Secure starting method and related equipment

By pre-installing a national root certificate within the processor and building a trust chain, and by performing trust measurements on intermediate certificates, user certificates, and basic input/output systems, the reliability and credibility of existing secure boot methods are addressed, achieving higher security and compliance.

CN121997331APending Publication Date: 2026-05-08HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD
Filing Date
2025-12-24
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing secure boot methods based on trusted roots are insufficient in terms of reliability, credibility, and authority, resulting in a degraded user experience.

Method used

Starting with the pre-installed national root certificate within the processor, a trust chain is built by performing trust measurements on intermediate certificates, user certificates, and basic input/output systems to ensure the reliability and credibility of secure boot.

Benefits of technology

It improves the reliability, credibility, and authority of the trust chain, enhances the compliance of secure boot, and facilitates the implementation and commercialization of secure boot methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121997331A_ABST
    Figure CN121997331A_ABST
Patent Text Reader

Abstract

The invention discloses a safe starting method and related equipment, and the safe starting method comprises the steps: responding to a detected preset safe starting condition, employing a national root certificate preset in a processor to carry out the trusted measurement of an intermediate root certificate, and enabling the intermediate root certificate to be stored in an external storage space of the processor; when the trusted measurement of the intermediate root certificate is passed, the intermediate root certificate is adopted to carry out trusted measurement on an intermediate application certificate, and the intermediate application certificate is stored in an external storage space of the processor; when the trusted measurement of the intermediate application certificate is passed, the intermediate application certificate is adopted to carry out trusted measurement on the user certificate, and the user certificate is stored in an external storage space of the processor; when the trusted measurement of the user certificate is passed, adopting the user certificate to carry out trusted measurement on the basic input / output system; and when the trusted measurement of the basic input and output system passes, running the basic input and output system. According to the technical scheme of the invention, the reliability, credibility and authority of trust chain verification can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of computer technology, and in particular to a secure boot method and related equipment. Background Technology

[0002] The secure boot method based on the root of trust has gradually become a requirement in computer security technology standards (such as GB / T39680-2020 Server Security Technical Requirements and Evaluation Criteria) in recent years. This means that when the system is powered on, the integrity of the Basic Input / Output System (BIOS) must be trusted and measured first, and the BIOS can only run after the trust measurement is passed, in order to prevent attacks on the BIOS.

[0003] However, existing secure boot methods based on roots of trust still have shortcomings in reliability, credibility, and authority, which reduces the user experience. Summary of the Invention

[0004] The problem solved by the embodiments of the present invention is to provide a secure startup method and related equipment that can improve the reliability, credibility and authority of the trust chain.

[0005] To address the above problems, embodiments of the present invention provide a secure boot method applied to a processor, comprising: In response to the detection of a preset secure boot condition, the intermediate certificate is assessed for trustworthiness using a pre-installed national root certificate within the processor. The intermediate certificate is stored in the processor's external storage space. When the trust measurement of the intermediate certificate passes, the user certificate is used to perform a trust measurement on the intermediate certificate, and the user certificate is stored in the external storage space of the processor. When the trust measurement of the user certificate passes, the trust measurement of the basic input / output system is performed using the user certificate; When the confidence metric of the basic input / output system passes, the basic input / output system is run.

[0006] Optionally, the intermediate certificate includes an intermediate root certificate; The step of using the pre-installed national root certificate in the processor to perform a trust measurement on the intermediate certificate includes: using the national root certificate to perform a trust measurement on the intermediate root certificate; Using the intermediate certificate to perform a trust measurement on the user certificate includes: using the intermediate root certificate to perform a trust measurement on the user certificate.

[0007] Optionally, the intermediate certificate may also include an intermediate application certificate; When the trust measurement of the intermediate root certificate passes, the secure boot method further includes: using the intermediate root certificate to perform a trust measurement on the intermediate application certificate; When the trust measurement of the intermediate application certificate passes, the step of using the intermediate certificate to perform a trust measurement of the user certificate includes: using the intermediate application certificate to perform a trust measurement of the user certificate.

[0008] Optionally, the user certificate includes user identification information, and the processor also has user identification information pre-installed. When the user certificate passes the trust measurement using the intermediate certificate, and before the basic input / output system passes the trust measurement using the user certificate, the trust measurement of the user certificate further includes: obtaining user identification information in the user certificate; comparing the user identification information in the user certificate with user identification information preset in the processor; and when it is determined that the user identification information in the user certificate is consistent with the trusted user identification information preset in the processor, the trust measurement of the user certificate passes.

[0009] Optionally, the user certificate includes public key version number information, and the processor also has the public key version number information of the user certificate pre-installed. Before performing a trust measurement on the user certificate using the intermediate certificate and before performing a trust measurement on the basic input / output system using the user certificate, the trust measurement of the user certificate further includes: obtaining the public key version number information in the user certificate; comparing the public key version number information in the user certificate with the public key version number information of the user certificate pre-installed in the processor; and when it is determined that the public key version number in the user certificate is greater than or equal to the public key version number of the user certificate pre-installed in the processor, the trust measurement of the user certificate passes.

[0010] Optionally, when the user certificate expires and is disabled, the secure boot method further includes: The public key version number of the user certificate pre-installed in the processor is upgraded so that the public key version number of the user certificate pre-installed in the processor is greater than the public key version number in the user certificate.

[0011] Optionally, before running the basic input / output system, the secure boot method further includes: The manufacturer application certificate is trusted using a manufacturer root certificate pre-installed within the processor, and the manufacturer application certificate is stored in the processor's external storage space. When the trust measurement of the manufacturer application certificate passes, the trust measurement of the manufacturer user certificate is performed using the manufacturer application certificate. The manufacturer user certificate is stored in the external storage space of the processor. The manufacturer user certificate includes the user certificate, or may also include the intermediate certificate. The basic input / output system is run when the trust metric for the manufacturer's user certificate passes.

[0012] Optionally, the preset safe startup condition includes powering on the processor.

[0013] Optionally, the national root certificate is stored in a one-time programmable memory within the processor.

[0014] Accordingly, embodiments of the present invention also provide a secure boot device applied to a processor, comprising: The first trust measurement module is used to perform a trust measurement on an intermediate certificate using a pre-installed national root certificate in the processor in response to the detection of a preset secure startup condition. The intermediate certificate is stored in the external storage space of the processor. The second trust measurement module is used to perform a trust measurement on the user certificate using the intermediate certificate when the trust measurement of the intermediate certificate passes, wherein the user certificate is stored in the external storage space of the processor. The third trust measurement module is used to perform a trust measurement on the basic input / output system using the user certificate when the trust measurement of the user certificate passes. A running module is used to run the basic input / output system when a confidence metric for the basic input / output system passes.

[0015] Optionally, the intermediate certificate includes an intermediate root certificate; The first trust measurement module is used to perform trust measurement on the intermediate root certificate using the national root certificate; The second trust measurement module is used to perform trust measurement on the user certificate using the intermediate application certificate.

[0016] Optionally, the intermediate certificate includes an intermediate root certificate and also includes an intermediate application certificate; The first trust measurement module is further configured to perform a trust measurement on the intermediate application certificate using the intermediate root certificate when the trust measurement of the intermediate root certificate passes. The second trust measurement module is used to perform trust measurement on the user certificate using the intermediate application certificate.

[0017] Optionally, the user certificate further includes user identification information, and the processor also has user identification information pre-installed. The second trust measurement module is further configured to: obtain user identification information in the user certificate when the trust measurement of the user certificate using the intermediate certificate passes, and before the trust measurement of the basic input / output system using the user certificate; compare the user identification information in the user certificate with user identification information preset in the processor; and when it is determined that the user identification information in the user certificate is consistent with the trusted user identification information preset in the processor, pass the trust measurement of the user certificate.

[0018] Optionally, the user certificate includes public key version number information, and the processor also has the public key version number information of the user certificate pre-installed. The second trust measurement module is further configured to: obtain the public key version number information in the user certificate when the trust measurement of the user certificate using the intermediate certificate passes, and before the trust measurement of the basic input / output system using the user certificate; compare the public key version number information in the user certificate with the public key version number information of the user certificate pre-installed in the processor; and when it is determined that the public key version number in the user certificate is greater than or equal to the public key version number of the user certificate pre-installed in the processor, the trust measurement of the user certificate passes.

[0019] Optionally, the secure boot device further includes a public key version number upgrade unit, used to upgrade the public key version number of the user certificate pre-installed in the processor when the user certificate expires and is prohibited from use, so that the public key version number of the user certificate pre-installed in the processor is greater than the public key version number in the user certificate.

[0020] Optionally, the safety start device further includes: The fourth trust measurement module is used to perform a trust measurement on the manufacturer application certificate using the manufacturer root certificate pre-installed in the processor before running the basic input / output system. The manufacturer application certificate is stored in the external storage space of the processor. The fifth trust measurement module is used to perform a trust measurement on the manufacturer user certificate using the manufacturer application certificate when the trust measurement of the manufacturer application certificate passes. The manufacturer user certificate is stored in the external storage space of the processor. The manufacturer user certificate includes the user certificate or may also include the intermediate certificate. The running module is used to run the basic input / output system when the trust metric of the manufacturer's user certificate passes.

[0021] Accordingly, embodiments of the present invention also provide a computer device, including: at least one memory and at least one processor; the memory stores one or more computer-executable instructions, and the processor invokes the one or more computer-executable instructions to execute the secure boot method as described in any of the preceding embodiments.

[0022] Accordingly, embodiments of the present invention also provide a computer program product, including a computer program / instructions, which, when executed by a processor, are used to implement the secure boot method as described in any of the preceding claims.

[0023] Accordingly, embodiments of the present invention also provide a storage medium storing one or more computer instructions for implementing the secure boot method as described in any of the preceding claims.

[0024] Compared with the prior art, the technical solution of the embodiments of the present invention has the following advantages: The secure boot method provided in this embodiment of the invention includes: in response to detecting a preset secure boot condition, performing a trust measurement on an intermediate root certificate using a pre-installed national root certificate within the processor, the intermediate root certificate being stored in the external storage space of the processor; when the trust measurement of the intermediate root certificate passes, performing a trust measurement on an intermediate application certificate using the intermediate root certificate, the intermediate application certificate being stored in the external storage space of the processor; when the trust measurement of the intermediate application certificate passes, performing a trust measurement on a user certificate using the intermediate application certificate, the user certificate being stored in the external storage space of the processor; when the trust measurement of the user certificate passes, performing a trust measurement on a basic input / output system using the user certificate; and when the trust measurement of the basic input / output system passes, running the basic input / output system.

[0025] The secure boot method provided in this invention constructs a trust chain starting with a national root certificate issued by a national root certificate authority. This can ensure the security of secure boot while improving the reliability, credibility, and authority of the trust chain verification. It also has significant advantages in terms of compliance, which helps the secure boot method to be implemented and commercialized. Attached Figure Description

[0026] Figure 1 and Figure 2 This is a flowchart illustrating an embodiment of the secure boot method provided by the present invention. Figure 3 This is a flowchart illustrating another embodiment of the secure boot method provided by the present invention. Figure 4 This is a flowchart illustrating another embodiment of the secure startup method provided by the present invention. Figure 5 This is a flowchart illustrating another embodiment of the secure startup method provided by the technical solution of the present invention; Figure 6 This is a schematic diagram of an optional structure of a computer device provided by the technical solution of the present invention. Detailed Implementation

[0027] As can be seen from the background technology, existing secure boot methods based on trusted roots still have shortcomings in reliability, credibility, and authority, which reduces the user experience.

[0028] To address the aforementioned technical problems, the present invention provides a secure boot method comprising: responding to the detection of a preset secure boot condition, performing a trust measurement on an intermediate root certificate using a pre-installed national root certificate within the processor, the intermediate root certificate being stored in the processor's external storage space; when the trust measurement of the intermediate root certificate passes, performing a trust measurement on an intermediate application certificate using the intermediate root certificate, the intermediate application certificate being stored in the processor's external storage space; when the trust measurement of the intermediate application certificate passes, performing a trust measurement on a user certificate using the intermediate application certificate, the user certificate being stored in the processor's external storage space; when the trust measurement of the user certificate passes, performing a trust measurement on a basic input / output system using the user certificate; and when the trust measurement of the basic input / output system passes, running the basic input / output system.

[0029] The secure boot method provided in this invention constructs a trust chain starting with a national root certificate issued by a national root certificate authority. This can ensure the security of secure boot while improving the reliability, credibility, and authority of the trust chain verification. It also has significant advantages in terms of compliance, which helps the secure boot method to be implemented and commercialized.

[0030] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0031] Figure 1 and Figure 2 This diagram illustrates a flowchart of an embodiment of the secure boot method provided by the present invention. Please refer to the references provided. Figure 1 and Figure 2 A secure boot method applied to a processor, comprising: Step S110: In response to the detection of a preset secure boot condition, the intermediate certificate is trusted using a pre-installed national root certificate in the processor. The intermediate certificate is stored in the external storage space of the processor. Step S120: When the trust measurement of the intermediate certificate passes, the user certificate is used to perform a trust measurement on the intermediate certificate, and the user certificate is stored in the external storage space of the processor; Step S130: When the trust measurement of the user certificate passes, the trust measurement of the basic input / output system is performed using the user certificate; Step S140: When the confidence metric of the basic input / output system passes, run the basic input / output system.

[0032] Please refer to the reference. Figure 1 and Figure 2 In step S110, in response to the detection of a preset secure boot condition, the intermediate certificate is trusted by using a pre-installed national root certificate in the processor. The intermediate certificate is stored in the external storage space of the processor.

[0033] In response to the detection of preset secure startup conditions, the intermediate root certificate is used to perform a trust measurement on the intermediate root certificate using the pre-installed country root certificate in the processor. This provides a basis for subsequently using the intermediate root certificate to perform a trust measurement on the intermediate application certificate when the trust measurement of the intermediate root certificate passes.

[0034] In this embodiment, the preset secure startup condition is that the processor is powered on. In other embodiments, the preset secure startup condition can also be any event prior to the operation of the basic input / output system; the specific setting can be made by those skilled in the art and is not limited here.

[0035] The national root certificate is issued by a national certificate authority (such as the Ministry of Industry and Information Technology), and has significant advantages in terms of reliability, credibility, authority, and compliance. Accordingly, establishing a trust chain starting with the national root certificate helps improve the reliability, credibility, authority, and compliance of the trust chain, and facilitates the implementation and commercialization of the secure boot method provided in this embodiment of the invention.

[0036] In some implementations, the national root certificate is stored in the processor's on-chip memory. Specifically, the national root certificate, as the starting point of the trust chain, is stored in secure storage within the processor's on-chip memory to ensure its integrity is not tampered with. As an example, the national root certificate is stored in one-time programmable memory (OTP) within the processor, such as a fuse (FUSE). The OTP is programmable only once, providing a one-time programming operation, and the data cannot be changed after programming.

[0037] In other embodiments, only the first public key of the national root certificate can be stored in the secure storage space on the processor chip to save on-chip storage space and improve resource utilization.

[0038] The intermediate certificates are issued by the various local Certificate Authorization Structures (CAs) under the National Certificate Authorization Authority.

[0039] In some implementations, the intermediate certificate includes an intermediate root certificate. Accordingly, the step of performing a trust measurement on the intermediate root certificate using a pre-installed national root certificate within the processor includes: performing a trust measurement on the intermediate root certificate using the pre-installed national root certificate within the processor.

[0040] The intermediate root certificate is a root certificate issued by the local certificate authority.

[0041] In some implementations, the step of using a pre-installed national root certificate to perform a trust measurement on the intermediate root certificate includes: obtaining a first public key of the national root certificate; obtaining a digital signature of the intermediate root certificate, wherein the digital signature of the intermediate root certificate is generated by encryption using a first private key that matches the first public key and is stored in the external storage space of the processor; and verifying the digital signature of the intermediate root certificate using the first public key.

[0042] In some implementations, the first public key and the first private key are generated using an asymmetric encryption algorithm. The asymmetric encryption algorithm can be a national cryptographic algorithm issued by the State Cryptography Administration, such as the SM2 algorithm. Of course, the asymmetric encryption algorithm can also be an internationally commercial cryptographic algorithm, such as RSA, DSA, ECDSA, Rabin, DH, ECC, ECDH, etc., and is not limited here.

[0043] The digital signature of the intermediate root certificate is obtained by encrypting it with a first private key that matches the first public key of the national root certificate. Accordingly, the intermediate root certificate is signed with the first private key that matches the first public key of the national root certificate. That is, the digital signature of the intermediate root certificate is directly derived from the private key of the national root certificate, so that the trust originating from the national root certificate is partially transferred to the intermediate root certificate.

[0044] The digital signature of the intermediate root certificate is encrypted data. Accordingly, storing the digital signature of the intermediate root certificate in the processor's external storage space can also ensure its integrity and prevent tampering. For example, the digital signature of the intermediate root certificate is stored in the processor's off-chip flash memory (FLASH).

[0045] As an example, the step of verifying the digital signature of the intermediate root certificate using the first public key includes: decrypting the digital signature of the intermediate root certificate using the first public key to obtain the original digest of the intermediate root certificate; calculating the digest of the intermediate root certificate using a preset hash algorithm; comparing the decrypted original digest of the intermediate root certificate with the calculated digest of the intermediate root certificate; when it is determined that the decrypted original digest of the intermediate root certificate is consistent with the calculated digest of the intermediate root certificate, it indicates that the intermediate root certificate has integrity, and correspondingly, the verification of the digital signature of the intermediate root certificate using the first public key passes; when it is determined that the decrypted original digest of the intermediate root certificate is inconsistent with the calculated digest of the intermediate root certificate, it indicates that the intermediate root certificate has been tampered with, and correspondingly, the verification of the digital signature of the intermediate root certificate using the first public key fails.

[0046] In some implementations, after obtaining the first public key of the national root certificate and before verifying the digital signature of the intermediate root certificate using the first public key, the system further includes an operation to verify the first public key of the national root certificate to ensure the integrity of the first public key of the national root certificate, thereby further improving the security of Secure Boot.

[0047] As an example, the steps for verifying the first public key of the national root certificate include: obtaining the first verification public key stored externally to the processor; calculating the hash value of the first verification public key; comparing the calculated hash value of the first public key with a first reserved hash value pre-stored internally in the processor; when the calculated hash value of the first public key matches the first reserved hash value internally in the processor, the verification of the first public key is successful; when the calculated hash value of the first public key does not match the first reserved hash value internally in the processor, the verification of the first public key fails.

[0048] When the verification of the first public key is successful, the operation of verifying the digital signature of the intermediate root certificate using the first public key can continue; when the verification of the first public key fails, the continued operation of the secure boot phase is terminated, and corresponding alarm prompts can be output so that the user can take appropriate measures.

[0049] In some implementations, the intermediate certificate further includes an intermediate application certificate. Accordingly, when the measurement of the intermediate root certificate passes, the secure boot method further includes: performing a trust measurement on the intermediate application certificate using the intermediate root certificate.

[0050] The intermediate application certificate is a certificate issued by various local certificate authorization structures under the national certificate authorization structure. Thus, through the two-level intermediate certificate structure consisting of the intermediate root certificate and the intermediate application certificate, the intermediate certificates issued by local certificate authorization structures for different technical fields can be distinguished.

[0051] In some implementations, the step of using the intermediate root certificate to perform a trust measurement on the intermediate application certificate includes: obtaining a second public key of the intermediate root certificate; obtaining a digital signature of the intermediate application certificate, wherein the digital signature of the intermediate application certificate is generated by encryption using a second private key that matches the second public key and is stored in the external storage space of the processor; and verifying the digital signature of the intermediate application certificate using the second public key.

[0052] Upon successful verification of the intermediate root certificate's trustworthiness, the plaintext of the intermediate root certificate can be obtained. Accordingly, the second public key can be retrieved from the intermediate root certificate.

[0053] In some implementations, the second public key and the second private key are generated using an asymmetric encryption algorithm. The asymmetric encryption algorithm can be a national cryptographic algorithm issued by the State Cryptography Administration, such as the SM2 algorithm. Of course, the asymmetric encryption algorithm can also be an internationally commercial cryptographic algorithm, such as RSA, DSA, ECDSA, Rabin, DH, ECC, ECDH, etc., and is not limited here.

[0054] The digital signature of the intermediate application certificate is obtained by encrypting it with a second private key that matches the second public key of the intermediate root certificate. Accordingly, by signing the intermediate application certificate with the second private key that matches the second public key of the intermediate root certificate, that is, by the digital signature of the intermediate application certificate originating from the second private key of the intermediate root certificate, the trust originating from the intermediate root certificate continues to be partially transferred to the intermediate application certificate.

[0055] The digital signature of the intermediate application certificate is encrypted data. Accordingly, storing the digital signature of the intermediate application certificate in the external storage space of the processor can also ensure its integrity and prevent tampering. For example, the digital signature of the intermediate application certificate is stored in flash memory outside the processor.

[0056] In some implementations, verifying the digital signature of the intermediate application certificate using the second public key can be achieved by decrypting the digital signature of the intermediate application certificate using the second public key to obtain the original digest of the intermediate application certificate, and then calculating the digest of the intermediate application certificate using a preset hash algorithm. If the original digest of the intermediate application certificate obtained by decryption is the same as the digest of the intermediate application certificate calculated using the preset hash algorithm, then the verification of the intermediate application certificate is successful; otherwise, the verification of the intermediate application certificate fails.

[0057] Accordingly, when the trust metrics for both the intermediate root certificate and the intermediate application certificate pass, the trust metrics for the intermediate certificate also pass.

[0058] The above description, using a two-tier structure (intermediate root certificate and intermediate application certificate) of an intermediate certificate issued by a local certificate authority as an example, illustrates the trust measurement operation of the intermediate certificate. In optional or alternative embodiments, the intermediate certificate can also employ more than two certificate structures; this is not a limitation.

[0059] Please refer to the reference. Figure 1 and Figure 2 Execute step S120: when the trust measurement of the intermediate certificate passes, use the intermediate certificate to perform a trust measurement of the user certificate, and the user certificate is stored in the external storage space of the processor.

[0060] The user certificate, also known as a BIOS signature certificate, is a certificate used to verify the digital signature of the BIOS.

[0061] In some implementations, the intermediate certificate includes an intermediate root certificate and an intermediate application certificate. Accordingly, the step of using the intermediate certificate to perform a trust measurement on the user certificate includes: using the intermediate application certificate to perform a trust measurement on the user certificate.

[0062] In some implementations, the step of using the intermediate application certificate to perform a trust measurement on the user certificate includes: obtaining a third public key of the intermediate application certificate; obtaining a digital signature of the user certificate, wherein the digital signature of the user certificate is generated by encryption using a third private key that matches the third public key and is stored in the external storage space of the processor; and verifying the digital signature of the user certificate using the third public key.

[0063] Upon successful verification of the intermediate application certificate's trustworthiness, the plaintext of the intermediate application certificate, which includes information about the third public key, can be obtained. Correspondingly, the third public key can be obtained from the plaintext of the intermediate root certificate.

[0064] In some implementations, the third public key and the third private key are generated using an asymmetric encryption algorithm. For details on asymmetric encryption algorithms, please refer to the preceding description; further explanation is unnecessary.

[0065] The digital signature of the user certificate is obtained by encrypting it with a third private key that matches the third public key of the intermediate application certificate. That is, the digital signature of the intermediate application certificate originates from the second private key of the intermediate root certificate, so that the trust from the intermediate application certificate continues to be partially passed down to the user certificate.

[0066] The digital signature of the user certificate is obtained by encryption using a third private key that matches the third public key of the intermediate application certificate. Accordingly, storing the digital signature of the user certificate in the external storage space of the processor ensures its integrity and prevents tampering. For example, the digital signature of the user certificate is stored in flash memory outside the processor.

[0067] As an example, the step of verifying the digital signature of the user certificate using the third public key includes: decrypting the digital signature of the user certificate using the third public key to obtain the original digest of the user certificate; calculating the digest of the user certificate using a preset hash algorithm; comparing the decrypted original digest of the user certificate with the digest of the user certificate calculated using the preset hash algorithm; when it is determined that the decrypted original digest of the user certificate is consistent with the digest of the user certificate calculated using the preset hash algorithm, it indicates that the user certificate has integrity, and correspondingly, the verification of the digital signature of the user certificate using the third public key passes; when it is determined that the decrypted original digest of the user certificate is inconsistent with the digest of the user certificate calculated using the preset hash algorithm, it indicates that the user certificate has been tampered with, and correspondingly, the verification of the digital signature of the user certificate using the third public key fails.

[0068] Please refer to the reference. Figure 1 and Figure 2 Execute step S130: when the trust measurement of the user certificate passes, use the user certificate to perform a trust measurement of the basic input / output system.

[0069] When the trust measurement of the user certificate passes, the trust measurement of the basic input / output system is performed using the user certificate, providing a basis for running the basic input / output system when the trust measurement of the basic input / output system passes in the future.

[0070] In some implementations, the step of using the user certificate to perform a trust measurement on the BIOS includes: obtaining the fourth public key of the user certificate; obtaining the digital signature of the BIOS, wherein the digital signature of the BIOS is generated by encryption using a fourth private key that matches the fourth public key and is stored in the external storage space of the processor; and verifying the digital signature of the BIOS using the fourth public key.

[0071] Upon successful verification of the user certificate's trustworthiness, the plaintext of the user certificate, which includes information about the fourth public key, can be obtained. Accordingly, the fourth public key can be extracted from the plaintext of the user certificate.

[0072] In some implementations, the fourth public key and the fourth private key are generated using an asymmetric encryption algorithm. Please refer to the preceding description for details on asymmetric encryption algorithms; further explanation is omitted here.

[0073] The digital signature of the BIOS is obtained by encrypting it with a fourth private key that matches the fourth public key of the user certificate. That is, the digital signature of the BIOS originates from the fourth private key of the user certificate, so that the trust from the user certificate can be further passed down to the BIOS.

[0074] The digital signature of the BIOS is obtained by encryption using a fourth private key that matches the fourth public key of the user certificate. Accordingly, storing the digital signature of the BIOS in the external storage space of the processor ensures its integrity and prevents tampering. For example, the digital signature of the BIOS is stored in flash memory outside the processor.

[0075] As an example, the steps of verifying the digital signature of the BIOS using the fourth public key include: decrypting the digital signature of the BIOS using the fourth public key to obtain the original digest of the BIOS; calculating the digest of the BIOS using a preset hash algorithm; comparing the original digest of the decrypted BIOS with the digest of the BIOS calculated using the preset hash algorithm; when it is determined that the original digest of the decrypted BIOS is the same as the digest of the BIOS calculated using the preset hash algorithm, it indicates that the BIOS has integrity, and accordingly, the verification of the BIOS using the fourth public key passes; when it is determined that the original digest of the decrypted BIOS is different from the digest of the BIOS calculated using the preset hash algorithm, it indicates that the BIOS has been tampered with, and accordingly, the verification of the BIOS using the fourth public key fails.

[0076] Please refer to the reference. Figure 1 and Figure 2Then, execute step S140, and when the confidence metric of the basic input / output system passes, run the basic input / output system.

[0077] When the trust measurement of the basic input / output system passes, the trust chain verification starting from the national root certificate passes, indicating that the BIOS has not been tampered with and has integrity. At this time, running the BIOS can ensure the security of BIOS operation.

[0078] It should be noted that in the above-mentioned secure boot method, for the same processor, user certificates issued by different local certificate authorities to different users can all pass the trust measurement, which means that the BIOS of different users can boot and run. This cannot prevent unauthorized operating systems or malicious programs from running at boot time, increasing the risk of system attacks.

[0079] To avoid the above situation, please refer to the following: Figure 3 The diagram shows a flowchart of another embodiment of the secure startup method provided by the present invention.

[0080] The similarities between this embodiment and the previous embodiments will not be repeated. The difference between this embodiment and the previous embodiments is that: when the trust measurement of the user certificate using the intermediate certificate passes, and before performing a trust measurement of the basic input / output system using the user certificate, the method further includes: comparing the user identification information USR_ID in the user certificate with the user identification information USR_ID pre-set in the processor; when it is determined that the user identification information USR_ID in the user certificate matches the user identification information USR_ID pre-set in the processor, a trust measurement of the basic input / output system using the user certificate can be performed; otherwise, the BIOS can be disabled.

[0081] The user certificate includes user identification information USR_ID, so by setting different user identification information USR_ID for user certificates issued to different users, the user certificates of different users can be distinguished from each other.

[0082] In some implementations, the user identification information USR_ID in the user certificate is set by the local certificate authority when issuing the user certificate.

[0083] In some implementations, the user identification information USR_ID pre-installed in the processor can be written into the processor by the user using a tool provided by the processor manufacturer.

[0084] In some implementations, the user identification information USR_ID pre-installed within the processor is stored in a secure storage space within the processor, which cannot be modified by unauthorized users, thereby ensuring the integrity of the user identification information USR_ID pre-installed within the processor.

[0085] The user identification information USR_ID in the user certificate is compared with the trusted user identification information USR_ID pre-set in the processor to determine whether the user identification information USR_ID in the user certificate is consistent with the user identification information USR_ID pre-set in the processor.

[0086] When it is determined that the user identification information USR_ID in the user certificate matches the user identification information USR_ID preset in the processor, the user certificate can be identified as the current user's user certificate. At this point, the user certificate can be used to continue performing a trust measurement on the BIOS, and if the trust measurement of the BIOS passes, the BIOS can be run.

[0087] When it is determined that the user identification information USR_ID in the user certificate is inconsistent with the user identification information USR_ID pre-installed in the processor, it can be determined that the user certificate is a user certificate of another user encrypted with the same intermediate application certificate's private key. In this case, the processor can disable the BIOS to prevent unauthorized operating systems or malicious programs from running at startup, thereby reducing the risk of system attacks and improving system security.

[0088] It is worth noting that after at least one of the intermediate certificate and / or user certificate becomes invalid or is revoked, the processor cannot connect to the network during the secure boot phase and therefore cannot obtain information about the invalid or revoked intermediate certificate and / or user certificate. Consequently, the intermediate certificate and / or user certificate can still pass the trust measurement even after their invalidation or revocation. When malware steals the invalid or revoked intermediate certificate and / or user certificate, it can use the private key in the invalid or revoked intermediate certificate and / or user certificate to tamper with the corresponding digital signature, thereby enabling the tampered BIOS to run through the trust measurement.

[0089] To avoid the above situations, please refer to the following: Figure 3 The diagram shows a flowchart of another embodiment of the secure startup method provided by the present invention.

[0090] The similarities between this embodiment and the previous embodiments will not be repeated. The difference between this embodiment and the previous embodiments is that: when the trust measurement of the user certificate using the intermediate certificate passes, and before performing a trust measurement of the basic input / output system using the user certificate, the method further includes: comparing the public key version number information in the user certificate with the public key version number information preset in the processor; when it is determined that the public key version number information in the user certificate is greater than or equal to the public key version number information preset in the processor, the operation of performing a trust measurement of the basic input / output system using the user certificate can be performed; otherwise, the BIOS can be disabled.

[0091] The public key version number information in the user certificate is the version number information of the public key used to verify the digital signature of the user certificate, which is also the version number information of the public key in the intermediate application certificate.

[0092] In some implementations, the public key version number information in the user certificate is set by the local certificate authority when issuing the user certificate.

[0093] In some implementations, the public key version number information pre-installed in the processor can be written into the processor by the user using a tool provided by the processor manufacturer.

[0094] In some implementations, the public key version number information pre-installed within the processor is stored in a secure storage space within the processor, such as OTP, which cannot be modified by unauthorized users, thereby ensuring the integrity of the public key version number information pre-installed within the processor.

[0095] The length of the user identifier can be set according to actual needs. For example, the length of the user identifier is 8 bits, or 1 byte.

[0096] In some implementations, when the user certificate is invalidated or revoked due to leakage or expiration, the secure boot method further includes: upgrading the public key version number information preset in the processor, so that the public key version number preset in the processor increases by a preset value, thereby making the public key version number preset in the processor greater than the public key version number of the user certificate.

[0097] In some implementations, the OTP storing the pre-set public key version number information within the processor supports bit-by-bit programming, meaning that only the programmed data is read when the one-time programmable memory is accessed. Accordingly, the pre-set public key version number information within the processor is upgraded by programming the data bits of the one-time programmable memory circuitry in the processor. Specifically, before programming, each data bit in the one-time programmable memory can be "0", serving as the initial public key certificate version information. After each user certificate update, the corresponding data bit in the one-time programmable memory is programmed to 1 to continuously upgrade the pre-set public key version number information within the processor.

[0098] Taking a one-time programmable memory with a storage space of one byte (i.e., 8 data bits to be programmed) as an example, the initial public key version number preset in the processor is "000000000". When the public key version number needs to be upgraded for the first time, the lowest data bit in the one-time programmable memory is programmed to "1" using a programming tool, updating the public key version number information in the one-time programmable memory to "00000001"; when the public key version number needs to be upgraded for the second time, the second data bit in the one-time programmable memory is programmed to "1" using the programming tool, updating the public key version number information in the one-time programmable memory to "00000011"; and so on. When the public key version number needs to be upgraded for the eighth time, the eighth bit in the one-time programmable memory is programmed to "1" using the programming tool, updating the public key version number information in the one-time programmable memory to "11111111". Thus, the public key version number stored in the one-time programmable memory within the processor can be continuously upgraded.

[0099] The public key version number information in the user certificate is compared with the trusted public key version number information pre-installed in the processor to determine whether the public key version number information in the user certificate is consistent with the public key version number information pre-installed in the processor.

[0100] When it is determined that the public key version number in the user certificate is greater than or equal to the public key version number preset in the processor, the trust measurement of the user certificate passes. At this point, the user certificate can be used to continue performing a trust measurement on the BIOS, and if the trust measurement of the BIOS passes, the BIOS can be run.

[0101] When a user certificate is invalidated or revoked, the pre-installed public key version number in the processor has been upgraded. This means the pre-installed public key version number is now greater than the public key version number in the invalidated or revoked user certificate. Therefore, the condition that the public key version number in the user certificate is greater than or equal to the pre-installed public key version number in the processor is no longer met, and the trust measurement of the user certificate fails. In this situation, the BIOS can be disabled, preventing unauthorized operating systems or malicious programs from running at startup, thus improving system security.

[0102] It should be noted that because user certificates are issued by various local certificate authorities, and there is a lack of information synchronization between these local certificate authorities, the uniqueness of user identifiers in user certificates issued by different local certificate authorities cannot be guaranteed. Furthermore, a problem in any link of a single trust chain will cause the entire trust chain to fail, and the reliability and security of the secure boot mechanism still need to be improved.

[0103] To solve the above problems, please refer to the following: Figure 4 The diagram shows a flowchart of another embodiment of the secure startup method provided by the present invention.

[0104] The similarities between this embodiment and the previous embodiments will not be repeated. The difference between this embodiment and the previous embodiments is that, before running the BIOS, the secure boot method further includes: performing a trust measurement on the manufacturer application certificate using a manufacturer root certificate pre-installed in the processor, the manufacturer application certificate being stored in the processor's external storage space; when the trust measurement of the manufacturer application certificate passes, performing a trust measurement on the manufacturer user certificate using the manufacturer application certificate, the manufacturer user certificate being stored in the processor's external storage space; when the trust measurement of the manufacturer user certificate passes, running the basic input / output system.

[0105] The manufacturer root certificate is a certificate issued by the processor manufacturer and serves as the starting point of the manufacturer's trust chain.

[0106] In some implementations, the manufacturer root certificate is stored in a secure storage location within the processor, which cannot be altered by unauthorized users, thus ensuring its integrity. As an example, the manufacturer root certificate is stored in a one-time programmable memory within the processor, such as a fuse (FUSE).

[0107] In other embodiments, only the fifth public key in the manufacturer's root certificate can be stored in the secure storage space on the processor chip to save on-chip storage space and improve resource utilization.

[0108] In some implementations, the step of using the manufacturer's root certificate to perform a trust measurement on the manufacturer's application certificate includes: obtaining the fifth public key of the manufacturer's root certificate; obtaining the digital signature of the manufacturer's application certificate, wherein the digital signature of the manufacturer's application certificate is generated by encryption using a fifth private key that matches the fifth public key and is stored in the external storage space of the processor; and verifying the digital signature of the manufacturer's application certificate using the fifth public key.

[0109] The manufacturer application certificate is stored within the processor. Accordingly, the processor can directly read the fifth public key from the manufacturer application certificate.

[0110] In some implementations, the fifth public key and the fifth private key are generated using an asymmetric encryption algorithm. For details on asymmetric encryption algorithms, please refer to the preceding description; further explanation is unnecessary.

[0111] The digital signature of the manufacturer application certificate is obtained by encrypting it with a fifth private key that matches the fifth public key of the manufacturer root certificate. That is, the digital signature of the manufacturer application certificate originates from the fifth private key of the manufacturer root certificate, so that the trust from the manufacturer root certificate continues to be partially passed down to the manufacturer application certificate.

[0112] The digital signature of the manufacturer application certificate is obtained by encryption using a fifth private key that matches the fifth public key of the manufacturer's root certificate. Accordingly, storing the digital signature of the manufacturer application certificate in the external storage space of the processor ensures its integrity and prevents tampering. For example, the digital signature of the manufacturer application certificate is stored in flash memory outside the processor.

[0113] As an example, the step of verifying the digital signature of the manufacturer's application certificate using the fifth public key includes: decrypting the digital signature of the manufacturer's application certificate using the fifth public key to obtain the original digest of the manufacturer's application certificate; calculating the digest of the manufacturer's application certificate using a preset hash function; when the original digest of the manufacturer's application certificate obtained by decryption is the same as the digest of the manufacturer's application certificate calculated using the preset hash function, the verification of the digital signature of the manufacturer's application certificate using the fifth public key passes; otherwise, when the original digest of the manufacturer's application certificate obtained by decryption is different from the digest of the manufacturer's application certificate calculated using the preset hash function, the verification of the digital signature of the manufacturer's application certificate using the fifth public key fails.

[0114] In some implementations, after obtaining the fifth public key of the manufacturer's root certificate and before verifying the digital signature of the manufacturer's application certificate using the fifth public key, an operation is further included to verify the fifth public key of the manufacturer's root certificate, so as to further ensure the integrity of the fifth public key of the manufacturer's root certificate.

[0115] As an example, the step of verifying the fifth public key of the manufacturer's root certificate includes: obtaining the second verification public key stored outside the processor; calculating the hash value of the second verification public key; comparing the calculated hash value of the second verification public key with a second reserved hash value pre-stored inside the processor; when the calculated hash value of the second verification public key matches the second reserved hash value inside the processor, the verification of the fifth public key of the manufacturer's root certificate is successful; when the calculated hash value of the second verification public key does not match the second reserved hash value inside the processor, the verification of the fifth public key of the manufacturer's root certificate fails.

[0116] When the verification of the fifth public key of the manufacturer's root certificate is successful, the operation of verifying the digital signature of the manufacturer's application certificate using the fifth public key can continue; when the verification of the fifth public key of the manufacturer's root certificate fails, the BIOS startup is prohibited, and corresponding alarm messages can be output so that the user can take appropriate measures.

[0117] In some implementations, the manufacturer user certificate includes a digital signature of the user certificate, wherein the digital signature of the manufacturer user certificate is obtained by secondary signing of the user certificate issued by a local certificate authority using a sixth private key that matches the sixth public key in the manufacturer application certificate.

[0118] In other implementations, the manufacturer user certificate includes digital signatures of the intermediate certificate and the user certificate, wherein the digital signature of the manufacturer user certificate is obtained by secondary signing of the intermediate certificate and the user certificate issued by the local certificate authority using a sixth private key that matches the sixth public key in the manufacturer application certificate.

[0119] Correspondingly, when processor manufacturers perform secondary signing on user certificates issued by different local certificate authorities, they can check the user identifier in the user certificate to ensure that the user identifier in the user certificate of different users is different, which helps to enhance the security and reliability of the trust chain verification.

[0120] In some implementations, the step of using the manufacturer application certificate to perform a trust measurement on the manufacturer user certificate includes: obtaining the sixth public key of the manufacturer application certificate; obtaining the digital signature of the manufacturer user certificate, wherein the digital signature of the manufacturer user certificate is generated by encryption using a sixth private key that matches the sixth public key and is stored in the external storage space of the processor; and verifying the digital signature of the manufacturer application certificate using the sixth public key.

[0121] Upon successful verification of the manufacturer application certificate's trustworthiness, the plaintext of the manufacturer application certificate, which includes information about the sixth public key, can be obtained. Accordingly, the sixth public key can be retrieved from the manufacturer application certificate.

[0122] In some implementations, the sixth public key and the sixth private key are generated using an asymmetric encryption algorithm. For details on asymmetric encryption algorithms, please refer to the preceding description; further explanation is unnecessary.

[0123] The digital signature of the manufacturer user certificate is obtained by encrypting it with a sixth private key that matches the sixth public key of the manufacturer application certificate. That is, the digital signature of the manufacturer user certificate originates from the sixth private key of the manufacturer application certificate, so that the trust from the manufacturer application certificate continues to be partially passed down to the manufacturer user certificate.

[0124] The digital signature of the manufacturer user certificate is obtained by encryption using a sixth private key that matches the sixth public key of the manufacturer application certificate. Accordingly, storing the digital signature of the manufacturer user certificate in the external storage space of the processor ensures its integrity and prevents tampering. For example, the digital signature of the manufacturer user certificate is stored in flash memory outside the processor.

[0125] As an example, the step of verifying the digital signature of the manufacturer's user certificate using the sixth public key includes: decrypting the digital signature of the manufacturer's user certificate using the sixth public key to obtain the original digest of the manufacturer's user certificate; calculating the digest of the manufacturer's user certificate using a preset hash function; when the original digest of the manufacturer's user certificate obtained by decryption is the same as the digest of the manufacturer's user certificate calculated using the preset hash function, the verification of the manufacturer's user certificate is successful; otherwise, the verification of the manufacturer's user certificate fails.

[0126] Therefore, the secure boot method in this embodiment establishes a dual trust chain with the national root certificate and the manufacturer root certificate to achieve dual verification, which can avoid the security risks caused by the failure of a single trust chain and thus help to enhance the security and reliability of trust chain verification.

[0127] Accordingly, embodiments of the present invention also provide a secure boot device, which is applied to a processor.

[0128] Figure 5 This diagram illustrates a structural schematic of an embodiment of the safe start device provided by the present invention. Please refer to the references provided. Figure 5 A safety start device 50, comprising: The first trust measurement module 501 is used to perform a trust measurement on an intermediate certificate using a pre-installed national root certificate in the processor in response to the detection of a preset security startup condition. The intermediate certificate is stored in the external storage space of the processor. The second trust measurement module 502 is used to perform a trust measurement on the user certificate using the intermediate certificate when the trust measurement of the intermediate certificate passes, wherein the user certificate is stored in the external storage space of the processor. The third trust measurement module 503 is used to perform a trust measurement on the basic input / output system using the user certificate when the trust measurement of the user certificate passes. The execution module 504 is used to run the basic input / output system when the confidence metric of the basic input / output system passes.

[0129] In some implementations, the intermediate certificate includes an intermediate root certificate. Accordingly, the first trust measurement module 501 is used to perform a trust measurement on the intermediate root certificate using the national root certificate; the second trust measurement module 502 is used to perform a trust measurement on the user certificate using the intermediate application certificate.

[0130] In some implementations, the intermediate certificate includes an intermediate root certificate and an intermediate application certificate. Accordingly, the first trust measurement module 501 is further configured to perform a trust measurement on the intermediate application certificate using the intermediate root certificate when the trust measurement of the intermediate root certificate passes; the second trust measurement module 502 is configured to perform a trust measurement on the user certificate using the intermediate application certificate.

[0131] In some implementations, the user certificate further includes user identification information, and the processor also has pre-stored user identification information. Accordingly, the second trust measurement module 502 is further configured to: obtain the user identification information in the user certificate when the trust measurement of the user certificate using the intermediate certificate passes, and before performing a trust measurement of the basic input / output system using the user certificate; compare the user identification information in the user certificate with the pre-stored user identification information in the processor; and when it is determined that the user identification information in the user certificate matches the pre-stored trusted user identification information in the processor, pass the trust measurement of the user certificate.

[0132] In some implementations, the user certificate includes public key version number information, and the processor also has the public key version number information of the user certificate pre-configured. Accordingly, the second trust measurement module 502 is further configured to: obtain the public key version number information in the user certificate when the trust measurement of the user certificate using the intermediate certificate passes, and before the trust measurement of the basic input / output system using the user certificate; compare the public key version number information in the user certificate with the public key version number information of the user certificate pre-configured in the processor; and when it is determined that the public key version number in the user certificate is greater than or equal to the public key version number of the user certificate pre-configured in the processor, pass the trust measurement of the user certificate.

[0133] In some embodiments, the secure boot device 50 further includes a public key version number upgrade unit 505, used to upgrade the public key version number of the user certificate pre-installed in the processor when the user certificate expires and is prohibited from use, so that the public key version number of the user certificate pre-installed in the processor is greater than the public key version number in the user certificate.

[0134] In some embodiments, the safety start device 50 further includes: The fourth trust measurement module 506 is used to perform a trust measurement on the manufacturer application certificate using the manufacturer root certificate pre-installed in the processor before running the basic input / output system. The manufacturer application certificate is stored in the external storage space of the processor. The fifth trust measurement module 507 is used to perform a trust measurement on the manufacturer user certificate using the manufacturer application certificate when the trust measurement of the manufacturer application certificate passes, wherein the user certificate is stored in the external storage space of the processor. The operation module 504 is used to run the basic input / output system when the trust measurement of the manufacturer's user certificate passes.

[0135] In some implementations, the preset secure startup condition includes powering on the processor.

[0136] In some implementations, the national root certificate is stored in a one-time programmable memory within the processor.

[0137] The secure boot device in this embodiment of the invention can be used to execute the aforementioned secure boot method, or other functional modules can be used to execute the aforementioned secure boot method. For a detailed description of the secure boot method, please refer to the foregoing section; it will not be repeated here.

[0138] Based on the same inventive concept, embodiments of the present invention also provide a computer device that can implement the secure boot method provided by the embodiments of the present invention through the above-described secure boot method in the form of a loading program.

[0139] refer to Figure 6 The diagram illustrates an optional hardware structure of a computer device according to an embodiment of the present invention. The computer device in this embodiment includes: at least one processor 01, at least one communication interface 02, at least one memory 03, and at least one communication bus 04.

[0140] In this embodiment, the number of processor 01, communication interface 02, memory 03 and communication bus 04 is at least one, and processor 01, communication interface 02 and memory 03 communicate with each other through communication bus 04.

[0141] Communication interface 02 can be an interface for a communication module used for network communication, such as an interface for a Global System for Mobile Communications (GSM) module.

[0142] Processor 01 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the secure boot method provided in this embodiment.

[0143] Memory 03 may include high-speed random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage device. Memory 03 stores one or more computer instructions, which are executed by processor 01 to implement the secure boot method provided in the foregoing embodiments.

[0144] It should be noted that the aforementioned computer device may also include other devices (not shown) that may not be essential to understanding the content disclosed in the embodiments of the present invention; given that these other devices may not be essential for understanding the content disclosed in the embodiments of the present invention, the embodiments of the present invention will not describe them one by one.

[0145] Based on the same inventive concept, embodiments of the present invention also provide a computer program product, including a computer program / instructions, which, when executed by a processor, are used to implement the secure boot method described in the embodiments of the present invention. For a detailed description of the secure boot method provided in the embodiments of the present invention, please refer to the foregoing section.

[0146] Based on the same inventive concept, embodiments of the present invention also provide a storage medium storing one or more computer instructions for implementing the secure boot method provided in the foregoing embodiments. For a detailed description of the secure boot method provided in the foregoing sections, please refer to the relevant sections.

[0147] The embodiments of the present invention described above are combinations of elements and features of the present invention. Unless otherwise stated, elements or features may be considered optional. Individual elements or features may be practiced without combination with other elements or features. Furthermore, embodiments of the present invention may be constructed by combining some elements and / or features. The order of operations described in the embodiments of the present invention may be rearranged. Some constructions of any embodiment may be included in another embodiment and may be replaced by corresponding constructions of another embodiment. It will be apparent to those skilled in the art that claims in the appended claims that are not explicitly referenced in each other may be combined to form embodiments of the present invention, or may be included as new claims in amendments filed after the submission of this application.

[0148] Embodiments of the present invention can be implemented by various means, such as hardware, firmware, software, or combinations thereof. In a hardware configuration, the method according to an exemplary embodiment of the present invention can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, etc.

[0149] In firmware or software configuration, embodiments of the present invention can be implemented in the form of modules, processes, functions, etc. Software code can be stored in a memory unit and executed by a processor. The memory unit is located inside or outside the processor and can send data to and receive data from the processor via various known means.

[0150] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is accorded the widest scope consistent with the principles and novel features disclosed herein.

[0151] While the present invention has been disclosed above, it is not limited thereto. Any person skilled in the art can make various modifications and alterations without departing from the spirit and scope of the invention; therefore, the scope of protection of the present invention should be determined by the scope defined in the claims.

Claims

1. A secure boot method applied to a processor, characterized in that, include: In response to the detection of a preset secure boot condition, the intermediate certificate is assessed for trustworthiness using a pre-installed national root certificate within the processor. The intermediate certificate is stored in the processor's external storage space. When the trust measurement of the intermediate certificate passes, the user certificate is used to perform a trust measurement on the intermediate certificate, and the user certificate is stored in the external storage space of the processor. When the trust measurement of the user certificate passes, the trust measurement of the basic input / output system is performed using the user certificate; When the confidence metric of the basic input / output system passes, the basic input / output system is run.

2. The secure startup method as described in claim 1, characterized in that, The intermediate certificate includes an intermediate root certificate; The step of using the pre-installed national root certificate in the processor to perform a trust measurement on the intermediate certificate includes: using the national root certificate to perform a trust measurement on the intermediate root certificate; Using the intermediate certificate to perform a trust measurement on the user certificate includes: using the intermediate root certificate to perform a trust measurement on the user certificate.

3. The safe startup method as described in claim 2, characterized in that, The intermediate certificate also includes an intermediate application certificate; When the trust measurement of the intermediate root certificate passes, the method further includes: using the intermediate root certificate to perform a trust measurement of the intermediate application certificate; When the trust measurement of the intermediate application certificate passes, the step of using the intermediate certificate to perform a trust measurement of the user certificate includes: using the intermediate application certificate to perform a trust measurement of the user certificate.

4. The secure startup method as described in claim 1, characterized in that, The user certificate includes user identification information, and the processor also has user identification information pre-installed. When the user certificate passes the trust measurement using the intermediate certificate, and before the basic input / output system passes the trust measurement using the user certificate, the trust measurement of the user certificate further includes: obtaining user identification information in the user certificate; comparing the user identification information in the user certificate with user identification information preset in the processor; and when it is determined that the user identification information in the user certificate is consistent with the trusted user identification information preset in the processor, the trust measurement of the user certificate passes.

5. The safe startup method as described in claim 1, characterized in that, The user certificate includes public key version number information, and the processor also has the public key version number information of the user certificate pre-installed. Before performing a trust measurement on the user certificate using the intermediate certificate and before performing a trust measurement on the basic input / output system using the user certificate, the trust measurement of the user certificate further includes: obtaining the public key version number information in the user certificate; comparing the public key version number information in the user certificate with the public key version number information of the user certificate pre-installed in the processor; and when it is determined that the public key version number in the user certificate is greater than or equal to the public key version number of the user certificate pre-installed in the processor, the trust measurement of the user certificate passes.

6. The secure startup method as described in claim 5, characterized in that, When the user certificate expires and is prohibited from use, the following also applies: The public key version number of the user certificate pre-installed in the processor is upgraded so that the public key version number of the user certificate pre-installed in the processor is greater than the public key version number in the user certificate.

7. The safe startup method according to any one of claims 1 to 6, characterized in that, Before running the basic input / output system, the following are also included: The manufacturer application certificate is trusted using a manufacturer root certificate pre-installed within the processor, and the manufacturer application certificate is stored in the processor's external storage space. When the trust measurement of the manufacturer application certificate passes, the trust measurement of the manufacturer user certificate is performed using the manufacturer application certificate. The manufacturer user certificate is stored in the external storage space of the processor. The manufacturer user certificate includes the user certificate, or may also include the intermediate certificate. The basic input / output system is run when the trust metric for the manufacturer's user certificate passes.

8. The secure startup method as described in claim 1, characterized in that, The preset safe startup conditions include the processor being powered on.

9. The secure startup method as described in claim 1, characterized in that, The national root certificate is stored in a one-time programmable memory within the processor.

10. A secure boot device applied to a processor, characterized in that, include: The first trust measurement module is used to perform a trust measurement on an intermediate certificate using a pre-installed national root certificate in the processor in response to the detection of a preset secure startup condition. The intermediate certificate is stored in the external storage space of the processor. The second trust measurement module is used to perform a trust measurement on the user certificate using the intermediate certificate when the trust measurement of the intermediate certificate passes, wherein the user certificate is stored in the external storage space of the processor. The third trust measurement module is used to perform a trust measurement on the basic input / output system using the user certificate when the trust measurement of the user certificate passes. A running module is used to run the basic input / output system when a confidence metric for the basic input / output system passes.

11. The safety start device as described in claim 10, characterized in that, The intermediate certificate includes an intermediate root certificate; The first trust measurement module is used to perform trust measurement on the intermediate root certificate using the national root certificate; The second trust measurement module is used to perform trust measurement on the user certificate using the intermediate application certificate.

12. The safety start device as described in claim 11, characterized in that, The intermediate certificate includes an intermediate root certificate and also includes an intermediate application certificate; The first trust measurement module is further configured to perform a trust measurement on the intermediate application certificate using the intermediate root certificate when the trust measurement of the intermediate root certificate passes. The second trust measurement module is used to perform trust measurement on the user certificate using the intermediate application certificate.

13. The safety start device as described in claim 10, characterized in that, The user certificate also includes user identification information, and the processor also has user identification information pre-installed. The second trust measurement module is further configured to: obtain user identification information in the user certificate when the trust measurement of the user certificate using the intermediate certificate passes, and before the trust measurement of the basic input / output system using the user certificate; compare the user identification information in the user certificate with user identification information preset in the processor; and when it is determined that the user identification information in the user certificate is consistent with the trusted user identification information preset in the processor, pass the trust measurement of the user certificate.

14. The safety start device as described in claim 10, characterized in that, The user certificate includes public key version number information, and the processor also has the public key version number information of the user certificate pre-installed. The second trust measurement module is further configured to obtain the public key version number information in the user certificate when the trust measurement of the user certificate using the intermediate certificate passes, and before the trust measurement of the basic input / output system using the user certificate; The public key version number information in the user certificate is compared with the public key version number information of the user certificate pre-installed in the processor; When it is determined that the public key version number in the user certificate is greater than or equal to the public key version number of the user certificate preset in the processor, the trust measurement of the user certificate is passed.

15. The safety start device as described in claim 14, characterized in that, Also includes: The public key version number upgrade unit is used to upgrade the public key version number of the user certificate pre-installed in the processor when the user certificate expires and is prohibited from use, so that the public key version number of the user certificate pre-installed in the processor is greater than the public key version number in the user certificate.

16. The safety start device as described in any one of claims 10 to 15, characterized in that, Also includes: The fourth trust measurement module is used to perform a trust measurement on the manufacturer application certificate using the manufacturer root certificate pre-installed in the processor before running the basic input / output system. The manufacturer application certificate is stored in the external storage space of the processor. The fifth trust measurement module is used to perform a trust measurement on the manufacturer user certificate using the manufacturer application certificate when the trust measurement of the manufacturer application certificate passes. The manufacturer user certificate is stored in the external storage space of the processor. The manufacturer user certificate includes the user certificate or may also include the intermediate certificate. The running module is used to run the basic input / output system when the trust metric of the manufacturer's user certificate passes.

17. A computer device, characterized in that, include: At least one memory and at least one processor; The memory stores one or more computer-executable instructions, and the processor invokes the one or more computer-executable instructions to execute the secure boot method as described in any one of claims 1 to 9.

18. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they are used to implement the secure boot method as described in any one of claims 1 to 9.

19. A storage medium, characterized in that, The storage medium stores one or more computer instructions, which are used to implement the secure boot method as described in any one of claims 1 to 9.