CN104572093A - Method for realizing bi-operation system starting of terminal equipment by using USB (universal serial bus) controller - Google Patents

Method for realizing bi-operation system starting of terminal equipment by using USB (universal serial bus) controller Download PDF

Info

Publication number
CN104572093A
CN104572093A CN201410843258.8A CN201410843258A CN104572093A CN 104572093 A CN104572093 A CN 104572093A CN 201410843258 A CN201410843258 A CN 201410843258A CN 104572093 A CN104572093 A CN 104572093A
Authority
CN
China
Prior art keywords
partition
workspace
startup
usb controller
hard disk
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201410843258.8A
Other languages
Chinese (zh)
Inventor
张建标
郁亚威
阎林
公备
艾蓉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing University of Technology
Original Assignee
Beijing University of Technology
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing University of Technology filed Critical Beijing University of Technology
Priority to CN201410843258.8A priority Critical patent/CN104572093A/en
Publication of CN104572093A publication Critical patent/CN104572093A/en
Pending legal-status Critical Current

Links

Abstract

The invention discloses a method for realizing bi-operation system starting of terminal equipment by using a USB (universal serial bus) controller and belongs to the technical field of dual operation system starting of the user terminal equipment. The method is characterized by including on a single hard disk provided with a working area and a free area, judging whether the USB controller is inserted or not by a BIOS (bi-operation system); if yes, executing a modified guide file GRLDR in the USB controller, verifying PIN of a user, loading a secret key, guiding to enter a reserved partition, executing a decryption program to decrypt the working area, and then entering the working area; if not, guiding to enter the free area by an MBR (master boot record), executing a partition boot record (PBR), in the type of BOOTMGR, of the free area, and entering the free area. Different from other methods for realizing bi-operation system starting through double hard disks, the method has the advantages that a mode of realizing bi-operation system starting through the same hard disk and multiple partitions is used, and through an encryption mechanism of a working area operation system, safety of the working area operation system is guaranteed, cost is lowered, and efficiency is improved.

Description

USB controller is used to realize the method for terminal device dual operating systems startup
Technical field
The present invention relates to a kind of method that the USB of use controller realizes the startup of guiding terminal equipment dual operating systems, on the terminal device two operating systems are installed, separate, switched between the two operating systems by a USB controller (also can be referred to as identity recognizer etc.), wherein first operating system supports that user surfs the web, install voluntarily and unload any software, belong to user free zone operating system environment, the internet behavior of user in second operating system, software is installed and is unloaded the control being strictly subject to background server, belong to user working area operating system environment, consider the requirement of working area manipulation system environment data security, working area manipulation system environments encipherment protection.
Background technology
Current subscriber terminal equipment is widely used, as user surfs the web, routine office work, generally all install microsoft operation system, these operating system supports that user installs voluntarily and unloads any software, brings very large hidden danger to the safety of system, easily suffer to be hidden in the attack such as virus or wooden horse in mounting software voluntarily, office system belongs to the operation system of unit, and the data related to are unit sensitive datas, and the leakage of data can bring security threat.How allowing user can optionally mounting software on the terminal device oneself used, can guaranteeing that again the safety of user when using office system is a problem demanding prompt solution.
Summary of the invention
The object of this invention is to provide a kind of USB controller and realize the method that terminal device dual operating systems starts, by a USB controller, namely bootablely enter working area manipulation system environments.First operating system of installing in the fdisk of terminal device, be defined as free zone environment, arbitrarily can surf the web, install and unload any software, this is identical with the use-pattern of current terminal device.But in install in fdisk second operating system; user logs in be needed to carry out authentication; internet behavior, installation and uninstall strictly will be subject to the control of service end; this operating system and data partition are subject to encipherment protection; even if this terminal device is stolen or also can not reveal office data when losing, its security is subject to strict protection.
The present invention is characterised in that: the method that the terminal device dual operating systems using USB controller to realize starts, it is characterized in that, be that the USB controller that a kind of UKEY of use and CD-ROM drive memory block merge realizes the method that in subscriber terminal equipment, in single hard disk, dual operating systems starts, comprise the following steps successively:
Step 1, initialization
Step 1.1, described USB controller is provided with: UKEY and memory block, wherein:
At least 1M byte memory block and use CD-ROM drive form, UKEY is provided with the user identity identification device identifying user individual recognition code PIN of identity in terminal device, stores boot GRLDR and disk partition decruption key file that bootable user enters the grub4dos of working area manipulation system on described single hard disk in described memory block;
Step 1.2, described single hard disk initialization:
The MBR of Windows NT type is installed to described single hard disk, starts anew to be divided into successively: the first subregion, the second subregion, the 3rd subregion, wherein:
Described second subregion is the workspace of user for handling official business, and comprises working area manipulation system and corresponding office data two parts, adopts the mode of point zone encryption to prevent the data access of disabled user in described workspace,
Described first subregion is reserved partition, and its partition boot record PBR is set to the entry code of workspace partition decrypted program, has deciphered rear guiding and has entered described workspace;
Described 3rd subregion is for the freely movable free zone of user, is the active partition of described single hard disk, comprises free zone operating system and corresponding user activity data two parts,
In addition, to be controlled the startup of described free zone operating system by described single hard disk for realizing subscriber terminal equipment, Windows startup manager file BOOTMGR file to be put under the root directory of described 3rd subregion and free zone, and the startup configuration data BCD file of current system put into by a newly-built BOOT file under the root directory of described free zone, delete the configuration information of the other system in described BCD configuration information except described free zone simultaneously, the partition boot record PBR of Windows startup manager BOOTMGR type is installed then to described free zone, the structure of PBR is followed successively by the jump instruction of 3B, the original manufacturer coding OEM ID of 8B, the basic input-output system BIOS parameter block of 25B, the spreading parameter block of 45B, the guidance code of 426B and the end code 55AA of partition boot record PBR,
For realizing the os starting controlling workspace with described USB controller, first in the CD-ROM drive bootstrap block of described USB controller, write the boot GRLDR of the grub4dos of amendment, secondly in the partition boot record PBR of described reserved partition, write the entry code of workspace partition decrypted program, secondaryly again under the root directory of described workspace, put into Windows startup manager BOOTMGR file, and the startup configuration data BCD file of current system put into by newly-built BOOT file under the root directory of described workspace, delete the configuration information of the other system in described BCD configuration information except described workspace simultaneously, the partition boot record PBR of Windows startup manager BOOTMGR type is installed finally to described workspace,
Step 2, realizes using USB controller to carry out the method for dual operating systems startup successively according to the following steps:
Step 2.1, basic input-output system BIOS carries out self-inspection when starting shooting to subscriber terminal equipment,
Step 2.2, after self-inspection completes, according to arranging, input-output system BIOS judges whether that described USB controller inserts, if do not perform step 2.3, performs step 2.4 if having,
Step 2.3, realizes described subscriber terminal equipment controls described free zone operating system startup by hard disk successively according to the following steps:
Step 2.3.1, performs the Master Boot Record in described single hard disk, guides and enters described free zone,
Step 2.3.2, guides after entering described free zone and can perform described free zone partition boot record PBR, then starts Windows startup manager BOOTMGR,
Step 2.3.3, Windows startup manager BOOTMGR reads and starts configuration data BCD file, loads Windows 7, starts described free zone operating system,
Step 2.4, realizes described subscriber terminal equipment controls described working area manipulation system startup by described USB controller successively according to the following steps:
Step 2.4.1, starts priority and judges:
If the startup priority of hard disk is higher than the priority of optical disk start-up, then perform step 2.3, otherwise perform step 2.4.2,
Step 2.4.2, described USB controller CD-ROM drive starts, and performs the grub4dos boot GRLDR of described amendment,
Step 2.4.3, described boot GRLDR can carry out user identity password PIN to user and verify, if checking is not passed through, then shut down, otherwise perform step 2.4.4,
Step 2.4.4, judges whether the memory block of described UKEY has key file, if do not have, then performs step 2.3.2, otherwise performs step 2.4.5,
Step 2.4.5, load key file to internal memory, guiding enters described reserved partition, perform the described partition boot record PBR of described reserved partition, thus execution decrypted program, decrypted program can be verified key: if authentication failed, shut down, otherwise utilizes double secret key workspace partition to be decrypted, perform step 2.4.6
Step 2.4.6, after having deciphered, guides and enters workspace, perform described partition boot record PBR, performs Windows startup manager BOOTMGR further, according to startup configuration data BCD files loading Windows7,
Whether step 2.4.7, utilize the USB of Windows7 to plug USB controller described in event monitoring and extract: if extract, shut down, otherwise monitoring is always until described USB controller is extracted.
This process as shown in Figure 4.
The present invention is different from other realize dual operating systems startup method by two hard disk, the multiple subregion of same hard disk is used to realize the mode of dual operating systems startup, under ensureing the prerequisite of working area manipulation security of system by the encryption mechanism of working area manipulation system partitioning, reduce cost, improve efficiency.
Accompanying drawing explanation
By the description carried out embodiment below in conjunction with accompanying drawing, these and/or other aspect of the present invention and advantage will become clear and be easier to understand, wherein:
Fig. 1 USB controller architecture.
UKEY: major function is authentication.Utilize the legitimacy of the PIN code checking USB controller user identity of UKEY, utilize the operating system partition, key file encryption and decryption hard disk operational district in USB controller.
Memory block: common U disk form (FAT32 etc.) or CD-ROM drive form, use CD-ROM drive form during the present invention specifically implements, major function is the associated documents storing boot and other necessity.
The Booting sequence figure of Fig. 2 Windows7
Fig. 3 PBR structural drawing (wherein dash area is needs amendment part)
Fig. 4 guide dual operating systems main logic process flow diagram (note: BIOS preferentially starts CD-ROM equipment, and only consider start time whether insert USB controller)
Fig. 5 does not have the hard disk startup boot flow of reserved partition (wherein dash area is needs encryption section)
Fig. 6 withs a hook at the end the hard disk startup boot flow (wherein dash area is needs encryption section) of subregion
Fig. 7 the invention process operational flowchart
Embodiment
For making above-mentioned purpose of the present invention, feature and advantage more become apparent, below in conjunction with accompanying drawing of the present invention, complete, detailed description is carried out to the technical scheme in the embodiment of the present invention.Embodiment described below is section Example of the present invention, is not whole embodiments.Based on embodiments of the invention, the every other embodiment that those skilled in the art obtain under the prerequisite not making creative work, all in protection scope of the present invention.
The method that dual system starts implemented by use USB controller described in this method, as shown in the USB controller architecture of instructions Fig. 1, is made up of UKEY module and memory module.
On a station terminal equipment, below operation is carried out in Microsoft windows 7 operating system environment.Now suppose that first subregion is reserved partition, second subregion is workspace, and the 3rd subregion is free zone.As shown in fdisk situation in the hard disk startup boot flow of the subregion of withing a hook at the end of instructions Fig. 6, as shown in Figure 7, concrete implementation step is as follows for the roughly implementation step of described method:
(1) startup item isolation is realized
Step 1: realize the startup of terminal device by hard disk controlling free zone operating system.
First under the root directory of described free zone system, put into Windows startup manager file BOOTMGR file, and under system root directory newly-built Boot file, put into the startup configuration data file BCD file of current system, delete the configuration information of the other system started in configuration data file BCD configuration information except described free zone simultaneously.
The partition boot record PBR of BOOTMGR type is installed then to described free zone.The effect of this kind of PBR finds and BOOTMGR program under performing current bay root directory, performs this program and deliver follow-up startup control.
Finally described free zone is set to active partition.
Like this when system is from hard disk startup, then the operating system in direct freedom of entry district.
Step 2: realize USB controller to control the startup of operating system in described workspace.
First, Windows startup manager file BOOTMGR file is put under the root directory of described workspace system, and under system root directory newly-built Boot file, put into the startup configuration data file BCD file of current system, delete the configuration information of the other system started in configuration data file BCD configuration information except described workspace simultaneously.
Then, the boot configuration information of the boot GRLDR of configuration grub4dos, directly can be directed to place, workspace subregion.
Then, be that boot files makes Bootable CD-ROM reflection with GRLDR, the CD-ROM drive form memory block of write USB controller.
Wherein the content of the boot configuration information of GRLDR is as follows:
timeout 10
title windows 7
root(hd0,1)
chainloader+1
Wherein (hd0,1) is place, described workspace subregion.
What parameter declaration: timeout 10 represented is the stand-by period is 10, title windows 7 represents that the title of display is " windows 7 ", root (hd0, 1) what represent be second main partition arranging terminal device first piece of hard disk is subregion to be launched, wherein x represents hard disk number, y represents partition number, x, y counts from 0, therefore place, described workspace partitioned representation is (hd0, 1), chainloader+1 represents and will start the partition boot record PBR controlling the subregion to be launched handed in just now set terminal device hard disk, finally completed in follow-up work by this partition boot record PBR.
Like this when system is from USB controller start up system, directly can enter the operating system of described workspace.Boot flow now as shown in Figure 5.
(2) described workspace safe handling
Step 1: after insertion USB controller enters working area manipulation system, workspace disk partition is encrypted.
Step 2: make the USB controller after the encryption of described workspace.The boot GRLDR of amendment grub4dos, achieves: before guiding enters reserved partition, carries out user identity password PIN verify user, if checking is not passed through, then shuts down, otherwise load key to internal memory also guiding enter reserved partition.
With the boot GRLDR of amended grub4dos for boot files makes Bootable CD-ROM reflection, in the CD-ROM drive of write USB controller.
Wherein the content of the boot configuration information of GRLDR is as follows:
timeout 10
title windows 7
root(hd0,0)
chainloader+1
Step 3: the partition boot record PBR revising described reserved partition
In described reserved partition, install self-defining partition boot record PBR, only amendment is as Shadow marks part in Fig. 3 PBR structure, is the entrance of the program realizing following functions:
A. verify the key be loaded in internal memory, if authentication failed, shut down, otherwise utilize double secret key workspace partition to be decrypted;
B. guide and enter workspace, perform partition boot record PBR.
Like this, when system is from USB controller start up system, can directly enter described reserved partition, perform the partition boot record PBR of reserved partition, described workspace is decrypted, then guide the operating system entering described workspace.Boot flow now as shown in Figure 6.
Step 4: monitor described USB controller
Register one from opening service in the operating system of workspace, the function that this service realizes is the insertion/extract event of Real-Time Monitoring USB controller, after USB controller is extracted, ejects screen locking shutdown after warning.
More than that use USB controller provided by the present invention realizes the detailed introduction of dual operating systems safe starting method, apply instantiation herein to set forth principle of the present invention and embodiment, above embodiment just understands method of the present invention for helping.It should be noted that; above embodiment is only unrestricted for illustration of technical scheme of the present invention; for the person of ordinary skill of the art; the present invention can have various modifications and variations; every do in method of the present invention and core concept thereof any amendment, equivalent replacement, improvement etc., all should be included within protection scope of the present invention.

Claims (1)

1. the method that the terminal device dual operating systems using USB controller to realize starts, it is characterized in that, be that the USB controller that a kind of UKEY of use and CD-ROM drive memory block merge realizes the method that in subscriber terminal equipment, in single hard disk, dual operating systems starts, comprise the following steps successively:
Step 1, initialization:
Step 1.1, described USB controller is provided with: UKEY and memory block, wherein:
At least 1M byte memory block and use CD-ROM drive form, UKEY is provided with the user identity identification device identifying user individual recognition code PIN of identity in terminal device, stores boot GRLDR and disk partition decruption key file that bootable user enters the grub4dos of working area manipulation system on described single hard disk in described memory block;
Step 1.2, described single hard disk initialization:
The MBR of Windows NT type is installed to described single hard disk, starts anew to be divided into successively: the first subregion, the second subregion, the 3rd subregion, wherein:
Described second subregion is the workspace of user for handling official business, and comprises working area manipulation system and corresponding office data two parts, adopts the mode of point zone encryption to prevent the data access of disabled user in described workspace,
Described first subregion is reserved partition, and its partition boot record PBR is set to the entry code of workspace partition decrypted program, has deciphered rear guiding and has entered described workspace;
Described 3rd subregion is for the freely movable free zone of user, is the active partition of described single hard disk, comprises free zone operating system and corresponding user activity data two parts,
In addition, to be controlled the startup of described free zone operating system by described single hard disk for realizing subscriber terminal equipment, Windows startup manager file BOOTMGR file to be put under the root directory of described 3rd subregion and free zone, and the startup configuration data BCD file of current system put into by a newly-built BOOT file under the root directory of described free zone, delete the configuration information of the other system in described BCD configuration information except described free zone simultaneously, the partition boot record PBR of Windows startup manager BOOTMGR type is installed then to described free zone, the structure of PBR is followed successively by the jump instruction of 3B, the original manufacturer coding OEM ID of 8B, the basic input-output system BIOS parameter block of 25B, the spreading parameter block of 45B, the guidance code of 426B and the end code 55AA of partition boot record PBR,
For realizing the os starting controlling workspace with described USB controller, first in the CD-ROM drive bootstrap block of described USB controller, write the boot GRLDR of the grub4dos of amendment, secondly in the partition boot record PBR of described reserved partition, write the entry code of workspace partition decrypted program, secondaryly again under the root directory of described workspace, put into Windows startup manager BOOTMGR file, and the startup configuration data BCD file of current system put into by newly-built BOOT file under the root directory of described workspace, delete the configuration information of the other system in described BCD configuration information except described workspace simultaneously, the partition boot record PBR of Windows startup manager BOOTMGR type is installed finally to described workspace,
Step 2, realizes using USB controller to carry out the method for dual operating systems startup successively according to the following steps:
Step 2.1, basic input-output system BIOS carries out self-inspection when starting shooting to subscriber terminal equipment,
Step 2.2, after self-inspection completes, according to arranging, input-output system BIOS judges whether that described USB controller inserts, if do not perform step 2.3, performs step 2.4 if having,
Step 2.3, realizes described subscriber terminal equipment controls described free zone operating system startup by hard disk successively according to the following steps:
Step 2.3.1, performs the Master Boot Record in described single hard disk, guides and enters described free zone,
Step 2.3.2, guides after entering described free zone and can perform described free zone partition boot record PBR, then starts Windows startup manager BOOTMGR,
Step 2.3.3, Windows startup manager BOOTMGR reads and starts configuration data BCD file, loads Windows 7, starts described free zone operating system,
Step 2.4, realizes described subscriber terminal equipment controls described working area manipulation system startup by described USB controller successively according to the following steps:
Step 2.4.1, starts priority and judges:
If the startup priority of hard disk is higher than the priority of optical disk start-up, then perform step 2.3, otherwise perform step 2.4.2,
Step 2.4.2, described USB controller CD-ROM drive starts, and performs the grub4dos boot GRLDR of described amendment,
Step 2.4.3, described boot GRLDR can carry out user identity password PIN to user and verify, if checking is not passed through, then shut down, otherwise perform step 2.4.4,
Step 2.4.4, judges whether the memory block of described UKEY has key file, if do not have, then performs step 2.3.2, otherwise performs step 2.4.5,
Step 2.4.5, load key file to internal memory, guiding enters described reserved partition, perform the described partition boot record PBR of described reserved partition, thus execution decrypted program, decrypted program can be verified key: if authentication failed, shut down, otherwise utilizes double secret key workspace partition to be decrypted, perform step 2.4.6
Step 2.4.6, after having deciphered, guides and enters described workspace, perform described partition boot record PBR, perform described Windows startup manager BOOTMGR further, according to startup configuration data BCD files loading Windows7,
Whether step 2.4.7, monitor described USB controller and extract: if extract, shut down, otherwise monitoring is always until described USB controller is extracted.
CN201410843258.8A 2014-12-30 2014-12-30 Method for realizing bi-operation system starting of terminal equipment by using USB (universal serial bus) controller Pending CN104572093A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410843258.8A CN104572093A (en) 2014-12-30 2014-12-30 Method for realizing bi-operation system starting of terminal equipment by using USB (universal serial bus) controller

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410843258.8A CN104572093A (en) 2014-12-30 2014-12-30 Method for realizing bi-operation system starting of terminal equipment by using USB (universal serial bus) controller

Publications (1)

Publication Number Publication Date
CN104572093A true CN104572093A (en) 2015-04-29

Family

ID=53088259

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410843258.8A Pending CN104572093A (en) 2014-12-30 2014-12-30 Method for realizing bi-operation system starting of terminal equipment by using USB (universal serial bus) controller

Country Status (1)

Country Link
CN (1) CN104572093A (en)

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106095468A (en) * 2016-07-20 2016-11-09 杭州华澜微电子股份有限公司 A kind of computer starting method and device
CN106156229A (en) * 2015-04-27 2016-11-23 宇龙计算机通信科技(深圳)有限公司 The processing method of file, device and terminal in a kind of multiple operating system terminal
CN106203142A (en) * 2016-07-20 2016-12-07 杭州华澜微电子股份有限公司 A kind of method and device of the Primary Hard Drive data protecting computer
CN107203338A (en) * 2017-04-25 2017-09-26 北京小鸟看看科技有限公司 A kind of storage method of virtual reality device, device and virtual reality device
CN107315945A (en) * 2017-07-11 2017-11-03 北京洋浦伟业科技发展有限公司 The disk decryption method and device of a kind of electronic equipment
CN108537044A (en) * 2018-04-10 2018-09-14 济南浪潮高新科技投资发展有限公司 It is a kind of based on the memory of U-Boot from adaptation method, apparatus and system
CN109033812A (en) * 2018-07-16 2018-12-18 山东华芯半导体有限公司 It is a kind of to control the device and method that UKEY logs in multi partition operating system by UEFI
CN110413291A (en) * 2019-07-18 2019-11-05 贵阳朗玛信息技术股份有限公司 Movable storage medium and preparation method thereof
CN110663027A (en) * 2017-06-16 2020-01-07 国际商业机器公司 Protecting operating system configuration using hardware
CN113485757A (en) * 2021-07-22 2021-10-08 北京青云科技股份有限公司 Decryption method, device, equipment and storage medium in system starting process

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101419654A (en) * 2008-12-05 2009-04-29 北京交通大学 Boot file credible verify based on mobile TPM
CN101673330A (en) * 2008-09-10 2010-03-17 中国瑞达系统装备公司 BIOS-based computer security protection method and system
CN101916348A (en) * 2010-08-16 2010-12-15 武汉天喻信息产业股份有限公司 Method and system for safely guiding operating system of user
CN103377054A (en) * 2012-04-16 2013-10-30 联想(北京)有限公司 Starting method and starting device

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101673330A (en) * 2008-09-10 2010-03-17 中国瑞达系统装备公司 BIOS-based computer security protection method and system
CN101419654A (en) * 2008-12-05 2009-04-29 北京交通大学 Boot file credible verify based on mobile TPM
CN101916348A (en) * 2010-08-16 2010-12-15 武汉天喻信息产业股份有限公司 Method and system for safely guiding operating system of user
CN103377054A (en) * 2012-04-16 2013-10-30 联想(北京)有限公司 Starting method and starting device

Cited By (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106156229A (en) * 2015-04-27 2016-11-23 宇龙计算机通信科技(深圳)有限公司 The processing method of file, device and terminal in a kind of multiple operating system terminal
CN106203142A (en) * 2016-07-20 2016-12-07 杭州华澜微电子股份有限公司 A kind of method and device of the Primary Hard Drive data protecting computer
CN106095468A (en) * 2016-07-20 2016-11-09 杭州华澜微电子股份有限公司 A kind of computer starting method and device
CN106095468B (en) * 2016-07-20 2019-07-19 杭州华澜微电子股份有限公司 A kind of computer starting method and device
CN107203338A (en) * 2017-04-25 2017-09-26 北京小鸟看看科技有限公司 A kind of storage method of virtual reality device, device and virtual reality device
CN110663027A (en) * 2017-06-16 2020-01-07 国际商业机器公司 Protecting operating system configuration using hardware
CN110663027B (en) * 2017-06-16 2023-05-16 国际商业机器公司 Method and system for securely booting a computing system
CN107315945A (en) * 2017-07-11 2017-11-03 北京洋浦伟业科技发展有限公司 The disk decryption method and device of a kind of electronic equipment
CN107315945B (en) * 2017-07-11 2019-08-23 北京梆梆安全科技有限公司 The disk decryption method and device of a kind of electronic equipment
CN108537044A (en) * 2018-04-10 2018-09-14 济南浪潮高新科技投资发展有限公司 It is a kind of based on the memory of U-Boot from adaptation method, apparatus and system
CN109033812A (en) * 2018-07-16 2018-12-18 山东华芯半导体有限公司 It is a kind of to control the device and method that UKEY logs in multi partition operating system by UEFI
CN110413291A (en) * 2019-07-18 2019-11-05 贵阳朗玛信息技术股份有限公司 Movable storage medium and preparation method thereof
CN113485757A (en) * 2021-07-22 2021-10-08 北京青云科技股份有限公司 Decryption method, device, equipment and storage medium in system starting process

Similar Documents

Publication Publication Date Title
CN104572093A (en) Method for realizing bi-operation system starting of terminal equipment by using USB (universal serial bus) controller
JP5565040B2 (en) Storage device, data processing device, registration method, and computer program
US8909940B2 (en) Extensible pre-boot authentication
US8745365B2 (en) Method and system for secure booting a computer by booting a first operating system from a secure peripheral device and launching a second operating system stored a secure area in the secure peripheral device on the first operating system
US7457945B2 (en) System and method for providing a secure firmware update to a device in a computer system
US8201239B2 (en) Extensible pre-boot authentication
JP4288209B2 (en) Security architecture for system on chip
CN101436233B (en) Hard disk multi-user partition switch control method, system and computer terminal
US20170244698A1 (en) Authentication processing for a plurality of self-encrypting storage devices
US20110246778A1 (en) Providing security mechanisms for virtual machine images
EP1944712A2 (en) Methods and apparatus for protecting data
JP2016025616A (en) Method for protecting data stored in disk drive, and portable computer
JP2004531004A (en) Security system and method for computer
CN104484625A (en) Computer with dual operating systems and implementation method thereof
US9448785B1 (en) System and method updating full disk encryption software
US20130227262A1 (en) Authentication device and authentication method
WO2011148224A1 (en) Method and system of secure computing environment having auditable control of data movement
CN113645179B (en) Method for configuring virtual entity, computer system and storage medium
CN106909829A (en) Suitable for the Software security protection system of Godson desktop computer and its guard method
TW202044022A (en) Update signals
CN112181513B (en) Trusted measurement method based on control host system guidance of hardware board card
US20080104711A1 (en) System and method for an isolated process to control address translation
CN102096782B (en) Internet banking safety authentication method based on removable medium of virtual machine
CN103823692A (en) Computer operating system starting method
EP3356987B1 (en) Securely writing data to a secure data storage device during runtime

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20150429

WD01 Invention patent application deemed withdrawn after publication