CPU attestation method and computing device
By communicating with the BIOS chip and utilizing the BIOS chip's authentication information to perform security verification on the CPU, the high cost caused by deploying additional authentication devices is solved, achieving efficient and reliable CPU security verification.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2026-04-02
AI Technical Summary
In existing technologies, CPU security verification requires the additional deployment of authentication equipment, resulting in higher server costs.
By communicating with the BIOS chip, the manager performs security verification based on the BIOS chip's authentication information and obtains the first authentication information. This information is then used to perform security verification on the CPU, avoiding the need to deploy additional authentication devices.
It improves the accuracy and reliability of CPU security verification and reduces the cost of computing devices.
Smart Images

Figure CN2025087142_02042026_PF_FP_ABST
Abstract
Description
Security verification method of CPU and computing device
[0001] The present application claims priority to the Chinese patent application No. 202411380092.0, filed on September 29, 2024, and entitled "Security verification method of CPU and computing device", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] Embodiments of the present application relate to the technical field of computing devices, and in particular to a security verification method of CPU and a computing device. BACKGROUND
[0003] With the development of technology, servers are widely used, and users' requirements for server security are also increasing. At present, one of the security services provided by the server is the security verification (CPU attestation) of the central processing unit (CPU), which is used to verify the integrity of the CPU and the CPU firmware.
[0004] In related technologies, the security verification of the CPU is usually performed by setting an authentication device, such as a complex programmable logic device (CPLD), in the server to verify the security of the CPU. However, this method requires additional deployment of authentication devices, resulting in high cost of the server. SUMMARY
[0005] Embodiments of the present application provide a security verification method of CPU and a computing device, which does not require additional deployment of authentication devices, thereby reducing the cost of the computing device.
[0006] In a first aspect, the embodiments of the present application provide a security verification method of CPU. The method is applied to a manager of a computing device, and the computing device includes a manager, a BIOS chip, and a central processing unit (CPU). The manager is in communication connection with the BIOS chip and the CPU, respectively. The method includes:
[0007] Based on the authentication information of the BIOS chip, the security of the BIOS chip is verified;
[0008] After the security verification of the BIOS chip is passed, first authentication information is obtained from the BIOS chip, wherein the first authentication information represents the authentication information of the CPU;
[0009] Based on the first authentication information, the security of the CPU is verified.
[0010] The beneficial effects of the embodiment are as follows: the manager can obtain the first authentication information from the BIOS chip after performing security verification on the BIOS chip based on the preset authentication information of the BIOS chip, and perform security verification on the CPU based on the first authentication information. In this way, the security verification on the BIOS chip can guarantee the integrity and reliability of the first authentication information used for security verification on the CPU, and guarantee that the first authentication information is not tampered with, so as to improve the accuracy of subsequent security verification on the CPU. At the same time, in this way, the reliable first authentication information is stored in the manager, and the security verification on the CPU is realized by using the manager, without the need to deploy additional authentication devices in the computing device, thereby saving the cost of the computing device.
[0011] In a possible implementation, the first authentication information includes a root certificate of the CPU and a history hash value of firmware required by the CPU; and obtaining the first authentication information from the BIOS chip includes:
[0012] obtaining the root certificate of the CPU and the history hash value of the firmware required by the CPU from the BIOS chip; or
[0013] obtaining the root certificate of the CPU from the BIOS chip, and obtaining the history hash value of the firmware required by the CPU from the memory of the manager.
[0014] The beneficial effects of the embodiment are as follows: in this way, the first authentication information can be flexibly updated.
[0015] In a possible implementation, performing security verification on the BIOS chip based on the authentication information of the BIOS chip includes:
[0016] performing security verification on the manager based on second authentication information; wherein the second authentication information represents authentication information of the manager;
[0017] performing security verification on the BIOS chip based on the authentication information of the BIOS chip after the security verification on the manager is passed.
[0018] The beneficial effects of the embodiment are as follows: in this way, the reliability of the firmware included in the manager can be guaranteed, and then the reliability of the authentication information stored in the manager can be guaranteed, and the accuracy of subsequent security verification on the BIOS chip and the CPU can be guaranteed.
[0019] In a possible implementation, before performing security verification on the CPU based on the first authentication information, the method further includes:
[0020] assigning the access right of the BIOS chip to the CPU.
[0021] The beneficial effect of the embodiment is that the manager can control the access right of the BIOS chip, and guarantee the security of the BIOS chip.
[0022] In a possible implementation, the method further includes:
[0023] After the security check of the CPU is passed, a start instruction is sent to the CPU, wherein the start instruction is used to instruct the CPU to acquire the required firmware of the CPU from the BIOS chip, and start the CPU based on the required firmware of the CPU.
[0024] The beneficial effect of the embodiment is that the manager can control the start of the CPU by using the start instruction after the security check of the CPU is passed, and guarantee the reliability of the CPU.
[0025] In a second aspect, the embodiment of the present application provides a security check method of a CPU, which is applied to a manager of a computing device, the computing device including the manager and a central processing unit (CPU), and the manager is in communication connection with the CPU; the manager includes first authentication information and second authentication information; the first authentication information represents the authentication information of the CPU, and the second authentication information represents the authentication information of the manager; and the method includes:
[0026] In the start process of the CPU, the security of the manager is checked based on the second authentication information; and after it is determined that the security check of the manager is passed, the security of the CPU is checked based on the first authentication information.
[0027] The beneficial effect of the embodiment is that the authentication information is stored in the manager, in the start process of the CPU, the security of the manager is checked based on the stored second authentication information, so as to guarantee the integrity and reliability of the manager and the firmware included in the manager, and after the security check of the manager is passed, the security of the CPU is checked based on the stored first authentication information, so as to guarantee the integrity and reliability of the firmware included in the CPU. In this way, no authentication device needs to be additionally deployed in the computing device, and the security check of the CPU can be realized by using the existing manager, and the cost of the computing device is reduced.
[0028] In a possible implementation, the manager includes a security core and a business core, the first authentication information and the second authentication information are included in the security core; and the security of the manager is checked based on the second authentication information, including:
[0029] The security core of the manager checks the security of the security core based on the second authentication information.
[0030] After determining that the security check of the manager is passed, the security core of the manager performs a security check on the business core based on the second authentication information.
[0031] The security check on the CPU based on the first authentication information after determining that the security check of the manager is passed comprises:
[0032] After determining that the security check of the business core is passed, the security core of the manager performs a security check on the CPU based on the first authentication information.
[0033] The beneficial effects of the embodiment are that the manager is divided into the security core and the business core, the first authentication information and the second authentication information are stored by the security core, the security and reliability of the authentication information are improved, and then the security core performs the security check on the manager and the CPU based on the authentication information, and the reliability of the security check on the manager and the CPU is improved.
[0034] In a possible implementation, the first authentication information is included in the security core; the first authentication information comprises a root certificate of the CPU and a historical hash value of firmware required by the CPU; and the security check on the CPU by the security core of the manager based on the first authentication information comprises:
[0035] The security core of the manager acquires a certificate chain of the CPU;
[0036] The security core of the manager verifies the certificate chain of the CPU based on the root certificate of the CPU;
[0037] After the certificate chain of the CPU is verified, the security core of the manager acquires a current hash value of the firmware required by the CPU;
[0038] The security core of the manager performs a security check on the CPU based on the historical hash value of the firmware required by the CPU and the current hash value of the firmware required by the CPU.
[0039] The beneficial effects of the embodiment are that the first authentication information is stored by the security core, the security and reliability of the authentication information are improved, and then the security core performs the security check on the CPU based on the first authentication information, and the reliability of the security check on the CPU is improved.
[0040] In a possible implementation, the computing device further comprises a BIOS chip and a multiplexer, an output end of the multiplexer is connected to the BIOS chip, and an input end of the multiplexer is connected to the security core of the manager and the CPU; the security core further comprises authentication information of the BIOS chip; and the method further comprises:
[0041] The security core of the manager performs security check on the BIOS chip based on the authentication information of the BIOS chip.
[0042] After determining that the security check on the BIOS chip is passed, the security core of the manager controls the multiplexer to turn on the channel between the CPU and the BIOS chip.
[0043] The BIOS chip is stored in the security core, and the security of the authentication information is improved. The security core performs security check on the BIOS chip based on the authentication information of the BIOS chip, and the reliability of the security check on the BIOS chip is improved. After the security check on the BIOS chip is passed, the channel between the CPU and the BIOS chip is turned on, and the security of the CPU is improved.
[0044] In a third aspect, the embodiments of the present application further provide a computing device, a manager, a central processing unit (CPU) and a memory, the manager is in communication connection with the CPU, and the manager is in communication connection with the memory;
[0045] The memory stores computer execution instructions;
[0046] The manager executes the computer execution instructions stored in the memory, so as to implement the security check method of the CPU according to the first aspect, or the security check method of the CPU according to any one of the second aspect.
[0047] The manager of the computing device can execute the computer execution instructions, so that the manager can obtain the first authentication information from the BIOS chip after performing security check on the BIOS chip based on the preset authentication information of the BIOS chip, and perform security check on the CPU based on the first authentication information. In this way, the integrity and reliability of the first authentication information used for security check on the CPU can be guaranteed based on the security check on the BIOS chip, and the first authentication information is not tampered with, so as to improve the accuracy of the subsequent security check on the CPU. At the same time, the reliable first authentication information is stored in the manager, and the security check on the CPU is realized by using the manager, without the need to deploy additional authentication devices in the computing device, thereby saving the cost of the computing device.
[0048] Alternatively, by storing the authentication information in the manager, in the startup process of the CPU, the manager can perform security verification on the manager based on the stored second authentication information, to guarantee the integrity and reliability of the manager and firmware included in the manager, and perform security verification on the CPU based on the stored first authentication information after the security verification of the manager passes, to guarantee the integrity and reliability of the firmware included in the CPU. In this way, no additional authentication device needs to be deployed in the computing device, and the security verification on the CPU can be implemented by using the existing manager, thereby reducing the cost of the computing device.
[0049] In a fourth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a manager, implements the security verification method of the CPU according to the first aspect, or the security verification method of the CPU according to any one of the second aspect.
[0050] Advantages of the embodiment: The manager of the computing device can execute the computer program, so that the manager can perform security verification on the BIOS chip based on the preset authentication information of the BIOS chip, obtain the first authentication information from the BIOS chip after the security verification on the BIOS chip, and perform security verification on the CPU based on the first authentication information. In this way, the security verification on the BIOS chip can guarantee the integrity and reliability of the first authentication information used for security verification on the CPU, and guarantee that the first authentication information is not tampered with, so as to improve the accuracy of the subsequent security verification on the CPU. At the same time, in this way, the reliable first authentication information is stored in the manager, and the security verification on the CPU is implemented by using the manager, without the need to deploy an additional authentication device in the computing device, thereby saving the cost of the computing device.
[0051] Alternatively, by storing the authentication information in the manager, in the startup process of the CPU, the manager can perform security verification on the manager based on the stored second authentication information, to guarantee the integrity and reliability of the manager and firmware included in the manager, and perform security verification on the CPU based on the stored first authentication information after the security verification of the manager passes, to guarantee the integrity and reliability of the firmware included in the CPU. In this way, no additional authentication device needs to be deployed in the computing device, and the security verification on the CPU can be implemented by using the existing manager, thereby reducing the cost of the computing device. BRIEF DESCRIPTION OF DRAWINGS
[0052] FIG. 1 is a structural schematic diagram of a computing device according to an embodiment of the present application;
[0053] FIG. 2 is a structural schematic diagram of another computing device according to an embodiment of the present application;
[0054] FIG. 3 is a flowchart of a security verification method of a CPU according to an embodiment of the present application;
[0055] Figure 4 is a flow diagram of a CPU security verification method according to an embodiment of the present application;
[0056] Figure 5 is a flow diagram of another CPU security verification method according to an embodiment of the present application;
[0057] Figure 6 is a flow diagram of another CPU security verification method according to an embodiment of the present application;
[0058] Figure 7 is a structural diagram of a CPU security verification device according to an embodiment of the present application;
[0059] Figure 8 is a structural diagram of another CPU security verification device according to an embodiment of the present application. DETAILED DESCRIPTION
[0060] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme of the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments made by those of ordinary skill in the art according to the inspiration of the embodiments of the present application belong to the scope of protection of the present application.
[0061] The terms "first", "second", "third", "fourth" and the like (if any) in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0062] First, the terms related to the embodiments of the present application are explained:
[0063] System trusted root: used to represent a root public key set.
[0064] Root certificate: a top-level certificate issued by a trusted certificate authority (CA), each root certificate contains the public key of a CA and related information, which constitutes the starting point of the public key infrastructure (PKI) trust chain and can be used to verify the authenticity of other certificates.
[0065] Certificate chain: a sequence composed of multiple certificates, forming a trust path from the root certificate to the device-specific components (such as firmware, operating system).
[0066] BIOS production package: a set of tools used to create and configure computing device system firmware, usually including binary files of BIOS firmware, configuration files, update tools and documents. Its main purpose is to help manufacturers customize and deploy BIOS during the production process to support specific hardware platforms and functions.
[0067] The embodiments of the present application propose a CPU security verification method, based on the device already deployed in the computing device as the manager of CPU security verification, to verify the integrity of the CPU and the firmware included in the CPU, thereby reducing the development cost of the computing device.
[0068] FIG. 1 is a structural schematic diagram of a computing device provided by the embodiments of the present application. As shown in FIG. 1, the computing device 100 includes a CPU 101 and a manager 102, and the CPU 101 and the manager 102 are in communication connection. The communication connection between the CPU 101 and the manager 102 can be achieved through an internal interface or a bus, and the communication connection mode of the embodiments of the present application is not limited, for example, it can be an improved integrated circuit bus (Improved Inter Integrated Circuit, I3C).
[0069] The manager 102 stores authentication information used to verify the integrity of the hardware devices and the firmware included in the hardware devices to which the computing device is attached. The authentication information can include, for example, system root of trust, key information, and feature information of the devices. The system root of trust can include public key certificates of various hardware, such as a public key certificate of the manager, a public key certificate of the CPU, a public key certificate of the BIOS chip, and the like. The manager can be a management module deployed in the computing device, such as a baseboard management controller (BMC) in the computing device, a monitoring management device in the computing device, a system management module (SMM) in the computing device, or the like. The specific form of the manager is not limited in the embodiments of the present application, and the above is only an exemplary description. In the following embodiments, the manager is taken as an example of the BMC.
[0070] It should be noted that the BMC can have different names in different computing devices. For example, it is referred to as iLO or iDRAC in some computing devices. The BMC, iLO, or iDRAC can all be understood as the BMC in the embodiments of the present application.
[0071] The CPU 101 is configured to perform computing tasks and control tasks in the computing device. It should be noted that the type and number of the CPU are not limited in the embodiments of the present application.
[0072] In some embodiments, the computing device 100 can further include a basic input output system (BIOS) chip 103, which is in communication connection with the CPU 101 and the manager 102. The BIOS chip can be, for example, a flash memory or an electrically erasable programmable read only memory (EEPROM), and the like, which stores the BIOS.
[0073] In some embodiments, the CPU 101 and the manager 102 are connected to the BIOS chip 103 based on a multiplexer 104, where the CPU 101 and the manager 102 are inputs of the multiplexer 104, and the BIOS chip 103 is an output of the multiplexer 104. The manager 102 can generate a control signal to control the multiplexer 104 to select a conducting channel. The form of the control signal is not limited in the embodiments of the present application. For example, a high level can represent a channel conducting between the CPU 101 and the BIOS chip 103, and a low level can represent a channel conducting between the manager 102 and the BIOS chip 103.
[0074] It should be noted that the embodiments of the present application do not limit the specific type of the computing device. The computing device can be any device containing similar structures as in FIG. 1. The computing device can include more or fewer components than shown, or combine certain components, or split certain components, or different arrangement of components. The components shown can be implemented in hardware, software, or a combination of software and hardware. For example, the computing device can be a server, a server cluster, a laptop computer, a desktop computer, a tablet computer, a mobile phone, an artificial intelligence device, etc.
[0075] FIG. 2 is a structural schematic diagram of another computing device provided by the embodiments of the present application. The computing device 200 shown in FIG. 2 includes a CPU 201 and a manager 202, and the manager 202 includes a security core 203 and a business core 204.
[0076] It can be understood that the manager 202 includes a CPU with multiple processing cores, and thus the manager can be structurally divided based on the number of processing cores to obtain the security core 203 and the business core 204.
[0077] The security core 203 is configured to process security-related functions and tasks in the manager. For example, the security core can perform security-related functions such as secure boot, encryption and decryption functions, identity verification and access control, etc. when the manager is a BMC.
[0078] The business core 204 is configured to process general management functions and business logic in the manager. For example, the business core can perform functions such as system monitoring, hardware state detection, fault detection and alarm, etc. when the manager is a BMC.
[0079] It should be noted that the embodiments of the present application do not limit how to divide the security core and the business core of the manager, and the embodiments of the present application do not limit the communication mode between the security core and the business core, which is related to the settings of the manager.
[0080] Referring to FIG. 2, the manager 202 can further include a memory 205 for storing firmware and data included in the manager. The memory 205 can be a non-volatile memory, for example, can be a flash memory, a One-Time Programmable (OTP) memory, an Electrically Erasable Programmable read only memory (EEPROM), or an embedded MultiMedia Card (EMMC), etc. The security core 203 and the business core 204 can share the memory 205.
[0081] In some embodiments, the computing device 202 can further include a BIOS chip 206 and a multiplexer 207. The CPU 201 and the security core 203 connect the BIOS chip 206 based on the multiplexer 207, where the CPU 201 and the security core 203 are inputs of the multiplexer 207, and the BIOS chip 206 is an output of the multiplexer 207. The security core 203 can generate a control signal to control the multiplexer 207 to select a conducting channel.
[0082] In the following, the technical solutions of the embodiments of the present application are described in detail through specific embodiments. It should be noted that the following several specific embodiments can be combined with each other, and the same or similar concepts or processes will not be described in detail in some embodiments.
[0083] Referring to FIG. 3, FIG. 3 is a flowchart of a security verification method of a CPU provided by an embodiment of the present application, where the channel between the manager and the BIOS chip in the embodiment has been conducted, in other words, the manager can communicate with the BIOS chip. Referring to FIG. 1 and FIG. 3, the method includes:
[0084] S301, the manager performs security verification on the BIOS chip based on authentication information of the BIOS chip.
[0085] For example, the authentication information of the BIOS chip can include a public key certificate of the BIOS chip and a digital signature of the BIOS chip, which are used to verify the integrity of the firmware included in the BIOS chip, where the firmware included in the BIOS chip can be used to initialize and test hardware components (such as CPU, memory, hard disk, etc.), provide basic input and output functions when the computing device is started, and guide the loading of the operating system. Therefore, it is necessary to verify the integrity of the firmware included in the BIOS chip.
[0086] The security check is used for verifying the reliability of the hardware identity, and / or verifying the integrity and reliability of the firmware included in the hardware, for example, whether the firmware included in the BIOS chip is complete or is changed.
[0087] In some possible implementation, in the production equipment stage or the maintenance update stage of the computing device, the user can store the authentication information of the BIOS chip into the manager, and burn the production package of the BIOS including the first authentication information into the BIOS chip, wherein the first authentication information represents the authentication information of the CPU, and the first authentication information can include the root certificate of the CPU and the history hash value of the required firmware of the CPU, which is used for security check of the CPU, and the authentication information of the BIOS chip has a corresponding relationship with the production package of the BIOS. In this way, the update of the first authentication information can be realized.
[0088] In some possible implementation, the authentication information of the BIOS chip can include the public key certificate of the BIOS chip and the digital signature of the BIOS chip; the digital signature of the BIOS chip includes the private key certificate of the BIOS chip and the history hash value of the BIOS chip; the history hash value of the BIOS chip represents the history hash value of the firmware included in the BIOS chip; and the history hash value can be generated when the BIOS chip is in the production equipment stage. The digital signature of the BIOS chip can be obtained by encrypting the history hash value of the BIOS chip based on the private key certificate of the BIOS chip, and is stored in the manager.
[0089] In this implementation, the manager can give the access right of the BIOS chip to the manager, in other words, the manager can control the multiplexer to turn on the channel between the manager and the BIOS chip, and obtain the current hash value of the BIOS chip, wherein the current hash value of the BIOS chip represents the current hash value of the firmware included in the BIOS chip, and the current hash value of the BIOS chip can be generated by the BIOS chip based on the currently included firmware and the hash algorithm. As mentioned above, the system trusted root is stored in the manager, and the public key certificate of each hardware is included in the system trusted root, in other words, the public key certificate of the BIOS chip is included, and further, the manager can decrypt the digital signature of the BIOS chip based on the public key certificate of the BIOS chip, and obtain the history hash value of the BIOS chip after decryption; if it is determined that the history hash value of the BIOS chip is consistent with the current hash value of the BIOS chip, it means that the security check of the BIOS chip is passed, and if it is determined that the history hash value of the BIOS chip is not consistent with the current hash value of the BIOS chip, it means that the firmware included in the BIOS chip is incomplete or is changed, which means that the security check of the BIOS chip fails.
[0090] S302、the manager obtains the first authentication information from the BIOS chip after the security check of the BIOS chip is passed.
[0091] Exemplarily, the firmware included in the BIOS chip can include first authentication information, which represents authentication information of the CPU and can be used for security verification of the CPU. For example, the reliability of the CPU identity can be verified, and the integrity and reliability of the firmware required by the CPU can be verified. It should be understood that the firmware required by the CPU represents the firmware related to the CPU included in the BIOS chip.
[0092] In some possible implementation manners, as mentioned before, the production package including the first authentication information is pre-burned in the BIOS chip, so that after the security verification of the BIOS chip by the manager is passed, the first authentication information can be acquired from the BIOS chip based on the channel between the manager and the BIOS chip of the multiplexer and stored in a preset storage location in the manager. The preset storage location can be a hardware security module (HSM) in the manager, or a non-volatile memory, and the non-volatile memory has access permission limitation to prevent the authentication information from being tampered, for example, can be an OTP memory or an EMMC; in other words, the authentication information stored in the OTP memory cannot be erased or modified again to ensure the reliability of the authentication information.
[0093] Taking an example that the first authentication information can include the root certificate of the CPU and the historical hash value of the firmware required by the CPU, in this implementation manner, the manager can acquire the root certificate of the CPU and the historical hash value of the firmware required by the CPU from the BIOS chip.
[0094] In some possible implementation manners, the digital signature of the CPU in the first authentication information can be pre-burned in the BIOS chip, and the root certificate of the CPU is stored in the manager, the manager can acquire the root certificate of the CPU from the BIOS chip and read the historical hash value of the firmware required by the CPU from the memory of the manager; in other words, the manager can acquire the first authentication information including the root certificate of the CPU and the historical hash value of the firmware required by the CPU and store the first authentication information. In this way, the first authentication information can be flexibly updated.
[0095] Optionally, the first authentication information can further include a public key certificate of the CPU. As mentioned above, the manager stores a system trusted root, which includes public key certificates of various hardware, in other words, a public key certificate of the CPU. It should be noted that the historical hash value of the firmware required by the CPU is in the form of a digital signature of the CPU to prevent tampering, and the digital signature of the CPU is obtained by encrypting the historical hash value of the firmware required by the CPU using a private key certificate of the CPU. Therefore, when performing security verification on the CPU, the manager can decrypt the digital signature of the CPU based on the public key certificate of the CPU to obtain the historical hash value of the firmware required by the CPU.
[0096] In some embodiments, before performing security verification on the BIOS chip, the manager can also perform security verification on itself. For example, the manager can perform security verification on the manager based on preset second authentication information, and perform security verification on the BIOS chip based on the authentication information of the BIOS chip after the security verification on the manager is passed. The second authentication information represents authentication information of the manager, which can include, for example, a public key certificate of the manager and a digital signature of the manager. The digital signature of the manager includes a private key certificate of the manager and a historical hash value of the manager. The historical hash value of the manager represents a historical hash value of the firmware included in the manager, which can be generated when the manager is in a production equipment stage. The digital signature of the manager can be obtained by encrypting the historical hash value of the manager based on the private key certificate of the manager and stored in the manager.
[0097] Specifically, as mentioned above, the manager stores a system trusted root, which includes public key certificates of various hardware, in other words, a public key certificate of the manager. Further, the manager can decrypt the digital signature of the manager based on the public key certificate of the manager to obtain the historical hash value of the manager. If it is determined that the historical hash value of the manager is consistent with the current hash value of the manager, it means that the security verification on the manager is passed. If it is determined that the historical hash value of the manager is inconsistent with the current hash value of the manager, it means that the firmware included in the manager is incomplete or has been changed, which means that the security verification on the manager fails. In this way, the reliability of the firmware included in the manager can be ensured, and the reliability of the authentication information stored in the manager can be ensured, and the accuracy of subsequent security verification on the BIOS chip and the CPU can be ensured.
[0098] S303, the manager performs security verification on the CPU based on the first authentication information.
[0099] In some possible implementation manners, the first authentication information includes a root certificate of the CPU and a history hash value of the firmware required by the CPU, and thus the manager can perform security verification on the CPU based on the root certificate of the CPU and the history hash value of the firmware required by the CPU. For example, the manager can verify a certificate chain of the CPU based on the root certificate of the CPU, and after verification, determine whether the hash value is consistent according to the history hash value of the firmware required by the CPU and a current hash value of the firmware required by the CPU, to determine whether the firmware required by the CPU is updated or tampered, and implement security verification on the CPU.
[0100] It should be understood that if the CPU is replaced or the firmware required by the CPU is tampered, the history hash value of the firmware required by the CPU in the first authentication information is different from the current hash value of the actual firmware required by the CPU, and the security verification of the CPU fails, and thus the integrity and reliability of the CPU can be ensured by this method.
[0101] In some embodiments, before performing security verification on the CPU, the manager gives the access permission of the BIOS chip to the CPU, in other words, the manager can control the multiplexer to turn on the channel between the CPU and the BIOS chip, and thus the CPU can obtain the current hash value of the firmware required by the CPU from the BIOS chip. In this way, the manager can control the access permission of the BIOS chip, and ensure the security of the BIOS chip.
[0102] In some embodiments, after the security verification of the CPU passes, a start instruction is sent to the CPU, where the start instruction is used to instruct the CPU to obtain the firmware required by the CPU from the BIOS chip and start the CPU based on the firmware required by the CPU. In this way, the manager can control the CPU to start by using the start instruction after the security verification of the CPU passes, and ensure the reliability of the CPU.
[0103] It should be noted that the public key certificate of the hardware included in the authentication information in the embodiments of the present application, for example, the public key certificate of the CPU, the public key certificate of the manager, or the public key certificate of the BIOS chip, can be stored in the manager in the form of a system trusted root, which can be stored in the manager in the production equipment stage or the maintenance update stage of the computing device. The public key certificate of each hardware can be read from the system trusted root when used, and the public key certificates of other hardware are similar, and will not be described in detail.
[0104] In this embodiment, the manager can obtain the first authentication information from the BIOS chip after performing security verification on the BIOS chip based on the preset authentication information of the BIOS chip, and perform security verification on the CPU based on the first authentication information. In this way, the security verification on the BIOS chip can guarantee the integrity and reliability of the first authentication information used for security verification on the CPU, and guarantee that the first authentication information is not tampered with, so as to improve the accuracy of subsequent security verification on the CPU. At the same time, in this way, the reliable first authentication information is stored in the manager, and the security verification on the CPU is realized by using the manager, without the need to deploy additional authentication devices in the computing device, thereby saving the cost of the computing device.
[0105] FIG. 4 is a flowchart of a security verification method of a CPU provided in an embodiment of the present application. Referring to FIGS. 1 and 4, in this embodiment, the multiplexer channel between the CPU and the BIOS chip is already connected, in other words, the CPU can communicate with the BIOS chip, and the method can include the following steps:
[0106] S401, in the CPU startup process, the manager performs security verification on the manager based on the second authentication information.
[0107] Exemplarily, the manager can include the first authentication information and the second authentication information, wherein the first authentication information represents the authentication information of the CPU, in other words, the first authentication information can be used to verify the integrity of the CPU and the firmware required by the CPU. Similarly, the second authentication information represents the authentication information of the manager, in other words, the second authentication information can be used to verify the integrity of the firmware included in the manager.
[0108] As mentioned above, the manager can obtain the first authentication information and store it in the preset storage location of the manager in the manner of the foregoing embodiments. The second authentication information can be stored in the preset storage location during the production and equipment stage of the manager or the computing device; or the second authentication information can be stored in the preset storage location during the maintenance or update stage of the manager, for example, when the firmware included in the manager is updated. The preset storage location can be a hardware security module (HSM) in the manager, or a non-volatile memory, and the non-volatile memory has access permission restriction to prevent the authentication information from being tampered with. The non-volatile memory can be an OTP memory, in other words, the authentication information stored in the OTP memory cannot be erased or modified again, so as to guarantee the reliability of the authentication information.
[0109] Exemplarily, the second authentication information can include a public key certificate of the manager and a digital signature of the manager, wherein the digital signature of the manager includes a private key certificate and a history hash value of the firmware included in the manager. It can be understood that the manager can determine the history hash value based on the firmware included in the manager in the production equipment stage, and encrypt the history hash value by using the private key certificate to obtain the digital signature of the manager. Therefore, the manager can perform security verification on the manager based on the pre-stored public key certificate of the manager and the digital signature of the manager in the system trusted root. For example, the manager can verify the private key certificate in the digital signature based on the public key certificate, if the verification is successful, the manager can obtain the history hash value of the firmware included in the manager, and then can determine whether the firmware included in the manager is updated or tampered based on the history hash value in the digital signature of the manager after obtaining the current hash value of the firmware included in the manager, to realize security verification on the manager.
[0110] It should be understood that if the manager is replaced or the firmware included in the manager is tampered, the history hash value of the firmware included in the manager in the second authentication information is different from the current hash value of the actual firmware included in the manager, and the security verification of the manager fails, therefore, the integrity and reliability of the manager can be guaranteed by this way.
[0111] Through this step, the manager can guarantee the integrity and reliability of the manager itself, so as to perform security verification on the CPU.
[0112] S402, after the manager determines that the security verification of the manager passes, performing security verification on the CPU based on the first authentication information.
[0113] As mentioned above, the first authentication information is included in the manager, and the first authentication information can be used to verify the integrity of the CPU and the firmware required by the CPU, therefore, the manager can perform security verification on the CPU based on the first authentication information.
[0114] Exemplarily, the first authentication information can include a public key certificate of the CPU, a root certificate of the CPU and a digital signature of the CPU, wherein the digital signature of the CPU includes a private key certificate and a history hash value of the firmware required by the CPU and the firmware. It can be understood that in the production equipment stage, the CPU can determine the history hash value based on the firmware required by the CPU included in the BIOS chip, and process the hash value by using the private key certificate to obtain the digital signature of the CPU. Therefore, the manager can first verify the certificate chain of the CPU based on the root certificate of the CPU, and after the verification is passed, the manager can perform security verification on the CPU based on the pre-stored public key certificate of the CPU in the system trusted root and the digital signature of the CPU. For example, the manager can verify the private key certificate in the digital signature based on the public key certificate, and if the verification is successful, the manager can obtain the history hash value of the firmware required by the CPU, and then can obtain the current hash value of the firmware required by the CPU from the BIOS chip based on the CPU, and determine whether the firmware required by the CPU is updated or tampered based on the history hash value in the digital signature of the CPU, to realize the security verification of the CPU.
[0115] It should be understood that if the CPU is replaced or the firmware required by the CPU is tampered, the history hash value of the firmware required by the CPU in the first authentication information is different from the current hash value of the actual firmware required by the CPU, and the security verification of the CPU cannot pass, so the integrity and reliability of the CPU can be guaranteed in this way.
[0116] Optionally, after the manager determines that the security verification of the CPU is passed, the manager can send a start instruction to the CPU, the start instruction being used to instruct the CPU to start, and the CPU can obtain the firmware required by the CPU from the BIOS chip based on the start instruction to start the CPU.
[0117] In this embodiment, by storing the authentication information in the manager, in the starting process of the CPU, the manager can perform security verification on the manager based on the stored second authentication information to guarantee the integrity and reliability of the manager and the firmware included in the manager, and perform security verification on the CPU based on the stored first authentication information after the security verification of the manager is passed, to guarantee the integrity and reliability of the firmware included in the CPU. In this way, no authentication device needs to be additionally deployed in the computing device, and the security verification of the CPU can be realized by using the existing manager, thereby reducing the cost of the computing device.
[0118] FIG. 5 is a flow diagram of another method for verifying security of a CPU according to an embodiment of the present application. In this embodiment, the second authentication information includes a public key certificate of the manager and a digital signature of the manager, the digital signature of the manager includes a historical hash value of the manager, and the digital signature of the manager is obtained by encrypting the historical hash value of the manager based on a private key certificate of the manager. The historical hash value of the manager is used to represent a historical hash value of firmware included in the manager, which may, for example, be a hash value determined when the manager is produced.
[0119] The first authentication information includes a public key certificate of the CPU, a root certificate of the CPU, and a digital signature of the CPU. The digital signature of the CPU includes a historical hash value of firmware required by the CPU, and the digital signature of the CPU is obtained by encrypting the historical hash value of the firmware required by the CPU based on a private key certificate of the CPU. The historical hash value of the firmware required by the CPU may, for example, be a hash value determined when the CPU is produced. Referring to FIGS. 1 and 5, in this embodiment, the multiplexer channel between the CPU and the BIOS chip is turned on, in other words, the CPU can communicate with the BIOS chip. The method can include the following steps:
[0120] S501. During the startup process of the CPU, the manager verifies the digital signature of the manager based on the public key certificate of the manager, and determines the historical hash value of the manager.
[0121] For example, the manager can decrypt the digital signature of the manager based on the public key certificate of the manager included in the system trusted root, and determine the historical hash value of the manager included in the decrypted digital signature of the manager.
[0122] It should be noted that the present embodiment does not limit the decryption method, which is related to the encryption algorithm used by the manager.
[0123] S502. The manager obtains a current hash value of the manager.
[0124] For example, the current hash value of the manager represents a current hash value of firmware included in the manager. The manager can generate the current hash value of the manager based on the firmware currently included in the manager and a hash algorithm. It should be noted that the present embodiment does not limit the hash algorithm for generating the hash value, which is consistent with the hash algorithm for generating the historical hash value of the manager. The hash algorithm may, for example, be a 256-bit secure hash algorithm (SHA-256) or a cyclic redundancy check (CRC) algorithm.
[0125] It should be noted that the embodiments of the present application do not limit the execution order of steps S501 and S502, for example, the execution order can be sequential execution or parallel execution, and the embodiments are only used as an example to illustrate the sequential execution.
[0126] S503, the manager performs security verification on the manager based on the historical hash value of the manager and the current hash value of the manager.
[0127] For example, the manager can determine whether the historical hash value of the manager and the current hash value of the manager are consistent to implement the security verification on the manager. If the manager determines that the historical hash value of the manager and the current hash value of the manager are consistent, it indicates that the firmware included in the manager is not replaced or tampered, and the security verification on the manager is passed, and step S504 is performed. If the manager determines that the historical hash value of the manager and the current hash value of the manager are inconsistent, it indicates that the firmware included in the manager may be replaced or tampered, and the security verification on the manager is not passed.
[0128] Optionally, if the security verification on the manager is not passed, the manager can return prompt information to the client of the computing device to prompt the user that the computing device has a fault. It should be noted that the embodiments of the present application do not limit the content of the prompt information.
[0129] S504, after determining that the security verification on the manager is passed, the manager obtains the certificate chain of the CPU.
[0130] For example, the certificate chain of the CPU can be used to represent the legitimacy of the identity of the CPU, in other words, the certificate chain of the CPU can be used to determine whether the CPU in the computing device is legitimate. The manager can send a certificate chain request instruction to the CPU, and the CPU returns the certificate chain of the CPU to the manager after receiving the certificate chain request instruction.
[0131] In one possible implementation, as mentioned above, with reference to FIG. 1, the manager and the CPU can be connected in communication through the I3C bus, therefore, the manager and the CPU can use the Management Component Transport Protocol (MCTP) based on the I3C bus to transmit the security data and commands defined by the Security Protocol and Data Model. In this implementation, the manager can be installed with a preset application, which can be used to implement the transmission of the security data and commands between the manager and the CPU, for example, the preset application can be libspdm software.
[0132] S505, the manager verifies the certificate chain of the CPU based on the root certificate of the CPU.
[0133] For example, the manager can verify the certificate chain of the CPU based on the root certificate of the CPU, for example, the manager can verify the first certificate included in the certificate chain of the CPU based on the root certificate of the CPU, if the verification is passed, the certificates included in the certificate chain of the CPU are verified level by level using the public key certificate included in the first certificate, until all the certificates included in the certificate chain of the CPU are verified, it is determined that the verification of the certificate chain of the CPU is passed. Through this step, the manager can determine the legitimacy of the CPU identity to prevent the CPU from being replaced.
[0134] S506, the manager verifies the digital signature of the CPU based on the public key certificate of the CPU after the certificate chain of the CPU is verified, and determines the historical hash value of the firmware required by the CPU.
[0135] After the manager determines that the certificate chain of the CPU is verified, the digital signature of the CPU is verified based on the public key certificate of the CPU, and the historical hash value of the firmware required by the CPU is determined. For example, the manager can decrypt the digital signature of the CPU based on the public key certificate of the CPU included in the system trusted root, and after decryption, the historical hash value of the firmware required by the CPU included in the digital signature of the CPU can be determined.
[0136] It should be noted that the decryption method of the embodiments of the present application is not limited, which is related to the encryption algorithm used by the CPU.
[0137] S507, the manager acquires the current hash value of the firmware required by the CPU.
[0138] For example, the CPU can generate the current hash value of the firmware required by the CPU based on the firmware required by the CPU stored in the current BIOS chip and the hash algorithm, and send it to the manager. It should be noted that the hash algorithm for generating the hash value is not limited by the embodiments of the present application, which is consistent with the hash algorithm for generating the historical hash value of the firmware required by the CPU, for example, it can be a 256-bit secure hash algorithm (Secure Hash Algorithm 256-bit, SHA-256) or a cyclic redundancy check (Cyclic Redundancy Check, CRC) algorithm.
[0139] In one possible implementation, the manager can send a hash value acquisition instruction to the CPU based on a preset application, and the CPU returns the current hash value of the firmware required by the CPU in response to the hash value acquisition instruction.
[0140] It should be noted that the embodiments of the present application do not limit the execution order of "verifying the digital signature of the CPU based on the public key certificate of the CPU" shown in step S506 and "obtaining the current hash value of the firmware required by the CPU by the manager" shown in step S507 after the root certificate of the CPU is verified based on the CPU, for example, the execution order can be sequential execution or parallel execution, and the embodiments of the present application are only used as an example to illustrate the sequential execution.
[0141] S508, the manager performs security check on the CPU based on the historical hash value of the firmware required by the CPU and the current hash value of the firmware required by the CPU.
[0142] For example, the manager can determine whether the historical hash value of the firmware required by the CPU and the current hash value of the firmware required by the CPU are consistent, to implement the security check on the CPU. If the manager determines that the historical hash value of the firmware required by the CPU and the current hash value of the firmware required by the CPU are consistent, it indicates that the firmware required by the CPU is not replaced or tampered, and the security check on the CPU is passed. If the manager determines that the historical hash value of the firmware required by the CPU and the current hash value of the firmware required by the CPU are inconsistent, it indicates that the firmware required by the CPU may be replaced or tampered, and the security check on the CPU is not passed.
[0143] Optionally, if the security check on the CPU is not passed, the manager can return prompt information to the client of the computing device to prompt the user that the computing device has a fault. It should be noted that the embodiments of the present application do not limit the content of the prompt information.
[0144] In the embodiments of the present application, during the startup process of the CPU, the manager performs security check on the manager based on the digital signature of the manager, and determines that the security check on the manager is passed, and then verifies the certificate chain of the CPU based on the root certificate of the CPU stored by the manager, to ensure the identity legitimacy of the CPU, and after the verification is passed, the manager performs security check on the CPU based on the public key certificate of the CPU and the digital signature of the CPU, to ensure the integrity and reliability of the firmware required by the CPU. In this way, the authentication device does not need to be additionally deployed in the computing device, and the manager can perform integrity verification on the manager, and also perform identity legitimacy verification on the CPU and integrity and reliability verification on the firmware required by the CPU based on the stored authentication information, thereby reducing the cost of the computing device.
[0145] FIG. 6 is a flow diagram of another method for security verification of a CPU according to an embodiment of the present application. Referring to FIG. 2, the manager can include a security core and a business core, and the multiplexer turns on a channel between the security core of the manager and the BIOS chip. The security core can include first authentication information, second authentication information, authentication information of the BIOS chip, first firmware, and second firmware. The first firmware can be a program that is run immediately after the manager is powered on, such as a bootloader, and the second firmware can be a program for security verification. Optionally, the first authentication information, the second authentication information, and the authentication information of the BIOS chip can be stored in an OTP memory of the security core, and the first authentication information, the second authentication information, and the authentication information of the BIOS chip can only be accessed by the security core and cannot be erased or modified again, so as to ensure the reliability of the first authentication information, the second authentication information, and the authentication information of the BIOS chip.
[0146] Referring to FIGS. 2 and 6, the method can include the following steps:
[0147] S601, in a CPU startup process, the security core of the manager performs security verification on the security core based on the second authentication information.
[0148] In a possible implementation, the second authentication information includes a public key certificate of the security core and a digital signature of the security core, and the digital signature of the security core includes a history hash value of the security core. The digital signature of the security core can be obtained by encrypting the history hash value of the security core based on a private key certificate of the security core, for example. The history hash value of the security core represents a history hash value of firmware included in the security core. The history hash value can be a hash value determined when the security core of the manager is produced, for example.
[0149] In this implementation, the security core of the manager runs the first firmware, verifies the digital signature of the security core based on the public key certificate of the security core included in the system trusted root, determines the history hash value of the security core, obtains a current hash value of the security core, and performs security verification on the security core based on the history hash value of the security core and the current hash value of the security core.
[0150] Exemplarily, the first firmware can be a bootloader, and the secure core runs the first firmware after the manager is powered on, and performs security verification on the secure core based on the second authentication information. The secure core of the manager can decrypt the digital signature of the secure core based on the public key certificate of the secure core, and after decryption, the history hash value of the secure core included in the digital signature of the secure core can be determined. The current hash value of the secure core represents the current hash value of the firmware included in the secure core. The secure core of the manager can generate the current hash value of the secure core based on the firmware included in the secure core and a hash algorithm. It should be noted that the hash algorithm for generating the hash value is not limited in the embodiments of the present application, and is consistent with the hash algorithm for generating the history hash value of the secure core, which can be, for example, a 256-bit secure hash algorithm (Secure Hash Algorithm 256-bit, SHA-256) or a cyclic redundancy check (Cyclic Redundancy Check, CRC) algorithm.
[0151] Exemplarily, the secure core of the manager can determine whether the history hash value of the secure core and the current hash value of the secure core are consistent, to implement security verification on the secure core of the manager. If the secure core of the manager determines that the history hash value of the secure core and the current hash value of the secure core are consistent, it indicates that the firmware included in the secure core of the manager has not been replaced or tampered with, and the security verification on the secure core is passed. If the secure core of the manager determines that the history hash value of the secure core and the current hash value of the secure core are inconsistent, it indicates that the firmware included in the secure core may have been replaced or tampered with, and the security verification on the secure core is not passed.
[0152] Optionally, if the security verification of the secure core of the manager is not passed, prompt information can be returned to the client of the computing device to prompt the user that the computing device has a fault. It should be noted that the content of the prompt information is not limited in the embodiments of the present application.
[0153] In this way, the second authentication information is stored by the secure core, the security and reliability of the authentication information are improved, and then the security verification on the secure core is implemented by the secure core based on the authentication information, and the reliability of the security verification of the secure core is improved.
[0154] It should be noted that the decryption method is not limited in the embodiments of the present application, and is related to the encryption algorithm used by the secure core, and the execution order of "determining the history hash value of the secure core" and "obtaining the current hash value of the secure core" is not limited in the embodiments of the present application, for example, it can be executed sequentially or in parallel, and the embodiments are only used as an example to illustrate the sequential execution.
[0155] S602, after determining that the security verification of the secure core is passed, the secure core of the manager performs security verification on the business core based on the second authentication information.
[0156] In a possible implementation, the second authentication information includes a public key certificate of the service core and a digital signature of the service core, and the digital signature of the service core includes a history hash value of the service core; for example, the digital signature of the service core can be obtained by encrypting the history hash value of the service core based on a private key certificate of the service core, and stored in the secure core. The history hash value of the service core represents a history hash value of firmware included in the service core, which can be a hash value determined by the service core of the manager in a production equipment stage, for example.
[0157] In this implementation, the secure core of the manager runs the second firmware, verifies the digital signature of the service core of the service core based on the public key certificate of the service core included in the system trusted root, determines the history hash value of the service core, obtains the current hash value of the service core, and performs security check on the service core based on the history hash value of the service core and the current hash value of the service core.
[0158] For example, after the security check of the secure core is passed, the secure core can run normally, and therefore, the secure core can run the second firmware for performing security check on the service core based on the second authentication information. The secure core of the manager can run the second firmware, decrypt the digital signature of the service core based on the public key certificate of the service core, and determine the history hash value of the service core included in the digital signature of the service core after decryption. The current hash value of the service core represents a current hash value of firmware included in the service core. The service core of the manager can generate the current hash value of the service core based on the firmware included in the current service core and a hash algorithm. It should be noted that the hash algorithm for generating the hash value is not limited in the embodiments of the present application, and is consistent with the hash algorithm for generating the history hash value of the service core, which can be a 256-bit secure hash algorithm (SHA-256) or a cyclic redundancy check (CRC) algorithm, for example.
[0159] Exemplarily, the security core can acquire the current hash value of the business core through the internal communication interface with the business core; or the business core can store the current hash value of the business core into the memory of the manager after generating the current hash value of the business core, and the security core can read the current hash value of the business core from the memory since the security core and the business core can share the memory. The security core of the manager can determine whether the historical hash value of the business core and the current hash value of the business core are consistent, to realize the security check of the business core of the manager. If the security core of the manager determines that the historical hash value of the business core and the current hash value of the business core are consistent, it indicates that the firmware included in the business core of the manager is not replaced or tampered, and the security check of the business core is passed. If the security core of the manager determines that the historical hash value of the business core and the current hash value of the business core are inconsistent, it indicates that the firmware included in the business core is possibly replaced or tampered, and the security check of the business core is failed.
[0160] In this way, the second authentication information is stored by the security core, the security of the authentication information and the reliability are improved, and then the security core realizes the security check of the business core based on the authentication information, and the reliability of the security check of the business core is improved.
[0161] It should be noted that the decryption manner is not limited in the embodiments of the present application, and is related to the encryption algorithm used by the business core. It should be noted that the execution order of "determining the historical hash value of the business core" and "acquiring the current hash value of the business core" is not limited in the embodiments of the present application, for example, the execution order can be sequential execution or parallel execution, and the embodiments are only illustrative taking the sequential execution as an example.
[0162] Optionally, if the security check of the business core of the manager is failed, prompt information can be returned to the client of the computing device to prompt the user that the computing device has a fault. It should be noted that the content of the prompt information is not limited in the embodiments of the present application.
[0163] Optionally, after the security core of the manager determines that the security check of the business core is passed, a start instruction can be returned to the business core, the start instruction can instruct the business core of the manager to operate the firmware included in the business core, to realize the function of the business core of the manager, for example, taking the manager as a BMC, the business core can execute functions such as system monitoring, hardware state detection, fault detection and alarm.
[0164] Through the step, the manager is divided into the security core and the business core, the second authentication information is stored by the security core, the security of the authentication information and the reliability are improved, and then the security core realizes the security check of the manager based on the authentication information, and the reliability of the security check of the manager is improved.
[0165] S603, the security core of the manager performs security verification on the BIOS chip based on the authentication information of the BIOS chip.
[0166] Exemplarily, referring to FIG. 2, the computing device can further include a BIOS chip, and the security core can further include authentication information of the BIOS chip, which represents authentication information of the BIOS chip and is used to verify the integrity of firmware included in the BIOS chip. It can be understood that the firmware stored in the BIOS chip is related to the operation of the CPU, and therefore, the integrity and reliability of the firmware included in the BIOS chip need to be ensured.
[0167] In a possible implementation, the authentication information of the BIOS chip can include a public key certificate of the BIOS chip and a digital signature of the BIOS chip; the digital signature of the BIOS chip includes a historical hash value of the BIOS chip; the historical hash value of the BIOS chip represents a historical hash value of the firmware included in the BIOS chip; and the historical hash value can be generated when the BIOS chip is in a production and equipment stage. The digital signature of the BIOS chip can be obtained by encrypting the historical hash value of the BIOS chip based on a private key certificate of the BIOS chip, and stored in the security core.
[0168] In this implementation, the security core of the manager performs security verification on the BIOS chip based on the authentication information of the BIOS chip included in the system trusted root, determines the historical hash value of the BIOS chip in response to a BIOS chip verification request triggered by the business core, acquires the current hash value of the BIOS chip based on a channel between the security core and the BIOS chip enabled by the multiplexer, and performs security verification on the BIOS chip based on the historical hash value of the BIOS chip and the current hash value of the BIOS chip.
[0169] Exemplarily, the BIOS chip verification request is used to instruct the security core to verify the BIOS chip. It can be understood that the business core can perform the function of hardware state detection, and thus the business core can trigger the verification request for the BIOS chip after the business core runs the firmware included in the business core. The security core of the manager can run the second firmware, decrypt the digital signature of the BIOS chip based on the public key certificate of the BIOS chip, and determine the historical hash value of the BIOS chip included in the digital signature of the BIOS chip after decryption. The current hash value of the BIOS chip represents the current hash value of the firmware included in the BIOS chip. The BIOS chip can generate the current hash value of the BIOS chip based on the currently included firmware and a hash algorithm. It should be noted that the hash algorithm for generating the hash value is not limited in the embodiments of the present application, and is consistent with the hash algorithm for generating the historical hash value of the BIOS chip, which can be, for example, a 256-bit secure hash algorithm (SHA-256) or a cyclic redundancy check (CRC) algorithm. It should be noted that the decryption method is not limited in the embodiments of the present application, and is related to the encryption algorithm used by the BIOS chip.
[0170] It should be understood that the security core can generate a control signal to control the multiplexer to turn on the channel between the security core and the BIOS chip, so as to realize the communication between the security core and the BIOS chip, and thus the security core can obtain the current hash value of the BIOS chip generated by the BIOS chip.
[0171] Exemplarily, the security core of the manager can determine whether the historical hash value of the BIOS chip and the current hash value of the BIOS chip are consistent, to realize the security verification of the BIOS chip. If the security core of the manager determines that the historical hash value of the BIOS chip and the current hash value of the BIOS chip are consistent, it indicates that the firmware included in the BIOS chip has not been replaced or tampered, and thus the security verification of the BIOS chip is passed. If the security core of the manager determines that the historical hash value of the BIOS chip and the current hash value of the BIOS chip are inconsistent, it indicates that the firmware included in the BIOS chip may be replaced or tampered, and thus the security verification of the BIOS chip is not passed.
[0172] In this way, the security core stores the authentication information of the BIOS chip, improves the security and reliability of the authentication information, and then the security core realizes the security verification of the BIOS chip based on the authentication information of the BIOS chip, improves the reliability of the security verification of the BIOS chip, and controls the channel between the CPU and the BIOS chip to be turned on after the security verification of the BIOS chip is passed, thereby improving the security of the CPU.
[0173] Optionally, if the security check of the BIOS chip fails, a prompt message can be returned to the client of the computing device to prompt the user that the computing device has a fault. It should be noted that the content of the prompt message is not limited in the embodiments of the present application.
[0174] S604, after the security core of the manager determines that the security check of the BIOS chip passes, the security core controls the multiplexer to turn on the channel between the CPU and the BIOS chip.
[0175] It can be understood that the firmware required by the CPU is stored in the BIOS chip, and therefore, after the security core determines that the security check of the BIOS chip passes, the security core can generate a control signal to control the multiplexer to turn on the channel between the CPU and the BIOS chip, so that the security core of the manager can obtain the current hash value of the firmware required by the CPU to perform a security check on the CPU.
[0176] S605, the security core of the manager obtains the certificate chain of the CPU.
[0177] Exemplarily, the certificate chain of the CPU can be used to represent the legitimacy of the identity of the CPU, in other words, the certificate chain of the CPU can be used to determine whether the CPU in the computing device is legitimate.
[0178] In a possible implementation, as described above with reference to FIG. 1, the manager and the CPU can be communicatively connected through the I3C bus, and therefore, the manager and the CPU can use the Management Component Transport Protocol (MCTP) based on the I3C bus to transmit the security data and commands defined by the Security Protocol and Data Model. In this implementation, the manager can be installed with a preset application, which can be used to implement the transmission of the security data and commands between the manager and the CPU.
[0179] For example, after the security core of the manager determines that the security check of the BIOS chip passes, the firmware included in the business core of the manager can trigger a CPU check request, and then the business core of the manager can run the preset application to communicate with the CPU, obtain the certificate chain of the CPU, and store the certificate chain in the memory of the manager, and the security core can obtain the certificate chain of the CPU from the memory.
[0180] S606, the security core of the manager verifies the certificate chain of the CPU based on the root certificate of the CPU.
[0181] Exemplarily, the security core of the manager can run the second firmware, and verify the certificate chain of the CPU based on the root certificate of the CPU. For example, the security core of the manager can verify the first certificate included in the certificate chain of the CPU based on the public key certificate of the CPU in the root certificate of the CPU, and if the verification is passed, use the public key certificate included in the first certificate to verify the certificates included in the certificate chain of the CPU level by level until all the certificates included in the certificate chain of the CPU are verified, and then determine that the verification of the certificate chain of the CPU is passed. Through this step, the security core of the manager can determine the legitimacy of the identity of the CPU to prevent the CPU from being replaced.
[0182] S607, after the security core of the manager verifies that the certificate chain of the CPU is passed, the security core of the manager acquires the current hash value of the firmware required by the CPU.
[0183] After the security core of the manager determines that the certificate chain of the CPU is verified, the public key certificate of the CPU is used to verify the digital signature of the CPU, and the historical hash value of the firmware required by the CPU is determined. For example, the security core of the manager can decrypt the digital signature of the CPU based on the public key certificate of the CPU, and after decryption, the historical hash value of the firmware required by the CPU included in the digital signature of the CPU can be determined.
[0184] It should be noted that the application embodiment does not limit the decryption method, which is related to the encryption algorithm used by the CPU.
[0185] Exemplarily, the current hash value of the firmware required by the CPU represents the current hash value of the firmware included in the CPU. The CPU can acquire the firmware required by the CPU from the BIOS chip and generate the current hash value of the firmware required by the CPU based on a hash algorithm, and send it to the business core of the manager. It should be noted that the application embodiment does not limit the hash algorithm for generating the hash value, which is consistent with the hash algorithm for generating the historical hash value of the firmware required by the CPU. For example, the hash algorithm can be a 256-bit secure hash algorithm (Secure Hash Algorithm 256-bit, SHA-256) or a cyclic redundancy check (Cyclic Redundancy Check, CRC) algorithm.
[0186] In a possible implementation, the business core of the manager can run a preset application for the CPU to communicate, acquire the current hash value of the firmware required by the CPU, and store it in the memory of the manager. The security core of the manager acquires the current hash value of the firmware required by the CPU from the memory.
[0187] S608, the security core of the manager performs security check on the CPU based on the historical hash value of the firmware required by the CPU and the current hash value of the firmware required by the CPU.
[0188] For example, the security core of the manager can determine whether the historical hash value of the CPU required firmware and the current hash value of the CPU required firmware are consistent, to implement the security check of the CPU. If the security core of the manager determines that the historical hash value of the CPU required firmware and the current hash value of the CPU required firmware are consistent, it indicates that the CPU required firmware is not replaced or tampered, and the security check of the CPU is passed. If the security core of the manager determines that the historical hash value of the CPU required firmware and the current hash value of the CPU required firmware are inconsistent, it indicates that the CPU required firmware may be replaced or tampered, and the security check of the CPU is not passed.
[0189] Optionally, if the security check of the CPU is not passed, prompt information can be returned to the client of the computing device to prompt the user that the computing device has a fault. It should be noted that the content of the prompt information is not limited in the embodiments of the present application.
[0190] In this way, the first authentication information is stored by the security core, the security and reliability of the authentication information are improved, and then the security core implements the security check of the CPU based on the first authentication information, and the reliability of the security check of the CPU is improved.
[0191] In some possible implementation manners, the second authentication information can be updated based on the update of the firmware included in the manager; the first authentication information can be updated based on the update of the firmware included in the manager, or can be updated based on the update of the firmware included in the BIOS chip.
[0192] In the embodiments, in the starting process of the CPU, the security core of the manager can verify the security core and the business core based on the second authentication information, after ensuring the safe starting of the manager, the security core of the manager performs the security check of the BIOS chip based on the authentication information of the BIOS chip, and switches the access right of the BIOS chip to the CPU after the security check of the BIOS chip is passed, and then controls the CPU to start based on the firmware included in the BIOS chip after the security check of the CPU based on the first authentication information is passed. In this way, the manager is divided into the security core and the business core, the first authentication information, the second authentication information and the authentication information of the BIOS chip are stored by the security core, and the business core cannot access the authentication information, the security and reliability of the authentication information are improved, and then the security core implements the security check of the manager, the BIOS chip and the CPU based on the authentication information, and the reliability of the security check is improved.
[0193] FIG. 7 is a structural schematic diagram of a security check device of a CPU provided in the embodiments of the present application. The device can be applied to the manager of a computing device. As shown in FIG. 7, the device 700 includes:
[0194] The first checking module 701 is configured to perform security checking on the BIOS chip based on the authentication information of the BIOS chip.
[0195] The obtaining module 702 is configured to obtain first authentication information from the BIOS chip after the security checking on the BIOS chip is passed.
[0196] The second checking module 703 is configured to perform security checking on the CPU based on the first authentication information.
[0197] In a possible implementation, the first authentication information includes a root certificate of the CPU and a history hash value of firmware required by the CPU.
[0198] The obtaining module 702 is configured to obtain the root certificate of the CPU and the history hash value of the firmware required by the CPU from the BIOS chip.
[0199] The obtaining module 702 is configured to obtain the root certificate of the CPU from the BIOS chip and obtain the history hash value of the firmware required by the CPU from the memory of the manager.
[0200] In a possible implementation, the first checking module 701 is configured to:
[0201] perform security checking on the manager based on second authentication information, wherein the second authentication information represents authentication information of the manager.
[0202] perform security checking on the BIOS chip based on the authentication information of the BIOS chip after the security checking on the manager is passed.
[0203] In a possible implementation, the apparatus further includes a control module configured to:
[0204] assign access authority of the BIOS chip to the CPU.
[0205] In a possible implementation, the apparatus further includes a sending module configured to:
[0206] send a start instruction to the CPU after the security checking on the CPU is passed, wherein the start instruction is used to instruct the CPU to obtain firmware required by the CPU from the BIOS chip and start the CPU based on the firmware required by the CPU.
[0207] The security checking apparatus of the CPU provided in this embodiment can perform the security checking method of the CPU in the method embodiments, and has similar beneficial effects, which will not be repeated here.
[0208] Figure 8 is a structural schematic diagram of a security verification device of a CPU provided by an embodiment of the present application. The device can be applied to a manager of a computing device, wherein the manager comprises first authentication information and second authentication information; the first authentication information represents authentication information of the CPU, and the second authentication information represents authentication information of the manager; as shown in Figure 8, the device 800 comprises:
[0209] a first verification module 801, configured to perform security verification on the manager based on the second authentication information during a startup process of the CPU;
[0210] a second verification module 802, configured to perform security verification on the CPU based on the first authentication information after determining that the security verification on the manager is passed.
[0211] In a possible implementation, the manager comprises a security core and a business core, and the security core comprises the first authentication information and the second authentication information; the first verification module 801 is specifically configured to:
[0212] the security core of the manager performs security verification on the security core based on the second authentication information;
[0213] after determining that the security verification on the security core is passed, the security core of the manager performs security verification on the business core based on the second authentication information;
[0214] the second verification module 802 is specifically configured to:
[0215] after determining that the security verification on the business core is passed, the security core of the manager performs security verification on the CPU based on the first authentication information.
[0216] In a possible implementation, the security core comprises the first authentication information; the first authentication information comprises a root certificate of the CPU and a historical hash value of firmware required by the CPU; the first verification module 801 is specifically configured to:
[0217] the security core of the manager acquires a certificate chain of the CPU;
[0218] the security core of the manager verifies the certificate chain of the CPU based on the root certificate of the CPU;
[0219] after the certificate chain of the CPU is verified, the security core of the manager acquires a current hash value of the firmware required by the CPU;
[0220] the security core of the manager performs security verification on the CPU based on the historical hash value of the firmware required by the CPU and the current hash value of the firmware required by the CPU.
[0221] In a possible implementation, the computing device further comprises a BIOS chip and a multiplexer, an output end of the multiplexer is connected to the BIOS chip, and input ends of the multiplexer are connected to the security core of the manager and the CPU; the security core further comprises authentication information of the BIOS chip; and the third checking module is specifically configured to:
[0222] The security core of the manager performs security checking on the BIOS chip based on the authentication information of the BIOS chip.
[0223] After determining that the security checking on the BIOS chip is passed, the security core of the manager controls the multiplexer to turn on a channel between the CPU and the BIOS chip.
[0224] The security checking device of the CPU provided in the embodiment can perform the security checking method of the CPU in the method embodiment, and has similar beneficial effects, which will not be repeated here.
[0225] The computing device provided in the embodiment can refer to the computing device shown in FIG. 1 or FIG. 2, and can perform the technical solutions in the method embodiment, and has similar beneficial effects, which will not be repeated here.
[0226] The embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores computer execution instructions. When the computer execution instructions are executed by a processor, the computer execution instructions are used to implement the technical solutions provided by any of the preceding method embodiments.
[0227] The embodiment of the present application further provides a computer program product, comprising a computer program. When the computer program is executed by a processor, the computer program is used to implement the technical solutions provided by the preceding method embodiments.
[0228] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the embodiments of the present application, and not to limit them; although the embodiments of the present application have been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A security check method of a CPU, characterized by, The method is applied to a manager of a computing device, the computing device comprising the manager, a BIOS chip and a central processing unit (CPU), the manager being communicatively connected with the BIOS chip and the CPU respectively; the method comprises: performing security verification on the BIOS chip based on authentication information of the BIOS chip; after the security verification on the BIOS chip is passed, obtaining first authentication information from the BIOS chip, wherein the first authentication information represents authentication information of the CPU; performing security verification on the CPU based on the first authentication information.
2. The method of claim 1, wherein, The first authentication information comprises a root certificate of the CPU and a historical hash value of firmware required by the CPU; obtaining the first authentication information from the BIOS chip comprises: obtaining the root certificate of the CPU and the historical hash value of the firmware required by the CPU from the BIOS chip; or obtaining the root certificate of the CPU from the BIOS chip and obtaining the historical hash value of the firmware required by the CPU from a memory of the manager.
3. The method of claim 1, wherein, The security verification on the BIOS chip based on the authentication information of the BIOS chip comprises: performing security verification on the manager based on second authentication information, wherein the second authentication information represents authentication information of the manager; after the security verification on the manager is passed, performing security verification on the BIOS chip based on the authentication information of the BIOS chip.
4. The method of claim 1, wherein, Before the security verification on the CPU based on the first authentication information, the method comprises: assigning access authority of the BIOS chip to the CPU.
5. The method of claim 1, wherein, The method further comprises: after the security verification on the CPU is passed, sending a start instruction to the CPU, wherein the start instruction is used to instruct the CPU to obtain firmware required by the CPU from the BIOS chip and start the CPU based on the firmware required by the CPU.
6. A security check method of a CPU, characterized by, The method is applied to a manager of a computing device, the computing device comprising the manager and a central processing unit (CPU), the manager being communicatively connected with the CPU; the manager comprises first authentication information and second authentication information; the first authentication information represents authentication information of the CPU, and the second authentication information represents authentication information of the manager; the method comprises: during a start process of the CPU, performing security verification on the manager based on the second authentication information; after it is determined that the security verification on the manager is passed, performing security verification on the CPU based on the first authentication information.
7. The method of claim 6, wherein, The manager comprises a security core and a business core, and the security core comprises the first authentication information and the second authentication information; the security verification on the manager based on the second authentication information comprises: the security core of the manager performs security verification on the security core based on the second authentication information; after it is determined that the security verification on the security core is passed, the security core of the manager performs security verification on the business core based on the second authentication information; the security verification on the CPU based on the first authentication information after it is determined that the security verification on the manager is passed comprises: After determining that the business core security check passes, the security core of the manager performs security check on the CPU based on the first authentication information.
8. The method of claim 7, wherein, The first authentication information comprises a root certificate of the CPU and a history hash value of firmware required by the CPU; the security core of the manager performs security check on the CPU based on the first authentication information, comprising: The security core of the manager acquires a certificate chain of the CPU; The security core of the manager verifies the certificate chain of the CPU based on the root certificate of the CPU; After the certificate chain of the CPU is verified, the security core of the manager acquires a current hash value of the firmware required by the CPU; The security core of the manager performs security check on the CPU based on the history hash value of the firmware required by the CPU and the current hash value of the firmware required by the CPU.
9. The method according to any of claims 7 or 8, characterized in that, The computing device further comprises a BIOS chip and a multiplexer, an output end of the multiplexer is connected to the BIOS chip, and an input end of the multiplexer is connected to the security core of the manager and the CPU; the security core further comprises authentication information of the BIOS chip; The method further comprises: The security core of the manager performs security check on the BIOS chip based on the authentication information of the BIOS chip; After determining that the security check of the BIOS chip passes, the security core of the manager controls the multiplexer to turn on a channel between the CPU and the BIOS chip.
10. A computing device, comprising: The computing device comprises a manager, a central processing unit (CPU) and a memory, the manager is in communication connection with the central processing unit, and the manager is in communication connection with the memory; The memory stores computer execution instructions; The manager executes the computer execution instructions stored in the memory to implement the security check method of the CPU according to any one of claims 1-5 or the security check method of the CPU according to any one of claims 6-9.
Citation Information
Patent Citations
Chip and method for starting chip
CN109542518A
Firmware starting method, chip and computing equipment
CN115935335A
Start verification system and method, electronic equipment and storage medium
CN117436090A
CPU security verification method and computing device
CN119272287A
Security Chip-Based Security Authentication Method and System, Security Chip, and Readable Storage Medium
US20230289424A1