Starting method and related device
By introducing trusted root and step-by-step measurement methods into the BMC chip, combined with dynamic measurement, the security problem of firmware tampering during server startup is solved, and a trusted trust chain is established to ensure the security and trustworthiness of the system.
Patent Information
- Application Number
- CN202510464762.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, the server has poor security problems during startup, especially after the BMC chip runs for a long time, it may be attacked or tampered, resulting in data leakage or tampering. Traditional startup methods cannot effectively ensure the security and credibility of the system.
By introducing a trusted root into the BMC chip, using the trusted root in the ROM to verify the first firmware, combining the first firmware and the second firmware for step-by-step measurement, a trust chain of trusted root-first firmware-second firmware-target firmware is established to ensure the security and trustworthiness of each firmware, and to monitor and dynamic measurements are carried out when the processor chip is restarted to ensure the overall security of the system.
It realizes the establishment of a complete trust chain during the server startup process, prevents firmware from being tampered with, and improves the security and trustworthiness of the system. Especially when the BMC chip is running for a long time, it reduces the risk of being attacked and ensures the overall security of the system.
Smart Images

Figure CN120372624A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology. Specifically, it relates to the technology of trusted boot and secure boot in the field of computer technology. More specifically, it relates to a boot method and related devices. Background Art
[0002] With the continuous popularization of cloud computing and big data application scenarios, the security of servers is of great significance to the integrity and confidentiality of user and enterprise data. For example, in cloud computing and big data application scenarios, servers are used to store and process a large amount of sensitive data, including user personal information, enterprise business secrets, financial data, etc. Ensuring the security of the server can prevent this data from being accessed or leaked without authorization. Therefore, it is of great significance to ensure that the server runs in a secure environment. Summary of the Invention
[0003] Embodiments of this specification provide a boot method and related devices to achieve the purpose of establishing a complete trust chain during the boot process and ensuring the security and trustworthiness of the on-chip system boot process.
[0004] To achieve the above technical objectives, the embodiments of this specification provide the following technical solutions:
[0005] In a first aspect, an embodiment of this specification provides a boot method applied to a baseboard management controller (BMC) chip of an on-chip system. The on-chip system further includes a processor chip. The BMC chip includes a read-only memory (ROM), a first processor core, and a second processor core. The ROM is used to store a trusted root. The processor chip includes a target firmware. The processor chip is used to run user applications. The boot method includes:
[0006] In response to a boot operation for the on-chip system, the BMC chip uses the trusted root to verify the signature of a first firmware. If the signature verification passes, the first processor core is started to run the first firmware to achieve secure boot;
[0007] Use the first firmware to perform a trusted boot process on the firmware to be measured, where the firmware to be measured includes the second firmware and the target firmware;
[0008] The first firmware is the firmware of the first processor core, and the second firmware is the firmware of the second processor core.
[0009] In a second aspect, an embodiment of this specification provides an on-chip system, as Figure 2As shown, it includes: a BMC chip and a processor chip. Among them, the BMC chip includes a ROM, a first processor core, and a second processor core. The ROM is used to store the trusted root. The processor chip includes target firmware, and the processor chip is used to run user applications;
[0010] The BMC chip is configured to:
[0011] In response to a startup operation for the system-on-chip, the BMC chip uses the trusted root to verify and sign the first firmware. If the verification and signature pass, the first processor core is started, and the first processor core runs the first firmware to achieve a secure startup;
[0012] Use the first firmware to perform a trusted startup process on the firmware to be measured. The firmware to be measured includes the second firmware and the target firmware;
[0013] The first firmware is the firmware of the first processor core, and the second firmware is the firmware of the second processor core.
[0014] Optionally, the BMC chip using the first firmware to perform a trusted startup process on the firmware to be measured specifically includes:
[0015] Use the first firmware, the second firmware, and the target firmware for hierarchical measurement to achieve the trusted startup of the second processor core and the processor chip.
[0016] Optionally, the BMC chip further includes a trusted computing module, and the trusted computing module includes a trusted password module;
[0017] The BMC chip using the first firmware, the second firmware, and the target firmware for hierarchical measurement to achieve the trusted startup of the second processor core and the processor chip specifically includes:
[0018] Use the first firmware to measure the second firmware to obtain a first measurement value and write it into the trusted computing module. When the first measurement value is consistent with the first standard value, the second firmware passes the measurement, and the second processor core is started; the first standard value includes the standard measurement value corresponding to the second processor core;
[0019] Use the second firmware to measure the target firmware to obtain a second measurement value and write it into the trusted computing module. When the second measurement value is consistent with the second standard value, the target firmware passes the measurement, and the processor chip is started to complete the trusted startup process; the second standard value includes the standard measurement value corresponding to the processor chip.
[0020] Optionally, the first processor core further includes: a measurement module;
[0021] After the BMC chip uses the first firmware to execute a trusted boot process on the firmware to be measured, it is further used for:
[0022] The first processor core runs the measurement module and uses the measurement module to perform dynamic measurement on the second processor core.
[0023] Optionally, the second processor core further includes: a proxy module and a startup management module, wherein the startup management module is used to measure the target firmware when the processor chip restarts, and the proxy module is used to obtain the address information of the code segment in the second processor core;
[0024] The specific process of the BMC chip using the measurement module to perform dynamic measurement on the second processor core is as follows:
[0025] The first processor core measures the proxy module and / or the startup management module using the measurement module at regular intervals or random times to obtain a dynamic measurement result, and the dynamic measurement result is used to characterize the trust level of the proxy module and / or the startup management module.
[0026] Optionally, the proxy module runs in the kernel mode, and the specific process of the BMC chip using the measurement module to measure the proxy module includes:
[0027] The first processor core looks up the code offset and the size of the proxy module in the kernel of the second processor core through the symbol table;
[0028] Based on the code offset, the physical address of the proxy module is obtained;
[0029] Based on the physical address of the proxy module and the size of the proxy module, a page table for accessing the physical address of the proxy module in the second processor core is established, the physical address of the second processor core is mapped to the virtual address of the first processor core, and based on the mapped virtual address, the code segment of the proxy module in the second processor core is accessed and the code segment of the proxy module is measured.
[0030] Optionally, the startup management module runs in the user mode, and the process of using the measurement module to measure the startup management module includes:
[0031] The first processor core calls the proxy module to obtain the code segment of the user-mode process, and based on the code segment of the user-mode process, obtains the physical address corresponding to the startup management module;
[0032] Forward the physical address corresponding to the startup management module to the measurement module;
[0033] The measurement module establishes a mapping page table based on the physical address of the startup management module, and measures the code segment of the startup management module based on the mapping page table. The mapping page table is used to describe the mapping relationship between the physical address and the virtual address of the startup management module.
[0034] Optionally, the second processor core further includes: a startup management module;
[0035] After the BMC chip uses the first firmware to execute a trusted startup process for the firmware to be measured, it is further used for:
[0036] The startup management module monitors the processor chip, and when the power-on signal of the processor chip is detected, measures at least part of the target firmware of the processor chip.
[0037] Optionally, the system-on-chip further includes: a complex programmable logic device CPLD, which is used for power-on timing control and power management of the system-on-chip; the firmware to be measured further includes CPLD firmware.
[0038] In a third aspect, an embodiment of this specification further provides a computing device, including a memory, a processor chip, a BMC chip, and a computer program stored in the memory and executable on the BMC chip. When the BMC chip executes the computer program, the startup method described above is implemented.
[0039] In a fourth aspect, an embodiment of this specification further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the startup method described above is implemented.
[0040] In a fifth aspect, an embodiment of this specification provides a computer program product or a computer program. The computer program product includes a computer program, and the computer program is stored in a computer-readable storage medium; a processor of the computer device reads the computer program from the computer-readable storage medium, and when the processor executes the computer program, the steps of the above-described startup method are implemented. Optionally, the computer program can be stored in a readable storage medium or the cloud of the computer device; the processor of the computer device reads the computer program from the readable storage medium or the cloud.
[0041] As can be seen from the above technical solution, the startup method provided by the embodiments of this specification is applied to the BMC chip of the system-on-chip. During the startup process of the system-on-chip, the BMC chip uses the root of trust stored in the ROM to verify the signature of the first firmware. If the signature verification passes, the first processor core is started, and the first processor core runs the first firmware to achieve secure startup. After the first processor core successfully starts securely, the first firmware is used to perform a trusted startup process on the firmware to be measured. In this way, by combining secure startup and trusted startup, for a system-on-chip containing a BMC chip, starting from the root of trust in the ROM, a complete trust chain of root of trust - first firmware - second firmware - target firmware is established, avoiding security risks caused by at least one of the first firmware and the second firmware being tampered with, which is beneficial to ensuring the overall security of the system-on-chip. Especially in the server application scenario, after a power-on, the continuous running time of the BMC chip can be calculated in months or years. Verifying the signature or measuring the relevant firmware of the BMC chip is of great significance for ensuring the security of the BMC chip itself. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.
[0043] Figure 1 Schematic flowchart of a startup method provided by an embodiment of this specification;
[0044] Figure 2 Schematic structural diagram of a system-on-chip provided by an embodiment of this specification;
[0045] Figure 3 Schematic diagram of the construction process of a trust chain provided by an embodiment of this specification;
[0046] Figure 4 Schematic diagram of another construction process of a trust chain provided by an embodiment of this specification;
[0047] Figure 5 Schematic structural diagram of a computing device provided by an embodiment of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] Unless otherwise defined, the technical terms or scientific terms used in the embodiments of this specification shall have the ordinary meanings understood by those of ordinary skill in the art to which this specification pertains. The terms "first", "second" and similar words used in the embodiments of this specification do not denote any order, quantity or importance, but are merely used to avoid confusion of components.
[0049] Unless the context otherwise requires, throughout this specification, "a plurality of" means "at least two", and "comprising" is interpreted as open and inclusive, that is, "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "examples", "specific examples" or "some examples" etc. are intended to indicate that specific features, structures, materials or characteristics related to the embodiment or example are included in at least one embodiment or example of this specification. The schematic representations of the above terms do not necessarily refer to the same embodiment or example.
[0050] The technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this specification without creative efforts shall fall within the scope of protection of this specification.
[0051] Overview
[0052] A Baseboard Management Controller (BMC) chip is a dedicated microcontroller embedded on the motherboard of a system-on-chip, and can be used to provide efficient system-on-chip management functions. The BMC chip can be a microcontroller that can operate independently of the central processor and operating system in the system-on-chip, and can monitor and manage the hardware status of the system-on-chip in real time. Even when the processor of the system-on-chip is in the shutdown state or the operating system cannot run properly, the BMC chip can still work. It is connected to other hardware components of the system-on-chip through the interfaces of various sensors, collects data and executes management tasks.
[0053] In application scenarios such as servers, the BMC chip can meet the operation and maintenance requirements of system administrators, such as remote management, hardware status monitoring, event recording and alarming. As mentioned above, in application scenarios such as servers, after the system-on-chip is powered on once, the BMC chip can run for a long time. During the continuous operation of the BMC chip, the central processor of the server can perform operations such as restart. That is, after the central processor is powered off, the BMC chip may not be powered off, that is, the operating states of the BMC chip and the central processor can be asynchronous. In this case, after the server is powered on once, the BMC chip may run continuously for several months. The traditional startup method of the system-on-chip has poor security in application scenarios such as servers. Attackers may steal or tamper with data by attacking hardware such as the central processor and BMC chip of the server, which may cause inestimable losses to server operators and users.
[0054] To solve this problem, the inventor proposes a startup method for the BMC chip applied to the system-on-chip. During the startup process of the system-on-chip, the BMC chip uses the trusted root stored in the ROM to verify the signature of the first firmware. If the signature verification passes, the first processor core is started to make the first processor core run the first firmware to achieve secure startup; after the first processor core is successfully started securely, the trusted startup process is performed on the firmware to be measured using the first firmware. In this way, by combining secure startup and trusted startup, for the system-on-chip containing the BMC chip, starting from the trusted root in the ROM, a complete trust chain of trusted root - first firmware - second firmware - target firmware is established, avoiding security risks caused by the tampering of at least one of the first firmware and the second firmware, which is beneficial to ensuring the overall security of the system-on-chip. Especially in the server application scenario, after being powered on once, the continuous operation time of the BMC chip can be calculated in months or years. Verifying the signature or measuring the relevant firmware of the BMC chip is of great significance for ensuring the security of the BMC chip itself.
[0055] For the scenario where the BMC chip is still running when the processor chip is restarted, a method for monitoring the processor chip and trusted startup after restart is proposed to ensure the security and trust of the processor chip after each restart.
[0056] In addition, considering the characteristic that the BMC chip runs for a long time, in order to reduce the risk of the BMC chip being attacked, tampered with or replaced during the long-term operation, a scheme for dynamically measuring the second processor core based on the heterogeneous multi-core BMC chip architecture is also proposed to ensure the security and trust of the BMC chip during the continuous operation process.
[0057] Based on the above concept, the embodiments of this specification provide a startup method. Next, the startup method provided by the embodiments of this specification will be described exemplarily with reference to the drawings.
[0058] Exemplary method
[0059] An embodiment of the present specification provides a startup method. As Figure 1 shown, it is applied to the Baseboard Management Controller (BMC) chip 10 of the system-on-chip (SoC) 100 as Figure 2 shown. The SoC 100 further includes a processor chip 20. The BMC chip 10 includes a Read-Only Memory (ROM) 13, a first processor core 11, and a second processor core 12. The ROM 13 is used to store the root of trust. The processor chip 20 includes target firmware. The processor chip 20 is used to run user applications. The startup method includes:
[0060] In response to a startup operation for the SoC 100, the BMC chip 10 verifies the signature of the first firmware using the root of trust. If the signature verification passes, the first processor core 11 is started, and the first processor core 11 runs the first firmware to achieve secure startup;
[0061] Use the first firmware to perform a trusted startup process on the firmware to be measured, where the firmware to be measured includes the second firmware and the target firmware;
[0062] The first firmware is the firmware of the first processor core 11, and the second firmware is the firmware of the second processor core 12.
[0063] In an embodiment of the present specification, the BMC chip 10 may be a multi-core chip architecture, that is, the BMC chip 10 may include a first processor core 11 and a second processor core 12. Among them, the first processor core 11 may be responsible for the security and trust transactions of the BMC chip 10 and the processor chip 20. In some embodiments, the first processor core 11 may be referred to as a trusted core; the second processor core 12 may be responsible for specific program operations, calculations, and other tasks. Therefore, the second processor core 12 may be referred to as a computing core. The number of the first processor core 11 and the second processor core 12 may be one or multiple, and the present specification does not limit this, which depends on the actual situation.
[0064] In the BMC chip 10, the trusted root in the ROM 13 can be written before loading the system-on-chip 100. During the operation of the entire system-on-chip 100, the trusted root in the ROM 13 can only be read, and no information can be written again. In this way, it can be avoided that the trusted root in the ROM 13 is tampered with after the system-on-chip 100 leaves the factory. Based on the characteristic that the information in the ROM 13 can only be written once, the startup method provided by the embodiments of this specification uses the trusted root stored in the ROM 13 to verify the signature of the first firmware. When the signature verification passes, the first processor core 11 is started, and the first processor core 11 runs the first firmware to achieve secure startup. Thus, the secure signature verification and startup of the first processor core 11 in the BMC chip 10 during the startup process are realized, ensuring the security and trustworthiness of the first firmware. After that, when the first processor core 11 runs the first firmware and successfully achieves secure startup, the first firmware can be used as the trusted root for trusted startup (since the security of the first firmware has been verified during the secure startup process, ensuring the security and trustworthiness of the first firmware during the trusted startup process), and the trusted startup process is performed on the second firmware and the target firmware and other measured firmware, realizing the construction of the trust chain for trusted startup. In this way, through the combination of secure startup and trusted startup, starting from the trusted root in the ROM 13, a complete trust chain of trusted root - first firmware - second firmware - target firmware is established, avoiding security risks caused by tampering with at least one of the first firmware and the second firmware, which is beneficial to ensuring the overall security of the system-on-chip 100.
[0065] In some embodiments, the first firmware may include the firmware required for the operation of the first processor core 11, the second firmware may include the firmware required for the operation of the second processor core 12, and the target firmware may include the firmware required for the operation of the processor chip 20. For example, in some embodiments, taking the processor core with the ARM architecture as an example, the first firmware, the second firmware, and the target firmware may include some or all of the BL1 firmware, BL2 firmware, BL31 firmware, BL32 firmware, and BL33 firmware. In addition, according to the functional design requirements, it may also include MM (Manage Mode) firmware, etc. This specification does not limit this, and it depends on the actual situation specifically.
[0066] In one embodiment, a feasible trusted startup process is provided. Specifically, the process of using the first firmware to perform the trusted startup process on the measured firmware includes:
[0067] Using the first firmware, the second firmware, and the target firmware for step-by-step measurement to achieve the trusted startup of the second processor core 12 and the processor chip 20.
[0068] During the startup process, the levels of the first firmware, the second firmware, and the target firmware decrease in sequence. That is, during the step-by-step measurement process, the first firmware measures the second firmware. In the case where the measurement verification passes, the second firmware is used to measure the target firmware to meet the establishment of the trust chain in the trusted startup process.
[0069] Measurement is a verification means used in the trusted startup process. Measurement can refer to calculating the hash of the firmware to verify its integrity and credibility. Different from the secure startup process, the verification means used in the secure startup process can be signature verification, and signature verification can be to verify the digital signature of software or firmware to ensure that its source is trusted and has not been tampered with.
[0070] In this embodiment, through the step-by-step measurement among the various firmwares in the trusted startup process, a reliable trust chain is established, ensuring that each firmware used to measure the next firmware in the trust chain is secure and reliable.
[0071] In one embodiment, a feasible step-by-step measurement process is provided. Specifically, the BMC chip 10 further includes a trusted computing module, and the trusted computing module includes a trusted password module;
[0072] The step-by-step measurement using the first firmware, the second firmware, and the target firmware to achieve the trusted startup of the second processor core 12 and the processor chip 20 includes:
[0073] Use the first firmware to measure the second firmware to obtain a first measurement value and write it into the trusted computing module. When the first measurement value is consistent with the first standard value, the second firmware passes the measurement and the second processor core 12 is started; the first standard value includes the standard measurement value corresponding to the second processor core 12;
[0074] Use the second firmware to measure the target firmware to obtain a second measurement value and write it into the trusted computing module. When the second measurement value is consistent with the second standard value, the target firmware passes the measurement and the processor chip 20 is started, completing the trusted startup process; the second standard value includes the standard measurement value corresponding to the processor chip 20.
[0075] In this embodiment, the step-by-step measurement process starts from a trusted root (such as the first firmware) and gradually verifies the subsequent startup components (such as the second firmware, the target firmware, etc.). In this way, a complete trust chain is established to ensure that each component is verified, thereby guaranteeing the credibility of the entire trusted startup process. Combined with the secure startup process, a complete trust chain starting from the ROM 13 of the BMC chip 10 is constructed.
[0076] In addition, the introduction of the Trusted Cryptography Module (TCM) in the trusted computing module further enhances the security and trustworthiness of the system. Specifically, the TCM can be a hardware security module that provides a higher level of security than software. It stores the initial root of trust (such as an initial hash value or key), which can be used to verify the integrity of each component during the startup process. Generally speaking, the introduction of the trusted computing module makes the system more trustworthy during the startup process. With hardware-level security protection, the system can better resist various security threats and improve user trust.
[0077] As described above, during the operation of the entire system, it may be the case that the processor chip 20 providing services to the user restarts, but the BMC chip 10 does not. To solve the problem of the processor chip 20 being attacked and tampered with during the restart process, an embodiment of this specification proposes a method for monitoring and measuring the processor chip 20. Specifically, the second processor core 12 further includes: a startup management module;
[0078] After performing the trusted startup process on the firmware to be measured using the first firmware, it further includes:
[0079] The startup management module monitors the processor chip 20, and when the power-on signal of the processor chip 20 is detected, it measures at least part of the target firmware of the processor chip 20.
[0080] In this embodiment, the startup management module can monitor the processor chip 20. When the power-on signal of the processor chip 20 is detected, it indicates that the processor chip 20 may have performed operations such as restarting, and it is necessary to re-measure at least part of the target firmware of the processor chip 20 again to ensure the security of the target firmware of the processor chip 20 during the restart process.
[0081] In some embodiments, the BMC chip 10 has access to the GPIO (General Purpose Input Output) module of the processor chip 20. Using this privilege, the startup management module can monitor the GPIO signals of the processor chip 20 in real time to obtain the power status of the processor chip 20, so as to comprehensively monitor the power-on and power-off status of the processor chip 20. When the processor chip 20 is powered on, the GPIO module will transmit a power-on signal to the BMC chip 10. After the startup management module detects this power-on signal, it can intercept the control right of the storage medium where the BIOS of the processor chip 20 is located. When the measurement of the target firmware fails, it can block the startup of the processor chip 20. When the measurement of the target firmware passes, it can send a GPIO signal to control the processor chip 20 to continue powering on.
[0082] As described above, in application scenarios such as servers, after the system-on-chip 100 is powered on once, the BMC chip 10 may run continuously for several months. During this process, the BMC chip 10 may be attacked, tampered with, or replaced, resulting in security problems in the system-on-chip 100. To solve this problem, the embodiments of this specification provide a solution for dynamically measuring the BMC chip 10. Specifically, in one embodiment of this specification, the first processor core 11 further includes: a measurement module;
[0083] After performing a trusted startup process on the firmware to be measured using the first firmware, it further includes:
[0084] The first processor core 11 runs the measurement module, and uses the measurement module to perform dynamic measurement on the second processor core 12.
[0085] During the continuous operation of the BMC chip 10, the first processor core 11 is mainly responsible for security-related matters, and the second processor core 12 is mainly responsible for computing-related matters. Such a division of labor may leave a communication interface for the second processor core 12 to interact with the processor chip 20, and users may attack the second processor core 12 through the processor chip 20. To ensure the security and credibility of the BMC chip 10 during continuous operation, in this embodiment, a measurement module is set in the first processor core 11. After the first processor core 11 is successfully started, the first processor core 11 runs this measurement module, and uses the measurement module to perform dynamic measurement on the second processor core 12, so as to ensure the security and credibility during the continuous operation of the BMC chip 10, and avoid the problem that the BMC chip 10 loses security and credibility due to being tampered with, replaced, or attacked during long-term operation.
[0086] In one embodiment of the present specification, the metric module performing dynamic metrics on the second processor core 12 may refer to the metric module performing metrics on the second processor core 12 regularly or irregularly, or may refer to performing metrics on the second processor core 12 when the operating state of the second processor core 12 meets specific conditions. The present specification does not limit this, and it depends on the actual situation specifically.
[0087] In an optional embodiment, a method for feasible dynamic metrics is provided. Specifically, the second processor core 12 further includes: a proxy module and a startup management module. Among them, the startup management module is used to perform metrics on the target firmware when the processor chip 20 restarts, and the proxy module is used to obtain the address information of the code segment in the second processor core 12;
[0088] The use of the metric module to perform dynamic metrics on the second processor core 12 includes:
[0089] The first processor core 11 performs metrics on the proxy module and / or the startup management module using the metric module at a predetermined time or a random time, and obtains a dynamic metric result, where the dynamic metric result is used to characterize the trustworthiness of the proxy module and / or the startup management module.
[0090] In this embodiment, a startup management module and a proxy module that can perform metrics on the target firmware when the processor chip 20 restarts are set in the second processor core 12. Using the startup management module and the proxy module to perform metrics on the target firmware when the processor chip 20 restarts can ensure the security and trustworthiness during the restart process of the processor chip 20, and timely discover problems such as the target firmware of the processor chip 20 being attacked or tampered with.
[0091] In addition, since the startup management module and the proxy module have interaction interfaces with the processor chip 20 to implement their respective functions, in order to timely discover the situation where the startup management module and the proxy module lose security due to being attacked by an attacker through this interaction interface during operation, in the embodiment of the present specification, the first processor core 11 can use the metric module to perform metrics on the proxy module and / or the startup management module that are vulnerable to attack, so as to obtain a dynamic metric result that characterizes the trustworthiness of the proxy module and / or the startup management module, and achieve dynamic metrics on the second processor core 12. In this embodiment, accurately discovering the modules in the second processor core 12 that are vulnerable to attack (i.e., the startup management module and the proxy module), performing dynamic metrics on them, while ensuring the security during the operation of the BMC chip 10, reducing the number of modules that need to be measured, which is beneficial to reducing the resource consumption of the BMC chip 10 and improving the execution efficiency of the method.
[0092] In one embodiment, a feasible process for measuring an agent module is provided. Specifically, the agent module runs in the kernel mode, and the process of measuring the agent module by using the measurement module includes:
[0093] The first processor core 11 looks up the code offset and the size of the agent module in the kernel of the second processor core 12 through the symbol table;
[0094] Based on the code offset, the physical address of the agent module is obtained;
[0095] Based on the physical address of the agent module and the size of the agent module, a page table for accessing the physical address of the agent module in the second processor core 12 is established, the physical address of the second processor core 12 is mapped to the virtual address of the first processor core 11, and based on the mapped virtual address, the code segment of the agent module in the second processor core 12 is accessed, and the code segment of the agent module is measured.
[0096] The symbol table can be a data structure generated by the second processor core 12 of the BMC chip 10 during kernel compilation. The symbol table can be used to record information such as the names, addresses, and types of various symbols (such as variables, functions, modules, etc.). The symbol table can be a mapping table, which can contain the names of symbols and the corresponding memory addresses. Based on the symbol table, the code offset and the size of the agent module in the kernel of the second processor core 12 can be obtained.
[0097] The code offset is the relative position starting from a certain reference address (such as the starting address of the code segment). It is a relative address used to represent the position of a certain code block or module in the code segment.
[0098] The size of the agent module is used to characterize the length of the memory space occupied by the agent module, and can be in bytes. In this embodiment, the physical address of the agent module can be obtained through the code offset of the agent module. Based on this physical address and the size of the agent module, a correct page table can be established to meet the requirement of mapping the physical address of the second processor core 12 to the virtual address of the first processor core 11, and based on the mapped virtual address, accessing the code segment of the agent module in the second processor core 12. When the code segment of the agent module can be accessed, the code segment of the agent module can be measured to meet the measurement requirements.
[0099] Since the function of the proxy module is to obtain the address information of the code segment in the second processor core 12, a relatively high privilege level is required to access the hardware resources and the memory space in the kernel mode. Therefore, the proxy module can run in the kernel mode to meet the privilege requirements for obtaining the code segment address information. Through the above process, it is possible to relatively simply implement the measurement of the proxy module running in the kernel mode, which is beneficial to improving the execution efficiency of the method.
[0100] In one embodiment, a feasible process for measuring the startup management module is provided. Specifically, the startup management module runs in the user mode, and the process of using the measurement module to measure the startup management module includes:
[0101] The first processor core 11 calls the proxy module to obtain the code segment of the user-mode process, and based on the code segment of the user-mode process, obtains the physical address corresponding to the startup management module;
[0102] Forward the physical address corresponding to the startup management module to the measurement module;
[0103] The measurement module establishes a mapping page table according to the physical address of the startup management module, and based on the mapping page table, measures the code segment of the startup management module. The mapping page table is used to describe the mapping relationship between the physical address and the virtual address of the startup management module.
[0104] In this embodiment, the startup management module does not need to access the hardware resources and the memory space in the kernel mode of the second processor core 12 and can run in the user mode, avoiding unnecessary modules having access rights to the hardware resources and the memory space of the second processor core 12. To implement the measurement of the startup management module in the user mode, the first processor core 11 uses the proxy module to obtain the code segment of the user-mode process, and based on the obtained code segment of the user-mode process, obtains the physical address corresponding to the startup management module, and forwards the obtained physical address to the measurement module, so that the measurement module establishes a mapping page table based on the physical address of the startup management module and measures the code segment of the startup management module based on the mapping page table. In this way, the proxy module running in the kernel mode is fully utilized to implement the measurement of the startup management module, meeting the requirement for dynamic measurement of the second processor core 12 on the basis of reducing the number of modules that need to run in the kernel mode.
[0105] In one embodiment, the system-on-chip 100 may further include a Complex Programmable Logic Device (CPLD). The CPLD may be disposed independently of the BMC chip 10 and the processor chip 20. The CPLD may be responsible for functions such as power-on timing control, power management, system timing and clock management, logic function implementation, hardware monitoring and fault detection. In order to achieve comprehensive measurement of the system-on-chip 100, in one embodiment, the firmware to be measured further includes CPLD firmware. Thus, including the CPLD firmware in the trusted measurement scope is beneficial to ensuring the comprehensive security and trustworthiness of the system-on-chip 100.
[0106] To more clearly show the trust chain construction process, refer to Figure 3 and Figure 4 , Figure 3 and Figure 4 which show the construction processes of the restart flow trust chain (i.e., the trust chain during the restart of the processor chip 20) and the startup flow trust chain (i.e., the trust chain during the startup of the system-on-chip 100). In Figure 3 and Figure 4 , the trusted password module can be used to provide a benchmark for trusted measurement. The first processor core 11 is represented as the BMC trusted core, the second processor core 12 is represented as the BMC computing core, and the hypervisor, BIOS (Basic Input / Output System), Bootloader, and Kernel (represented as the host operating system kernel in Figure 4 ) can be represented as part of the target firmware. Application may refer to an application program running in the operating system of the processor chip 20 ( Figure 4 is referred to as the host operating system in it), and in Figure 4 , it may specifically refer to a critical application program.
[0107] Exemplary system
[0108] In an exemplary embodiment of the present specification, a system-on-chip 100 is further provided. As Figure 2 shown, it includes: a BMC chip 10 and a processor chip 20, wherein the BMC chip 10 includes a ROM 13, a first processor core 11, and a second processor core 12. The ROM 13 is used to store the root of trust, and the processor chip 20 includes target firmware. The processor chip 20 is used to run user applications;
[0109] The BMC chip 10 is configured to:
[0110] In response to a startup operation for the system-on-chip 100, the BMC chip 10 uses the trusted root to verify the signature of the first firmware. If the signature verification passes, the first processor core 11 is started, and the first processor core 11 runs the first firmware to achieve a secure startup.
[0111] The first firmware is used to perform a trusted startup process on the firmware to be measured, where the firmware to be measured includes the second firmware and the target firmware.
[0112] The first firmware is the firmware of the first processor core 11, and the second firmware is the firmware of the second processor core 12.
[0113] Optionally, the BMC chip 10 using the first firmware to perform a trusted startup process on the firmware to be measured specifically includes:
[0114] Using the first firmware, the second firmware, and the target firmware for hierarchical measurement to achieve the trusted startup of the second processor core 12 and the processor chip 20.
[0115] Optionally, the BMC chip 10 further includes a trusted computing module, and the trusted computing module includes a trusted password module.
[0116] The BMC chip 10 using the first firmware, the second firmware, and the target firmware for hierarchical measurement to achieve the trusted startup of the second processor core 12 and the processor chip 20 specifically includes:
[0117] Using the first firmware to measure the second firmware to obtain a first measurement value and write it into the trusted computing module. When the first measurement value is consistent with the first standard value, the measurement of the second firmware passes, and the second processor core 12 is started; the first standard value includes the standard measurement value corresponding to the second processor core 12.
[0118] Using the second firmware to measure the target firmware to obtain a second measurement value and write it into the trusted computing module. When the second measurement value is consistent with the second standard value, the measurement of the target firmware passes, and the processor chip 20 is started to complete the trusted startup process; the second standard value includes the standard measurement value corresponding to the processor chip 20.
[0119] Optionally, the first processor core 11 further includes: a measurement module.
[0120] After the BMC chip 10 uses the first firmware to perform a trusted startup process on the firmware to be measured, it is further used for:
[0121] The first processor core 11 runs the metric module and uses the metric module to perform dynamic metrics on the second processor core 12.
[0122] Optionally, the second processor core 12 further includes: a proxy module and a startup management module, wherein the startup management module is used to perform metrics on the target firmware when the processor chip 20 restarts, and the proxy module is used to obtain the address information of the code segment in the second processor core 12;
[0123] The BMC chip 10 using the metric module to perform dynamic metrics on the second processor core 12 specifically includes:
[0124] The first processor core 11 measures the proxy module and / or the startup management module using the metric module at regular intervals or randomly, and obtains a dynamic metric result, which is used to characterize the trust level of the proxy module and / or the startup management module.
[0125] Optionally, the proxy module runs in the kernel state. The process of the BMC chip 10 using the metric module to measure the proxy module specifically includes:
[0126] The first processor core 11 looks up the code offset and the size of the proxy module in the kernel of the second processor core 12 through the symbol table;
[0127] Based on the code offset, the physical address of the proxy module is obtained;
[0128] Based on the physical address of the proxy module and the size of the proxy module, a page table for accessing the physical address of the proxy module in the second processor core 12 is established, the physical address of the second processor core 12 is mapped to the virtual address of the first processor core 11, and based on the mapped virtual address, the code segment of the proxy module in the second processor core 12 is accessed, and the code segment of the proxy module is measured.
[0129] Optionally, the startup management module runs in the user state. The process of using the metric module to measure the startup management module includes:
[0130] The first processor core 11 calls the proxy module to obtain the code segment of the user state process, and based on the code segment of the user state process, obtains the physical address corresponding to the startup management module;
[0131] Forward the physical address corresponding to the startup management module to the metric module;
[0132] The measurement module establishes a mapping page table according to the physical address of the startup management module, and measures the code segment of the startup management module based on the mapping page table. The mapping page table is used to describe the mapping relationship between the physical address and the virtual address of the startup management module.
[0133] Optionally, the second processor core 12 further includes: a startup management module;
[0134] After the BMC chip 10 uses the first firmware to execute a trusted startup process for the firmware to be measured, it is further used for:
[0135] The startup management module monitors the processor chip 20, and when the power-on signal of the processor chip 20 is detected, measures at least part of the target firmware of the processor chip 20.
[0136] Optionally, the system-on-chip 100 further includes: a complex programmable logic device CPLD, which is used for power-on timing control and power management of the system-on-chip 100; the firmware to be measured further includes CPLD firmware.
[0137] For the specific limitations of the system-on-chip 100, reference can be made to the limitations on the startup method in the above text, which will not be elaborated here. Each module in the above system-on-chip 100 can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above modules.
[0138] Exemplary computing device
[0139] Another embodiment of the present application also proposes a computing device, see Figure 5 As shown, an exemplary embodiment of this specification also provides a computing device, including: a memory, a processor chip, a BMC chip, and a computer program stored on the memory and executable on the BMC chip. When the BMC chip executes the computer program, it executes the steps in the startup method according to various embodiments of this specification described in the above embodiments of this specification.
[0140] The internal structure of this computing device can be as Figure 5 As shown, this computing device includes a processor chip and a BMC chip connected by a system bus ( Figure 5(not shown in the figure), a memory, a network interface, and an input device. Among them, the processor of the computing device is used to provide computing and control capabilities. The memory of the computing device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computing device is used to communicate with an external terminal through a network connection. When the computer program is executed by the BMC chip, it performs the steps in the startup method according to various embodiments of this specification described in the above embodiments of this specification.
[0141] The processor may include a main processor, and may also include a baseband chip, a modem, etc.
[0142] It can be understood that each step of the above method embodiments can be completed by the integrated logic circuit of the hardware in the BMC chip or the instructions in the form of software. The various methods, steps, and logic block diagrams disclosed in the embodiments of this specification can be implemented or executed.
[0143] The processor in the embodiments of this specification may be an integrated circuit chip with signal processing capabilities. During implementation, the processor in the computing device may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0144] It can be understood that the memory in the embodiments of this specification may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0145] The input device may include a device for receiving user input data and information, such as a keyboard, a mouse, a camera, a scanner, a light pen, a voice input device, a touch screen, a pedometer, or a gravity sensor, etc.
[0146] The output device may include devices that allow information to be output to the user, such as a display screen, a printer, a speaker, etc.
[0147] The communication interface may include devices such as any transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), etc.
[0148] The computing device may further include a display component and a voice component. The display component may be a liquid crystal display screen or an electronic ink display screen. The input device of the computing device may be a touch layer covering the display component, or a button, a trackball, or a touchpad provided on the housing of the computing device, or an external keyboard, touchpad, or mouse, etc.
[0149] Those skilled in the art can understand that Figure 5 the structure shown in is only a block diagram of some structures related to the solution of this specification, and does not constitute a limitation on the computing device to which the solution of this specification is applied. The specific computing device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0150] Exemplary Computer Program Product and Storage Medium
[0151] In addition to the above methods and devices, the startup method provided by the embodiments of this specification may also be a computer program product, which includes computer program instructions. When the computer program instructions are run by a processor, the processor is caused to execute the steps in the startup method according to various embodiments of this specification described in the "Exemplary Method" section of this specification.
[0152] The above computer program product may be specifically implemented in a manner of hardware, software, or a combination thereof. In an alternative embodiment, the computer program product is specifically embodied as a computer storage medium. In another alternative embodiment, the computer program product is specifically embodied as a software product, such as a Software Development Kit (SDK), etc.
[0153] The computer program product may be written in any combination of one or more programming languages for executing the program code of the operations of the embodiments of the present specification. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0154] In addition, the embodiments of the present specification also provide a computer-readable storage medium having stored thereon a computer program, and the computer program is executed by a processor to perform the steps in the startup method according to various embodiments of the present specification described in the above "Exemplary Method" section.
[0155] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium, and when the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present specification can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0156] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0157] The above-described embodiments merely represent several implementation manners of this specification. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the solutions provided by the embodiments of this specification. It should be noted that for those of ordinary skill in the art, without departing from the concept of this specification, several modifications and improvements can still be made, and these all fall within the protection scope of this specification. Therefore, the protection scope of the patent of this specification shall be subject to the appended claims.
Claims
1. A startup method, characterized in that, A Baseboard Management Controller (BMC) chip applied to a System on Chip (SoC), where the SoC further includes a processor chip. The BMC chip includes a Read-Only Memory (ROM), a first processor core, and a second processor core. The ROM is used to store the root of trust. The processor chip includes target firmware, and the processor chip is used to run user applications. The startup method includes: In response to a startup operation for the SoC, the BMC chip uses the root of trust to verify the signature of the first firmware. When the signature verification passes, the first processor core is started, and the first processor core runs the first firmware to achieve a secure startup; Use the first firmware to perform a trusted startup process on the firmware to be measured, where the firmware to be measured includes the second firmware and the target firmware; The first firmware is the firmware of the first processor core, and the second firmware is the firmware of the second processor core.
2. The method according to claim 1, wherein The step of using the first firmware to perform a trusted startup process on the firmware to be measured includes: Perform step-by-step measurement using the first firmware, the second firmware, and the target firmware to achieve the trusted startup of the second processor core and the processor chip.
3. The method according to claim 2, wherein The BMC chip further includes a trusted computing module, and the trusted computing module includes a trusted password module; The step of performing step-by-step measurement using the first firmware, the second firmware, and the target firmware to achieve the trusted startup of the second processor core and the processor chip includes: Use the first firmware to measure the second firmware to obtain a first measurement value and write it into the trusted computing module. When the first measurement value is consistent with the first standard value, the measurement of the second firmware passes, and the second processor core is started; the first standard value includes a standard measurement value corresponding to the second processor core; Use the second firmware to measure the target firmware to obtain a second measurement value and write it into the trusted computing module. When the second measurement value is consistent with the second standard value, the measurement of the target firmware passes, and the processor chip is started to complete the trusted startup process; the second standard value includes a standard measurement value corresponding to the processor chip.
4. The method according to claim 1, wherein The first processor core further includes: a measurement module; After performing the trusted startup process on the firmware to be measured using the first firmware, it further includes: The first processor core runs the measurement module and uses the measurement module to perform dynamic measurement on the second processor core.
5. The method according to claim 4, wherein The second processor core further includes: a proxy module and a startup management module, where the startup management module is used to measure the target firmware when the processor chip restarts, and the proxy module is used to obtain the address information of the code segment in the second processor core; The step of performing dynamic measurement on the second processor core using the measurement module includes: The first processor core measures the proxy module and / or the startup management module using the measurement module at a predetermined time or a random time, and obtains a dynamic measurement result, where the dynamic measurement result is used to characterize the trust level of the proxy module and / or the startup management module.
6. The method according to claim 5, characterized in that The proxy module runs in the kernel mode. The process of measuring the proxy module by using the measurement module includes: The first processor core looks up the code offset and the size of the proxy module in the kernel of the second processor core through the symbol table; Based on the code offset, obtain the physical address of the proxy module; Based on the physical address of the proxy module and the size of the proxy module, establish a page table for accessing the physical address of the proxy module in the second processor core, map the physical address of the second processor core to the virtual address of the first processor core, and based on the mapped virtual address, access the code segment of the proxy module in the second processor core and measure the code segment of the proxy module.
7. The method according to claim 5, wherein The startup management module runs in the user mode. The process of measuring the startup management module by using the measurement module includes: The first processor core calls the proxy module, obtains the code segment of the user-mode process, and based on the code segment of the user-mode process, obtains the physical address corresponding to the startup management module; Forward the physical address corresponding to the startup management module to the measurement module; The measurement module establishes a mapping page table according to the physical address of the startup management module, and based on the mapping page table, measures the code segment of the startup management module. The mapping page table is used to describe the mapping relationship between the physical address and the virtual address of the startup management module.
8. The method according to any one of claims 1 to 7, characterized in that The second processor core further includes: a startup management module; After using the first firmware to perform a trusted startup process on the firmware to be measured, it further includes: The startup management module monitors the processor chip. When the power-on signal of the processor chip is detected, at least part of the target firmware of the processor chip is measured.
9. The method according to any one of claims 1 to 7, characterized in that The system-on-chip further includes: a complex programmable logic device CPLD, which is used for power-on timing control and power management of the system-on-chip; the firmware to be measured further includes CPLD firmware.
10. A system on chip, characterized in that, Includes: A BMC chip and a processor chip. Among them, the BMC chip includes a ROM, a first processor core and a second processor core. The ROM is used to store the trusted root. The processor chip includes target firmware, and the processor chip is used to run user applications; The BMC chip is configured to: In response to a startup operation for the system-on-chip, the BMC chip uses the trusted root to verify the signature of the first firmware. When the signature verification passes, start the first processor core to make the first processor core run the first firmware to achieve secure startup; Use the first firmware to perform a trusted startup process on the firmware to be measured. The firmware to be measured includes the second firmware and the target firmware; The first firmware is the firmware of the first processor core, and the second firmware is the firmware of the second processor core.
11. A computing device, characterized in that, Includes a memory, a processor chip, a BMC chip, and a computer program stored on the memory and executable on the BMC chip. When the BMC chip executes the computer program, the startup method according to any one of claims 1 to 9 is implemented.
12. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the startup method according to any one of claims 1 to 9 is implemented.