Hardware driving method, device and equipment for basic input and output system
By detecting hardware fingerprints and generating description files during the BIOS startup process, combined with a layered driver method, the compatibility issue of BIOS adaptation to different CPU architectures is solved, the code reuse rate is improved, and the adaptation verification cycle is shortened.
Patent Information
- Application Number
- CN202510759660.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-09-05
AI Technical Summary
Existing BIOS is difficult to adapt and be compatible with CPU architectures of different platforms, resulting in low code reuse rate and long verification cycle.
By detecting hardware fingerprint information during the BIOS startup process, generating a hardware description file, and adopting a layered driver method during the initialization process, including a general driver layer, a platform adaptation layer, and a hardware abstraction layer, automatic hardware identification and matching is achieved.
It improves the BIOS's adaptability and compatibility, as well as the code reuse rate, and shortens the adaptation and verification cycle for different platform CPU architectures.
Smart Images

Figure CN120596162A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a hardware driving method, device and equipment for a basic input and output system. Background Art
[0002] The BIOS (Basic Input / Output System) is a set of programs stored on a ROM (Read Only Memory) chip on a computer's motherboard. It stores the computer's most important basic input / output (BIO) programs, system settings, power-on self-test (PTS) routines, and system bootstrap routines. The BIOS acts as a bridge between software and hardware, providing the lowest-level hardware support, resolving immediate hardware requirements, and providing the most direct and fundamental hardware configuration and control for the computer.
[0003] During the era when x86 (a processor instruction set architecture) dominated traditional servers, BIOS development relied on a relatively unified instruction set architecture (ISA) and firmware interface specifications, with platform adaptation primarily requiring minor adjustments based on chipset iterations. However, the server industry is currently accelerating its domestic substitution efforts, and domestically produced CPU (Central Processing Unit) platforms are characterized by four parallel technology paths: 1) x86-compatible CPU platforms; 2) CPU platforms using the ARMv8 (a processor architecture); 3) CPU platforms using proprietary instruction sets; and 4) CPU platforms using the open-source RISC-V (an open-source modular instruction set) architecture. This heterogeneous landscape makes it difficult for a single BIOS version to adapt to multiple CPU architectures, resulting in limited code reuse and lengthy verification cycles. Therefore, how to make BIOS compatible with different CPU architectures, improve BIOS compatibility and code reuse, and thus shorten the adaptation and verification cycles for different CPU architectures, is an urgent issue. Summary of the Invention
[0004] The purpose of the present invention is to provide a hardware driving method, device and equipment for a basic input and output system, so that the BIOS can be adapted and compatible with the CPU architectures of different platforms, improve the adaptation compatibility and code reuse rate of the BIOS, and thus shorten the adaptation cycle and verification cycle of the CPU architectures of different platforms.
[0005] To solve the above technical problems, the present invention provides a hardware driving method for a basic input / output system, comprising:
[0006] During the startup of the basic input and output system, hardware fingerprint information is detected and collected; wherein the hardware fingerprint information includes central processing unit architecture information, memory information and peripheral interface information;
[0007] Generate a hardware description file of a target processor platform according to the hardware fingerprint information; wherein the target processor platform is any preset central processing unit architecture platform;
[0008] During the initialization process of the basic input and output system, the layered driver of the hardware is completed according to the hardware description file; wherein the layered driver includes a general driver layer, a platform adaptation layer and a hardware abstraction layer.
[0009] On the other hand, detection and collection of hardware fingerprint information includes:
[0010] Reading a central processing unit identification register to obtain the central processing unit architecture information; wherein the central processing unit architecture information includes a component number in the central processing unit identification register;
[0011] Parsing memory serial presence detection data to obtain the memory information; wherein the memory information includes at least one of memory type information, capacity information, speed information, voltage information, timing information, and manufacturer information;
[0012] Scan the peripheral bus, peripheral devices and peripheral functions level by level to obtain device tree structure information; wherein the peripheral interface information includes the device tree structure information.
[0013] On the other hand, the startup process is a security stage or an initialization stage, and the initialization process is an execution drive environment stage.
[0014] On the other hand, generating a hardware description file of a target processor platform according to the hardware fingerprint information includes:
[0015] Determining whether the hardware fingerprint information matches any preset device feature of the preset central processing unit architecture platform;
[0016] If so, the matched preset central processing unit architecture platform is used as the target processor platform, and a hardware description file corresponding to the hardware fingerprint information is generated.
[0017] On the other hand, after generating the hardware description file of the target processor platform according to the hardware fingerprint information, the method further includes:
[0018] Encrypting and storing the hardware description file in a security chip;
[0019] The hardware description file is transferred to the initialization process through the switch block mechanism of the initialization phase of the basic input and output system.
[0020] On the other hand, according to the hardware description file, completing the hierarchical driver of the hardware includes:
[0021] Loading a driver for a general function through the general driver layer based on the UEFI standard protocol; wherein the general function includes at least one of a peripheral component interconnect standard initialization function, a universal serial bus initialization function, and a hard disk interface bus initialization function;
[0022] Converting the preset instruction set and the preset memory management policy into the instruction set and the memory management policy of the target processor platform through the platform adaptation layer;
[0023] The proprietary driver of the target processor platform is loaded through the hardware abstraction layer and a dynamic link library.
[0024] On the other hand, before completing the hierarchical driver of the hardware according to the hardware description file, the method further includes:
[0025] Through a preset configurable security policy engine, the loaded driver is subjected to security and trustworthiness verification corresponding to the target processor platform; wherein, the security and trustworthiness verification includes at least one of secure boot verification of the unified extensible firmware interface, encryption algorithm verification and trusted root verification.
[0026] On the other hand, by presetting a configurable security policy engine, the driver to be loaded is subjected to security and trustworthiness verification corresponding to the target processor platform, including:
[0027] Performing certificate verification on the driver to be loaded and obtaining a certificate verification result;
[0028] If the certificate verification result is passed, use the target encryption algorithm corresponding to the target processor platform to perform signature verification on the driver to be loaded and obtain the signature verification result;
[0029] If the signature verification result is verification passed, when the driver to be loaded is in a trusted execution environment, a measurement result corresponding to the driver to be loaded is obtained and a corresponding audit log is generated.
[0030] The present invention also provides a hardware driver for a basic input / output system, comprising:
[0031] A probe detection module is used to detect and collect hardware fingerprint information during the startup process of the basic input and output system; wherein the hardware fingerprint information includes central processing unit architecture information, memory information and peripheral interface information;
[0032] A file generation module, configured to generate a hardware description file of a target processor platform based on the hardware fingerprint information; wherein the target processor platform is any preset central processing unit architecture platform;
[0033] The modular driver module is used to complete the hierarchical driver of the hardware according to the hardware description file during the initialization process of the basic input and output system; wherein the hierarchical driver includes a general driver layer, a platform adaptation layer and a hardware abstraction layer.
[0034] In addition, the present invention also provides a hardware driver device for a basic input / output system, comprising:
[0035] Memory for storing computer programs;
[0036] The processor is configured to implement the steps of the above-mentioned basic input and output system hardware driving method when executing the computer program.
[0037] The present invention provides a hardware driving method for a basic input / output system, comprising: detecting and collecting hardware fingerprint information during the startup process of the basic input / output system; wherein the hardware fingerprint information includes central processing unit architecture information, memory information, and peripheral interface information; generating a hardware description file of a target processor platform based on the hardware fingerprint information; wherein the target processor platform is any preset central processing unit architecture platform; and completing a hierarchical driving of the hardware based on the hardware description file during the initialization process of the basic input / output system; wherein the hierarchical driving includes a universal driver layer, a platform adaptation layer, and a hardware abstraction layer.
[0038] As can be seen, the present invention uses an embedded probe to generate an HDF (Hierarchical Data Format) file during the BIOS startup process, enabling automatic identification and matching of multi-architecture parameters. This utilizes the HDF file during BIOS initialization to implement layered hardware drivers, enabling the BIOS to adapt and be compatible with CPU architectures on different platforms. This improves BIOS compatibility and code reuse, thereby shortening the adaptation and verification cycles for different CPU architectures. Furthermore, the present invention provides a hardware driver device and apparatus for a basic input / output system (BIOS), also achieving the aforementioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0040] Figure 1 A flowchart of a hardware driving method for a basic input / output system provided by an embodiment of the present invention;
[0041] Figure 2 A schematic diagram of a flow chart of a dynamic hardware detection mechanism provided by an embodiment of the present invention;
[0042] Figure 3 A schematic diagram of a process flow of a driver loading process provided by an embodiment of the present invention;
[0043] Figure 4 A schematic diagram of a flow chart of a secure and trustworthy verification process provided by an embodiment of the present invention;
[0044] Figure 5 A structural block diagram of a hardware driver for a basic input / output system provided by an embodiment of the present invention;
[0045] Figure 6 This is a structural diagram of a hardware driver device of a basic input / output system provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0046] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0047] Please refer to Figure 1 , Figure 1 This is a flowchart of a hardware driving method for a basic input / output system provided by an embodiment of the present invention. The method may include:
[0048] Step 101: During the startup of the basic input and output system, hardware fingerprint information is detected and collected; wherein the hardware fingerprint information includes central processing unit architecture information, memory information and peripheral interface information.
[0049] It is understood that the Basic Input / Output System (BIOS) startup process in this embodiment may be the process before hardware driver initialization during BIOS power-up, such as the SEC (security phase) or PEI (Pre-EFIIinitialization) phase before the BIOS DXE (Driver Execution Environment) phase. In this embodiment, during the BIOS startup process (such as the SEC or PEI phase), an embedded probe module automatically identifies key parameters (i.e., hardware fingerprint information) such as central processing unit (CPU) architecture information, memory information, and peripheral interface information to generate a corresponding hardware description file (Hierarchical Data Format, HDF) to provide a basis for subsequent driver loading.
[0050] The specific content of the hardware fingerprint information in this embodiment, that is, the specific method of detecting and collecting the hardware fingerprint information during the startup process of the basic input and output system in this step, can be set by the designer according to practical scenarios and user needs. For example, the process of detecting and collecting the hardware fingerprint information can include: reading the central processing unit identification register to obtain the central processing unit architecture information; wherein the central processing unit architecture information includes the part number in the central processing unit identification register; that is, by reading the CPU identification register (i.e., the central processing unit identification register), the corresponding PartNum (part number) can be obtained, thereby determining the instruction set used by the CPU architecture (i.e., the target processor platform); for example, reading the ARM (Advanced RISC Machine, a type of processor) CPU identification register MIDR_EL1 to obtain PartNum = 0x662; accordingly, the central processing unit architecture information can also include instruction set information and / or CPU architecture identification corresponding to the part number, and this embodiment does not impose any restrictions on this.
[0051] Accordingly, the above-mentioned process of detecting and collecting hardware fingerprint information may further include parsing memory serial presence detection data to obtain memory information; wherein the memory information includes at least one of memory type information, capacity information, speed information (or frequency information), voltage information, timing information, and manufacturer information. For example, in this step, the memory controller may scan and parse the data (i.e., memory serial presence detection data) in an SPD (Serial Presence Detect) EEPROM (Electrically Erasable Programmable Read Only Memory) to identify specific memory information such as memory type information, capacity information, speed / frequency information, voltage information, timing information, and manufacturer information, thereby completing memory initialization.
[0052] Correspondingly, the above-mentioned process of detecting and collecting hardware fingerprint information may also include: scanning the peripheral bus, peripheral devices, and peripheral functions level by level to obtain device tree structure information; wherein the peripheral interface information includes device tree structure information. For example, when the peripheral bus is a PCIe (Peripheral Component Interconnect Express, a high-speed serial computer expansion bus standard) bus or a PCI (Peripheral Component Interconnect) bus, the bus, devices, and functions can be scanned level by level through the configuration space (PCI configuration space) or autonomous protocol to obtain device tree structure information, thereby constructing a complete device tree structure and realizing peripheral topology detection.
[0053] For example, if Figure 2 As shown, in this embodiment, the embedded probe module in the BIOS can be used to start the BIOS (such as Figure 2 Hardware fingerprint information is collected during the SEC phase of the Power On process. The following three detection modes can be performed: a) Instruction set probe: Reads the CPU identification register to obtain the corresponding PartNum, for example, reads the ARM CPU identification register MIDR_EL1 to obtain PartNum = 0x662; b) Memory controller scan: Parses the data of the SPD EEPROM to identify the specific memory information (i.e., memory information), and then completes the memory initialization; c) PCIe topology detection: Scans the bus, device, and function level by level through the PCI configuration space or autonomous protocol to build a complete device tree structure.
[0054] Step 102: Generate a hardware description file of a target processor platform according to the hardware fingerprint information; wherein the target processor platform is any preset central processing unit architecture platform.
[0055] Accordingly, in this step, the hardware fingerprint information collected by dynamic detection in step 101 can be structured and stored to generate a hardware description file (HDF) of the target processor platform, thereby achieving a unified description of heterogeneous hardware, covering key information such as CPU architecture, memory configuration, peripheral topology and security chip, and providing a basis for subsequent driver loading.
[0056] Correspondingly, the specific method of generating the hardware description file of the target processor platform according to the hardware fingerprint information in this step can be set by the designer according to the usage scenario and user needs. For example, it can be determined whether the hardware fingerprint information matches the preset device characteristics of any preset central processor architecture platform, such as Figure 2 If yes, the preset CPU architecture platform is used as the target processor platform, and a hardware description file corresponding to the hardware fingerprint information is generated; if no, an exception handling process can be triggered, such as an alarm, an error, or a prompt message indicating that the CPU architecture is incompatible.
[0057] The specific process of generating the hardware description file corresponding to the hardware fingerprint information, i.e., the specific content of the hardware description file, can be set by the designer based on practical scenarios and user needs. For example, a hardware description file for the target processor platform can be generated based on the hardware fingerprint information using a preset general description method; or a hardware description file for the target processor platform can be generated based on the hardware fingerprint information using a target description method. The target description method can be a preset description method corresponding to the target processor platform. In other words, description methods (i.e., preset description methods) corresponding to different preset central processing unit architecture platforms can be pre-set, so that the hardware description file is generated using the corresponding description method (i.e., preset description method) based on the target processor platform with feature matching. This embodiment does not impose any restrictions on this.
[0058] Further, such as Figure 2 As shown, this step may also include: encrypting and storing the hardware description file in the security chip; passing the hardware description file to the initialization process through the switching block mechanism of the basic input and output system initialization phase; thereby realizing the encrypted storage and transmission of the hardware description file. For example, after the hardware description file is generated, it is encrypted and stored in the NVDIMM (non-volatile dual in-line memory module) area of the security chip, such as Figure 2The hardware fingerprint information is stored in the NVDIMM area of the TPCM (Trusted Platform Control Module) chip (such as address 0xFE0A0000) in the PEI stage and is passed to the subsequent initialization process (such as the DXE stage) through the HOB (Hand-off Block) mechanism in the PEI stage to ensure that the hardware fingerprint information is shared in the system startup process.
[0059] Step 103: During the initialization of the basic input / output system, the layered driver of the hardware is completed according to the hardware description file; wherein the layered driver includes a general driver layer, a platform adaptation layer and a hardware abstraction layer.
[0060] It can be understood that this embodiment adopts a modular driver layered architecture, which divides the hardware driver into three layers, namely the general driver layer, the platform adaptation layer and the hardware abstraction layer; through the three-layered driver, the hardware driver of the CPU architecture of different platforms is realized, so that the BIOS can adapt and be compatible with the CPU architecture of different platforms, thereby solving the following problems faced in the related technology when developing CPU BIOS of different architectures: ① Instruction set fragmentation causes differences in startup protocols, such as the need to implement underlying logic such as mode initialization and exception vector table configuration separately; ② The complexity of hardware abstraction layer reconstruction is doubled, and there are architectural-level differences in the power state machines and memory training algorithms of different CPUs.
[0061] Among them, the universal driver layer in this embodiment can be used to implement drivers of general functions that are independent of the CPU architecture based on UEFI (Unified Extensible Firmware Interface) standard protocols, such as PCI, USB (Universal Serial Bus) and SATA (Serial Advanced Technology Attachment, a hard disk interface bus); the platform adaptation layer can be used to provide instruction set conversion and memory management adaptation for different CPU architectures; the hardware abstraction layer (HAL) can be used to isolate specific hardware differences (such as TPCM chips) and load the required platform-specific drivers through the dynamic link library (DLL).
[0062] Correspondingly, this step may include: loading the driver of the general function (such as Figure 3UEFI standard driver in the target processor platform); wherein the common functions include at least one of PCI initialization function (or PCIe initialization function), USB initialization function and SATA initialization function; through the platform adaptation layer, converting the preset instruction set and preset memory management policy into the instruction set and memory management policy of the target processor platform; through the hardware abstraction layer, loading the proprietary driver of the target processor platform through the dynamic link library.
[0063] For example, the universal driver layer can achieve unified support for heterogeneous hardware platforms through three core mechanisms: protocol standardization, asynchronous loading optimization, and security enhancement. It is mainly based on UEFI standard protocols (such as PCI, USB, SATA, and ACPI), and achieves architecture independence by abstracting common hardware features. Its core design may include modules and their functions, such as: PCI or PCIe initialization module, used to complete device enumeration and resource configuration, and realize PCI or PCIe initialization function; USB initialization module, used to complete main control initialization and device enumeration, and realize USB initialization function; SATA or AHCI (Advanced Host Controller Interface) initialization module, used to complete disk identification and data transmission, and realize SATA or AHCI initialization function; ACPI (Advanced Configuration and Power Management Interface) initialization module, used to complete power management and thermal control, and realize ACPI initialization function.
[0064] Correspondingly, the platform adaptation layer can serve as a bridge connecting universal drivers and hardware differences. It is necessary to implement instruction set conversion and memory management adaptation for different domestic CPU architectures. Its core modules may include: instruction set conversion module: a pre-designed converter is used to handle the convention differences of CPU calls of different architectures, and then key conversion functions are used to convert them into unified architecture instructions to convert the preset instruction set into the instruction set of the target processor platform, such as GDT (global descriptor table) → TTB (Thread Building Blocks) conversion or NEON (a single instruction multiple data instruction set) → LSX (an encoding instruction) instruction mapping; memory management adaptation module: through the four core mechanisms of address mapping unification, cache policy abstraction, permission model conversion and memory barrier standardization, the preset memory management policy is converted into the memory management policy of the target processor platform to achieve cross-architecture compatibility.
[0065] Accordingly, the Hardware Abstraction Layer (HAL) can be used to isolate specific hardware differences and load proprietary drivers for the target processor platform on demand through a dynamic link library (DLL). The hardware abstraction layer can adopt a layered design, including: a core framework layer, which provides basic service interfaces and defines standardized hardware-independent interfaces (such as memory management, interrupt control, and security services), ensuring that upper-layer applications do not need to be aware of underlying hardware differences; a platform abstraction layer, which isolates specific hardware differences (such as TPCM chips and CPU instruction sets) and loads platform-specific drivers on demand through a dynamic link library; and a driver service layer, which implements specific hardware operation logic, such as hot plugging and online updates.
[0066] Furthermore, to achieve compatibility between security verification systems for different CPU architectures, this embodiment can also include a secure and trusted verification module within the BIOS. This module can leverage a pre-built, configurable security policy engine to define multi-standard verification processes using a policy description language, centrally managing verification processes such as UEFI Secure Boot, encryption algorithms, and trusted roots (e.g., TPCM chips) to implement module signature verification and malicious code defense before driver loading. That is, before completing the hardware layered driver based on the hardware description file in step 103, the process can also include: performing secure and trusted verification of the target processor platform on the driver to be loaded using a pre-configured security policy engine; wherein the secure and trusted verification includes at least one of secure boot verification, encryption algorithm verification, and trusted root verification for the unified extensible firmware interface.
[0067] Among them, the specific settings of the above-mentioned security and trustworthy verification module, that is, the specific process of performing security and trustworthy verification corresponding to the target processor platform on the loaded driver through the preset configurable security policy engine, can be set by the designer according to practical scenarios and user needs. For example, the security and trustworthy verification module may include: an encryption algorithm compatibility submodule and a standardized interface encapsulation submodule, which are used to achieve compatible verification of multiple certificate chains; for example, the encryption algorithm compatibility submodule can be used to define unified verification rules through the "policy description language", supporting international encryption algorithms such as international RSA (an asymmetric encryption algorithm) and international ECC (elliptic curve encryption algorithm), national encryption algorithms of the national secret SM series (such as SM2, SM3 and SM4, etc.) and autonomous encryption algorithms. Hybrid verification logic; the standardized interface encapsulation submodule can be used to abstract the firmware verification process of UEFI Secure Boot and the hardware trusted root measurement logic of the TPCM chip into a common interface to adapt to hardware environments with different security standards.
[0068] Correspondingly, the security and trusted verification module can also include a dynamic certificate chain loading submodule and a policy-driven verification submodule to achieve compatibility of hybrid certificate chains; for example, the dynamic certificate chain loading submodule can be used to support parallel verification of international CA (Certification Authority), national secret CA and private CA certificate chains, and automatically select the optimal verification path through the certificate chain priority arbitration algorithm; the policy-driven verification submodule can be used to dynamically match the verification rules of the certificate chain according to hardware characteristics (such as the above-mentioned hardware fingerprint information) to avoid the risk of manufacturer lock-in.
[0069] Correspondingly, the security and trusted verification module can also include a national secret algorithm hardware acceleration sub-module and a parallel processing sub-module to implement an encryption service engine; for example, the national secret algorithm hardware acceleration sub-module can be used to implement hardware acceleration of the national secret encryption algorithm using the TPCM chip through the cryptographic service interface of the TPCM chip (such as SM2 key generation and SM3 hash calculation, etc.); the parallel processing sub-module can be used to split the national secret algorithm tasks to the corresponding CPU core for processing, and use the multi-core CPU architecture to reduce the load pressure on the single core.
[0070] In addition, the security and trust verification module can also include a measurement unification submodule and a dynamic policy synchronization submodule to achieve the adaptation of the Trusted Execution Environment (TEE) and the mutual recognition of measurements across TEEs. For example, the measurement unification submodule can be used to utilize the defined cross-TEE measurement protocol to convert the measurement results of different TEEs through the "security intermediary layer"; the dynamic policy synchronization submodule can be used to automatically synchronize security policies between TEEs based on hardware fingerprint information (such as CPU microcode version) to ensure the consistency of heterogeneous security domains.
[0071] For example, if Figure 4 As shown, the process of performing security and trustworthy verification of the target processor platform corresponding to the driver to be loaded by presetting a configurable security policy engine may include: verifying the certificate of the driver to be loaded (such as Figure 4 TPCM certificate verification in the ), obtain the certificate verification result; if the certificate verification result is verified, use the target encryption algorithm corresponding to the target processor platform (such as Figure 4 SM2 national secret algorithm in the to-be-loaded driver), perform signature verification on the to-be-loaded driver, and obtain the signature verification result; if the signature verification result is verification passed, that is, the signature is in the driver module whitelist, then when the to-be-loaded driver is in a trusted execution environment, obtain the measurement result corresponding to the to-be-loaded driver and generate the corresponding audit log, such as Figure 4As shown, the Trustzone can be initialized, the measurement results of the measurement kernel can be stored in the PCR (Platform Configuration Register), an audit log can be generated, and the operating system (OS) can be entered; if the signature verification result is verification failure, the driver to be loaded can be started in standard mode.
[0072] Furthermore, in this embodiment, the dynamic hardware detection mechanism can also be applied to the dynamic resource scheduling process of the server cluster. For example, when the method provided in this embodiment is applied to the controlled nodes in the server cluster, it can also include detecting and collecting hardware fingerprint information in the same or similar manner as step 101 according to the hardware detection instruction sent by the master control node, and sending the collected hardware fingerprint information (or the corresponding hardware description file) to the master control node, so that the master control node can perform resource scheduling according to the hardware fingerprint information returned by each controlled node, thereby realizing dynamic allocation and load balancing of computing or storage resources.
[0073] In this embodiment, the embodiment of the present invention generates an HDF file based on the embedded probe during the BIOS startup process to achieve automatic identification and matching of multi-architecture parameters; thereby utilizing the hardware description file during the BIOS initialization process to complete the layered drive of the hardware, enabling the BIOS to adapt and be compatible with the CPU architectures of different platforms, thereby improving the BIOS's adaptability and compatibility and code reuse rate, thereby shortening the adaptation cycle and verification cycle of different platform CPU architectures.
[0074] Corresponding to the above method embodiment, an embodiment of the present invention further provides a hardware driving device for a basic input / output system. The hardware driving device for a basic input / output system described below and the hardware driving method for a basic input / output system described above can refer to each other.
[0075] Please refer to Figure 5 , Figure 5 This is a block diagram of a hardware driver for a basic input / output system provided by an embodiment of the present invention. The device may include:
[0076] The probe detection module 10 is used to detect and collect hardware fingerprint information during the startup process of the basic input and output system; wherein the hardware fingerprint information includes central processing unit architecture information, memory information and peripheral interface information;
[0077] The file generation module 20 is used to generate a hardware description file of a target processor platform according to the hardware fingerprint information; wherein the target processor platform is any preset central processing unit architecture platform;
[0078] The modular driver module 30 is used to complete the hierarchical driver of the hardware according to the hardware description file during the initialization process of the basic input and output system; wherein the hierarchical driver includes a general driver layer, a platform adaptation layer and a hardware abstraction layer.
[0079] In another aspect, the probe detection module 10 may include:
[0080] The instruction set probe submodule is used to read the central processing unit identification register to obtain the central processing unit architecture information; wherein the central processing unit architecture information includes the component number in the central processing unit identification register;
[0081] A memory controller scanning submodule, configured to parse memory serial presence detection data and obtain memory information; wherein the memory information includes at least one of memory type information, capacity information, speed information, voltage information, timing information, and manufacturer information;
[0082] The peripheral topology detection submodule is used to scan the peripheral bus, peripheral devices and peripheral functions step by step to obtain device tree structure information; wherein the peripheral interface information includes device tree structure information.
[0083] On the other hand, the startup process is a security phase or an initialization phase, and the initialization process is a phase for executing a driver environment.
[0084] In another aspect, the file generation module 20 may include:
[0085] A feature matching submodule is used to determine whether the hardware fingerprint information matches the preset device features of any preset CPU architecture platform;
[0086] The generation submodule is used to use the matched preset central processing unit architecture platform as the target processor platform if a match is found, and generate a hardware description file corresponding to the hardware fingerprint information.
[0087] In another aspect, the apparatus may further comprise:
[0088] A storage module, used for encrypting and storing the hardware description file in a security chip;
[0089] The transfer module is used to transfer the hardware description file to the initialization process through the switch block mechanism of the initialization phase of the basic input and output system.
[0090] In another aspect, the modular drive module 30 may include:
[0091] A general loading submodule, configured to load a driver for a general function through a general driver layer based on the Unified Extensible Firmware Interface standard protocol; wherein the general function includes at least one of a peripheral component interconnect standard initialization function, a universal serial bus initialization function, and a hard disk interface bus initialization function;
[0092] The platform adaptation submodule is used to convert the preset instruction set and the preset memory management policy into the instruction set and the memory management policy of the target processor platform through the platform adaptation layer;
[0093] The hardware abstraction submodule is used to load the proprietary driver of the target processor platform through the hardware abstraction layer and the dynamic link library.
[0094] In another aspect, the apparatus may further comprise:
[0095] A security and trustworthiness verification module is used to perform security and trustworthiness verification on the target processor platform for the loaded driver through a preset configurable security policy engine; wherein, the security and trustworthiness verification includes at least one of the secure boot verification, encryption algorithm verification and trusted root verification of the unified extensible firmware interface.
[0096] In another aspect, the secure and trusted verification module may include:
[0097] The certificate verification submodule is used to verify the certificate of the driver to be loaded and obtain the certificate verification result;
[0098] The signature verification submodule is used to perform signature verification on the driver to be loaded using the target encryption algorithm corresponding to the target processor platform if the certificate verification result is verification passed, and obtain the signature verification result;
[0099] The measurement submodule is used to obtain the measurement result corresponding to the driver to be loaded and generate a corresponding audit log if the signature verification result is passed and the driver to be loaded is in a trusted execution environment.
[0100] In this embodiment, the embodiment of the present invention generates an HDF file based on the embedded probe during the BIOS startup process to achieve automatic identification and matching of multi-architecture parameters; thereby utilizing the hardware description file during the BIOS initialization process to complete the layered drive of the hardware, enabling the BIOS to adapt and be compatible with the CPU architectures of different platforms, thereby improving the BIOS's adaptability and compatibility and code reuse rate, thereby shortening the adaptation cycle and verification cycle of different platform CPU architectures.
[0101] Corresponding to the above method embodiment, an embodiment of the present invention further provides a computer program product. The computer program product described below and the hardware driving method of a basic input and output system described above can refer to each other.
[0102] A computer program product (such as BIOS) includes a computer program / instruction, which, when executed by a processor, implements the steps of the hardware driving method of the basic input and output system provided by the above method embodiment.
[0103] Corresponding to the above method embodiment, an embodiment of the present invention further provides a computer-readable storage medium. The computer-readable storage medium described below and the hardware driving method of a basic input / output system described above can refer to each other.
[0104] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the hardware driving method for a basic input / output system provided in the above method embodiment.
[0105] Corresponding to the above method embodiment, an embodiment of the present invention further provides a hardware driver device for a basic input / output system. The hardware driver device for a basic input / output system described below and the hardware driver method for a basic input / output system described above can refer to each other.
[0106] Please refer to Figure 6 , Figure 6 This is a schematic diagram of the structure of a hardware driver device for a basic input / output system provided by an embodiment of the present invention. The device may include:
[0107] Memory D1, for storing computer programs;
[0108] The processor D2 is configured to implement the steps of the basic input / output system hardware driving method provided by the above method embodiment when executing a computer program.
[0109] The device provided in this embodiment may specifically be a server.
[0110] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. References to the common and similar parts between the various embodiments are sufficient. The devices, apparatuses, computer program products, and computer-readable storage media disclosed in the embodiments are described briefly because they correspond to the methods disclosed in the embodiments. For relevant details, refer to the description of the methods.
[0111] The above describes in detail the hardware driver method, device, and apparatus for a basic input / output system provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is intended only to help understand the method and core concept of the present invention. It should be noted that, for those skilled in the art, various improvements and modifications may be made to the present invention without departing from the principles of the present invention, and such improvements and modifications also fall within the scope of protection of the present invention.
Claims
1. A hardware driving method for a basic input / output system, characterized in that: include: During the startup of the basic input and output system, hardware fingerprint information is detected and collected; wherein the hardware fingerprint information includes central processing unit architecture information, memory information and peripheral interface information; Generate a hardware description file of a target processor platform according to the hardware fingerprint information; wherein the target processor platform is any preset central processing unit architecture platform; During the initialization process of the basic input and output system, the layered driver of the hardware is completed according to the hardware description file; wherein the layered driver includes a general driver layer, a platform adaptation layer and a hardware abstraction layer.
2. The hardware driving method of the basic input and output system according to claim 1, characterized in that: Detect and collect hardware fingerprint information, including: Reading a central processing unit identification register to obtain the central processing unit architecture information; wherein the central processing unit architecture information includes a component number in the central processing unit identification register; Parsing memory serial presence detection data to obtain the memory information; wherein the memory information includes at least one of memory type information, capacity information, speed information, voltage information, timing information, and manufacturer information; Scan the peripheral bus, peripheral devices and peripheral functions level by level to obtain device tree structure information; wherein the peripheral interface information includes the device tree structure information.
3. The hardware driving method of the basic input and output system according to claim 1, characterized in that: The startup process is a security phase or an initialization phase, and the initialization process is an execution drive environment phase.
4. The hardware driving method of the basic input and output system according to claim 1, characterized in that: Generate a hardware description file for the target processor platform based on the hardware fingerprint information, including: Determining whether the hardware fingerprint information matches any preset device feature of the preset central processing unit architecture platform; If so, the matched preset central processing unit architecture platform is used as the target processor platform, and a hardware description file corresponding to the hardware fingerprint information is generated.
5. The hardware driving method of the basic input and output system according to claim 1, characterized in that: After generating a hardware description file of the target processor platform according to the hardware fingerprint information, the method further includes: Encrypting and storing the hardware description file in a security chip; The hardware description file is transferred to the initialization process through the switch block mechanism of the initialization phase of the basic input and output system.
6. The hardware driving method of the basic input and output system according to claim 1, characterized in that: According to the hardware description file, the hardware layer driver is completed, including: Loading a driver for a general function through the general driver layer based on the UEFI standard protocol; wherein the general function includes at least one of a peripheral component interconnect standard initialization function, a universal serial bus initialization function, and a hard disk interface bus initialization function; Converting the preset instruction set and the preset memory management policy into the instruction set and the memory management policy of the target processor platform through the platform adaptation layer; The proprietary driver of the target processor platform is loaded through the hardware abstraction layer and a dynamic link library.
7. The hardware driving method of a basic input / output system according to any one of claims 1 to 6, characterized in that: Before completing the layered driver of the hardware according to the hardware description file, the following steps are also included: Through a preset configurable security policy engine, the loaded driver is subjected to security and trustworthiness verification corresponding to the target processor platform; wherein, the security and trustworthiness verification includes at least one of secure boot verification of the unified extensible firmware interface, encryption algorithm verification and trusted root verification.
8. The hardware driving method of the basic input and output system according to claim 7, characterized in that: Through a preset configurable security policy engine, the driver to be loaded is subjected to security and trustworthiness verification corresponding to the target processor platform, including: Performing certificate verification on the driver to be loaded and obtaining a certificate verification result; If the certificate verification result is passed, use the target encryption algorithm corresponding to the target processor platform to perform signature verification on the driver to be loaded and obtain the signature verification result; If the signature verification result is verification passed, when the driver to be loaded is in a trusted execution environment, a measurement result corresponding to the driver to be loaded is obtained and a corresponding audit log is generated.
9. A hardware driver for a basic input / output system, characterized in that: include: A probe detection module is used to detect and collect hardware fingerprint information during the startup process of the basic input and output system; wherein the hardware fingerprint information includes central processing unit architecture information, memory information and peripheral interface information; A file generation module, configured to generate a hardware description file of a target processor platform based on the hardware fingerprint information; wherein the target processor platform is any preset central processing unit architecture platform; The modular driver module is used to complete the hierarchical driver of the hardware according to the hardware description file during the initialization process of the basic input and output system; wherein the hierarchical driver includes a general driver layer, a platform adaptation layer and a hardware abstraction layer.
10. A hardware driver for a basic input / output system, characterized in that: include: memory for storing computer programs; A processor is configured to implement the steps of the hardware driving method of a basic input / output system as claimed in any one of claims 1 to 8 when executing the computer program.
Citation Information
Patent Citations
Method of device driver management
CN107015807A
Software and hardware adaptation method and device, equipment and storage medium
CN120045233A
System and method for accelerated device initialization
US20050038981A1