Domestic server protection device based on trusted card
By using a domestically developed server protection device based on a trusted card, comprehensive measurement and protection of the BIOS FLASH chip and BMC FLASH chip is achieved, solving the problems of passive defense and narrow protection range in existing technologies, and improving the data security and independent controllability of the server.
Patent Information
- Application Number
- CN202520318168.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2035-02-26
AI Technical Summary
Existing server protection methods mainly employ passive defense mechanisms, which cannot effectively resist data security threats. Furthermore, existing trusted cards have a narrow protection scope and fail to fully measure BMC firmware.
Design a domestic server protection device based on a trusted card. By connecting the trusted card, CPU processor, CPLD chip, BMC chip, BIOS FLASH chip, BMC FLASH chip and four SWITCH chips, it realizes measurement protection of BIOS FLASH chip and BMC FLASH chip, and supports online updating of BIOS FLASH chip data by BMC chip.
It achieves comprehensive data protection for BIOS FLASH chip and BMC FLASH chip, with more complete functions, higher applicability, reduced cost, and improved independent controllability and security by using domestically produced components.
Smart Images

Figure CN223897880U_ABST
Abstract
Description
Technical Field
[0001] This utility model belongs to the field of server technology, specifically relating to a domestically produced server protection device based on a trusted card. Background Technology
[0002] As informatization deepens across various sectors, the security of the massive amounts of data generated by their rapid development has become a key constraint on their progress. Therefore, data security has become a major concern. Servers, due to their high-performance data processing capabilities, are widely used, making the security of server data crucial to addressing data security issues.
[0003] However, existing technologies for server protection have the following drawbacks:
[0004] Traditional protection methods, such as firewalls and antivirus software, mainly adopt passive defense mechanisms and cannot actively and effectively protect data. Therefore, they cannot effectively resist the increasing threats to server data security. Existing server protection using trusted cards has a narrow scope, such as only measuring BIOS firmware data and not BMC firmware. Utility Model Content
[0005] The purpose of this invention is to address the problems raised in the background art by proposing a domestically produced server protection device based on a trusted card.
[0006] To achieve the above objectives, the technical solution adopted by this utility model is as follows:
[0007] This utility model proposes a domestic server protection device based on a trusted card, comprising a trusted card, a CPU processor, a CPLD chip, a BMC chip, a BIOS FLASH chip, a BMC FLASH chip, a first SWITCH chip, a second SWITCH chip, a third SWITCH chip, and a fourth SWITCH chip, wherein:
[0008] The CPLD chip is electrically connected to the trusted card, the CPU processor, the BMC chip, the second SWITCH chip, the third SWITCH chip, and the fourth SWITCH chip, respectively. The trusted card, the first SWITCH chip, the third SWITCH chip, the fourth SWITCH chip, and the BIOS FLASH chip are electrically connected in sequence. The second SWITCH chip is also electrically connected to the first SWITCH chip, the BMC chip, and the BMC FLASH chip, respectively. The BMC chip is also electrically connected to the third SWITCH chip, and the CPU processor is also electrically connected to the fourth SWITCH chip.
[0009] Preferably, the domestic server protection device based on the trusted card further includes an LED light, which is electrically connected to the CPLD chip.
[0010] Preferably, both the BIOS FLASH chip and the BMC FLASH chip are GD25LB512MEFIR chips.
[0011] Preferably, each of the SWITCH chips is a TS3A27518EIPWRQ1 chip.
[0012] Preferably, the BMC chip is model E2000S.
[0013] Compared with the prior art, the beneficial effects of this utility model are as follows:
[0014] This domestically developed server protection device based on a trusted card utilizes a connection design between the trusted card, CPU processor, CPLD chip, BMC chip, BIOS FLASH chip, and four SWITCH chips. This design allows the trusted card to measure both the BMC and BIOS FLASH chips, thus protecting their data. Furthermore, it enables the BMC chip to update the BIOS FLASH chip's data online, resulting in a more comprehensive and versatile device. The device also features a simple structure, reducing costs, and its core components are domestically produced, ensuring high levels of autonomy, controllability, and security. Attached Figure Description
[0015] Figure 1 This is a block diagram of the module of the domestic server protection device based on the trusted card of this utility model. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0017] like Figure 1 As shown, a domestically developed server protection device based on a trusted card is provided, including a trusted card, a CPU processor, a CPLD chip, a BMC chip, a BIOS FLASH chip, a BMC FLASH chip, a first SWITCH chip, a second SWITCH chip, a third SWITCH chip, and a fourth SWITCH chip, wherein:
[0018] The CPLD chip is electrically connected to the trusted card, CPU processor, BMC chip, second SWITCH chip, third SWITCH chip and fourth SWITCH chip respectively. The trusted card, first SWITCH chip, third SWITCH chip, fourth SWITCH chip and BIOS FLASH chip are electrically connected in sequence. The second SWITCH chip is also electrically connected to the first SWITCH chip, BMC chip and BMCFLASH chip respectively. The BMC chip is also electrically connected to the third SWITCH chip. The CPU processor is also electrically connected to the fourth SWITCH chip.
[0019] It should be noted that in this embodiment, the Tianjin Phytium S5000C is selected as the CPU processor, the Unisplendour PGC7KD-6CMBG400 is selected as the CPLD chip, the Phytium E2000S is selected as the BMC chip, the GigaDevice GD25LB512MEFIR chip is selected as the BIOS FLASH chip and BMC FLASH chip, the TI TS3A27518EIPWRQ1 is selected as the SWITCH chip, and a domestic trusted card (a trusted card, a PCIE trusted cryptographic card specifically used to enhance system security) is selected.
[0020] Specifically, the link corresponding to the electrical connection between the first SWITCH chip and the trusted card is defined as the first signal channel; the link corresponding to the electrical connection between the first SWITCH chip and the second SWITCH chip is defined as the third signal channel; the link corresponding to the electrical connection between the first SWITCH chip and the third SWITCH chip is defined as the second signal channel; the link corresponding to the electrical connection between the second SWITCH chip and the BMC FLASH chip is defined as the fourth signal channel; the link corresponding to the electrical connection between the second SWITCH chip and the BMC chip is defined as the fifth signal channel; the link corresponding to the electrical connection between the third SWITCH chip and the BMC chip is defined as the sixth signal channel; the link corresponding to the electrical connection between the third SWITCH chip and the fourth SWITCH chip is defined as the seventh signal channel; the link corresponding to the electrical connection between the fourth SWITCH chip and the CPU processor is defined as the eighth signal channel; and the link corresponding to the electrical connection between the fourth SWITCH chip and the BIOS FLASH chip is defined as the ninth signal channel.
[0021] After the server powers on, the trusted card performs measurement on the BMC FLASH chip to achieve protection (data protection of the BMC FLASH firmware is achieved through measurement). The trusted card sends a low-level first SW signal to switch to BMC FLASH chip measurement, a low-level first RST signal to continuously reset the CPU processor, and a low-level second RST signal to continuously reset the BMC chip to the CPLD chip. The CPLD chip sends a low-level third RST signal to continuously reset the CPU processor, and a low-level fourth RST signal to continuously reset the BMC chip. It also sends a low-level second SW signal to the second SWITCH chip (connecting the third and fourth signal channels), and sends high / low level signals to enable the LED to turn on and off (the LED displays the measurement results). The trusted card sends a low-level third SW signal to the first SWITCH chip (connecting the first and third signal channels of the first SWITCH chip), and the trusted card measures the BMC FLASH chip.
[0022] When the BMC FLASH chip measurement is successful, the trusted card sequentially sends a high-level first SW signal to disable the BMC FLASH chip measurement, a high-level first GOOD signal to indicate the completion of the BMC FLASH chip measurement, a high-level second RST signal, and a low-level fourth SW signal to switch to the BIOS FLASH chip measurement to the CPLD chip. The CPLD chip sends a high-level second SW signal to the second SWITCH chip (connecting the fourth and fifth signal channels), and also sends a high-level fourth RST signal to the BMC chip, releasing the BMC chip's reset. The CPLD chip also sends a high-level fifth SW signal to the fourth SWITCH chip (connecting the ninth and seventh signal channels), and a low-level sixth SW signal to the third SWITCH chip (connecting the seventh and second signal channels). The trusted card then sends a high-level third SW signal to the first SWITCH chip (connecting the first and second signal channels of the first SWITCH chip). The trusted card measures the BIOS FLASH chip (achieving data protection for the BIOS FLASH firmware through measurement).
[0023] When the BIOS FLASH chip measurement is successful, the trusted card sequentially pulls the fourth SW signal, the second GOOD signal, and the first RST signal high and sends them to the CPLD chip. The CPLD chip sends a low-level fifth SW signal to the fourth SWITCH chip (connecting the ninth signal channel with the eighth signal channel). The CPLD chip also sends a high-level third RST signal to the CPU processor, causing the CPU processor's reset to be released.
[0024] When updating the BIOS FLASH chip data online using the BMC chip (i.e., BIOS FLASH firmware), the BMC chip sends the seventh and eighth SW signals to the CPLD chip. The CPLD chip then sends a high-level sixth SW signal to the third SWITCH chip (connecting the sixth and seventh signal channels), and sends a high-level fifth SW signal to the fourth SWITCH chip (connecting the ninth and seventh signal channels). The latest BIOS FLASH chip data is uploaded to the BMC chip's web management page. The BMC chip then releases the functions corresponding to the seventh and eighth SW signals. The CPLD chip then sends a low-level sixth SW signal to the third SWITCH chip (connecting the seventh and second signal channels), and also sends a low-level fifth SW signal to the fourth SWITCH chip (connecting the ninth and eighth signal channels).
[0025] The signals above represent the following meanings: SW signal indicates a switching signal, RST signal indicates a reset signal, and GOOD signal indicates a completion signal.
[0026] The measurement process of the trusted card and the online update of the BIOS FLASH chip by the BMC chip are well-known technologies in this field and will not be described in detail.
[0027] In one embodiment, the domestically produced server protection device based on the trusted card also includes an LED light, which is electrically connected to the CPLD chip.
[0028] It should be noted that the CPLD chip sends a signal to the LED to enable the LED display (in this embodiment, the LED is a red-green dual-color LED). The LED prompts display the measurement results of the trusted card. For example, in this embodiment, when the trusted card starts measuring the BMC FLASH chip, the green LED is off, and the red LED flashes twice per second; when the measurement is completed, the green LED flashes twice per second for two seconds and then stays on, while the red LED goes off, indicating that the measurement of the BMC FLASH chip is complete, that is, the data protection of the BMC FLASH chip is completed; when the measurement fails, the green LED goes off, and the red LED flashes twice per second for two seconds and then stays on.
[0029] When the trusted card begins measuring the BIOS FLASH chip, the green LED goes out, and the red LED flashes 4 times per second. When the measurement is complete, the green LED flashes 4 times per second for two seconds and then stays on, while the red LED goes out, indicating that the measurement of the BIOS FLASH chip is complete, thus completing the data protection of the BIOS FLASH. When the measurement fails, the green LED goes out, and the red LED flashes 4 times per second for two seconds and then stays on.
[0030] This domestically developed server protection device based on a trusted card utilizes a connection design between the trusted card, CPU processor, CPLD chip, BMC chip, BIOS FLASH chip, and four SWITCH chips. This design allows the trusted card to measure both the BMC and BIOS FLASH chips, thus protecting their data. Furthermore, it enables the BMC chip to update the BIOS FLASH chip's data online, resulting in a more comprehensive and versatile device. The device also features a simple structure, reducing costs, and its core components are domestically produced, ensuring high levels of autonomy, controllability, and security.
[0031] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the utility model patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A domestically produced server protection device based on a trusted card, characterized in that: The domestically produced server protection device based on a trusted card includes a trusted card, a CPU processor, a CPLD chip, a BMC chip, a BIOS FLASH chip, a BMC FLASH chip, a first SWITCH chip, a second SWITCH chip, a third SWITCH chip, and a fourth SWITCH chip, wherein: The CPLD chip is electrically connected to the trusted card, the CPU processor, the BMC chip, the second SWITCH chip, the third SWITCH chip, and the fourth SWITCH chip, respectively. The trusted card, the first SWITCH chip, the third SWITCH chip, the fourth SWITCH chip, and the BIOS FLASH chip are electrically connected in sequence. The second SWITCH chip is also electrically connected to the first SWITCH chip, the BMC chip, and the BMC FLASH chip, respectively. The BMC chip is also electrically connected to the third SWITCH chip, and the CPU processor is also electrically connected to the fourth SWITCH chip.
2. The domestic server protection device based on a trusted card as described in claim 1, characterized in that: The domestic server protection device based on the trusted card also includes an LED light, which is electrically connected to the CPLD chip.
3. The domestic server protection device based on a trusted card as described in claim 1, characterized in that: Both the BIOS FLASH chip and the BMC FLASH chip are GD25LB512MEFIR chips.
4. The domestic server protection device based on a trusted card as described in claim 1, characterized in that: The model of each SWITCH chip is TS3A27518EIPWRQ1.
5. A domestically produced server protection device based on a trusted card as described in claim 1, characterized in that: The BMC chip is model E2000S.