The invention relates to the technical field of
computer hardware security, in particular to a secure startup hardware root of trust module integrated on a mainboard and a
verification method, comprising the following steps: establishing a trusted environment by the hardware root of trust module after being powered on, and actively acquiring
original data of
firmware to be verified through a private
bus of the mainboard, and performing isolation
measurement and verification in the internal security area. And after the
verification is passed, generating a security start token containing a temporary
session key, and transmitting the security start token to a next-level component. And the next-level component needs to send a
certificate confirmation request, the
system control right is released after the
certificate confirmation request is verified again by the hardware module, and then the hardware module enters a silent monitoring state. According to the method, the authenticity of the measurement
source data is ensured from the
physical level, dynamic transmission and continuous maintenance of trust are realized through a two-way confirmation mechanism, and the capability of defending
firmware tampering and persistent
attack of a
system bottom layer is effectively improved.