一种开发板Linux系统安全认证多启动方法

By using a hardware root of trust and a multi-level authentication and resource isolation mechanism in the bootloader, the security and isolation issues of the multi-boot scheme for the development board are solved, and the secure dynamic switching of multiple systems and data protection are realized.

CN121765713BActive Publication Date: 2026-07-17BEIJING XUNWEI ELECTRONICS CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING XUNWEI ELECTRONICS CO LTD
Filing Date
2025-12-26
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Traditional multi-boot solutions for development boards lack authentication and isolation mechanisms, making them vulnerable to malicious code injection. Shared storage across multiple systems can lead to data leaks, and system crashes can affect other systems. Furthermore, the source of unauthorized boots cannot be traced. Existing improvement solutions are not optimized for the resource constraints of development boards and the dynamic switching between multiple systems.

Method used

It employs hardware root of trust initialization and storage area partitioning, combined with Bootloader for multi-level authentication and resource isolation, uses asymmetric key pairs for encrypted communication between systems, and records tamper-proof audit logs to achieve secure dynamic switching and storage isolation of multiple systems.

Benefits of technology

It effectively resists malicious image booting and data leakage between systems, enables dynamic switching between multiple systems on demand, adapts to the limited computing power of development boards, records the boot process and abnormal events, and facilitates the tracing of illegal operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121765713B_ABST
    Figure CN121765713B_ABST
Patent Text Reader

Abstract

本发明公开一种开发板Linux系统安全认证多启动方法,包括步骤一、硬件信任根初始化与存储区划分,步骤二、硬件信任根自检和度量,步骤三、启动项动态加载和多级认证,步骤四、安全上下文建立与系统切换,步骤五、多系统隔离与协同,步骤六、安全审计与异常处理;本发明以硬件信任根为锚点实现全链路认证,结合存储与资源隔离机制,有效抵御恶意镜像启动与系统间数据泄露,同时可实现多系统按需动态切换,灵活适配调试、升级、故障恢复等场景,通过优化认证算法与资源管理的轻量化设计,适配开发板有限算力,且可对启动过程与异常事件进行完整记录,便于追溯非法操作。
Need to check novelty before this filing date? Find Prior Art