Safe starting method, device and equipment of processing device and readable storage medium
Through the dual processing core mechanism, the boot startup files of the processing device are detected in a layered manner, ensuring the secure startup of the preset management system and the main system, solving the problem of safe startup of the processing device and improving the security and stability of the system.
Patent Information
- Application Number
- CN202510397425.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-08
AI Technical Summary
The lack of mature safe start method for processing devices in the prior art, which makes it difficult for processing devices to be safely started, and reduces product competitiveness.
The dual processing core mechanism is adopted. When the processing device is powered on, the boot startup file of the preset management system is tampered with the first processing core. If it is not tampered, the preset management system will be started, and the boot startup file of the main system will be detected through the preset management system. If it is not tampered, the second processing core will be awakened to start the main system.
It realizes layered protection of the preset management system and the main system, and uses the security isolation mechanism to prevent boot files from being maliciously tampered with, improving the overall security and stability of the processing device.
Smart Images

Figure CN120277675A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of processing device design, and in particular, to a method, device, equipment and readable storage medium for safely starting a processing device. Background Art
[0002] With the development of processing device technology, the security of processing devices has been increasingly emphasized. The safe start of a processing device is an important part of the security of the processing device. However, in the related art, there is a lack of a mature method for safely starting a processing device, resulting in the difficulty of safely starting the processing device and reducing the product competitiveness.
[0003] Therefore, how to provide a solution to the above technical problems is what those skilled in the art need to solve currently. Summary of the Invention
[0004] The object of the present invention is to provide a method, device, equipment and readable storage medium for safely starting a processing device. The safe start solution of the processing device uses a first processing core to detect tampering of a first target file for booting a preset management system when the processing device is powered on. When there is no tampering, the preset management system is started; subsequently, the preset management system detects tampering of a second target file for booting the main system, and wakes up the second processing core to start the main system after confirming no tampering. This process realizes hierarchical protection for the startup of the preset management system and the main system, forms a security isolation mechanism using two processing cores, effectively prevents the boot file from being maliciously tampered with, ensures the startup security of the two systems, and improves the overall security and stability of the processing device system.
[0005] To solve the above technical problems, the present invention provides a method for safely starting a processing device, which is applied to a first processing core of the processing device and includes:
[0006] After power-on, determine whether the first target file is tampered with, where the first target file is used for booting the preset management system;
[0007] If the first target file is not tampered with, start the preset management system through the first target file;
[0008] Judge whether the second target file has been tampered with through the preset management system, where the second target file is used for booting the main system of the processing device;
[0009] If the second target file is not tampered with, wake up the second processing core of the processing device so that the second processing core starts the main system of the processing device through the second target file.
[0010] On the other hand, determining whether the first target file is tampered with includes:
[0011] Determine whether the first target file can pass the accuracy verification of a preset data accuracy verification method;
[0012] If it can pass, determine that the first target file has not been tampered with;
[0013] If it does not pass, determine that the first target file has been tampered with;
[0014] Determining whether the second target file has been tampered with through a preset management system includes:
[0015] Determine whether the second target file can pass the accuracy verification of a preset data accuracy verification method;
[0016] If it can pass, determine that the second target file has not been tampered with;
[0017] If it does not pass, determine that the second target file has been tampered with.
[0018] On the other hand, the first target file includes a boot file and a preset management system file;
[0019] The second target file includes a boot file and the main system file of the processing device;
[0020] Among them, the boot file is used as a carrier for the boot program, and the boot program is used to boot the preset management system and the main system of the processing device.
[0021] On the other hand, determining whether the first target file can pass the accuracy verification of a preset data accuracy verification method includes:
[0022] Based on the first key in the one-time programmable read-only memory, verify the signature of the boot file package through a key matching mechanism, where the boot file package includes a boot file, a second key matching the first key, a data feature identification code of the preset management system file, and a third key;
[0023] Calculate the data feature identification code of the boot file through a preset data accuracy verification method;
[0024] Determine whether the calculated data feature identification code of the boot file is consistent with the first identification code in the one-time programmable read-only memory, where the first identification code is the pre-stored data feature identification code of the boot file;
[0025] If it is consistent with the first identification code in the one-time programmable read-only memory, determine that the boot file passes the accuracy verification;
[0026] Verify the signature of the preset management system file package through a key matching mechanism based on the third key, where the preset management system file package includes a preset management system file and a fourth key that matches the third key;
[0027] Calculate the data feature identification code of the preset management system file through a preset data accuracy verification method;
[0028] Judge whether the calculated data feature identification code of the preset management system file is consistent with the data feature identification code in the boot startup file package;
[0029] If it is consistent with the data feature identification code in the boot startup file package, it is determined that the preset management system file passes the accuracy verification.
[0030] On the other hand, the key matching mechanism includes an asymmetric key algorithm, the first key and the third key are public keys, and the second key and the fourth key are private keys;
[0031] The data accuracy verification method includes a hash algorithm.
[0032] On the other hand, determining whether the second target file can pass the accuracy verification of the preset data accuracy verification method includes:
[0033] Expand the second target file to the preset security processing device so that the preset security processing device verifies the accuracy of the second target file through the preset data accuracy verification method;
[0034] Receive the accuracy verification result sent by the preset security processing device, where the accuracy verification result includes passed and not passed;
[0035] Determine whether the second target file passes the accuracy verification of the preset data accuracy verification method according to the accuracy verification result.
[0036] On the other hand, the processing device includes a baseboard management controller, and the preset management system includes a real-time operating system.
[0037] To solve the above technical problems, the present invention also provides a security startup device for a processing device, which is applied to the first processing core of the processing device and includes:
[0038] A first judgment module, configured to judge whether the first target file is tampered with after power-on, where the first target file is used for the boot startup of the preset management system. If the first target file is not tampered with, trigger the first action module;
[0039] A first action module, configured to start the preset management system through the first target file;
[0040] A second judgment module, used for judging whether the second target file has been tampered with through a preset management system, and triggering the first wake-up module if the second target file has not been tampered with, wherein the second target file is used for booting and starting the main system of the processing device;
[0041] The first wake-up module is used to wake up the second processing core of the processing device so that the second processing core starts the main system of the processing device through the second target file.
[0042] In order to solve the above technical problems, the present invention further provides a secure boot device for a processing device, comprising:
[0043] Memory for storing computer programs;
[0044] A processor is used to implement the steps of the secure startup method of the processing device as described above when executing the computer program.
[0045] In order to solve the above technical problems, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the secure startup method of the processing device as described above are implemented.
[0046] Beneficial effects: The present invention provides a secure startup method for a processing device. The secure startup scheme for the processing device uses the first processing core to detect tampering of the "first target file for booting the preset management system" when the processing device is powered on, and starts the preset management system if it has not been tampered with; then, the preset management system detects tampering of the "second target file for booting the main system", and wakes up the second processing core to start the main system after confirming that it has not been tampered with. This process realizes layered protection for the startup of the preset management system and the main system, uses two processing cores to form a security isolation mechanism, effectively prevents the boot file from being maliciously tampered with, ensures the startup security of the two systems, and improves the overall security and stability of the processing device system.
[0047] The present invention also provides a secure boot device, equipment and readable storage medium for a processing device, which have the same beneficial effects as the secure boot method for the processing device mentioned above. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the relevant technologies and the drawings required for use in the embodiments are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0049] Figure 1Schematic flowchart of the first method for secure startup of the processing device provided by the present invention;
[0050] Figure 2 Schematic flowchart of the second method for secure startup of the processing device provided by the present invention;
[0051] Figure 3 Schematic flowchart of the third method for secure startup of the processing device provided by the present invention;
[0052] Figure 4 Schematic diagram of the structure of a processing device provided by the present invention;
[0053] Figure 5 Schematic flowchart of the pre - configuration work of a processing device provided by the present invention;
[0054] Figure 6 Schematic flowchart of the fourth method for secure startup of the processing device provided by the present invention;
[0055] Figure 7 Schematic diagram of the structure of a secure startup device for a processing device provided by the present invention;
[0056] Figure 8 Schematic diagram of the structure of a secure startup device for a processing device provided by the present invention;
[0057] Figure 9 Schematic diagram of the structure of a computer - readable storage medium provided by the present invention. Detailed implementation manners
[0058] The core of the present invention is to provide a method, device, equipment and readable storage medium for secure startup of a processing device. The secure startup solution of this processing device, with the help of the first processing core, detects tampering of the "first target file for booting the preset management system" when the processing device is powered on. When there is no tampering, it boots the preset management system; subsequently, the preset management system detects tampering of the "second target file for booting the main system", and after confirming no tampering, wakes up the second processing core to boot the main system. This process realizes hierarchical protection for the startup of the preset management system and the main system, forms a security isolation mechanism by using two processing cores, effectively prevents the boot file from being maliciously tampered with, ensures the startup security of the two systems, and improves the overall security and stability of the processing device system.
[0059] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0060] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of the secure startup method for the first processing device provided by the present invention. The secure startup method of the processing device is applied to the first processing core of the processing device and includes:
[0061] S101: After power-on, determine whether the first target file has been tampered with, where the first target file is used for the boot startup of the preset management system;
[0062] Specifically, considering the technical problems in the above background art, and also considering that (1) by waking up and starting the processing core where the main system of the processing device is located through another processing core, a secure isolation mechanism can be formed to enhance the startup security of the main system of the processing device; (2) whether it is the preset management system used to wake up the "processing core where the main system of the processing device is located" or the main system of the processing device, the accuracy of the target files required for the boot startup of these two systems is also related to the startup security of the "main system of the processing device". Therefore, in the embodiments of the present invention, it is intended to use the first processing core of the processing device to assist in waking up the "processing core where the main system of the processing device is located", and also to perform anti-tampering verification on the target files required for the boot startup of the preset management system and the main system, so as to ensure the startup security of the main system of the processing device from two aspects: "secure isolation of the processing core" and "file anti-tampering".
[0063] Specifically, based on the above concept, the secure startup method of the processing device is applied to the first processing core of the processing device. First, it is intended to start the preset management system in the first processing core. Therefore, in this step, the first processing core can determine whether the first target file has been tampered with after power-on, and trigger the actions of subsequent steps based on the judgment result.
[0064] S102: If the first target file has not been tampered with, start the preset management system through the first target file;
[0065] Specifically, the first target file has not been tampered with, which means that the preset management system can be safely and reliably started through the first target file, and will not affect the startup security of the main system of the processing device. Therefore, in this step, the preset management system can be started through the first target file when the first target file has not been tampered with, so that related actions can be subsequently performed through the preset management system.
[0066] S103: determining whether the second target file has been tampered with by a preset management system, wherein the second target file is used for booting and starting the main system of the processing device;
[0067] Specifically, after the preset management system is started, the preset management system can be used to determine whether the second target file (used to boot and start the main system of the processing device) has been tampered with, so as to analyze whether the main system can be safely started through the second target file and trigger the actions of subsequent steps.
[0068] S104: If the second target file has not been tampered with, waking up the second processing core of the processing device so that the second processing core starts the main system of the processing device through the second target file.
[0069] Specifically, when the second target file has not been tampered with, it means that the main system can be safely started through the second target file, and the main system is located in the second processing core. Therefore, in this step, the second processing core of the processing device can be awakened when the second target file has not been tampered with, so that the second processing core can start the main system of the processing device through the second target file. In the embodiment of the present invention, the first target file required to boot the preset management system and the second target file required to boot the main system are both verified for tamper-proofing, which ensures the startup security of the main system from the entire link, and the preset management system is located in the first processing core, which is securely isolated from the second processing core, further improving the startup security of the main system.
[0070] The present invention provides a secure startup method for a processing device. The secure startup scheme for the processing device uses a first processing core to detect tampering of a "first target file for booting a preset management system" when the processing device is powered on, and starts the preset management system if it has not been tampered with; then, the preset management system detects tampering of a "second target file for booting a main system", and wakes up the second processing core to start the main system after confirming that it has not been tampered with. This process realizes layered protection for the startup of the preset management system and the main system, uses two processing cores to form a security isolation mechanism, effectively prevents the boot file from being maliciously tampered with, ensures the startup security of the two systems, and improves the overall security and stability of the processing device system.
[0071] Based on the above embodiments:
[0072] As an alternative embodiment, determining whether the first target file has been tampered with includes:
[0073] Determining whether the first target file can pass the accuracy verification of a preset data accuracy verification method;
[0074] If it can pass, it is determined that the first target file has not been tampered with;
[0075] If it fails to pass, it is determined that the first target file has been tampered with;
[0076] Determining whether the second target file has been tampered with by a preset management system includes:
[0077] Determining whether the second target file can pass the accuracy verification of a preset data accuracy verification method;
[0078] If it can pass, it is determined that the second target file has not been tampered with;
[0079] If it fails to pass, it is determined that the second target file has been tampered with.
[0080] Specifically, considering that by using a relevant data accuracy verification method to perform accuracy verification on the target file, it is possible to efficiently and accurately determine whether the target file has been tampered with. Therefore, in the embodiments of the present invention, when determining whether the first target file and the second target file have been tampered with, the accuracy verification can be performed through a preset data accuracy verification method, which can ensure the efficiency and accuracy of the anti-tampering judgment.
[0081] Of course, in addition to this method, the anti-tampering judgment of the first target file and the second target file can also be performed in other ways, which are not limited in the embodiments of the present invention.
[0082] As an alternative embodiment, the first target file includes a boot startup file and a preset management system file;
[0083] The second target file includes a boot startup file and the main system file of the processing device;
[0084] Among them, the boot startup file is used as a carrier for the boot startup program, and the boot startup program is used to boot the preset management system and the main system of the processing device.
[0085] Specifically, considering that before some software systems start, tasks such as system initialization, software system kernel loading, device driver support, environment variable management, and system boot management need to be performed, and these functions can be integrated through the boot startup file. Therefore, in the embodiments of the present invention, the first target file includes a boot startup file and a preset management system file, while the second target file includes a boot startup file and the main system file of the processing device.
[0086] Among them, considering that in the first processing core and the second processing core of the processing device, the software systems in the two processing cores can theoretically share the same set of boot programs, therefore, in the embodiments of the present invention, the boot file is used as the carrier of the boot program, and the boot program can be respectively used to boot the preset management system and the main system of the processing device, thereby helping to reduce the storage space occupation.
[0087] As an optional embodiment, determining whether the first target file can pass the accuracy verification of the preset data accuracy verification method includes:
[0088] Based on the first key in the one-time programmable read-only memory, the boot file package is verified and signed through a key matching mechanism. Among them, the boot file package includes a boot file, a second key matching the first key, a data feature identification code of the preset management system file, and a third key;
[0089] Through the preset data accuracy verification method, calculate the data feature identification code of the boot file;
[0090] Judge whether the calculated data feature identification code of the boot file is consistent with the first identification code in the one-time programmable read-only memory, where the first identification code is the pre-stored data feature identification code of the boot file;
[0091] If it is consistent with the first identification code in the one-time programmable read-only memory, it is determined that the boot file passes the accuracy verification;
[0092] Based on the third key, the preset management system file package is verified and signed through a key matching mechanism. Among them, the preset management system file package includes a preset management system file and a fourth key matching the third key;
[0093] Through the preset data accuracy verification method, calculate the data feature identification code of the preset management system file;
[0094] Judge whether the calculated data feature identification code of the preset management system file is consistent with the data feature identification code in the boot file package;
[0095] If it is consistent with the data feature identification code in the boot file package, it is determined that the preset management system file passes the accuracy verification.
[0096] Specifically, for a better description of the embodiments of the present invention, please refer to Figure 2 , Figure 2Schematic flowchart of the second method for secure startup of the processing device provided by the present invention. After the first processing core is powered on, it first executes the Boot ROM (Boot Read-Only Memory) stage, and then based on the matching of the first key and the second key in the One-Time Programmable Read-Only Memory (OTP ROM), it verifies the signature of the boot startup file package through the key matching mechanism. After the signature verification passes, the contents of the boot startup file package can be obtained. Then, the data feature identification code of the boot startup file in the boot startup file package can be calculated, and it is judged whether it is consistent with the first identification code in the One-Time Programmable Read-Only Memory. If they are consistent, based on the matching relationship between the third key and the fourth key, the signature of the preset management system file package can be verified by the third key. After the signature verification passes, the contents of the preset management system file package can be obtained. Then, the data feature identification code of the preset management system file is calculated, and it is judged whether it is consistent with the second identification code (the pre-stored data feature identification code of the preset management system file used as a reference) in the boot startup file package. If they are consistent, the preset management system can be started through the preset management system file.
[0097] Specifically, considering that the verification method of "the data feature identification codes of the boot startup file and the preset management system file" level by level can terminate the startup immediately when the file to be verified first (such as the boot startup file) fails the verification, reducing unnecessary verification work. Therefore, in the embodiments of the present invention, the "boot startup file and the preset management system file" can be verified level by level through the data feature identification code, and the "data feature identification code used as a reference" of each corresponding level of file is stored in the file package of the higher-level file: that is, the "data feature identification code used as a reference" of the boot startup file is stored in the One-Time Programmable Read-Only Memory, and the "data feature identification code used as a reference" of the preset management system file is stored in the boot startup file package.
[0098] Specifically, under the above storage architecture, in order to further enhance the security of each part of the boot startup file package and the preset management system file package, in the embodiments of the present invention, the boot startup file package and the preset management system file package are respectively encrypted. The "data feature identification code used as a benchmark" of the boot startup file and the first key for decrypting the boot startup file package are both stored in the one-time programmable read-only memory, thereby ensuring the security of these two items through the OTP ROM. And the content in the boot startup file package can be obtained only after verifying the signature of the boot startup file package with the first key, ensuring the content security of the boot startup file package; while the "data feature identification code used as a benchmark" of the preset management system file, the third key for decrypting the preset management system file package, and the second key matching the first key are stored in the boot startup file package. The "fourth key matching the third key" and the preset management system file are stored in the preset management system file package. The preset management system file package can be decrypted with the third key, and the accuracy of the preset management system file can be verified with the data feature identification code stored in the boot startup file package.
[0099] Specifically, considering that some boot startup files include multiple levels of boot startup sub-files to implement a multi-level boot startup process, therefore, in the embodiments of the present invention, the case where "the boot startup file includes two levels of boot startup sub-files" is taken as an example for illustration. For a better illustration of the embodiments of the present invention, please refer to Figure 3 , Figure 3 which is a schematic flowchart of the secure startup method of the third processing device provided by the present invention. It can be considered that the "boot startup file package" is composed of the first boot startup sub-file package and the second boot startup sub-file package. The boot startup file includes the first boot startup sub-file and the second boot startup sub-file. The second key includes Figure 3 the first sub-key in Figure 3 , and the third key includes Figure 3After the first processing core is powered on, it first executes the Boot ROM (Boot Read - Only Memory) stage. Then, based on the matching relationship between the first key and the first sub - key in the one - time programmable read - only memory, it verifies the signature of the first boot - up sub - file package through the key matching mechanism. After the signature verification passes, it can obtain the contents of the first boot - up sub - file package. Then, it can calculate the data feature identification code of the first boot - up sub - file in the first boot - up sub - file package and determine whether it is consistent with the first identification code in the one - time programmable read - only memory. If they are consistent, it can verify the signature of the second boot - up sub - file package through the second sub - key based on the matching relationship between the second sub - key and the third sub - key. After the signature verification passes, it can obtain the contents of the second boot - up sub - file package. Then, it can calculate the data feature identification code of the second boot - up sub - file and determine whether it is consistent with the first sub - identification code in the first boot - up sub - file package. If they are consistent, it can verify the signature of the preset management system file package through the fourth sub - key based on the matching relationship between the fourth sub - key and the fourth key. After the signature verification passes, it can obtain the contents of the preset management system file package. Then, it calculates the data feature identification code of the preset management system file and determines whether it is consistent with the second identification code (the pre - stored data feature identification code of the preset management system file used as a benchmark) in the second boot - up sub - file package. If they are consistent, it can start the preset management system through the preset management system file.
[0100] Among them, Figure 3 The first boot - up sub - file in it can be Uboot - spl (U - Boot Secondary Program Loader), and correspondingly, the second boot - up sub - file can be Uboot (Universal Boot Loader). The embodiments of the present invention do not make limitations here.
[0101] In addition, in addition to the verification method through the "data accuracy verification method" as described above, other verification methods can also be combined to verify the boot file and / or the preset management system file. For example, it can be checked whether the version number of the target file (boot file and / or preset management system) is consistent with the corresponding preset reference version number. If it is consistent, the version number verification is passed; if it is inconsistent, the version number verification fails. It can also be compared whether the metadata information of the target file (which can include creation time, modification time, file size, etc.) is consistent with the corresponding preset reference metadata information. If any one of the parameters in the metadata information is inconsistent, the metadata verification fails; if all the parameters in the metadata information are consistent, the metadata verification passes. After passing the "data accuracy verification", version number verification, and metadata verification, the target file can be determined to be safe.
[0102] As an alternative embodiment, the key matching mechanism includes an asymmetric key algorithm. The first key and the third key are public keys, and the second key and the fourth key are private keys.
[0103] The data accuracy verification method includes a hash algorithm.
[0104] Specifically, considering that the above key matching and signature verification work can be efficiently and securely implemented through asymmetric keys, the first to fourth keys in the embodiments of the present invention can be implemented using asymmetric keys, where the first key and the third key are public keys, and the second key and the fourth key are private keys.
[0105] Of course, in addition to asymmetric keys, the first to fourth keys can also be of other types, and the embodiments of the present invention do not limit this here.
[0106] Specifically, considering that the hash algorithm can efficiently and securely verify and protect the target data, the data accuracy verification method in the embodiments of the present invention can be a hash algorithm, and the aforementioned data feature identification code can be a hash value.
[0107] Of course, in addition to the hash algorithm, the data accuracy verification method can also be of many other types, and the embodiments of the present invention do not limit this here.
[0108] As an alternative embodiment, determining whether the second target file can pass the accuracy verification of the preset data accuracy verification method includes:
[0109] Extend the second target file to a preset security processing device so that the preset security processing device verifies the accuracy of the second target file through the preset data accuracy verification method.
[0110] Receive the accuracy verification result sent by the preset security processing device, where the accuracy verification result includes passed and not passed.
[0111] Determine whether the second target file passes the accuracy verification of the preset data accuracy verification method according to the accuracy verification result.
[0112] Specifically, considering that in the stage of "judging whether the second target file can pass the accuracy verification of the preset data accuracy verification method" through the preset management system, the extraction stage of the OTP ROM content has passed. Therefore, in the embodiments of the present invention, a security processing device "embedded with a second identification code" can be set. In this way, the second target file can be extended to the preset security processing device through the preset management system, so that the preset security processing device can verify the accuracy of the second target file through the preset data accuracy verification method, and then receive the accuracy verification result sent by the preset security processing device, and determine whether the second target file passes the accuracy verification of the preset data accuracy verification method according to the accuracy verification result. For example, the preset security processing device can directly send the result of "whether the second target file passes the accuracy verification of the preset data accuracy verification method".
[0113] Among them, the preset security processing device can be of various types. For example, it can be a TPM (Trusted Platform Module) chip, etc. The embodiments of the present invention do not limit this here.
[0114] As an optional embodiment, the processing device includes a baseboard management controller, and the preset management system includes a real-time operating system.
[0115] Specifically, both the processing device and the preset management system can be of various types. For example, the processing device can be a BMC (Baseboard Management Controller), and the preset management system can be an RTOS (Real-Time Operating System), etc. The embodiments of the present invention do not limit this here.
[0116] Specifically, for better illustration of the embodiments of the present invention, please refer to Figures 4 to 6 , Figure 4 which is a schematic structural diagram of a processing device provided by the present invention, Figure 5 which is a schematic flowchart of the pre-configuration work of a processing device provided by the present invention, Figure 6 which is a schematic flowchart of the fourth security startup method of the processing device provided by the present invention. In Figure 4Among them, the baseboard management controller (main system) and the preset management system are located in different processing cores. Data communication can be carried out between the two processing cores through shared memory and IPI (Inter-Processor Interrupt). The BMC (in the processing core where it is located) is respectively connected to sensors, complex programmable logic devices, fans, and DDR (Double Data Rate random access memory). The preset management system (in the processing core where it is located) can be connected to the trusted platform module and DDR.
[0117] Specifically, in Figure 5 , various keys as shown in Figure 2 and Figure 3 can be pre-generated, and then the keys are replaced at various positions in Figures 2 to 3 . Finally, the relevant content (to be written into the OTP ROM) can be written into the OTP ROM. In Figure 6 , after the system is powered on, the programmable read-only memory can be initialized first, and then the first boot sub-file can be verified, the second boot sub-file can be verified, the preset management system can be started, and the main system file can be verified. When all these stages pass smoothly, the main system can be started finally.
[0118] Among them, for the BMC system, its main system file can include kernel (kernel system) and rofs (Read-Only File System).
[0119] Please refer to Figure 7 , Figure 7 which is a schematic structural diagram of a secure startup device of a processing device provided by the present invention and is applied to the first processing core of the processing device, including:
[0120] The first judgment module 71 is used to judge whether the first target file is tampered with after power-on. Among them, the first target file is used for the boot startup of the preset management system. If the first target file is not tampered with, the first action module is triggered;
[0121] The first action module 72 is used to start the preset management system through the first target file;
[0122] The second judgment module 73 is used to judge whether the second target file is tampered with through the preset management system. If the second target file is not tampered with, the first wake-up module is triggered. Among them, the second target file is used for the boot startup of the main system of the processing device;
[0123] The first wake-up module 74 is used to wake up the second processing core of the processing device so that the second processing core can start the main system of the processing device through the second target file.
[0124] Based on the above embodiments:
[0125] As an alternative embodiment, the first action module 72 includes:
[0126] A first judgment sub-module, configured to judge whether the first target file can pass the accuracy verification of a preset data accuracy verification method. If it can pass, the first determination module is triggered; if it fails to pass, the second determination module is triggered;
[0127] A first determination module, configured to determine that the first target file has not been tampered with;
[0128] A second determination module, configured to determine that the first target file has been tampered with;
[0129] The second judgment module 73 includes:
[0130] A second judgment sub-module, configured to judge whether the second target file can pass the accuracy verification of a preset data accuracy verification method. If it can pass, the third determination module is triggered; if it fails to pass, the fourth determination module is triggered;
[0131] A third determination module, configured to determine that the second target file has not been tampered with;
[0132] A fourth determination module, configured to determine that the second target file has been tampered with.
[0133] As an alternative embodiment, the first judgment sub-module includes:
[0134] A first signature verification module, configured to perform signature verification on the boot file package based on the first key in the one-time programmable read-only memory through a key matching mechanism. The boot file package includes a boot file, a second key matching the first key, a data feature identification code of a preset management system file, and a third key;
[0135] A first calculation module, configured to calculate the data feature identification code of the boot file through a preset data accuracy verification method;
[0136] A third judgment sub-module, configured to judge whether the calculated data feature identification code of the boot file is consistent with the first identification code in the one-time programmable read-only memory. The first identification code is a pre-stored data feature identification code of the boot file. If it is consistent with the first identification code in the one-time programmable read-only memory, the fifth determination module is triggered;
[0137] A fifth determination module, configured to determine that the boot file passes the accuracy verification;
[0138] The second signature verification module is used to verify the signature of the preset management system file package based on the third key through a key matching mechanism, where the preset management system file package includes the preset management system file and the fourth key matching the third key;
[0139] The second calculation module is used to calculate the data feature identification code of the preset management system file through a preset data accuracy verification method;
[0140] The fourth judgment sub-module is used to judge whether the calculated data feature identification code of the preset management system file is consistent with the data feature identification code in the boot startup file package. If it is consistent with the data feature identification code in the boot startup file package, the sixth determination module is triggered;
[0141] The sixth determination module is used to determine that the preset management system file passes the accuracy verification.
[0142] As an optional embodiment, the second judgment sub-module includes:
[0143] The first expansion module is used to expand the second target file into the preset security processing device so that the preset security processing device can verify the accuracy of the second target file through a preset data accuracy verification method;
[0144] The first receiving module is used to receive the accuracy verification result sent by the preset security processing device, where the accuracy verification result includes passed and not passed;
[0145] The first determination module is used to determine whether the second target file passes the accuracy verification of the preset data accuracy verification method according to the accuracy verification result.
[0146] For the introduction of the secure startup device of the processing device provided in the embodiments of the present invention, please refer to the embodiments of the secure startup device of the processing device described above. The embodiments of the present invention will not be repeated here.
[0147] Please refer to Figure 8 , Figure 8 FIG. is a schematic structural diagram of a secure startup device of a processing device provided by the present invention. The secure startup device of the processing device includes:
[0148] A memory 81 for storing computer programs;
[0149] A processor 82 for implementing the steps of the secure startup method of the processing device in the foregoing embodiments when executing the computer program.
[0150] For the introduction of the secure startup device of the processing device provided in the embodiments of the present invention, please refer to the embodiments of the secure startup method of the processing device described above. The embodiments of the present invention will not be repeated here.
[0151] Please refer to Figure 9 , Figure 9 which is a schematic structural diagram of a computer-readable storage medium provided by the present invention. A computer program 92 is stored on the computer-readable storage medium 91. When the computer program 92 is executed by a processor, the steps of the secure startup method of the processing device in the foregoing embodiments are implemented.
[0152] For the introduction of the computer-readable storage medium provided by the embodiments of the present invention, please refer to the embodiments of the secure startup method of the foregoing processing device, and the embodiments of the present invention will not be elaborated herein.
[0153] The embodiments of the present invention further provide a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the secure startup method of the processing device in the foregoing embodiments are implemented.
[0154] For the introduction of the computer program product provided by the embodiments of the present invention, please refer to the embodiments of the secure startup method of the foregoing processing device, and the embodiments of the present invention will not be elaborated herein.
[0155] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part. It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, article or device including the element.
[0156] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for secure startup of a processing device, characterized in that, The first processing core applied to a processing device includes: After power-on, determine whether the first target file has been tampered with, where the first target file is used for the boot startup of a preset management system; If the first target file has not been tampered with, start the preset management system through the first target file; Judge whether the second target file has been tampered with through the preset management system, where the second target file is used for the boot startup of the main system of the processing device; If the second target file has not been tampered with, wake up the second processing core of the processing device so that the second processing core starts the main system of the processing device through the second target file.
2. The safety startup method of the processing device according to claim 1, characterized in that Determining whether the first target file has been tampered with includes: Judge whether the first target file can pass the accuracy verification of a preset data accuracy verification method; If it can pass, determine that the first target file has not been tampered with; If it fails to pass, determine that the first target file has been tampered with; Judging whether the second target file has been tampered with through the preset management system includes: Judge whether the second target file can pass the accuracy verification of a preset data accuracy verification method; If it can pass, determine that the second target file has not been tampered with; If it fails to pass, determine that the second target file has been tampered with.
3. The safety startup method of the processing device according to claim 2, characterized in that, The first target file includes a boot startup file and a preset management system file; The second target file includes a boot startup file and the main system file of the processing device; Among them, the boot startup file is used as a carrier for the boot startup program, and the boot startup program is used to boot the startup of the preset management system and the main system of the processing device.
4. The safety startup method of the processing device according to claim 3, characterized in that Judging whether the first target file can pass the accuracy verification of a preset data accuracy verification method includes: Based on the first key in the one-time programmable read-only memory, verify the signature of the boot startup file package through a key matching mechanism, where the boot startup file package includes a boot startup file, a second key matching the first key, a data feature identification code of the preset management system file, and a third key; Calculate the data feature identification code of the boot startup file through a preset data accuracy verification method; Judge whether the calculated data feature identification code of the boot startup file is consistent with the first identification code in the one-time programmable read-only memory, where the first identification code is the pre-stored data feature identification code of the boot startup file; If it is consistent with the first identification code in the one-time programmable read-only memory, determine that the boot startup file passes the accuracy verification; Based on the third key, verify the signature of the preset management system file package through a key matching mechanism, where the preset management system file package includes a preset management system file and a fourth key matching the third key; Calculate the data feature identification code of the preset management system file through a preset data accuracy verification method; Judge whether the calculated data feature identification code of the preset management system file is consistent with the data feature identification code in the boot startup file package; If it is consistent with the data feature identification code in the boot startup file package, determine that the preset management system file passes the accuracy verification.
5. The safety startup method of the processing device according to claim 4, characterized in that, The key matching mechanism includes an asymmetric key algorithm, the first key and the third key are public keys, and the second key and the fourth key are private keys; The data accuracy verification method includes a hashing algorithm.
6. The safety startup method of the processing device according to any one of claims 2 to 5, characterized in that Determining whether a second target file can pass the accuracy verification of a preset data accuracy verification method includes: Expanding the second target file to a preset security processing device so that the preset security processing device verifies the accuracy of the second target file through the preset data accuracy verification method; Receiving the accuracy verification result sent by the preset security processing device, where the accuracy verification result includes passed and not passed; Determining whether the second target file passes the accuracy verification of the preset data accuracy verification method according to the accuracy verification result.
7. The safety startup method of the processing device according to claim 1, wherein The processing device includes a baseboard management controller, and the preset management system includes a real-time operating system.
8. A safety startup device for a processing device, characterized in that Applied to the first processing core of the processing device, it includes: A first judgment module, configured to judge whether a first target file is tampered with after power-on, where the first target file is used for the boot startup of the preset management system. If the first target file is not tampered with, the first action module is triggered; A first action module, configured to start the preset management system through the first target file; A second judgment module, configured to judge whether a second target file is tampered with through the preset management system. If the second target file is not tampered with, the first wake-up module is triggered, where the second target file is used for the boot startup of the main system of the processing device; A first wake-up module, configured to wake up the second processing core of the processing device so that the second processing core starts the main system of the processing device through the second target file.
9. A safety startup device for a processing device, characterized in that, It includes: A memory, configured to store a computer program; A processor, configured to implement the steps of the security startup method of the processing device according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, the steps of the security startup method of the processing device according to any one of claims 1 to 7 are implemented.