Method and apparatus for booting server, and storage medium and electronic device

By deploying a trusted platform module on the server and using the target account's authentication information to encrypt and authenticate the startup data, the problem of low security in the server operating environment is solved, and higher security is achieved.

WO2025246556A1PCT designated stage Publication Date: 2025-12-04INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/083214
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-31
Filing Date
2025-03-18
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

The security of the server operating environment in the current technology is low, and the security functions that rely on the processor cannot be perceived by users, which poses a significant security risk.

Method used

Deploy a trusted platform module on the server to store the target account's authentication information and use this authentication information to encrypt and authenticate the startup information, ensuring the security of the startup data.

Benefits of technology

By authenticating startup data using the target account's private authentication method, the security of the server startup is improved by preventing the use of tampered startup data that could compromise server startup security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025083214_04122025_PF_FP_ABST
    Figure CN2025083214_04122025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present application are a method and apparatus for booting a server, and a storage medium and an electronic device. The method comprises: receiving a target request sent by a target account, so as to boot a target server; when it is determined that the target account has permission to call the target server, retrieving from a trusted platform module target authentication information corresponding to the target account, and retrieving from the target server a target authentication file corresponding to the target account; using a target authentication mode indicated by the target authentication information to perform decryption authentication on the target authentication file, so as to obtain target boot information; performing data verification on target boot data, which is indicated by the target boot information; and when the target boot data passes the verification, using the target boot data to boot the target server. By means of the present application, the problem in the related art of the security of an operating environment of a server being relatively low is solved, thereby achieving the effect of improving the security of the operating environment of the server.
Need to check novelty before this filing date? Find Prior Art

Description

Server startup methods and devices, storage media and electronic devices

[0001] Cross-reference to related applications

[0002] This application claims priority to Chinese Patent Application No. 2024106967498, filed on May 31, 2024, entitled "Server Startup Method and Apparatus, Storage Medium and Electronic Device", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of computers, and in particular to a server startup method and apparatus, storage medium and electronic device. Background Technology

[0004] A server is a type of computer that runs faster, handles higher loads, and is more expensive than a regular computer. Servers provide computing or application services to other client machines on a network (such as PCs, smartphones, ATMs, and even large equipment like train systems). During the server startup process, the BIOS (Basic Input / Output System) initializes all hardware devices and prepares the boot environment. It is considered the bridge connecting hardware devices and the operating system and is one of the most important components of a server. Without security features, viruses and Trojans can easily corrupt the integrity of the BIOS code, leading to a series of serious losses. To ensure the security and reliability of the server's operating environment, some manufacturers have proposed server protection functions, such as Intel's Boot Guard. Boot Guard introduces an encapsulation called ACM (Authenticated Code Module), which adds this function to the processor. By pre-storing the server's BIOS boot data, the BIOS sends the obtained boot data to the processor for verification when the server needs to be started. Only after successful verification can the server run. While this approach can ensure the security of the server's operating environment to a certain extent, it is entirely dependent on the processor. The root of trust in the security chain also comes from the processor manufacturer. For users of the server, it is impossible to perceive or determine the security of the server's operating environment. For users with security needs, the server's operating environment still has significant security vulnerabilities. Summary of the Invention

[0005] This application provides a server startup method and apparatus, storage medium and electronic device to at least solve the problem of low security in the server operating environment in related technologies.

[0006] According to one embodiment of this application, a server startup method is provided, applied to a basic input / output system (PIS). The target server is deployed with an IPS and a trusted platform module (TPP), the IPS and the TPP are connected. The method includes: receiving a target request sent by a target account to start the target server; if it is determined that the target account has access to the target server, retrieving target authentication information corresponding to the target account from the TPP, and retrieving a target authentication file corresponding to the target account from the target server, wherein the target authentication file is obtained by the target account encrypting and authenticating the startup information of the target server using the target authentication method indicated by the target authentication information, and the startup information indicates the startup data used to start the target server; decrypting and authenticating the target authentication file using the target authentication method indicated by the target authentication information to obtain target startup information; verifying the target startup data indicated by the target startup information; and starting the target server using the target startup data if the target startup data verification passes.

[0007] In some embodiments, retrieving target authentication information corresponding to the target account from the trusted platform module includes:

[0008] Obtain the target business function of the target server requested by the target request;

[0009] Retrieve the target authentication information configured for the target business function by the target account from the trusted platform module.

[0010] In some embodiments, retrieving target authentication information configured for the target business function by the target account from the trusted platform module includes:

[0011] Determine one or more target startup data required to achieve the target business function, wherein each target startup data records the startup method of the corresponding hardware device deployed on the target server;

[0012] Retrieve the target authentication information of the target account corresponding to the target startup data from the trusted platform module.

[0013] In some embodiments, retrieving the target authentication information corresponding to the target startup data of the target account from the trusted platform module includes:

[0014] Determine the target storage location corresponding to the target authentication information from the corresponding authentication information and the storage area within the trusted platform module;

[0015] Send a target acquisition request to the trusted platform module, wherein the target acquisition request is used to request the authentication information stored in the target storage location;

[0016] Receive the target authentication information returned by the trusted platform module in response to the target's request.

[0017] In some embodiments, a central processing unit (CPU) is also deployed on the target server motherboard. The CPU is connected to the basic input / output system and the trusted platform module via a serial peripheral interface bus.

[0018] Send a target acquisition request to the trusted platform module, including:

[0019] Generate target instructions in the serial peripheral device interface protocol format;

[0020] The target instruction is sent to the central processing unit via the serial peripheral device interface bus. The target instruction is used to instruct the central processing unit to send a target acquisition request in the serial peripheral device interface protocol format to the trusted platform module.

[0021] In some embodiments, retrieving the target authentication file corresponding to the target account from the target server includes:

[0022] Obtain the target business function of the target server requested by the target request;

[0023] Select one or more target authentication files corresponding to the target business function from multiple reference authentication files stored in the server. Each reference authentication file is obtained by encrypting the reference startup information by the target account. The reference startup information is used to indicate the data content recorded in the reference startup data used to start the target server. Each reference startup data records the startup method of the corresponding hardware device deployed on the target server.

[0024] In some embodiments, a baseboard management controller is deployed on the target server motherboard, and the baseboard management controller is connected to the basic input / output system.

[0025] Select one or more target authentication files corresponding to the target business function from multiple reference authentication files stored on the server, including:

[0026] Filter out the target authentication file that corresponds to the target account calling the target business function from the account, business function and authentication file with corresponding relationship;

[0027] The target storage location for storing the target authentication file is determined from multiple storage locations in the baseboard management controller, wherein the storage locations in the baseboard management controller and the reference authentication file have a meaningful correspondence;

[0028] Extract the target authentication file from the target storage location.

[0029] In some embodiments, determining a target storage location for storing the target authentication file from multiple storage locations of the substrate management controller includes:

[0030] Obtain the memory mapping table of the baseboard management controller, wherein the memory mapping table is used to indicate the memory space allocation of the baseboard management controller;

[0031] Locate the target storage location in the memory of the baseboard management controller used to store the target authentication file from the memory mapping table.

[0032] In some embodiments, before obtaining the memory mapping table of the trusted platform module, the method further includes:

[0033] Receive a reference authentication file sent by a reference server, where the reference server is configured to maintain the running status of the target server;

[0034] Select unoccupied reference storage locations from the content space of the baseboard management controller;

[0035] The reference authentication file is stored in the reference storage location, and the correspondence between the reference storage location and the reference authentication file is updated in the memory mapping table.

[0036] In some embodiments, the target authentication file is decrypted and authenticated using the target authentication method indicated by the target authentication information to obtain target startup information, including:

[0037] Extract the decryption key corresponding to the target authentication file based on the target authentication information;

[0038] The target authentication file is decrypted using the decryption key to obtain the target startup information.

[0039] In some embodiments, the target authentication file is decrypted using a decryption key to obtain target startup information, including:

[0040] The target authentication file is decrypted using the public key of the target account to obtain the candidate authentication file. The target authentication file is obtained by encrypting the candidate authentication file using the private key corresponding to the public key of the target account. The decryption key includes the public key of the account.

[0041] Obtain the public key of the reference server for the candidate authentication file from the trusted platform module. The reference server is configured to maintain the running status of the target server. The reference server is configured to use the private key corresponding to the public key to encrypt the target startup information and send the encrypted candidate authentication file to the target account for authentication.

[0042] The server's public key is used to decrypt the candidate authentication file to obtain the target startup information.

[0043] In some embodiments, the decryption key corresponding to the target authentication file is converted from the target authentication information, including one of the following:

[0044] If the target authentication information is the public key of the target account, the public key will be used as the decryption key.

[0045] If the target authentication information indicates the target encryption method used by the target account for the target authentication file, determine the decryption method corresponding to the target encryption method; and generate a decryption key for decrypting the target authentication file according to the decryption method.

[0046] In some embodiments, before filtering out the target authentication file corresponding to the target account calling the target business function from the accounts, business functions, and authentication files with corresponding relationships, the method further includes:

[0047] Detect the communication status between the baseboard management controller and the basic input / output system;

[0048] When the communication status indicates that the basic input / output system is in an open circuit state, the target authentication file corresponding to the target business function is selected from multiple initial authentication files stored in the buffer corresponding to the basic input / output system. Among them, the multiple initial authentication files are the authentication files used by the basic input / output system to start the target server for the target account within a reference time period before the current time.

[0049] In some embodiments, after selecting the target authentication file corresponding to the target business function from multiple initial authentication files stored in the cache corresponding to the basic input / output system, the method further includes:

[0050] Upon detection of restored communication between the basic input / output system and the baseboard management controller, multiple reference authentication files stored in the baseboard management controller are extracted;

[0051] Update the initial certification file using the reference certification file.

[0052] In some embodiments, data verification is performed on the target startup data indicated by the target startup information, including:

[0053] Match the target startup information with the target startup data in the target server;

[0054] If the target startup information and the target startup data match, the target startup data verification is deemed successful.

[0055] If the target startup information and target startup data do not match, it is determined that the target startup data verification failed.

[0056] In some embodiments, matching target boot information with target boot data in the target server includes:

[0057] The target startup data is calculated using an information digest algorithm to obtain a candidate information digest, which is used to indicate the data content carried by the target startup data.

[0058] Match the candidate information digest with the target information digest, where the target initiation information includes the target information digest;

[0059] If the target information digest and the candidate information digest are the same, it is determined that the target startup data and the target startup information match.

[0060] When the target information digest and the candidate information digest are different, it is determined that the target startup data and the target startup information do not match.

[0061] According to another embodiment of this application, a server startup device is provided, applied to a basic input / output system (PIS). The target server has an PIS and a trusted platform module (TPP) deployed on it. The PIS and TPP are connected. The device includes:

[0062] The receiving module is configured to receive target requests sent by the target account to start the target server. The retrieval module is configured to, if it is determined that the target account has the right to call the target server, retrieve the target authentication information corresponding to the target account from the trusted platform module and retrieve the target authentication file corresponding to the target account from the target server. The target authentication file is obtained by the target account encrypting and authenticating the startup information of the target server using the target authentication method indicated by the target authentication information. The startup information is used to indicate the startup data used to start the target server. The authentication module is configured to decrypt and authenticate the target authentication file using the target authentication method indicated by the target authentication information to obtain the target startup information. The verification module is configured to verify the target startup data indicated by the target startup information. The startup module is configured to start the target server using the target startup data if the target startup data verification passes.

[0063] According to yet another embodiment of this application, a non-volatile computer-readable storage medium is also provided, wherein a computer program is stored in the non-volatile computer-readable storage medium, and the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0064] According to yet another embodiment of this application, an electronic device is also provided, including a memory and a processor, wherein a computer program is stored in the memory and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0065] According to yet another embodiment of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0066] This application deploys a trusted platform module connected to a basic input / output system on the target server. The trusted platform module stores authentication information for accounts with access to the target server. It also imports an authentication file into the target server, obtained by encrypting the startup information using the authentication method indicated by the authentication information after the account verifies the startup information. This ensures that the startup data used by the target server is authenticated by the account using the server, and that the account controls the authentication method for authenticating the startup data. Upon receiving a target request, the system retrieves the target account's authentication information from the trusted platform module and the corresponding target authentication file from the server. The target authentication file is then decrypted and authenticated using the target authentication method indicated by the authentication information to obtain the startup information. This information is used to verify the target startup data. The server runs based on startup data pre-authenticated using a private authentication method by the target account, preventing the use of tampered startup data and ensuring the security of the server's operating environment. Therefore, this addresses the problem of low security in server operating environments in related technologies, thereby improving the security of the server's operating environment. Attached Figure Description

[0067] Figure 1 is a hardware structure block diagram of a server device for a server startup method according to an embodiment of this application;

[0068] Figure 2 is a flowchart of a server startup method according to an embodiment of this application;

[0069] Figure 3 is a schematic diagram of an optional server system according to an embodiment of this application;

[0070] Figure 4 is a schematic diagram of information interaction according to an embodiment of this application;

[0071] Figure 5 is a schematic diagram of an optional server hardware connection according to an embodiment of this application;

[0072] Figure 6 is an optional startup data verification flowchart according to an embodiment of this application;

[0073] Figure 7 is a structural block diagram of a server startup device according to an embodiment of this application. Detailed Implementation

[0074] The embodiments of this application will be described in detail below with reference to the accompanying drawings and examples.

[0075] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0076] The methods and embodiments provided in this application can be executed in a server device or a similar computing device. Taking a server device as an example, FIG1 is a hardware structure block diagram of a server device for a server startup method according to an embodiment of this application. As shown in FIG1, the server device may include one or more (only one is shown in FIG1) processors 102 (processors 102 may include, but are not limited to, microprocessors MCU (Microcontroller Unit) or programmable logic devices FPGA (Field-Programmable Gate Array), etc.) and a memory 104 configured to store data. The server device may also include a transmission device 106 configured for communication and an input / output device 108. Those skilled in the art will understand that the structure shown in FIG1 is only illustrative and does not limit the structure of the server device. For example, the server device may also include more or fewer components than shown in FIG1, or have a different configuration than shown in FIG1.

[0077] The memory 104 may be configured to store computer programs, such as application software programs and modules, like the computer program corresponding to the server startup method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, thereby implementing the aforementioned method. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may include memory remotely located relative to the processor 102, and these remote memories can be connected to the server device via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0078] The transmission device 106 is configured to receive or send data via a network. Examples of such networks may include a wireless network provided by a communication provider for the server device. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module configured to communicate wirelessly with the Internet.

[0079] This embodiment provides a server startup method. Figure 2 is a flowchart of the server startup method according to an embodiment of this application. As shown in Figure 2, it is applied to a basic input / output system. The target server is equipped with a basic input / output system and a trusted platform module. The basic input / output system is connected to the trusted platform module. The trusted platform module stores authentication information of a reference account with calling authority over the target server. The authentication information is used to indicate the authentication method for the reference account to encrypt and authenticate the data. The target server imports an authentication file obtained by the reference account encrypting and authenticating the startup information of the target server using the authentication method after the information verification is passed. The startup information is used to indicate the startup data used to start the target server. The process includes the following steps:

[0080] Step S202: Receive the target request sent by the target account to start the target server;

[0081] Step S204: If it is determined that the target account has the right to call the target server, retrieve the target authentication information corresponding to the target account from the trusted platform module and retrieve the target authentication file corresponding to the target account from the target server. The target authentication file is obtained by the target account using the target authentication method indicated by the target authentication information to encrypt and authenticate the startup information of the target server. The startup information is used to indicate the startup data used to start the target server.

[0082] Step S206: Decrypt and authenticate the target authentication file using the target authentication method indicated by the target authentication information to obtain the target startup information;

[0083] Step S208: Perform data verification on the target startup data indicated by the target startup information;

[0084] Step S210: If the target startup data verification passes, start the target server using the target startup data.

[0085] Through the above steps, a trusted platform module connected to the basic input / output system is deployed on the target server. This trusted platform module stores authentication information for accounts with access to the target server. It also imports an authentication file into the target server, obtained by encrypting the startup information using the authentication method indicated by the authentication information after the account verifies the startup information. This ensures that the startup data used by the target server is authenticated by the account using the server, and that the account controls the authentication method for authenticating the startup data. Upon receiving a target request, the system retrieves the target account's authentication information from the trusted platform module and the corresponding target authentication file from the server. The target authentication file is then decrypted and authenticated using the target authentication method indicated by the authentication information to obtain the startup information. This information is used to verify the target startup data. The server runs based on startup data pre-authenticated using a private authentication method by the target account, preventing the use of tampered startup data and ensuring the security of the server's operating environment. Therefore, this addresses the issue of low security in server operating environments in related technologies, effectively improving the security of the server's operating environment.

[0086] Optionally, in this embodiment of the application, the trusted platform module stores authentication information of a reference account that has access to the target server. The authentication information is used to indicate the authentication method for the reference account to encrypt and authenticate the data. The target server imports an authentication file obtained by the reference account encrypting and authenticating the startup information of the target server after the information verification is passed. The startup information is used to indicate the startup data used to start the target server.

[0087] Optionally, in this embodiment of the application, during the server startup process, the Trusted Platform Module (TPM) is a secure storage module that is allowed to be accessed by the basic input / output system. Based on the secure storage characteristics of the Trusted Platform Module, the authentication information stored in the Trusted Platform Module is guaranteed not to be stolen.

[0088] Optionally, in this embodiment, the authentication information stored in the trusted platform module may be stored in the trusted platform module by a reference server configured to maintain the operation of the target server, or it may be stored in the trusted platform module by the user according to their usage needs of the target server. For example, the reference server configures authentication information for the account using the server and stores this authentication information in the trusted platform module. Alternatively, the account requesting to use the target server may send its own authentication information to the reference server for review, and the reference server stores it in the trusted platform module after the review is passed. Alternatively, the account using the server may be stored in the trusted platform module. For example, the reference account sends a request to the reference server to invoke the target server. After the target server verifies the request, it issues authorization information to the target account. This authorization information indicates that the reference account has the right to invoke the target server, and the reference account uses this authorization information to access the trusted platform module, storing its own authentication information in the trusted platform module. This solution does not limit this.

[0089] Optionally, in the embodiments of this application, the authentication information may include, but is not limited to, the encryption key used by the reference account to encrypt and authenticate the data, the decryption key corresponding to the encryption key, the key generation method for generating the encryption key used by the reference account to authenticate the data, the key generation method for generating the decryption key, etc., and this solution does not limit this.

[0090] Optionally, in this embodiment, startup data is used to indicate the startup method for starting the server. Different startup data indicate different startup methods to implement different business functions of the server. For example, startup data may be data used to start the corresponding hardware device deployed on the service. This solution does not limit this.

[0091] In the embodiment provided in step S202 above, the target request may, but is not limited to, carry a business function that requests the server to handle the business. That is, the server can divide its startup data according to the business function, so that different startup data can be called according to different business functions. Alternatively, the server can further divide its startup data according to the type of business function it implements, and then, when a request calls the server's target business function, the startup data in the server can be filtered to obtain a set of startup data for implementing the server's target business function.

[0092] Optionally, in this embodiment, the target account is an account registered on the server and having a login relationship with the target server. That is, the target account can be an account logged in on the server client corresponding to the target server; or the target account can be an account logged in on a webpage bound to the target server; or the target account can be an account logged in on a candidate server that has a binding relationship with the target server. The candidate server is set to call the relevant business functions on the server to complete the business functions of the candidate server. This solution does not limit this.

[0093] In the embodiment provided in step S204 above, the trusted platform module can provide an API (Application Programming Interface) for other modules (such as the Basic Input / Output System) to call in order to obtain the target authentication information corresponding to the target account. The caller can request the target authentication information by sending specific request parameters, such as the target account ID (Identity Document) or username.

[0094] Optionally, in this embodiment, the authentication file can be stored in the server in correspondence with the corresponding startup data, that is, the authentication file and startup data with corresponding relationship are stored in the same location in the server, which facilitates the data retrieval of candidates. For example, the authentication file and startup data with corresponding relationship can be stored in the BMC (Baseboard Management Controller) of the server, which facilitates the BMC candidate to call the startup data to perform startup operation on the server. This solution does not limit this.

[0095] In the embodiment provided in step S206 above, the startup information can be obtained by joint signature authentication by the target account using the target server and the maintenance party for maintaining the target server, thereby ensuring the security and reliability of the authentication file. For example, the maintenance party of the target server uses its private key to encrypt and authenticate the startup information to obtain an authenticated file, and then sends the authenticated file to the target account. The target account uses its private key to sign and authenticate the authentication file to obtain the target authentication file. At this time, decrypting the target authentication file requires the decryption key of the target account and the decryption key of the maintenance party. Therefore, the corresponding decryption key can be converted from the authentication information to decrypt and authenticate the target authentication file.

[0096] In the embodiment provided in step S208 above, the target startup information is the startup information obtained by pre-authentication of the target account. The startup information records the startup data used to start the server after the target account has been authenticated. By using the target startup information to verify the target startup data, the security of the target startup data to be called during the server startup process is protected, and the server is prevented from using tampered startup data to perform startup operations. This solution does not limit this aspect.

[0097] This application employs a method for protecting the static area of ​​the server firmware BIOS without relying on the processor. It utilizes the characteristics of a High-Quality Trusted Platform Module (TPM) and a developed verification algorithm to verify the BIOS static area. This achieves secure boot and prevents intrusion by Trojans and other viruses. Figure 3 is a schematic diagram of an optional server system according to an embodiment of this application. As shown in Figure 3, the system includes a target server, a target account using the target server, and a reference server configured to maintain the target server. The target account is registered on the server and has a login relationship with the target server; that is, the target account can be an account logged in on the server client corresponding to the target server; or the target account can be an account logged in on a webpage bound to the target server; or the target account can be an account logged in on a candidate server bound to the target server. The candidate server is configured to call relevant business functions on the server to complete the business functions of the candidate server. Before the server starts, the reference server sends startup information containing the startup data to the target account for authentication. After the target account successfully authenticates the startup information, it uses the target account's authentication method to encrypt and authenticate the startup information to obtain an authentication file, which is then sent to the reference server. The reference server stores the authentication file on the target server. Subsequently, when the target account issues a target request to call the server, it can retrieve the authentication file and the authentication information stored on the server. The authentication information is then used to decode the authentication file to obtain the startup information, thereby enabling the use of the startup information to verify the startup data to be called by the server.

[0098] Figure 4 is a schematic diagram of information interaction according to an embodiment of this application. As shown in Figure 4, to ensure the security of boot information, this application can set two sets of keys to encrypt and authenticate the authentication information. The user (using the reference account of the target server) generates a key pair as the root key pair, which is the root of trust for secure boot and is responsible for encrypting the certificate of the secondary key. The server vendor (the reference server that maintains the target server) generates a key pair as the secondary key pair, which is responsible for encrypting the BIOS static area (boot data). To ensure the security of the public key, the public keys of the root key and the secondary key are stored in the Trusted Platform Module (TPM). The private key of the root key is stored on the user's end, and the private key of the secondary key is stored on the server vendor's end. The root key is the source of the root of trust in this scheme, and at the same time, the root key is controlled by the user, which meets the customer's security requirements. It supports user customization of the BIOS encryption area (boot data), focusing on the user and allowing the user to select important areas. These important areas may be the core code area within the BIOS, or the code area of ​​user-customized functions, etc. After the user customizes the BIOS encryption zone, the reference server selects different secondary key private keys to encrypt the corresponding secondary certificates based on the zone type selected by the user. Then, all secondary certificates are sent to the user. The user uses the root key's private key to encrypt all secondary certificates into the corresponding root certificates and sends them to the reference server. Next, the reference server writes all root certificates into the BMC out-of-band and writes the public key of the root key provided by the user into the Trusted Platform Module (TPM).

[0099] As an optional implementation, retrieving the target authentication information corresponding to the target account from the trusted platform module includes:

[0100] Obtain the target business function of the target server requested by the target request;

[0101] Retrieve the target authentication information configured for the target business function by the target account from the trusted platform module.

[0102] Optionally, in this embodiment of the application, the target account can use a fixed authentication information to authenticate the startup information of all business functions of the server.

[0103] Optionally, in this embodiment of the application, the target account can configure different authentication information for different business functions, that is, use different authentication information to authenticate the startup information of different business functions of the server. Then, different authentication information can be set according to the importance of the business function. The higher the importance of the business function, the higher the security level of the authentication method indicated by the authentication information, and the higher the complexity of performing the authentication operation. The lower the importance of the business function, the lower the security level of the authentication method indicated by the authentication service, and the lower the complexity of performing the authentication operation.

[0104] By configuring corresponding authentication information for different business functions, the system avoids the use of the same authentication method by target accounts to perform encrypted authentication of startup information for different business functions. This ensures the accuracy of the authentication files, prevents the files from being stolen or tampered with, and thus guarantees the security of the server's operating environment.

[0105] As an optional implementation, the target authentication information configured for the target business function by the target account is retrieved from the trusted platform module, including:

[0106] Determine one or more target startup data required to achieve the target business function, wherein each target startup data records the startup method of the corresponding hardware device deployed on the target server;

[0107] Retrieve the target authentication information of the target account corresponding to the target startup data from the trusted platform module.

[0108] Optionally, in this embodiment, the authentication information may be generated based on the data content of the corresponding startup data. For example, a key generation algorithm can be used to calculate the data content of the startup data to obtain key information for signing and authenticating the startup information corresponding to the startup data. The authentication information includes key information, and this solution does not limit this.

[0109] By taking the above steps, the startup data in the server is split into segments with a certain granularity, and corresponding authentication methods are configured for the startup data. This avoids using the same authentication method to authenticate different startup information, reducing the risk of startup information being stolen, deciphered, or tampered with.

[0110] As an optional implementation, the target authentication information corresponding to the target startup data of the target account is retrieved from the trusted platform module, including:

[0111] Determine the target storage area corresponding to the target authentication information from the corresponding authentication information and the storage areas within the trusted platform module;

[0112] Send a target acquisition request to the trusted platform module, wherein the target acquisition request is used to request the authentication information stored in the target storage area;

[0113] Receive the target authentication information returned by the trusted platform module in response to the target's request.

[0114] Optionally, in this embodiment, the authentication information can be stored in a continuous area within the trusted platform module, or the same authentication information can be stored in multiple non-contiguous storage areas within the trusted platform module. When obtaining authentication information stored in the trusted platform module, if the obtained authentication information is sub-authentication information from multiple storage areas, the target authentication information can be obtained by splicing the multiple sub-authentication information according to the order of their storage areas within the trusted platform module. This solution does not limit this.

[0115] Based on the above, by dividing and allocating the storage space of the trusted platform module, we can achieve effective utilization of the storage space of the trusted platform module, improve the storage efficiency of authentication information, avoid storage disorder of authentication information, and facilitate subsequent use.

[0116] As an optional embodiment, a central processing unit (CPU) is also deployed on the target server motherboard. The CPU is connected to the basic input / output system and the trusted platform module via a serial peripheral interface bus.

[0117] Send a target acquisition request to the trusted platform module, including:

[0118] Generate target instructions in the serial peripheral device interface protocol format;

[0119] The target instruction is sent to the central processing unit via the serial peripheral device interface bus. The target instruction is used to instruct the central processing unit to send a target acquisition request in the serial peripheral device interface protocol format to the trusted platform module.

[0120] As an optional embodiment, the method further includes, before sending the target acquisition request to the trusted platform module:

[0121] Retrieve the target authorization value stored in the Basic Input / Output System (PIS), where the target authorization value indicates the PIS's access rights to the Trusted Platform Module (TPM).

[0122] Send a permission verification request carrying the target authorization value to the trusted platform module. The permission verification request is used to request the trusted platform module to verify the data access permissions of the basic input / output system based on the target authorization value.

[0123] Optionally, in this embodiment, the target authorization value represents the basic input / output system's read permission to the trusted platform module. The basic input / output system can use a fixed authorization value to access the trusted platform module. Alternatively, different authorization values ​​may be stored on the trusted platform module for different authentication information. The basic input / output system needs to use the corresponding authorization value to access the storage area in the trusted platform module used to store the corresponding authentication information. This solution does not limit this.

[0124] By setting an authorization value for the Basic Input / Output System (BIOS) on the Trusted Platform Module, authentication is performed using the authorization value before the BIOS requests authentication information from the Trusted Platform Module. This ensures the secure storage of authentication information by the Trusted Authentication Platform and prevents the theft of authentication information from the Trusted Platform Module.

[0125] As an optional implementation, retrieving the target authentication file corresponding to the target account from the target server includes:

[0126] Obtain the target business function of the target server requested by the target request;

[0127] Select one or more target authentication files corresponding to the target business function from multiple reference authentication files stored in the server. Each reference authentication file is obtained by encrypting the reference startup information by the target account. The reference startup information is used to indicate the data content recorded in the reference startup data used to start the target server. Each reference startup data records the startup method of the corresponding hardware device deployed on the target server.

[0128] Optionally, in this embodiment, the reference startup data is obtained by segmenting the startup data deployed in the server according to a certain granularity, such as segmenting according to the device type of the hardware device started by the startup data, or segmenting according to the business function implemented by the hardware device started by the startup data. This solution does not limit this.

[0129] By segmenting the startup data in the server into multiple reference startup data sets through the above steps, the flexibility of server startup data management is ensured. Server maintainers can add corresponding reference startup data as needed, and then assemble and splice multiple reference startup information to obtain a startup data set for implementing corresponding business functions. This reduces the amount of data maintenance required by maintenance personnel. In addition, the reference startup data can be flexibly combined to enable the server to support different business functions and improve the flexibility of the server's business functions.

[0130] As an optional embodiment, a baseboard management controller is deployed on the target server motherboard, and the baseboard management controller is connected to the basic input / output system.

[0131] Select one or more target authentication files corresponding to the target business function from multiple reference authentication files stored on the server, including:

[0132] Filter out the target authentication file that corresponds to the target account calling the target business function from the account, business function and authentication file with corresponding relationship;

[0133] The target storage location for storing the target authentication file is determined from multiple storage locations in the baseboard management controller, wherein the storage locations in the baseboard management controller and the reference authentication file have a meaningful correspondence;

[0134] Extract the target authentication file from the target storage location.

[0135] Based on the above, by segmenting the storage location of the baseboard management controller, the corresponding authentication files are configured with corresponding storage locations in the baseboard management controller. This ensures the effective use of the baseboard management controller's storage location and improves the storage efficiency of authentication files, facilitating subsequent retrieval of authentication files.

[0136] As an optional embodiment, determining a target storage location for storing the target authentication file from multiple storage locations of the baseboard management controller includes:

[0137] Obtain the memory mapping table of the baseboard management controller, wherein the memory mapping table is used to indicate the memory space allocation of the baseboard management controller;

[0138] Locate the target storage location in the memory of the baseboard management controller used to store the target authentication file from the memory mapping table.

[0139] As an optional embodiment, before obtaining the memory mapping table of the trusted platform module, the method further includes:

[0140] Receive a reference authentication file sent by a reference server, where the reference server is configured to maintain the running status of the target server;

[0141] Select unoccupied reference storage locations from the content space of the baseboard management controller;

[0142] The reference authentication file is stored in the reference storage location, and the correspondence between the reference storage location and the reference authentication file is updated in the memory mapping table.

[0143] Optionally, in the embodiments of this application, the storage location occupied by the authentication file in the baseboard management controller can be a continuous storage location, or the authentication file can occupy multiple non-contiguous storage locations in the baseboard management controller.

[0144] Based on the above, when storing authentication files in the baseboard management controller, the authentication files are stored in unoccupied storage locations by filtering the unoccupied storage locations in the baseboard management controller, thereby ensuring the effective use of the baseboard management controller's storage space and avoiding waste of storage space.

[0145] As an optional embodiment, the target authentication file is decrypted and authenticated using the target authentication method indicated by the target authentication information to obtain target startup information, including:

[0146] Extract the decryption key corresponding to the target authentication file based on the target authentication information;

[0147] The target authentication file is decrypted using the decryption key to obtain the target startup information.

[0148] Optionally, in the embodiments of this application, the target authentication information may carry a decryption key for decrypting the authentication information, or it may store a key generation method for generating the decryption key.

[0149] As an optional embodiment, the target authentication file is decrypted using a decryption key to obtain target startup information, including:

[0150] The target authentication file is decrypted using the public key of the target account to obtain the candidate authentication file. The target authentication file is obtained by encrypting the candidate authentication file using the private key corresponding to the public key of the target account. The decryption key includes the public key of the account.

[0151] Obtain the public key of the reference server for the candidate authentication file from the trusted platform module. The reference server is configured to maintain the running status of the target server. The reference server is configured to use the private key corresponding to the public key to encrypt the target startup information and send the encrypted candidate authentication file to the target account for authentication.

[0152] The server's public key is used to decrypt the candidate authentication file to obtain the target startup information.

[0153] Through the above steps, the startup information is jointly encrypted and authenticated by the target account on the target server and the reference server that maintains the operation function of the target server. That is, the reference server first encrypts and authenticates the startup information and sends the encrypted and authenticated file to the target account for authentication. This ensures that the target account receives an encrypted version of the startup information, avoiding the problem of startup information leakage caused by sending the server's startup information in plaintext to the target user, and ensuring the security of the server's startup information.

[0154] As an optional embodiment, the decryption key corresponding to the target authentication file is converted from the target authentication information, including one of the following:

[0155] If the target authentication information is the public key of the target account, the public key will be used as the decryption key.

[0156] If the target authentication information indicates the target encryption method used by the target account for the target authentication file, determine the decryption method corresponding to the target encryption method; and generate a decryption key for decrypting the target authentication file according to the decryption method.

[0157] As an optional embodiment, before filtering out the target authentication file corresponding to the target account calling the target business function from the corresponding accounts, business functions, and authentication files, the method further includes:

[0158] Detect the communication status between the baseboard management controller and the basic input / output system;

[0159] When the communication status indicates that the basic input / output system is in an open circuit state, the target authentication file corresponding to the target business function is selected from multiple initial authentication files stored in the buffer corresponding to the basic input / output system. Among them, the multiple initial authentication files are the authentication files used by the basic input / output system to start the target server for the target account within a reference time period before the current time.

[0160] By caching the authentication files used by the target account in the cache area of ​​the basic input / output system, the system can verify the startup data after the basic input / output system and the baseboard management controller lose contact. This improves the operational stability of the server system and avoids the impact of a broken link between the basic input / output system and the baseboard management controller on the server startup.

[0161] As an optional embodiment, after selecting the target authentication file corresponding to the target business function from multiple initial authentication files stored in the cache corresponding to the basic input / output system, the method further includes:

[0162] Upon detection of restored communication between the basic input / output system and the baseboard management controller, multiple reference authentication files stored in the baseboard management controller are extracted;

[0163] Update the initial certification file using the reference certification file.

[0164] After restoring communication between the Elementary Input / Output System (IIIOS) and the Baseboard Management Controller (BMC) through the above steps, the reference authentication file in the BMC is called to update the authentication file stored in the IIIOS's buffer, thus ensuring the accuracy of the authentication file stored in the IIIOS's buffer.

[0165] As an optional embodiment, data verification is performed on the target startup data indicated by the target startup information, including:

[0166] Match the target startup information with the target startup data in the target server;

[0167] If the target startup information and the target startup data match, the target startup data verification is deemed successful.

[0168] If the target startup information and target startup data do not match, it is determined that the target startup data verification failed.

[0169] As an optional embodiment, matching the target startup information with the target startup data in the target server includes:

[0170] The target startup data is calculated using an information digest algorithm to obtain a candidate information digest, which is used to indicate the data content carried by the target startup data.

[0171] Match the candidate information digest with the target information digest, where the target initiation information includes the target information digest;

[0172] If the target information digest and the candidate information digest are the same, it is determined that the target startup data and the target startup information match.

[0173] When the target information digest and the candidate information digest are different, it is determined that the target startup data and the target startup information do not match.

[0174] As an optional embodiment, after determining that the target startup data verification failed, the method further includes:

[0175] Control the target server to crash and generate a target notification message indicating that the target's startup data has been tampered with;

[0176] The target notification message is sent to the reference server, which is configured to maintain the target server's startup data based on the target notification message.

[0177] Optionally, in the embodiments of this application, the reference server's operation on the startup data maintenance of the target server may include, but is not limited to, reconfiguring the startup data and re-acquiring the target authentication file obtained by authenticating the startup information of the target account with the startup data. This solution does not limit this.

[0178] Based on the above, after detecting that the target startup data on the server has been tampered with, the server is first shut down to prevent data theft caused by the server operating in an incorrect environment. Then, a target notification message is sent to the reference server to request startup data maintenance for the target server, thereby enabling the server to resume normal operation as soon as possible and improving the server's operational stability.

[0179] Figure 5 is a schematic diagram of an optional server hardware connection according to an embodiment of this application. As shown in Figure 5, from a hardware perspective, the CPU (Central Processing Unit) SPI (Serial Peripheral Interface) bus connects the BIOS and TPM, and the eSPI (Enhanced Serial Peripheral Interface) bus connects the BMC. From a software perspective, after the eSPI bus connection between the BIOS and BMC is successfully established, the Host to bridge device connected to the BMC is initialized during enumeration, and then the device's MMIO (Memory-Mapped I / O) resources are used for data interaction. In this scheme, the root certificate of each region is written into the BMC in advance. During the server startup phase, the BIOS can use MMIO to read the root certificate of each region written into the BMC. The BIOS and TPM previously use SPI commands for data interaction. In this scheme, the public key of the root key is written into the TPM in advance, and during the server startup phase, the BIOS can use SPI commands to read the public key of the root key written into the TPM.

[0180] Figure 6 is an optional boot data verification flowchart according to an embodiment of this application. As shown in Figure 6, after power-on, the BIOS reads the root certificate of each encrypted region from the BMC. Simultaneously, the BIOS also reads the root certificate of each encrypted region (boot data) from its own chip's NVRAM (Non-Volatile Random Access Memory). The root certificates of each encrypted region read from the BMC and the BIOS's NVRAM are compared. If they are inconsistent, the root certificate of each encrypted region read from the BMC is saved to the BIOS's NVRAM. In other words, the BMC has higher priority than the BIOS's NVRAM. Saving to the BIOS's NVRAM mainly prevents the inability to obtain the correct root certificate for each encrypted region from the BMC due to communication failure during boot. In the event of communication failure with the BMC, the root certificate of each encrypted region can be retrieved from the BIOS's NVRAM.

[0181] Next, the BIOS retrieves the public keys for the root key and secondary key from the Trusted Platform Module (TPM). Obtaining the public keys from the TPM ensures their authenticity and security. The public key of the root key is used to decrypt the root certificate of each encrypted zone, and then the public key of the secondary key is used to decrypt the secondary certificate of each encrypted zone to obtain the hash value of each encrypted zone. For example, the hash value of zone 1 is 1_A, the hash value of zone 2 is 2-A, the hash value of zone 3 is 3-A, and so on, with the hash value of zone N being NA. Simultaneously, before running the encrypted zone code, the BIOS calculates the hash value of encrypted zone 1 as 1_B, the hash value of zone 2 as 2-B, the hash value of zone 3 as 3_B, and so on, with the hash value of zone N being NB. The system compares the hash values ​​of the same region. For example, it compares 1_A and 1_B of region 1, and 2_A and 2_B of region 2. If the hash values ​​are the same, the verification passes and the encrypted code is allowed to run. Otherwise, the verification fails and a verification failure log is recorded for users to view. At the same time, the server crash mechanism is triggered to prevent users from suffering a series of serious losses due to running code that has been tampered with by viruses or Trojans.

[0182] This application supports multiple sets of secondary certificates to adapt to different encryption zones selected by users, thus meeting their various customized package needs. For example, if a user customizes three packages, each with different application scenarios, the encryption zone combinations the user focuses on will also differ. This solution provides one secondary certificate for each encryption zone, for example, 1 to 10, providing 10 secondary certificates for 10 encryption zones. Package 1 requires encryption zones 1, 3, 5, and 7, and is named Secondary Certificate Combination 1; Package 2 requires encryption zones 1, 2, 3, 4, and 5, and is named Secondary Certificate Combination 2; Package 3 requires encryption zones 2, 4, 6, and 8, and is named Secondary Certificate Combination 3. Different encryption zone combinations form different secondary certificate combinations. This solution does not limit the number of secondary certificate combinations; everything is configured around customer needs. Upon shipment, if the user orders Package 1, Secondary Certificate Combination 1 will be written to the TPM. If the user orders Package 2, Secondary Certificate Combination 2 will be written to the TPM. If the user orders Package 3, Secondary Certificate Combination 3 will be written to the TPM.

[0183] The secure boot method for servers provided in the above embodiments can help servers detect and prevent intrusion of malware and viruses during startup. The advantages of this application are its excellent security implementation scheme, its freedom from the limitations of server processor chip manufacturers, and its customer-centric approach, ensuring the security of the BIOS static area based on user requirements.

[0184] Breaking free from the limitations of server processor chip manufacturers enables cross-platform solution unification, while also achieving code standardization, saving development and testing manpower, and making it easier for users to understand and use.

[0185] Employing both root and secondary encryption layers, this solution enhances security while supporting customizable encryption zone combinations. This allows users to use different encryption and verification zones for different service plans. The solution meets the needs of various application scenarios across different service plans, offering convenient customization. Simply write the public key combination of different secondary keys into the TPM at the time of shipment, saving release and self-testing time for duplicate versions across different service plans.

[0186] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM (Read-Only Memory) / RAM (Random Access Memory), magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.

[0187] This embodiment also provides a server startup device, which is configured to implement the above embodiments and optional implementations, and will not be repeated as already described. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0188] Figure 7 is a structural block diagram of a server startup device according to an embodiment of this application, applied to a basic input / output system. The target server is equipped with a basic input / output system and a trusted platform module, which are connected. As shown in Figure 7, the device includes:

[0189] The receiving module is configured to receive target requests sent by the target account in order to start the target server;

[0190] The retrieval module is configured to retrieve the target authentication information corresponding to the target account from the trusted platform module and the target authentication file corresponding to the target account from the target server, provided that the target account has the right to call the target server. The target authentication file is obtained by the target account encrypting and authenticating the startup information of the target server using the target authentication method indicated by the target authentication information. The startup information is used to indicate the startup data used by the target server to start.

[0191] The authentication module is configured to decrypt and authenticate the target authentication file using the target authentication method indicated by the target authentication information to obtain the target startup information.

[0192] The verification module is configured to perform data verification on the target startup data indicated by the target startup information;

[0193] The startup module is configured to start the target server using the target startup data if the target startup data verification passes.

[0194] Based on the above, a trusted platform module connected to the basic input / output system is deployed on the target server. This trusted platform module stores authentication information for accounts with access to the target server. It also imports an authentication file into the target server, obtained by encrypting the startup information using the authentication method indicated by the authentication information after the account verifies the startup information. This ensures that the startup data used by the target server is authenticated by the account using the server, and that the account controls the authentication method for authenticating the startup data. Upon receiving a target request, the system retrieves the target account's authentication information from the trusted platform module and the corresponding target authentication file from the server. The target authentication file is then decrypted and authenticated using the target authentication method indicated by the authentication information to obtain the startup information. This information is used to verify the target startup data. The server runs based on startup data pre-authenticated using a private authentication method by the target account, preventing the use of tampered startup data and ensuring the security of the server's operating environment. Therefore, this addresses the issue of low security in server operating environments in related technologies, effectively improving the security of the server's operating environment.

[0195] In some embodiments, the retrieval module includes:

[0196] The first acquisition unit is set to acquire the target business function of the target server requested to be invoked by the target request.

[0197] The retrieval unit is configured to retrieve the target authentication information configured for the target business function from the target account in the trusted platform module.

[0198] In some embodiments, the retrieval unit is configured to:

[0199] Determine one or more target startup data required to achieve the target business function, wherein each target startup data records the startup method of the corresponding hardware device deployed on the target server;

[0200] Retrieve the target authentication information of the target account corresponding to the target startup data from the trusted platform module.

[0201] In some embodiments, the retrieval unit is configured to:

[0202] Determine the target storage area corresponding to the target authentication information from the corresponding authentication information and the storage areas within the trusted platform module;

[0203] Send a target acquisition request to the trusted platform module, wherein the target acquisition request is used to request the authentication information stored in the target storage area;

[0204] Receive the target authentication information returned by the trusted platform module in response to the target's request.

[0205] In some embodiments, a central processing unit (CPU) is also deployed on the target server motherboard. The CPU is connected to the basic input / output system and the trusted platform module via a serial peripheral interface bus.

[0206] The call unit is set to:

[0207] Generate target instructions in the serial peripheral device interface protocol format;

[0208] The target instruction is sent to the central processing unit via the serial peripheral device interface bus. The target instruction is used to instruct the central processing unit to send a target acquisition request in the serial peripheral device interface protocol format to the trusted platform module.

[0209] In some embodiments, the apparatus further includes:

[0210] The acquisition module is configured to acquire the target authorization value stored in the Basic Input / Output System before sending a target acquisition request to the Trusted Platform Module, wherein the target authorization value is used to indicate the access rights of the Basic Input / Output System to the Trusted Platform Module;

[0211] The sending module is configured to send a permission verification request carrying a target authorization value to the trusted platform module. The permission verification request is used to request the trusted platform module to verify the data access permissions of the basic input / output system based on the target authorization value.

[0212] In some embodiments, the retrieval module includes:

[0213] The second acquisition unit is configured to acquire the target business function of the target server requested to be invoked by the target request.

[0214] The filtering unit is configured to select one or more target authentication files corresponding to the target business function from multiple reference authentication files stored in the server. Each reference authentication file is obtained by encrypting reference startup information by the target account. The reference startup information is used to indicate the data content recorded in the reference startup data used by the target server to start. Each reference startup data records the startup method of the corresponding hardware device deployed on the target server.

[0215] In some embodiments, a baseboard management controller is deployed on the target server motherboard, and the baseboard management controller is connected to the basic input / output system.

[0216] The filter cell is set to:

[0217] Filter out the target authentication file that corresponds to the target account calling the target business function from the account, business function and authentication file with corresponding relationship;

[0218] The target storage location for storing the target authentication file is determined from multiple storage locations in the baseboard management controller, wherein the storage locations in the baseboard management controller and the reference authentication file have a meaningful correspondence;

[0219] Extract the target authentication file from the target storage location.

[0220] In some embodiments, the filtering unit is configured as follows:

[0221] Obtain the memory mapping table of the baseboard management controller, wherein the memory mapping table is used to indicate the memory space allocation of the baseboard management controller;

[0222] Locate the target storage location in the memory of the baseboard management controller used to store the target authentication file from the memory mapping table.

[0223] In some embodiments, the apparatus further includes:

[0224] The receiving module is configured to receive a reference authentication file sent by the reference server before obtaining the memory mapping table of the trusted platform module. The reference server is configured to maintain the running status of the target server.

[0225] The first filtering module is configured to filter out unoccupied reference storage locations from the content space of the baseboard management controller;

[0226] The update module is configured to store the reference authentication file in a reference storage location and update the mapping between the reference storage location and the reference authentication file in the memory map table.

[0227] In some embodiments, the authentication module includes:

[0228] The conversion unit is configured to convert the target authentication information into the decryption key corresponding to the target authentication file.

[0229] The decryption unit is configured to use a decryption key to decrypt the target authentication file and obtain the target startup information.

[0230] In some embodiments, the decryption unit is configured as follows:

[0231] The target authentication file is decrypted using the public key of the target account to obtain the candidate authentication file. The target authentication file is obtained by encrypting the candidate authentication file using the private key corresponding to the public key of the target account. The decryption key includes the public key of the account.

[0232] Obtain the public key of the reference server for the candidate authentication file from the trusted platform module. The reference server is configured to maintain the running status of the target server. The reference server is configured to use the private key corresponding to the public key to encrypt the target startup information and send the encrypted candidate authentication file to the target account for authentication.

[0233] The server's public key is used to decrypt the candidate authentication file to obtain the target startup information.

[0234] In some embodiments, the conversion unit is configured to perform one of the following operations:

[0235] If the target authentication information is the public key of the target account, the public key will be used as the decryption key.

[0236] If the target authentication information indicates the target encryption method used by the target account for the target authentication file, determine the decryption method corresponding to the target encryption method; and generate a decryption key for decrypting the target authentication file according to the decryption method.

[0237] In some embodiments, the apparatus further includes:

[0238] The first detection module is configured to detect the communication status between the baseboard management controller and the basic input / output system before filtering out the target authentication file corresponding to the target account calling the target business function from the account, business function and authentication file with corresponding relationship;

[0239] The second filtering module is configured to, when the communication status indicates that the basic input / output system is in an open circuit state, filter out the target authentication file corresponding to the target business function from multiple initial authentication files stored in the buffer corresponding to the basic input / output system. The multiple initial authentication files are authentication files used by the basic input / output system to start the target server for the target account within a reference time period before the current time.

[0240] In some embodiments, the apparatus further includes:

[0241] The second detection module is configured to, after filtering out the target authentication file corresponding to the target service function from multiple initial authentication files stored in the cache corresponding to the basic input / output system, extract multiple reference authentication files stored in the baseboard management controller when the resumption of communication between the basic input / output system and the baseboard management controller is detected.

[0242] The update module is configured to update the initial authentication file using a reference authentication file.

[0243] In some embodiments, the verification module includes:

[0244] The matching unit is configured to match the target startup information with the target startup data in the target server;

[0245] The first determining unit is configured to determine that the target startup data verification is successful if the target startup information and the target startup data match.

[0246] If the target startup information and target startup data do not match, the second determining unit determines that the target startup data verification has failed.

[0247] In some embodiments, the matching unit is configured as:

[0248] The target startup data is calculated using an information digest algorithm to obtain a candidate information digest, which is used to indicate the data content carried by the target startup data.

[0249] Match the candidate information digest with the target information digest, where the target initiation information includes the target information digest;

[0250] If the target information digest and the candidate information digest are the same, it is determined that the target startup data and the target startup information match.

[0251] When the target information digest and the candidate information digest are different, it is determined that the target startup data and the target startup information do not match.

[0252] In some embodiments, the apparatus further includes:

[0253] The processing module is configured to shut down the target server and generate a target notification message indicating that the target startup data has been tampered with after determining that the target startup data verification has failed.

[0254] The sending module is configured to send target notification messages to a reference server configured to maintain the target server, wherein the reference server is configured to maintain the startup data of the target server based on the target notification messages.

[0255] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0256] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above method embodiments when run.

[0257] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0258] Embodiments of this application also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0259] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0260] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0261] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0262] The embodiments described herein also provide a computer program that includes computer instructions stored in a computer-readable storage medium; a processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps in any of the above method embodiments.

[0263] The examples in this embodiment can be referred to the examples described in the above embodiments and exemplary implementations, and will not be repeated here.

[0264] Obviously, those skilled in the art should understand that the modules or steps of this application described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this application is not limited to any particular combination of hardware and software.

[0265] The above are merely optional embodiments of this application and are not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.

Claims

1. A server starting method, comprising: applying to a basic input / output system, wherein a target server is deployed with the basic input / output system and a trusted platform module, the basic input / output system is connected with the trusted platform module, and the method comprises: receiving a target request sent by a target account to start the target server; in a case where it is determined that the target account has a calling right to the target server, calling target authentication information corresponding to the target account from the trusted platform module, and calling a target authentication file corresponding to the target account from the target server, wherein the target authentication file is obtained by using a target authentication mode indicated by the target authentication information to encrypt and authenticate starting information of the target server, and the starting information is used to indicate starting data used for starting the target server; decrypting and authenticating the target authentication file by using the target authentication mode indicated by the target authentication information to obtain target starting information; performing data verification on target starting data indicated by the target starting information; in a case where the target starting data passes the verification, starting the target server by using the target starting data. 2.The method of claim 1, wherein: the calling of the target authentication information corresponding to the target account from the trusted platform module comprises: obtaining a target business function of the target server requested to be called by the target request; calling the target authentication information configured by the target account for the target business function from the trusted platform module. 3.The method of claim 2, wherein: the calling of the target authentication information configured by the target account for the target business function from the trusted platform module comprises: determining one or more target starting data required to implement the target business function, wherein each target starting data records a starting mode of a corresponding hardware device deployed on the target server; calling the target authentication information corresponding to the target starting data of the target account from the trusted platform module. 4.The method of claim 3, wherein: the calling of the target authentication information corresponding to the target starting data of the target account from the trusted platform module comprises: determining a target storage area corresponding to the target authentication information from authentication information having a corresponding relationship and a storage area in the trusted platform module; sending a target acquisition request to the trusted platform module, wherein the target acquisition request is used to request to acquire authentication information stored in the target storage area; receiving the target authentication information returned by the trusted platform module in response to the target acquisition request. 5.The method of claim 4, wherein: the target server is further deployed with a central processing unit, and the central processing unit is connected with the basic input / output system and the trusted platform module through a serial peripheral interface bus, and the sending of the target acquisition request to the trusted platform module comprises: generating a target instruction in a serial peripheral interface protocol format; sending the target instruction to the central processing unit through the serial peripheral interface bus, wherein the target instruction is used to instruct the central processing unit to send the target acquisition request in the serial peripheral interface protocol format to the trusted platform module.

6. The method of claim 1, wherein: the target authentication file corresponding to the target account is obtained from the target server, comprising: obtaining a target service function of the target server requested by the target request; filtering one or more target authentication files corresponding to the target service function from a plurality of reference authentication files stored in the server, wherein each reference authentication file is obtained by encrypting reference start information for the target account, and the reference start information is used to indicate data content recorded in reference start data used by the target server to start, and each reference start data records a start mode of a corresponding hardware device deployed on the target server.

7. The method of claim 6, wherein: the target server is deployed with a baseboard management controller connected with the basic input / output system, the one or more target authentication files corresponding to the target service function are filtered from a plurality of reference authentication files stored in the server, comprising: filtering a target authentication file corresponding to the target account calling the target service function from an account, a service function and an authentication file having a corresponding relationship; determining a target storage location for storing the target authentication file from a plurality of storage locations of the baseboard management controller, wherein the storage locations in the baseboard management controller and the reference authentication files have a corresponding relationship; extracting the target authentication file from the target storage location.

8. The method of claim 7, wherein: the target storage location for storing the target authentication file is determined from a plurality of storage locations of the baseboard management controller, comprising: obtaining a memory mapping table of the baseboard management controller, wherein the memory mapping table is used to indicate memory space allocation of the baseboard management controller; finding the target storage location for storing the target authentication file in the memory of the baseboard management controller from the memory mapping table.

9. The method of claim 8, wherein: before the memory mapping table of the trusted platform module is obtained, the method further comprises: receiving the reference authentication file sent by a reference server, wherein the reference server is a server configured to maintain a running state of the target server; filtering a reference storage location in an unoccupied state from a memory space of the baseboard management controller; storing the reference authentication file in the reference storage location, and updating a corresponding relationship between the reference storage location and the reference authentication file to the memory mapping table.

10. The method of claim 1, wherein the decrypting and authenticating the target authentication file by using the target authentication manner indicated by the target authentication information to obtain target start information comprises: converting a decryption key corresponding to the target authentication file according to the target authentication information; and decrypting the target authentication file by using the decryption key to obtain the target start information.

11. The method of claim 10, wherein the decrypting the target authentication file by using the decryption key to obtain the target start information comprises: decrypting the target authentication file by using an account public key of the target account to obtain a candidate authentication file, wherein the target authentication file is obtained by encrypting the candidate authentication file by using an account private key corresponding to the account public key of the target account, and the decryption key comprises the account public key; obtaining a server public key of a reference server for the candidate authentication file from the trusted platform module, wherein the reference server is a server configured to maintain a running state of the target server, the reference server is configured to encrypt the target start information by using a server private key corresponding to the server public key, and send the encrypted candidate authentication file to the target account for authentication; and decrypting the candidate authentication file by using the server public key to obtain the target start information.

12. The method of claim 10, wherein the converting the decryption key corresponding to the target authentication file according to the target authentication information comprises one of: in a case where the target authentication information is an account public key of the target account, determining the account public key as the decryption key; and in a case where the target authentication information is information indicating a target encryption manner adopted by the target account for the target authentication file, determining a decryption manner corresponding to the target encryption manner, and generating the decryption key for decrypting the target authentication file according to the decryption manner.

13. The method of claim 7, wherein before the filtering the target authentication file corresponding to the target account calling the target service function from the account, the service function and the authentication file having the corresponding relationship, the method further comprises: detecting a communication state between the baseboard management controller and the basic input output system; and in a case where the communication state is used to indicate that the basic input output system is in an off state, filtering the target authentication file corresponding to the target service function from a plurality of initial authentication files stored in a cache area corresponding to the basic input output system, wherein the plurality of initial authentication files are authentication files used by the basic input output system to start the target server for the target account within a reference time period before a current time.

14. The method of claim 13, wherein ​ ​ ​ ​ ​ ​ ​ ​ ​ After selecting the target authentication file corresponding to the target service function from multiple initial authentication files stored in the buffer corresponding to the basic input / output system, the method further includes: Upon detection of restored communication between the basic input / output system and the baseboard management controller, the plurality of reference authentication files stored in the baseboard management controller are extracted; The initial authentication file is updated using the reference authentication file.

15. The method according to claim 1, characterized in that, The data verification of the target startup data indicated by the target startup information includes: Match the target startup information with the target startup data in the target server; If the target startup information and the target startup data match, it is determined that the target startup data verification has passed; If the target startup information and the target startup data do not match, it is determined that the target startup data verification has failed.

16. The method according to claim 15, characterized in that, The step of matching the target startup information with the target startup data in the target server includes: The target startup data is calculated using an information digest algorithm to obtain a candidate information digest, wherein the candidate information digest is used to indicate the data content carried by the target startup data; The candidate information digest and the target information digest are matched, wherein the target initiation information includes the target information digest; If the target information digest and the candidate information digest are the same, it is determined that the target startup data and the target startup information are a match. If the target information digest and the candidate information digest are different, it is determined that the target startup data and the target startup information do not match.

17. A server startup device, characterized in that, A device applied to a basic input / output system, wherein the basic input / output system and a trusted platform module are deployed on a target server, the basic input / output system is connected to the trusted platform module, and the device includes: The receiving module is configured to receive target requests sent by the target account in order to start the target server; The retrieval module is configured to, when it is determined that the target account has access to the target server, retrieve the target authentication information corresponding to the target account from the trusted platform module and retrieve the target authentication file corresponding to the target account from the target server. The target authentication file is obtained by the target account encrypting and authenticating the startup information of the target server using the target authentication method indicated by the target authentication information. The startup information is used to indicate the startup data used to start the target server. The authentication module is configured to decrypt and authenticate the target authentication file using the target authentication method indicated by the target authentication information to obtain the target startup information; The verification module is configured to perform data verification on the target startup data indicated by the target startup information; The startup module is configured to start the target server using the target startup data if the target startup data verification passes.

18. A non-volatile computer-readable storage medium, characterized in that, The non-volatile computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the method described in any one of claims 1 to 16.

19. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 16.

20. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 16.

Citation Information

Patent Citations

  • BIOS verification method, configuration method, equipment and system

    CN110245495A

  • Safety PXE method based on domestic network platform

    CN110610091A

  • Remote management method and device based on active measurement

    CN110929263A

  • Method and device for trusted measurement of multi-path server and computer equipment

    CN114048484A

  • Server starting method and device, storage medium and electronic equipment

    CN118260774A