Secure boot method for chip, chip, electronic device, and storage medium
By using asynchronous concurrent interaction method during chip startup, notification message interaction between the business module and the security module solves the problem of low chip startup efficiency in the prior art, and achieves faster startup time and higher performance.
Patent Information
- Application Number
- PCT/CN2024/123861
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-10-10
- Publication Date
- 2025-05-08
AI Technical Summary
During the startup process, existing chips need to perform security verification on multiple mirror files, resulting in multiple communications between the security module and the service module, resulting in low chip startup efficiency and poor performance.
The service module transmits two notification messages to the security module, indicating the start and exit of the security verification process respectively. During this process, the service module continues to transport the mirror file to the running memory, and the security module continues to verify until all files are checked.
Through asynchronous concurrent interaction, communication resources between the business module and the security module are saved, the chip start-up time is shortened, and the chip start-up performance is greatly improved.
Smart Images

Figure CN2024123861_08052025_PF_FP_ABST
Abstract
Description
Chip secure startup method, chip, electronic device and storage medium
[0001] This application claims priority to Chinese patent application No. 202311442109.6 filed on October 31, 2023, entitled “Secure startup method for chip, chip, electronic device and storage medium”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of chip technology, and in particular to a chip secure startup method, chip, electronic device, and storage medium. Background Art
[0003] Chips are semiconductor components, often called integrated circuits, and are widely used in various smart devices, such as smart terminals, smart home appliances, and smart cars. To ensure chip security during startup, image files loaded at each stage of the chip's startup process are typically verified for security. Only after passing the verification can the corresponding image file be loaded.
[0004] In related technologies, a security module independent of the service module is deployed on the chip to ensure secure booting of the chip. The security module communicates with the service module based on the System Control and Management Interface (SCMI) and provides security verification for image files. For example, a synchronous serial communication method is used to verify each of the multiple image files involved in the chip booting process.
[0005] However, since the chip startup process often involves a large number of image files, the above method requires multiple communications between the security module and the business module, resulting in low chip startup efficiency and poor performance.
[0006] Summary of the Invention
[0007] The embodiments of the present application provide a secure boot method for a chip, a chip, an electronic device, and a storage medium, which can effectively shorten the chip boot time and improve the chip boot performance. The technical solution is as follows:
[0008] In a first aspect, a secure boot method for a chip is provided, wherein the chip involved in this application includes a business module and a security module independent of the business module, and the chip can be applied to various electronic devices, such as smart terminal devices, V2X devices, and physical servers. The method includes: after the business module transmits a first notification message to the security module, it begins to move multiple image files in the memory to the chip's running memory, and the first notification message indicates the start of a security verification process for the multiple image files; the security module receives the first notification message and performs a security verification on the image files that have been moved to the running memory; if the multiple image files have been moved to the running memory and the multiple image files have completed the security verification, the business module transmits a second notification message to the security module and loads the multiple image files in the running memory, and the second notification message indicates the exit of the security verification process.
[0009] Through the above method, during the secure startup process of the chip, the business module transmits two notification messages to the security module to respectively instruct the security module to start and exit the security verification process for the image file. After the business module instructs the security module to start the security verification process, the business module begins to continuously move the image file to the running memory. It should be understood that this process is continuous, that is, after the business module moves an image file to the running memory, it does not need to wait for the security module to perform a security verification on it, but continues to move the next image file. In addition, the security module begins to continuously verify the image files that have been moved to the running memory until all the image files have been moved to the running memory and the security verification has been completed. The business module instructs the security module to exit the security verification process. Through this asynchronous concurrent interaction method between the business module and the security module, not only the communication resources between the business module and the security module are saved, but also the chip startup time is shortened, and the chip startup performance is greatly improved. For example, taking the chip as an intelligent driving chip as an example, since intelligent driving chips widely use advanced processes and cannot implement built-in flash memory (Flash), intelligent driving chips usually use external Flash to implement non-volatile storage. According to security requirements, the image file stored in the external Flash needs to be encrypted and stored. In this way, during the safe startup process of the intelligent driving chip, the image file stored in the external Flash needs to be moved to the running memory and the image file needs to be securely verified. The secure startup method provided by this application can greatly shorten the chip startup time and thus improve the chip startup performance. It should be understood that this is only an example. The secure startup method provided by this application can be applied to chips in which various startup processes involve the transportation and security verification of image files, and this application does not limit this.
[0010] In some embodiments, the business module runs trusted firmware, and the security module runs secure firmware. The trusted firmware and the security firmware communicate via a system control and management interface (SCMI) to establish a communication connection between the business module and the security module. Based on the foregoing, it can be seen that the business module and the security module can execute their respective functions concurrently. This reduces the strong coupling between the trusted firmware on the business module and the secure firmware on the security module, making the execution of functions on both sides independent of each other and improving the robustness of the system.
[0011] In some embodiments, the business module transmits a first notification message to the security module, including: the business module runs the trusted firmware, and sends a first interrupt signal to the security firmware running on the security module based on the SCMI, so that the security module obtains the first notification message from the register when receiving the first interrupt signal; the business module transmits a second notification message to the security module, including: the business module runs the trusted firmware, and sends a second interrupt signal to the security firmware running on the security module based on the SCMI, so that the security module obtains the second notification message from the register when receiving the second interrupt signal. For example, the business module runs the trusted firmware, writes the first notification message to the register (which can be understood as a mailbox) according to the message format negotiated with the security firmware, and then sends a first interrupt signal to the security firmware running on the security module based on the SCMI standard channel, so that the security module obtains the first notification message from the register after receiving the first interrupt signal. The transmission process of the second notification message is similar, so it will not be repeated.
[0012] In some embodiments, the memory is integrated on the chip, or the memory is located outside the chip and connected to the chip.
[0013] In some embodiments, before the business module transmits the first notification message to the security module, the method further includes: the business module creates a task list in the shared memory, the task list indicates the transfer status of each image file in the multiple image files, and the first notification message indicates the security verification process based on the task list, wherein the business module and the security module both have access rights to the shared memory.
[0014] In some embodiments, after the service module moves the first image file indicated by the task list to the running memory, the method further includes: the service module updating the moving status of the first image file in the task list;
[0015] The security module performs a security check on the image file that has been moved to the running memory, including: the security module reads that the moving status of the first image file in the task list is successful, and performs a security check on the first image file.
[0016] In some embodiments, after the security module performs a security check on the first image file, the method further includes: the security module updating the security check result of the first image file in the task list. In this manner, since the business module can also access the task list, the business module can promptly obtain the security check result of the first image file in the task list, providing technical support for determining whether to notify the security module to exit the security check process.
[0017] In some embodiments, the first notification message includes a storage address of the task list in the shared memory.
[0018] In some embodiments, the task list further indicates at least one of the following: a storage address of each image file in the running memory, verification parameters involved in a security verification process of each image file, and a security verification result of each image file.
[0019] In some embodiments, the security module includes a security submodule and at least one computing submodule, the security submodule is used to send security verification tasks corresponding to the multiple image files to the at least one computing submodule, and the at least one computing submodule is used to execute the security verification tasks corresponding to the multiple image files.
[0020] In some embodiments, the business module is a business core in the chip used to run an operating system, the security submodule is a security core in the chip used for secure booting, and the computing submodule is a computing core in the chip used to perform security verification tasks.
[0021] In some embodiments, the security module performs a security check on the image file that has been moved to the running memory, including: the security sub-module sends a security check task corresponding to the second image file to the at least one computing sub-module through a first-in-first-out FIFO channel based on a buffer descriptor BD based on the second image file that has been moved to the running memory.
[0022] In some embodiments, the security module performs a security check on the image file that has been moved to the running memory, including:
[0023] The security submodule determines, based on the third image file and the fourth image file that have been transferred to the running memory and the task execution status of the plurality of computing submodules, a first computing submodule and a second computing submodule that are in an idle state among the plurality of computing submodules;
[0024] The security submodule issues the security verification task corresponding to the third image file and the security verification task corresponding to the fourth image file to the first computing submodule and the second computing submodule respectively, so that the first computing submodule and the second computing submodule concurrently execute the security verification task corresponding to the third image file and the security verification task corresponding to the fourth image file.
[0025] Through the above method, the security module can send the security verification task of the image file to multiple idle computing sub-modules through the security sub-module. In this way, the multi-channel hardware acceleration mechanism between the security sub-module and the computing sub-module in the security module is fully utilized, that is, the chip resources are fully utilized, which can greatly improve the execution efficiency of the security verification task and further improve the chip startup performance.
[0026] In some embodiments, if the multiple image files have been moved to the running memory and the multiple image files have completed security verification, the business module transmits a second notification message to the security module and loads the multiple image files in the running memory, including:
[0027] If the business module has moved the multiple image files to the running memory and read the security verification results for the multiple image files, the second notification message is transmitted to the security module, and the multiple image files in the running memory are loaded.
[0028] In a second aspect, an embodiment of the present application provides a chip, the chip including a service module and a security module, the service module and the security module being communicatively connected;
[0029] The business module is configured to start moving the multiple image files in the memory to the running memory of the chip after transmitting a first notification message to the security module, wherein the first notification message indicates the start of a security verification process for the multiple image files;
[0030] The security module is configured to receive the first notification message and perform a security check on the image file that has been moved to the running memory;
[0031] The business module is also used to transmit a second notification message to the security module and load the multiple image files in the running memory if the multiple image files have been moved to the running memory and the multiple image files have completed security verification, and the second notification message indicates to exit the security verification process.
[0032] In some embodiments, trusted firmware runs on the business module, and secure firmware runs on the security module. The trusted firmware and the secure firmware transmit messages based on the system control management interface SCMI to achieve a communication connection between the business module and the security module.
[0033] In some embodiments, the business module is used to:
[0034] Running the trusted firmware, and sending a first interrupt signal to the security firmware running on the security module based on the SCMI, so that the security module obtains the first notification message from a register when receiving the first interrupt signal;
[0035] The trusted firmware is run, and a second interrupt signal is sent to the security firmware running on the security module based on the SCMI, so that the security module obtains the second notification message from the register when the second interrupt signal is received.
[0036] In some embodiments, the memory is integrated on the chip, or the memory is located outside the chip and connected to the chip.
[0037] In some embodiments, the security module includes a security submodule and at least one computing submodule, the security submodule is used to send security verification tasks corresponding to the multiple image files to the at least one computing submodule, and the at least one computing submodule is used to execute the security verification tasks corresponding to the multiple image files.
[0038] In some embodiments, the business module is a business core in the chip used to run an operating system, the security submodule is a security core in the chip used for secure booting, and the computing submodule is a computing core in the chip used to perform security verification tasks.
[0039] In a third aspect, an embodiment of the present application provides an electronic device, which includes a chip, the chip including a business module and a security module, and the chip is used to implement the chip security startup method provided in the first aspect or any optional method of the first aspect.
[0040] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium for storing at least one program code, wherein the at least one program code is used to implement the secure boot method for a chip provided in the first aspect or any optional embodiment of the first aspect. The storage medium includes, but is not limited to, volatile memory, such as random access memory, and non-volatile memory, such as flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0041] In a fifth aspect, embodiments of the present application provide a computer program product that, when executed on a chip, enables the chip to implement the secure boot method for a chip provided in the first aspect or any optional embodiment of the first aspect. The computer program product may be a software installation package, which can be downloaded and executed on the chip when the functions of the aforementioned chip need to be implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] FIG1 is a schematic diagram of a secure boot process of a chip;
[0043] FIG2 is a schematic diagram of an implementation environment provided by an embodiment of the present application;
[0044] FIG3 is a schematic diagram of the structure of a chip provided in an embodiment of the present application;
[0045] FIG4 is a schematic structural diagram of an electronic device provided in an embodiment of the present application;
[0046] FIG5 is a flow chart of a secure boot method for a chip provided in an embodiment of the present application;
[0047] FIG6 is a schematic diagram of the structure of a task list provided in an embodiment of the present application;
[0048] FIG7 is a schematic diagram of a secure boot method for a chip provided in an embodiment of the present application;
[0049] FIG8 is a schematic structural diagram of a secure boot device for a chip provided in an embodiment of the present application. DETAILED DESCRIPTION
[0050] In order to make the purpose, technical solutions and advantages of this application clearer, the following will further describe the implementation methods of this application in detail with reference to the accompanying drawings. It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data need to comply with the relevant laws, regulations and standards of the relevant countries and regions. For example, the mirror files involved in this application are all obtained with full authorization.
[0051] For ease of understanding, the key terms and key concepts involved in this application are explained below.
[0052] An image file is a file similar to a rar or zip compressed file. It converts a specific series of files into a single file in a certain format for users to download and use, such as operating system images, game images, etc. Image files can be recognized by specific software and burned to a CD.
[0053] The System Control and Management Interface (SCMI) is a set of operating system-independent software interfaces for system management. SCMI defines a set of commands, messages, and data structures to provide a common communication interface for operating systems, virtual machines, firmware, and hardware.
[0054] Firmware can have different definitions, and all reasonable interpretations in the computer field are applicable to this application. For example, it can be explained as follows: a program that is pre-installed in the read-only memory inside the hardware product and is bundled with the hardware product. For example, the basic input and output system (BIOS) of a computer is a type of firmware. Firmware can also be interpreted as: a program running in a "non-control processor", and the above-mentioned "non-control processor" refers to a processor that does not directly run an operating system, such as a processor in a peripheral device. The above-mentioned "non-control processor" can also refer to some cores in a processor used for a bare metal virtual machine system. Firmware can also be interpreted as: an operating system that does not support dynamic installation of applications and an executable file that does not support dynamic installation of applications. It should be noted that the above explanation is only for illustration and should not be regarded as a limitation on the technical solution of this application.
[0055] The following is an introduction to the application scenarios and implementation environment involved in this application.
[0056] The technical solution provided by the embodiment of the present application can be applied to the secure boot process of a chip. Schematically, referring to Figure 1, Figure 1 is a schematic diagram of the secure boot process of a chip. As shown in Figure 1, a security module independent of the business module is deployed on the chip. After the chip is powered on, the security module executes the secure boot code (bootrom security boot code, BSBC) to enter the secure boot process. After the BSBC passes the verification, the xLoader program (a user program) is booted to start. During the xLoader startup process, the business module firmware HBOOT2 and the security module firmware hardware security module (hardware secure module, HSM) are verified and loaded. Among them, the business module firmware HBOOT2 includes ARM trusted firmware (Arm trusted firmware, ATF) and unified extensible firmware interface (unified extensible firmware interface, UEFI). During the UEFI loading phase, multiple image files are involved, such as the file system RAMFS (such as rootFS), the trusted execution environment operating system (TEEOS), and the protected environment key storage (PEK) (usually responsible for the configuration of virtual machines and each core), etc. After the multiple image files are moved from the non-volatile memory to the chip's running memory and security verification is performed on them, the corresponding image files are loaded to complete the chip startup. It should be understood that in order to ensure the security of the image files, manufacturers usually encrypt the image files when producing chips, and use a trusted signature system (such as a certificate authority) to digitally sign the image files. Therefore, the encrypted image files need to be decrypted and verified during the chip startup process, that is, a security verification is performed.
[0057] Based on this, the present application provides a chip security boot method that can accelerate the chip security boot process and improve the chip boot performance. Among them, the chip involved in the present application includes a business module and a security module independent of the business module, and the chip can be applied to various electronic devices. Referring to Figure 2, Figure 2 is a schematic diagram of an implementation environment provided by an embodiment of the present application. As shown in Figure 2, the chip 100 involved in the present application can be applied to various electronic devices 200.
[0058] Illustratively, the electronic device 200 is a smart terminal device, such as a mobile phone, a tablet computer, a wearable device, an in-vehicle device, an augmented reality (AR), a virtual reality (VR) device, a laptop computer, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA) or other mobile terminal devices.
[0059] In some embodiments, the electronic device 200 may also be a V2X device, such as a smart car (or intelligent car), a digital car, an unmanned car (or driverless car or pilotless car or automobile), a self-driving car (or autonomous car), a pure electric vehicle (or battery EV), a hybrid electric vehicle (HEV), a range-extended EV (REEV), a plug-in hybrid electric vehicle (PHEV), a new energy vehicle (new energy vehicle), or a roadside unit (RSU). The electronic device 200 may also be a B2C device or a B2B device, etc., but the present application is not limited thereto.
[0060] In some embodiments, the electronic device 200 can also be an independent physical server, or a server cluster or distributed file system composed of multiple physical servers, or a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and basic cloud computing services such as big data and artificial intelligence platforms, etc., but the present application is not limited to this.
[0061] In addition, the electronic device 200 involved in the present application can access a wired network or a wireless network. Schematically, the wireless network or wired network uses standard communication technology and / or protocol. The network includes but is not limited to a data center network (data center network), a storage area network (SAN), a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a dedicated network or any combination of a virtual private network. In some implementations, the data exchanged over the network is represented using technologies and / or formats including hypertext markup language (HTML), extensible markup language (XML), etc. In addition, conventional encryption technologies such as secure sockets layer (SSL), transport layer security (TLS), virtual private network (VPN), and internet protocol security (IPsec) can be used to encrypt all or part of the links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above-mentioned data communication technologies.
[0062] The structure of the chip 100 will be described below with reference to FIG. 3 .
[0063] Figure 3 is a schematic diagram of the structure of a chip provided in an embodiment of the present application. As shown in Figure 3, chip 100 includes a service module 101, a security module 102, a memory 103, a communication interface 104, and a bus 105. The service module 101, the security module 102, the memory 103, and the communication interface 104 are connected to each other via the bus 105.
[0064] The business module 101 is used to run the operating system to provide corresponding services. The business module 101 is, for example, the core of a central processing unit (CPU), that is, an arithmetic logic unit (ALU), or a control unit (CU), which is not limited in this application. In some embodiments, the business module 101 is also called a business core, a main core, a main control core, etc., which is not limited in this application. In an embodiment of the present application, a trusted firmware runs on the business module 101, which is used to carry the image file to be loaded, instruct the security module 102 to start a security verification process for the image file, instruct the security module 102 to exit the security verification process for the image file, and so on during the startup process of the chip 100. For example, the trusted firmware is ARM trusted firmware (ATF).
[0065] Security module 102 is used to deploy high-security applications such as secure boot, secure upgrades for software / firmware / keys / certificates, and key management. In some embodiments, security module 102 includes a security submodule and at least one computing submodule, with the security submodule communicatively connected to the at least one computing submodule. In some embodiments, security module 102 is referred to as a high-security subsystem, which boots and operates independently of the main system of chip 100.
[0066] Among them, the security submodule is used to issue a security verification task for the image file to at least one computing submodule. Schematically, the security submodule is, for example, a CPU core. In some embodiments, the security submodule is also called a security core, a high-security core, etc., which is not limited in this application. In the embodiment of the present application, a security firmware runs on the security submodule of the security module 102, which is used to start the security verification process for the image file and exit the security verification process for the image file according to the instruction of the business module 101 during the startup process of the chip 100. For example, the security firmware is a hardware secure module (HSM).
[0067] At least one computing submodule is used to perform security verification tasks for the image file. Schematically, the computing submodule is, for example, a CPU core. In some embodiments, the computing submodule is also referred to as a computing core or a security algorithm core (SAC), and is used to perform security verification tasks corresponding to the image file, such as decryption tasks, digest calculation tasks, signature verification tasks, etc., but the present application is not limited thereto. It should be understood that the present application does not limit the number of computing submodules. The computing submodule can be one or more. Schematically, when there are multiple computing submodules, multiple computing submodules in an idle state can concurrently execute security verification tasks, thereby improving chip startup performance.
[0068] The memory 103 includes a double data rate memory (DDR), a static random access memory (SRAM), or other types of dynamic storage devices that can store information and instructions, or includes any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. In the embodiment of the present application, the running memory of the chip 100 is implemented by at least one of the aforementioned memories, which is not limited in this application. The running memory refers to the memory required when the program is running. In addition, the shared memory of the chip 100 is implemented by at least one of the aforementioned memories, which is not limited in this application. Schematically, the business module 101 and the security module 102 both have access rights to the shared memory. In this application, the shared memory can also be understood as a secure memory for storing relevant information that the chip 100 needs to store securely during the startup process. For example, the running memory and shared memory of the chip 100 can be different memory spaces on the same DDR. This application does not limit the memory allocation method involved in the chip 100. In actual applications, memory allocation can be performed according to needs. In some embodiments, the chip 100 further includes a non-volatile memory (NVM), such as a universal flash storage (UFS), an embedded multi-media card (EMMC), etc., but the present application is not limited thereto. The non-volatile memory is used to store the image file to be loaded during the startup process of the chip 100. In other embodiments, the non-volatile memory is located outside the chip 100 and is connected to the chip 100, but the present application is not limited thereto.
[0069] The communication interface 104 is used to provide program instructions and / or data. The communication interface 104 may include a peripheral component interconnect express (PCIe) communication interface, other common peripheral interfaces, etc., which are not limited in this application. For example, the chip 100 may communicate with other devices or communication networks through the peripheral interface.
[0070] The bus 105 may include a path for transmitting information between various components of the chip 100 (eg, the service module 101 , the security module 102 , the memory 103 , and the communication interface 104 ).
[0071] It should be noted that the above FIG3 shows only a hardware structure diagram of the chip 100 provided in this application. In some embodiments, the chip may also include other components to achieve more functions, and this application is not limited thereto.
[0072] In addition, an embodiment of the present application further provides an electronic device, as shown in FIG4 , which is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. As shown in FIG4 , the electronic device 200 includes a chip 100 and an interface 300 . The chip 100 includes a service module and a security module. The interface 300 is used to exchange commands with the outside of the electronic device 200. The chip 100 is used to implement the secure boot method of the chip provided in the following method embodiment.
[0073] The secure boot method of the chip provided in this application is introduced below with reference to FIG5 .
[0074] Figure 5 is a flowchart of a secure boot method for a chip provided in an embodiment of the present application. As shown in Figure 5, the method is applied to a chip 100, which includes a business module and a security module. Taking the interaction between the business module and the security module as an example, the method includes the following steps 501 to 507.
[0075] 501. A service module transmits a first notification message to a security module. The first notification message indicates starting a security verification process for multiple image files.
[0076] In an embodiment of the present application, after the chip is powered on or restarted, the startup program is executed (refer to the content shown in Figure 1 above for this stage, which will not be repeated here), and the UEFI loading stage is entered. The business module transmits a first notification message to the security module to instruct the security module to start a security verification process for multiple image files. In some embodiments, the business module runs the trusted firmware and sends a first interrupt signal to the security firmware running on the security module based on SCMI, so that the security module obtains the first notification message from the register when it receives the first interrupt signal. Schematically, the first interrupt signal is a doorbell interrupt, and the trusted firmware and the security firmware transmit messages based on the SCMI standard channel. For example, the business module runs the trusted firmware, writes the first notification message to the register (which can be understood as a Mailbox) in accordance with the message format negotiated with the security firmware, and then sends the first interrupt signal to the security firmware running on the security module based on the SCMI standard channel, so that the security module obtains the first notification message from the register after receiving the first interrupt signal.
[0077] In some embodiments, the business module creates a task list in the shared memory, and the task list indicates the transport status of each image file in a plurality of image files. Accordingly, the first notification message indicates a security verification process based on the task list. Wherein, both the business module and the security module have access rights to the shared memory, and the transport status indicates whether the image file has been transported from the memory to the running memory of the chip. For example, the transport status is reflected by a preset flag bit, but the present application is not limited to this. Schematically, the first notification message includes the storage address of the task list in the shared memory. Since both the business module and the security module can access the shared memory, the security module can read the transport status of each image file in the task list according to the storage address of the task list in the shared memory when receiving the first notification message, and perform a security verification on the image files that have been transported to the running memory. This process can also be understood as the process of issuing the task list.
[0078] Schematically, referring to FIG6, FIG6 is a schematic diagram of the structure of a task list provided in an embodiment of the present application. As shown in FIG6, the task list includes the file index of each image file, the file identification ID, the storage address of the image file in the running memory (including the starting address and length), the transport status of the image file, the verification parameters involved in the security verification process (such as the relevant parameters involved in decryption, signature verification or digest calculation), and the security verification results, etc. The present application is not limited to this. It should be noted that "..." in the task list shown in FIG6 indicates omission.
[0079] 502. The security module receives a first notification message.
[0080] In the embodiment of the present application, the security module receives the first notification message and returns a notification message of successful reception to the business module.
[0081] In some embodiments, taking the case where the service module transmits the first notification message based on SCMI as an example, the security module obtains the first notification message from the register when receiving the first interrupt signal.
[0082] In some embodiments, taking the example of the business module sending a task list to the security module, the first notification message includes the storage address of the task list in the shared memory. Accordingly, the security module can read the transfer status of each image file in the task list according to the storage address of the task list in the shared memory, and perform a security check on the image files that have been transferred to the running memory, that is, start the security check process for the image files.
[0083] 503. The business module starts to move multiple image files in the memory to the chip's running memory.
[0084] In an embodiment of the present application, a plurality of image files to be loaded during the chip startup process are stored in the memory, and the present application does not limit the type of the image file. In some embodiments, the memory is integrated on the chip, or the memory is located outside the chip and connected to the chip, and the present application does not limit the deployment method of the memory. For example, the memory is a non-volatile memory. Schematically, after the business module transmits the first notification message to the security module, it runs the trusted firmware and starts to move the plurality of image files stored in the memory to the running memory of the chip, that is, copying the plurality of image files to the running memory. It should be understood that this process is continuous, that is, after the business module moves an image file to the running memory, it does not need to wait for the security module to perform a security check on it, but continues to move the next image file.
[0085] In some embodiments, taking the example of the business module sending a task list to the security module, for any image file (hereinafter referred to as the first image file), after the business module moves the first image file from the storage to the running memory, the transport status of the first image file in the task list is updated, that is, the transport status of the first image file is updated to transport successfully. Taking the transport status as embodied by a preset flag bit as an example, this process can also be understood as a setting process for the transport flag bit. Schematically, after the business module moves the first image file to the running memory, other relevant information of the first image file in the task list is updated, such as the storage address of the first image file in the running memory, the verification parameters involved in the security verification process, etc., but the present application is not limited to this.
[0086] 504. The security module performs a security check on the image file that has been moved to the running memory.
[0087] In an embodiment of the present application, this step 504 is executed concurrently with the above-mentioned step 503, that is, in the process of the business module moving multiple image files to the running memory, the security module runs the security firmware, and performs a security check on the image files that have been moved to the running memory according to the moving status of the multiple image files. In some embodiments, taking the business module sending a task list to the security module as an example, for any image file (continue to take the first image file as an example), if the business module moves the first image file from the storage to the running memory, updates the storage address of the first image file in the running memory to the tab of the task list, and updates the moving status of the first image file in the task list, then the security module reads the moving status of the first image file in the task list as a successful move, performs a security check on the first image file, and updates the security check result of the first image file to the task list. For example, the security module reads the moving status of each image file in the task list based on a polling mechanism, and this application does not limit this.
[0088] Based on the chip structure shown in FIG3 , it can be seen that the security module includes a security submodule and at least one computing submodule. The security submodule is used to send security verification tasks corresponding to multiple image files to at least one computing submodule. The at least one computing submodule is used to execute security verification tasks corresponding to multiple image files. The security verification tasks include decryption tasks, summary calculation tasks (i.e., hash calculation tasks), or signature verification tasks for image files, etc. The present application is not limited to this. Schematically, in this step, for any image file that has been moved to the running memory (hereinafter referred to as the second image file), the security submodule runs the security firmware and sends the security verification task corresponding to the second image file to at least one computing submodule. For example, based on the second image file, the security submodule sends the security verification task corresponding to the second image file to at least one computing submodule through a first in, first out (FIFO) channel based on a buffer descriptor (BD). Among them, FIFO is a first-in-first-out data buffer. The security sub-module fills the storage address of the second image file in the running memory and the verification parameters involved in the security verification process into the BD table of the shared memory in BD format, and sends the BD address to the calculation sub-module through the FIFO channel. After receiving the BD address, the calculation sub-module reads the BD table, obtains the storage address of the second image file in the running memory and the verification parameters involved in the security verification process, executes the corresponding security verification task, and updates the security verification result to the task list tab.
[0089] In some embodiments, if the security module includes multiple computing submodules, multiple computing submodules in an idle state can concurrently execute multiple security verification tasks. Schematically, the security submodule determines the first computing submodule and the second computing submodule in an idle state among the multiple computing submodules based on the third image file, the fourth image file, and the task execution status of the multiple computing submodules that have been moved to the running memory; the security submodule issues the security verification task corresponding to the third image file and the security verification task corresponding to the fourth image file to the first computing submodule and the second computing submodule, respectively, so that the first computing submodule and the second computing submodule concurrently execute the security verification task corresponding to the third image file and the security verification task corresponding to the fourth image file. This process can also be understood as the process of the security submodule issuing the security verification task based on the task execution saturation of the computing submodule. In this way, the multi-channel hardware acceleration mechanism between the security submodule and the computing submodule is fully utilized, that is, the chip resources are fully utilized, which can greatly improve the execution efficiency of the security verification task, thereby improving the chip startup performance. It should be noted that the present application does not limit the execution logic of the security sub-module sending security verification tasks to the computing sub-module. For example, the security sub-module can check whether the task channels of multiple computing sub-modules are saturated. If they are saturated, poll to check whether the task has been completed. If there is a task that has been completed, it indicates that there is a computing sub-module in an idle state, and then send the task to it to ensure that the task channel is in a saturated state. If all tasks have been sent down, poll to check whether the task has been completed.
[0090] In some embodiments, the security submodule issues security verification tasks to at least one computing submodule based on their priority. The higher the priority of a security verification task, the longer it takes to execute. For example, the security submodule prioritizes issuing hash calculation tasks to at least one computing submodule. This allows for full utilization of the computing submodule's computing resources and improves task execution efficiency, although this application is not limited to this.
[0091] It should be understood that since the above-mentioned steps 503 and 504 are executed concurrently, the business module and the security module can execute their respective functions concurrently. That is, the strong coupling relationship between the trusted firmware on the business module and the secure firmware on the security module is reduced, so that the functional execution on both sides of the business module and the security module are independent of each other, thereby improving the robustness of the system.
[0092] 505. If the multiple image files have been moved to the running memory and the multiple image files have completed security verification, the business module transmits a second notification message to the security module, and the second notification message indicates to exit the security verification process.
[0093] In an embodiment of the present application, if the business module has moved multiple image files to the execution memory and has read the security verification results for the multiple image files, a second notification message is transmitted to the security module. For example, if the task list in the shared memory stores the security verification results for the multiple image files, and the business module reads the security verification results for the multiple image files from the task list, the second notification message is transmitted to the security module.
[0094] In some embodiments, the business module runs the trusted firmware and sends a second interrupt signal to the security firmware running on the security module based on SCMI, so that the security module obtains the second notification message from the register when receiving the second interrupt signal. Schematically, the second interrupt signal is a doorbell interrupt, and the trusted firmware and the security firmware are transmitted based on SCMI. For example, the business module runs the trusted firmware, writes the second notification message to the register (which can be understood as a mailbox) in accordance with the message format negotiated with the security firmware, and then sends the second interrupt signal to the security firmware running on the security module based on SCMI, so that the security module obtains the second notification message from the register after receiving the second interrupt signal.
[0095] 506. The security module receives the second notification message.
[0096] In an embodiment of the present application, the security module receives the second notification message and returns a notification message of successful receipt to the business module. In some embodiments, taking the business module transmitting the second notification message based on SCMI as an example, when the security module receives the second interrupt signal, it obtains the second notification message from the register and exits the security verification process.
[0097] 507. The business module loads multiple image files in the running memory.
[0098] In an embodiment of the present application, the business module loads multiple image files in the running memory to complete the secure startup of the chip.
[0099] The above steps 501 to 507 are described below with reference to FIG7 . FIG7 is a schematic diagram of a secure boot method for a chip provided by an embodiment of the present application. As shown in FIG7 , taking the example of a business module running the trusted firmware ATF and the security module running the secure firmware HSM, the secure boot method for the chip includes the following steps:
[0100] Step 1: After the chip is powered on or restarted, ATF and HSM are initialized. ATF transmits a first notification message to HSM to issue a task list, that is, notifies HSM of the storage address of the task list in the shared memory.
[0101] Step 2: The HSM receives the first notification message and confirms that it has received the task list.
[0102] Step 3: ATF starts to move multiple image files in the storage to the chip's running memory. Each time an image file is moved, the moving status of the corresponding image file in the task list and the storage address of the image file in the running memory are updated until multiple image files are moved successfully.
[0103] Step 4: The HSM starts a security verification process to perform a security verification on the image file that has been moved to the running memory. According to the task execution status of multiple computing sub-modules, the security verification task is issued to multiple idle computing sub-modules to enable multiple computing sub-modules to execute tasks concurrently.
[0104] Step 5: If the ATF has moved multiple image files to the running memory and reads the security verification results for the multiple image files in the task list, a second notification message is transmitted to the HSM, that is, the HSM is notified to exit the security verification process.
[0105] Based on the chip secure boot method shown in Figures 5 to 7 above, it can be seen that during the chip secure boot process, the business module transmits two notification messages to the security module to respectively instruct the security module to start and exit the security verification process for the image file. After the business module instructs the security module to start the security verification process, the business module begins to continuously transfer the image file to the chip's running memory, and the security module begins to continuously verify the image file that has been transferred to the running memory until all the image files have been transferred to the running memory and the security verification has been completed. The business module then instructs the security module to exit the security verification process. This asynchronous concurrent interaction method between the business module and the security module not only saves communication resources between the business module and the security module, but also shortens the chip boot time and significantly improves the chip boot performance. Moreover, the business module and the security module concurrently execute their respective functions, which reduces the strong coupling relationship between the trusted firmware on the business module and the secure firmware on the security module, making the function execution on both sides independent of each other, and finally verifying the security verification results, thereby improving the robustness of the system. In addition, the security module can send the security verification task of the image file to multiple idle computing sub-modules through the security sub-module. In this way, the multi-channel hardware acceleration mechanism between the security sub-module and the computing sub-module in the security module is fully utilized, that is, the chip resources are fully utilized, which can greatly improve the execution efficiency of the security verification task and further improve the chip startup performance.
[0106] The present application also provides a secure boot device for a chip, as shown in FIG8 , which is a schematic structural diagram of a secure boot device for a chip provided in an embodiment of the present application. The device can implement the steps performed by the chip in the above method embodiment. Schematically, the device includes a message transmission unit 801, a file handling unit 802, a message receiving unit 803, a security verification unit 804, and a file loading unit 805, wherein the message transmission unit 801, the file handling unit 802, and the file loading unit 805 are configured in the business module of the chip, the message receiving unit 803 and the security verification unit 804 are configured in the security module of the chip, and the business module is communicatively connected to the security module.
[0107] A message transmission unit 801 is configured to transmit a first notification message to a security module, where the first notification message indicates starting a security verification process for multiple image files;
[0108] A file transfer unit 802 is used to transfer multiple image files in the memory to the running memory of the chip;
[0109] The message receiving unit 803 receives a first notification message;
[0110] The security verification unit 804 is used to perform security verification on the image file that has been moved to the running memory;
[0111] The message transmission unit 801 is further configured to transmit a second notification message to the security module if the plurality of image files have been moved to the running memory and the plurality of image files have completed security verification, the second notification message indicating the exit of the security verification process;
[0112] The file loading unit 805 is used to load multiple image files in the running memory.
[0113] In some embodiments, the above-mentioned message transmission unit 801, file handling unit 802, message receiving unit 803, security verification unit 804 and file loading unit 805 are also used to collaboratively implement the other steps performed by the business module and the security module in the embodiment shown in Figure 5. It should be understood that the device provided in the above embodiment only uses the division of the above-mentioned functional units as an example when performing a secure boot of the chip. In actual applications, the above-mentioned functions can be assigned to different functional units as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the secure boot device for the chip provided in the above embodiment and the secure boot method embodiment for the chip belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0114] In this application, the terms "first", "second", etc. are used to distinguish between identical or similar items with substantially the same effects and functions. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor is there a limitation on quantity and order of execution. It should also be understood that although the following description uses the terms first, second, etc. to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the various described examples, a first notification message may be referred to as a second notification message, and similarly, a second notification message may be referred to as a first notification message. Both the first notification message and the second notification message may be notification messages, and in some cases, may be separate and different notification messages.
[0115] In this application, the term "at least one" means one or more, and the term "multiple" means two or more. For example, multiple notification messages refer to two or more notification messages.
[0116] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
[0117] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of program structure information. The program structure information includes one or more program instructions. When the program instructions are loaded and executed on a computing device, all or part of the processes or functions described in the embodiments of the present application are generated.
[0118] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or may be accomplished by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0119] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A secure startup method for a chip, characterized in that: The chip includes a business module and a security module, the business module is communicatively connected with the security module, and the method includes: After transmitting a first notification message to the security module, the business module starts to move the multiple image files in the memory to the running memory of the chip, wherein the first notification message indicates to start a security verification process for the multiple image files; The security module receives the first notification message and performs a security check on the image file that has been moved to the running memory; If the multiple image files have been moved to the running memory and the multiple image files have completed security verification, the business module transmits a second notification message to the security module and loads the multiple image files in the running memory, and the second notification message indicates to exit the security verification process.
2. The method according to claim 1, characterized in that The business module runs a trusted firmware, the security module runs a secure firmware, and the trusted firmware and the secure firmware transmit messages based on the system control management interface SCMI to achieve communication connection between the business module and the security module.
3. The method according to claim 2, characterized in that The business module transmits a first notification message to the security module, including: the business module runs the trusted firmware and sends a first interrupt signal to the security firmware running on the security module based on the SCMI, so that the security module obtains the first notification message from a register when receiving the first interrupt signal; The business module transmits a second notification message to the security module, including: the business module runs the trusted firmware, and sends a second interrupt signal to the security firmware running on the security module based on the SCMI, so that the security module obtains the second notification message from the register when receiving the second interrupt signal.
4. The method according to any one of claims 1 to 3, characterized in that The memory is integrated on the chip, or the memory is located outside the chip and connected to the chip.
5. The method according to any one of claims 1 to 4, characterized in that Before the service module transmits the first notification message to the security module, the method further includes: The business module creates a task list in the shared memory, the task list indicates the transfer status of each image file in the multiple image files, and the first notification message indicates to perform the security verification process based on the task list, wherein the business module and the security module both have access rights to the shared memory.
6. The method according to claim 5, characterized in that After the business module moves the first image file indicated by the task list to the running memory, the method further includes: The business module updates the transport status of the first image file in the task list; The security module performs a security check on the image file that has been transferred to the running memory, including: the security module reads that the transfer status of the first image file in the task list is successful, and performs a security check on the first image file.
7. The method according to claim 6, characterized in that After the security module performs security verification on the first image file, the method further includes: The security module updates the security verification result of the first image file into the task list.
8. The method according to any one of claims 5 to 7, characterized in that The first notification message includes a storage address of the task list in the shared memory.
9. The method according to any one of claims 5 to 8, characterized in that The task list further indicates at least one of the following: a storage address of each image file in the running memory, a verification parameter involved in a security verification process of each image file, and a security verification result of each image file.
10. The method according to any one of claims 1 to 9, characterized in that The security module includes a security submodule and at least one computing submodule, wherein the security submodule is used to send security verification tasks corresponding to the multiple image files to the at least one computing submodule, and the at least one computing submodule is used to execute the security verification tasks corresponding to the multiple image files.
11. The method according to claim 10, characterized in that The business module is a business core in the chip used to run the operating system, the security submodule is a security core in the chip used for secure startup, and the computing submodule is a computing core in the chip used to perform security verification tasks.
12. The method according to claim 10 or 11, characterized in that: The security module performs a security check on the image file that has been moved to the running memory, including: the security sub-module sends a security check task corresponding to the second image file that has been moved to the running memory to the at least one computing sub-module through a first-in-first-out FIFO channel based on a buffer descriptor BD.
13. The method according to any one of claims 10 to 12, characterized in that The security module performs security verification on the image file that has been transferred to the running memory, including: The security submodule determines a first computing submodule and a second computing submodule in an idle state among the multiple computing submodules based on the third image file and the fourth image file that have been transferred to the running memory and the task execution status of the multiple computing submodules; The security submodule sends the security verification task corresponding to the third image file and the security verification task corresponding to the fourth image file to the first computing submodule and the second computing submodule respectively, so that the first computing submodule and the second computing submodule concurrently execute the security verification task corresponding to the third image file and the security verification task corresponding to the fourth image file.
14. The method according to any one of claims 1 to 13, characterized in that If the multiple image files have been moved to the running memory and the multiple image files have completed security verification, the business module transmits a second notification message to the security module and loads the multiple image files in the running memory, including: If the business module has moved the multiple image files to the running memory and read the security verification results for the multiple image files, the second notification message is transmitted to the security module, and the multiple image files in the running memory are loaded.
15. A chip, characterized in that: The chip includes a business module and a security module, and the business module is communicatively connected with the security module; The business module is used to start moving multiple image files in the memory to the running memory of the chip after transmitting a first notification message to the security module, wherein the first notification message indicates starting a security verification process for the multiple image files; The security module is configured to receive the first notification message and perform a security check on the image file that has been moved to the running memory; The business module is also used to transmit a second notification message to the security module and load the multiple image files in the running memory if the multiple image files have been moved to the running memory and the multiple image files have completed security verification, and the second notification message indicates to exit the security verification process.
16. The chip according to claim 15, characterized in that: The business module runs a trusted firmware, the security module runs a secure firmware, and the trusted firmware and the secure firmware transmit messages based on the system control management interface SCMI to achieve communication connection between the business module and the security module.
17. The chip according to claim 16, characterized in that: The business module is used to: Running the trusted firmware, and sending a first interrupt signal to the security firmware running on the security module based on the SCMI, so that the security module obtains the first notification message from a register when receiving the first interrupt signal; The trusted firmware is run, and a second interrupt signal is sent to the security firmware running on the security module based on the SCMI, so that the security module obtains the second notification message from the register when receiving the second interrupt signal.
18. The chip according to any one of claims 15 to 17, characterized in that: The memory is integrated on the chip, or the memory is located outside the chip and connected to the chip.
19. The chip according to any one of claims 15 to 18, characterized in that: The security module includes a security submodule and at least one computing submodule, wherein the security submodule is used to send security verification tasks corresponding to the multiple image files to the at least one computing submodule, and the at least one computing submodule is used to execute the security verification tasks corresponding to the multiple image files.
20. The chip according to claim 19, characterized in that The business module is a business core in the chip used to run the operating system, the security submodule is a security core in the chip used for secure startup, and the computing submodule is a computing core in the chip used to perform security verification tasks.
21. An electronic device, characterized in that: The electronic device comprises a chip, wherein the chip comprises a service module and a security module, and the chip is used to implement the secure boot method for a chip as claimed in any one of claims 1 to 14.
22. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store at least one section of program code, and the at least one section of program code is used to implement the secure boot method of a chip as described in any one of claims 1 to 14.
23. A computer program product, characterized in that When the computer program product runs on a chip, the chip is enabled to implement the secure boot method for a chip as claimed in any one of claims 1 to 14.
Citation Information
Patent Citations
Secure starting method of chip, chip, electronic equipment and storage medium
CN119917170A
Method, system, android device and media for verifying the validity of a primary system image
CN109460262A
Starting method for system comprising multi-core processor and system adopting method
CN114064138A
Trusted computing architecture and trusted computing method based on single chip
CN115062353A
Controller starting method and device, electronic equipment and storage medium
CN115934194A