Server boot inspection system

KR103022915B1Active Publication Date: 2026-09-21INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
KR1020257032103
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Priority Date
2024-12-10
Filing Date
2025-06-06
Publication Date
2026-09-21
Estimated Expiration
2045-06-06

Smart Images

  • Figure 112025109357422-PCT00001_ABST
    Figure 112025109357422-PCT00001_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a server boot inspection system, wherein the system comprises a system boot device and a target inspector, wherein the system boot device comprises a system controller, a management controller, a switch, and a memory, wherein the target boot firmware of the server system is stored in the memory, and the target inspection information of the server system is stored in the target inspector; the switch controls the system controller to communicate with the memory when the server system is booted; and controls the management controller to communicate with the memory when the boot firmware in the memory is waiting for an update; the system controller is configured to access the target inspector and the memory when the server system is booted; and to inspect the target boot firmware using the target inspection information. According to the present application, the problem of low security in the server boot stage in related technology is resolved, thereby achieving the effect of improving the security of the server boot stage.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] [Cross-reference of related applications]

[0002] This application claims priority to a Chinese patent application filed with the Chinese Intellectual Property Office on December 10, 2024, with application number 202411812509.6 and titled "Server Boot Inspection System," all of which are incorporated by reference into this application.

[0003] [Technology Field]

[0004] The embodiments of the present application relate to the field of computers, specifically to a server boot inspection system. Background Technology

[0005] As the server boot phase is the initial stage of the system operation cycle and security directly impacts the system's subsequent operation, security checks on the server boot process are critical for the safe operation of the server system. In related technologies, server architectures generally utilize a configuration where the management controller and the system controller are connected to memory together. In this configuration, the management controller is used to update, maintain, and manage the boot firmware stored in memory, while the system controller is used to call the boot firmware in memory during system booting. However, this architecture presents several challenges: on the one hand, the simultaneous access to memory by the management controller and the system controller leads to errors or corruption in the boot firmware data; on the other hand, there is a risk that the boot firmware in memory may be tampered with. Consequently, when the system controller controls system booting, there is a high probability that it will call tampered boot firmware to boot the system, thereby lowering the security of the server boot phase. The problem to be solved

[0007] The embodiments of the present application provide a server boot inspection system for at least solving the problem of low security in the server boot phase in related technology. means of solving the problem

[0009] According to one embodiment of the present application, a server boot inspection system is provided, which,

[0010] It includes a system boot device and a target checker, wherein the system boot device includes a system controller, a management controller, a switch, and memory, and the management controller, the system controller, and memory are all connected to the switch, and the target checker is connected to the system boot device, and the target boot firmware of the server system is stored in the memory, and the target check information of the server system is stored in the target checker, and the target check information is used to indicate the firmware data status of the boot firmware that is allowed to be used when the server system boots;

[0011] The switch controls the system controller to communicate with memory when the server system is booted; and controls the management controller to communicate with memory when the boot firmware in memory is waiting for an update;

[0012] The system controller is configured to access the target checker and memory when the server system is booted; and to check the target boot firmware using the target check information.

[0013] Optionally, the target inspector is connected to the connection link between the system controller and the switch.

[0014] Optionally, the server boot check system further comprises a reference checker, wherein the reference checker is connected to a connection link between a management controller and a switch, and the reference checker stores reference check information of the server system, and the reference check information is used to indicate firmware data provided in the boot firmware that is permitted to be written into memory;

[0015] The management controller is configured to access a reference checker when the boot firmware in memory is waiting for an update; to check the reference boot firmware to be updated in memory using the reference check information; and, if the check for the reference boot firmware passes, to access memory and update the reference boot firmware in memory.

[0016] Optionally, the server boot check system further includes a synchronization controller, wherein the synchronization controller is connected to a reference checker and a target checker, respectively;

[0017] The synchronization controller matches a first information version of reference inspection information with a second information version of target inspection information; and if the first information version and the second information version do not match, it is configured to update the target inspection information stored in the target inspector using the reference inspection information.

[0018] Optionally, the switch is configured with a first interface connected to a system controller, a second interface connected to a management controller, and a third interface connected to memory;

[0019] The switch is configured to control the first interface and the third interface to communicate when the server system is booted; and to control the second interface and the third interface to communicate when the boot firmware in memory is waiting for an update.

[0020] Optionally, the switch is further configured with a fourth interface, and the target checker is connected to the fourth interface, and reference check information is further stored in the target checker, and the reference check information is used to indicate firmware data provided in the boot firmware that is allowed to be written in memory;

[0021] The switch is configured to control the first interface and the fourth interface to be connected when the server system is booted, and to control the first interface and the third interface to be connected when the system controller accesses target inspection information stored in the target inspector; to control the second interface and the fourth interface to be connected when the boot firmware in memory is waiting for an update, and to control the second interface and the third interface to be connected when the management controller accesses reference inspection information stored in the target inspector.

[0022] Optionally, the memory includes a plurality of sub-memories, and a switch is connected to each sub-memory;

[0023] Multiple sub-memories are configured to redundantly store the boot firmware required to boot the server system.

[0024] Optionally, the memory further includes a storage controller, wherein a first port of the storage controller is connected to a switch and a second port of the storage controller is connected to each sub-memory;

[0025] The storage controller is configured to control the access state of each sub-memory.

[0026] Optionally, the second port of the storage controller includes a plurality of sub-ports, each sub-port being connected to a sub-memory in a one-to-one correspondence;

[0027] The storage controller is configured to screen one target sub-memory to be accessed from a plurality of sub-memories when an access request for a sub-memory is received; and to control the sub-port connected to the target sub-memory and the first port in a connected state.

[0028] Optionally, the storage controller includes a logic control element and a reference switch, wherein the logic control element is connected to the reference switch, and the reference switch is configured with a first port and a plurality of sub-ports;

[0029] The logic control element controls the reference switch to regulate the on-off state between the first port and each sub-port.

[0030] Optionally, when an access request for a sub-memory is received, the logic control element screens a first sub-memory that is not occupied among a plurality of sub-memories; and when the number of first sub-memories is a plurality, the logic control element is configured to screen a target sub-memory among the plurality of first sub-memories whose call priority is greater than or equal to the target priority according to the priority information of the sub-memories, wherein the priority information is determined according to the storage performance of each sub-memory.

[0031] Optionally, the logic control element is also configured to detect the occupancy status of each second sub-memory when the access request is an update request for the boot firmware, wherein the second sub-memory is a memory excluding the target sub-memory from a plurality of sub-memories; and when the second sub-memory is not occupied, to update the boot firmware after the update stored in the target sub-memory to the second sub-memory.

[0032] Optionally, the logic control element is also configured to obtain the access failure frequency in which an access failure occurred when each sub-memory was accessed prior to the current time; to obtain the access order of the multiple sub-memories by sorting the multiple sub-memories according to the ascending order of the access failure frequencies; and to determine the access order as priority information when the multiple sub-memories are accessed.

[0033] Optionally, the target checker is connected to a connection link between the storage controller and the switch, and the target checker further stores reference check information of the server system, and the reference check information is used to indicate firmware data provided in the boot firmware that is allowed to be written into memory;

[0034] The management controller is configured to access the target checker when the boot firmware in memory is waiting for an update; to check the reference boot firmware to be updated in memory using reference check information; and to access the memory and update the reference boot firmware in memory when the check for the reference boot firmware passes.

[0035] Optionally, the target checker is connected to a connection link between a sub-memory and a corresponding sub-port, and the target checker further stores reference check information of the server system, and the reference check information is configured to indicate firmware data provided in the boot firmware that is allowed to be written into memory;

[0036] The management controller is configured to access the target checker when the boot firmware in memory is waiting for an update; to check the reference boot firmware to be updated in memory using reference check information; and, if the check for the reference boot firmware passes, to access the target sub-memory and update the reference boot firmware to the target sub-memory. Effects of the invention

[0037] According to the present application, a switch is arranged to connect a system controller, a management controller, and memory, thereby controlling the system controller to communicate with memory when the server system is booted; and by controlling the management controller to communicate with memory when boot firmware in memory is waiting for an update, the system controller and the management controller are effectively prevented from simultaneously accessing memory, thereby preventing data misalignment and data corruption issues of the boot firmware stored in memory. Additionally, a target checker connected to a system boot device is arranged so that the system controller accesses the target checker during the process of booting the server system to inspect the target boot firmware stored in memory, and prevents the system controller from booting the system using tampered boot firmware, thereby improving the security of the server system booting process. Accordingly, the problem of low security in the server boot stage in related technologies can be resolved, and the effect of improving the security of the server boot stage can be achieved. Brief explanation of the drawing

[0039] FIG. 1 is a hardware connection diagram of a server boot inspection system according to an embodiment of the present application. FIG. 2 is a schematic diagram 1 of a server boot inspection system according to an embodiment of the present application. FIG. 3 is a schematic diagram 2 of a server boot inspection system according to an embodiment of the present application. FIG. 4 is a schematic diagram 3 of a server boot inspection system according to an embodiment of the present application. FIG. 5 is a schematic diagram 1 of a server boot inspection system switching a connection link according to an embodiment of the present application. FIG. 6 is a schematic diagram 2 of a server boot inspection system switching a connection link according to an embodiment of the present application. FIG. 7 is a schematic diagram 4 of a server boot inspection system according to an embodiment of the present application. FIG. 8 is a schematic diagram 5 of a server boot inspection system according to an embodiment of the present application. FIG. 9 is a schematic diagram 6 of a server boot inspection system according to an embodiment of the present application. FIG. 10 is a schematic diagram 7 of a server boot inspection system according to an embodiment of the present application. FIG. 11 is a schematic diagram 8 of a server boot inspection system according to an embodiment of the present application. FIG. 12 is a schematic diagram 1 of a server BIOS security inspection system according to an embodiment of the present application. FIG. 13 is a schematic diagram 2 of a server BIOS security inspection system according to an embodiment of the present application. FIG. 14 is a schematic diagram 1 of an optimized server BIOS security inspection system according to an embodiment of the present application. FIG. 15 is a schematic diagram 2 of an optimized server BIOS security inspection system according to an embodiment of the present application. Specific details for implementing the invention

[0040] Hereinafter, embodiments of the present application will be described in detail with reference to the drawings and examples.

[0041] It must be explained that terms such as "first," "second," etc., in the specification, claims, and drawings of this application are intended to distinguish similar objects and are not necessarily intended to describe a specific order or sequence.

[0042] In this embodiment, a server boot inspection system is provided, FIG. 1 is a hardware connection diagram of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 1, the system comprises,

[0043] It includes a system boot device and a target checker, wherein the system boot device includes a system controller, a management controller, a switch, and memory, and the management controller, the system controller, and memory are all connected to the switch, and the target checker is connected to the system boot device, and the target boot firmware of the server system is stored in the memory, and the target check information of the server system is stored in the target checker, and the target check information is used to indicate the firmware data status of the boot firmware that is allowed to be used when the server system boots;

[0044] The switch controls the system controller to communicate with memory when the server system is booted; and controls the management controller to communicate with memory when the boot firmware in memory is waiting for an update;

[0045] The system controller is configured to access the target checker and memory when the server system is booted; and to check the target boot firmware using the target check information.

[0046] According to the above, by placing a switch connecting the system controller, the management controller, and the memory, the system controller is controlled to communicate with the memory when the server system is booted; and by controlling the management controller to communicate with the memory when the boot firmware in the memory is waiting for an update, the system controller and the management controller are effectively prevented from simultaneously accessing the memory, thereby preventing data misalignment and data corruption issues of the boot firmware stored in the memory. Additionally, by placing a target checker connected to the system boot device, the system controller accesses the target checker during the process of booting the server system to inspect the target boot firmware stored in the memory, and by preventing the system controller from booting the system using tampered boot firmware, the security of the server system booting process can be improved. Therefore, the problem of low security in the server boot phase in related technologies can be resolved, and the effect of improving the security of the server boot phase can be achieved.

[0047] Optionally, in an embodiment of the present application, the system controller is configured to communicate with memory via a switch when the server system is booted, wherein the system controller and the switch are connected via a serial peripheral interface (SPI) bus, and when the system needs to be booted, the switch controls the connection link between the system controller and the storage controller to be connected and the connection link between the management controller and the memory to be disconnected, thereby enabling the system controller to load and execute the boot firmware of the server system stored in memory. Additionally, during the booting process, the system controller can access a target checker and perform a legitimacy check on the boot firmware using target check information stored in the target checker to ensure that the server boots in a safe state. In an embodiment of the present application, the system controller may be a Platform Controller Hub (PH), a Central Processing Unit (CPU), etc., but is not limited thereto, and the present means are not limited thereto.

[0048] Optionally, in an embodiment of the present application, the management controller is configured to communicate with memory via a switch during the boot firmware update step; when the management controller needs to access memory, the management controller transmits an access request to memory to the switch, and upon receiving the access request, the switch controls the connection link between the management controller and memory to be connected and controls the connection link between the system controller and memory to be disconnected, thereby enabling the management controller to access and update the boot firmware in memory. In the process of updating the boot firmware stored in memory, to ensure the security of the boot firmware update, the management controller communicates with a checker to access reference check information stored in the checker (reference check information is used to indicate firmware data provided in the boot firmware that is permitted to be written to memory), and uses the reference check information to perform a legality check on the updated firmware, thereby ensuring the security and integrity of the updated firmware. In an embodiment of the present application, the management controller may be a Baseboard Management Controller (BMC), an Integrated Light-Out (iLO), etc., but is not limited thereto; Here, iLO is a control element with server remote management capabilities, and it is a remote server management processor embedded in the motherboard of the server and computing module. By using iLO, the server can be monitored and controlled from a remote location. If the management controller is iLO, remote access to the server can be implemented through remote access to iLO, and furthermore, access requests to memory can be transmitted to the switch via an external access method. When the switch establishes the connection link between the management controller and the memory, updates and upgrades to the boot firmware are implemented by accessing the boot firmware within the memory through iLO.

[0049] Optionally, in an embodiment of the present application, the switch is configured to dynamically switch the data path according to the server state (boot or waiting for update) so that the system controller and the management controller can access the memory independently. When the server is in the boot state, the switch turns on the data path between the system controller and the memory, and when the boot firmware in the memory is in the waiting state for update, the switch switches to the data path between the system controller and the memory, thereby ensuring the independence and security of the data update. In an embodiment of the present application, the switch may be a MUX (Multiplexer), SPI Switch ICs (SPI bus switch integrated circuits), etc., but is not limited thereto, and the present means is not limited thereto.

[0050] Optionally, in an embodiment of the present application, the memory is configured to store boot firmware of a server system, and the memory is connected to a system controller and a management controller via a switch to ensure safe and independent access during the booting and updating process of the firmware. The memory may be designed as a single unit or as multiple redundant units. The design of multiple redundant memories ensures that the system can read data from other healthy memories even if a failure occurs in any memory. For example, when the server system boots, the firmware in each of the multiple memories can be inspected, and if it is discovered that the firmware data in any memory has been tampered with or corrupted, the system automatically switches to another memory to read the correct firmware data, thereby preventing abnormal booting of the server caused by the corruption of the firmware data in any memory. In an embodiment of the present application, the memory may be Flash (Flash Memory), SSD (Solid State Drive), MRAM (Magnetoresistive Random Access Memory), etc., but is not limited thereto, and the present means is not limited thereto.

[0051] Optionally, in an embodiment of the present application, the checker is configured to perform a security check on the firmware data in memory during the server system boot phase and the firmware data update phase in memory. The checker stores the server system check information, and in the firmware data update phase in memory, the management controller communicates with the checker before writing the updated firmware to memory, checks the updated firmware using the check information in the checker, and allows the management controller to write the updated firmware to memory only if the check passes; in the server system boot phase, the system controller first accesses the checker, checks the firmware data in memory using the check information in the checker, and allows the system controller to boot the server system using the firmware data only if the check passes. In an embodiment of the present application, the checker may be a Trusted Platform Module (TPM), a Secure Boot ROM (SBR), etc., but is not limited thereto, and the present means are not limited thereto.

[0052] Optionally, in an embodiment of the present application, FIG. 1 is a hardware connection diagram of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 1, the system boot device comprises a system controller, a management controller, a switch, and a memory, wherein the management controller, the system controller, and the memory are directly connected to the switch via an SPI bus, and the target inspector is connected to the system boot device, and when the boot firmware in the memory needs to be updated via the management controller, the management controller transmits an SEL signal (select signal) to the switch, and the switch controls the management controller to communicate with the memory by switching the SPI bus path, the management controller loads a new firmware file and communicates with the TPM before writing it to the memory, performs a legality check on the updated firmware using inspection information stored therein, and if the check passes, allows the management controller to write the updated firmware to the memory; When the server is booted, the switch disconnects the connection between the management controller and memory and switches to the path between the system controller and memory, and the system controller accesses the TPM to obtain target inspection information and performs an integrity and legality check on the target boot firmware in memory to ensure that the firmware data completely matches the inspection information, and if the inspection passes, the system controller allows the server to boot using the target boot firmware.

[0053] As an optional embodiment, the target inspector is connected to a connection link between the system controller and the switch.

[0054] Optionally, in an embodiment of the present application, FIG. 2 is a schematic diagram 1 of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 2, a TPM (target inspector) is connected to a connection link between a PCH (system controller) and a MUX (switch), and the PCH, management controller, TPM, and FLASH (memory) are connected via an SPI bus, and the TPM is directly connected to the PCH, and the management controller and PCH can each independently access FLASH through MUX switching, and when the server system is in the boot phase, the MUX controls the PCH to communicate with FLASH, and then the PCH accesses the TPM located between the PCH and the MUX to obtain target inspection information stored in the TPM, and the PCH performs a security inspection on the target boot firmware stored in FLASH using the target inspection information, and if the inspection passes, the PCH boots the server system using the target boot firmware.

[0055] According to the above configuration, by connecting the target checker to the connection link between the system controller and the switch, the target checker performs a legality and integrity check on the boot firmware in memory when the server system boots, thereby ensuring security during the process of booting and operating the server.

[0056] As an optional embodiment, the server boot check system further comprises a reference checker, wherein the reference checker is connected to a connection link between a management controller and a switch, and the reference checker stores reference check information of the server system, and the reference check information is used to indicate firmware data provided in boot firmware that is allowed to be written into memory;

[0057] The management controller is configured to access a reference checker when the boot firmware in memory is waiting for an update; to check the reference boot firmware to be updated in memory using the reference check information; and, if the check for the reference boot firmware passes, to access memory and update the reference boot firmware in memory.

[0058] Optionally, in an embodiment of the present application, FIG. 3 is a schematic diagram 2 of a server boot inspection system according to an embodiment of the present application, and as illustrated in FIG. 3, the server boot inspection system includes TPM0 (target inspector) and also includes TPM1 (reference inspector), TPM1 is connected to a connection link between a management controller and a MUX (switch), and when the boot firmware in memory is in a waiting state for an update, the management controller transmits an SEL signal to the MUX, and after receiving the signal transmitted by the management controller, the MUX switches the channel to control the management controller to communicate with the FLASH, the management controller accesses TPM1 to obtain reference inspection information stored therein before writing the updated firmware to the FLASH, furthermore, the management controller uses the reference inspection information to perform an integrity and legality check on the new firmware data to be written to the FLASH, and if the check passes, the management controller allows the new firmware data to be written to the FLASH and completes the update of the boot firmware in the FLASH; When the server is booted, the MUX blocks the connection link between the management controller and FLASH and switches the channel to control the PCH to communicate with FLASH; the PCH accesses TPM0 to obtain the target inspection information stored therein, and furthermore, the PCH uses the target inspection information to perform integrity and legality checks on the target boot firmware within FLASH; if the check passes, the PCH allows the server system to boot using the target boot firmware.

[0059] According to the above configuration, a reference checker is connected to a connection link between a management controller and a switch, thereby ensuring that the server can perform security checks on the boot firmware through a checker on the corresponding link during both the upgrade and boot processes, thus preventing FLASH information from being illegally damaged or tampered with during the boot firmware upgrade process, thereby ensuring the security of the server system during the upgrade and boot.

[0060] As an optional embodiment, the server boot check system further includes a synchronization controller, wherein the synchronization controller is connected to a reference checker and a target checker, respectively;

[0061] The synchronization controller matches a first information version of reference inspection information with a second information version of target inspection information; and if the first information version and the second information version do not match, it is configured to update the target inspection information stored in the target inspector using the reference inspection information.

[0062] Optionally, in an embodiment of the present application, FIG. 4 is a schematic diagram 3 of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 4, the server boot inspection system further includes a synchronization controller, the synchronization controller is connected to a reference inspector (TPM1) and a target inspector (TPM0), respectively, and the synchronization controller is configured to monitor, maintain, and manage the consistency of inspection information between different inspectors of the server system.

[0063] Optionally, in an embodiment of the present application, during server booting or within a specified maintenance and management cycle, the synchronization controller actively triggers synchronization of the inspection information of the target inspector and the reference inspector, and the synchronization controller reads the current latest first version of information from the reference inspector while simultaneously reading the current latest second version of information from the target inspector, and furthermore, the synchronization controller compares the two versions of inspection information to check whether they match, and if the first version of information and the second version of information do not match, the synchronization controller updates the information in the target inspector using the latest inspection information in the reference inspector to ensure that the information versions of all inspectors match.

[0064] According to the above configuration, by installing a synchronization controller between the target checker and the reference checker, it is possible to ensure that the check information stored in the system remains consistent and up-to-date, thereby reducing the risk of verification using outdated or incorrect check information and further enhancing the overall security and reliability of the server system.

[0065] As an optional embodiment, the switch is configured with a first interface connected to a system controller, a second interface connected to a management controller, and a third interface connected to memory;

[0066] The switch is configured to control the first interface and the third interface to communicate when the server system is booted; and to control the second interface and the third interface to communicate when the boot firmware in memory is waiting for an update.

[0067] Optionally, in an embodiment of the present application, FIG. 5 is a schematic diagram 1 of a server boot inspection system according to an embodiment of the present application switching connection links, and as shown in FIG. 5, a switch (MUX) is configured with a first interface, a second interface, and a third interface, wherein the first interface is configured to be connected to a system controller (PCH), the second interface is configured to be connected to a management controller, and the third interface is configured to be connected to memory (FLASH). When the server system is booted, the switch (MUX) controls the first interface and the third interface to be connected, that is, controls the system controller (PCH) and the memory (FLASH) to be connected; and when the boot firmware in the memory is waiting for an update, the switch (MUX) controls the second interface and the third interface to be connected, that is, controls the management controller and the memory (FLASH) to be connected.

[0068] According to the above configuration, the management controller and the system controller are controlled to access memory independently and securely through a switch, thereby preventing boot firmware errors caused by the management controller and the system controller accessing memory simultaneously, which improves the security and stability of the server system operation.

[0069] As an optional embodiment, the switch is further configured with a fourth interface, and a target checker is connected to the fourth interface, and reference check information is further stored in the target checker, and the reference check information is used to indicate firmware data provided in boot firmware that is allowed to be written in memory;

[0070] The switch is configured to control the first interface and the fourth interface to be connected when the server system is booted, and to control the first interface and the third interface to be connected when the system controller accesses target inspection information stored in the target inspector; to control the second interface and the fourth interface to be connected when the boot firmware in memory is waiting for an update, and to control the second interface and the third interface to be connected when the management controller accesses reference inspection information stored in the target inspector.

[0071] Optionally, in an embodiment of the present application, FIG. 6 is a schematic diagram 2 of a server boot inspection system according to an embodiment of the present application switching a connection link, and as shown in FIG. 6, a fourth interface is further configured in the switch (MUX), and a target inspector (TPM) is connected to the fourth interface, and the TPM stores target inspection information used to indicate the firmware data status of the boot firmware allowed to be used when the server system is booted, and also stores reference inspection information used to indicate the firmware data provided in the boot firmware allowed to be written in memory.

[0072] Optionally, in an embodiment of the present application, when the boot firmware in memory is waiting for an update, the management controller transmits an SEL signal to the MUX, and the MUX controls the second interface and the fourth interface to be in communication, that is, controls the management controller to be in communication with the TPM, furthermore, the management controller may access the TPM to obtain reference check information stored therein, and after the management controller obtains the reference check information, the MUX controls the second interface and the third interface to be in communication, that is, controls the management controller to be in communication with the FLASH, and the management controller performs a security check on the new boot firmware using the obtained reference check information, and if the check passes, the management controller allows the new firmware data to be written to the FLASH; When the server system is booted, the MUX blocks the connection between the second interface and the third interface, controls the first interface and the fourth interface to communicate, and controls the PCH to communicate with the TPM. The PCH can access the TPM to obtain target inspection information stored therein. After the PCH obtains the target inspection information, the MUX controls the first interface and the third interface to communicate, that is, controls the PCH to communicate with the FLASH. The PCH uses the obtained target inspection information to perform a security check on the target boot firmware within the FLASH, and if the check passes, the PCH allows the server to boot using the target boot firmware.

[0073] According to the above configuration, by adding a fourth interface for connecting a target inspector and adding control logic for a switch, security inspections of firmware data during the update and boot phases of the server can be performed simultaneously through a single inspector, thereby improving security during the process of booting and updating the server, as well as simplifying the system configuration.

[0074] As an optional embodiment, the memory includes a plurality of sub-memories, and a switch is connected to each of the respective sub-memories;

[0075] Multiple sub-memories are configured to redundantly store the boot firmware required to boot the server system.

[0076] Optionally, in an embodiment of the present application, FIG. 7 is a schematic diagram 4 of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 7, the memory includes a plurality of sub-memories (e.g., FLASH0, FLASH1, etc.), and a switch (MUX) is connected to each of the sub-memories, and each sub-memory independently stores a copy of a complete server boot firmware, and through such a redundant memory design, when a failure or data corruption occurs in one or more sub-memories, the system can still load firmware from another healthy sub-memory to ensure normal booting and operation of the server.

[0077] According to the above configuration, the memory is designed to include multiple sub-memories, and a switch is connected to each sub-memory, thereby improving the data redundancy and fault tolerance of the system, which can enhance the stability and security of the server.

[0078] As an optional embodiment, the memory further comprises a storage controller, wherein a first port of the storage controller is connected to a switch and a second port of the storage controller is connected to each sub-memory;

[0079] The storage controller is configured to control the access state of each sub-memory.

[0080] Optionally, in an embodiment of the present application, FIG. 8 is a schematic diagram 5 of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 8, the memory further includes a storage controller, wherein the first port of the storage controller is connected to a switch (MUX) and serves to receive access requests and commands from the switch (MUX), and the second port of the storage controller is connected to each sub-memory (e.g., FLASH0, FLASH1) and can dynamically control the access state in which each sub-memory is accessed according to the command of the switch, that is, determine which sub-memory can be read or written.

[0081] According to the above configuration, the storage controller is connected to the sub-memory in a one-to-one correspondence through the second port, so that the storage controller can independently control access to each sub-memory and does not affect the state of other sub-memories, thereby improving the security of data storage and the flexibility of access control.

[0082] As an optional embodiment, the second port of the storage controller includes a plurality of sub-ports, each sub-port is connected to a sub-memory in a one-to-one correspondence;

[0083] The storage controller is configured to screen one target sub-memory to be accessed from a plurality of sub-memories when an access request for a sub-memory is received; and to control the sub-port connected to the target sub-memory and the first port in a connected state.

[0084] Optionally, in an embodiment of the present application, the second port of the storage controller includes a plurality of sub-ports, each sub-port being connected to a sub-memory in a one-to-one correspondence, and the storage controller can control the connection state between the switch and the plurality of sub-memories by controlling the connection state between the first port and the plurality of sub-ports. When a server needs to boot or perform a firmware update, the system controller or management controller transmits an access request to the storage controller through the switch, and after receiving the access request, the storage controller performs a status check and screening on the plurality of sub-memories. The master memory and slave memory are pre-configured in the plurality of sub-memories to check the status of the master memory first. If the current health status of the master memory is good, the current master memory is determined as the target sub-memory. If a failure or data corruption occurs in the master memory, the status of the plurality of slave memories is checked sequentially again, and the slave memory checked as having a good health status first is used as the target sub-memory. In an embodiment of the present application, the access history of each sub-memory is checked through a storage controller, and based on the access frequency or load balance of each sub-memory, a sub-memory that has been accessed relatively infrequently within a certain period of time is preferentially selected as a target sub-memory, thereby preventing data overload or wear problems caused by consecutively accessing the same sub-memory multiple times and enabling balanced data access. Furthermore, after the target sub-memory is determined, the storage controller allows data reading or writing operations by controlling the sub-port connected to the target sub-memory and the first port (i.e., the port connected to the switch) to be in a connected state.

[0085] According to the above configuration, a storage controller is installed in memory, and a sub-port design corresponding one-to-one with the sub-memory is used to improve the security of data storage and the flexibility of access control, and to strengthen the stability and security of the server during the booting and firmware update processes.

[0086] As an optional embodiment, the storage controller includes a logic control element and a reference switch, wherein the logic control element is connected to the reference switch, and the reference switch is configured with a first port and a plurality of sub-ports;

[0087] The logic control element controls the reference switch to regulate the on-off state between the first port and each sub-port.

[0088] Optionally, in an embodiment of the present application, the storage controller includes a logic control element and a reference switch, wherein the logic control element controls the reference switch to regulate the on-off state between a first port and a plurality of sub-ports corresponding to a plurality of sub-memories, and the logic control element may be a Complex Programmable Logic Device (CPLD), a Field-Programmable Gate Array (FPGA), etc., but is not limited thereto, and the present means is not limited thereto. FIG. 9 is a schematic diagram 6 of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 9, the logic control element (CPLD) is connected to a reference switch (MUX1), and the reference switch (MUX1) is configured with a first port (a port connected to switch MUX0) and a plurality of sub-ports (ports connected to a plurality of sub-memories).

[0089] Optionally, in an embodiment of the present application, in the BIOS security check system of a server, sub-memories are designated as Master FLASH (assumed to be FLASH0) and Slave FLASH (assumed to be FLASH1). According to this design, when the PCH (System Controller) boots normally and when the management controller performs a BIOS firmware update, operations and data interactions can be performed only on the Master FLASH. The Slave FLASH is isolated at this stage and does not allow direct external access, thereby ensuring the security and stability of the data. By periodically synchronizing the data of FLASH0 with FLASH1, the CPLD isolates direct operations of FLASH1 by the PCH and the management controller and ensures the security and stability of the FLASH1 data.

[0090] Optionally, in an embodiment of the present application, if FLASH0 fails to pass the TPM check due to abnormal operation of FLASH0 or abnormal refresh of the management controller, the CPLD switches the authority of FLASH, switches FLASH1 as the master FLASH to enable normal system use, and switches FLASH0 as the slave FLASH to ensure stable operation of the machine and isolate the impact of abnormal FLASH0 data on the system, and additionally, the CPLD reports the abnormal event to the system and notifies the operations and maintenance manager to take timely action.

[0091] According to the above configuration, a logic control element and a reference switch are combined to provide the server security inspection system with advanced data access control and storage resource management capabilities, thereby significantly improving the security, stability, and management efficiency of the system.

[0092] As an optional embodiment, the logic control element is configured to screen a first sub-memory that is not occupied among a plurality of sub-memories when an access request for a sub-memory is received; and, if the number of first sub-memories is a plurality, to screen a target sub-memory among the plurality of first sub-memories whose call priority is greater than or equal to the target priority according to priority information of the sub-memories, wherein the priority information is determined according to the storage performance of each sub-memory.

[0093] Optionally, in an embodiment of the present application, when a logic control element receives an access request for a sub-memory, the logic control element first screens all unoccupied first sub-memories, that is, when there is no sub-memory currently undergoing read and write operations and the number of first sub-memories is 1, the current unique one first sub-memory is determined as the target sub-memory, and when there are multiple first sub-memories, the logic control element further screens according to priority information of each sub-memory, the priority information is determined according to the storage performance of the sub-memory, such as the read and write speed of the memory, storage capacity, data access delay, etc., and furthermore, the logic control element screens for the optimal target sub-memory from the first sub-memory that is unoccupied and has a priority higher than the target priority.

[0094] According to the above configuration, through the intelligent screening and priority management mechanism of the logic control element, the server security inspection system can efficiently and safely access sub-memory, thereby ensuring data security and system stability during the boot phase and firmware update process.

[0095] As an optional embodiment, the logic control element is also configured to detect the occupancy status of each second sub-memory when the access request is an update request for the boot firmware, wherein the second sub-memory is a memory excluding the target sub-memory from a plurality of sub-memories; and when the second sub-memory is not occupied, to update the boot firmware after the update stored in the target sub-memory to the second sub-memory.

[0096] Optionally, in an embodiment of the present application, when a logic control element receives a request to update the boot firmware, checks the occupancy status of all second sub-memories (i.e., sub-memories other than the target sub-memory) to ensure that other unoccupied sub-memories can be configured for backup or subsequent updates after the target sub-memory performs the firmware update, and furthermore, if it is detected that one or more second sub-memories are in an unoccupied state, the logic control element updates the boot firmware after the update stored in the target sub-memory to the second sub-memories.

[0097] According to the above configuration, redundant firmware backups are provided to the server, so that even if a failure occurs in the target sub-memory, the system can boot normally through the second sub-memory, thereby improving the stability and usability of the server.

[0098] As an optional embodiment, the logic control element is also configured to obtain an access failure frequency in which an access failure occurred when each sub-memory was accessed prior to the current time; to obtain an access order of the multiple sub-memories by sorting the multiple sub-memories according to the ascending order of the access failure frequencies; and to determine the access order as priority information when the multiple sub-memories are accessed.

[0099] Optionally, in an embodiment of the present application, a logic control element continuously monitors the access history of each sub-memory and records the number of failures that occurred when the sub-memory is accessed within a specific time window, including but not limited to events such as data read failure, write delay, and data integrity check failure, and comprehensively extracts the access failure frequency of each sub-memory. Based on the acquired access failure frequency data, the logic control element sorts a plurality of sub-memories according to the ascending order of access failure frequency to obtain the access order of the plurality of sub-memories, and determines the access order as priority information when the plurality of sub-memories are accessed. Additionally, the priority of the sub-memory can be adjusted in real time according to dynamic changes in the failure frequency. For example, during the sub-memory access process, if a sudden increase in the failure frequency of the sub-memory currently being accessed is detected, the logic control element immediately lowers the priority and, when the sub-memory failure frequency is higher than a certain threshold, isolates it from the normal access list to prevent it from having an additional impact on the system.

[0100] Optionally, in an embodiment of the present application, FIG. 9 is a schematic diagram 6 of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 9, when the server system boot firmware needs to perform an online upgrade, the management controller transmits an SEL signal to MUX0 (switch), and MUX0 controls the management controller to communicate with the storage controller, and after the storage controller receives an access request for the sub-memory, screens the target sub-memory from a plurality of sub-memories according to the priority information of the sub-memory, and during the firmware update process, the management controller safely writes new firmware data to the target sub-memory, and after the firmware update is completed in the target sub-memory (e.g., FLASH0), the logic control element (CPLD) begins to perform a redundant backup of the firmware data with the sub-memory. First, the CPLD detects the current occupancy status of sub-memories other than the target sub-memory in the system (i.e., the second sub-memory, e.g., FLASH1). If the second sub-memory is not occupied, the CPLD transmits a control signal to MUX1 (reference switch) to adjust the connection status between MUX1 and the sub-memory, switches the data path from the target sub-memory to the second sub-memory, and the CPLD updates the boot firmware after the update stored in the target sub-memory to the second sub-memory.When the server is booted, MUX0 blocks the connection between the management controller and MUX1 and switches the link to control the PCH to communicate with MUX1. Subsequently, the PCH accesses the TPM (Target Checker) to obtain the target check information stored therein and performs an integrity and legality check on the target boot firmware within the target sub-memory to ensure that the firmware data completely matches the check information. If the check passes, the PCH is allowed to boot the server using the target boot firmware. If the check of the target boot firmware within the target sub-memory fails, the CPLD automatically switches the data access link between MUX1 and the sub-memory according to the preset priority information of the sub-memory to communicate the second sub-memory, which is in a normal state, with MUX1. Furthermore, since the PCH can boot using the boot firmware within the second sub-memory, it is ensured that the server can be quickly recovered when a memory failure occurs, and the stable operation of the system is maintained. Furthermore, during server operation, the CPLD continuously monitors the status and failure frequency of all sub-memories, dynamically adjusts priority information, and ensures that the system can perform data access by selecting the optimal sub-memory based on the latest performance data and health conditions.

[0101] According to the above configuration, the server security inspection system can not only safely and efficiently complete firmware updates, but also reduce system downtime caused by memory anomalies through data redundancy synchronization and fault switching strategies, and improve the stability and security of the system in complex operating environments.

[0102] As an optional embodiment, the target checker is connected to a connection link between a storage controller and a switch, and the target checker further stores reference check information of a server system, and the reference check information is used to indicate firmware data provided in boot firmware that is allowed to be written into memory;

[0103] The management controller is configured to access the target checker when the boot firmware in memory is waiting for an update; to check the reference boot firmware to be updated in memory using reference check information; and to access the memory and update the reference boot firmware in memory when the check for the reference boot firmware passes.

[0104] Optionally, in an embodiment of the present application, FIG. 10 is a schematic diagram 7 of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 10, a target inspector (TPM) is connected to a connection link between a storage controller and a switch (MUX0), and the TPM stores target inspection information used to indicate the firmware data status of the boot firmware allowed to be used when the server system is booted, and also stores reference inspection information used to indicate the firmware data provided in the boot firmware allowed to be written in memory.

[0105] Optionally, in an embodiment of the present application, by installing a TPM on the connection link between MUX0 and the storage controller, it is ensured that both the PCH and the management controller can directly access the TPM without the need for MUX0 to frequently switch data paths, thereby reducing the frequency and complexity of data switching and improving the efficiency and stability of data transmission. Regardless of whether it is a BIOS upgrade or a BIOS boot, both can directly access the TPM to perform legitimacy and integrity checks on the boot firmware.

[0106] According to the above configuration, by connecting the target inspector to the connection link between the storage controller and the switch, it is possible to ensure that both the system controller and the management controller can directly access the TPM, thereby reducing the processing load on the switch and decreasing resource consumption of the server system.

[0107] As an optional embodiment, the target checker is connected to a connection link between a sub-memory and a corresponding sub-port, and the target checker further stores reference check information of a server system, and the reference check information is used to indicate firmware data provided in boot firmware that is allowed to be written into memory;

[0108] The management controller is configured to access the target checker when the boot firmware in memory is waiting for an update; to check the reference boot firmware to be updated in memory using reference check information; and, if the check for the reference boot firmware passes, to access the target sub-memory and update the reference boot firmware to the target sub-memory.

[0109] Optionally, in an embodiment of the present application, FIG. 11 is a schematic diagram 8 of a server boot inspection system according to an embodiment of the present application, and as shown in FIG. 11, a target inspector (TPM) is connected to a connection link between a sub-memory and a corresponding sub-port, so that the TPM can directly participate in the inspection of firmware data stored in the sub-memory without the help of a switch, thereby simplifying the data path and reducing delays and potential errors in the data transmission process.

[0110] Optionally, in an embodiment of the present application, both the TPM and a plurality of sub-memories are installed behind the SPI bus MUX1 (reference switch) so that the TPM can monitor and verify the integrity and legitimacy of the firmware data in the sub-memories in real time. When performing a BIOS online upgrade, for the BIOS firmware to be upgraded, the server must enter the S5 state (STBY standby state), at which time the PWRON signal (level signal) becomes low level to control the MUX0 chip to switch to the management controller, that is, ensuring that the management controller has control authority over the SPI bus and is completely isolated from the PCH. The management controller first selects the first FLASH via the SEL signal to ensure that the SPI path from the management controller to FLASH0 is connected, then loads the burning file of the BIOS FW (i.e., the BIOS firmware file), and subsequently, the management controller calls the hash check value of the TPM to check the security and legitimacy of the BIOS FW burning file. Only if the check passes is the management controller allowed to burn the BIOS FW file to FLASH0. If the burning is successful, the management controller selects the SPI bus of FLASH1 via the SEL signal, repeats the previous steps, and burns the BIOS FW file to FLASH1, thereby ensuring that the BIOS FW files in the two FLASH dies match. During server operation, if the active FLASH is tampered with or the FW integrity check fails, the server can switch to the other FLASH to boot, thereby ensuring normal booting of the server BIOS and improving the security and stability of the server.

[0111] In a normal boot scenario of the server, when the server is powered on, the PWRON signal becomes high level to control MUX0 to switch to the PCH, completely isolating the connection of the management controller, thereby ensuring the security of the channel and preventing risks such as tampering of the BIOS FW by the management controller channel; at this time, the PCH loads the BIOS FW in FLASH0 and simultaneously checks the integrity and legality of the BIOS FW through the TPM, and if the check passes, the BIOS FW is executed until the server boots normally, and if the check fails, the PCH switches to FLASH1 via the SEL signal to perform the same FW integrity and legality check, and if the check is normal, booting continues, and if it fails, the server's power-on is prohibited, and the user is notified that there is an abnormality in the server's BIOS and booting is impossible, so that action is taken as soon as possible.

[0112] According to the above configuration, by designing the target inspector to be directly connected between the sub-memory and the corresponding sub-port, the data transmission path can be simplified, complex data switching in assemblies such as switches is prevented, and the server system's defense capabilities against firmware security threats are effectively enhanced through real-time security inspection.

[0113] Optionally, in an embodiment of the present application, a server BIOS security inspection system is further provided, FIG. 12 is a schematic diagram 1 of a server BIOS security inspection system according to an embodiment of the present application, and as shown in FIG. 12, a PCH (system controller), a BMC (management controller), a TPM (target inspector), and a FLASH (memory) die are connected via an SPI bus, the TPM is directly connected to the PCH, and the BMC and PCH can access the BIOS FLASH in a time-sharing manner through MUX (switch) switching to implement an upgrade of the BIOS FW (boot firmware), but the BMC cannot interact with the TPM. The BIOS FLASH is set to FLASH0 and FLASH1, and if one of the FLASHs malfunctions or the BIOS FW within the FLASH fails the TPM check, it automatically switches to the other FLASH to boot. If both FLASHs are damaged or fail the check, the server does not boot and notifies the user that the BIOS FLASH is damaged or tampered with. By installing dual BIOS FLASHs, a hard backup of the BIOS FW is implemented, thereby ensuring the security and stability of the BIOS.

[0114] When an online upgrade of the BIOS FW is required, the SPI MUX chip is controlled via the BMC to switch the SPI bus to the BMC, and the BIOS FW can be burned into the FLASH. If necessary, the BIOS FW of one or two FLASHs can be upgraded, which improves convenience.

[0115] When the BIOS FW performs an online upgrade, the FW file can be written to the FLASH die even if illegal manipulation or FLASH information tampering exists. This results in problems where the server cannot boot normally due to BIOS information being tampered with or the firmware being corrupted, posing a significant threat to the security and reliability of the server. During an online upgrade, the BMC cannot access the TPM, so it cannot verify whether the BIOS FW upgrade file is complete and legal. Furthermore, since the BMC only checks the integrity of the BIOS FW file, it cannot guarantee the security and legality of the BIOS FW upgrade file.

[0116] FIG. 13 is a schematic diagram 2 of a server BIOS security inspection system according to an embodiment of the present application. As shown in FIG. 13, a single BIOS FLASH of the TPM module is connected to the BMC and PCH via an SPI bus and switched between them via a MUX, thereby ensuring that both the PCH and BMC can access the BIOS FLASH, but only the PCH can access the TPM and the BMC cannot access it normally. It also ensures that the legitimacy and integrity of the FW can be checked through the TPM during BIOS booting, and ensures the security of the server during the booting and operation process.

[0117] The PCH and BMC communicate with the BIOS FLASH by switching the MUX chip, and this means can only guarantee the integrity and legality of the BIOS FW when the BIOS boots. That is, when the BIOS boots, the BIOS is checked through the TPM, and if the check passes, the BIOS is allowed to boot normally. If the BIOS is illegally tampered with or the BIOS FW is damaged, or if the check is abnormal, i.e., a fail, the BIOS boot is prohibited, thereby guaranteeing the security and legality of the BIOS boot.

[0118] When upgrading the BIOS via the BMC, the BMC switches the connection of the MUX to the BMC via the SEL signal, thereby directly burning the FW file onto the BIOS FLASH. Since the BMC only checks the integrity of the file burned onto the BIOS FW and cannot access the TPM, it can directly burn or modify the BIOS FW. Once the burning is complete, it checks the legitimacy of the BIOS FW upon power-on. If the BIOS FW is illegally modified at this time, the system cannot prevent this action, and eventually, the server is abnormally tampered with and fails the legitimacy check, making booting impossible and affecting the security and stability of the server.

[0119] FIG. 14 is a schematic diagram 1 of an optimized server BIOS security inspection system according to an embodiment of the present application. As shown in FIG. 14, the TPM module and two BIOS FLASH modules are all installed behind the SPI bus MUX to ensure that both the PCH and the BMC can access the TPM. Regardless of whether it is a BIOS upgrade or a BIOS boot, the legitimacy and integrity of the FW can be checked through the TPM, thereby ensuring the security of the server during upgrades and booting.

[0120] The two BIOS FLASH flashes and the TPM are installed to be directly connected via the SPI bus, allowing the TPM to monitor and verify the integrity and legitimacy of the two FLASH data in real time. When performing an online BIOS upgrade, the server must enter the S5 state (STBY standby state) for the BIOS FW to be upgraded; at this time, the PWRON signal becomes low to control the MUX chip to switch to the BMC, thereby ensuring that the BMC has control over the SPI bus and is completely isolated from the PCH. The BMC first selects the first FLASH via the SEL signal to ensure that the SPI path from the BMC to FLASH0 is connected, then loads the BIOS burning file, and subsequently, the BMC calls the HASH check value of the TPM to check the security and legitimacy of the BIOS FW burning file, and only if the check passes is the BMC allowed to burn the BIOS FW file to FLASH0, and if the burning is successful, the BMC selects the SPI bus of FLASH1 via the SEL signal, repeats the previous step, and burns the BIOS FW file to FLASH1, thereby ensuring that the BIOS FW files in the two FLASH dies match, and while the server is operating, if the active FLASH is tampered with or the FW integrity check fails, it can switch to the other FLASH to boot, thereby ensuring normal booting of the server BIOS and improving the security and stability of the server.

[0121] In a normal boot scenario of the server, when the server is powered on, the PWRON signal becomes high level to control the MUX to switch to the PCH, completely isolating the connection of the BMC, thereby ensuring the security of the pathway and preventing risks such as tampering of the BIOS FW by the BMC pathway; at this time, the PCH loads the BIOS FW in FLASH0 and simultaneously checks the integrity and legality of the BIOS FW through the TPM, and if the check passes, the BIOS FW is executed until the server boots normally, and if the check fails, the PCH switches to FLASH1 via the SEL signal to perform the same FW integrity and legality check, and if the check is normal, the server continues to boot, and if it fails, the server's power-on is prohibited, and the user is notified that there is an abnormality in the server's BIOS and booting is impossible, so that they take action as soon as possible.

[0122] In a scenario where the server operates normally, the PWRON signal is always high and the SPI channel is always maintained in contact with the PCH, allowing the integrity and legality of the inspection data to be checked in real time. Through this, after normal power-on, the PCH has sole control and cannot be modified, thereby preventing the risk of the BMC tampering with or damaging the BIOS FW or data.

[0123] The installation of dual BIOS FLASH ensures hardware redundancy in the BIOS FW design and improves the security and stability of the server; by establishing BMC access to the TPM pathway, it ensures the security and legitimacy of online upgrades of BIOS FW files, thereby preventing tampering or damage to the BIOS.

[0124] FIG. 15 is a schematic diagram 2 of an optimized server BIOS security inspection system according to an embodiment of the present application, and as shown in FIG. 15, the actions of three hosts related to the topology, namely PCH\BMC\CPLD (Logical Control Unit), performing read and write operations on two flashes must all pass the inspection of the TPM.

[0125] FLASH0 is the master FLASH and FLASH1 is the slave FLASH. When the PCH boots normally, it accesses the flash and performs data interactions, or when the BMC upgrades the BIOS FW, only the master flash, i.e., flash0, can be manipulated. FLASH1 is the slave FLASH, and the CPLD periodically synchronizes the data from flash0 to FLASH1, thereby isolating direct manipulation of FLASH1 by the PCH and BMC and ensuring the security and stability of the FLASH1 data.

[0126] If FLASH fails to pass the TPM check due to abnormal operation of FLASH0 or abnormal refresh of BMC, CPLD switches the authority of the two FLASHs, switches FLASH1 as the master FLASH to enable normal system use, and switches FLASH0 as the slave FLASH to ensure stable operation of the machine and isolate the impact of abnormal flash data on the system. Additionally, CPLD reports the abnormal event to the system and notifies the operations and maintenance manager to take timely action.

[0127] Specific examples of the present embodiment may refer to the examples described in the above embodiments and exemplary embodiments, and the present embodiment is not described further herein.

[0128] Of course, those skilled in the art should understand that each module or each step of the above-described application may be implemented through a general-purpose computing device, and may be integrated into a single computing device or distributed across a network of multiple computing devices; and since they may be implemented through program code executable by a computing device, they may be stored in a storage device and executed by a computing device; in some cases, steps illustrated or described may be performed in an order different from the order herein; they may be fabricated as individual integrated circuit modules; or multiple modules or steps thereof may be fabricated and implemented as a single integrated circuit module. As such, the present application is not limited by any specific combination of hardware and software.

[0129] The above is merely a preferred embodiment of the present application and is not intended to limit the present application. Those skilled in the art may make various changes and modifications to the present application. Any modifications, equivalent substitutions, improvements, etc. made within the scope of the principles of the present application shall be included within the scope of protection of the present application.

Claims

Claim 1 A server boot inspection system comprises a system boot device and a target inspector, wherein the system boot device comprises a system controller, a management controller, a switch, and a memory, and the management controller, the system controller, and the memory are all connected to the switch, and the target inspector is connected to the system boot device, and the target boot firmware of the server system is stored in the memory, and the target inspection information of the server system is stored in the target inspector, and the target inspection information is used to indicate the firmware data status of the boot firmware that is allowed to be used when the server system is booted; the switch controls the system controller to communicate with the memory when the server system is booted; and controls the management controller to communicate with the memory when the boot firmware in the memory is waiting for an update; and the system controller accesses the target inspector and the memory when the server system is booted; A server boot inspection system configured to inspect the target boot firmware using the target inspection information, wherein the target inspector is connected to a connection link between the system controller and the switch, and the server boot inspection system further includes a reference inspector, wherein the reference inspector is connected to a connection link between the management controller and the switch, wherein the reference inspector stores reference inspection information of the server system, and the reference inspection information is used to indicate firmware data provided in the boot firmware that is allowed to be written in the memory; wherein the management controller accesses the reference inspector when the boot firmware in the memory is waiting for an update; uses the reference inspection information to inspect the reference boot firmware to be updated in the memory; and, if the inspection of the reference boot firmware passes, accesses the memory and is configured to update the reference boot firmware in the memory. Claim 2 A server boot inspection system according to claim 1, characterized in that the target inspector is configured to perform a security inspection on the target boot firmware in memory during the server system boot phase and the firmware data update phase in memory. Claim 3 A server boot inspection system according to claim 1, wherein the management controller is configured to transmit a switching signal to the switch when the boot firmware in memory is in an update waiting state; the switch controls the management controller to communicate with the memory in response to the switching signal; and the management controller is configured to access reference inspection information stored in the reference inspector before writing the reference boot firmware to be updated to the memory, and to use the reference inspection information to inspect the firmware data of the reference boot firmware to be updated, and if the inspection passes, to allow the management controller to write the firmware data of the reference boot firmware to the memory. Claim 4 A server boot inspection system according to claim 1, wherein the server boot inspection system further comprises a synchronization controller, wherein the synchronization controller is connected to the reference inspector and the target inspector, respectively; wherein the synchronization controller matches a first information version of the reference inspection information with a second information version of the target inspection information; and wherein, if the matching of the first information version and the second information version does not match, the server boot inspection system is configured to update the target inspection information stored in the target inspector using the reference inspection information. Claim 5 A server boot inspection system according to paragraph 2, wherein the switch blocks the connection link between the management controller and the memory when the server is in a boot state and controls the system controller to communicate with the memory; and the system controller accesses target inspection information stored in the target inspector when the server is in a boot state; performs an integrity and legality check on the target boot firmware in memory using the target inspection information, and is configured to boot the server system using the target boot firmware if the check passes. Claim 6 A server boot inspection system according to claim 1, wherein the switch is configured with a first interface connected to the system controller, a second interface connected to the management controller, and a third interface connected to the memory; wherein the switch is configured to control the first interface and the third interface to communicate when the server system is booted; and to control the second interface and the third interface to communicate when the boot firmware in the memory is waiting for an update. Claim 7 A server boot inspection system according to claim 6, wherein the switch further comprises a fourth interface, the target inspector is connected to the fourth interface, the target inspector further stores reference inspection information, and the reference inspection information is used to indicate firmware data provided in the boot firmware that is allowed to be written in the memory; wherein the switch controls the first interface and the fourth interface to be in communication when the server system is booted, and controls the first interface and the third interface to be in communication when the system controller accesses the target inspection information stored in the target inspector; and controls the second interface and the fourth interface to be in communication when the boot firmware in the memory is waiting for an update, and controls the second interface and the third interface to be in communication when the management controller accesses the reference inspection information stored in the target inspector. Claim 8 A server boot inspection system according to claim 1, wherein the memory comprises a plurality of sub-memories and the switch is connected to each of the respective sub-memories; and wherein the plurality of sub-memories are configured to redundantly store boot firmware required to boot the server system. Claim 9 A server boot inspection system according to claim 8, wherein the memory further comprises a storage controller, wherein a first port of the storage controller is connected to the switch and a second port of the storage controller is connected to each of the sub-memories; and wherein the storage controller is configured to control the access state in which each of the sub-memories is accessed. Claim 10 A server boot inspection system according to claim 9, wherein the second port of the storage controller includes a plurality of sub-ports, each of which is connected to the sub-memory in a one-to-one correspondence; and wherein, when an access request for the sub-memory is received, the storage controller screens one target sub-memory to be accessed from the plurality of sub-memories; and is configured to control the sub-port connected to the target sub-memory and the first port in a connected state. Claim 11 A server boot inspection system according to claim 10, wherein the storage controller is also configured to detect the past access frequency of each of the sub-memories and to determine the sub-memory in which the past access frequency is lower than the set frequency as the target sub-memory. Claim 12 A server boot inspection system according to claim 10, wherein the storage controller comprises a logic control element and a reference switch, wherein the logic control element is connected to the reference switch and the reference switch is configured with the first port and a plurality of the sub-ports; and wherein the logic control element controls the reference switch to regulate the on-off state between the first port and each of the sub-ports. Claim 13 A server boot inspection system according to claim 12, wherein the logic control element is configured to screen a first sub-memory that is not occupied among a plurality of the sub-memories when an access request for the sub-memory is received; and, when the number of the first sub-memories is a plurality, to screen a target sub-memory in which the call priority among the plurality of the first sub-memories is greater than or equal to the target priority according to the priority information of the sub-memories, wherein the priority information is determined according to the storage performance of each of the sub-memories. Claim 14 A server boot inspection system according to claim 12, wherein the logic control element further detects the occupancy status of each second sub-memory when the access request is an update request for boot firmware, wherein the second sub-memory is a sub-memory excluding the target sub-memory from a plurality of sub-memories; and when the second sub-memory is not occupied, the system is configured to update the boot firmware after the update stored in the target sub-memory to the second sub-memory. Claim 15 A server boot inspection system according to claim 13, wherein the logic control element further obtains an access failure frequency in which an access failure occurs when each of the sub-memories is accessed before receiving an access request for the sub-memories; obtains an access order of the plurality of sub-memories by sorting the plurality of sub-memories according to the ascending order of the access failure frequencies; and is configured to determine the access order as priority information when the plurality of sub-memories are accessed. Claim 16 A server boot inspection system according to claim 9, wherein the target inspector is connected to a connection link between the storage controller and the switch, and the target inspector further stores reference inspection information of the server system, and the reference inspection information is used to indicate firmware data provided in the boot firmware that is allowed to be written in the memory; and the management controller is configured to access the target inspector when the boot firmware in the memory is waiting for an update; to inspect the reference boot firmware to be updated in the memory using the reference inspection information; and, when the inspection of the reference boot firmware passes, to access the memory and update the reference boot firmware in the memory. Claim 17 A server boot inspection system according to claim 10, wherein the target inspector is connected to a connection link between the sub-memory and a corresponding sub-port, and the target inspector further stores reference inspection information of the server system, and the reference inspection information is used to indicate firmware data provided in the boot firmware that is allowed to be written in the memory; and the management controller is configured to access the target inspector when the boot firmware in the memory is waiting for an update; to inspect the reference boot firmware to be updated in the memory using the reference inspection information; and, when the inspection of the reference boot firmware passes, to access the target sub-memory and update the reference boot firmware in the target sub-memory. Claim 18 delete Claim 19 delete Claim 20 delete

Citation Information

Patent Citations

  • A server flash security management method and system

    CN109670319A

  • A system and method for secure boot of server

    CN110109715A

  • Server startup verification system

    CN119293803A