] The method provided in this embodiment triggers the security core to call the built-in trusted root certificate in response to the system power-on signal, and verifies the bootloader according to the trusted root certificate; if the bootloader is trusted, the security chip is called based on the bootloader to verify Uboot; if the verification result of the secure boot program for Uboot is trusted, the security chip is called based on Uboot to verify the system to be loaded and the security verification program; if the verification results of the system to be loaded and the security verification program are both trusted, the security chip is called based on the security verification program to verify the critical components of each application to be loaded; if the verification result of the critical components of the application to be loaded is trusted, the security chip is called based on the critical components to verify the application program corresponding to the critical components; if the verification result of the application program corresponding to the critical components is trusted, the application program is started; if the verification result of Uboot is not trusted, or the verification results of the system to be loaded and the security verification program are not trusted, or the verification result of the critical components of the application to be loaded is not trusted, the system is restarted, thereby realizing the sequential transfer process of the trust chain in the entire startup process and ensuring the security of system startup.

[0112] Figure 4 It is a structural schematic diagram of the secure boot processing device for the application program provided in the embodiment of the present application. As Figure 4 shown, the device includes:

[0113] A security module 401, configured to call a secure boot program in response to a system power-on signal to verify whether Uboot is trusted according to the secure boot program; wherein, the secure boot program includes calling a security chip to verify Uboot.

[0114] A service module 402, configured to, if the verification result of the secure boot program for Uboot is trusted, call a security chip based on Uboot to verify the system to be loaded and the security verification program; wherein, the system to be loaded includes a kernel and an initialization process.

[0115] The service module 402 is further configured to, if the verification results of the system to be loaded and the security verification program are both trusted, call a security chip based on the security verification program to verify the critical components of each application to be loaded.

[0116] The service module 402 is further configured to, if the verification result of the critical components of the application to be loaded is trusted, start the application program based on the critical components.

[0117] Optionally, the service module 402 is specifically configured to call a secure startup program to verify whether Uboot is trustworthy according to the secure startup program, including:

[0118] Trigger the secure core to call the built-in trusted root certificate, and verify the bootloader according to the trusted root certificate; wherein, the bootloader is used to guide the secure chip to verify Uboot;

[0119] If the bootloader is trustworthy, call the secure chip to verify Uboot based on the bootloader.

[0120] Optionally, the service module 402 is specifically configured to start an application program based on the key component, including:

[0121] Call the secure chip to verify the application program corresponding to the key component based on the key component;

[0122] If the verification result of the application program corresponding to the key component is trustworthy, start the application program.

[0123] Optionally, on the basis of the above embodiment, it further includes: a restart module 403, configured to restart the system if the verification result of Uboot is untrustworthy, or the verification results of the system and the security verification program to be loaded are untrustworthy, or the verification result of the key component of the application to be loaded is untrustworthy.

[0124] The application program secure startup processing device provided in this embodiment can execute the application program secure startup processing method in the above embodiment, and its implementation principle and technical effects are similar, which will not be elaborated here in this embodiment.

[0125] Embodiments of the present invention can divide functional modules for an electronic device or a main control device according to the above method examples. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional module. It should be noted that the division of modules in the embodiments of the present invention is illustrative, only a logical function division, and there can be other division methods in actual implementation.

[0126] In the specific implementation of the foregoing application program secure startup processing device, each module can be implemented as a processor, and the processor can execute computer execution instructions stored in the memory, so that the processor executes the above application program secure startup processing method.

[0127] Figure 5 This is a schematic diagram of the secure startup system structure provided for the embodiments of this application. As Figure 5 shown, a secure startup system includes:

[0128] An embedded multimedia card 501, a security chip 502, and a system-on-chip 503, where the embedded multimedia card 501 and the security chip 502 are respectively connected to the system-on-chip 503;

[0129] Wherein, the system-on-chip 503 includes a security core and a service core. The security core is used to verify Uboot according to the built-in trusted root certificate of the security core, and the service core is used to verify the service to be loaded in the embedded multimedia card 501 according to the Uboot verified by the security core.

[0130] Specifically, the Uboot for verifying the system legality and the secure boot program for verifying the Uboot legality are all encapsulated in the security core inside the system-on-chip 503, while the security verification program for calling and verifying the service application program is encapsulated in the service core inside the system-on-chip 503, so as to ensure the security of power-on startup through the built-in security core, avoiding the original security core being bypassed from external hardware, such as bypassing the verification process through a short-circuit method to implement a system and application program startup process without security verification, and ensuring the secure startup of the system and applications after power-on through the external security chip 502.

[0131] Figure 6 It is a schematic diagram of the hardware structure of the electronic device provided by the embodiment of the present application. As Figure 6 shown, the electronic device includes:

[0132] At least one processor 601 and a memory 602.

[0133] The electronic device further includes a communication component 603.

[0134] Wherein, the processor 601, the memory 602, and the communication component 603 are connected through a bus 604.

[0135] In a specific implementation process, at least one processor 601 executes the computer-executable instructions stored in the memory 602, so that at least one processor 601 executes the secure boot processing method of the application program executed on the electronic device side as described above.

[0136] For the specific implementation process of the processor 601, reference can be made to the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here in this embodiment.

[0137] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU for short), or other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.

[0138] The memory may include high-speed RAM memory and may also include non-volatile storage NVM, such as at least one disk memory.

[0139] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of this application is not limited to only one bus or one type of bus.

[0140] The functions implemented for the electronic device and the main control device are described above for the solution provided by the embodiments of the present invention.

[0141] It can be understood that in order to implement the above functions, the electronic device or the main control device includes the corresponding hardware structure and / or software module for executing each function.

[0142] Combined with the units and algorithm steps of each example described in the embodiments disclosed in the embodiments of the present invention, the embodiments of the present invention can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described function for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiments of the present invention.

[0143] This application also provides a computer program product, including a computer program, which implements the secure startup processing method of the application program when executed by a processor.

[0144] The computer program product provided in this embodiment can execute the security startup processing method of the application program in the above embodiment. Its implementation principle and technical effects are similar, and will not be elaborated here in this embodiment.

[0145] This application also provides a computer-readable storage medium. Computer-executable instructions are stored in this computer-readable storage medium. When the processor executes these computer-executable instructions, the security startup processing method of the above application program is implemented.

[0146] The computer-readable storage medium provided in this embodiment can execute the security startup processing method of the application program in the above embodiment. Its implementation principle and technical effects are similar, and will not be elaborated here in this embodiment.

[0147] The above-mentioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.

[0148] An exemplary readable storage medium is coupled to the processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC).

[0149] Of course, the processor and the readable storage medium can also exist as discrete components in an electronic device or a master control device.

[0150] Those of ordinary skill in the art can understand that all or part of the steps to implement the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps included in the above method embodiments; and the aforementioned storage medium includes various media such as ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0151] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards, and corresponding operation entrances are provided for users to choose to authorize or reject.

[0152] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for secure startup processing of an application, characterized in that, Including: In response to the system power-on signal, call the secure boot program to verify whether Uboot is trustworthy according to the secure boot program; wherein, the secure boot program includes calling the secure chip to verify Uboot; If the verification result of Uboot by the secure boot program is trustworthy, then based on Uboot, call the secure chip to verify the system to be loaded and the security verification program; wherein, the system to be loaded includes a kernel and an initialization process; If the verification results of the system to be loaded and the security verification program are both trustworthy, then based on the security verification program, call the secure chip to verify the key components of each application to be loaded; If the verification result of the key components of the application to be loaded is trustworthy, then start the application program based on the key components.

2. The method according to claim 1, wherein The calling the secure boot program to verify whether Uboot is trustworthy according to the secure boot program includes: Trigger the secure core to call the built-in trusted root certificate, and verify the bootloader according to the trusted root certificate; wherein, the bootloader is used to guide the secure chip to verify Uboot; If the bootloader is trustworthy, then based on the bootloader, call the secure chip to verify Uboot.

3. The method according to claim 1, wherein Also including: If the verification result of Uboot is untrustworthy, or the verification results of the system to be loaded and the security verification program are untrustworthy, or the verification result of the key components of the application to be loaded is untrustworthy, then restart the system.

4. The method according to claim 1, wherein The starting the application program based on the key components includes: Based on the key components, call the secure chip to verify the application program corresponding to the key components; If the verification result of the application program corresponding to the key components is trustworthy, then start the application program.

5. A system-on-chip, characterized in that, Including: A security module, configured to, in response to the system power-on signal, call the secure boot program to verify whether Uboot is trustworthy according to the secure boot program; wherein, the secure boot program includes calling the secure chip to verify Uboot; A service module, configured to, if the verification result of Uboot by the secure boot program is trustworthy, then based on Uboot, call the secure chip to verify the system to be loaded and the security verification program; wherein, the system to be loaded includes a kernel and an initialization process; The service module is further configured to, if the verification results of the system to be loaded and the security verification program are both trustworthy, then based on the security verification program, call the secure chip to verify the key components of each application to be loaded; The service module is further configured to, if the verification result of the key components of the application to be loaded is trustworthy, then start the application program based on the key components.

6. The system-on-chip according to claim 5, characterized in that Also including: A restart module, configured to restart the system if the verification result of Uboot is untrustworthy, or the verification results of the system to be loaded and the security verification program are untrustworthy, or the verification result of the key components of the application to be loaded is untrustworthy.

7. A secure boot system, characterized in that, Including: An embedded multimedia card, a security chip, and a system-on-chip, where the embedded multimedia card and the security chip are respectively connected to the system-on-chip; wherein, the system-on-chip includes a security core and a service core, the security core is used to verify Uboot according to the built-in trusted root certificate of the security core, and the service core is used to verify the service to be loaded in the embedded multimedia card according to the Uboot verified by the security core.

8. An electronic device, characterized in that, Comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 4.

9. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of claims 1 to 4.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Safe and credible starting method and system for power terminal

    CN115879087A

  • Device booting with an initial protection component

    US20110307711A1