Startup verification system, method, electronic device, and storage medium
By setting the verification module and key on the physical signal controller of the CPU processor and the data transmission bus of the CPU processor in the ARM architecture, the problem of how to ensure the security of the CPU processor is solved, and the secure startup and high reliability of the computing device are achieved.
Patent Information
- Application Number
- PCT/CN2024/115903
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-18
- Filing Date
- 2024-08-30
- Publication Date
- 2025-06-26
AI Technical Summary
How to ensure the security of the emerging ARM architecture CPU processor, especially during startup.
By setting up a verification module on the physical signal controller of the computing device and the data transmission bus of all CPUs, the first and second keys are added, respectively, and a secure verification is performed at startup. The BMC is responsible for reading and verifying these keys to ensure that the physical signal controller and CPU are operating properly before starting the computing device.
Multi-level secure boot verification of computing devices is realized, ensuring that the physical signal controller and CPU are started only under normal conditions, thereby improving the safety and reliability of computing devices.
Smart Images

Figure CN2024115903_26062025_PF_FP_ABST
Abstract
Description
Startup verification system, method, electronic device and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on December 18, 2023, with application number 202311744963.8, and application name “A startup verification system, method, electronic device and storage medium”, all contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of network security technology, and in particular to a startup verification system, method, electronic device, and non-volatile readable storage medium. Background Art
[0004] Server security is paramount. To improve the security of the controller area within server processors, various server processor manufacturers have developed unique security features. However, for the emerging ARM (Advanced RISC Machines) architecture CPU (Central Processing Unit), there are challenges in ensuring its security and CPU startup security.
[0005] Summary of the Invention
[0006] The embodiments of the present application provide a startup verification system, method, electronic device and non-volatile readable storage medium to solve the problem of how to ensure the security of the emerging ARM architecture CPU processor and the startup security of the CPU.
[0007] In order to solve the above technical problems, the embodiments of the present application are implemented as follows:
[0008] In a first aspect, some embodiments of the present application provide a startup verification system, which is applied to a computing device. The system includes: a first verification module and a second verification module. A first key is added to the first verification module, and a second key is added to the second verification module.
[0009] The first verification module is provided on a data transmission bus of a physical signal controller of a computing device, so as to perform a security verification on the physical signal controller of the computing device when the computing device is started;
[0010] The second verification module is set on the data transmission bus of all CPUs of the computing device to perform security verification on all CPUs when the computing device is started.
[0011] In some embodiments, the second verification module is in communication with the physical signal controller, and the system further includes: a BMC, wherein:
[0012] The BMC is in communication with the physical signal controller to read the first key of the physical signal controller when the computing device is started to perform a security check on the physical signal controller, and after the physical signal controller is successfully checked, read and check the second keys of all CPUs in sequence.
[0013] In some embodiments, the first verification module and the second verification module are both verifiers, the first key is added to a preset program in the first verification module, and the second key is added to a preset program in the second verification module.
[0014] In some embodiments, the CPU is an ARM architecture, and the physical signal controller is a CPLD or FPGA.
[0015] In some embodiments, the second verification module and the BMC are respectively connected to the physical signal controller for communication via an I2C bus.
[0016] In a second aspect, some embodiments of the present application provide a method for verifying startup of a computing device, the method comprising:
[0017] In response to the computing device being started, verifying the first key corresponding to the physical signal controller of the computing device to obtain a first verification result;
[0018] In response to the first verification result indicating that the first key verification is successful, verifying the second key corresponding to the CPU of the computing device read in sequence to obtain a second verification result;
[0019] In response to the second verification result indicating that the second key verification is successful, the computing device is started.
[0020] In some embodiments, verifying a first key corresponding to a physical signal controller of a computing device to obtain a first verification result includes:
[0021] Reading a first key in a verification module provided on a data transmission bus of the physical signal controller;
[0022] The first key is verified based on a pre-stored verification key of the first key to obtain a first verification result.
[0023] In some embodiments, after verifying the first key corresponding to the read physical signal controller to obtain a first verification result, the method further includes:
[0024] In response to the first verification result indicating that the first key verification failed, determining that the computing device cannot be normally started;
[0025] Generate and output a prompt message indicating that an abnormality has occurred in the physical signal controller.
[0026] In some embodiments, verifying the second keys corresponding to the CPUs of the computing devices read in sequence to obtain a second verification result includes:
[0027] Reading the second key in the verification module set on the data transmission bus of all CPUs through the physical signal controller;
[0028] The second key is verified based on the pre-stored verification key of the second key to obtain a second verification result.
[0029] In some embodiments, after verifying the second keys corresponding to the CPUs of the computing devices read in sequence and obtaining a second verification result, the method further includes:
[0030] In response to the second verification result indicating that the second key verification failed, determining that the computing device cannot be normally started;
[0031] Generates and outputs a prompt message indicating a CPU abnormality.
[0032] In some embodiments, the number of CPUs is multiple.
[0033] Verifying the second keys corresponding to the CPUs of the computing devices read in sequence to obtain a second verification result includes:
[0034] reading, through the physical signal controller, a third key in a verification module provided on a data transmission bus of a master CPU among the multiple CPUs;
[0035] Verifying the third key based on a pre-stored verification key of the third key to obtain a third verification result;
[0036] In response to the third verification result indicating that the third key verification is successful, reading a fourth key in a verification module provided on a data transmission bus of a slave CPU among the multiple CPUs, where both the third key and the fourth key are the second key;
[0037] The fourth key is verified based on the pre-stored verification key of the fourth key to obtain a second verification result.
[0038] In some embodiments, after starting the computing device in response to the second verification result indicating that the second key verification is successful, the method further includes:
[0039] In response to the third verification result indicating that the third key verification failed, using the third verification result as the second verification result, and determining that the computing device cannot be normally started;
[0040] Generate and output a prompt message indicating that an abnormality has occurred in the main CPU.
[0041] In some embodiments, in response to the second verification result indicating that the second key verification is successful, starting the computing device includes:
[0042] If the second verification result indicates that the fourth key verification fails, starting the computing device based on the single-way startup mode;
[0043] Generates and outputs a prompt message indicating that an abnormality has occurred in the slave CPU.
[0044] In some embodiments, in response to the second verification result indicating that the second key verification is successful, starting the computing device includes:
[0045] When the second verification result indicates that the fourth key verification is successful, the computing device is started based on the multi-way startup mode.
[0046] In a third aspect, some embodiments of the present application provide an electronic device, including:
[0047] A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, any one of the above-mentioned verification methods for starting a computing device is implemented.
[0048] In a fourth aspect, some embodiments of the present application provide a non-volatile readable storage medium, which, when the instructions in the non-volatile readable storage medium are executed by the processor of an electronic device, enables the electronic device to execute any of the above-mentioned verification methods initiated by the computing device.
[0049] In an embodiment of the present application, a verification module with a key added is set on the data transmission bus of the physical signal controller to perform security verification on the physical signal controller of the computing device. At the same time, a verification module with a key added is set on the data transmission bus of all CPUs to perform security verification on the CPU. This allows the computing device to be securely started up at multiple levels. The computing device can only be started normally when the physical signal controller and the CPU are both normal, thereby improving the security and reliability of the computing device.
[0050] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0052] FIG1 is a schematic structural diagram of a startup verification system provided by some embodiments of the present application;
[0053] FIG2 is a schematic structural diagram of another startup verification system provided by some embodiments of the present application;
[0054] FIG3 is a flowchart of a method for verifying startup of a computing device according to some embodiments of the present application;
[0055] FIG4 is a schematic diagram of a system architecture provided in some embodiments of the present application;
[0056] FIG5 is a schematic diagram of a security verification process provided in some embodiments of the present application;
[0057] FIG6 is a schematic diagram of a security verification sequence provided by some embodiments of the present application;
[0058] FIG7 is a schematic diagram of a verification process provided in some embodiments of the present application;
[0059] FIG8 is a schematic structural diagram of an electronic device provided in some embodiments of the present application. DETAILED DESCRIPTION
[0060] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0061] FIG1 and FIG2 are schematic diagrams showing the structure of a startup verification system provided by some embodiments of the present application.
[0062] As shown in Figures 1 and 2, the startup verification system 100 can be applied to a computing device. The startup verification system 100 specifically includes a first verification module 110 and a second verification module 120. The first verification module 110 has a first key added thereto, and the second verification module 120 has a second key added thereto. In this example, the first key and the second key can be the same key or different keys, depending on business needs, and this embodiment does not impose any limitations thereto.
[0063] In this example, the computing device may be, but is not limited to, a server (such as an ARM architecture server, etc.).
[0064] The first verification module 110 can be provided on the data transmission bus of the physical signal controller 111 of the computing device to perform a security verification on the physical signal controller 111 of the computing device when the computing device is started. Specifically, the first key can be verified to be correct based on a pre-stored verification key of the first key. If the first key is verified to be correct based on the pre-stored verification key of the first key, the verification is successful, indicating that there is no abnormality in the physical signal controller 111.
[0065] The second verification module 110 can be provided on the data transmission bus of all CPUs of the computing device to perform a security verification on all CPUs when the computing device is started. Specifically, the second key can be verified to be correct based on a pre-stored verification key of the second key. If the second key is correct based on the pre-stored verification key of the second key, the verification is successful, indicating that all CPUs of the computing device are normal. In the following process, the connection structure and verification process of a single CPU and a dual CPU will be described in detail, and this embodiment will not be repeated here.
[0066] In another specific implementation of the present application, the first verification module 110 and the second verification module 120 are both verifiers, the first key can be added to a preset program (such as a startup program, etc.) in the first verification module 110, and the second key can be added to a preset program (such as a startup program) in the second verification module 120.
[0067] Some embodiments of the present application configure the verification module as a smaller verifier, which can set a security verification key on the data transmission bus while reducing the size of the device to perfectly adapt to the data transmission bus.
[0068] It is understandable that the first verification module and the second verification module are not limited to the above-mentioned verification module structure, and may also be other hardware structures. Specifically, it can be determined according to business requirements, and this embodiment does not impose any restrictions on this.
[0069] In a specific implementation of the present application, the CPU may be an ARM architecture CPU, and the physical signal controller 111 may be a CPLD (Complex Programmable Logic Device) or an FPGA (Field-Programmable Gate Array).
[0070] Of course, the physical signal controller is not limited to hardware structures such as CPLD or FPGA, and can also be other hardware structures. Specifically, the specific type of the physical signal controller can be determined according to business requirements, and this embodiment does not limit this.
[0071] In another specific implementation of the present application, the secure boot verification system 100 may further include: a BMC (Baseboard Management Controller) 130 (as shown in Figures 1 and 2). The BMC can be used to manage the startup and operation of the computing device. The second verification module 120 can be communicatively connected to the physical signal controller 111, and the BMC 130 can be communicatively connected to the physical signal controller 111. In a specific implementation, the second verification module 120 and the BMC 130 are respectively communicatively connected to the physical signal controller 111 via an I2C (Inter-Integrated Circuit) bus. Of course, this is not limited to this. Other physical buses can also be used to communicatively connect the second verification module 120 and the BMC 130 to the physical signal controller 111. Specifically, it can be determined according to business needs, and this embodiment does not limit this.
[0072] When the computing device starts, the BMC 130 may read the first key of the physical signal controller 111 to perform security verification on the physical signal controller 111 , and after the physical signal controller 111 is successfully verified, read and verify the second keys of all CPUs in sequence.
[0073] In this application, the computing device can be a single-core computing device (i.e., only one CPU) or a dual-core computing device (i.e., two CPUs). The key verification process for a single-core computing device and a dual-core computing device can be described in detail below with reference to Figures 1 and 2, respectively.
[0074] In another specific implementation of the present application, when only one CPU is provided in the computing device, as shown in FIG1 , the computing device is provided with a CPU 112 , and a second verification module 120 is provided on the data transmission bus of the CPU 112 .
[0075] In a specific implementation, first, BMC130 can be started. If BMC130 cannot be started, it means that BMC130 has a fault. If BMC130 can be started normally, the first key in the first verification module 110 on the data transmission bus of the physical signal controller 111 can be read, and the first key can be verified to be correct. Specifically, a verification key of the first key is pre-stored in BMC130 for verifying whether the first key is correct. If the first key is correct, it means that there is no abnormality in the physical signal controller 111 and it can be started normally. At this time, the second key in the second verification module 120 on the data transmission bus of CPU112 can be read by the physical signal controller 111 to verify whether the second key is correct. Specifically, a verification key of the second key is pre-stored in BMC130 for verifying whether the second key is correct. If the second key is correct, it means that there is no abnormality in CPU112 and the computing device can be started normally.
[0076] It is understandable that when the first key check error occurs, it means that the physical signal controller 111 is damaged or replaced, and the computing device cannot start normally. When the second key check error occurs, it means that the CPU 112 is damaged or replaced, and the computing device cannot start normally.
[0077] In this example, the first key and the verification key for the first key are a paired public key and private key. In actual applications, the first key can be a private key, and the verification key for the first key can be the paired public key. Alternatively, the first key can be a public key, and the verification key for the first key can be the paired private key, etc.
[0078] The second key and the verification key for the second key are a paired public key and private key. In practical applications, the second key can be a private key, and the verification key for the second key is the paired public key. Alternatively, the second key can be a public key, and the verification key for the second key is the paired private key, etc.
[0079] Some embodiments of the present application can verify whether the core components of the computing device (CPU and physical signal controller) are damaged, destroyed by malicious attacks, or illegally replaced, etc. through key verification, thereby ensuring the safe startup of the computing device.
[0080] In another specific implementation of the present application, when multiple CPUs are provided in the computing device, such as two CPUs, as shown in Figure 2, there are two CPUs provided in the computing device, namely the master CPU 113 and the slave CPU 114, and a second verification module 120 is provided on the data transmission bus of the master CPU 113. At the same time, a second verification module 120 is also provided on the data transmission bus of the slave CPU 114, and a corresponding second key is provided in the second verification module 120.
[0081] In a specific implementation, first, start BMC130. If BMC130 cannot start, it means that BMC130 has a fault. If BMC130 can start normally, the first key in the first verification module 110 on the data transmission bus of the physical signal controller 111 can be read to verify whether the first key is correct. Specifically, a verification key for the first key is pre-stored in BMC130 to verify whether the first key is correct. If the first key is correct, it means that there is no abnormality in the physical signal controller 111 and it can be started normally. At this time, the second key in the second verification module 120 on the data transmission bus of the main CPU 113 can be read by the physical signal controller 111 to verify whether the second key of the main CPU 113 is correct. If the second key of the main CPU 113 is correct, it means that there is no abnormality in the main CPU 113 and it can be started normally. Then, the physical signal controller 111 can read the second key in the second verification module 120 on the data transmission bus of the slave CPU 114 to verify whether the second key of the slave CPU 114 is correct. If the second key of the slave CPU 114 is correct, it means that there is no abnormality in the slave CPU 114 and it can be started normally. In this case, the computing device can be dual-booted.
[0082] It is understood that if the first key verification error occurs, it indicates that the physical signal controller 111 is damaged or replaced, and the computing device cannot be started normally. If the second key verification error occurs on the master CPU 113, it indicates that the master CPU 113 is damaged or replaced, and the computing device cannot be started normally. If the second key verification error occurs on the master CPU 113, but the second key verification error occurs on the slave CPU 114, it indicates that the slave CPU 114 is damaged or replaced, and the computing device can be started only through the master CPU 113.
[0083] In this example, the first key and the verification key for the first key are a paired public key and private key. In actual applications, the first key can be a private key, and the verification key for the first key can be the paired public key. Alternatively, the first key can be a public key, and the verification key for the first key can be the paired private key, etc.
[0084] The second key and the verification key for the second key are a paired public key and private key. In practical applications, the second key can be a private key, and the verification key for the second key is the paired public key. Alternatively, the second key can be a public key, and the verification key for the second key is the paired private key, etc.
[0085] In actual applications, the second key of the master CPU 113 and the key of the slave CPU 114 may be the same key or different keys. Specifically, it may be determined according to business requirements, and this embodiment does not impose any limitation on this.
[0086] Some embodiments of the present application are aimed at dual-core computing devices. A device with a built-in security verification key can be physically linked to the data transmission bus of the physical signal controller, CPU0, and CPU1. When the computing device management firmware BMC is started, it communicates with the above-mentioned components through the physical bus and verifies in turn whether the key value is correct. Different startup states are fed back according to the verification results to inform the user whether the current status of the computing device is normal, thereby improving the security and reliability of the dual-core computing device.
[0087] Of course, the above technical solutions of the embodiments of the present application are not limited to single-core computing devices and dual-core computing devices, but can also be applied to multi-core computing devices, such as 4-core or 8-core computing devices. The verification method is similar to that of the dual-core computing device, that is, first verifying the key of the physical signal controller, then verifying the key of the master CPU, and finally verifying the key of the slave CPU. Of course, in the case of a multi-core computing device, the keys of multiple slave CPUs can be verified synchronously or asynchronously, which can be determined according to business needs and is not limited by this embodiment.
[0088] Some embodiments of the present application provide a startup verification system, which performs security verification on the physical signal controller of the computing device by setting a verification module with a key added on the data transmission bus of the physical signal controller. At the same time, a verification module with a key added is set on the data transmission bus of all CPUs to perform security verification on the CPU. This allows the computing device to be securely started up at multiple levels. The computing device can be started normally only when the physical signal controller and the CPU are both normal, thereby improving the security and reliability of the computing device.
[0089] 3 , a flowchart of the steps of a verification method for startup of a computing device provided in some embodiments of the present application is shown. As shown in FIG3 , the verification method for startup of a computing device may include: step 301 , step 302 and step 303 .
[0090] Step 301: In response to the computing device being started, a first key corresponding to a physical signal controller of the computing device is verified to obtain a first verification result.
[0091] Some embodiments of the present application can be applied to computing device management devices, that is, the execution subject is a computing device management device, such as a BMC, etc. In the following implementation process of the present application, the computing device management device will be described in detail using a BMC as an example.
[0092] In a specific implementation, after the BMC is started, when the computing device (such as an ARM server, etc.) is started, the first key corresponding to the physical signal controller (such as a CPLD, etc.) of the computing device can be read, and the first key can be verified to obtain a first verification result. Specifically, the verification key of the first key can be pre-stored in the BMC to verify the first key and obtain a verification result. As shown in Figure 7, the BMC can send a boot verification request to the EROT (i.e., the verification module in this example, the built-in key). After the EROT receives the verification request, it enters a verification waiting state. At the same time, the BMC can start the boot verification command to verify the key. If the key verification of EROT passes, it is determined that EROT can start normally. When EROT is started, the corresponding computing device hardware, such as the physical signal controller, CPU, etc., can be started.
[0093] The reading and verification process of the first key may be described in detail in conjunction with the following specific implementation.
[0094] In a specific implementation of the present application, the above step 301 may include:
[0095] Sub-step A1: Reading a first key in a verification module provided on a data transmission bus of the physical signal controller.
[0096] In this embodiment, a verification module (such as a verifier) is provided on a data transmission bus (such as an SPI (Serial Peripheral Interface) bus) of the physical signal controller, and a first key is added to the verification module.
[0097] When the computing device starts, the BMC can read the first key in the verification module set on the data transmission bus of the physical signal controller. For example, the BMC and the physical signal controller can be connected via an I2C bus, and the BMC can read the first key in the verification module set on the data transmission bus of the physical signal controller via the I2C bus.
[0098] After reading the first key in the verification module set on the data transmission bus of the physical signal controller, sub-step A2 is executed.
[0099] Sub-step A2: Based on a pre-stored verification key of the first key, verify the first key to obtain a first verification result.
[0100] After reading the first key in the verification module set on the data transmission bus of the physical signal controller, the first key can be verified based on the verification key of the first key pre-stored in the BMC to obtain a first verification result.
[0101] In this example, when the first key is a private key, the verification key of the first key pre-stored in the BMC is the matching public key. When the first key is a public key, the verification key of the first key pre-stored in the BMC is the matching private key, etc.
[0102] If the first verification result indicates that the first key verification has failed, it indicates that the physical signal controller has an abnormality (e.g., the physical signal controller is damaged or replaced). In this case, it can be determined that the computing device cannot start normally. At the same time, a prompt message indicating that the physical signal controller has an abnormality can be generated and output to prompt operation and maintenance personnel to promptly inspect and maintain the physical signal controller.
[0103] In this example, the prompt information used to indicate that an abnormality has occurred in the physical signal controller may be a sound prompt information, a warning light prompt information, etc. Specifically, the specific form of the prompt information may be determined according to business requirements, and this embodiment does not impose any restrictions on this.
[0104] After the first verification result indicates that the first key verification is successful, step 302 is performed.
[0105] Step 302: In response to the first verification result indicating that the first key verification is successful, the second key corresponding to the CPU of the computing device is verified in sequence to obtain a second verification result.
[0106] After the first verification result indicates that the first key verification is successful, the second key corresponding to the CPU of the computing device can be read in response to the first verification result indicating that the first key verification is successful, and the second key can be verified to obtain a second verification result. Specifically, a verification key for the second key can be pre-stored in the BMC to verify the second key to obtain the verification result.
[0107] In a specific implementation, the computing device may be a single-core computing device or a dual-core computing device. The CPU verification process for a single-core computing device may be described in detail in conjunction with the following specific implementation.
[0108] In a specific implementation of the present application, the above step 302 may include:
[0109] Sub-step B1: reading the second key in the verification module provided on the data transmission bus of all CPUs through the physical signal controller.
[0110] In this embodiment, when only one CPU is provided in the computing device (i.e., a single-core computing device), the second key in the verification module provided on the data transmission bus of the CPU can be read through the physical signal controller. Specifically, during design, the verification module provided on the data transmission bus of the CPU can be communicatively connected to the physical signal controller via a physical bus (such as an I2C bus, etc.). After the first key verification of the physical signal controller is successful, the second key in the verification module provided on the data transmission bus of the CPU can be read through the physical signal controller.
[0111] After the second key in the verification module set on the data transmission bus of the CPU is read through the physical signal controller, sub-step B2 is executed.
[0112] Sub-step B2: Verify the second key based on the pre-stored verification key of the second key to obtain a second verification result.
[0113] After the second key in the verification module set on the data transmission bus of the CPU is read through the physical signal controller, the second key can be verified based on the verification key of the second key pre-stored in the BMC to obtain a second verification result.
[0114] In this example, when the second key is a private key, the verification key of the second key pre-stored in the BMC is the matching public key. When the second key is a public key, the verification key of the second key pre-stored in the BMC is the matching private key, etc.
[0115] When the second verification result indicates that the second key verification has failed, it means that the CPU has an abnormality. At this time, it can be determined that the computing device cannot start normally. At the same time, a prompt message indicating that the CPU has an abnormality can be generated and output to prompt the operation and maintenance personnel to perform abnormality inspection and maintenance on the CPU in a timely manner.
[0116] The verification process for the CPU of a dual-core computing device may be described in detail in conjunction with the following specific implementation methods.
[0117] In another specific implementation of the present application, the above step 302 may include:
[0118] Sub-step C1: reading, through the physical signal controller, a third key in a verification module provided on a data transmission bus of a master CPU among the multiple CPUs.
[0119] In this embodiment, when multiple CPUs are provided within the computing device (i.e., a multi-core computing device), these multiple CPUs each include: a master CPU and at least one slave CPU. For a dual-core structure, as shown in FIG4 , CPU0 is the master CPU, CPU1 is the slave CPU, and a second verification module for adding a corresponding key is provided on the data transmission bus between CPU0 and CPU1. The second verification module is connected to the physical signal controller via the I2C bus, and the baseboard management (BMC) is connected to the physical signal controller via the I2C bus. The BMC can communicate with the second verification module via the I2C bus to read the key therein.
[0120] When verifying the CPU's key, a physical signal control signal can be used to first read a third key from a verification module located on a data transmission bus of a master CPU among the multiple CPUs. In this example, when the computing device is a multi-core computing device, the third key is one of the second keys described in step 302.
[0121] After reading the third key in the verification module set on the data transmission bus of the master CPU among the multiple CPUs, sub-step C2 is executed.
[0122] Sub-step C2: verifying the third key based on the pre-stored verification key of the third key to obtain a third verification result.
[0123] After reading the third key in the verification module set on the data transmission bus of the main CPU, the third key can be verified based on the verification key of the third key pre-stored in the BMC to obtain a third verification result.
[0124] In this example, when the third key is a private key, the verification key of the third key pre-stored in the BMC is the matching public key. When the third key is a public key, the verification key of the third key pre-stored in the BMC is the matching private key, etc.
[0125] In this example, if the third verification result indicates that the third key verification has failed, the third verification result can be used as the second verification result described in step 302. In this case, it can be determined that the main CPU of the computing device has an abnormality (such as being damaged or replaced), and that the computing device cannot be started normally. In this case, a prompt message indicating that the main CPU has an abnormality can be generated and output to prompt operation and maintenance personnel to promptly inspect and maintain the main CPU of the computing device.
[0126] When the third verification result indicates that the third key verification is successful, it can be determined that the master CPU can start normally. At this time, the third verification result can be used as an intermediate verification result and the key of the slave CPU can be verified.
[0127] Sub-step C3: In response to the third verification result indicating that the third key verification is successful, read the fourth key in the verification module set on the data transmission bus of the slave CPU among the multiple CPUs, where the third key and the fourth key are both the second key.
[0128] In response to the third verification result indicating that the third key verification is successful, the fourth key in the verification module set on the data transmission bus of the slave CPU in the multiple CPUs can be read, wherein the third key and the fourth key are both the second key described in step 302.
[0129] After the fourth key in the verification module set on the data transmission bus of the slave CPU among the multiple CPUs is read, sub-step C4 is executed.
[0130] Sub-step C4: verifying the fourth key based on the pre-stored verification key of the fourth key to obtain a second verification result.
[0131] After the fourth key is read, the fourth key may be verified based on a pre-stored verification key of the fourth key to obtain a second verification result.
[0132] In this example, when the fourth key is a private key, the verification key of the fourth key pre-stored in the BMC is the matching public key. When the fourth key is a public key, the verification key of the fourth key pre-stored in the BMC is the matching private key, etc.
[0133] If the second verification result indicates that the fourth key verification has failed, indicating that an abnormality has occurred in the slave CPU, the computing device is started in single-socket boot mode, i.e., the computing device is started via the master CPU. Simultaneously, a prompt message indicating the abnormality has occurred in the slave CPU can be generated and output to prompt operation and maintenance personnel to promptly conduct abnormality inspection and maintenance.
[0134] If the second verification result indicates that the fourth key verification is successful, it means that both the master and slave CPUs are normal. At this time, the computing device can be started based on the multi-way startup mode, that is, the master CPU and the slave CPU are started at the same time to start the computing device.
[0135] After the second verification result indicates that the second key verification is successful, step 303 is executed.
[0136] Step 303: In response to the second verification result indicating that the second key verification is successful, start the computing device.
[0137] In response to the second verification result indicating that the second key verification is successful, the computing device may be started.
[0138] Some embodiments of the present application set a verification module with a key added on the data transmission bus of the physical signal controller to perform security verification on the physical signal controller of the computing device. At the same time, a verification module with a key added on the data transmission bus of all CPUs is set to perform security verification on the CPU, so that the computing device can be securely started from multiple levels. The computing device can be started normally only when the physical signal controller and the CPU are normal, thereby improving the security and reliability of the computing device when it is started.
[0139] In this embodiment, the security keys of the physical signal controller and the CPU can also be updated. Specifically, the BMC can write the updated keys into the verification modules provided on the data transmission buses of the physical signal controller and the CPU, respectively, to complete the key replacement. Furthermore, the computing device is shut down and restarted after key verification is completed.
[0140] The above implementation process can be described as follows with reference to FIG5 .
[0141] 5, a schematic diagram of a security verification process provided by some embodiments of the present application is shown. As shown in FIG5, the verification process (taking the computing device as a dual-core server as an example) may include the following steps:
[0142] 1. Start the management firmware BMC.
[0143] 2. The BMC reads the key of the CPLD (the physical signal controller in this example) through the I2C bus to verify whether the key of the CPLD is correct. If the key of the CPLD is incorrect, the server shuts down. If the key of the CPLD is correct, the server continues.
[0144] 3. Start the CPLD normally and read the key of CPU0 (i.e., the main CPU) to verify whether the key of CPU0 is correct. If the key of CPU0 is incorrect, the server will shut down. If the key of CPU0 is correct, continue.
[0145] 4. Start CPU0 normally and read the key of CPU1 (i.e., slave CPU) to verify whether the key of CPU1 is correct. If the key of CPU1 is incorrect, start the server through CPU0 alone. If the key of CPU1 is correct, continue.
[0146] 5. Start CPU1 normally, and start the server through CPU0 and CPU1.
[0147] The processing process of the hardware architecture of this embodiment can be shown in Figure 6 (taking a dual-core server as an example of a computing device). After the BMC is started, the CPLD key can be verified. If the CPLD key verification fails, the server is shut down. If the CPLD key verification succeeds, the CPU0 key is verified. If the CPU0 key verification fails, the server is shut down. If the CPU0 key verification succeeds, the CPU1 key is verified. If the CPU1 key verification fails, the single-core server is started. If the CPU1 key verification succeeds, the dual-core server is started.
[0148] Through the above-mentioned verification process, some embodiments of the present application can verify the security keys of the server's physical signal controller, main CPU, and slave CPU through the I2C bus via the BMC at startup, thereby improving the security level of the server to a technical level.
[0149] Of course, the above technical solutions of some embodiments of the present application are not limited to single-core servers and dual-core servers, but can also be applied to multi-core servers, such as 4-core or 8-core servers. The verification method is similar to that of the dual-core server, that is, first verifying the key of the physical signal controller, then verifying the key of the master CPU, and finally verifying the key of the slave CPU. Of course, in the case of a multi-core server, the keys of multiple slave CPUs can be verified synchronously or asynchronously, which can be determined according to business needs, and this embodiment does not limit this.
[0150] Some embodiments of the present application provide a verification method for starting a computing device, which performs security verification on the physical signal controller of the computing device by setting a verification module with a key added on the data transmission bus of the physical signal controller. At the same time, a verification module with a key added is set on the data transmission bus of all CPUs to perform security verification on the CPU. This allows security startup verification of the computing device to be performed at multiple levels. The computing device can be started normally only when the physical signal controller and the CPU are both normal, thereby improving the security and reliability of the computing device when it is started.
[0151] In addition, some embodiments of the present application also provide an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the verification method for starting the computing device when executed by the processor.
[0152] FIG8 shows a block diagram of an electronic device 800 of some embodiments of the present application. As shown in FIG8 , the electronic device 800 includes a central processing unit (CPU) 801, which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) 802 or loaded from a storage unit 808 into a random access memory (RAM) 803. In RAM 803, various programs and data required for the operation of the electronic device 800 can also be stored. CPU 801, ROM 802, and RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0153] Multiple components in the electronic device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, a microphone, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the electronic device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0154] The various processes and procedures described above may be executed by the processing unit 801. For example, the method of any of the above embodiments may be implemented as a computer software program, which is tangibly contained in a non-volatile computer-readable storage medium, such as the storage unit 808. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the CPU 801, one or more actions in the method described above may be performed.
[0155] Some embodiments of the present application further provide a computer non-volatile readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the various processes of the above-mentioned verification method embodiment for starting a computing device are implemented, and the same technical effects are achieved. To avoid repetition, they are not described here. Among them, the computer non-volatile readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0156] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A startup verification system, characterized in that: Applied to a computing device, the system comprises: a first verification module and a second verification module, wherein a first key is added to the first verification module and a second key is added to the second verification module, wherein: The first verification module is arranged on the data transmission bus of the physical signal controller of the computing device, so as to perform security verification on the physical signal controller of the computing device when starting the computing device; the first verification module is a verifier, and the first key is added to a preset program in the first verification module; The second verification module is arranged on the data transmission bus of all the CPUs of the computing device, so as to perform security verification on all the CPUs when starting the computing device.
2. The system according to claim 1, characterized in that The second verification module is in communication with the physical signal controller, and the system further includes: a BMC, wherein: The BMC is communicatively connected with the physical signal controller so as to read the first key of the physical signal controller when the computing device is started to perform a security check on the physical signal controller, and after the physical signal controller is successfully checked, read and check the second keys of all the CPUs in sequence.
3. The system according to claim 1, characterized in that The second verification module is a verifier, and the second key is added to a preset program in the second verification module.
4. The system according to claim 1, characterized in that The CPU is of ARM architecture, and the physical signal controller is of CPLD or FPGA.
5. The system according to claim 2, characterized in that The second verification module and the BMC are respectively connected to the physical signal controller for communication via an I2C bus.
6. A method for verifying startup of a computing device, characterized in that: Applied to BMC, the method comprises: In response to the computing device being started, verifying the first key corresponding to the physical signal controller of the computing device read to obtain a first verification result; In response to the first verification result indicating that the first key verification is successful, verifying the second key corresponding to the CPU of the computing device read in sequence to obtain a second verification result; In response to the second verification result indicating that the second key verification is successful, starting the computing device.
7. The method according to claim 6, characterized in that The step of verifying the first key corresponding to the physical signal controller of the computing device to obtain a first verification result includes: Reading the first key in a verification module provided on a data transmission bus of the physical signal controller; The first key is verified based on a pre-stored verification key of the first key to obtain the first verification result.
8. The method according to claim 6, characterized in that After verifying the first key corresponding to the physical signal controller of the computing device and obtaining a first verification result, the method further includes: In response to the first verification result indicating that the first key verification fails, determining that the computing device cannot be normally started; Generate and output prompt information for indicating that an abnormality occurs in the physical signal controller.
9. The method according to claim 6, characterized in that The step of verifying the second keys corresponding to the CPUs of the computing devices read in sequence to obtain a second verification result includes: Through the physical signal controller, read the verification module set on the data transmission bus of all the CPUs the second key; The second key is verified based on a pre-stored verification key of the second key to obtain the second verification result.
10. The method according to claim 9, characterized in that After verifying the second keys corresponding to the CPUs of the computing devices read in sequence to obtain a second verification result, the method further includes: In response to the second verification result indicating that the second key verification fails, determining that the computing device cannot be normally started; Generate and output prompt information for indicating that the CPU is abnormal.
11. The method according to claim 6, characterized in that The number of the CPUs is multiple, The step of verifying the second keys corresponding to the CPUs of the computing devices read in sequence to obtain a second verification result includes: Reading, by means of the physical signal controller, a third key in a verification module provided on a data transmission bus of a main CPU among the plurality of CPUs; Verifying the third key based on a pre-stored verification key of the third key to obtain a third verification result; In response to the third verification result indicating that the third key verification is successful, reading a fourth key in a verification module provided on a data transmission bus of a slave CPU among the plurality of CPUs, wherein both the third key and the fourth key are the second key; The fourth key is verified based on a pre-stored verification key of the fourth key to obtain the second verification result.
12. The method according to claim 11, characterized in that After starting the computing device in response to the second verification result indicating that the second key verification is successful, the method further includes: In response to the third verification result indicating that the third key verification fails, using the third verification result as the second verification result to determine that the computing device cannot be normally started; Generate and output prompt information for indicating that the main CPU is abnormal.
13. The method according to claim 11, characterized in that In response to the second verification result indicating that the second key verification is successful, starting the computing device includes: When the second verification result indicates that the fourth key verification fails, starting the computing device based on a single-way startup mode; Generate and output prompt information for indicating that an abnormality occurs in the slave CPU.
14. The method according to claim 11, characterized in that In response to the second verification result indicating that the second key verification is successful, starting the computing device includes: When the second verification result indicates that the fourth key verification is successful, the computing device is started based on the multi-way startup mode.
15. The method according to claim 6, characterized in that The method comprises: Updating a first key corresponding to a physical signal controller of the computing device; Updating the second keys corresponding to the CPUs of the computing device in sequence; Shut down and restart the computing device.
16. The method according to claim 7, characterized in that The verifying the first key based on the pre-stored verification key of the first key includes: Sending a boot boot verification request to a verification module provided on the data transmission bus of the physical signal controller; the boot boot verification request is used to make the verification module provided on the data transmission bus of the physical signal controller enter a verification waiting state; Start a boot verification command; the boot verification command is used to verify the first key.
17. The method according to claim 7, characterized in that The first key and the verification key of the first key constitute a pair of matching keys; if the first key is a public key, the verification key of the first key is a private key; if the first key is a private key, the verification key of the first key is a public key.
18. The method according to claim 11, characterized in that The number of the slave CPUs is multiple; the number of the fourth keys is multiple; The step of reading a fourth key in a verification module provided on a data transmission bus of a slave CPU among the plurality of CPUs comprises: Reading a fourth key in a verification module provided on a data transmission bus of a plurality of slave CPUs among the plurality of CPUs; The verifying the fourth key based on the pre-stored verification key of the fourth key to obtain the second verification result includes: The plurality of fourth keys are verified by synchronous verification or asynchronous verification.
19. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, the verification method initiated by the computing device according to any one of claims 6 to 18 is implemented.
20. A non-volatile readable storage medium, characterized in that: When the instructions in the non-volatile readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the verification method initiated by a computing device as described in any one of claims 6 to 18.
Citation Information
Patent Citations
Method and device for updating application program in electronic control unit
CN103713932A
Intelligent Internet of Things gateway and data transmission method
CN112769686A
Start verification system and method, electronic equipment and storage medium
CN117436090A
Offloading raid reconstruction to a secondary controller of a storage system
US20200319972A1