Basic input and output system configuration method

By using flash memory to store BIOS configuration data and public keys in the computer, and using secure boot methods to verify the operating system image file, the problem of complexity and information leakage in BIOS configuration of different computers is solved, thus achieving security and simplification of BIOS configuration.

CN121326418APending Publication Date: 2026-01-13MITAC COMP (SHUN DE) LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410935179.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-07-12
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

In the existing technology, computer manufacturers need to configure different BIOSes for different computers, which makes the production process complex and prone to errors, and the information in the BIOS is easily leaked during the switching process.

Method used

By storing BIOS configuration data and public keys in flash memory on the computer to be configured, and using a secure boot method to verify the operating system image file, BIOS configuration is only performed after successful verification, ensuring that only legitimate manufacturers can update the BIOS configuration data.

Benefits of technology

It effectively protects BIOS information from being stolen or unintentionally leaked, simplifies the BIOS configuration process, and improves production security and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121326418A_ABST
    Figure CN121326418A_ABST
Patent Text Reader

Abstract

The invention discloses a basic input / output system configuration method. A computer to be configured is used for executing the following steps: obtaining a product number of the computer to be configured; judging whether the to-be-configured computer product serial number is consistent with a to-be-compared computer product serial number or not; if not, updating a product number change mark into a to-be-changed mark; verifying an operating system image file to be verified by using a secure boot method; when the operating system image file is successfully verified, judging whether the product number change mark is the mark to be changed or not; when it is judged that the to-be-changed mark is not the to-be-changed mark, updating the to-be-compared computer product number with the to-be-configured computer product number; and configuring the basic input / output system of the computer to be configured according to the basic input / output system configuration data corresponding to the computer to be configured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a system configuration method, and more particularly to a basic input output system configuration method. BACKGROUND

[0002] In the past, different computers produced by different computer manufacturers mostly need to establish a dedicated basic input output system (BIOS, hereinafter referred to as BIOS). This makes the motherboard manufacturer have to configure different BIOS for different computer motherboards when producing the motherboard, resulting in complex production process and prone to errors.

[0003] However, since the single BIOS that can support multiple computer configurations often stores relevant information of different computer manufacturers (such as logo, computer manufacturer name, computer product name, customized BIOS function, etc.), these information may be leaked due to human error or intentional operation during the process of switching the BIOS to adapt to different products.

[0004] Therefore, how to protect the relevant information of the computer manufacturers involved when using a single BIOS that adapts to multiple computer configurations has become one of the issues that the relevant technical field wants to solve. SUMMARY

[0005] Therefore, the purpose of the present application is to provide a basic input output system configuration method that can overcome at least one disadvantage of the prior art.

[0006] Therefore, a basic input / output system configuration method is provided. The method is performed by a computer to be configured. The computer to be configured includes a processor and a flash memory connected to the processor. The flash memory stores a basic input / output system, a plurality of basic input / output system configuration data respectively corresponding to a plurality of computer product numbers, and a plurality of public keys respectively corresponding to the computer product numbers. The basic input / output system configuration method includes the following steps: (A) obtaining a computer product number to be configured corresponding to the computer to be configured; (B) determining whether the computer product number to be configured is consistent with a computer product number to be compared; (C) when it is determined that the computer product number to be configured is not consistent with the computer product number to be compared, updating a product number change marker to a desired change marker; (D) obtaining, from the flash memory, a public key corresponding to the computer product number to be compared according to the computer product number to be configured; (E) obtaining an operating system image file to be verified, the operating system image file including a private key; (F) verifying the operating system image file by a secure boot method according to the public key and the private key; (G) when the operating system image file is successfully verified, determining whether the product number change marker is the desired change marker; (H) when it is determined that the product number change marker is the desired change marker, updating the computer product number to be compared to the computer product number to be configured; (I) obtaining basic input / output system configuration data corresponding to the computer product number to be configured from the flash memory; and (J) configuring the basic input / output system by the basic input / output system configuration data obtained in step (I).

[0007] In particular, between step (C) and step (D), the method further includes the following step: (K) disabling a hot key function of the basic input / output system and stopping displaying any manufacturer information that can be used to identify any computer manufacturer.

[0008] In particular, after step (B), the method further includes the following step: (L) when it is determined that the computer product number to be configured is consistent with the computer product number to be compared, the method proceeds to step (D).

[0009] In particular, before step (A), the method further includes the following steps: (M) determining whether the flash memory stores the computer product number to be compared; and (N) when it is determined that the flash memory stores the computer product number to be compared, obtaining the computer product number to be compared from the flash memory.

[0010] In particular, the computer to be configured further comprises a field replaceable unit connected to the processor, and after step (N), the method further comprises the following steps: (O) determining whether the field replaceable unit stores the product number of the computer to be configured; (P) when it is determined that the field replaceable unit stores the product number of the computer to be configured, the process proceeds to step (A); and (Q) when it is determined that the field replaceable unit does not store the product number of the computer to be configured, the process proceeds to step (D) with the product number of the computer to be compared as the product number of the computer to be configured.

[0011] In particular, in step (A), the computer to be configured obtains the product number of the computer to be configured from the field replaceable unit.

[0012] In particular, the computer to be configured further comprises a field replaceable unit connected to the processor, and after step (M), the method further comprises the following steps: (R) when it is determined that the flash memory does not store the product number of the computer to be compared, determining whether the field replaceable unit stores the product number of the computer to be configured; (S) when it is determined that the field replaceable unit stores the product number of the computer to be configured, updating the product number change marker to the desired change marker; and (T) the process proceeds to step (D).

[0013] In particular, between steps (S) and (T), the method further comprises the following steps: (U) deactivating the hot key function of the basic input / output system and stopping the display of any vendor information that can be used to identify any computer manufacturer.

[0014] Compared with the prior art, the basic input / output system configuration method of the present application has the following advantages. Since only the computer manufacturer of the computer to be configured or a few authorized manufacturers have the operating system image file corresponding to the computer to be configured, only when the operating system image file to be verified is verified by the public key corresponding to the computer to be configured, it can be determined that the operator holding the operating system image file belongs to the manufacturer corresponding to the computer to be configured, and the computer to be configured can be reconfigured with the basic input / output system configuration data corresponding to the computer to be configured, thereby avoiding the information stored in the BIOS of the computer to be configured from being stolen or inadvertently disclosed by malicious persons. BRIEF DESCRIPTION OF DRAWINGS

[0015] Other features and effects of the present application will be clearly presented in the embodiments with reference to the accompanying drawings.

[0016] Figure 1 FIG. 1 is a block diagram illustrating a computer to be configured used in a basic input / output system configuration method according to an embodiment of the present application;

[0017] Figure 2Fig. 1 is a flowchart illustrating an exemplary pre-process portion of the BIOS configuration method performed by a processor of a computer to be configured according to an embodiment of the present application;

[0018] Figure 3 Fig. 2 is a flowchart illustrating an exemplary configuration portion of the BIOS configuration method performed by the processor of the computer to be configured according to the embodiment of the present application. DETAILED DESCRIPTION

[0019] Before the present application is described in detail, it is to be understood that like elements are denoted by like numerals throughout the description.

[0020] Referring to Figure 1 A BIOS configuration method according to an embodiment of the present application is performed by a computer to be configured 1. The computer to be configured 1 includes a flash memory 11, a field replace unit 12, and a processor 13 connected to the flash memory 11 and the field replace unit 12.

[0021] The flash memory 11 stores a BIOS, a plurality of BIOS configuration data respectively corresponding to a plurality of stock keeping units (SKUs), and a plurality of public keys respectively corresponding to the SKUs, and is used to store a SKU to be matched. The flash memory 11 is, for example, a non-volatile random-access memory (NVRAM).

[0022] The field replace unit 12 is used to store a SKU to be configured corresponding to the computer to be configured 1.

[0023] The operation of the processor 13 will be described in detail below.

[0024] Referring to Figure 2 and Figure 3 Fig. 1 is a flowchart illustrating an exemplary pre-process portion of the BIOS configuration method performed by a processor of a computer to be configured according to an embodiment of the present application;

[0025] In step S21, the processor 13 determines whether the flash memory 11 stores the SKU to be matched. When it is determined that the flash memory 11 stores the SKU to be matched, the process proceeds to step S22; otherwise, the process proceeds to step S25.

[0026] It is worth mentioning that this step is needed because the basic input / output system of the computer to be configured 1 is in a general mode set by the motherboard manufacturer when the basic input / output system has not been configured. In the general mode, no computer product number to be compared is stored in the flash memory 11, or only a preset number value is stored. Only when the basic input / output system of the computer to be configured 1 has been configured, the computer product number to be compared different from the preset number value is stored. Therefore, by this step, it can be identified whether the basic input / output system is in the general mode or in a customized configuration mode corresponding to the computer product number to be compared.

[0027] In step S22, the processor 13 obtains the computer product number to be compared from the flash memory 11.

[0028] In step S23, the processor 13 determines whether the field replacement unit 12 stores the computer product number to be configured. When it is determined that the field replacement unit 12 stores the computer product number to be configured, the flow proceeds to step S24; otherwise, the flow proceeds to step S27.

[0029] It is worth mentioning that because the field replacement unit 12 sometimes has a problem such as a format error of the computer product number to be configured written in advance, only when the computer product number to be configured exists and is correctly formatted, the processor 13 determines that the field replacement unit 12 stores the computer product number to be configured, otherwise, if the field replacement unit 12 does not store the computer product number to be configured or the computer product number to be configured stored in the field replacement unit 12 is incorrectly formatted, the processor 13 determines that the field replacement unit 12 does not store the computer product number to be configured.

[0030] In step S24, the processor 13 obtains the computer product number to be configured corresponding to the computer to be configured 1 from the field replacement unit 12. At this time, the computer product number to be configured and the computer product number to be compared are obtained, and the flow enters the configuration flow part and proceeds to step S301.

[0031] In step S25, the processor 13 determines whether the field replacement unit 12 stores the computer product number to be configured. When it is determined that the field replacement unit 12 stores the computer product number to be configured, the flow proceeds to step S302; otherwise, the flow proceeds to step S26.

[0032] In step S26, the processor 13 generates a request failure message indicating that the request for the computer to be configured 1 number failed. Afterwards, the operator can exit the process, for example, by pressing any key, or return to step S25 for re-evaluation after correcting the computer to be configured product number in the field replacement unit 12 (not shown).

[0033] In step S27, the processor 13 uses the computer product number to be compared as the computer product number to be configured, and the subsequent process begins from step S304.

[0034] In step S301, the processor 13 determines whether the product number of the computer to be configured matches the product number of the computer to be compared. If it is determined that the product number of the computer to be configured matches the product number of the computer to be compared, the process proceeds to step S304; otherwise, the process proceeds to step S302.

[0035] In step S302, a product number change flag corresponding to the computer product number to be compared is updated to a change flag. This step is used to indicate that the computer product number to be configured is different from the computer product number to be compared, to indicate that the computer product number to be compared is in a state that needs to be updated, and that the computer product number to be compared will be replaced by the computer product number to be configured in the future.

[0036] In step S303, the processor 13 selectively disables the hotkey function of the basic input / output system (PIS) based on the product number change mark, and selectively stops displaying any manufacturer information that can identify any computer manufacturer. This step ensures that the operator can correctly operate the PIS and that the PIS can be operated safely by a qualified operator. Therefore, when the product number change mark is a preset change mark, it indicates successful verification, and the processor 13 is in a state where it can display manufacturer information. Conversely, when the product number change mark is the desired change mark, it indicates failed verification. In this case, the processor 13 disables the hotkey function of the PIS based on the desired change mark and stops displaying any manufacturer information that can identify any computer manufacturer. This ensures that the operator cannot operate the PIS or see any manufacturer information before successful verification, preventing the leakage of manufacturer information.

[0037] In step S304, the processor 13 obtains from the flash memory 11 the public key corresponding to the computer product number to be compared, which is the same as the computer product number to be configured.

[0038] In step S305, an operating system image file (OS image) to be verified is obtained. This operating system image file contains a private key. This operating system image file is, for example, input by an operator to the computer 1 to be configured via a Universal Serial Bus (USB).

[0039] In step S306, the processor 13 verifies the operating system image file using the Secure Boot method based on the public key and the private key. If the operating system image file is successfully verified, the process proceeds to step S307; if the operating system image file fails to be verified, the process proceeds to step S311.

[0040] It is worth noting that the secure boot method primarily utilizes a digital signature mechanism to identify the trustworthiness of the operating system. Previously, this signature was used to verify whether the operating system could be used to boot the computer. However, in this step, it is applied to determine whether the operator attempting to customize the Basic Input / Output System (BIOS) with the configuration data corresponding to the computer to be configured (e.g., verifying whether the operator belongs to the computer manufacturer of the computer to be configured (1) or one of the few authorized manufacturers). This is because only the computer manufacturer of the computer to be configured (1) or one of the few authorized manufacturers possesses the operating system image file corresponding to the computer to be configured (1), and only the operating system image file corresponding to the computer to be configured (1) can be verified using the public key corresponding to the computer to be configured (1) in the secure boot method. Therefore, if the operating system image file is verified, it means that the operator who inputs the operating system image file is qualified; conversely, if the operating system image file fails to be verified, it means that the operator who inputs the operating system image file is not qualified. This step applies the existing and mature technology of Secure Boot to a new purpose, reducing the time spent developing new verification methods, and enhancing its versatility in practical applications since most computers have Secure Boot built-in.

[0041] In step S307, the processor 13 determines whether the product number change mark is the mark to be changed. When it is determined that the product number change mark is the mark to be changed, that is, when the product number change mark matches the mark to be changed, the process proceeds to step S308; when it is determined that the product number change mark is not the mark to be changed, the processor 13 proceeds to the subsequent power-on process.

[0042] In step S308, the processor 13 updates the comparison computer product number with the configuration computer product number. More specifically, the comparison computer product number stored in the flash memory 11 is replaced with the configuration computer product number.

[0043] In step S309, the processor 13 obtains basic input / output system configuration data from the flash memory 11, which corresponds to the computer product number and is the same as the computer product number to be configured.

[0044] In step S310, the processor 13 configures the basic input / output system (PIS) using the PIS configuration data obtained in step S309. This step successfully customizes the PIS and allows the processor 13 to continue with the subsequent boot process.

[0045] In step S311, the processor 13 generates a verification failure message indicating that the operating system image file has failed to be verified. Afterwards, the operator can exit the process by pressing any key, or enter another operating system image file to return to step S306 for re-verification (not shown).

[0046] In summary, firstly, by disabling the hotkey function of the Basic Input / Output System (BIOS) and stopping the display of any vendor information before the operator is verified, vendor information is initially protected. Secondly, since only the computer manufacturer of the computer to be configured (1) or a few authorized vendors possess the operating system image file corresponding to the computer to be configured (1), only when the operating system image file to be verified is authenticated using the public key corresponding to the computer to be configured (1) can it be considered that the operator holding the operating system image file belongs to the corresponding vendor of the computer to be configured (1). Only then will the computer to be configured (1) reconfigure the BIOS with the BIOS configuration data corresponding to the computer to be configured (1), thus preventing the information stored in the BIOS by the computer manufacturer of the computer to be configured (1) from being stolen by malicious individuals or unintentionally leaked. Therefore, the purpose of this invention is indeed achieved.

[0047] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for configuring a Basic Input / Output System (BIOS), executed using a computer to be configured, the computer comprising a processor and a flash memory connected to the processor, the flash memory storing a BIOS, multiple BIOS configuration data corresponding to multiple computer product numbers, and multiple public keys corresponding to the computer product numbers, characterized in that, This basic input / output system configuration method includes the following steps: (A) Obtain a product number of the computer to be configured that corresponds to the computer to be configured; (B) Determine whether the product number of the computer to be configured matches the product number of a computer to be compared; (C) When it is determined that the product number of the computer to be configured does not match the product number of the computer to be compared, update a product number change mark to a mark to be changed; (D) Based on the product number of the computer to be configured, obtain the public key corresponding to the product number of the computer to be compared, which is the same as the product number of the computer to be configured, from the flash memory; (E) Obtain an operating system image file to be verified, which contains a private key; (F) Verify the operating system image file using the secure boot method based on the public key and the private key; (G) When the operating system image file is successfully verified, determine whether the product number change mark is the mark to be changed; (H) When it is determined that the product number change mark is the mark to be changed, the product number of the computer to be compared is updated with the product number of the computer to be configured; (I) Obtain basic input / output system configuration data from the flash memory that corresponds to the same computer product number as the computer product number to be configured; and (J) Configure the basic input / output system using the basic input / output system configuration data obtained in step (I).

2. The basic input / output system configuration method according to claim 1, characterized in that, Between step (C) and step (D) are the following steps: (K) Disable the hotkey function of the basic input / output system and stop displaying any manufacturer information that can be used to identify any computer manufacturer.

3. The basic input / output system configuration method according to claim 1, characterized in that, The following steps are included after step (B): (L) When it is determined that the product number of the computer to be configured matches the product number of the computer to be compared, the process proceeds to step (D).

4. The basic input / output system configuration method according to claim 1, characterized in that, The following steps are included prior to step (A): (M) Determine whether the flash memory stores the product number of the computer to be compared; and (N) When it is determined that the flash memory stores the product number of the computer to be compared, the product number of the computer to be compared is obtained from the flash memory.

5. The basic input / output system configuration method according to claim 4, characterized in that, The computer to be configured also includes a field replacement unit connected to the processor, and after step (N) further includes the following steps: (O) Determine whether the field replacement unit stores the product number of the computer to be configured; (P) When it is determined that the field replacement unit stores the product number of the computer to be configured, the process proceeds to step (A); and (Q) When it is determined that the field replacement unit does not store the product number of the computer to be configured, the product number of the computer to be compared is used as the product number of the computer to be configured, and the process proceeds to step (D).

6. The basic input / output system configuration method according to claim 5, characterized in that, In step (A), the computer to be configured is obtained from the field replacement unit with the corresponding computer product number.

7. The basic input / output system configuration method according to claim 4, characterized in that, The computer to be configured also includes a field replacement unit connected to the processor, and the following steps are included after step (M): (R) When it is determined that the flash memory does not store the product number of the computer to be compared, determine whether the field replacement unit stores the product number of the computer to be configured. (S) When it is determined that the field replacement unit stores the product number of the computer to be configured, the product number change mark is updated to the desired change mark; and (T) The process proceeds through steps (D).

8. The basic input / output system configuration method according to claim 7, characterized in that, The following steps are also included between step (S) and step (T): (U) Disable the hotkey function of the basic input / output system and stop displaying any manufacturer information that can be used to identify any computer manufacturer.