Safe starting device of domestic mainboard
The motherboard safe boot device, designed using domestically produced TPCM chips and CPLD devices, solves the security risks of computer motherboards relying on foreign products, realizes safe boot and autonomy of domestically produced motherboards, and ensures the security and information sovereignty of computer systems.
Patent Information
- Application Number
- CN202423281360.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2034-12-30
AI Technical Summary
The current reliance on foreign products for computer motherboards poses security risks, such as the implantation of backdoor programs, data theft or surveillance, threatening information sovereignty and security.
A domestic motherboard secure boot device is designed using domestically produced TPCM chips and CPLD devices. By prioritizing power-on boot of the TPCM chip, a reliable measurement of the BIOS firmware and secure initialization of the operating system are achieved. Combined with domestically produced BIOS FLASH memory and SWITCH signal switcher, the secure boot of the motherboard is ensured.
It improves the security and autonomy of computer motherboards, ensures domestic design, avoids security risks, and safeguards information sovereignty and security.
Smart Images

Figure CN223665000U_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The utility model belongs to computer technology field, and specifically relates to a safe starting device of domestic mainboard. BACKGROUND
[0002] The mainboard starting is important to the normal operation of computer. The mainboard as the heart of computer, connects and coordinates various hardware components, such as CPU, memory, hard disk etc. In the starting process, the BIOS chip of mainboard is responsible for power-on self-test and loads operating system, which is the basis for the smooth start of computer.
[0003] Computer, server as the core equipment of information storage, processing and transmission, carries a large number of key data and sensitive information. Excessive dependence on foreign products may have security risks, such as being implanted backdoor program, data theft or monitoring, which seriously threatens the information sovereignty and security of the country. UTILITY MODEL CONTENT
[0004] The utility model aims at solving the problems in the background art and provides a safe starting device of domestic mainboard.
[0005] To achieve the above object, the utility model takes the technical scheme that:
[0006] The utility model provides a safe starting device of domestic mainboard, which comprises a CPLD device, a TPCM chip, a CPU device, a SWITCH signal switcher and a BIOS FLASH memory, wherein:
[0007] The CPLD device is electrically connected with the SWITCH signal switcher, the TPCM chip and the CPU device respectively, and the TPCM chip and the CPU device are electrically connected with the SWITCH signal switcher, and the SWITCH signal switcher is electrically connected with the BIOS FLASH memory.
[0008] Preferably, the CPLD device and the TPCM chip are both provided with a GPIO interface connected with each other.
[0009] Preferably, the TPCM chip and the CPU device are connected with the SWITCH signal switcher through an SPI bus.
[0010] Preferably, the SWITCH signal switcher is connected with the BIOS FLASH memory through an SPI bus.
[0011] Preferably, the safe starting device of domestic mainboard further comprises a bridge connected with the CPU device, and the bridge is connected with the TPCM chip through a PCIE bus.
[0012] Preferably, the TPCM chip is provided with an M.2 slot, and the bridge is connected with the M.2 slot of the TPCM chip through a PCIE bus.
[0013] Compared with the prior art, the utility model has the beneficial effects that:
[0014] The safety starting device of the domestic mainboard makes the TPCM chip as a safety module to be powered on before other devices in the mainboard, so that the mainboard can be safe, and the device is designed with domestic products, improving safety and autonomy. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1 The module block diagram of the safety starting device of the domestic mainboard. DETAILED DESCRIPTION
[0016] In order to make the purpose, technical scheme and advantages of the present application more clear, the present application is further described in detail below in combination with the drawings and examples. It should be understood that the specific examples described herein are only used to explain the present application, and are not used to limit the present application.
[0017] As Figure 1 shown, a safety starting device of a domestic mainboard is provided, comprising a CPLD device, a TPCM chip, a CPU device, a SWITCH signal switcher and a BIOS FLASH memory, wherein:
[0018] The CPLD device is respectively connected with the SWITCH signal switcher, the TPCM chip and the CPU device, and the TPCM chip and the CPU device are both connected with the SWITCH signal switcher, and the SWITCH signal switcher is connected with the BIOS FLASH memory.
[0019] The safety starting device of the domestic mainboard further comprises a bridge connected with the CPU device, and the bridge is connected with the TPCM chip through a PCIE bus; the TPCM chip is provided with an M.2 slot, and the bridge is connected with the M.2 slot of the TPCM chip through the PCIE bus; wherein the bridge is used for the expansion of a PCIE link, when the PCIE link of the CPU device is insufficient, the CPU device communicates with the TPCM chip through the bridge, and the bridge can be selected from domestic Loongson, Shenwei and Feiteng chips.
[0020] It should be noted that the CPU, as the central processing unit, can be a domestic processor chip such as Loongson 3B6000, Phytium D2000, or Shenwei 831. Based on existing knowledge, a TPCM chip (Trusted Platform Control Module) is a chip embedded within the computer that provides a root of trust. This root of trust includes: Trusted Measure Root (RTM), Trusted Memory Root (RTS), and Trusted Report Root (RTR). TPCM chips can be domestic trusted chips from companies such as National Technology, Trusted Huatai, and Guoxin. The CPLD device is used to control the power-on startup sequence between the TPCM chip, the computer motherboard, and other components. The CPLD device resets the CPU, bridge chip, and TPCM chip via a reset signal. Figure 1 In the CPLD signal, CPU_RST represents the reset signal for resetting the CPU, BG_RST represents the reset signal for resetting the bridge chip, and RST_CTRL represents the reset signal for resetting the TPCM chip. The CPLD can be a domestic chip from companies like Unisoc or Anlu. Simultaneously, the CPLD also controls the SWITCH switcher to switch the channel between the CPU and the TPCM chip. Figure 1 The text indicates that the CPLD device controls the SWITCH signal switch via the SPI_CTRL signal. The SWITCH signal switch can be a TS3A27518EIP device. The BIOS FLASH memory is a non-volatile memory used to store the BIOS firmware (a program file required for CPU device startup). The BIOS FLASH memory can be a domestic chip such as GigaDevice, and the BIOS firmware can be a domestic Kunlun Trusted Firmware.
[0021] In one embodiment, both the CPLD device and the TPCM chip are provided with interconnected GPIO interfaces.
[0022] In one embodiment, both the TPCM chip and the CPU device are connected to a SWITCH signal switcher via an SPI bus. The SWITCH signal switcher switches the SPI channel between the CPU device and the TPCM chip.
[0023] In one embodiment, the SWITCH signal switcher is connected to the BIOS FLASH memory via the SPI bus.
[0024] The working process of the safety boot device on domestically produced motherboards:
[0025] After the mainboard is powered on, the CPLD device first powers on the TPCM chip through the RST_CTRL reset signal (that is, the TPCM chip is started first, other devices are controlled in the Reset state, after detecting that the TPCM chip is in place, an power-on completion signal is given to the TPCM chip, and the TPCM chip informs the CPLD device to give the control right of reading the BIOS FLASH memory to the TPCM chip through the GPIO interface), the TPCM chip performs RTM trusted measurement root on the BIOS FLASH memory (this process belongs to the function of the TPCM chip and belongs to the prior art); the TPCM chip sends the GPIO[0:1] signal to the CPLD device through the GPIO interface, and after the CPLD device receives the signal, the SWITCH signal switch is controlled to switch the SPI channel, so that the SPI channel between the SWITCH signal switch and the TPCM chip is opened, and then the TPCM chip starts active measurement on the BIOS FLASH memory (this process belongs to the function of the TPCM chip and belongs to the prior art), and sends the measurement process and result to the CPLD device through the SWITCH signal switch, if the measurement is passed, the CPLD device controls the SWITCH signal switch to switch the SPI channel, so that the SPI channel between the SWITCH signal switch and the CPU is opened, and then the CPLD device powers on and resets the CPU device and the bridge through the CPU_RST reset signal and the BG_RST reset signal, after the TPCM chip performs trusted measurement on the BIOS firmware, starts self-checking and initialization of the operating system, after the initialization is completed, the security measurement of the operating system kernel information is performed, after the measurement is successful, the OS loader starts operating system loading and running (this process belongs to the function of the TPCM chip and belongs to the prior art). During this period, the BIOS firmware and the TPCM chip interact as necessary, complete hardware initialization and software security measurement according to the configuration strategy provided, and complete startup. Among them, the operating system selects a domestic Kirin trusted operating system.
[0026] The secure boot device of the domestic mainboard makes the TPCM chip as a security module to be powered on and started before other devices in the mainboard, so that the mainboard can be safe, and the device uses domestic design, improving the security and autonomy.
[0027] The above-described embodiments only express several embodiments of the present application, and the description is more specific and detailed, but it cannot be understood as limiting the scope of the utility model patent. It should be pointed out that for ordinary skilled persons in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A safe boot device for a domestically produced motherboard, characterized in that: The safe starting device of the domestic mainboard comprises a CPLD device, a TPCM chip, a CPU device, a SWITCH signal switcher and a BIOS FLASH memory. The CPLD device is electrically connected with the SWITCH signal switcher, the TPCM chip and the CPU device respectively, the TPCM chip and the CPU device are electrically connected with the SWITCH signal switcher, and the SWITCH signal switcher is electrically connected with the BIOS FLASH memory.
2. The secure booting apparatus of a homegrown motherboard as claimed in claim 1, wherein: The CPLD device and the TPCM chip are both provided with a GPIO interface connected with each other.
3. The secure booting apparatus of the homegrown motherboard as claimed in claim 1, wherein: The TPCM chip and the CPU device are connected with the SWITCH signal switcher through an SPI bus.
4. The secure boot apparatus of the homegrown motherboard as claimed in claim 1, wherein: The SWITCH signal switcher is connected with the BIOS FLASH memory through an SPI bus.
5. The secure booting apparatus of the homegrown motherboard as claimed in claim 1, wherein: The safe starting device of the domestic mainboard further comprises a bridge connected with the CPU device, and the bridge is connected with the TPCM chip through a PCIE bus.
6. The secure boot apparatus of the homegrown motherboard as claimed in claim 5, wherein: An M.2 slot is arranged on the TPCM chip, and the bridge is connected with the M.2 slot of the TPCM chip through a PCIE bus.