Control method and electronic equipment

By maintaining the reset signal of the peripheral interface and performing security verification during the startup of electronic devices through the baseboard management controller, the problem of unisolated peripheral interface connected devices is solved, thereby improving the security of electronic devices and the isolation effect of the startup process.

CN121902122APending Publication Date: 2026-04-21LENOVO (BEIJING) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
LENOVO (BEIJING) LTD
Filing Date
2025-12-31
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies fail to isolate devices connected to peripheral interfaces during the startup process of electronic devices after security verification fails, resulting in low security.

Method used

The baseboard management controller keeps the reset signal of the peripheral interface in an disabled state when the power is turned on or off, and performs security verification through the system management bus. Devices that fail verification are marked. When the DC power is turned on, the reset signal of the unverified device is released to enable it.

Benefits of technology

This technology enables the isolation of peripheral interface devices that fail verification during the power-on process of electronic devices, thereby improving the security of electronic devices and the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121902122A_ABST
    Figure CN121902122A_ABST
Patent Text Reader

Abstract

The invention discloses a control method and electronic equipment, and the control method comprises the steps: responding to the connection of an external power supply or the disconnection of a DC power supply, maintaining a reset signal of each first peripheral interface of the electronic equipment through a first controller of the electronic equipment, and enabling each first peripheral interface to be in a non-enabling state; when the first peripheral interface is in the device connection state, performing security verification on the device connected with the first peripheral interface through a system management bus of the electronic device in a target verification mode; under the condition that the verification of the equipment connected with the first peripheral interface fails, adding a first mark to the equipment connected with the first peripheral interface; if the power-on instruction is received, turning on a direct-current power supply of the electronic equipment; the reset signal of the second peripheral interface is released through the first controller, so that the second peripheral interface is in an enabled state, and the second peripheral interface is the first peripheral interface of the connected equipment without adding the first mark.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a control method and electronic device. Background Technology

[0002] To improve security, security verification can be performed on devices connected to some peripheral interfaces (such as PCIe interfaces) of electronic devices during the startup process.

[0003] Currently, after a security verification fails, only an alarm message is usually issued, and the device connected to the corresponding peripheral interface is not isolated, resulting in low security. Summary of the Invention

[0004] This application provides a control method, comprising: responding to connecting an external power supply or disconnecting a DC power supply, maintaining a reset signal for each first peripheral interface of the electronic device via a first controller of the electronic device, such that each first peripheral interface is in an disabled state; when the first peripheral interface is in a device connection state, performing security verification on the device connected to the first peripheral interface via the system management bus of the electronic device in a target verification manner; if the device connected to the first peripheral interface fails verification, adding a first mark to the device connected to the first peripheral interface; if a power-on command is received, turning on the DC power supply of the electronic device; and releasing a reset signal for a second peripheral interface via the first controller, such that the second peripheral interface is a first peripheral interface of the connected device that has not added the first mark.

[0005] In some embodiments, after releasing the reset signal of the second peripheral interface through the first controller to enable the second peripheral interface, the method further includes: performing security verification on the device connected to the second peripheral interface through the first bus of the electronic device in the target verification method, wherein the first bus connects to each of the first peripheral interfaces; if the verification of the device connected to the second peripheral interface fails, maintaining the reset signal of the second peripheral interface through the first controller to change the second peripheral interface from the enabled state to the disabled state; and starting the operating system of the electronic device based on the boot system to enable the electronic device to enter the power-on state.

[0006] In some embodiments, before turning on the DC power supply of the electronic device, the method further includes: determining whether security verification of all devices connected to the target first peripheral interface has been completed, wherein the devices connected to the target first peripheral interface support security verification via the system management bus in the target verification method; and performing the step of turning on the DC power supply of the electronic device if security verification of all devices connected to the target first peripheral interface has been completed.

[0007] In some embodiments, after turning on the DC power supply of the electronic device, the method further includes: enumerating each of the first peripheral interfaces based on the boot system; and, if the enumeration is completed, performing the step of performing security verification on the device connected to the second peripheral interface through the first bus of the electronic device in the target verification manner.

[0008] In some embodiments, before the boot system starts the operating system of the electronic device and puts the electronic device into a power-on state, the method further includes: determining whether security verification of all devices connected to the target second peripheral interface has been completed, wherein the devices connected to the target second peripheral interface support security verification via the first bus in the target verification method; and granting the boot system permission to start the operating system of the electronic device if the security verification of all devices connected to the target second peripheral interface has been completed.

[0009] In some embodiments, before starting the operating system of the electronic device based on the boot system to put the electronic device into a power-on state, the method further includes: determining the duration for completing the enumeration; and if the duration reaches a target duration, performing the step of starting the operating system of the electronic device based on the boot system to put the electronic device into a power-on state.

[0010] In some embodiments, the method further includes: when the electronic device is powered on and there is an operation to insert a hot-swappable device into the first peripheral interface, performing security verification on the hot-swappable device connected to the first peripheral interface through the system management bus in the target verification method; and when the hot-swappable device connected to the first peripheral interface is successfully verified, releasing the reset signal of the first peripheral interface through the first controller, so that the first peripheral interface is enabled.

[0011] In some embodiments, the method further includes: if the hot-swappable device connected to the first peripheral interface does not support security verification via the system management bus using the target verification method, the first controller releases a reset signal for the first peripheral interface to enable the first peripheral interface.

[0012] In some embodiments, the method further includes: when the hot-swappable device connected to the first peripheral interface does not support security verification via the system management bus in the target verification method, and the reset signal of the first peripheral interface has been released, performing security verification on the first peripheral interface via the first bus in the target verification method, wherein the first bus connects to each of the first peripheral interfaces; and when the verification of the hot-swappable device connected to the first peripheral interface fails, maintaining the reset signal of the first peripheral interface via the first controller, thereby changing the first peripheral interface from an enabled state to an disabled state.

[0013] This application also proposes an electronic device, including a baseboard management controller, a plurality of first peripheral interfaces, a first controller, and a system management bus. The baseboard management controller is configured to: in response to connecting an external power supply or disconnecting a DC power supply, maintain the reset signal of each of the first peripheral interfaces of the electronic device through the first controller, so that each of the first peripheral interfaces is in an disabled state; when the first peripheral interface is in a device connection state, perform security verification on the device connected to the first peripheral interface in a target verification manner through the system management bus of the electronic device; if the device connected to the first peripheral interface fails verification, add a first mark to the device connected to the first peripheral interface; if a power-on command is received, turn on the DC power supply of the electronic device; release the reset signal of a second peripheral interface through the first controller, so that the second peripheral interface is in an enabled state, wherein the second peripheral interface is the first peripheral interface of the connected device that has not added the first mark. Attached Figure Description

[0014] To more clearly illustrate the technical solutions of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 The flow chart of the control method in the embodiments of this application Figure 1 ; Figure 2 The flow chart of the control method in the embodiments of this application Figure 2 ; Figure 3 The flow chart of the control method in the embodiments of this application Figure 3 ; Figure 4 The flow chart of the control method in the embodiments of this application Figure 4 ; Figure 5 The flow chart of the control method in the embodiments of this application Figure 5 ; Figure 6 The flow chart of the control method in the embodiments of this application Figure 6 ; Figure 7 The flow chart of the control method in the embodiments of this application Figure 7 ; Figure 8 The flow chart of the control method in the embodiments of this application Figure 8 ; Figure 9 This is a structural block diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0016] Various embodiments and features of this application are described herein with reference to the accompanying drawings.

[0017] It should be understood that various modifications can be made to the embodiments described herein. Therefore, the above description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this application will be apparent to those skilled in the art.

[0018] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.

[0019] These and other features of this application will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.

[0020] It should also be understood that although this application has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of this application.

[0021] The above and other aspects, features and advantages of this application will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.

[0022] Specific embodiments of this application are described thereafter with reference to the accompanying drawings; however, it should be understood that the claimed embodiments are merely examples of this application, which can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the application. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but merely serve as the basis and representative basis for the claims to teach those skilled in the art to use this application in a variety of substantially any suitable detailed structures.

[0023] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in other embodiments,” all of which may refer to one or more of the same or different embodiments according to this application.

[0024] One control method according to an embodiment of this application maintains the reset signals of each first peripheral interface of an electronic device in response to connecting or disconnecting an external power supply, thus disabling each first peripheral interface. The method then performs security verification on devices connected to the first peripheral interfaces via the system management bus of the electronic device using a target verification method, adding a first mark to devices that fail verification. If a power-on command is received, the DC power supply of the electronic device is turned on, and the reset signals of the first peripheral interfaces of connected devices that have not yet been marked are released. By maintaining the reset signals of all first peripheral interfaces when the external power supply is connected or disconnected, and releasing only the reset signals of first peripheral interfaces that have not failed verification during the power-on process, the method isolates peripheral interface devices that have failed verification during the power-on process, thereby improving the security of the electronic device.

[0025] like Figure 1 As shown, the control method includes the following steps: In step S101, in response to connecting or disconnecting the external power supply, the first controller of the electronic device maintains the reset signal of each first peripheral interface of the electronic device, so that each first peripheral interface is in an disabled state.

[0026] In this embodiment, the execution entity of the control method can be the BMC (Baseboard Management Controller) of the electronic device. The electronic device may include, for example, any of a personal computer, server, workstation, or mobile device equipped with a baseboard management controller and a first peripheral interface. The electronic device includes multiple first peripheral interfaces, which may be PCIe interfaces or other types of peripheral interfaces. The first controller can be used to control the first peripheral interfaces, and may include, for example, an FPGA (Field Programmable Gate Array) or a PSoC (Programmable System-on-Chip), etc. The FPGA and PSoC can respectively control the first peripheral interfaces at different locations of the electronic device.

[0027] The electronic device can be powered on by connecting its power cord or adapter to an external AC power source. The DC power supply can be disconnected in response to a power-off command to the electronic device. The electronic device is in a powered-off state whether the external power supply is connected or the DC power supply is disconnected. In response to connecting or disconnecting the external power supply, the first controller maintains the reset signal of each first peripheral interface, thus disabling each first peripheral interface and isolating devices connected to the first peripheral interface. For example, the first controller can set the reset signal of each first peripheral interface to a low level to maintain the reset signal. When the first peripheral interface is a PCIe interface, the reset information is a PERST signal.

[0028] Step S102: When the first peripheral interface is in a device connection state, the device connected to the first peripheral interface is securely verified through the system management bus of the electronic device in a target verification manner.

[0029] In this embodiment, if the first peripheral interface is in a device connection state, it means that a device is connected to the first peripheral interface. It can be determined whether the device connected to the first peripheral interface supports security verification in the target verification mode through the system management bus (SMBUS) of the electronic device. If it supports it, the device is security verified in the target verification mode through the system management bus (SMBUS) to determine whether the device has any security risks.

[0030] When the first peripheral interface is a PCIe interface, the target verification method can be based on SPDM (Security Protocol and Data Model). First, it can be determined whether the device connected to the first peripheral interface supports MCTP (Management Component Transport Protocol) based on the system management bus. If it does, then it can be determined whether the device connected to the first peripheral interface supports SPDM based on the system management bus. This can efficiently determine whether the device connected to the first peripheral interface supports SPDM based on the system management bus.

[0031] Understandably, if the device connected to the first peripheral interface does not support security verification via the system management bus using the target verification method, then security verification will not be performed on it for the time being.

[0032] Step S103: If the device connected to the first peripheral interface fails to be verified, add a first mark to the device connected to the first peripheral interface.

[0033] In this embodiment, if the device connected to the first peripheral interface fails to verify, a first flag indicating the verification failure is added to the device connected to the first peripheral interface, and the first controller can be notified.

[0034] Step S104: If a power-on command is received, turn on the DC power supply of the electronic device.

[0035] In this embodiment, the power-on command can be triggered by pressing the power button on the electronic device, or it can be a remote power-on command sent by another electronic device. Upon receiving a power-on command, the DC power supply to the electronic device is turned on, causing the electronic device to enter the power-on process.

[0036] Step S105: Release the reset signal of the second peripheral interface through the first controller, so that the second peripheral interface is in an enabled state. The second peripheral interface is the first peripheral interface of the connected device that has not added the first mark.

[0037] In this embodiment, the second peripheral interface is the first peripheral interface of the connected device that has not been marked with the first tag. The device connected to the second peripheral interface may include a device that supports and successfully performs security verification via the system management bus using the target verification method, a device that does not support and has not performed security verification via the system management bus using the target verification method, or a device that supports and has not yet performed or completed security verification via the system management bus using the target verification method. The reset signal of the second peripheral interface is released by the first controller, thereby enabling the second peripheral interface. For example, the reset signal of each second peripheral interface can be set to a high level by the first controller to release each reset signal.

[0038] For example, if each first peripheral interface includes interface one, interface two, interface three, and interface four, then in response to connecting or disconnecting the external power supply or the DC power supply, the first controller maintains the reset signals of interface one, interface two, interface three, and interface four, keeping the first peripheral interfaces in an enabled state. If the devices connected to interface one, interface three, and interface four support security verification via the system management bus using target verification, and the device connected to interface two does not support security verification via the system management bus using target verification, then security verification is performed on the devices connected to interface one, interface three, and interface four respectively via the system management bus using target verification. If the devices connected to interface one and interface three are successfully verified, and the device connected to interface four fails to be verified, then a first mark is added to the device connected to interface four, interface one, interface two, and interface three are identified as second peripheral interfaces, and the reset signals of interface one, interface two, and interface three are released, keeping interface one, interface two, and interface three in an enabled state. Since the reset signal of interface four is still maintained by the first controller, interface four remains in an enabled state, thereby isolating interface four, which failed verification.

[0039] Alternatively, after receiving the power-on command, if the device connected to interface 1 has been successfully verified, the device connected to interface 4 has failed verification, and security verification has not yet been performed on interface 3, then interface 1, interface 2, and interface 3 will be designated as the second peripheral interface, and the reset signals of interface 1, interface 2, and interface 3 will be released, enabling interface 1, interface 2, and interface 3.

[0040] The control method of this application embodiment includes: in response to connecting an external power supply or disconnecting a DC power supply, maintaining the reset signals of each first peripheral interface of the electronic device through a first controller of the electronic device, so that each first peripheral interface is in an disabled state; when the first peripheral interface is in a device connection state, performing security verification on the device connected to the first peripheral interface through the system management bus of the electronic device in a target verification manner; if the verification of the device connected to the first peripheral interface fails, adding a first mark to the device connected to the first peripheral interface; if a power-on command is received, turning on the DC power supply of the electronic device; and releasing the reset signal of a second peripheral interface through the first controller, so that the second peripheral interface is in an enabled state, the second peripheral interface being the first peripheral interface of the connected device that has not been marked with the first mark. By maintaining the reset signals of all first peripheral interfaces when connecting an external power supply or disconnecting a DC power supply, and releasing only the reset signals of the first peripheral interfaces that have not failed verification during the power-on process of the electronic device, isolation of peripheral interface devices that have failed verification is achieved during the power-on process, thereby improving the security of the electronic device.

[0041] In some embodiments of this application, after the reset signal of the second peripheral interface is released through the first controller, thereby enabling the second peripheral interface, as follows: Figure 2 As shown, it also includes the following steps: Step S106: The device connected to the second peripheral interface is securely verified through the first bus of the electronic device in the target verification method. The first bus connects to each of the first peripheral interfaces.

[0042] In this embodiment, the electronic device includes a first bus connected to each first peripheral interface. If the first peripheral interface is a PCIe interface, the first bus is a PCIe bus. Some devices connected to second peripheral interfaces may not support security verification via the system management bus using a target verification method, but they may support security verification via the electronic device's first bus using a target verification method. Therefore, after the DC power is turned on, the first bus operates. For each second peripheral interface, it is first determined whether it supports security verification via the first bus using a target verification method. If it does, then security verification is performed via the first bus using a target verification method.

[0043] In step S107, if the device verification of the second peripheral interface fails, the first controller maintains the reset signal of the second peripheral interface, so that the second peripheral interface changes from the enabled state to the disabled state.

[0044] In this embodiment, if the device connected to the second peripheral interface fails to be verified, it indicates that the device has a security risk. The first controller then maintains the reset signal of the second peripheral interface, causing the second peripheral interface to change from an enabled state to a disabled state, thereby isolating it.

[0045] Step S108: Start the operating system of the electronic device based on the boot system, so that the electronic device enters the power-on state.

[0046] In this embodiment, the boot system can be UEFI (Unified Extensible Firmware Interface) or BIOS (Basic Input Output System). The operating system of the electronic device is started based on the boot system, thus putting the electronic device into a power-on state.

[0047] By re-verifying the devices connected to the second peripheral interface via the first bus after the DC power is turned on, and retaining the reset signal of the second peripheral interface corresponding to the failed verification device, security is further improved. Based on the boot system, the operating system of the electronic device is started, enabling the electronic device to enter the power-on state. This achieves the goal of isolating the failed verification peripheral interface devices while allowing the electronic device to start normally, thus improving the user experience.

[0048] In some embodiments of this application, before turning on the DC power supply of the electronic device, the following steps are further included: Determine whether security verification of all devices connected to the target first peripheral interface has been completed, wherein the devices connected to the target first peripheral interface support security verification via the system management bus using the target verification method; After completing security verification of all devices connected to the target first peripheral interface, the step of turning on the DC power supply of the electronic device is performed.

[0049] In this embodiment, a verified mark can be added to the device that has completed verification. The verification mark is used to determine whether the security verification of all devices connected to the target first peripheral interface has been completed. If not, the DC power supply of the electronic device is turned on after the security verification of all devices connected to the target first peripheral interface has been completed. The device connected to the target first peripheral interface supports security verification via the system management bus in the target verification mode.

[0050] By turning on the DC power only after completing security verification of all devices connected to the target's first peripheral interface, the security is further improved by avoiding turning on the DC power and releasing the corresponding reset signal of the devices connected to the target's first peripheral interface before security verification is performed.

[0051] In some embodiments of this application, the baseboard management controller pre-configures a first setting, which indicates whether to power on the DC power supply only after completing security verification of all devices connected to the target first peripheral interfaces. Upon receiving a power-on command, the baseboard management controller can, according to the first setting, either power on the DC power supply only after completing security verification of all devices connected to the target first peripheral interfaces, or power on the DC power supply directly, thereby improving the flexibility of the power-on process. The baseboard management controller can read and write this first setting, and the first controller can also read this first setting.

[0052] In some embodiments of this application, after the DC power supply to the electronic device is turned on, the method further includes: The boot system enumerates each of the first peripheral interfaces; Upon completion of the enumeration, the step of performing security verification on the device connected to the second peripheral interface via the first bus of the electronic device in the target verification manner is executed.

[0053] In this embodiment, after the DC power is turned on, the boot system enumerates each first peripheral interface, enabling the operating system to correctly identify and utilize the devices connected to the first peripheral interfaces. Enumeration may include processes such as device discovery, reading device information, loading drivers, resource allocation, and device configuration. After the enumeration is completed, the device connected to the second peripheral interface is then securely verified via the first bus using a target verification method, thereby achieving accurate security verification of the device connected to the second peripheral interface.

[0054] In some embodiments of this application, before the operating system of the electronic device is started based on the boot system, thus putting the electronic device into a power-on state, the method further includes: Determine whether security verification of all devices connected to the target second peripheral interface has been completed, wherein the devices connected to the target second peripheral interface support security verification via the first bus in the target verification method; After completing security verification of all devices connected to the target secondary peripheral interface, the boot system is granted permission to launch the operating system of the electronic device.

[0055] In this embodiment, a verified tag can be added to the devices that have completed verification. Based on the verified tag, it can be determined whether security verification of all devices connected to the target second peripheral interface is complete. If not, after completing security verification of all devices connected to the target second peripheral interface, the boot system is granted permission to start the operating system of the electronic device, enabling the boot system to start the operating system of the electronic device. The devices connected to the target second peripheral interface support security verification via the first bus using a target verification method.

[0056] By granting the boot system permission to start the operating system of the electronic device only after completing security verification of all devices connected to the target's second peripheral interface, the system avoids starting the operating system of the electronic device through the boot system before security verification of the devices connected to the target's second peripheral interface, thus further improving security.

[0057] In some embodiments of this application, the baseboard management controller pre-configures a second setting. This second setting indicates whether to grant the boot system permission to start the operating system of the electronic device only after completing security verification of all devices connected to the target second peripheral interfaces. The baseboard management controller can, based on the second setting, grant the boot system permission to start the operating system of the electronic device only after completing security verification of all devices connected to the target second peripheral interfaces, or directly grant the boot system permission to start the operating system of the electronic device, thereby improving the flexibility of the boot process. The baseboard management controller can read and write this second setting, and the first controller can also read this second setting.

[0058] In some embodiments of this application, before the operating system of the electronic device is started based on the boot system, thus putting the electronic device into a power-on state, the method further includes: Determine the duration for completing the enumeration; If the duration reaches the target duration, the step of starting the operating system of the electronic device based on the boot system is executed, so that the electronic device enters the power-on state.

[0059] In this embodiment, timing is performed after the enumeration is completed to determine the duration. If the duration reaches the target duration, the operating system of the electronic device is started based on the boot system, and the electronic device enters the power-on state. This provides a certain amount of time for security verification of the device connected to the target second peripheral interface, increasing the number of devices that can be verified and thus improving security. On the other hand, if a problem occurs during the security verification process and the security verification cannot continue, the subsequent security verification process can be skipped, and the operating system of the electronic device can be started based on the boot system, avoiding boot failure or excessive boot time.

[0060] In some embodiments of this application, such as Figure 3 As shown, the control method further includes the following steps: Step S201: When the electronic device is powered on and there is an operation to insert a hot-swappable device into the first peripheral interface, the hot-swappable device connected to the first peripheral interface is securely verified through the system management bus using the target verification method.

[0061] In this embodiment, some first peripheral interfaces support the insertion of hot-swappable devices. For example, when the first peripheral interface is a PCIe interface, the hot-swappable device may include any one of the following: storage device, network device, computing accelerator card, etc.

[0062] If the electronic device is powered on and there is an operation to insert a hot-swappable device into the first peripheral interface, it is determined whether the hot-swappable device supports security verification via the system management bus using target verification. If it does, security verification is performed via the system management bus using target verification to determine if the hot-swappable device poses a security risk. At this time, because the reset signal of the first peripheral interface is held, the first peripheral interface is in an disabled state, the hot-swappable device cannot work, and is in an isolated state.

[0063] Step S202: If the hot-swappable device connected to the first peripheral interface is successfully verified, the first controller releases the reset signal of the first peripheral interface, so that the first peripheral interface is in an enabled state.

[0064] In this embodiment, if the hot-swappable device connected to the first peripheral interface is successfully verified, it indicates that the hot-swappable device has no security risk. The first controller releases the reset signal of the first peripheral interface, so that the first peripheral interface is in an enabled state.

[0065] Because the first controller maintains the reset signal of each first peripheral interface after the external power is turned on or the DC power is turned off, it can isolate the hot-swappable device before it is inserted, which improves safety. The system management bus performs safety verification on the hot-swappable device in a target verification manner. After the verification is passed, the corresponding reset signal is released, so that the hot-swappable device without safety risks can operate normally.

[0066] In some embodiments of this application, such as Figure 4 As shown, the control method further includes the following steps: Step S203: If the hot-swappable device connected to the first peripheral interface does not support security verification via the system management bus using the target verification method, the first controller releases the reset signal of the first peripheral interface, thereby enabling the first peripheral interface.

[0067] In this embodiment, some hot-swappable devices may not support security verification via the system management bus using the target verification method. For these hot-swappable devices, the first controller can first release the reset signal of the first peripheral interface to enable the first peripheral interface, thereby enabling the hot-swappable device to operate normally.

[0068] In some embodiments of this application, such as Figure 5 As shown, the control method further includes the following steps: Step S204: When the hot-swappable device connected to the first peripheral interface does not support security verification via the system management bus using the target verification method, and the reset signal of the first peripheral interface has been released, security verification of the first peripheral interface is performed via the first bus using the target verification method. The first bus connects each of the first peripheral interfaces.

[0069] In this embodiment, some hot-swappable devices that do not support security verification via the system management bus using target verification may support security verification via the first bus using target verification. If the hot-swappable device connected to the first peripheral interface does not support security verification via the system management bus using target verification, and the reset signal of the first peripheral interface has been released, it is determined whether the hot-swappable device supports security verification via the first bus using target verification. If it does, then security verification of the hot-swappable device is performed via the first bus using target verification.

[0070] Step S205: If the verification of the hot-swappable device connected to the first peripheral interface fails, the first controller maintains the reset signal of the first peripheral interface, so that the first peripheral interface changes from an enabled state to an disabled state.

[0071] In this embodiment, if the verification fails, it indicates that the hot-swappable device has a security risk. The first controller maintains the reset signal of the first peripheral interface, so that the first peripheral interface changes from the enabled state to the disabled state.

[0072] In this way, by using the first bus to perform target verification on hot-pluggable devices that have released the corresponding reset signal but do not support the system management bus for target verification, security verification is performed. If the verification fails, the reset signal is restored, which further improves security.

[0073] To further illustrate the technical concept of this application, the technical solution will now be explained in conjunction with specific application scenarios.

[0074] This application provides a control method applied to an electronic device including a BMC, an FPGA, a backplane PSoC (i.e., a first controller), and multiple PCIe interfaces. The BMC is the executing entity of this control method. Figure 6 and Figure 7 As shown, it includes the following steps: Step S301: Connect the external power supply or disconnect the DC power supply.

[0075] Step S302: The PERST signal of all PCIe interfaces is maintained by the FPGA and the backplane PSoC.

[0076] Step S303: When the PCIe interface is in the device connection state, perform SPDM verification on the device connected to the PCIe interface through SMBUS, and add a first mark to the device that fails the verification.

[0077] In this embodiment, it is determined whether the device connected to the PCIe interface supports SPDM verification via SMBUS. If it does, SPDM verification is performed on the device via SMBUS, and a first mark is added to the device that fails verification, and the FPGA and the backplane PSoC are notified.

[0078] Step S304: Power-on command received.

[0079] Step S305: Is it necessary to turn on the DC power supply after completing the security verification of all devices connected to the target first PCIe interface? If yes, proceed to step S306; otherwise, proceed to step S307.

[0080] The target is that the device connected to the first PCIe interface supports SPDM verification via SMBUS.

[0081] Step S306: Wait for the security verification of all target devices connected to the first PCIe interface to be completed.

[0082] Step S307: Turn on the DC power supply.

[0083] Step S308: Release the PERST signal of the PCIe interface of the connected device that has not been marked with the first tag via the FPGA and the backplane PSoC.

[0084] Step S309: Enumerate each PCIe interface based on UEFI.

[0085] Step S310: Determine the target second PCIe interface and execute step S313.

[0086] The device connected to the second PCIe interface of the target device has not been marked with the first tag and supports SPDM verification via the PCIe bus.

[0087] Step S311: Is it necessary to load the operating system via UEFI after completing the security verification of all devices connected to the target second PCIe interface? If yes, proceed to step S313; otherwise, proceed to step S312.

[0088] Step S312: Load the operating system via UEFI.

[0089] Step S313: Perform SPDM verification on the device connected to the target second PCIe interface via the PCIe bus.

[0090] Step S314: In the event of verification failure, maintain the PERST signal of the corresponding PCIe interface through the FPGA and the backplane PSoC.

[0091] Step S315: Determine whether security verification of all devices connected to the target second PCIe interface has been completed. If yes, proceed to step S316; otherwise, proceed to steps S313 and S317.

[0092] Step S316: Grant UEFI permission to load the operating system, then execute step S312. Step S317: Has a timeout occurred? If yes, proceed to step S312; otherwise, proceed to step S313.

[0093] In this embodiment, the duration of the enumeration is determined. If the duration reaches the target duration, a timeout is determined; otherwise, no timeout is determined.

[0094] By applying the above technical solutions, the PERST signal of all PCIe interfaces is maintained when the external power supply is connected or the DC power supply is disconnected. During the power-on process of the electronic device, only the PERST signal of the PCIe interface that has not experienced verification failure is released, thus isolating the PCIe interface device that failed verification during the power-on process and improving the security of the electronic device. After the DC power supply is turned on, the device connected to the target second PCIe interface is re-verified through the PCIe bus, and the PERST signal of the target second PCIe interface corresponding to the device that failed verification is maintained again, further improving security. Based on UEFI, the operating system of the electronic device is booted, enabling the electronic device to enter the power-on state. This achieves the goal of isolating the PCIe interface device that failed verification while allowing the electronic device to start normally, improving the user experience.

[0095] This application also proposes a control method applied to an electronic device including a BMC, an FPGA, a backplane PSoC (i.e., a first controller), and multiple PCIe interfaces. The BMC is the executing entity of this control method. Figure 8 As shown, it includes the following steps: Step S401: A hot-plugged device is detected inserted into the PCIe interface.

[0096] Step S402: Determine whether the hot-swappable device supports SPDM verification via SMBUS. If yes, proceed to step S403; otherwise, proceed to step S406.

[0097] Step S403: Perform SPDM verification on the hot-swappable device via SMBUS.

[0098] Step S404: If the verification is successful, release the PERST signal of the PCIe interface where the hot-swappable device is located through the system FPGA and the backplane PSoC.

[0099] Step S405, End.

[0100] Step S406: Release the PERST signal of the PCIe interface where the hot-swappable device is located through the system FPGA and the backplane PSoC.

[0101] Step S407: Determine whether the hot-swappable device supports SPDM verification via the PCIe bus. If yes, proceed to step S408; otherwise, proceed to step S405.

[0102] Step S408: Perform SPDM verification on the hot-swappable device via the PCIe bus.

[0103] In step S409, if the verification fails, the PERST signal of the PCIe interface where the hot-swappable device is located is maintained through the system FPGA and the backplane PSoC.

[0104] By applying the above technical solutions, the system FPGA and backplane PSoC maintain the PERST signal of each PCIe interface after the external power supply is connected or the DC power supply is disconnected. This allows for initial isolation of hot-swappable devices, improving security. Furthermore, security verification of hot-swappable devices is performed via SMBUS using SPDM verification. Upon successful verification, the corresponding PERST signal is released, allowing hot-swappable devices without security risks to operate normally. For hot-swappable devices that have released their corresponding PERST signals but do not support SMBUS SPDM verification, security verification is performed via the PCIe bus. If verification fails, the PERST signal is re-established, further enhancing security.

[0105] This application also proposes an electronic device, such as... Figure 9As shown, the device includes a baseboard management controller, multiple first peripheral interfaces, a first controller, and a system management bus. The baseboard management controller is configured to: in response to connecting or disconnecting an external power supply or a DC power supply, maintain the reset signal of each first peripheral interface of the electronic device through the first controller, so that each first peripheral interface is in an disabled state; when the first peripheral interface is in a device connection state, perform security verification on the device connected to the first peripheral interface in a target verification manner through the system management bus of the electronic device; if the verification of the device connected to the first peripheral interface fails, add a first mark to the device connected to the first peripheral interface; if a power-on command is received, turn on the DC power supply of the electronic device; and release the reset signal of a second peripheral interface through the first controller, so that the second peripheral interface is in an enabled state, wherein the second peripheral interface is the first peripheral interface of the connected device that has not added the first mark.

[0106] The electronic device of this application embodiment utilizes a baseboard management controller to maintain the reset signals of all first peripheral interfaces when the external power supply is turned on or the DC power supply is turned off, and releases the reset signals of only the first peripheral interfaces that have not failed verification during the power-on process of the electronic device, thereby isolating the peripheral interface devices that have failed verification during the power-on process and improving the security of the electronic device.

[0107] Other embodiments of the electronic device described in this application may be found in the corresponding embodiments of the control method described in this application.

[0108] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0109] The above embodiments are merely exemplary embodiments of this application and are not intended to limit this application. The scope of protection of this application is defined by the claims. Those skilled in the art can make various modifications or equivalent substitutions to this application within its substance and scope of protection, and such modifications or equivalent substitutions should also be considered to fall within the scope of protection of this application.

Claims

1. A control method, comprising: In response to connecting or disconnecting the external power supply, the first controller of the electronic device maintains the reset signal of each of the first peripheral interfaces of the electronic device, so that each of the first peripheral interfaces is in an disabled state. When the first peripheral interface is in a device connection state, the device connected to the first peripheral interface is securely verified through the system management bus of the electronic device in a target verification manner. If the device connected to the first peripheral interface fails to be verified, a first mark is added to the device connected to the first peripheral interface; If a power-on command is received, the DC power supply of the electronic device is turned on; The first controller releases a reset signal for the second peripheral interface, enabling the second peripheral interface. The second peripheral interface is the first peripheral interface of the connected device that has not been marked with the first tag.

2. The control method as described in claim 1, further comprising, after releasing the reset signal of the second peripheral interface through the first controller to enable the second peripheral interface: The device connected to the second peripheral interface is securely verified through the first bus of the electronic device in the target verification method, wherein the first bus connects to each of the first peripheral interfaces. If the device connected to the second peripheral interface fails to be verified, the first controller maintains the reset signal of the second peripheral interface, so that the second peripheral interface changes from the enabled state to the disabled state. The operating system of the electronic device is started based on the boot system, so that the electronic device enters the power-on state.

3. The control method as described in claim 1, further comprising, before turning on the DC power supply of the electronic device: Determine whether security verification of all devices connected to the target first peripheral interface has been completed, wherein the devices connected to the target first peripheral interface support security verification via the system management bus using the target verification method; After completing security verification of all devices connected to the target first peripheral interface, the step of turning on the DC power supply of the electronic device is performed.

4. The control method as described in claim 2, further comprising, after turning on the DC power supply of the electronic device: The boot system enumerates each of the first peripheral interfaces; Upon completion of the enumeration, the step of performing security verification on the device connected to the second peripheral interface via the first bus of the electronic device in the target verification manner is executed.

5. The control method as described in claim 4, further comprising, before starting the operating system of the electronic device based on the boot system to put the electronic device into a power-on state: Determine whether security verification of all devices connected to the target second peripheral interface has been completed, wherein the devices connected to the target second peripheral interface support security verification via the first bus in the target verification method; After completing security verification of all devices connected to the target secondary peripheral interface, the boot system is granted permission to launch the operating system of the electronic device.

6. The control method of claim 4, further comprising, before starting the operating system of the electronic device based on the boot system to put the electronic device into a power-on state: Determine the duration for completing the enumeration; If the duration reaches the target duration, the step of starting the operating system of the electronic device based on the boot system is executed, so that the electronic device enters the power-on state.

7. The control method as described in claim 1, further comprising: When the electronic device is powered on and there is an operation to insert a hot-swappable device into the first peripheral interface, the hot-swappable device connected to the first peripheral interface is securely verified through the system management bus using the target verification method. If the hot-swappable device connected to the first peripheral interface is successfully verified, the first controller releases the reset signal of the first peripheral interface, thereby enabling the first peripheral interface.

8. The control method as described in claim 7, further comprising: If the hot-swappable device connected to the first peripheral interface does not support security verification via the system management bus using the target verification method, the first controller releases the reset signal of the first peripheral interface, thereby enabling the first peripheral interface.

9. The control method as described in claim 8, further comprising: When the hot-swappable device connected to the first peripheral interface does not support security verification via the system management bus using the target verification method, and the reset signal of the first peripheral interface has been released, the first peripheral interface is securely verified via the first bus using the target verification method, and the first bus connects each of the first peripheral interfaces; If the verification of the hot-swappable device connected to the first peripheral interface fails, the first controller maintains the reset signal of the first peripheral interface, causing the first peripheral interface to change from an enabled state to an disabled state.

10. An electronic device comprising a baseboard management controller, a plurality of first peripheral interfaces, a first controller, and a system management bus, wherein the baseboard management controller is configured to: In response to connecting or disconnecting the external power supply, the first controller of the electronic device maintains the reset signal of each of the first peripheral interfaces of the electronic device, so that each of the first peripheral interfaces is in an disabled state. When the first peripheral interface is in a device connection state, the device connected to the first peripheral interface is securely verified through the system management bus of the electronic device in a target verification manner. If the device connected to the first peripheral interface fails to be verified, a first mark is added to the device connected to the first peripheral interface; If a power-on command is received, the DC power supply of the electronic device is turned on; The first controller releases a reset signal for the second peripheral interface, enabling the second peripheral interface. The second peripheral interface is the first peripheral interface of the connected device that has not been marked with the first tag.