The application discloses a kind of kernel start-up measurement and trusted
verification method and
system based on U-Boot, it is related to
embedded system security technical field.In the initialization safety check module after U-Boot starts, establish initial trusted root and empty PCR register;Determine execution address range by loading kernel image and by decompression,
relocation, according to kernel, start parameter and device tree data, hierarchically calculate first, second, third type of measurement value, extended write soft PCR register;After
operating system kernel starts, extract measurement result and pass to kernel, compare with preset trusted reference value, any item mismatch triggers safety strategy, start blocking, limited mode, multi-dimensional alarm.The application constructs safety check module by
software TPM and
software PCR, without relying on hardware trusted module can realize kernel start-up whole process trusted protection, and measurement range is comprehensive, safety mechanism is perfect and strong universality, with wide application value.