Data processing methods and electronic devices for implementing trusted platform module functions
By dividing the baseboard management controller into secure and non-secure execution environments, establishing sessions, and utilizing the secure execution environment to process data, the issues of low compatibility and security of trusted platform modules are resolved, thereby improving the compatibility and security of the server.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-26
- Publication Date
- 2026-04-03
AI Technical Summary
In existing technologies, trusted platform modules suffer from low compatibility and security issues. Independent modules increase motherboard complexity, while integrated modules rely on processor hardware resources, which means that security cannot be guaranteed when the processor is damaged.
The baseboard management controller is divided into a secure execution environment and a non-secure execution environment. By establishing a session between the processor and the non-secure execution environment, the secure execution environment is used to process the data in the communication request, thereby realizing the trusted platform module function.
This improves server compatibility and security, avoiding the compatibility and security issues caused by the trusted platform module's reliance on the processor.
Smart Images

Figure CN121585469B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to a data processing method and electronic device for implementing the functions of a trusted platform module. Background Technology
[0002] As data volumes increase, the demands on servers also rise, and server security directly impacts system trustworthiness and data integrity. To ensure server security, a trusted platform module is used as a secure cryptographic processor to encrypt and decrypt data, providing hardware-level security.
[0003] Currently, in related technologies, trusted platform modules are either independent hardware physical chips or integrated trusted platform modules. However, independent trusted platform modules increase the complexity of server motherboard design and have incompatibility issues; integrated trusted platform modules rely on hardware resources provided by the processor, requiring driver adaptation design, and cannot guarantee server security when the processor fails. Therefore, trusted platform modules in these technologies suffer from low compatibility and security. Summary of the Invention
[0004] This application provides a data processing method and electronic device for implementing the functions of a trusted platform module, so as to at least solve the problems of low compatibility and security of trusted platform modules in related technologies.
[0005] This application provides a data processing method for implementing the functions of a trusted platform module, including:
[0006] In response to the power-on operation of the baseboard management controller, a root key and a derived key are created through a secure execution environment, wherein the baseboard management controller has a secure execution environment and a non-secure execution environment.
[0007] In response to the detection of a change in the reset signal, the startup firmware of the secure execution environment verification system is used to generate firmware verification results.
[0008] Based on the firmware verification results, a session is created for the processor and a non-secure execution environment, generating a secure session channel.
[0009] The communication request is received by the processor through a non-secure execution environment, wherein the communication request is sent by the processor to the non-secure execution environment through a secure session channel.
[0010] The secure execution environment receives communication requests from the insecure execution environment and processes the data in the communication requests based on the root key and the derived key to generate processed secure data.
[0011] The processed secure data is sent to the processor through an insecure execution environment to enable data processing for the Trusted Platform Module.
[0012] This application also provides a data processing apparatus for implementing the functions of a trusted platform module, including:
[0013] The first creation module is used to create a root key and a derived key in response to the power-on operation of the baseboard management controller through a secure execution environment, wherein the baseboard management controller has a secure execution environment and a non-secure execution environment.
[0014] The first generation module is used to generate firmware verification results in response to the detection of a change in the reset signal by executing the startup firmware of the secure environment verification system.
[0015] The second creation module is used to create sessions for the processor and non-secure execution environment based on the firmware verification results, and to generate secure session channels.
[0016] The first receiving module is used to receive communication requests sent by the processor through a non-secure execution environment, wherein the communication requests are sent by the processor to the non-secure execution environment through a secure session channel.
[0017] The second receiving module is used to receive communication requests sent by the non-secure execution environment through the secure execution environment, and process the data in the communication request according to the root key and the derived key to generate processed secure data.
[0018] The first sending module is used to send the processed secure data to the processor through an insecure execution environment in order to realize the data processing function of the trusted platform module.
[0019] This application also provides an electronic device, including: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of any of the above-described data processing methods for implementing the functions of a trusted platform module.
[0020] This application also provides a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, it implements the steps of any of the above-described data processing methods for implementing the functions of a trusted platform module.
[0021] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the above-described data processing methods for implementing the functions of a trusted platform module.
[0022] By dividing the baseboard management controller into a secure execution environment and a non-secure execution environment, establishing a session between the processor and the non-secure execution environment, and processing the data in the communication request using the secure execution environment according to the communication request sent by the processor, the function of the trusted platform module can be realized. Therefore, the technical problems of low compatibility and security caused by the trusted platform module's dependence on the processor in related technologies can be solved, and the compatibility and security of the server can be improved. Attached Figure Description
[0023] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a schematic diagram illustrating an application scenario of the data processing method for implementing the trusted platform module function provided in the embodiments of this application;
[0025] Figure 2 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 1 ;
[0026] Figure 3 This application provides a system framework diagram for implementing the trusted platform module functionality.
[0027] Figure 4 A schematic diagram of the architecture of the virtual trusted platform module provided in the embodiments of this application;
[0028] Figure 5 This is a schematic diagram of the architecture of TrustZone provided in an embodiment of this application;
[0029] Figure 6 A schematic diagram illustrating the secure startup of the baseboard management controller provided in an embodiment of this application;
[0030] Figure 7 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 2 ;
[0031] Figure 8 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 3 ;
[0032] Figure 9 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 4 ;
[0033] Figure 10 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 5 ;
[0034] Figure 11 This is a schematic diagram of the structure of a data processing device for implementing the trusted platform module function provided in an embodiment of this application;
[0035] Figure 12 A schematic diagram of the structure of the electronic device provided in this application. Detailed Implementation
[0036] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.
[0037] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0038] First, let me explain the terms used in this application:
[0039] Baseboard Management Controller: This is a dedicated controller used for monitoring and managing servers. Its main functions include device information management, server status monitoring and management, remote server control management, and maintenance management.
[0040] Trusted Platform Module (TPM): A Trusted Platform Module is a hardware security technology whose core function is to enhance security by securely storing encryption keys used for encryption and decryption. It ensures that the operating system and firmware are authentic and have not been tampered with.
[0041] To address the issues of low compatibility and security in trusted platform modules in related technologies, this application proposes the following technical concept: The inventors considered dividing the baseboard management controller into a secure execution environment and a non-secure execution environment. By establishing a session between the processor and the non-secure execution environment, and processing the data in the communication request using the secure execution environment based on the communication request sent by the processor, the function of the trusted platform module is realized.
[0042] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0043] The specific application environment architecture or specific hardware architecture on which the execution of the data processing method to realize the functions of the trusted platform module depends is described here.
[0044] refer to Figure 1 , Figure 1 This is a schematic diagram of an application scenario for a data processing method for implementing the functions of a trusted platform module, provided in an embodiment of this application. The application scenario includes a processor 101 and a baseboard management controller 102.
[0045] Specifically, the baseboard management controller 102 is equipped with a secure execution environment and a non-secure execution environment. After the baseboard management controller 102 is powered on, it creates a root key and a derived key. When a change in the reset signal is detected, it creates a session between the processor 101 and the non-secure execution environment based on the reset signal, generates a secure session channel, receives communication requests sent by the processor 101 through the non-secure execution environment, receives communication requests sent by the non-secure execution environment through the secure execution environment, processes the data in the communication request based on the root key and the derived key, generates processed secure data, and sends the processed secure data to the processor 101 to realize the data processing function of the trusted platform module.
[0046] Figure 2 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 1 ,like Figure 2 As shown, embodiments of this application provide a data processing method for implementing the functions of a trusted platform module. The method is described in detail below:
[0047] S201: In response to the power-on operation of the baseboard management controller, a root key and a derived key are created through a secure execution environment, wherein the baseboard management controller has a secure execution environment and a non-secure execution environment.
[0048] In this embodiment, the baseboard management controller is independent of the system and can continue to operate even when the system is powered off or malfunctions, providing out-of-band management functions.
[0049] In this embodiment, the baseboard management controller selects a chip that supports TrustZone, and selects a two-wire serial bus in the baseboard management controller bus to connect a powered erasable programmable read-only memory to store the root key.
[0050] TrustZone is a hardware security architecture built into the chip that achieves security isolation by creating two parallel and completely isolated operating environments.
[0051] In this embodiment, the write protection switch of the electrically erasable programmable read-only memory is controlled by the general purpose input / output port of the board management controller.
[0052] In this embodiment, the general-purpose input / output port controlling the write protection switch of the electrically erasable programmable read-only memory is set to be inaccessible in non-safe execution environments and is only accessible in safe execution environments.
[0053] Figure 3 This is a system framework diagram for implementing the trusted platform module function as provided in the embodiments of this application.
[0054] like Figure 3 As shown, the baseboard management controller is equipped with a non-secure execution environment and a secure execution environment. Each environment's SOC (System on Chip) is configured with a processor core and a security configuration register.
[0055] In an insecure execution environment, when the last bit of the security configuration register is 1, it indicates an insecure state. In an insecure state, the processor can only access resources in the insecure execution environment.
[0056] In the secure execution environment, when the last bit of the security configuration register is 0, it indicates a secure state. In the secure state, the processor can access resources in the secure execution environment.
[0057] Figure 4 This is a schematic diagram of the architecture of the virtual trusted platform module provided in the embodiments of this application.
[0058] like Figure 4 As shown, after the processor establishes a session with the insecure execution environment, it sends a communication request to the client application of the insecure execution environment according to the management component transport protocol. It then calls the client interface of the trusted execution environment and sends the communication request to the trusted execution environment operating system of the secure execution environment through the open-source trusted execution environment driver. In the secure execution environment, it calls the internal interface of the trusted execution environment and the hardware abstraction layer to parse the communication request and executes the functions of the trusted execution environment according to the type of communication request.
[0059] Figure 5This is a schematic diagram of the architecture of TrustZone provided in an embodiment of this application.
[0060] like Figure 5 As shown, the trusted application implements the trusted platform module function in the trusted operating system of the open-source trusted execution environment of the secure execution environment of the baseboard management controller.
[0061] In this embodiment, the functions of the trusted platform module include, but are not limited to, key generation, encryption, decryption, hash calculation, integrity measurement, and configuration registers.
[0062] In this embodiment, the protocol for communication between the processor and the baseboard management controller in the insecure execution environment is a layered communication protocol.
[0063] Among them, the layered communication protocol is a protocol that combines the intelligent management function of the management component transmission protocol with the physical connection capability of a two-wire serial bus.
[0064] In this embodiment, the processor and the baseboard management controller establish a trusted session using the Management Component Transport Protocol (MTP) to ensure that the TPM command requests sent by the processor to the baseboard management controller or the TPM responses returned by the baseboard management controller to the processor are secure.
[0065] In this embodiment, after the client application in the non-secure execution environment of the baseboard management controller receives the processor request, it communicates with the secure execution environment through the trusted execution environment client interface. After receiving the request, the TPM module of the secure execution environment processes it and sends the processing result to the non-secure execution environment.
[0066] In this embodiment, when the system is powered on, the trusted application in the secure execution environment needs to calculate the hash value of the BIOS (Basic Input Output System) firmware and compare it with the hash value stored in the flash memory of the baseboard management controller. If the comparison results are consistent, the BIOS firmware is allowed to be loaded and the power-on is performed; otherwise, a command to disallow power-on is sent to the complex programmable logic device.
[0067] Figure 6 This is a schematic diagram illustrating the secure startup of the baseboard management controller provided in an embodiment of this application.
[0068] like Figure 6 As shown, in this embodiment, after the baseboard management controller is powered on, the open-source trusted execution environment starts and initializes the hardware platform.
[0069] The hardware platform initialization operations include, but are not limited to, dividing the memory into a secure storage area and a normal storage area, and setting the one-way two-wire serial bus containing the electrically erasable programmable read-only memory (EROM) for storing the key and the general-purpose input / output interface controlling the EROM write protection switch as a secure device and secure access permissions.
[0070] Specifically, after the secure world is started, the TPM module obtains the root key from the key storage module. If the obtained value is 0xFF, it indicates that the device is starting up for the first time and the root key is generated by the random number generator.
[0071] In this embodiment, the key storage module is an electrically erasable programmable read-only memory.
[0072] Specifically, the write protection of the electrically erasable programmable read-only memory is turned off through the general-purpose input / output port, the root key is written into the electrically erasable programmable read-only memory, and the protection of the electrically erasable programmable read-only memory is turned on through the general-purpose input / output port.
[0073] S202: In response to the detection of a change in the reset signal, the firmware of the secure execution environment verification system is used to generate a firmware verification result.
[0074] Specifically, the TPM module within the secure execution environment verifies the system boot firmware BIOS, generates firmware verification results, and ensures secure system boot.
[0075] S203: Create a session for the processor and a non-secure execution environment based on the firmware verification result, and generate a secure session channel.
[0076] Specifically, when the reset signal is pulled low, the TPM module of the secure execution environment compares the hash value calculated by the BIOS firmware service with the hash value stored in the flash memory of the baseboard management controller. If the comparison results match, the BIOS firmware is allowed to be loaded and the power-on is performed; otherwise, a command is sent to the complex programmable logic device to disallow the power-on.
[0077] S204: Receive a communication request sent by the processor through a non-secure execution environment, wherein the communication request is sent by the processor to the non-secure execution environment through a secure session channel.
[0078] In this embodiment, the processor sends a communication request to the insecure execution environment through an established trusted session.
[0079] S205: Receive communication requests sent by non-secure execution environments through a secure execution environment, and process the data in the communication requests according to the root key and the derived key to generate processed secure data.
[0080] In this embodiment, communication requests include, but are not limited to, key generation requests, data encryption requests, and data decryption requests.
[0081] S206: Send the processed secure data to the processor through an insecure execution environment to realize the data processing function of the Trusted Platform Module.
[0082] In this embodiment, the insecure execution environment sends the processed secure data to the processor through a trusted session.
[0083] As can be seen from the above embodiments, by dividing the baseboard management controller into a secure execution environment and a non-secure execution environment, establishing a session between the processor and the non-secure execution environment, and processing the data in the communication request using the secure execution environment according to the communication request sent by the processor, the function of the trusted platform module is realized, thus avoiding the problems of low compatibility and security caused by the trusted platform module's dependence on the processor in related technologies.
[0084] In one embodiment of this application, step S201 includes:
[0085] S201a: Query whether key data is stored in the key storage module through the secure execution environment, and generate key query results.
[0086] Specifically, the secure execution environment queries the storage status of the key via the secure bus.
[0087] Specifically, if key data is found, the key's metadata is returned.
[0088] S201b: If no key data is found in the key query results, the root key and derived key are created in the secure execution environment based on the key query results.
[0089] Specifically, if no key data is detected in the key query results, the key creation sub-process is triggered.
[0090] S201c: The root key and derived key are sent to the key storage module through the secure execution environment, and the root key and derived key are encrypted and stored to complete the creation of the root key and derived key.
[0091] Specifically, the secure execution environment sends the newly generated root key and derived key to the key storage module via a secure bus. The key storage module then encrypts the root key and derived key using its internally stored key.
[0092] Specifically, the encrypted key is stored in a designated location in the secure storage area and marked as "activated". After storage is complete, the key storage module returns a "creation successful" confirmation signal to the secure execution environment, completing the creation of the root key.
[0093] As can be seen from the above embodiments, by creating a key acquisition instruction based on the startup instruction through a secure execution environment, generating a root key and derived keys using a key storage module, and storing the generated root key and derived keys, the security of key storage and access is improved.
[0094] Figure 7 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 2 In one embodiment of this application, step S201b includes:
[0095] S301: Generate a seed generation instruction based on the key query result through the secure execution environment, and send the seed generation instruction to the random number generator so that the random number generator can generate a key seed according to the seed generation instruction.
[0096] Specifically, the secure execution environment generates a seed generation instruction based on the key query result. The instruction is sent to the physical random number generator through the hardware interface of the secure execution environment. The physical random number generator generates a high-entropy random number as the key seed based on the instruction and returns the key seed to the secure execution environment through an interrupt signal.
[0097] In this embodiment, the seed generation instruction specifies the seed length and random number quality requirements.
[0098] S302: Generate the root key according to the preset encryption algorithm and key seed.
[0099] Specifically, a fixed-length root key is generated using a key seed as input through a key derivation function.
[0100] S303: Create a derived key of the root key according to the preset key derivation rules.
[0101] Specifically, based on the key derivation rules, multiple derivative keys are derived from the root key.
[0102] In this embodiment, the key derivation rules include using different labels and context parameters.
[0103] S304: Create an association identifier for the root key and the derived key to complete the creation of the root key and the derived key.
[0104] Specifically, the secure execution environment generates a unique association identifier for the root key and each derived key. The association identifier is stored in the secure memory of the secure execution environment in the form of key-value pairs and is sent to the key storage module as metadata along with the key.
[0105] As can be seen from the above embodiments, the problem of insufficient entropy value per second generated by traditional trusted platform modules is solved by using a random number generator and a preset encryption algorithm. The generation of a key seed by the random number generator ensures that the generated key is unpredictable and improves the security of the key.
[0106] Figure 8 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 3 In one embodiment of this application, before step S201, the method further includes:
[0107] S401: In response to the power-on operation of the baseboard management controller, the memory storage area is divided and storage area division information is generated.
[0108] Specifically, physical memory is divided into multiple logical partitions to obtain storage area partitioning information.
[0109] In this embodiment, the information recorded in the storage area partitioning information includes, but is not limited to, the starting address, size, and access attributes of each area.
[0110] S402: Obtain the communication bus and control port of the key storage module based on the storage area division information.
[0111] Specifically, based on the storage area division information, the security access permissions of the key storage module are set through the system control unit.
[0112] In this embodiment, the secure execution environment is granted read and write permissions, while the insecure execution environment is prohibited from direct access.
[0113] S403: Mark the communication bus and control port of the key storage module as a secure device and create secure access permissions to complete the hardware initialization.
[0114] Specifically, the secure execution environment configures the security access permissions of the key storage module to the system bus and sets the security flag bits of the bus.
[0115] In this embodiment, the security designation is used to distinguish between secure access and insecure access.
[0116] As can be seen from the above embodiments, by initializing the hardware, dividing the storage area into a secure storage area and a normal storage area, setting security access permissions, and adding the security access permissions to the bus of the key storage module, the security of the key storage module is improved.
[0117] In one embodiment of this application, step S202 includes:
[0118] S202a: In response to the detection of a change in the reset signal, calculate the hash value of the system firmware through the secure execution environment.
[0119] Specifically, when the baseboard management controller receives a hardware reset signal, the secure execution environment loads the system firmware from flash memory into secure memory and uses a hash algorithm to calculate the hash value of the firmware.
[0120] S202b: Compare the hash value of the system firmware with the preset hash value in the flash memory of the baseboard management controller.
[0121] Specifically, the secure execution environment reads a preset hash value from the read-only area of the baseboard management controller's flash memory, compares the calculated hash value with the preset hash value byte by byte, and generates a comparison result.
[0122] S202c: If the hash value of the system firmware is the same as the preset hash value in the flash memory of the baseboard management controller, a firmware verification result is generated. The firmware verification result is used to create a session between the processor and the non-secure execution environment, and to generate a secure session channel.
[0123] Specifically, if the hash values are the same, a session channel is established; if the hash values are different, a failure to create the channel is returned.
[0124] As can be seen from the above embodiments, by calculating the hash value of the system firmware, a secure transmission trusted session is established between the processor and the insecure execution environment, thereby improving the security of the interaction between the baseboard management controller and the processor.
[0125] Figure 9 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 4 In one embodiment of this application, the method further includes the following step before step S205:
[0126] S501: Create a target key pair based on a key generation request through a secure execution environment, wherein the target key pair includes a target public key and a target private key.
[0127] Specifically, the secure execution environment receives a key generation request from the insecure execution environment and generates a target key pair using an asymmetric encryption algorithm. The key pair is generated in the secure execution environment's cryptographic library; the private key is stored in secure memory, and the public key is exported.
[0128] S502: The target private key is encrypted using the stored key in a secure execution environment to generate an encrypted target private key.
[0129] Specifically, the secure execution environment obtains the storage key from the key storage module, and the storage key is a symmetric key.
[0130] Specifically, the target private key is encrypted using a stored key and an encryption algorithm to generate an encrypted target private key and an authentication tag. The encryption process is performed in an isolated area of a secure execution environment.
[0131] S503: Store the encrypted target private key to the key storage module through a secure execution environment, and generate the storage result.
[0132] Specifically, the secure execution environment sends the encrypted target private key to the key storage module via the secure bus. The key storage module writes the encrypted target private key into its non-volatile storage area and updates the key management table.
[0133] S504: The target public key is sent to the insecure execution environment based on the stored result through the secure execution environment.
[0134] Specifically, if the storage result is successful, the secure execution environment will transfer the target public key to the insecure execution environment via shared memory.
[0135] S505: The target public key is sent to the processor via a secure session channel through an insecure execution environment to complete key generation.
[0136] Specifically, the insecure execution environment sends the target public key to the processor through an established trusted session.
[0137] As can be seen from the above embodiments, by creating a target key pair in a secure execution environment, encrypting and storing the target private key according to the stored key, and sending the target public key to the processor through an insecure execution environment to generate the key, the problems of low compatibility and security of trusted platform modules are avoided.
[0138] In one embodiment of this application, when the communication request is a data encryption request, step S205 includes:
[0139] S205a: Send a data encryption request to the key storage module through the secure execution environment, so that the key storage module can obtain the stored key and the encrypted target private key according to the data encryption request.
[0140] Specifically, upon receiving a data encryption request, the secure execution environment sends the request to the key storage module, specifying the storage key and the encrypted target private key. The key storage module retrieves the key from the storage area and returns it via the secure bus.
[0141] In this embodiment, the data encryption request includes plaintext data and a target key identifier.
[0142] S205b: Decrypt the encrypted target private key using the stored key sent by the key storage module to obtain the target private key.
[0143] Specifically, the secure execution environment uses a stored key and a corresponding decryption algorithm to decrypt the encrypted target private key. The decryption process takes place in the secure memory of the secure execution environment, ensuring that the private key exists only in plaintext form within the secure environment.
[0144] S205c: Encrypt the plaintext data in the data encryption request according to the target private key to generate processed ciphertext secure data.
[0145] Specifically, the secure execution environment encrypts the plaintext data using the target private key and an encryption algorithm. The encrypted ciphertext secure data is formatted as standard output and returned to the insecure execution environment or sent directly to the processor via the secure execution environment.
[0146] As can be seen from the above embodiments, by sending the data encryption request to the key storage module to obtain the storage key and the target private key, and using the target private key to encrypt the plaintext data to generate the processed ciphertext secure data, the functions of the trusted platform are performed within the baseboard management controller, thus avoiding the problems of low compatibility and security of the trusted platform module.
[0147] In one embodiment of this application, when the communication request is a data decryption request, step S205 includes:
[0148] S205d: Sends a data decryption request to the key storage module through the secure execution environment, so that the key storage module can obtain the stored key and the encrypted target public key according to the data decryption request.
[0149] Specifically, upon receiving a data decryption request, the secure execution environment sends the request to the key storage module, specifying the storage key and the encrypted target public key to be retrieved. After verifying the request, the key storage module returns the key materials.
[0150] S205e: Decrypt the encrypted target public key based on the stored key sent by the key storage module to obtain the target public key.
[0151] Specifically, the secure execution environment uses a stored key to decrypt the encrypted target public key using the same decryption algorithm as during encryption. The decrypted target public key is then loaded into a protected area of secure memory.
[0152] S205f: Decrypt the ciphertext data in the data decryption request based on the target public key to generate processed plaintext secure data.
[0153] Specifically, the secure execution environment uses the target public key and decryption algorithm to decrypt the ciphertext data. After the decrypted plaintext secure data is verified for integrity, it is returned to the insecure execution environment.
[0154] As can be seen from the above embodiments, by sending the data decryption request to the key storage module to obtain the storage key and the target public key, and using the target public key to decrypt the ciphertext data and generate the processed plaintext secure data, the functions of the trusted platform are performed within the baseboard management controller, thus avoiding the compatibility and security problems of the trusted platform module.
[0155] Figure 10 A flowchart illustrating the data processing method for implementing the trusted platform module function provided in this application embodiment. Figure 5 In one embodiment of this application, before step S205, the method further includes:
[0156] S601: Obtain the priority identifier in the communication request.
[0157] Specifically, the message header is decoded, and the priority identifier is obtained according to the predefined communication protocol.
[0158] S602: Sort multiple communication requests according to priority identifiers and generate a priority list.
[0159] Specifically, the sorting engine is invoked to parse the priority identifiers, and the priority is sorted in descending order according to the priority sorting strategy set in the sorting engine to generate a priority list.
[0160] S603: Add the timestamp of the communication request according to the priority list to obtain the processing queue of the communication request.
[0161] Specifically, timestamps are added based on the priority list through the queue management module.
[0162] In this embodiment, the timestamp records the time when the communication request enters the ordered queue.
[0163] As can be seen from the above embodiments, by prioritizing communication requests and processing them in descending order of priority, and by adding timestamps, high-priority requests are prevented from being shelved.
[0164] In one embodiment of this application, step S603 includes:
[0165] S603a: Obtain the system clock source and add a timestamp to each request in the priority list.
[0166] Specifically, the clock interface is called to iterate through each communication request node and add a timestamp.
[0167] S603b: Reorder requests of the same priority level based on timestamps.
[0168] Specifically, if there are requests with the same priority, the requests are sorted a second time based on their timestamps.
[0169] S603c: Encapsulates the sorted sequence into a processing queue data structure.
[0170] Specifically, the sequence after secondary sorting is instantiated into a processing queue data structure, which can be a linked list or an array.
[0171] As can be seen from the above embodiments, by attaching a high-precision timestamp to the request, performing secondary sorting on requests of the same level, and encapsulating the secondary sorted sequence into a queue data structure, precise time-series scheduling of request processing is achieved, thereby improving the system's processing efficiency.
[0172] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.
[0173] Figure 11 This is a schematic diagram of the structure of a data processing device for implementing the functions of a trusted platform module, as provided in an embodiment of this application. Figure 11 As shown, embodiments of this application also provide a data processing device 110 for implementing the functions of a trusted platform module, including: a first creation module 1101, a first generation module 1102, a second creation module 1103, a first receiving module 1104, a second receiving module 1105, and a first sending module 1106.
[0174] The first creation module 1101 is used to create a root key and a derived key in response to the power-on operation of the baseboard management controller through a secure execution environment, wherein the baseboard management controller has a secure execution environment and a non-secure execution environment.
[0175] The first generation module 1102 is used to generate firmware verification results in response to the detection of a change in the reset signal by executing the startup firmware of the secure environment verification system.
[0176] The second creation module 1103 is used to create a session for the processor and the non-secure execution environment based on the firmware verification result, and to generate a secure session channel.
[0177] The first receiving module 1104 is used to receive a communication request sent by the processor through a non-secure execution environment, wherein the communication request is sent by the processor to the non-secure execution environment through a secure session channel.
[0178] The second receiving module 1105 is used to receive communication requests sent by the non-secure execution environment through the secure execution environment, and process the data in the communication request according to the root key and the derived key to generate processed secure data.
[0179] The first sending module 1106 is used to send the processed secure data to the processor through an insecure execution environment in order to realize the data processing function of the trusted platform module.
[0180] In one embodiment of this application, the first creation module 1101 includes:
[0181] The query unit is used to query whether key data is stored in the key storage module through the secure execution environment and generate key query results.
[0182] The creation unit is used to create a root key and a derivative key based on the key query results if no key data is found in the key query results.
[0183] The first sending unit is used to send the root key and the derived key to the key storage module through the secure execution environment, and to encrypt and store the root key and the derived key in order to complete the creation of the root key and the derived key.
[0184] In one embodiment of this application, the creation unit includes:
[0185] The first generation subunit is used to generate a seed generation instruction based on the key query result through a secure execution environment, and send the seed generation instruction to the random number generator so that the random number generator generates a key seed according to the seed generation instruction.
[0186] The second generation subunit is used to generate the root key according to the preset encryption algorithm and key seed.
[0187] The first creation subunit is used to create a derived key of the root key according to a preset key derivation rule.
[0188] The second creation subunit is used to create the association identifier between the root key and the derived key in order to complete the creation of the root key and the derived key.
[0189] In one embodiment of this application, the data processing apparatus 110 for implementing the trusted platform module function further includes:
[0190] The partitioning module is used to partition the memory storage area and generate storage area partitioning information in response to the power-on operation of the baseboard management controller.
[0191] The first acquisition module is used to acquire the communication bus and control port of the key storage module based on the storage area division information.
[0192] The tagging module is used to mark the communication bus and control port of the key storage module as a secure device and create secure access permissions to complete the hardware initialization.
[0193] In one embodiment of this application, the first generation module 1102 includes:
[0194] The calculation unit is used to calculate the hash value of the system firmware through a secure execution environment in response to the detection of a change in the reset signal.
[0195] The comparison unit is used to compare the hash value of the system firmware with the preset hash value in the flash memory of the baseboard management controller.
[0196] The generation unit is used to generate a firmware verification result if the hash value of the system firmware is the same as the preset hash value in the flash memory of the baseboard management controller. The firmware verification result is used to create a session between the processor and the non-secure execution environment, and to generate a secure session channel.
[0197] In one embodiment of this application, the data processing apparatus 110 for implementing the trusted platform module function further includes:
[0198] The third creation module is used to create a target key pair based on a key generation request through a secure execution environment. The target key pair includes a target public key and a target private key.
[0199] The encryption module is used to encrypt the target private key based on the stored key in a secure execution environment, thereby generating an encrypted target private key.
[0200] The storage module is used to store the encrypted target private key to the key storage module through a secure execution environment, generating the storage result.
[0201] The second sending module is used to send the target public key to the insecure execution environment based on the storage result through the secure execution environment.
[0202] The third sending module is used to send the target public key to the processor through a secure session channel in an insecure execution environment to complete key generation.
[0203] In one embodiment of this application, the second receiving module 1105 includes:
[0204] The second sending unit is used to send a data encryption request to the key storage module through a secure execution environment, so that the key storage module can obtain the stored key and the encrypted target private key according to the data encryption request.
[0205] The first decryption unit is used to decrypt the encrypted target private key according to the storage key sent by the key storage module, and obtain the target private key.
[0206] The encryption unit is used to encrypt the plaintext data in the data encryption request according to the target private key, and generate the processed ciphertext secure data.
[0207] In one embodiment of this application, the second receiving module 1105 further includes:
[0208] The third sending unit is used to send a data decryption request to the key storage module through the secure execution environment, so that the key storage module can obtain the stored key and the encrypted target public key according to the data decryption request.
[0209] The second decryption unit is used to decrypt the encrypted target public key according to the storage key sent by the key storage module, so as to obtain the target public key.
[0210] The third decryption unit is used to decrypt the ciphertext data in the data decryption request based on the target public key, and generate processed plaintext secure data.
[0211] In one embodiment of this application, the data processing apparatus 110 for implementing the trusted platform module function further includes:
[0212] The second acquisition module is used to acquire the priority identifier in the communication request.
[0213] The second generation module is used to sort multiple communication requests according to priority identifiers and generate a priority list.
[0214] Add a module to add timestamps to communication requests based on a priority list to obtain a processing queue for communication requests.
[0215] For a description of the features of the data processing device that implements the trusted platform module function in the corresponding embodiment, please refer to the relevant description of the data processing method that implements the trusted platform module function in the corresponding embodiment, which will not be repeated here.
[0216] Figure 12 A schematic diagram of the structure of the electronic device provided in this application. Figure 12 As shown, the electronic device 120 provided in this embodiment includes at least one processor 1201 and a memory 1202. Optionally, the electronic device 120 further includes a communication component 1203. The processor 1201, memory 1202, and communication component 1203 are connected via a bus.
[0217] In the specific implementation process, at least one processor 1201 executes computer execution instructions stored in memory 1202, causing at least one processor 1201 to execute the above-described data processing method embodiment for implementing the functions of the trusted platform module.
[0218] The specific implementation process of processor 1201 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0219] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0220] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0221] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0222] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above embodiments of the data processing method for implementing the functions of a trusted platform module when it is run.
[0223] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.
[0224] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above embodiments of the data processing method for implementing the functions of a trusted platform module.
[0225] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above embodiments of the data processing method for implementing the functions of a trusted platform module.
[0226] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0227] The foregoing has provided a detailed description of a data processing method and electronic device for implementing the functions of a trusted platform module. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only intended to aid in understanding the method and core ideas of this application. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A data processing method for implementing the functions of a trusted platform module, characterized in that, include: In response to the power-on operation of the baseboard management controller, the memory storage area is divided and storage area division information is generated; Based on the storage area partitioning information, obtain the communication bus and control port of the key storage module; The communication bus and control port of the key storage module are marked as secure devices, and secure access permissions are created to complete the hardware initialization; In response to the power-on operation of the baseboard management controller, a root key and a derived key are created through a secure execution environment, wherein the baseboard management controller has a secure execution environment and a non-secure execution environment. In response to the detection of a change in the reset signal, a firmware verification result is generated through the startup firmware of the secure execution environment verification system; Based on the firmware verification results, a session is created for the processor and the insecure execution environment, generating a secure session channel; The non-secure execution environment receives a communication request sent by the processor, wherein the communication request is sent by the processor to the non-secure execution environment through the secure session channel; When the communication request is a key generation request, the secure execution environment creates a target key pair according to the key generation request, wherein the target key pair includes a target public key and a target private key; The target private key is encrypted using the stored key within the secure execution environment to generate an encrypted target private key. The encrypted target private key is stored in the key storage module through the secure execution environment, generating a storage result. The target public key is sent to the insecure execution environment based on the storage result through the secure execution environment. The target public key is sent to the processor through the insecure execution environment via a secure session channel to complete key generation; The secure execution environment receives the communication request sent by the insecure execution environment, and processes the data in the communication request according to the root key and the derived key to generate processed secure data. The processed secure data is sent to the processor through the insecure execution environment to realize the data processing function of the trusted platform module.
2. The data processing method for implementing the trusted platform module function according to claim 1, characterized in that, The creation of the root key and derived key through a secure execution environment includes: The secure execution environment queries whether the key storage module stores key data, and generates a key query result. If no key data is found in the key query result, a root key and a derived key are created in the secure execution environment based on the key query result. The root key and the derived key are sent to the key storage module through the secure execution environment, and the root key and the derived key are encrypted and stored to complete the creation of the root key and the derived key.
3. The data processing method for implementing the trusted platform module function according to claim 2, characterized in that, The process of creating a root key and derived keys based on the key query result through the secure execution environment includes: The secure execution environment generates a seed generation instruction based on the key query result and sends the seed generation instruction to the random number generator so that the random number generator generates a key seed according to the seed generation instruction. A root key is generated based on a preset encryption algorithm and the key seed; A derived key of the root key is created according to a preset key derivation rule; Create an association identifier for the root key and the derived key to complete the creation of the root key and the derived key.
4. The data processing method for implementing the trusted platform module function according to claim 1, characterized in that, In response to the detection of a change in the reset signal, the firmware verification result is generated through the startup firmware of the secure execution environment verification system, including: In response to the detection of a change in the reset signal, the hash value of the system firmware is calculated through the secure execution environment; The hash value of the system firmware is compared with the preset hash value in the flash memory of the baseboard management controller; If the hash value of the system firmware is the same as the preset hash value in the flash memory of the baseboard management controller, a firmware verification result is generated. The firmware verification result is used to create a session between the processor and the non-secure execution environment, and to generate a secure session channel.
5. The data processing method for implementing the trusted platform module function according to claim 1, characterized in that, When the communication request is a data encryption request, the process of receiving the communication request sent by the insecure execution environment through the secure execution environment, and processing the data in the communication request according to the root key and the derived key to generate processed secure data includes: The secure execution environment sends the data encryption request to the key storage module, so that the key storage module can obtain the storage key and the encrypted target private key according to the data encryption request. The encrypted target private key is decrypted using the storage key sent by the key storage module to obtain the target private key. The plaintext data in the data encryption request is encrypted using the target private key to generate processed ciphertext secure data.
6. The data processing method for implementing the functions of a trusted platform module according to claim 1, characterized in that, When the communication request is a data decryption request, the process of receiving the communication request sent by the insecure execution environment through the secure execution environment, and processing the data in the communication request according to the root key and the derived key to generate processed secure data includes: The secure execution environment sends the data decryption request to the key storage module, so that the key storage module can obtain the stored key and the encrypted target public key according to the data decryption request. The encrypted target public key is decrypted using the storage key sent by the key storage module to obtain the target public key; The encrypted data in the data decryption request is decrypted using the target public key to generate processed plaintext secure data.
7. The data processing method for implementing the functions of a trusted platform module according to any one of claims 1 to 6, characterized in that, Before receiving the communication request sent by the insecure execution environment through the secure execution environment, the method further includes: Retrieve the priority identifier from the communication request; Multiple communication requests are sorted according to the priority identifier to generate a priority list; The timestamps of communication requests are added to the priority list to obtain the processing queue for communication requests.
8. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the data processing method for implementing the functions of a trusted platform module as described in any one of claims 1 to 7 when executing the computer program.
Citation Information
Patent Citations
Cloud platform verification method and assembly, and ARM cloud platform
CN115687039A
Encapsulation of a TCPA trusted platform module functionality within a server management coprocessor subsystem
CN1723425A