Firmware execution method, device and system, storage medium, and electronic device
Through the dual mechanism of digital signature verification and credible metric information verification of the target firmware of the input and output system, the security risks caused by the simple firmware verification method in the prior art are solved, ensuring the integrity and credibility of the firmware.
Patent Information
- Application Number
- PCT/CN2024/137545
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-12-06
- Publication Date
- 2025-07-03
AI Technical Summary
In the prior art, the firmware verification method of the input and output system is relatively simple, and there is a risk that the firmware has not been tampered with, resulting in server security risks.
By performing digital signature verification of the target firmware of the input and output system and obtaining the first trusted metric information when the verification is passed, two-factor verification is performed to determine whether the target firmware is executed.
Improves server security, prevents firmware from being tampered with, and ensures firmware integrity and trustworthiness.
Smart Images

Figure CN2024137545_03072025_PF_FP_ABST
Abstract
Description
Firmware execution method and device, system, storage medium and electronic device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on December 28, 2023, with application number 202311839060.8 and application name “Firmware execution method and device, system, storage medium and electronic device”, all contents of which are incorporated by reference into this application. Technical Field
[0003] Embodiments of the present application relate to the field of communications, and more specifically, to a firmware execution method and apparatus, a system, a non-volatile readable storage medium, and an electronic device. Background Art
[0004] The Basic Input / Output System (BIOS) is a set of programs stored in the Flash Read-Only Memory (Flash ROM) on the motherboard. The BIOS stores the computer's most important basic input / output programs, power-on self-test routines, system startup routines, and system configuration information. As the manager of the server motherboard's most basic hardware settings and control processes, the BIOS provides many usability features for the server.
[0005] With the development of network technology, network security threats are becoming increasingly serious. Because the BIOS provides the lowest-level, most direct hardware configuration and control for a computer, it takes precedence over the operating system. If the BIOS firmware is damaged or tampered with by hackers, it can cause irreversible data loss or even hardware damage. To address these security threats and address security vulnerabilities within the firmware, regular firmware updates are required.
[0006] In order to ensure the integrity of BIOS firmware updates and prevent the BIOS firmware from being tampered with, in the prior art, servers generally use the following three methods: 1) The first method is to add a Trusted Platform Module (TPM). TPM is a secure encryption processor designed to perform encryption operations on BIOS firmware or software. In order to verify the credibility of the firmware or software, TPM is generally installed on the server. TPM technology can provide hardware-based security-related functions. TPM includes multiple physical security mechanisms for preventing BIOS firmware or software from being tampered with, making it impossible for malicious software to tamper with the relevant functions of TPM. Therefore, the TPM can be used to verify the firmware signature to ensure the integrity of the BIOS firmware update and prevent the BIOS firmware from being tampered with. However, this method may have the problem that the security mechanism is useless if the manufacturer's key is leaked. 2) The second method is to use Platform Firmware Resilience (PFR technology). PFR technology requires a high-specification Field-Programmable Gate Array (FPGA) or Complex Programmable Logic Device (CPLD) to perform hardware integrity verification to prevent BIOS firmware tampering. However, the second method brings the following problems: high-specification FPGAs are expensive, resulting in high cost pressure, and the PFR function is relatively complex to use, which is not conducive to user maintenance and use. 3) The third method is to implement BIOS dynamic measurement based on the board management controller (BMC). This method requires the Basic Input / Output System Flash (BIOS Flash) in the BIOS to periodically switch the read / write bus to the BMC, which then performs verification. This method may cause the host system to stop working when the BIOS Flash is switched to the BMC, resulting in a temporary suspension of host services, which is in turn detrimental to user services.
[0007] In the existing technology, the verification method for the firmware of the input and output system is relatively simple, and there is still a risk of undetected firmware tampering, which in turn brings security risks to the server and has not yet been effectively solved. Summary of the Invention
[0008] The embodiments of the present application provide a firmware execution method and device, system, non-volatile readable storage medium and electronic device to at least solve the problem that the verification method for the firmware of the input and output system in the related art is relatively simple, and there is still a risk of undetected firmware tampering, which in turn brings security risks to the server.
[0009] According to one embodiment of the present application, a firmware execution method is provided, which is applied to a server, wherein the server includes: a central processing unit, a south bridge controller connected to the central processing unit, a security platform module and a motherboard management controller connected to the south bridge controller, including: performing digital signature verification on target firmware of an input / output system, wherein the input / output system is a system running on the central processing unit; when the digital signature verification of the target firmware passes, obtaining first trust metric information of the target firmware, and determining a verification result of the first trust metric information; and determining whether to execute the target firmware based on the verification result.
[0010] In an exemplary embodiment, determining a verification result of first trusted metric information includes: determining whether the first trusted metric information is consistent with second trusted metric information generated by a first terminal, wherein the second trusted metric information is generated by the first terminal according to a target firmware; and determining a verification result based on whether the first trusted metric information is consistent with the second trusted metric information.
[0011] In an exemplary embodiment, determining a verification result based on whether the first trust metric information is consistent with the second trust metric information includes: when the first trust metric information is consistent with the second trust metric information, determining that the verification result indicates that the first trust metric information has passed the verification; when the first trust metric information is inconsistent with the second trust metric information, determining that the verification result indicates that the first trust metric information has not passed the verification.
[0012] In an exemplary embodiment, obtaining first trust metric information of the target firmware includes: obtaining third trust metric information of each sub-firmware in the target firmware, and fourth trust metric information of the overall firmware corresponding to the target firmware, wherein the first trust metric information includes: third trust metric information and fourth trust metric information, wherein each sub-firmware is a partial firmware in the target firmware, and each sub-firmware is set to perform a function.
[0013] In an exemplary embodiment, determining a verification result of verifying the first trust metric information includes: determining a plurality of fifth trust metric information and sixth trust metric information in the second trust metric information generated by the first terminal, wherein each fifth trust metric information is generated by the first terminal according to each sub-firmware in the target firmware, and the sixth trust metric information is generated by the first terminal according to the overall firmware corresponding to the target firmware; and determining the verification result according to the plurality of third trust metric information, the fourth trust metric information, the plurality of fifth trust metric information and the sixth trust metric information.
[0014] In an exemplary embodiment, determining a verification result based on multiple third trust metric information, fourth trust metric information, multiple fifth trust metric information and sixth trust metric information includes: determining the third trust metric information and the fifth trust metric information corresponding to each sub-firmware; determining whether the third trust metric information and the fifth trust metric information corresponding to each sub-firmware are consistent to obtain a first comparison result; and determining whether the fourth trust metric information is consistent with the sixth trust metric information to obtain a second comparison result; and determining a verification result based on the first comparison result and the second comparison result.
[0015] In an exemplary embodiment, a verification result is determined based on the first comparison result and the second comparison result, including: when the fifth trust metric information and the third trust metric information corresponding to each sub-firmware are consistent, and the sixth trust metric information is consistent with the fourth trust metric information, determining that the verification result indicates that the first trust metric information has passed the verification; when the fifth trust metric information and the third trust metric information corresponding to any sub-firmware are inconsistent, and / or the sixth trust metric information is inconsistent with the fourth trust metric information, determining that the verification result indicates that the first trust metric information has not passed the verification.
[0016] In an exemplary embodiment, determining whether the third trust metric information and the fifth trust metric information corresponding to each sub-firmware are consistent includes: determining whether the first sub-firmware is executed, wherein after the first sub-firmware is executed, the memory resources of the in-band host system of the server are available; in the case of executing the first sub-firmware, determining whether the third trust metric information and the fifth trust metric information corresponding to the first sub-firmware are consistent, and determining whether the third trust metric information and the fifth trust metric information corresponding to the second sub-firmware are consistent, wherein the second sub-firmware is a sub-firmware other than the first sub-firmware in the target firmware.
[0017] In an exemplary embodiment, determining whether to execute the target firmware is based on the verification result, including: executing the target firmware when the verification result indicates that the first trust metric information has passed the verification; prohibiting the execution of the target firmware when the verification result indicates that the first trust metric information has not passed the verification, and sending an alarm message to a second terminal corresponding to the input-output system, wherein the second terminal is a terminal for managing the input-output system, and the alarm message is used to indicate that the target firmware is dangerous.
[0018] In an exemplary embodiment, obtaining the first trust metric information of the target firmware includes at least one of the following: obtaining metadata of the target firmware, and determining the first trust metric information of the target firmware based on the metadata, wherein the metadata includes at least one of the following: creation time, modification time, and file size; obtaining permission settings of the target firmware, and determining the first trust metric information of the target firmware based on the permission settings; wherein the permissions corresponding to the permission settings include: read permission, write permission, and execute permission; obtaining source information and propagation path of the target firmware, and determining the first trust metric information of the target firmware based on the source information and propagation path; obtaining a digital summary of the target firmware, and determining the first trust metric information of the target firmware based on the digital summary.
[0019] In an exemplary embodiment, digital signature verification is performed on the target firmware of the input-output system, including: obtaining a digital certificate and a first digital signature corresponding to the target firmware, wherein the digital certificate carries a public key, and the first digital signature is generated by the first terminal by signing the target firmware according to the public key; signing the target firmware according to the public key to obtain a second digital signature of the target firmware; and digital signature verification is performed on the target firmware of the input-output system according to the first digital signature and the second digital signature.
[0020] In an exemplary embodiment, digital signature verification is performed on the target firmware of the input / output system based on the first digital signature and the second digital signature, including: when the first digital signature is consistent with the second digital signature, determining that the digital signature verification of the target firmware has passed; when the first digital signature is inconsistent with the second digital signature, determining that the digital signature verification of the target firmware has failed.
[0021] In an exemplary embodiment, digital signature verification is performed on the target firmware of the input-output system, including: obtaining a digital certificate and a first digital summary signature corresponding to the target firmware, wherein the digital certificate carries a public key, the digital summary signature is generated by a first terminal signing a first digital summary corresponding to the target firmware, and the first digital summary is generated by the first terminal performing a hash operation on the target firmware; performing a hash operation on the target firmware to obtain a second digital summary, and signing the second digital summary according to the public key to obtain a second digital summary signature; and digital signature verification is performed on the target firmware of the input-output system according to the first digital summary signature and the second digital summary signature.
[0022] In an exemplary embodiment, digital signature verification is performed on target firmware of an input / output system based on a first digital digest signature and a second digital digest signature, including: when the first digital digest signature and the second digital digest signature are consistent, determining that the digital signature verification of the target firmware has passed; when the first digital digest signature and the second digital digest signature are inconsistent, determining that the digital signature verification of the target firmware has failed.
[0023] In an exemplary embodiment, before obtaining the first trust metric information of the target firmware, the method also includes: determining whether the first trust metric information is obtained; if the first trust metric information is not obtained, sending an alarm message to a second terminal corresponding to the input-output system, wherein the second terminal is a terminal for managing the input-output system, and the alarm message is used to indicate that the target firmware is in danger.
[0024] In an exemplary embodiment, after obtaining the first trust measurement information of the target firmware, the method also includes: performing digital signature verification on the first trust measurement information through a trusted security platform module of a server, wherein the server is a terminal loaded with an input-output system; if the digital signature verification of the first trust measurement information passes, determining a verification result of the first trust measurement information; if the digital signature verification of the first trust measurement information fails, sending an alarm message to a second terminal corresponding to the input-output system, wherein the second terminal is a terminal for managing the input-output system, and the alarm message is used to indicate that the target firmware is in danger.
[0025] In an exemplary embodiment, digital signature verification of the target firmware of the input-output system includes at least one of the following: digital signature verification of the target firmware of the input-output system through a trusted security platform module of a server, wherein the server is a terminal loaded with the input-output system; digital signature verification of the target firmware of the input-output system through a motherboard management controller of the server.
[0026] In an exemplary embodiment, determining a verification result of verifying the first trust metric information includes: determining the verification result of verifying the first trust metric information by a motherboard management controller of a server, wherein the server is a terminal equipped with an input and output system.
[0027] According to another embodiment of the present application, a firmware execution device is provided, including: a first verification module, configured to perform digital signature verification on the target firmware of the input and output system; a second verification module, configured to obtain first trust metric information of the target firmware when the digital signature verification of the target firmware passes, and determine the verification result of the first trust metric information; a determination module, configured to determine whether to execute the target firmware based on the verification result.
[0028] According to another embodiment of the present application, a firmware execution system is provided, including: a trusted security platform module, configured to perform digital signature verification on the target firmware of the input and output system; a motherboard management controller, configured to obtain first trust measurement information of the target firmware when the digital signature verification of the target firmware passes, and determine a verification result of the verification of the first trust measurement information; and a central processing unit, configured to determine whether to execute the target firmware based on the verification result.
[0029] According to another embodiment of the present application, a computer non-volatile readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.
[0030] According to another embodiment of the present application, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0031] Through the present application, since the target firmware of the input-output system is digitally signed and verified, if the digital signature verification passes, the target firmware is verified by obtaining the first trust metric information of the target firmware. Whether to execute the target firmware is determined based on the verification result of the first trust metric information. In other words, the present application performs digital signature verification and trust metric information verification on the target firmware, doubly verifying whether the firmware has been tampered with, and restarts the input-output system if the verification passes. Therefore, it can solve the problem in the prior art that the verification method for the firmware of the input-output system is relatively simple, and there is still a risk of not discovering the firmware being tampered with, which in turn brings hidden dangers of insecurity to the server, thereby achieving the effect of improving the security of the server. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] FIG1 is a hardware structure block diagram of a server device for a firmware execution method according to an embodiment of the present application;
[0033] FIG2 is a flowchart of a firmware execution method according to an embodiment of the present application;
[0034] FIG3 is a hardware diagram of a firmware upgrade method based on trusted verification according to an embodiment of the present application;
[0035] FIG4 is a flowchart of a firmware upgrade method based on trusted verification according to an embodiment of the present application;
[0036] FIG5 is a structural block diagram of a firmware execution device according to an embodiment of the present application. DETAILED DESCRIPTION
[0037] The embodiments of the present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0038] It should be noted that the terms "first", "second", etc. in the description and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0039] The method embodiments provided in the embodiments of the present application can be executed in a server device or a similar computing device. Taking operation on a server device as an example, FIG1 is a hardware structure block diagram of a server device of a firmware execution method of an embodiment of the present application. As shown in FIG1 , the server device may include one or more (only one is shown in FIG1 ) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 configured to store data, wherein the above-mentioned server device may also include a transmission device 106 and an input / output device 108 configured to have a communication function. It will be understood by those skilled in the art that the structure shown in FIG1 is only for illustration and does not limit the structure of the above-mentioned server device. For example, the server device may also include more or fewer components than those shown in FIG1 , or have a configuration different from that shown in FIG1 .
[0040] The memory 104 can be configured to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the execution method of the firmware in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implementing the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may include a memory remotely located relative to the processor 102, and these remote memories may be connected to a server device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0041] The transmission device 106 is configured to receive or transmit data via a network. Examples of such a network may include a wireless network provided by a communication provider of a server device. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In one embodiment, the transmission device 106 may be a radio frequency (RF) module configured to communicate with the Internet wirelessly.
[0042] In this embodiment, a method for executing firmware is provided. FIG2 is a flow chart of the method for executing firmware according to an embodiment of the present application, which is applied to the server device of FIG1 . As shown in FIG3 , the server includes: a central processing unit, a south bridge controller connected to the central processing unit, a security platform module connected to the south bridge controller, and a motherboard management controller. As shown in FIG2 , the process includes the following steps:
[0043] Step S202, digital signature verification is performed on the target firmware of the input / output system;
[0044] The digital signature verification is the first level of verification performed on the target firmware. The step S202 is performed by a security platform module of the server or a security platform module in the motherboard management controller.
[0045] Step S204: if the digital signature of the target firmware is verified successfully, obtaining first trust metric information of the target firmware, and determining a verification result of the first trust metric information;
[0046] The above step S204 is performed by the motherboard management controller in the server.
[0047] That is, when the first verification is passed, the target firmware is subjected to a second verification, that is, the trustworthy measurement information of the target firmware is verified.
[0048] Verifying the trustworthiness of the BIOS firmware (i.e., the target firmware of this application) refers to the process of evaluating and verifying the BIOS firmware to ensure the reliability and security of the BIOS firmware. The first trustworthiness information can be determined based on at least one of the following: the BIOS firmware version number, the BIOS firmware manufacturer information, etc. When the firmware is executed, the first trustworthiness information can be generated based on the above information.
[0049] Step S206: Determine whether to execute the target firmware according to the verification result.
[0050] The above step S206 is performed by the motherboard management controller in the server.
[0051] Through the above steps, the target firmware of the input / output system is digitally signed and verified. If the digital signature verification passes, the target firmware is verified by obtaining the first trust metric information of the target firmware. Whether to execute the target firmware is determined based on the verification result of the first trust metric information. In other words, the present application performs digital signature verification and trust metric information verification on the target firmware, doubly verifying whether the firmware has been tampered with. If the verification passes, the input / output system is restarted. Therefore, the problem in the prior art that the verification method for the firmware of the input / output system is relatively simple and still has the risk of not discovering the firmware being tampered with, thereby bringing hidden dangers of insecurity to the server can be solved, thereby achieving the effect of improving the security of the server.
[0052] Optionally, determining a verification result of the first trusted measurement information includes: determining whether the first trusted measurement information is consistent with second trusted measurement information generated by the first terminal, wherein the second trusted measurement information is generated by the first terminal according to the target firmware; and determining a verification result based on whether the first trusted measurement information is consistent with the second trusted measurement information.
[0053] Optionally, the verification result is determined based on whether the first trusted measurement information is consistent with the second trusted measurement information, including: when the first trusted measurement information is consistent with the second trusted measurement information, determining that the verification result indicates that the first trusted measurement information has passed the verification; when the first trusted measurement information is inconsistent with the second trusted measurement information, determining that the verification result indicates that the first trusted measurement information has not passed the verification.
[0054] It is understood that whether the first trust metric information has been verified can be determined by determining whether the first trust metric information is consistent with the second trust metric information generated by the first terminal. Only when the first trust metric information and the second trust metric information are consistent can the first trust metric information be determined to have been verified. The first terminal may be a terminal corresponding to the server manufacturer.
[0055] By adopting the above technical solution of verifying the first trust metric information when the digital signature of the target firmware is verified, the protection capability of the BIOS against malware and attacks can be enhanced, thereby improving the security and credibility of the BIOS.
[0056] The above-mentioned step S204 of obtaining the first trust metric information of the target firmware can also be performed through the following technical solution: obtaining the third trust metric information of each sub-firmware in the target firmware, and the fourth trust metric information of the overall firmware corresponding to the target firmware, wherein the first trust metric information includes: the third trust metric information and the fourth trust metric information, wherein each sub-firmware is a partial firmware in the target firmware, and each sub-firmware is set to perform a function.
[0057] In the process of obtaining the first trust metric information of the target firmware, third trust metric information of each sub-firmware of the target firmware and fourth trust metric information of the entire firmware corresponding to the target firmware may also be obtained.
[0058] The fourth trust metric information of the overall firmware corresponding to the benchmark firmware is determined based on one of the following: version information, security mark, digital summary and other information.
[0059] The sub-firmware of the above-mentioned target firmware includes but is not limited to: boot loader (Bootloader), kernel (Kernel), file system (File system), device drivers (Device drivers), applications (Applications), configuration files (Configuration files), library files (Libraries), etc. These sub-firmware can together constitute the target firmware.
[0060] Among them, each sub-firmware has corresponding functions, for example: Bootloader is responsible for booting BIOS when the device starts and initializing BIOS; Kernel is the core part of BIIOS, responsible for managing BIOS resources and providing basic functions, etc., which are not listed here one by one.
[0061] Through the above technical solution, not only the trust measurement information of the entire firmware corresponding to the target firmware is verified, but also the trust measurement information of each internal part of the target firmware is verified. This can ensure that each sub-firmware in the target firmware is trustworthy and has not been maliciously tampered with, thereby improving the security of the BIOS.
[0062] Optionally, determining a verification result of the first trusted measurement information includes: determining multiple fifth trusted measurement information and sixth trusted measurement information in the second trusted measurement information generated by the first terminal, wherein each fifth trusted measurement information is generated by the first terminal based on each sub-firmware in the target firmware, and the sixth trusted measurement information is generated by the first terminal based on the overall firmware corresponding to the target firmware; and determining the verification result based on multiple third trusted measurement information, fourth trusted measurement information, multiple fifth trusted measurement information and sixth trusted measurement information.
[0063] Optionally, the verification result is determined based on multiple third trust metric information, fourth trust metric information, multiple fifth trust metric information and sixth trust metric information, including: determining the third trust metric information and fifth trust metric information corresponding to each sub-firmware; determining whether the third trust metric information and fifth trust metric information corresponding to each sub-firmware are consistent to obtain a first comparison result; and determining whether the fourth trust metric information is consistent with the sixth trust metric information to obtain a second comparison result; and determining the verification result based on the first comparison result and the second comparison result.
[0064] Optionally, the verification result is determined based on the first comparison result and the second comparison result, including: when the fifth trusted measurement information and the third trusted measurement information corresponding to each sub-firmware are consistent, and the sixth trusted measurement information is consistent with the fourth trusted measurement information, determining that the verification result indicates that the first trusted measurement information has passed the verification; when the fifth trusted measurement information and the third trusted measurement information corresponding to any sub-firmware are inconsistent, and / or the sixth trusted measurement information is inconsistent with the fourth trusted measurement information, determining that the verification result indicates that the first trusted measurement information has not passed the verification.
[0065] After obtaining multiple third trust metric information and fourth trust metric information, it is necessary to determine multiple fifth trust metric information generated by each sub-firmware of the target firmware and the sixth trust metric information generated by the overall firmware corresponding to the target firmware based on the second trust metric information. Compare the third trust metric information with the fifth trust metric information to determine whether the third trust metric information and the fifth trust metric information are consistent to obtain a first comparison result; compare the fourth trust metric information with the sixth trust metric information to determine whether the fourth trust metric information and the sixth trust metric information are consistent to obtain a second comparison result. Only when the first comparison result shows that the third trust metric information and the fifth trust metric information are consistent, and the second comparison result shows that the fourth trust metric information and the sixth trust metric information are consistent, can it be determined that the first trust metric information has passed the verification. Conversely, when the first comparison result shows that the third trust metric information and the fifth trust metric information are inconsistent, and / or the second comparison result shows that the fourth trust metric information and the sixth trust metric information are inconsistent, it is determined that the first trust metric information has failed the verification.
[0066] The above technical solution verifies the trustworthiness information of each component and the entire target firmware. Only when all components and the entire target firmware pass the trustworthiness information verification can the first trustworthiness information be determined to have passed verification. This technical solution ensures the integrity and trustworthiness of the target firmware, prevents tampering with the target firmware or the insertion of malicious code, and improves the security and stability of the target firmware while also improving its trustworthiness.
[0067] Optionally, determining whether the third trust metric information and the fifth trust metric information corresponding to each sub-firmware are consistent includes: determining whether to execute the first sub-firmware, wherein, after executing the first sub-firmware, the memory resources of the in-band host system of the server are available; in the case of executing the first sub-firmware, determining whether the third trust metric information and the fifth trust metric information corresponding to the first sub-firmware are consistent, and determining whether the third trust metric information and the fifth trust metric information corresponding to the second sub-firmware are consistent, wherein the second sub-firmware is a sub-firmware other than the first sub-firmware in the target firmware.
[0068] It is understandable that, when executing the first firmware, the memory resources of the in-band host system of the server are available, and the trust metric information of the target firmware can be verified through the memory resources. Optionally, when executing the first sub-firmware, determine whether the third trust metric information and the fifth trust metric information of the first firmware corresponding to the target firmware are consistent. If they are inconsistent, that is, if the first sub-firmware fails to pass the verification, it is necessary to prohibit the execution of the first sub-firmware. If the first sub-firmware passes the verification, check whether the third trust metric information and the fifth trust metric information corresponding to the second sub-firmware are consistent. Execute the above steps in a loop until it is determined whether all sub-firmware in the target firmware have passed the verification.
[0069] Optionally, determining whether to execute the target firmware is based on the verification result, including: executing the target firmware when the verification result indicates that the first trust metric information has passed the verification; prohibiting the execution of the target firmware when the verification result indicates that the first trust metric information has not passed the verification, and sending an alarm message to the second terminal corresponding to the input and output system, wherein the second terminal is a terminal for managing the input and output system, and the alarm message is used to indicate that the target firmware is dangerous.
[0070] After determining the verification result of the first trust metric information, whether to execute the target firmware can be determined based on the verification result. Optionally, if the first trust metric information passes the verification, the target firmware can be executed; if the first trust metric information fails the verification, the execution of the target firmware is prohibited, and an alarm message indicating that the target firmware is in danger is sent to the second terminal corresponding to the input / output system.
[0071] In other words, the target firmware can only be executed if the first trust metric information passes verification. If the hostile trust metric information fails verification, the target firmware is determined to be dangerous. This technical solution strengthens monitoring of the target firmware, improves security protection capabilities, and effectively reduces potential risks.
[0072] Optionally, obtaining the first trust metric information of the target firmware includes at least one of the following: obtaining metadata of the target firmware, and determining the first trust metric information of the target firmware based on the metadata, wherein the metadata includes at least one of the following: creation time, modification time, and file size; obtaining permission settings of the target firmware, and determining the first trust metric information of the target firmware based on the permission settings; wherein the permissions corresponding to the permission settings include: read permission, write permission, and execute permission; obtaining source information and propagation path of the target firmware, and determining the first trust metric information of the target firmware based on the source information and propagation path; obtaining a digital summary of the target firmware, and determining the first trust metric information of the target firmware based on the digital summary.
[0073] There are many ways to determine the first trust metric information, including but not limited to: 1) determining the first trust metric information based on metadata; 2) determining the first trust metric information based on the permission settings of the target firmware; 3) determining the first trust metric information based on the source information and propagation path of the target firmware; 4) determining the first trust metric information based on the digital summary of the target firmware.
[0074] After the first trust metric information of the target firmware is obtained in the above manner, the technical solution of verifying the first trust metric information of the target firmware can be executed.
[0075] Optionally, digital signature verification is performed on the target firmware of the input-output system, including: obtaining a digital certificate and a first digital signature corresponding to the target firmware, wherein the digital certificate carries a public key, and the first digital signature is generated by the first terminal by signing the target firmware based on the public key; signing the target firmware based on the public key to obtain a second digital signature of the target firmware; and digital signature verification is performed on the target firmware of the input-output system based on the first digital signature and the second digital signature.
[0076] Optionally, the digital signature of the target firmware of the input and output system is verified based on the first digital signature and the second digital signature, including: when the first digital signature is consistent with the second digital signature, determining that the digital signature verification of the target firmware has passed; when the first digital signature is inconsistent with the second digital signature, determining that the digital signature verification of the target firmware has failed.
[0077] The embodiment of the present application performs digital signature verification and trusted measurement information verification on the target firmware, and determines the security of the target firmware through double verification. Among them. The method for verifying the digital signature of the target firmware can be: obtaining the digital certificate and the first digital signature corresponding to the target firmware. That is, obtaining the digital certificate of the target firmware, and obtaining the first digital signature of the target firmware by combining the public key carried in the digital certificate with the digital signature algorithm. After obtaining the first digital signature, the target firmware can be signed by the public key to obtain the second digital signature. The first digital signature and the second digital signature can be verified. If the first digital signature and the second digital signature are consistent, it can be determined that the target firmware has passed the verification; if the first digital signature and the second digital signature are inconsistent, it can be determined that the target firmware has not passed the verification.
[0078] The above method of digital signature verification of the target firmware can ensure the integrity and authenticity of the target firmware to prevent unauthorized modification and tampering; in this way, the security and stability of the input and output system can be ensured.
[0079] Optionally, digital signature verification is performed on the target firmware of the input-output system, including: obtaining a digital certificate and a first digital summary signature corresponding to the target firmware, wherein the digital certificate carries a public key, the first digital summary signature is generated by the first terminal signing the first digital summary corresponding to the target firmware, and the first digital summary is generated by the first terminal performing a hash operation on the target firmware; performing a hash operation on the target firmware to obtain a second digital summary, and signing the second digital summary according to the public key to obtain a second digital summary signature; and digital signature verification is performed on the target firmware of the input-output system according to the first digital summary signature and the second digital summary signature.
[0080] Optionally, digital signature verification is performed on the target firmware of the input / output system based on the first digital digest signature and the second digital digest signature, including: when the first digital digest signature is consistent with the second digital digest signature, determining that the digital signature verification of the target firmware has passed; when the first digital digest signature is inconsistent with the second digital digest signature, determining that the digital signature verification of the target firmware has failed.
[0081] It is understood that the digital signature of the target firmware can be verified by verifying the digital digest of the target firmware to determine whether it has passed verification. Optionally, a digital certificate for the target firmware can be obtained and the public key can be determined using the digital certificate. A hash operation can be performed on the target firmware via the first terminal to generate a first digital digest of the target firmware. The first digital digest of the target firmware can then be signed by the first terminal to obtain the first digital digest signature.
[0082] After obtaining the first digital signature, a hash operation is performed on the target firmware to obtain a second digital summary, and the second digital summary is signed according to the public key carried in the digital certificate to obtain the second digital summary signature.
[0083] The obtained first digital digest signature and the second digital digest signature are compared. If the first digital digest signature and the second digital digest signature are consistent, it can be determined that the digital signature verification of the target firmware has passed; if the first digital digest signature and the second digital digest signature are inconsistent, it can be determined that the digital signature verification of the target firmware has failed.
[0084] By obtaining the first and second digital digest signatures of the target firmware and determining whether digital signature verification has passed based on whether the digital digest signatures are consistent, the technical solution can verify the integrity and authenticity of the target firmware's data, ensuring that the target firmware has not been tampered with or modified during transmission and storage.
[0085] Optionally, before obtaining the first trust metric information of the target firmware, the method also includes: determining whether the first trust metric information is obtained; if the first trust metric information is not obtained, sending an alarm message to a second terminal corresponding to the input and output system, wherein the second terminal is a terminal for managing the input and output system, and the alarm message is used to indicate that the target firmware is in danger.
[0086] It is understandable that, when the first credibility metric information is not obtained, it can be considered that the target firmware is dangerous, and then an alarm message is sent to the second terminal.
[0087] Optionally, after obtaining the first trusted measurement information of the target firmware, the method also includes: performing digital signature verification on the first trusted measurement information through the trusted security platform module of the server; if the digital signature verification of the first trusted measurement information passes, determining the verification result of the first trusted measurement information; if the digital signature verification of the first trusted measurement information fails, sending an alarm message to a second terminal corresponding to the input-output system, wherein the second terminal is a terminal for managing the input-output system, and the alarm message is used to indicate that the target firmware is in danger.
[0088] It is understood that the target firmware is first digitally signed and verified. If the digital signature verification passes, the target firmware can be verified for trustworthiness and the verification result can be obtained. If the digital signature verification fails, an alarm is directly sent to the second terminal, indicating that the target firmware is dangerous, without verifying the trustworthiness of the target firmware.
[0089] Optionally, performing digital signature verification on the target firmware of the input / output system includes at least one of the following: performing digital signature verification on the target firmware of the input / output system through the trusted security platform module of the server; performing digital signature verification on the target firmware of the input / output system through the motherboard management controller of the server.
[0090] There are many ways to verify the digital signature of the target firmware, for example: verifying the digital signature of the target firmware through a trusted security platform of the server; or verifying the target firmware through a mainboard management controller of the server.
[0091] Optionally, determining a verification result of verifying the first trustworthy metric information includes: determining a verification result of verifying the first trustworthy metric information by a motherboard management controller of the server.
[0092] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a non-volatile readable storage medium (such as ROM (Read-Only Memory, Read-Only Memory) / RAM (Random Access Memory, Random Access Memory), a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods of each embodiment of the present application.
[0093] In order to better understand the process of the execution method of the above-mentioned firmware, the implementation process of the execution method of the above-mentioned firmware is described below in combination with an optional embodiment, but it is not used to limit the technical solution of the embodiment of this application.
[0094] One embodiment of the present application proposes a firmware upgrade method based on trusted verification. FIG3 is a hardware schematic diagram of a firmware upgrade method based on trusted verification according to one embodiment of the present application. As shown in FIG3, one embodiment of the present application aims to send its own trusted measurement information to the BMC through the BIOS, verify the integrity of the BIOS firmware (i.e., the target firmware of the present application) through the trusted measurement information, and report the verification results to the remote management computer, thereby achieving the technical effect of preventing the BIOS firmware from being tampered with. Optionally, FIG4 is a flowchart of a firmware upgrade method based on trusted verification according to one embodiment of the present application, as shown in FIG4:
[0095] Step S401, power on.
[0096] The server manufacturer compiles the BIOS firmware with a key signature. While compiling the BIOS firmware, it generates the original trust measurement information of each part of the BIOS firmware image and the original trust measurement information of the entire image (excluding the dynamic area) (i.e., the first trust measurement information of this application).
[0097] The signed BIOS firmware and trust measurement information are distributed to users of servers equipped with a TPM module. After receiving the signed BIOS firmware and trust measurement information, the server user uploads the trust measurement information to the server's BMC when upgrading the BIOS firmware. Simultaneously, the server host is shut down, and the BIOS firmware is partially or completely flashed, and then the flashed server host is turned on.
[0098] Step S402: Firmware signature verification.
[0099] During the Power-On Self-Test (POST) process, the BIOS uses the hardware TPM module to verify the signature of the BIOS firmware image. After the signature verification passes, the BIOS firmware can be executed. (This is the digital signature verification mentioned in this application);
[0100] Step S403: Calculate the trustworthiness information of each part of the image and the whole part through the hardware TPM.
[0101] After the signature verification is passed, the BIOS firmware image is executed, and during the execution process, the hardware TPM module is used to calculate the execution-time trust measurement information (i.e., the second trust measurement information of this application) of each part of the image and the entire image (excluding the dynamic area).
[0102] In step S404, the BIOS transmits the execution-time trust measurement information obtained in step S403 to the BMC via an interface such as a shared memory.
[0103] Step S405, step S405, determine whether the measurement information exists during execution.
[0104] The BMS determines whether the BIOS has uploaded the execution-time trust measurement information after booting. If the execution-time trust measurement information has not been uploaded, but the BIOS firmware has been executed, step S407 is executed; if the execution-time trust measurement information has been uploaded, step S406 is executed;
[0105] Step S406: verify the trustworthiness information.
[0106] The BMC uses the execution-time trust metric information distributed synchronously with the BIOS firmware to verify the trust metric information uploaded by the BIOS during the power-on self-test process. If the verification passes, the verification ends. If the verification fails, step S407 is executed.
[0107] Step S407: Send an alarm to the remote computer (ie, the second terminal of this application).
[0108] At this point, the BIOS firmware is determined to be unsafe, and an alarm is sent to the remote management computer.
[0109] One embodiment of the present application provides a method for verifying the integrity of the firmware image and preventing tampering, which can be detected in real time to determine whether the firmware has been damaged or tampered with. Even if the key is leaked, the method can provide verification. The above technical solution is convenient for server management and maintenance personnel to use. Furthermore, the above technical solution utilizes the server's built-in TPM module, eliminating the need for expensive security controllers such as FPGAs, to complete the verification of the BIOS firmware, resulting in a low cost. This provides a relatively high firmware security verification mechanism at a low cost and in a relatively simple manner.
[0110] In this embodiment, a firmware execution device is also provided, which is configured to implement the above-mentioned embodiments and preferred embodiments. Details that have already been described will not be repeated. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0111] FIG5 is a structural block diagram of a firmware execution device according to an embodiment of the present application. As shown in FIG5 , the device includes:
[0112] A first verification module 52 is configured to perform digital signature verification on the target firmware of the input / output system;
[0113] The second verification module 54 is configured to obtain first trust metric information of the target firmware when the digital signature of the target firmware is verified successfully, and determine a verification result of the first trust metric information;
[0114] The determination module 56 is configured to determine whether to execute the target firmware according to the verification result.
[0115] The above-mentioned device is used to verify the digital signature of the target firmware of the input / output system. If the digital signature verification passes, the target firmware is verified by obtaining the first trust metric information of the target firmware. Whether to execute the target firmware is determined based on the verification result of the first trust metric information. In other words, the present application verifies the digital signature of the target firmware and verifies the trust metric information, doubly verifying whether the firmware has been tampered with. If the verification passes, the input / output system is restarted. Therefore, the problem in the prior art that the verification method for the firmware of the input / output system is relatively simple and there is still a risk of not discovering the firmware being tampered with, thereby bringing hidden dangers of insecurity to the server can be solved, thereby achieving the effect of improving the security of the server.
[0116] In an exemplary embodiment, the second verification module 54 is also configured to determine whether the first trust metric information is consistent with the second trust metric information generated by the first terminal, wherein the second trust metric information is generated by the first terminal according to the target firmware; and determine the verification result based on whether the first trust metric information is consistent with the second trust metric information.
[0117] In an exemplary embodiment, the second verification module 54 is further configured to determine that, when the first trust metric information is consistent with the second trust metric information, the verification result indicates that the first trust metric information has passed the verification; and when the first trust metric information is inconsistent with the second trust metric information, the verification result indicates that the first trust metric information has not passed the verification.
[0118] In an exemplary embodiment, the second verification module 54 is also configured to obtain third trust metric information of each sub-firmware in the target firmware, and fourth trust metric information of the overall firmware corresponding to the target firmware, wherein the first trust metric information includes: third trust metric information and fourth trust metric information, wherein each sub-firmware is a partial firmware in the target firmware, and each sub-firmware is configured to perform a function.
[0119] In an exemplary embodiment, the second verification module 54 is also configured to determine multiple fifth trust measurement information and sixth trust measurement information in the second trust measurement information generated by the first terminal, wherein each fifth trust measurement information is generated by the first terminal based on each sub-firmware in the target firmware, and the sixth trust measurement information is generated by the first terminal based on the overall firmware corresponding to the target firmware; and the verification result is determined based on multiple third trust measurement information, fourth trust measurement information, multiple fifth trust measurement information and sixth trust measurement information.
[0120] In an exemplary embodiment, the second verification module 54 is also configured to determine the third trust metric information and the fifth trust metric information corresponding to each sub-firmware; determine whether the third trust metric information and the fifth trust metric information corresponding to each sub-firmware are consistent to obtain a first comparison result; and determine whether the fourth trust metric information is consistent with the sixth trust metric information to obtain a second comparison result; and determine the verification result based on the first comparison result and the second comparison result.
[0121] In an exemplary embodiment, the second verification module 54 is further configured to determine that the verification result indicates that the first trust metric information has passed the verification when the fifth trust metric information and the third trust metric information corresponding to each sub-firmware are consistent, and the sixth trust metric information is consistent with the fourth trust metric information; and to determine that the verification result indicates that the first trust metric information has not passed the verification when the fifth trust metric information and the third trust metric information corresponding to any sub-firmware are inconsistent, and / or the sixth trust metric information is inconsistent with the fourth trust metric information.
[0122] In an exemplary embodiment, the second verification module 54 is also configured to determine whether to execute the first sub-firmware, wherein after the first sub-firmware is executed, the memory resources of the in-band host system of the server are available; in the case of executing the first sub-firmware, determine whether the third trust metric information and the fifth trust metric information corresponding to the first sub-firmware are consistent, and determine whether the third trust metric information and the fifth trust metric information corresponding to the second sub-firmware are consistent, wherein the second sub-firmware is other sub-firmware in the target firmware except the first sub-firmware.
[0123] In an exemplary embodiment, the determination module 56 is further configured to execute the target firmware when the verification result indicates that the first trust metric information has passed the verification; and to prohibit the execution of the target firmware when the verification result indicates that the first trust metric information has not passed the verification, and to send an alarm message to the second terminal corresponding to the input-output system, wherein the second terminal is a terminal for managing the input-output system, and the alarm message is used to indicate that the target firmware is in danger.
[0124] In an exemplary embodiment, the second verification module 54 is further configured to obtain metadata of the target firmware, and determine the first trust metric information of the target firmware based on the metadata, wherein the metadata includes at least one of the following: creation time, modification time, and file size; obtain permission settings of the target firmware, and determine the first trust metric information of the target firmware based on the permission settings; wherein the permissions corresponding to the permission settings include: read permission, write permission, and execute permission; obtain source information and propagation path of the target firmware, and determine the first trust metric information of the target firmware based on the source information and propagation path; obtain a digital summary of the target firmware, and determine the first trust metric information of the target firmware based on the digital summary.
[0125] In an exemplary embodiment, the first verification module 52 is also configured to obtain a digital certificate and a first digital signature corresponding to the target firmware, wherein the digital certificate carries a public key, and the first digital signature is generated by the first terminal by signing the target firmware based on the public key; the target firmware is signed based on the public key to obtain a second digital signature of the target firmware; and the digital signature of the target firmware of the input and output system is verified based on the first digital signature and the second digital signature.
[0126] In an exemplary embodiment, the first verification module 52 is also configured to determine that the digital signature verification of the target firmware has passed when the first digital signature is consistent with the second digital signature; and to determine that the digital signature verification of the target firmware has failed when the first digital signature is inconsistent with the second digital signature.
[0127] In an exemplary embodiment, the first verification module 52 is also configured to obtain a digital certificate and a first digital summary signature corresponding to the target firmware, wherein the digital certificate carries a public key, the digital summary signature is generated by the first terminal signing the first digital summary corresponding to the target firmware, and the first digital summary is generated by the first terminal performing a hash operation on the target firmware; a hash operation is performed on the target firmware to obtain a second digital summary, and the second digital summary is signed according to the public key to obtain a second digital summary signature; and the digital signature of the target firmware of the input and output system is verified according to the first digital summary signature and the second digital summary signature.
[0128] In an exemplary embodiment, the first verification module 52 is further configured to determine that the digital signature verification of the target firmware has passed when the first digital digest signature is consistent with the second digital digest signature; and to determine that the digital signature verification of the target firmware has failed when the first digital digest signature is inconsistent with the second digital digest signature.
[0129] In an exemplary embodiment, the first verification module 52 is also configured to determine whether the first trust metric information is obtained; if the first trust metric information is not obtained, an alarm message is sent to the second terminal corresponding to the input-output system, wherein the second terminal is a terminal for managing the input-output system, and the alarm message is used to indicate that the target firmware is in danger.
[0130] In an exemplary embodiment, the second verification module 54 is further configured to perform digital signature verification on the first trusted measurement information through the trusted security platform module of the server; if the digital signature verification of the first trusted measurement information passes, determine the verification result of the first trusted measurement information; if the digital signature verification of the first trusted measurement information fails, send an alarm message to the second terminal corresponding to the input and output system, wherein the second terminal is a terminal for managing the input and output system, and the alarm message is used to indicate that the target firmware is in danger.
[0131] In an exemplary embodiment, the first verification module 52 is further configured to perform digital signature verification on the target firmware of the input / output system through the trusted security platform module of the server; and perform digital signature verification on the target firmware of the input / output system through the motherboard management controller of the server.
[0132] In an exemplary embodiment, the determination module 56 is further configured to determine a verification result of the first trust metric information through a motherboard management controller of the server.
[0133] It should be noted that the above modules can be implemented through software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.
[0134] An embodiment of the present application also provides a firmware execution system, including: a trusted security platform module, configured to perform digital signature verification on the target firmware of the input and output system; a motherboard management controller, configured to obtain first trust measurement information of the target firmware when the digital signature verification of the target firmware passes, and determine the verification result of the first trust measurement information; a central processing unit, configured to determine whether to execute the target firmware based on the verification result.
[0135] An embodiment of the present application further provides a computer non-volatile readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.
[0136] In an exemplary embodiment, the above-mentioned computer non-volatile readable storage medium may include but is not limited to: a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and other media that can store computer programs.
[0137] An embodiment of the present application further provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0138] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0139] The examples in this embodiment can refer to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail here.
[0140] Obviously, those skilled in the art should understand that the modules or steps of the present application described above can be implemented using a general-purpose computing device, they can be concentrated on a single computing device, or distributed across a network composed of multiple computing devices, they can be implemented using program code executable by the computing device, and thus, they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be performed in a different order than herein, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.
[0141] The above are merely optional embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may be subject to various modifications and variations. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A method for executing firmware, characterized in that, Applied to a server, where the server includes: a central processing unit, a south bridge controller connected to the central processing unit, a security platform module and a motherboard management controller connected to the south bridge controller, including: Performing digital signature verification on the target firmware of the input / output system, where the input / output system is a system running on the central processing unit; When the digital signature verification of the target firmware passes, obtaining first trusted measurement information of the target firmware and determining a verification result for verifying the first trusted measurement information; Determining whether to execute the target firmware according to the verification result.
2. The method according to claim 1, wherein: Determining the verification result for verifying the first trusted measurement information includes: Determining whether the first trusted measurement information is consistent with second trusted measurement information generated by a first terminal, where the second trusted measurement information is generated by the first terminal according to the target firmware; Determining the verification result according to whether the first trusted measurement information is consistent with the second trusted measurement information.
3. The method according to claim 2, wherein: Determining the verification result according to whether the first trusted measurement information is consistent with the second trusted measurement information includes: When the first trusted measurement information is consistent with the second trusted measurement information, determining that the verification result indicates that the first trusted measurement information passes the verification; When the first trusted measurement information is inconsistent with the second trusted measurement information, determining that the verification result indicates that the first trusted measurement information fails to pass the verification.
4. The method according to claim 1, wherein: Obtaining the first trusted measurement information of the target firmware includes: Obtaining third trusted measurement information of each sub-firmware in the target firmware and fourth trusted measurement information of the overall firmware corresponding to the target firmware, where the first trusted measurement information includes: the third trusted measurement information and the fourth trusted measurement information, and each sub-firmware is a part of the target firmware, and each sub-firmware is set to execute a function.
5. The method according to claim 4, wherein: Determining the verification result for verifying the first trusted measurement information includes: Determining a plurality of fifth trusted measurement information and sixth trusted measurement information in the second trusted measurement information generated by the first terminal, where each fifth trusted measurement information is generated by the first terminal according to each sub-firmware in the target firmware, and the sixth trusted measurement information is generated by the first terminal according to the overall firmware corresponding to the target firmware; Determining the verification result according to the plurality of third trusted measurement information, the fourth trusted measurement information, the plurality of fifth trusted measurement information and the sixth trusted measurement information.
6. The method according to claim 5, wherein: Determining the verification result according to the plurality of third trusted measurement information, the fourth trusted measurement information, the plurality of fifth trusted measurement information and the sixth trusted measurement information includes: Determine the third trusted measurement information and the fifth trusted measurement information corresponding to each sub-firmware; Determine whether the third trusted measurement information and the fifth trusted measurement information corresponding to each sub-firmware are consistent to obtain a first comparison result; and determine whether the fourth trusted measurement information and the sixth trusted measurement information are consistent to obtain a second comparison result; Determine the verification result according to the first comparison result and the second comparison result.
7. The method according to claim 6, wherein, Determining the verification result according to the first comparison result and the second comparison result includes: When the fifth trusted measurement information and the third trusted measurement information corresponding to each sub-firmware are both consistent, and the sixth trusted measurement information is consistent with the fourth trusted measurement information, determine that the verification result indicates that the first trusted measurement information passes the verification; When the fifth trusted measurement information and the third trusted measurement information corresponding to any one sub-firmware are inconsistent, and / or, the sixth trusted measurement information is inconsistent with the fourth trusted measurement information, determine that the verification result indicates that the first trusted measurement information fails to pass the verification.
8. The method according to claim 6, wherein, Determining whether the third trusted measurement information and the fifth trusted measurement information corresponding to each sub-firmware are consistent includes: Determine whether to execute the first sub-firmware, wherein after executing the first sub-firmware, the memory resources of the in-band host system of the server are available; When the first sub-firmware is executed, determine whether the third trusted measurement information and the fifth trusted measurement information corresponding to the first sub-firmware are consistent, and determine whether the third trusted measurement information and the fifth trusted measurement information corresponding to the second sub-firmware are consistent, wherein the second sub-firmware is other sub-firmware in the target firmware except the first sub-firmware.
9. The method according to claim 1, wherein, Determining whether to execute the target firmware according to the verification result includes: When the verification result indicates that the first trusted measurement information passes the verification, execute the target firmware; When the verification result indicates that the first trusted measurement information fails to pass the verification, prohibit the execution of the target firmware, and send an alarm message to the second terminal corresponding to the input / output system, wherein the second terminal is a terminal for managing the input / output system, and the alarm message is used to indicate that the target firmware is dangerous.
10. The method according to claim 1, wherein, Obtaining the first trusted measurement information of the target firmware includes at least one of the following: Obtain the metadata of the target firmware, and determine the first trusted measurement information of the target firmware according to the metadata, wherein the metadata includes at least one of the following: creation time, modification time, file size; Obtain the permission setting of the target firmware, and determine the first trusted measurement information of the target firmware according to the permission setting; wherein the permissions corresponding to the permission setting include: read permission, write permission, execute permission; Obtain the source information and propagation path of the target firmware, and determine the first trusted measurement information of the target firmware according to the source information and the propagation path; Obtain the digital digest of the target firmware, and determine the first trusted measurement information of the target firmware according to the digital digest.
11. The method according to claim 1, wherein: Performing digital signature verification on the target firmware of the input / output system includes: Obtain the digital certificate and the first digital signature corresponding to the target firmware, wherein the digital certificate carries a public key, and the first digital signature is generated by the first terminal signing the target firmware according to the public key; Sign the target firmware according to the public key to obtain the second digital signature of the target firmware; Perform digital signature verification on the target firmware of the input / output system according to the first digital signature and the second digital signature.
12. The method according to claim 11, wherein: Performing digital signature verification on the target firmware of the input / output system according to the first digital signature and the second digital signature includes: When the first digital signature is consistent with the second digital signature, determine that the digital signature verification of the target firmware passes; When the first digital signature is inconsistent with the second digital signature, determine that the digital signature verification of the target firmware fails.
13. The method according to claim 1, wherein: Performing digital signature verification on the target firmware of the input / output system includes: Obtain the digital certificate and the first digital digest signature corresponding to the target firmware, wherein the digital certificate carries a public key, the first digital digest signature is generated by the first terminal signing the first digital digest corresponding to the target firmware, and the first digital digest is generated by the first terminal performing a hash operation on the target firmware; Perform a hash operation on the target firmware to obtain a second digital digest, and sign the second digital digest according to the public key to obtain the second digital digest signature; Perform digital signature verification on the target firmware of the input / output system according to the first digital digest signature and the second digital digest signature.
14. The method according to claim 13, wherein: Performing digital signature verification on the target firmware of the input / output system according to the first digital digest signature and the second digital digest signature includes: When the first digital digest signature is consistent with the second digital digest signature, determine that the digital signature verification of the target firmware passes; When the first digital digest signature is inconsistent with the second digital digest signature, determine that the digital signature verification of the target firmware fails.
15. The method according to claim 1, wherein: Before obtaining the first trusted measurement information of the target firmware, the method further includes: Determine whether the first trusted measurement information is obtained; In the case where the first trusted measurement information is not obtained, an alarm message is sent to a second terminal corresponding to the input / output system, where the second terminal is a terminal for managing the input / output system, and the alarm message is used to indicate that the target firmware is dangerous.
16. The method according to claim 1, wherein: After obtaining the first trusted measurement information of the target firmware, the method further includes: Performing digital signature verification on the first trusted measurement information through a trusted security platform module of the server; In the case where the digital signature verification of the first trusted measurement information passes, determining a verification result of verifying the first trusted measurement information; In the case where the digital signature verification of the first trusted measurement information fails, an alarm message is sent to a second terminal corresponding to the input / output system, where the second terminal is a terminal for managing the input / output system, and the alarm message is used to indicate that the target firmware is dangerous.
17. The method according to claim 1, wherein: Performing digital signature verification on the target firmware of the input / output system includes at least one of the following: Performing digital signature verification on the target firmware of the input / output system through a trusted security platform module of the server; Performing digital signature verification on the target firmware of the input / output system through a motherboard management controller of the server.
18. The method according to claim 1, wherein: Determining a verification result of verifying the first trusted measurement information includes: Determining a verification result of verifying the first trusted measurement information through a motherboard management controller of the server.
19. An execution device for firmware, wherein: It includes: A first verification module configured to perform digital signature verification on the target firmware of the input / output system; A second verification module configured to, in the case where the digital signature verification of the target firmware passes, obtain the first trusted measurement information of the target firmware and determine a verification result of verifying the first trusted measurement information; A determination module configured to determine whether to execute the target firmware according to the verification result.
20. An execution system for firmware, wherein: It includes: A trusted security platform module configured to perform digital signature verification on the target firmware of the input / output system; A motherboard management controller configured to, in the case where the digital signature verification of the target firmware passes, obtain the first trusted measurement information of the target firmware and determine a verification result of verifying the first trusted measurement information; A central processing unit configured to determine whether to execute the target firmware according to the verification result.
21. A computer non-volatile readable storage medium, wherein: A computer program is stored in the computer non-volatile readable storage medium, and when the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 18 are implemented.
22. An electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the method described in any one of claims 1 to 18 are implemented.
Citation Information
Patent Citations
Method for realizing secure and trusted startup, security architecture system and related equipment
CN115618364A
Method for realizing secure and trusted startup, security architecture system and related equipment
CN115618365A
Trusted loading method and device for firmware support package, terminal and storage medium
CN116302165A
Basic input and output system firmware upgrading method and device
CN116679967A
Firmware execution method, device and system, storage medium and electronic equipment
CN117494232A