The invention relates to the technical field of computer
system security, and particularly discloses an
RAID (redundant array of independent disks) card and TPM (
trusted platform module)
chip collaborative
system trusted startup method, which comprises the following steps: S1, after a
system is powered on, starting by using a TPM
chip as a trusted root, and executing
integrity measurement to establish a trusted startup chain; s2, after
BIOS verification is passed and before a bootLoader is loaded, the
BIOS initiates
integrity measurement and
verification of the
RAID card, and the
measurement and verification of the
RAID card at least comprise
verification of
firmware of the RAID card and feature values of a system hard disk connected with the
firmware; s3, only after verification of the RAID card is passed, the system loads and executes subsequent BootLoader and an
operating system kernel from a system disk on the RAID card, and starting is completed; s4, during normal operation of the system, the TPM
chip performs periodic or triggered dynamic measurement on the RAID card and the system disk thereof through the
system management bus, and executes a security
processing strategy when the measurement is abnormal; and the trust chain is expanded to the storage subsystem, so that comprehensive security protection is realized.