TPCM authentication trusted starting method and device based on X86 platform and storage medium
By adding a TPCM trigger verification circuit and an SPI switching circuit to the motherboard hardware circuit of the X86 platform, and combining UEFI firmware with an external TPCM module, the problem of lacking TPCM authentication boot on the X86 platform is solved, and the integrity and security reliability of the boot chain are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING HELISHI SYST INTEGRATION CO LTD
- Filing Date
- 2025-12-03
- Publication Date
- 2026-05-08
AI Technical Summary
Existing technologies struggle to introduce a startup control mechanism with TPCM as the root of trust on the x86 platform. They lack a proactive TPCM measurement and power supply timing coordination control mechanism during the initial power-on phase, and a secondary trusted authentication and startup control mechanism during the system restart phase.
By adding a TPCM trigger verification circuit and an SPI switching circuit to the motherboard hardware circuit of the X86 platform, and by utilizing UEFI firmware to cooperate with an external TPCM module, active measurement and encryption operations are introduced during the first power-on and system restart processes to achieve TPCM-certified trusted boot.
The TPCM authentication boot mechanism is introduced on the x86 platform to improve the integrity of the boot chain and enhance the security and reliability of the first power-on and restart process.
Smart Images

Figure CN121997327A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial control trusted technology, and in particular to a TPCM authentication trusted boot method, device and storage medium based on the x86 platform. Background Technology
[0002] With the increasing demands for network security and trusted computing from industrial control, cloud computing, and IoT devices, boot systems based on roots of trust are gradually becoming a critical foundational capability. The Trusted Platform Control Module (TPCM), as a security chip or equivalent hardware module embedded in computing devices, can measure and verify the boot firmware during the device's power-on startup process, and is an important component of the domestic trusted computing system. A typical trusted boot process generally involves the TPCM powering on first, performing a self-test, and then performing a step-by-step integrity measurement of the boot firmware, bootloader, and operating system kernel, thereby gradually establishing a chain of trust during system startup.
[0003] Currently, most trusted boot solutions in the industrial control field are deployed on main control platforms that use domestic central processing units (CPUs), such as processors based on certain domestic instruction architectures. By reserving interfaces that conform to the TPCM standard in the chip or on the motherboard, the TPCM can suspend the processor reset during the initial power-on phase, prioritize access to the boot flash memory, perform measurement and verification of the basic input / output system or boot firmware, and trigger the trusted authentication process again during the system restart phase to achieve consistent control of the boot software environment.
[0004] However, in common international brand x86 architecture processor platforms (such as some existing Intel processors), security modules that conform to international Trusted Platform Module (TPCM) standards are typically integrated, without built-in hardware units that conform to domestic TPCM standards. Existing motherboard designs also generally lack boot timing control circuitry and switchable boot flash memory access paths reserved for external TPCMs. Existing trusted boot solutions based on domestically produced central processing units are difficult to directly port to such x86 platforms. This makes it difficult to introduce an active measurement and authentication mechanism based on TPCM as the root of trust during initial power-on and system restart on these platforms, hindering the achievement of the certified trusted boot requirements under a unified domestic trusted computing system. Summary of the Invention
[0005] In view of this, the present application provides a TPCM-authenticated trusted boot method, apparatus and storage medium based on the x86 platform to solve the problems of existing technologies, such as the difficulty in introducing a boot control mechanism with TPCM as the root of trust on the x86 platform, the lack of a TPCM active measurement and power supply timing coordination control mechanism in the initial power-on stage, and the lack of a secondary trusted authentication and boot control mechanism in the system restart stage.
[0006] A first aspect of this application provides a TPCM-based trusted boot method for an x86 platform, comprising: upon initial power-on, controlling a switchable interface circuit to be in a first connected state connecting the flash memory and the SPI interface of the TPCM; a trigger verification circuit outputting a reset trigger signal to the TPCM, causing the TPCM to read boot firmware from the flash memory through the first connected state and perform integrity verification on the boot firmware to obtain an initial power-on verification result; when the initial power-on verification result indicates that the boot firmware has passed verification, controlling the nuclear power supply circuit to supply power to the central processing unit, and controlling the switchable interface circuit to switch to a second connected state connecting the flash memory and the SPI interface of the central processing unit, causing the central processing unit to load and... The system executes the boot firmware to complete the initial power-on boot control. During system restart, the switchable interface circuit is kept in the second connected state, allowing the CPU to read the boot firmware from flash memory and enter a suspended state. In the suspended state, the trigger verification circuit outputs a reset trigger signal to the TPCM again and controls the switchable interface circuit to switch to the first connected state, allowing the TPCM to read the boot firmware from flash memory through the first connected state and perform integrity verification on the boot firmware to obtain the restart verification result. When the restart verification result indicates that the boot firmware has passed the verification, the switchable interface circuit is restored to the second connected state, allowing the CPU to continue loading and executing the boot firmware from flash memory through the second connected state to complete the boot control of the system restart process.
[0007] A second aspect of this application provides a TPCM-certified trusted boot device based on an x86 platform, comprising: a power-on module, configured to, upon initial power-on, control a switchable interface circuit to be in a first connected state connecting the flash memory and the SPI interface of the TPCM, and a trigger verification circuit to output a reset trigger signal to the TPCM, causing the TPCM to read boot firmware from the flash memory through the first connected state and perform integrity verification on the boot firmware to obtain an initial power-on verification result; and a power supply module, configured to, when the initial power-on verification result indicates that the boot firmware has passed verification, control a nuclear power supply circuit to supply power to the central processing unit, and control the switchable interface circuit to switch to a second connected state connecting the flash memory and the SPI interface of the central processing unit, causing the central processing unit to load and execute the boot firmware from the flash memory through the second connected state. The system consists of four modules: a firmware update module for initial power-on startup control; a restart module for maintaining the switchable interface circuit in the second connected state during system restart, allowing the CPU to read the startup firmware from flash memory and enter a suspended state; a switching module for outputting a reset trigger signal to the TPCM again during the suspended state and controlling the switchable interface circuit to switch to the first connected state, allowing the TPCM to read the startup firmware from flash memory through the first connected state and perform integrity verification on the startup firmware to obtain a restart verification result; and a startup module for restoring the switchable interface circuit to the second connected state when the restart verification result indicates that the startup firmware has passed the verification, allowing the CPU to continue loading and executing the startup firmware from flash memory through the second connected state to complete the system restart process.
[0008] A third aspect of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the computer program to implement the steps of the above-described method.
[0009] A fourth aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described method.
[0010] The above-described technical solutions adopted in the embodiments of this application can achieve the following beneficial effects: Upon initial power-up, the switchable interface circuit is controlled to enter a first connectivity state, connecting the flash memory to the SPI interface of the TPCM. A reset trigger signal is output to the TPCM via the trigger verification circuit, causing the TPCM to read the boot firmware from the flash memory and perform integrity verification, thus obtaining the initial power-up verification result. When the initial power-up verification result indicates that the boot firmware has passed verification, the nuclear power supply circuit is controlled to supply power to the central processing unit (CPU), and the switchable interface circuit is controlled to switch to a second connectivity state, connecting the flash memory to the SPI interface of the CPU. This allows the CPU to load and execute the boot firmware from the flash memory via the second connectivity state, completing the initial power-up control. During system restart, the switchable interface circuit is kept in the second connected state, allowing the central processing unit (CPU) to read the boot firmware from flash memory and enter a suspended state. In the suspended state, the trigger verification circuit outputs a reset trigger signal to the TPCM again and controls the switchable interface circuit to switch to the first connected state. This allows the TPCM to read the boot firmware from flash memory through the first connected state and perform integrity verification on the boot firmware, obtaining a restart verification result. When the restart verification result indicates that the boot firmware has passed the verification, the switchable interface circuit is restored to the second connected state, allowing the CPU to continue loading and executing the boot firmware from flash memory through the second connected state, thus completing the boot control of the system restart process. This application introduces a TPCM-certified boot mechanism into the x86 platform, improving the integrity of the boot chain and enhancing the security and reliability of the first power-on and restart processes. Attached Figure Description
[0011] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0012] Figure 1 This is a schematic diagram of the system architecture and principle provided in the embodiments of this application; Figure 2 This is a flowchart illustrating the TPCM authentication trusted boot method based on the X86 platform provided in the embodiments of this application; Figure 3 This is a schematic diagram of the structure of the TPCM authentication trusted boot device based on the X86 platform provided in the embodiments of this application; Figure 4 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0013] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0014] TPCM is a security chip (or equivalent firmware / hardware module) embedded in computing devices (such as servers, computers, and IoT devices), and serves as the "root of trust" in a trusted computing system.
[0015] The Trusted Startup Process (TPCM) is a sophisticated mechanism of step-by-step measurement and verification that ensures that the computing platform is built on a trusted foundation from the moment it is powered on.
[0016] Currently, most trusted authentication boot solutions in the industrial control field are based on domestically produced CPU main control hardware platforms with ARM or LoongArch architectures, and there are no trusted authentication boot solutions based on X86 architecture CPU main control platforms.
[0017] Despite challenges such as motherboard design and ecosystem maturity, TPCM and the proactive immune trusted computing system it represents will become increasingly important in x86 platform applications with high security requirements, driven by growing cybersecurity demands and the development of domestically developed trusted computing technologies.
[0018] The key stages of the trusted boot process for mainstream domestic CPUs are as follows: 1. TPCM priority startup: TPCM is powered on first, performs self-test, and suspends the CPU reset signal; 2. Firmware Verification: TPCM actively measures the integrity of firmware code such as BIOS / UEFI; 3. Bootloader Verification: Release CPU reset and measure the integrity of the bootloader by verified firmware or EMM; 4. OS kernel verification: The integrity of the operating system kernel is measured by a verified bootloader or EMM. 5. Trust chain extension: From TPCM to firmware, bootloader, and OS kernel, trust is measured and passed on level by level. 6. Proactive Immunity: After the system is running, TPCM continuously provides dynamic trust measurement, cryptographic services, etc.
[0019] Currently, common international brand x86 CPUs (such as Intel) typically do not directly integrate hardware modules compliant with the Chinese TPCM standard. These CPUs usually integrate firmware or chips compliant with the international TPM standard. The current mainstream trusted boot solutions for domestic CPUs are not applicable to international brand x86 CPU platforms, and the secondary trusted authentication during system restart cannot be applied to current product designs.
[0020] In addition, common international brand (such as Intel) x86 CPUs do not usually integrate built-in hardware modules that conform to the Chinese TPCM standard. Therefore, the mainstream domestic CPU trusted boot scheme is not applicable to international brand x86 CPU platforms, and the secondary trusted authentication during the system restart phase cannot be applied to the current product design.
[0021] By adding a TPCM trigger verification circuit and an SPI switching circuit to the motherboard hardware circuit, and by utilizing UEFI firmware to cooperate with an external TPCM module, active measurement and encryption operations are introduced during the first power-on and restart power-on processes of Intel x86 architecture CPUs, thereby achieving product-certified trusted boot functionality.
[0022] In view of the problems existing in the prior art, this application provides a TPCM chip-based trusted boot method for Intel x86 architecture CPUs. The traditional boot sequence of the x86 platform is that the CPU executes BIOS / UEFI code first after power-on. To allow the TPCM to boot before the CPU and gain control, modifications to the motherboard hardware design and close cooperation between the BIOS / UEFI firmware are required. This application introduces active measurement and encryption operations during the first power-on and restart power-on processes of the Intel x86 architecture CPU by adding a TPCM trigger verification circuit and an SPI switching circuit to the motherboard hardware circuit, and by utilizing UEFI firmware in cooperation with an external TPCM module, thereby achieving product-certified trusted boot functionality.
[0023] Before describing the embodiments in detail, the system architecture and principles of this solution in a real-world scenario will be introduced below with reference to the accompanying drawings and embodiments. Figure 1 This is a schematic diagram of the system architecture and principle provided in the embodiments of this application, such as... Figure 1 As shown, the system architecture and principles involved in the TPCM chip authentication trusted boot method of this application include the following: The motherboard's main control platform uses a CPU based on the x86 architecture. The CPU connects to a switchable interface circuit located in the same core power supply domain via the CPU_SPI interface. In this embodiment, the switchable interface circuit is implemented by an analog switch circuit. Its other side is connected to the flash memory chip storing the boot firmware via the FLASH_SPI bus, and to an external TPCM module via the TPCM_SPI bus. By controlling the conduction path of the analog switch, it can switch between two connection states: "FLASH_SPI connected to CPU_SPI" and "FLASH_SPI connected to TPCM_SPI", thereby switching the access rights to the flash memory between the CPU and the TPCM.
[0024] The TPCM module, serving as the trusted root unit in this solution, connects to the switchable interface circuit via the TPCM_SPI interface to directly access the BIOS / UEFI boot firmware stored in the FLASH memory under authorized conditions. The TPCM is also electrically connected to both the trigger verification circuit and the nuclear power supply circuit. On one side, it receives a reset trigger signal from the trigger verification circuit via the RESET signal line; on the other side, it outputs a control signal to the nuclear power supply circuit via the CHECK_OK signal line to characterize the boot firmware verification result. Upon receiving the reset trigger signal, the TPCM initializes itself and reads and verifies the integrity of the boot firmware in the flash memory through the currently connected TPCM_SPI—FLASH_SPI path, driving the CHECK_OK signal based on the verification result.
[0025] The trigger verification circuit is located in the bypass of the motherboard power and control logic. Its input side is connected to the motherboard power-on control or system restart control signal, and its output side is connected to the TPCM module through the RESET signal line. When the motherboard is powered on for the first time or the system is in the software restart process, the trigger verification circuit generates a reset trigger pulse according to the preset timing logic, pulling the TPCM into a controlled initial working state to start the TPCM's reliability measurement process.
[0026] The nuclear power supply circuit provides core power to the CPU and other devices in the same power domain. Its input side receives a reference voltage from the system power supply, and its control side receives the CHECK_OK signal from the TPCM. According to preset logic, the nuclear power supply circuit only outputs nuclear power to the CPU when the CHECK_OK signal indicates that the boot firmware has passed verification; otherwise, it maintains a power-off or reset state for the CPU. This connection ensures that the CPU's power-on and reset are no longer dependent on the TPCM's verification results.
[0027] Based on the above connections, this solution forms a closed control chain at the hardware level: "Trigger Verification Circuit—TPCM—Switchable Interface Circuit—FLASH—Core Power Supply Circuit—CPU". On the one hand, the switchable interface circuit switches the SPI access path to the boot flash memory between the TPCM and the CPU. On the other hand, the CHECK_OK signal output by the TPCM controls the power supply timing of the core power supply circuit to the CPU. Thus, during the motherboard's first power-on and system restart, the TPCM can perform integrity verification on the boot firmware in the flash memory before the CPU obtains the boot firmware or before the CPU continues to execute the boot process, and control the CPU's boot accordingly.
[0028] The technical solution of this application will now be described in detail with reference to the accompanying drawings and specific embodiments.
[0029] Figure 2 This is a flowchart illustrating the TPCM authentication trusted boot method based on the X86 platform provided in this application embodiment. Figure 2 As shown, the TPCM authentication trusted boot method based on the x86 platform may specifically include: S201, when powered on for the first time, the control switchable interface circuit is in the first connected state that connects the flash memory and the SPI interface of the TPCM. The trigger verification circuit outputs a reset trigger signal to the TPCM, so that the TPCM reads the boot firmware from the flash memory through the first connected state and performs integrity verification on the boot firmware to obtain the first power-on verification result. S202, when the initial power-on verification result indicates that the boot firmware has passed the verification, the nuclear power supply circuit is controlled to supply power to the central processing unit, and the switchable interface circuit is controlled to switch to the second connection state that connects the flash memory and the SPI interface of the central processing unit, so that the central processing unit loads and executes the boot firmware from the flash memory through the second connection state to complete the initial power-on boot control. S203, when the system restarts, controls the switchable interface circuit to remain in the second connected state, so that the central processing unit reads the boot firmware from the flash memory and enters the suspended state; S204, in the suspended state, the trigger verification circuit outputs a reset trigger signal to the TPCM again and controls the switchable interface circuit to switch to the first connected state, so that the TPCM can read the boot firmware from the flash memory through the first connected state and perform integrity verification on the boot firmware to obtain the restart verification result. S205, when the restart verification result indicates that the boot firmware has passed the verification, controls the switchable interface circuit to return to the second connected state, so that the central processing unit continues to load and execute the boot firmware from the flash memory through the second connected state to complete the boot control of the system restart process.
[0030] In some embodiments, upon initial power-on, controlling the switchable interface circuit to be in a first connectivity state, connecting the flash memory to the SPI interface of the TPCM, includes: When the motherboard is powered on, the analog switch in the switchable interface circuit is set to be connected to the SPI interface side of the flash memory and disconnected from the SPI interface side of the central processing unit, so that the flash memory is only connected to the SPI interface of the TPCM. When the nuclear power supply circuit does not supply power to the central processing unit, the trigger verification circuit outputs a reset trigger signal to the TPCM, so that the TPCM reads the boot firmware from the flash memory through the first connection state and performs integrity verification on the boot firmware.
[0031] Specifically, in the motherboard hardware design, the switchable interface circuit is arranged as an array of analog switches. One end of the array is connected to the CPU_SPI pin of the CPU and the TPCM_SPI pin of the TPCM, and the other end is connected to the FLASH_SPI pin of the FLASH memory. The control terminal of the analog switch is driven by the control logic circuit on the motherboard or the control pin of the TPCM. During the initial power-on phase, the control terminal is configured by default through pull-up or pull-down resistors, so that the analog switch automatically enters the first connection state of "FLASH_SPI and TPCM_SPI are on, and CPU_SPI is off" after the power-on is stable. In this state, the FLASH is only connected to the SPI interface of the TPCM, and the CPU_SPI side does not form an effective signal path with the FLASH.
[0032] Regarding power timing, the enable pin of the nuclear power supply circuit is connected to the CHECK_OK signal or an equivalent control signal output by the TPCM. Initially, the nuclear power supply circuit remains off, not providing core power to the CPU, keeping the CPU in a power-down and reset hold state. After the motherboard powers on, the main power supply outputs a stable voltage, and the trigger verification circuit detects the motherboard power-on event, for example, by monitoring the rising edge of the main power supply voltage or a power good indication signal. After a preset startup stabilization time delay, the trigger verification circuit outputs a reset trigger pulse that meets the TPCM specifications to the RESET pin of the TPCM.
[0033] Upon receiving the RESET pulse, the TPCM initializes its internal registers and security logic, then enters the firmware verification process. Since the switchable interface circuit is in its first connected state at this time, the TPCM establishes SPI communication with the FLASH via the TPCM_SPI interface and the FLASH_SPI bus. Following the address mapping preset in the firmware, it sequentially reads the code and configuration areas of the BIOS / UEFI boot firmware stored in the FLASH. The TPCM's internal measurement unit performs integrity verification on the read boot firmware data according to a preset algorithm. This includes calculating digests of critical code segments and comparing them with pre-stored reference values, or performing digital signature verification on the entire firmware image.
[0034] In some examples, if a read error or data anomaly is detected during the verification process, the TPCM keeps the CHECK_OK signal disabled. When all predetermined areas have been verified and the results meet the preset verification rules, the TPCM updates its internal state, generates the first power-on verification result, and sets the CHECK_OK signal to an active level when the result indicates that the boot firmware has passed the verification.
[0035] With the CHECK_OK signal active, the nuclear power supply circuit responds to this signal by enabling its output stage, applying the core power supply voltage to the CPU's power pins to power on the CPU. Simultaneously, the motherboard control logic or TPCM drives the control terminal of the switchable interface circuit based on the current state, switching the analog switch from the first connected state to a second connected state: "FLASH_SPI and CPU_SPI are on, but not with TPCM_SPI," releasing TPCM access to the FLASH. At this point, after power-on reset, the CPU accesses the FLASH via the CPU_SPI interface and the switchable interface circuit, loading and executing the BIOS / UEFI boot firmware that has passed TPCM verification, thus entering the subsequent boot program and operating system loading process.
[0036] Through the above embodiments, on a motherboard based on the x86 architecture, by forcing the switchable interface circuit to be in a state of connection between FLASH and TPCM during the first power-on phase, and by triggering the TPCM to complete the boot firmware integrity verification by the trigger verification circuit when the CPU is not powered on, the boot flash memory is measured and controlled by the TPCM before being accessed by the CPU, thereby improving the reliability of the boot firmware and the security of the boot process during the motherboard's first power-on boot process.
[0037] In some embodiments, the trigger verification circuit outputs a reset trigger signal to the TPCM, causing the TPCM to read the boot firmware from the flash memory through a first connected state and perform integrity verification on the boot firmware to obtain the first power-on verification result, including: During the motherboard power-on process, the trigger verification circuit generates a reset trigger signal with a preset timing based on the power-on status signal and outputs it to the TPCM. After receiving the reset trigger signal, the TPCM completes its own initialization, establishes SPI communication with the flash memory through the first connectivity state, reads the boot firmware data stored in the flash memory in the order of the preset address range, and performs integrity verification on the boot firmware data based on the preset verification strategy, generating the first power-on verification result to indicate whether the boot firmware has passed the verification.
[0038] Specifically, during the initial power-on phase, a trigger verification circuit controls the TPCM to perform a controlled triggering process, enabling the TPCM to complete the integrity verification of the boot firmware after gaining access to the flash memory. For example, the input of the trigger verification circuit on the motherboard is connected to the power-on status signal output by the main power module. This power-on status signal can be a power-good indication signal or a power-on stability flag generated by a voltage detection circuit. The output of the trigger verification circuit is connected to the reset control pin of the TPCM via a RESET signal line. This pin outputs a preset timing reset trigger pulse to the TPCM after detecting that the motherboard is in the initial power-on process and the power supply is stable. Through this connection method, the TPCM's startup timing and reset timing are uniformly controlled by the trigger verification circuit, coordinating with the CPU's power-on and SPI switching logic.
[0039] In some examples, the trigger verification circuit can be implemented using a power monitoring chip in conjunction with an RC delay network and simple logic gates. The power monitoring chip detects that the main power supply voltage has reached the rated range and remains stable. When the power supply voltage is unstable, it maintains its reset output at a valid level to disable the TPCM. When the power supply voltage is detected to be stable and remains so for a predetermined time, the power monitoring chip generates a valid level flip at its output. This flip signal is converted into a narrow pulse or fixed-width reset waveform that conforms to the TPCM datasheet requirements after RC delay and shaping circuitry. This waveform is then sent to the TPCM as a reset trigger signal through the RESET signal line, causing the TPCM to be pulled into the initialization process at a preset time after the power supply stabilizes. For scenarios that require distinguishing between the first power-on and system restart, the trigger verification circuit can also logically combine the power-on status signal with the restart flag signal from the restart control circuit, outputting the corresponding reset trigger timing only when the motherboard is detected to be in the first power-on path, thereby avoiding accidental TPCM reset during other operating phases.
[0040] Upon receiving a reset trigger signal, the TPCM first performs clearing and initialization operations on its internal registers and security logic to reset its own operating state. After initialization, the TPCM enables its TPCM_SPI interface according to a preset configuration and establishes an SPI communication connection with the FLASH through the switchable interface circuit currently in the first connected state. The TPCM internally stores address mapping information describing the storage location of the boot firmware in the FLASH and the corresponding verification strategy, such as the starting address, length, block size, and reference digest value or overall signature value of the firmware image. Following this address mapping, the TPCM drives the TPCM_SPI interface to sequentially read the boot firmware data from the preset address range of the FLASH. During the reading process, a block-based reading method can be used, temporarily storing each block of data in an internal cache or a dedicated measurement register.
[0041] While completing data reading, the TPCM performs integrity verification on the boot firmware data according to a preset verification strategy. For example, in some implementations, the TPCM calculates a message digest for each data block and compares it with a pre-stored reference digest value; in another implementation, the TPCM calculates a hash value for the overall image of the boot firmware and uses an internal security unit to verify the pre-stored signature, thereby confirming that the firmware image has not been tampered with. When all address ranges to be verified have been verified and the results meet the preset conditions, the TPCM internally generates an initial power-on verification result indicating that the verification has passed and maps this result to the valid state of the CHECK_OK output signal; if any block verification fails or the overall signature verification fails, the TPCM generates an initial power-on verification result indicating that the verification has failed and keeps the CHECK_OK output in an invalid or fault state so that subsequent power management logic can block the CPU from powering on.
[0042] Through the design of this embodiment, during the first power-on process of the motherboard, the trigger verification circuit can output a reset trigger signal to the TPCM in a controlled timing sequence after the power supply stabilizes. This ensures that the TPCM completes its initialization when the switchable interface circuit is in the first connected state and the CPU has not yet been powered on. It also performs integrity verification on the boot firmware through SPI communication with the FLASH, thereby realizing the boot firmware reliability measurement based on the power-on status signal at the hardware level. This is beneficial to improving the reliability and anti-tampering capability of the boot firmware data during the first power-on, laying the foundation for the subsequent reliable boot of the CPU.
[0043] In some embodiments, controlling the switchable interface circuit to switch to a second connectivity state that connects the flash memory to the SPI interface of the central processing unit, so that the central processing unit loads and executes the boot firmware from the flash memory through the second connectivity state, including: When the initial power-on verification result indicates that the boot firmware has passed the verification, the TPCM outputs a control signal for power supply to the nuclear power supply circuit based on the initial power-on verification result, so that the nuclear power supply circuit supplies power to the central processing unit. During the process of powering on and resetting the central processing unit, the switchable interface circuit is controlled to switch from the first connected state to the second connected state, so that the central processing unit establishes SPI communication with the flash memory through the second connected state, loads the boot firmware from the flash memory according to the preset boot sequence, and executes the boot firmware.
[0044] Specifically, after the TPCM performs integrity verification on the boot firmware in the flash memory through the first connectivity state and generates the first power-on verification result, the TPCM is responsible for driving the central processing unit to power on and releasing control over the boot flash memory access path.
[0045] In some examples, the CHECK_OK output of the TPCM is electrically connected to the enable control terminal of the nuclear power supply circuit, and the output of the nuclear power supply circuit is connected to the core power supply pin of the central processing unit. When the initial power-on verification result indicates that the boot firmware has passed the verification, the internal state machine of the TPCM sets the CHECK_OK signal to an active level. After detecting that CHECK_OK is active, the nuclear power supply circuit enables its output stage and applies a predetermined nuclear power voltage to the power supply pin of the central processing unit, thereby causing the central processing unit to transition from the power-down reset state to the power-on reset process.
[0046] To ensure exclusive access to flash memory by the TPCM before the CPU powers on, the switchable interface circuit remains in the first connected state until the CHECK_OK signal is valid. This means the analog switch connects the FLASH_SPI and TPCM_SPI paths but disconnects the CPU_SPI path. After the nuclear power supply circuit begins supplying power to the CPU, the CPU completes level stabilization and clock initialization via its internal power-on reset circuit. Simultaneously, the control logic circuit on the motherboard monitors the power good indicator signal from the nuclear power supply circuit and the valid CHECK_OK status output by the TPCM. When it determines that the CPU power supply voltage is stable and startup is permitted, it outputs a state toggle signal to the control terminal of the analog switch via a control pin, switching the switchable interface circuit from the first connected state to the second connected state.
[0047] Furthermore, in the second connected state, the analog switch connects the FLASH_SPI and CPU_SPI paths, and sets the TPCM_SPI port to an off or high-impedance state, so that the flash memory is only connected to the CPU's SPI interface. At this time, after the CPU is reset, according to its internally programmed boot process, it sends a read command to the FLASH via the CPU_SPI interface, sequentially reads the BIOS / UEFI boot firmware image stored in the FLASH according to the preset boot order, loads the key boot code and configuration data into the internal cache or off-chip memory, and begins executing the boot firmware to complete low-level hardware initialization, peripheral configuration, and bootloader loading. Since the TPCM has previously performed integrity verification on the boot firmware within the same address range and the verification result is successful, the CPU actually loads and executes the firmware content that has been confirmed as complete and reliable by the TPCM.
[0048] Through the design of this embodiment, when the initial power-on verification result indicates that the boot firmware has passed the verification, the TPCM drives the nuclear power supply circuit to supply power to the central processing unit and, in conjunction with the switchable interface circuit, completes the controlled switching from the first connected state to the second connected state. This ensures that the central processing unit can only obtain SPI access to the flash memory and load and execute the boot firmware if the verification is passed. Thus, at the hardware level, the coordinated control of the boot power supply timing and the boot firmware access path is realized, improving the security and boot chain reliability of the initial power-on boot process of the motherboard based on the X86 platform.
[0049] In some embodiments, during system restart, controlling the switchable interface circuit to remain in the second connected state, causing the central processing unit to read the boot firmware from flash memory and enter a suspended state, including: Upon receiving a system restart command, the nuclear power supply circuit continues to supply power to the central processing unit (CPU), and the switchable interface circuit is controlled to remain in the second connected state. This allows the CPU to read at least part of the boot code from the flash memory through the second connected state after a reset, execute a preset restart initialization operation based on the boot code, and stop the subsequent boot process when it reaches the preset suspension point, entering a suspended state.
[0050] Specifically, regarding the system's operation in a software restart scenario, the implementation method of the CPU entering a suspended state while maintaining power supply is explained. The motherboard includes a CPU, flash memory, a switchable interface circuit, a TPCM (Through-Time Processing Unit), a trigger verification circuit, and a core power supply circuit. During normal system operation, the core power supply circuit provides a stable core power supply to the CPU, and the switchable interface circuit is in a second connected state, enabling the flash memory to connect to the CPU's CPU_SPI interface via FLASH_SPI.
[0051] When the operating system or upper-layer application issues a system restart command, the restart control logic first sends a reset request to the central processing unit (CPU). Upon receiving the restart command, the CPU performs pre-shutdown cleanup operations and generates a reset signal through internal or external restart control circuitry. Throughout the restart process, the nuclear power supply circuit does not cut off power to the CPU but maintains continuous power output, keeping the CPU in a powered-on reset state. Simultaneously, the motherboard control logic does not change the current configuration of the switchable interface circuit, keeping it in the second connected state. That is, FLASH_SPI remains connected to CPU_SPI but disconnected from TPCM_SPI, thus ensuring that the CPU can still directly access the flash memory after the reset.
[0052] After the central processing unit (CPU) completes its reset, its internal boot process is similar to the initial power-on phase. The CPU reads the entry code of the BIOS / UEFI firmware from the flash memory via the CPU_SPI interface and a switchable interface circuit, loads and executes this boot code. To achieve a suspended state, this embodiment adds a dedicated initialization process for the reboot path to the BIOS / UEFI firmware. When it is detected that the current boot is a reboot scenario (e.g., by checking a specific reboot flag register or the reboot flag bit stored in the CMOS), the boot code only performs some basic hardware initialization operations and necessary environment recovery operations, such as reconfiguring the clock, bus controller, and interrupt controller. After completing these preset reboot initialization operations, it does not continue to execute the regular bootloader loading process, but jumps to a waiting logic.
[0053] In this waiting logic, the BIOS / UEFI firmware monitors status indicators from the TPCM or motherboard control logic via polling or interrupts, such as reading the verification completion flag mapped to a specific I / O port or memory unit. When the execution flow reaches this waiting logic and begins monitoring the flag, the CPU stops loading more boot code, maintains only the currently initialized runtime environment, and no longer continues executing the regular boot path, thus entering a logically suspended state. At this time, although the CPU is still powered on and running, its boot process has been paused at a preset suspension point, reserving a time window for subsequent TPCM trusted verification and SPI path switching.
[0054] Through the above embodiments, in the system restart scenario, the nuclear power supply circuit continuously supplies power to the central processing unit (CPU), and the switchable interface circuit remains in the second connected state, enabling the CPU to read and execute part of the boot code from the flash memory according to the preset process after reset. At the same time, by setting a specific restart hang point in the BIOS / UEFI, the CPU enters a hang state after completing the necessary restart initialization, providing a controllable pause stage for the subsequent trusted verification of TPCM and the continued execution of the boot process. This facilitates the introduction of TPCM-based secondary authentication control for the restart stage without disrupting the existing restart mechanism of the x86 platform.
[0055] In some embodiments, the TPCM reads the boot firmware from the flash memory through a first connectivity state and performs an integrity check on the boot firmware to obtain a reboot check result, including: In the suspended state, the trigger verification circuit generates a reset trigger signal based on the system restart state and outputs it to the TPCM. After receiving the reset trigger signal, the TPCM completes its own initialization, establishes SPI communication with the flash memory through the first connection state, reads the boot firmware data stored in the flash memory in the order of the preset address range, and verifies the boot firmware data based on the preset integrity verification strategy, generating a restart verification result to indicate whether the boot firmware has passed the verification during the system restart process.
[0056] Specifically, when the system is in a restart suspension state, the TPCM is triggered again by the trigger verification circuit to perform integrity verification on the boot firmware in the flash memory. In some examples, the restart control logic set on the motherboard works in conjunction with the operating system or upper-level software. When the central processing unit completes the aforementioned restart initialization process and stops at the suspension point set by the BIOS / UEFI firmware, the restart control logic generates a system restart status signal according to the current system operating mode. This status signal is input to the trigger verification circuit to indicate that the current stage is the trusted verification stage under the restart path. In this stage, the central processing unit is still powered by the core power supply circuit, but the execution process has stopped at the suspension point and no longer initiates new access requests to the FLASH. The switchable interface circuit has switched to the first connected state according to the control of the previous stage, making FLASH_SPI and TPCM_SPI connected and CPU_SPI disconnected.
[0057] Furthermore, upon receiving the system restart status signal, the trigger verification circuit, in conjunction with the detection results of the main power supply, power good indication, and CPU suspended status flag, generates a reset trigger signal according to a pre-set restart verification timing sequence, and outputs it to the TPCM's reset control pin via the RESET signal line. Similar to the initial power-on phase, the trigger verification circuit can be implemented using a combination of a power monitoring chip, logic gate circuits, and timing circuits. The difference is that, in a restart scenario, its triggering condition is jointly limited by the system restart status signal and the suspended status flag. Only when it is confirmed that the central processing unit has entered the suspended state and the switchable interface circuit has switched to the first connected state will a valid reset trigger pulse be output to avoid erroneous resets of the TPCM during normal operation.
[0058] Furthermore, upon receiving the reset trigger signal, the TPCM executes an internal initialization process, clearing the state information left over from the previous verification process and reconfiguring its internal registers. It then enables the TPCM_SPI interface, establishing an SPI communication path with the FLASH through the switchable interface circuit currently in the first connected state. The TPCM internally stores storage layout information describing the boot firmware image in the FLASH, including the boot firmware's starting address, length, partition boundaries, and a list of address ranges required for reboot verification. Based on this layout information, the TPCM reads the boot firmware data from the FLASH in a preset address range order. It can use a block-based reading method, sequentially importing each block of data into an internal buffer or measurement register, and performing digest calculations or checksum accumulation on each block.
[0059] Furthermore, after fully reading the boot firmware data within the preset address range, the TPCM verifies the read data according to a preset integrity verification strategy. For example, in one implementation, the TPCM calculates the hash value of the critical code segments related to the reboot path and compares it with a reference hash value pre-stored in a secure storage area; in another implementation, the TPCM performs message digest operation on the overall boot firmware image and uses an internal security unit to verify the pre-stored digital signature to determine whether the boot firmware in the flash memory has been tampered with since the last trusted write.
[0060] Based on the verification results, TPCM internally generates a reboot verification result to indicate whether the firmware has passed verification during the system reboot process, stores the result in the internal status register, and updates the exported status flags to provide a basis for the subsequent status recovery of the switchable interface circuit and the continued boot process of the central processing unit.
[0061] The method in this embodiment enables the TPCM to be reset under controlled conditions based on the system restart state, while the central processing unit remains suspended and does not access the flash memory in the system restart scenario. The TPCM then performs an independent integrity check on the boot firmware in the flash memory through the first connectivity state, generating a clear restart check result. This allows for the reliable measurement of the boot firmware during the restart phase without interrupting the CPU power supply, which is beneficial for timely detection of firmware tampering risks during the restart process and improves the reliability and consistency of the system restart path.
[0062] In some embodiments, controlling the switchable interface circuit to return to a second connected state, enabling the central processing unit to continue loading and executing boot firmware from flash memory through the second connected state to complete the boot control of the system restart process, including: When the reboot verification result indicates that the boot firmware has passed the verification, the TPCM outputs a control signal for resuming the boot process based on the reboot verification result. This signal controls the switchable interface circuit to switch from the first connected state to the second connected state and provides a resumption execution instruction to the CPU, which is in a suspended state. This allows the CPU to release the suspended state while maintaining power supply and continue to load the remaining boot firmware from the flash memory and execute the boot firmware through the restored second connected state.
[0063] Specifically, after the TPCM completes the integrity verification of the boot firmware and generates the reboot verification result during the reboot phase, the TPCM takes the lead in restoring the connectivity of the switchable interface circuit and wakes up the central processing unit that is in a suspended state, so that it can continue to complete the reboot boot process.
[0064] In some examples, the TPCM has an internal status register for storing the reboot verification result. When the verification logic determines that the boot firmware data within the preset address range in the flash memory meets the integrity verification rules, the reboot verification result is set to a state indicating that it has passed, and the control logic module outputs a control signal for resuming the boot process on an external pin based on the result.
[0065] The control signal is sent to the control pin connected to the switchable interface circuit to drive the switching of the conduction path of the analog switch. On the other hand, it can be indirectly transmitted to the central processing unit or its accessible status register through the signal line connected to the motherboard control logic or system management bus to trigger the central processing unit to exit the suspended state.
[0066] The switchable interface circuit still uses an analog switch array, with its control terminal connected to the control output pin of the TPCM or the control signal input terminal buffered by the motherboard control logic. When the reboot verification result indicates that the boot firmware has passed the verification, the TPCM sets the control signal used for boot recovery to an active level. Upon detecting this active level, the motherboard control logic outputs a state toggle signal to the control terminal of the analog switch, causing the switchable interface circuit to switch from the first connected state to the second connected state. This disconnects the conduction path between FLASH_SPI and TPCM_SPI, and connects the path between FLASH_SPI and CPU_SPI, thereby restoring the direct connection between the flash memory and the CPU SPI interface. During this switching process, the CPU continues to be powered by the core power supply circuit, but its instruction execution flow remains at the hang point set by the BIOS / UEFI firmware, in a waiting state where it will not continue loading subsequent boot code.
[0067] Furthermore, while outputting control signals to the switchable interface circuit, the TPCM also provides a resumption execution instruction to the CPU through a pre-agreed method. In one implementation, the TPCM generates an external event to the CPU by controlling GPIO pins, level-triggered interrupt pins, or System Management Interrupt (SMI) trigger pins on the motherboard, causing the CPU, which is in a suspended state, to jump out of the waiting loop and execute the firmware logic after the suspension point. In another implementation, the BIOS / UEFI reads the TPCM status register mapped in the I / O port or memory space through polling while in a suspended state. When it detects that the flag bit used to indicate that the restart verification has passed is set, it considers that it has received the resumption execution instruction, thereby ending the suspension waiting process. Regardless of the method used, after confirming that the TPCM verification has passed and the switchable interface circuit has returned to the second connectivity state, the CPU continues to access the boot firmware in the FLASH through the CPU_SPI interface.
[0068] With the suspension state lifted, the central processing unit (CPU) loads the remaining boot firmware code and configuration data from flash memory through the restored second connectivity state according to the preset boot sequence, and continues to execute the subsequent boot process of BIOS / UEFI, including completing peripheral controller initialization, memory detection and configuration, boot device selection, and loading of the operating system bootloader.
[0069] Before entering this stage, the boot firmware in the flash memory has already undergone integrity verification by TPCM through the first connectivity state under the reboot path, and the second connectivity state is restored and the central processing unit is allowed to continue execution only when the reboot verification result is passed. Therefore, the central processing unit actually loads and executes the boot firmware that has been confirmed to be complete and reliable during the reboot process.
[0070] Through the design of this embodiment, in the system restart scenario, when the restart verification result indicates that the boot firmware has passed the verification, the TPCM outputs a recovery boot control signal to drive the switchable interface circuit to switch from the first connected state back to the second connected state, and sends a recovery execution instruction to the central processing unit in the suspended state. This allows the central processing unit to continue loading and executing the remaining boot firmware from the flash memory through the second connected state without interrupting power. Thus, without disrupting the original x86 restart process, the TPCM verification result is closely linked with the SPI access path control and CPU execution recovery, realizing a reliable closed loop of the boot control link in the restart process. This is beneficial to improving the overall security of the system restart process and the consistency of the boot chain.
[0071] The following are embodiments of the apparatus described in this application, which can be used to execute the embodiments of the method described in this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the method described in this application.
[0072] Figure 3 This is a schematic diagram of the structure of the TPCM authentication trusted boot device based on the X86 platform provided in the embodiments of this application. Figure 3 As shown, the TPCM-certified trusted boot device based on the x86 platform includes: The power-on module 301 is used to control the switchable interface circuit to be in the first connected state that connects the flash memory and the SPI interface of the TPCM when the power is first powered on. The trigger verification circuit outputs a reset trigger signal to the TPCM, so that the TPCM reads the boot firmware from the flash memory through the first connected state and performs integrity verification on the boot firmware to obtain the first power-on verification result. The power supply module 302 is used to control the nuclear power supply circuit to supply power to the central processing unit when the initial power-on verification result indicates that the boot firmware has passed the verification, and to control the switchable interface circuit to switch to the second connection state that connects the flash memory and the SPI interface of the central processing unit, so that the central processing unit loads and executes the boot firmware from the flash memory through the second connection state to complete the initial power-on boot control. The restart module 303 is used to control the switchable interface circuit to remain in the second connected state when the system restarts, so that the central processing unit reads the boot firmware from the flash memory and enters the suspended state. The switching module 304 is used to output a reset trigger signal to the TPCM again when the suspend state is in which the trigger verification circuit is in the first connected state, and control the switchable interface circuit to switch to the first connected state, so that the TPCM can read the boot firmware from the flash memory through the first connected state, and perform integrity verification on the boot firmware to obtain the restart verification result. The startup module 305 is used to control the switchable interface circuit to return to the second connected state when the restart verification result indicates that the startup firmware has passed the verification, so that the central processing unit continues to load and execute the startup firmware from the flash memory through the second connected state to complete the startup control of the system restart process.
[0073] In some embodiments, Figure 3 When the motherboard is powered on, the power-on module 301 sets the analog switch in the switchable interface circuit to be connected to the SPI interface side of the flash memory and disconnected from the SPI interface side of the central processing unit, so that the flash memory is only connected to the SPI interface of the TPCM. When the nuclear power supply circuit does not supply power to the central processing unit, the trigger verification circuit outputs a reset trigger signal to the TPCM, so that the TPCM reads the boot firmware from the flash memory through the first connection state and performs integrity verification on the boot firmware.
[0074] In some embodiments, Figure 3 During the motherboard power-on process, the power-on module 301 generates a reset trigger signal with a preset timing based on the power-on status signal by the trigger verification circuit and outputs it to the TPCM. After receiving the reset trigger signal, the TPCM completes its own initialization, establishes SPI communication with the flash memory through the first connection state, reads the boot firmware data stored in the flash memory in the order of the preset address range, and performs integrity verification on the boot firmware data based on the preset verification strategy, generating the first power-on verification result to indicate whether the boot firmware has passed the verification.
[0075] In some embodiments, Figure 3 When the power supply module 302 indicates that the startup firmware has passed the initial power-on verification, the TPCM outputs a control signal for startup power supply to the nuclear power supply circuit based on the initial power-on verification result, so that the nuclear power supply circuit supplies power to the central processing unit. During the process of powering on and resetting the central processing unit, the switchable interface circuit is controlled to switch from the first connected state to the second connected state, so that the central processing unit establishes SPI communication with the flash memory through the second connected state, loads the startup firmware from the flash memory according to the preset startup sequence, and executes the startup firmware.
[0076] In some embodiments, Figure 3 When the restart module 303 receives the system restart command, it keeps the nuclear power supply circuit continuously supplying power to the central processing unit and controls the switchable interface circuit to remain in the second connected state. This allows the central processing unit to read at least part of the boot code of the boot firmware from the flash memory through the second connected state after reset, execute the preset restart initialization operation according to the boot code, and stop the subsequent boot process when it reaches the preset suspension point and enters the suspension state.
[0077] In some embodiments, Figure 3In the suspended state, the switching module 304 generates a reset trigger signal based on the system restart state through the trigger verification circuit and outputs it to the TPCM. After receiving the reset trigger signal, the TPCM completes its own initialization, establishes SPI communication with the flash memory through the first connection state, reads the boot firmware data stored in the flash memory in the order of the preset address range, and verifies the boot firmware data based on the preset integrity verification strategy, generating a restart verification result to indicate whether the boot firmware has passed the verification during the system restart process.
[0078] In some embodiments, Figure 3 When the reboot verification result indicates that the boot firmware has passed the verification, the boot module 305 outputs a control signal for resuming boot based on the reboot verification result. This control the switchable interface circuit to switch from the first connected state to the second connected state and provides a resumption execution instruction to the central processing unit (CPU) which is in a suspended state. This allows the CPU to release the suspended state while maintaining power supply and continue to load the remaining boot firmware from the flash memory and execute the boot firmware through the restored second connected state.
[0079] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0080] Figure 4 This is a schematic diagram of the electronic device 4 provided in an embodiment of this application. Figure 4 As shown, the electronic device 4 of this embodiment includes: a processor 401, a memory 402, and a computer program 403 stored in the memory 402 and executable on the processor 401. When the processor 401 executes the computer program 403, it implements the steps in the various method embodiments described above. Alternatively, when the processor 401 executes the computer program 403, it implements the functions of each module / unit in the various device embodiments described above.
[0081] Electronic device 4 can be a desktop computer, laptop, handheld computer, cloud server, or other electronic device. Electronic device 4 may include, but is not limited to, processor 401 and memory 402. Those skilled in the art will understand that... Figure 4 This is merely an example of electronic device 4 and does not constitute a limitation on electronic device 4. It may include more or fewer components than shown, or different components.
[0082] The processor 401 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0083] The memory 402 can be an internal storage unit of the electronic device 4, such as a hard disk or RAM of the electronic device 4. The memory 402 can also be an external storage device of the electronic device 4, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc., equipped on the electronic device 4. The memory 402 can also include both internal and external storage units of the electronic device 4. The memory 402 is used to store computer programs and other programs and data required by the electronic device.
[0084] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0085] If integrated modules / units are implemented as software functional units and sold or used as independent products, they can be stored in a readable storage medium (e.g., a computer-readable storage medium). Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program may include computer program code, which may be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable storage medium may include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0086] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A TPCM-authenticated trusted boot method based on the x86 platform, characterized in that, include: Upon initial power-on, the switchable interface circuit is in the first connected state, which connects the flash memory to the SPI interface of the TPCM. The trigger verification circuit outputs a reset trigger signal to the TPCM, enabling the TPCM to read the boot firmware from the flash memory through the first connected state and perform integrity verification on the boot firmware to obtain the initial power-on verification result. When the initial power-on verification result indicates that the boot firmware has passed the verification, the nuclear power supply circuit is controlled to supply power to the central processing unit, and the switchable interface circuit is controlled to switch to the second connection state that connects the flash memory and the SPI interface of the central processing unit, so that the central processing unit loads and executes the boot firmware from the flash memory through the second connection state to complete the initial power-on boot control. When the system restarts, the control switchable interface circuit remains in the second connected state, causing the central processing unit to read the boot firmware from the flash memory and enter a suspended state; In the suspended state, the trigger verification circuit outputs a reset trigger signal to the TPCM again and controls the switchable interface circuit to switch to the first connected state, so that the TPCM reads the boot firmware from the flash memory through the first connected state and performs integrity verification on the boot firmware to obtain the restart verification result. When the reboot verification result indicates that the boot firmware has passed the verification, the control switchable interface circuit is restored to the second connected state, so that the central processing unit continues to load and execute the boot firmware from the flash memory through the second connected state to complete the boot control of the system reboot process.
2. The method according to claim 1, characterized in that, Upon initial power-on, controlling the switchable interface circuit to be in a first connectivity state, connecting the flash memory to the SPI interface of the TPCM, includes: When the motherboard is powered on, the analog switch in the switchable interface circuit is set to be connected to the SPI interface side of the flash memory and disconnected from the SPI interface side of the central processing unit, so that the flash memory is only connected to the SPI interface of the TPCM. When the nuclear power supply circuit does not supply power to the central processing unit, the trigger verification circuit outputs a reset trigger signal to the TPCM, so that the TPCM reads the boot firmware from the flash memory through the first connection state and performs integrity verification on the boot firmware.
3. The method according to claim 2, characterized in that, The trigger verification circuit outputs a reset trigger signal to the TPCM, causing the TPCM to read the boot firmware from the flash memory through the first connected state and perform an integrity verification on the boot firmware to obtain the first power-on verification result, including: During the motherboard power-on process, the trigger verification circuit generates a reset trigger signal with a preset timing based on the power-on status signal and outputs it to the TPCM. After receiving the reset trigger signal, the TPCM completes its own initialization, establishes SPI communication with the flash memory through the first connectivity state, reads the boot firmware data stored in the flash memory in the order of the preset address range, and performs integrity verification on the boot firmware data based on the preset verification strategy, generating the first power-on verification result to indicate whether the boot firmware has passed the verification.
4. The method according to claim 1, characterized in that, The control switchable interface circuit switches to a second connectivity state, connecting the flash memory to the SPI interface of the central processing unit, enabling the central processing unit to load and execute the boot firmware from the flash memory through the second connectivity state, including: When the initial power-on verification result indicates that the boot firmware has passed the verification, the TPCM outputs a control signal for power supply to the nuclear power supply circuit based on the initial power-on verification result, so that the nuclear power supply circuit supplies power to the central processing unit. During the process of powering on and resetting the central processing unit, the switchable interface circuit is controlled to switch from the first connected state to the second connected state, so that the central processing unit establishes SPI communication with the flash memory through the second connected state, loads the boot firmware from the flash memory according to the preset boot sequence, and executes the boot firmware.
5. The method according to claim 1, characterized in that, The step of controlling the switchable interface circuit to remain in the second connected state during system restart, causing the central processing unit to read the boot firmware from flash memory and enter a suspended state, includes: Upon receiving a system restart command, the nuclear power supply circuit continues to supply power to the central processing unit, and the switchable interface circuit is controlled to remain in the second connected state. After the central processing unit is reset, it reads at least part of the boot code of the boot firmware from the flash memory through the second connected state, executes the preset restart initialization operation according to the boot code, and stops the subsequent boot process when it reaches the preset suspension point, and enters the suspension state.
6. The method according to claim 1, characterized in that, The step of enabling the TPCM to read the boot firmware from the flash memory through the first connectivity state and performing an integrity check on the boot firmware to obtain a reboot check result includes: In the suspended state, the trigger verification circuit generates a reset trigger signal based on the system restart state and outputs it to the TPCM. After receiving the reset trigger signal, the TPCM completes its own initialization, establishes SPI communication with the flash memory through the first connected state, reads the boot firmware data stored in the flash memory in the order of the preset address range, and verifies the boot firmware data based on the preset integrity verification strategy, generating a restart verification result to indicate whether the boot firmware passes the verification during the system restart process.
7. The method according to claim 1, characterized in that, The control switchable interface circuit is restored to the second connected state, enabling the central processing unit to continue loading and executing the boot firmware from flash memory through the second connected state to complete the boot control of the system restart process, including: When the reboot verification result indicates that the boot firmware has passed the verification, the TPCM outputs a control signal for resuming the boot process based on the reboot verification result. This control the switchable interface circuit to switch from the first connected state to the second connected state and provides a resumption execution instruction to the central processing unit (CPU) which is in a suspended state. This allows the CPU to release the suspended state while maintaining power supply, and continue to load the remaining boot firmware from the flash memory and execute the boot firmware through the restored second connected state.
8. A TPCM-authenticated trusted boot device based on the x86 platform, characterized in that, include: The power-on module is used to control the switchable interface circuit to be in the first connected state that connects the flash memory and the SPI interface of the TPCM when the power is first turned on. The trigger verification circuit outputs a reset trigger signal to the TPCM, so that the TPCM reads the boot firmware from the flash memory through the first connected state and performs integrity verification on the boot firmware to obtain the first power-on verification result. The power supply module is used to control the nuclear power supply circuit to supply power to the central processing unit when the initial power-on verification result indicates that the boot firmware has passed the verification, and to control the switchable interface circuit to switch to a second connection state that connects the flash memory and the SPI interface of the central processing unit, so that the central processing unit loads and executes the boot firmware from the flash memory through the second connection state to complete the initial power-on boot control. The restart module is used to control the switchable interface circuit to remain in the second connected state when the system restarts, so that the central processing unit reads the boot firmware from the flash memory and enters the suspended state; The switching module is used to, in the suspended state, have the trigger verification circuit output a reset trigger signal to the TPCM again, and control the switchable interface circuit to switch to the first connected state, so that the TPCM can read the boot firmware from the flash memory through the first connected state, and perform integrity verification on the boot firmware to obtain the restart verification result. The startup module is used to control the switchable interface circuit to return to the second connected state when the restart verification result indicates that the startup firmware has passed the verification, so that the central processing unit continues to load and execute the startup firmware from the flash memory through the second connected state to complete the startup control of the system restart process.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 7.