The invention belongs to the technical field of computer
trusted computing, and particularly relates to a method and
system for constructing a TPCM trusted root based on a multi-core BMC, and the method comprises the steps: selecting the multi-core BMC, configuring one core as a trusted core, and achieving the physical and logic isolation with other cores; tPCM related codes are integrated in the trusted core, and a TCM module is combined to provide a running environment for the TPCM; when the
system is started, the TPCM performs measurement check on the BMC code and the
BIOS code, and if the BMC code and the
BIOS code are abnormal, a
security policy is started In the
system operation process, the TPCM monitors hardware,
firmware and
software of a calculation part in real time, and discovers abnormal behaviors to block and give an alarm; and meanwhile, the management interface is connected with a trusted management center, so that remote configuration and monitoring are realized. A multi-core BMC is used as a protection component, a
server host side is used as a calculation component, and a trust
chain model of a star-shaped trusted topological structure is constructed. According to the method, the TPCM trusted root is constructed by using the existing resources of the multi-core BMC, so that the hardware cost is reduced, the real-time performance of trusted measurement and the monitoring comprehensiveness are improved, and the running safety and credibility of the
server are improved.