WO2022057720A1 - 一种可信验证的系统、方法、主板、微型板卡及存储介质 - Google Patents
一种可信验证的系统、方法、主板、微型板卡及存储介质 Download PDFInfo
- Publication number
- WO2022057720A1 WO2022057720A1 PCT/CN2021/117387 CN2021117387W WO2022057720A1 WO 2022057720 A1 WO2022057720 A1 WO 2022057720A1 CN 2021117387 W CN2021117387 W CN 2021117387W WO 2022057720 A1 WO2022057720 A1 WO 2022057720A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- board
- verification
- mainboard
- micro
- tpcm
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/575—Secure boot
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/572—Secure firmware programming, e.g. of basic input output system [BIOS]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/82—Protecting input, output or interconnection devices
- G06F21/85—Protecting input, output or interconnection devices interconnection devices, e.g. bus-connected or in-line devices
Definitions
- the embodiments of the present application relate to the field of computer technology, and in particular, to a system, method, motherboard, micro board, and storage medium for trusted verification.
- the basic architecture of the current device is shown in Figure 1A.
- the trusted platform control module (TPCM) on the main board is powered on first, and the firmware in the main board is credibly verified, and the high-speed serial expansion bus (peripheral component interconnect express, PCIE) has not been powered up yet.
- PCIE peripheral component interconnect express
- the embodiments of the present application provide a system, method, main board, micro board and storage medium for credible verification, so as to at least partially solve the above problems.
- a trusted verification system including:
- the miniature board is connected to the main board, and the miniature board includes a first trusted platform control module TPCM;
- the first TPCM When the system is powered on and started, the first TPCM performs credible verification on the micro-board; and after the credible verification of the micro-board is passed, it controls other components of the system to leave the reset state, The mainboard is credibly verified by the mainboard verification component used for credible verification of the mainboard.
- a mainboard for credible verification wherein the mainboard includes a complex programmable logic device CPLD and a second trusted platform control module TPCM;
- the CPLD receives the control signal from the micro card that has passed the credible verification, and controls the second TPCM to leave the reset state;
- the second TPCM performs credible verification on the motherboard.
- a trusted verification mini-board is connected to a main board, and the mini-board includes a first trusted platform control module TPCM;
- the first TPCM When the device is powered on and started, the first TPCM performs credible verification on the micro-board, and after the credible verification of the micro-board is passed, controls other components to leave the reset state, and is used to verify the main board.
- the mainboard verification component that performs credible verification performs credible verification on the mainboard.
- a server which includes the motherboard according to the second aspect.
- a credible verification method is provided, which is applied to a system including a main board and a micro board, and the method includes:
- a computer storage medium is provided on which a computer program is stored, and when the program is executed by a processor, the aforementioned method for trusted verification is implemented.
- the micro-board when the system is powered on and started, firstly, based on the first trusted platform control module TPCM on the micro-board, the micro-board itself is credibly verified, and after the verification is passed, the micro-board is controlled. Other components in the card leave the reset state to work normally, and then the mainboard is authenticated credibly by the mainboard verification component in the system, so as to realize the comprehensive credible verification of the system when the system is started.
- 1A is a schematic diagram of the architecture involved in the current system
- 1B is a schematic diagram of a trusted verification system provided by an embodiment of the present application.
- 1C is a schematic diagram of another trusted verification system provided by an embodiment of the present application.
- FIG. 1D is a schematic structural diagram of a motherboard for credible verification provided by an embodiment of the present application.
- FIG. 1E is a schematic structural diagram of a micro-board card for credible verification provided by an embodiment of the present application.
- FIG. 2 is a schematic flowchart of trusted verification performed by a system according to an embodiment of the present application
- FIG. 3 is a schematic flowchart of a credible verification method provided by an embodiment of the present application.
- TPCM Trusted Platform Control Module, Trusted Platform Control Module.
- the relevant information of the device can be pre-stored in the TPCM and used for trusted verification.
- FPGA Field Programmable Logic Gate Array, Field Programmable Gate Array. It appears as a semi-custom circuit in the field of Application Specific Integrated Circuit (ASIC), with programmable and storable functions.
- ASIC Application Specific Integrated Circuit
- CPLD Complex Programmable Logic Device, Complex Programmable Logic Device. Users can construct digital integrated circuits with logic functions in CPLD according to their needs. For example, with the help of the integrated development software platform, the corresponding target files are generated by methods such as schematic diagram and hardware description language, and the code is transferred to the target chip to realize the designed digital system.
- PCIE High-speed serial expansion bus standard, Peripheral Component Interconnect Express.
- PCIE card is connected to the motherboard through the specification of PCIE.
- FIG. 1A is a schematic diagram of the architecture involved in the current system.
- the TPCM in the motherboard will be powered on first, but the PCIE card will not be powered on.
- the firmware in the mainboard the system is started, but the firmware in the PCIE cannot be credibly verified.
- Micro board It is a physical board device with its own CPU and ROM/RAM, which can run an independent operating system and can be connected to other hardware through the system bus to provide virtual input and output IO devices on the hardware. , IO request processing and forwarding services, the micro board can also contain programmable components CPLD, FPGA and so on.
- CPLD programmable components
- FPGA field-programmable gate array
- MOC Microserver On Card
- the first TPCM the TPCM in the mini board
- Second TPCM TPCM in the motherboard.
- the embodiments of the present application provide a system for trusted verification, which implements more comprehensive trusted verification during startup.
- the system includes:
- a mainboard a mainboard
- a microserver microboard on the card the microboard is connected to the mainboard, and the microboard includes a first trusted platform control module TPCM;
- the first TPCM When the system is powered on and started, the first TPCM performs credible verification on the micro board, and controls other components in the system to leave the reset state after the micro board passes the credible verification , and the mainboard is credibly verified through the mainboard verification component used for credible verification of the mainboard.
- the micro board when the system is powered on and started, the micro board is powered on and started before the main board. Before the micro board completes the authentic verification, the main board (including the components in the main board) is kept in a reset state.
- the first TPCM in the mini-board starts to work first, and other components in the mini-board are also in the reset state, waiting for the first TPCM to verify the micro-board. letter verification.
- the first TPCM can directly control the components on the micro board (including other components in the micro board and the mainboard verification component) to disengage Reset state and perform trusted verification of the motherboard through the motherboard verification component.
- the first TPCM can also indirectly control the components on the mainboard (including other components in the mainboard and the mainboard verification component) to leave the reset state through a corresponding control signal, so that the mainboard verification component starts to verify the mainboard. Carry out feasibility verification.
- the first TPCM may enable the main board verification component in the main board through the programmable components located in the other components in the micro board, so as to The mainboard is credibly verified by the mainboard verification component in the mainboard.
- the programmable components in the other components in the micro board can be complex programmable logic devices CPLD and/or field programmable logic gate array FPGA arranged in the micro board, and they can send commands to the CPLD in the main board.
- the power signal enables the CPLD in the mainboard to activate the mainboard verification component in the mainboard, and perform credible verification of the mainboard.
- the mainboard verification component that performs credible verification on the mainboard may be a component in a micro board, or a component in the mainboard.
- the first TPCM can send an enable signal through the programmable component CPLD or FPGA in the micro board to control the CPLD on the main board to activate the second TPCM in the main board, so that the second TPCM can perform credible verification on the main board.
- the mainboard verification component that performs credible verification on the mainboard may be an FPGA module disposed in a micro board.
- FIG. 1B is a schematic diagram of a trusted verification system provided by an embodiment of the present application, and the device includes:
- the FPGA is connected to the main board; specifically, the FPGA can be connected to all the Describe the CPU and CPLD in the motherboard.
- the first TPCM When the system is powered on, the first TPCM performs credible verification on the micro-board, and controls other components in the micro-board to disengage after passing the credible verification of the micro-board reset state;
- the FPGA is used to perform credible verification on the main board after the credible verification of the micro board is passed.
- the first TPCM in the micro card will be powered on first, and act as a component for performing trusted authentication on the micro card.
- other components including FPGA) on the micro board and components on the main board are in the reset state.
- firmware in the micro board includes systems such as System on Chip (SOC), Basic Input Output System (BIOS), Baseboard Manager Controller (BMC), etc.
- SOC System on Chip
- BIOS Basic Input Output System
- BMC Baseboard Manager Controller
- some firmware or some system codes may exist in each component, and the trusted verification of the first TPCM to the micro board may include the trusted verification of the firmware or system codes of these components.
- the first TPCM when the first TPCM is powered on, it is first in the Serial Peripheral Interface (SPI) master mode.
- SPI Serial Peripheral Interface
- the BIOS and BMC of the micro board can be read based on the SPI master interface. firmware, and perform trusted verification of firmware in BIOS and BMC.
- the first TPCM may pre-store a trusted metric root in a register of the first TPCM (for example, a hash value of firmware pre-obtained by trusted hardware, or a pre-stored trusted partial code of a specified location of firmware)
- the specific verification method can be that the first TPCM confirms the firmware metric value of the firmware (that is, the hash value of the firmware, or the code of the specified position of the firmware), and matches the firmware metric value with the pre-stored trusted metric root, if If the two are consistent, it is confirmed that the firmware is trustworthy.
- the first TPCM can send the SOC reset failure signal and the BMC reset failure signal, so that the SOC and the BMC leave the reset state and start to work normally, and the SOC starts to load the BIOS
- the firmware in the BMC starts to load the firmware in the BMC.
- the first TPCM switches to the SPI slave mode, starts to communicate with the SPI master process of the SOC, and passively accepts the peripheral devices connected to the micro board and the preset micro board information. And information about peripherals and preset micro boards.
- the specific peripheral devices may include the model, unique identifier, name, etc. of the peripheral devices connected to the mini-board, and the mini-board information may include firmware codes and SOC versions of the peripherals connected to the mini-board.
- the first TPCM can perform credible verification on the system code of the SOC. After the system code of the operating system of the SOC is credibly verified, it means that the micro board itself is trusted. At this time, the SOC loads the system code of the SOC to complete the startup of the micro board. .
- the manner of performing credible verification on peripheral devices, preset micro-board card information, and the system code of the SOC is similar to the manner in which trusted verification is performed on firmware in the micro-board card, and will not be repeated here.
- the FPGA After the trusted verification is completed for the micro board, the FPGA has been instructed by the first TPCM to leave the reset state, and starts to work normally, and is used as the main function module to realize the trusted verification of the motherboard. Components are still in reset.
- the mainboard includes the BIOS and BMC in the mainboard, and components such as the operating system that exist on the mainboard.
- the FPGA performs credible verification on the mainboard, which may include operations on the BIOS, BMC and the mainboard.
- the system performs trusted verification.
- the SPI master device on the FPGA can obtain the firmware in the main board, and the The firmware in the main board is credibly verified, wherein the firmware in the main board includes the firmware of the basic input output system BIOS of the main board and the firmware of the baseboard management controller BMC of the main board.
- the specific verification method is similar to the previous one.
- the FPGA can pre-store a trusted measurement root (for example, the hash value of the firmware pre-obtained by the trusted hardware, or the pre-stored trusted partial code of the specified location of the firmware),
- the specific verification method can be that the FPGA confirms the firmware metric value of the firmware on the motherboard (that is, the hash value of the firmware, or the code of the specified location of the firmware), and matches the firmware metric value with the pre-stored trusted metric root, if If the two are consistent, it is confirmed that the firmware on the motherboard is credible.
- the FPGA After the FPGA carries out credible verification to the firmware in the mainboard, the FPGA sends a reset failure signal of the BMC and BIOS on the mainboard, and controls the BIOS and BMC of the mainboard to leave the reset state, while the platform of the mainboard Controller hub (Platform Controller Hub, PCH, also known as integrated south bridge) loads the firmware in the BIOS of the mainboard, and the BMC of the mainboard loads the firmware in the BMC of the mainboard.
- PCH Planform Controller Hub
- the FPGA switches to the serial peripheral device interface SPI slave mode, and performs credible verification on the peripheral devices in the mainboard and preset mainboard information.
- the peripheral devices in the motherboard may include the model, unique identifier, name, etc. of the peripheral devices connected to the motherboard, and the preset motherboard information may include the firmware code of each peripheral device connected to the motherboard, the version of the operating system on the motherboard, etc. Wait.
- the FPGA performs credible verification on the peripheral devices in the mainboard and the preset mainboard information
- the FPGA performs credible verification on the code of the operating system on the mainboard, and after the verification is passed, the mainboard
- the code of the operating system on the motherboard is loaded, thereby constructing the hardware trusted environment of the entire system.
- FIG. 1C A schematic diagram of a system comprising:
- micro-server micro-board card on the card, the micro-board card includes a first trusted platform control module TPCM, and the main board includes a second trusted platform control module TPCM;
- the first TPCM When the system is powered on, the first TPCM performs credible verification on the micro-board, and controls other components in the micro-board to disengage after passing the credible verification of the micro-board reset state, and enable the mainboard verification component in the mainboard through the programmable components (for example, the CPLD in the micro board) in the other components after leaving the reset state, so as to pass the mainboard verification component in the mainboard.
- the second TPCM performs credible verification on the motherboard.
- the BMC on the micro board that has been out of the reset state can generate a main board control signal, and the control signal passes through the programmable components provided in the micro board. It is sent to the mainboard, and the mainboard controls the second TPCM to leave the reset state according to the control instruction, and the second TPCM performs credible verification on the mainboard.
- the programmable components in the micro board can be a complex programmable logic device CPLD or a field programmable logic gate array FPGA arranged in the micro board.
- the control command received in the mainboard may be a complex programmable logic device CPLD disposed in the mainboard, and then the CPLD on the mainboard controls the second TPCM to leave the reset state according to the control signal, and starts to perform credible verification on the mainboard.
- the process of the second TPCM's credible verification of the motherboard is as follows:
- the second TPCM reads the firmware in the mainboard, and performs credible verification on the firmware in the mainboard, wherein the firmware in the mainboard includes the firmware of the basic input output system BIOS of the mainboard and the baseboard management of the mainboard The firmware of the controller BMC.
- the calculated firmware metric value is consistent with the value pre-stored in the second TPCM, the verification is passed.
- the second TPCM sends out a control signal to control the BIOS and BMC of the mainboard to leave the reset state and start loading the verified firmware. Further, the second TPCM is switched to the serial peripheral device interface SPI slave mode, the main board communicates with the SPI master control of the PCH, and the peripheral devices in the main board and the preset main board information are credibly verified , after the verification of the peripheral device and the mainboard information is passed, the second TPCM performs credible verification on the code of the operating system on the mainboard, and starts the system after the verification is passed.
- the micro-board when the system is powered on and started, firstly based on the first trusted platform control module TPCM on the micro-board, the micro-board itself is trusted to verify, and after the verification is passed, the micro-board is controlled
- the other components in the device are released from the reset state to work normally, and then the mainboard is credibly verified by the mainboard verification component used for credible verification of the mainboard, so as to realize the comprehensive credible verification of the system when the system is started.
- the startup process of the system can be interrupted to maintain the safe operating environment of the system.
- the FPGA in the micro board can also monitor the information in the memory of the main board to determine whether the content running in the main board is credible.
- the information in the memory of the motherboard may include the name of the running process, the number of the process, the space occupied by the process, the interface called by the process, and so on.
- monitoring the information in the memory by the FPGA may include determining the obtained hash value of the information in the memory; and matching the hash value of the information in the memory with the hash value pre-stored in the FPGA.
- the pre-stored hash value may be a hash value corresponding to the names or identifiers of some dangerous processes that adversely affect the security of data or programs on the motherboard, which is equivalent to a blacklist. Therefore, if the relevant hash value of a process in the memory on the motherboard is the same as the pre-stored hash value, it can be considered that some processes with security risks are running on the device where the motherboard is located; or, the pre-stored hash value is The value can also be the hash value corresponding to the name or identifier of the confirmed security process, which is equivalent to a white list, so if the relevant hash value of a process exists in the memory on the motherboard and the pre-stored hash value is different.
- the process can be considered to be a process with a security risk. Further, corresponding monitoring can be performed on the process that has security risks, or the micro-board can be called to forcibly close the process, so as to realize the maintenance of a dynamic security environment.
- the motherboard in the system may be a server motherboard.
- the FPGA module in the micro board of the system is used to perform credible verification on the main board, which specifically includes:
- the system is powered on and starts;
- the system includes a micro board and a main board.
- the first TPCM in the micro board is powered on and works, and the rest of the components are in a reset state;
- the first TPCM verifies the BIOS of the micro board and the firmware in the BMC;
- the verification is passed, the SOC and BMC on the micro board are out of the reset state, and the SOC and BMC on the micro board are loaded with firmware;
- the first TPCM switches to the slave mode, and verifies the peripherals of the micro board and the information of the micro board;
- the verification is passed, and the first TPCM verifies the system code of the SOC;
- the verification is passed, and the FPGA on the micro board verifies the BIOS of the main board and the firmware in the BMC;
- the verification is passed, the BIOS and BMC on the motherboard are out of the reset state, and the BIOS and BMC on the motherboard are loaded with firmware;
- the FPGA is switched to the slave mode, and the peripherals and mainboard information of the mainboard are verified;
- the verification is passed, and the FPGA verifies the code of the operating system on the motherboard;
- the verification is passed, the mainboard loads the code of the operating system on the mainboard, and the device starts.
- the FPGA can also monitor the memory information in the mainboard to realize dynamic monitoring of the security environment of the system.
- FIG. 1D is a schematic structural diagram of a credibly verified mainboard provided by an embodiment of the application, and the mainboard includes complex Programmable logic device CPLD and second trusted platform control module TPCM;
- the CPLD receives the control signal from the micro card that has passed the credible verification, and controls the second TPCM to leave the reset state;
- the second TPCM performs credible verification on the motherboard.
- FIG. 1E is a schematic structural diagram of a trusted verification micro board provided by an embodiment of the application, and the The micro board is connected to the main board (not shown in the figure), and the micro board includes a first trusted platform control module TPCM;
- the first TPCM When the device is powered on and started, the first TPCM performs credible verification on the micro-board, and after the credible verification of the micro-board is passed, controls other components to leave the reset state, and is used to verify the main board.
- the mainboard verification component that performs credible verification performs credible verification on the mainboard.
- the main board verification component includes a field programmable logic gate array FPGA arranged in a micro board, and/or a complex programmable logic device CPLD.
- a server including: the main board for credible verification as described in the second aspect;
- the server it also includes the trusted verification micro board as described in the third aspect.
- a fifth aspect of the embodiments of the present application further provides a credible verification method, which is applied to a system including a main board and a micro board, as shown in FIG. 3 , which is a reliable verification method provided by the embodiments of the present application.
- a schematic flowchart of a method for letter verification, the method specifically includes:
- the trusted verification of the micro board may be performed by using the first TPCM in the micro board to perform trusted verification on the micro board;
- the first TPCM controls other components in the micro board and the mainboard verification component to leave the reset state after the trusted verification of the micro board is passed, and passes all the components after leaving the reset state.
- the motherboard verification component performs credible verification on the motherboard;
- the main board verification component in the micro board includes a field programmable logic gate array FPGA arranged in the micro board, and the FPGA is connected to the main board; the micro board passes the The FPGA performs credible verification of the motherboard.
- FPGA field programmable logic gate array
- the first TPCM controls other components in the micro board to leave the reset state after passing the trusted verification of the micro board, and controls other components in the other components after leaving the reset state.
- the programming component enables the mainboard verification component in the mainboard to perform credible verification on the mainboard through the mainboard verification component in the mainboard.
- the mainboard verification component in the mainboard includes the second TPCM in the mainboard; the micro-board card performs an enabling operation on the mainboard verification component in the mainboard through the programmable component to pass all
- the second TPCM in the motherboard performs credible verification on the motherboard.
- the micro board sends a control instruction to the main board through a programmable component provided in the micro board; the main board controls the second TPCM to leave the reset state according to the control instruction, and The main board is credibly verified through the second TPCM.
- the programmable components include: a complex programmable logic device CPLD and/or a field programmable logic gate array FPGA.
- the micro board also includes a basic input output system BIOS and a baseboard management controller BMC, and performing credible verification on the micro board includes reading firmware, and performing credible verification on the firmware, wherein , the firmware includes the firmware in the basic input output system BIOS of the micro board and the firmware in the BMC of the micro board.
- performing credible verification on the firmware includes: confirming that the hash value of the firmware is matched with a pre-stored hash value, and if the two are consistent, confirming that the firmware is credible.
- the SOC and the BMC are controlled to leave the reset state; correspondingly, the SOC loads the firmware in the BIOS, and the BMC loads the Firmware in BMC;
- performing credible verification on the micro board includes: switching the first TPCM to the serial peripheral device interface SPI slave mode, and verifying the peripheral devices on the micro board and the preset micro board. information for trusted verification.
- the peripheral devices on the micro-board and the preset micro-board information pass the credible verification; perform credible verification on the system code of the SOC, and after the verification is passed, the SOC loads the Describe the system code of the SOC.
- performing credible verification on the mainboard includes: obtaining firmware in the mainboard, and performing credible verification on the firmware in the mainboard, wherein the firmware in the mainboard includes the basic input output system of the mainboard The firmware of the BIOS and the firmware of the baseboard management controller BMC of the motherboard.
- controlling the mainboard to get out of the reset state includes: after the firmware in the mainboard is credibly verified and passed, controlling the BIOS and BMC of the mainboard to get out of the reset state
- the platform controller hub PCH of the mainboard loads the firmware in the BIOS of the mainboard
- the BMC of the mainboard loads the firmware in the BMC of the mainboard.
- performing credible verification on the mainboard includes: performing credible verification on peripheral devices in the mainboard and preset mainboard information.
- the information in the memory of the motherboard is acquired, and the information in the memory is monitored.
- monitoring the information in the memory includes: determining a hash value of the code of the information in the memory obtained; comparing the hash value of the code of the information in the memory with a pre-stored hash value. to match.
- the micro board when the system is powered on and started, the micro board is powered on and started before the main board, and before the trusted verification of the micro board is passed, the main board remains in a reset state; accordingly, After the credible verification of the micro-board card is passed, the micro-board card controls the passing mainboard to leave the reset state.
- the motherboard is a server motherboard.
- the micro-board when the system is powered on and started, firstly based on the first trusted platform control module TPCM on the micro-board, the micro-board itself is trusted to verify, and after the verification is passed, the micro-board is controlled
- the other components in the system are out of the reset state to work normally, and then the mainboard is credibly verified by the mainboard verification component used for credible verification of the mainboard, so as to realize the comprehensive credible verification of the system when the system is started.
- a computer storage medium is further provided on which a computer program is stored, and when the program is executed by a processor, the method for trusted verification as described in FIG. 3 is implemented.
- each component/step described in the embodiments of the present application may be split into more components/steps, or two or more components/steps or part of operations of components/steps may be combined into New components/steps to achieve the purpose of the embodiments of the present application.
- the above-mentioned methods according to the embodiments of the present application can be implemented in hardware, firmware, or as software or computer codes that can be stored in a recording medium (such as CD ROM, RAM, floppy disk, hard disk, or magneto-optical disk), or implemented through Network downloaded computer code originally stored in a remote recording medium or non-transitory machine-readable medium and will be stored in a local recording medium so that the methods described herein can be stored on a computer using a general purpose computer, special purpose processor or programmable or such software processing on a recording medium of dedicated hardware such as ASIC or FPGA.
- a recording medium such as CD ROM, RAM, floppy disk, hard disk, or magneto-optical disk
- Network downloaded computer code originally stored in a remote recording medium or non-transitory machine-readable medium and will be stored in a local recording medium so that the methods described herein can be stored on a computer using a general purpose computer, special purpose processor or programmable or such software processing on a recording medium of dedicated hardware such as A
- a computer, processor, microprocessor controller or programmable hardware includes storage components (eg, RAM, ROM, flash memory, etc.) that can store or receive software or computer code, when the software or computer code is executed by a computer, When accessed and executed by a processor or hardware, a method of trusted authentication as described herein is achieved. Furthermore, when a general purpose computer accesses code for implementing the method of trusted verification shown herein, execution of the code converts the general purpose computer into a special purpose computer for performing the method of trusted verification shown herein.
- storage components eg, RAM, ROM, flash memory, etc.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Stored Programmes (AREA)
Abstract
Description
Claims (31)
- 一种可信验证的系统,包括:主板;和,微型板卡,所述微型板卡连接所述主板,所述微型板卡中包括第一可信平台控制模块TPCM;当所述系统通电启动时,第一TPCM,对所述微型板卡进行可信验证;并在所述微型板卡的可信验证通过后,控制所述微型板卡的其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
- 如权利要求1所述的系统,其中,所述第一TPCM在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件和所述主板验证部件脱离复位状态,并通过脱离复位状态后的所述主板验证部件对所述主板进行可信验证。
- 如权利要求2所述的系统,其中,所述微型板卡中的所述主板验证部件包括设置于所述微型板卡中的现场可编程逻辑门阵列FPGA,所述FPGA连接所述主板;所述微型板卡通过所述FPGA对所述主板进行可信验证。
- 如权利要求1所述的系统,其中,所述第一TPCM在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态,并通过脱离复位状态后的所述其它部件中的可编程部件对所述主板中的主板验证部件进行使能操作,以通过所述主板中的主板验证部件对所述主板进行可信验证。
- 如权利要求4所述的系统,其中,所述主板中的主板验证部件包括所述主板中的第二TPCM;所述微型板卡通过所述可编程部件对所述主板中的主板验证部件进行使能操作,以通过所述主板中的第二TPCM对所述主板进行可信验证。
- 如权利要求5所述的系统,其中,所述微型板卡通过设置于所述微型板卡中的可编程部件发送控制指令至所述主板;所述主板根据所述控制指令,控制所述第二TPCM脱离复位状态,并通过所述第二TPCM对所述主板进行可信验证。
- 如权利要求4-6任一项所述的系统,其中,所述可编程部件包括:复杂可编程逻辑器件CPLD和/或现场可编程逻辑门阵列FPGA。
- 如权利要求1所述的系统,其中,所述微型板卡中还包括基本输入输出系统BIOS和基板管理控制器BMC;所述第一TPCM,对所述微型板卡进行可信验证,包括:所述第一TPCM读取固件,对所述固件进行可信验证,其中,所述固件包括所述微型板卡的基本输入输出系统BIOS中的固件和所述微型板卡的BMC中的固件。
- 如权利要求8所述的系统,其中,所述第一TPCM读取固件,对所述固件进行可信验证,包括:所述第一TPCM读取固件,确认所述固件的哈希值,与预存于所述第一TPCM中的哈希值进行匹配,若二者一致,则确认所述固件可信。
- 如权利要求8所述的系统,其中,所述微型板卡中还包括片上系统SOC;当对所述固件进行可信验证通过后,所述第一TPCM控制所述SOC和所述BMC脱离复位状态;相应的,所述SOC加载所述BIOS中的固件,以及,所述BMC加载所述BMC中的固件。
- 如权利要求10所述的系统,其中,所述第一TPCM,对所述微型板卡进行可信验证,包括:所述第一TPCM切换为串行外围设备接口SPI从模式,对所述微型板卡上的外围设备和预设的微型板卡信息进行可信验证。
- 如权利要求11所述的系统,其中,当所述微型板卡上的外围设备和预设的微型板卡信息进行可信验证通过后,所述第一TPCM对所述SOC的系统代码进行可信验证,在验证通过后,所述SOC加载所述SOC的系统代码。
- 如权利要求3所述的系统,其中,所述微型板卡通过所述FPGA对所述主板进行可信验证包括:所述FPGA,获取所述主板中的固件,并对所述主板中的固件进行可信验证,其中主板中的固件包括所述主板的基本输入输出系统BIOS的固件和所述主板的基板管理控制器BMC的固件。
- 如权利要求13所述的系统,其中,所述FPGA还用于,对所述主板中的固件进行可信验证通过之后,控制所述主板的BIOS和BMC脱离复位状态;相应的,所述主板的平台控制器集线器PCH加载所述主板的BIOS中的固件,所述主板的BMC加载所述主板的BMC中的固件。
- 如权利要求14所述的系统,其中,所述微型板卡通过所述FPGA对所述主板进行可信验证,包括:所述FPGA,切换为串行外围设备接口SPI从模式,对所述主板上的外围设备和预设的主板信息进行可信验证。
- 如权利要求15所述的系统,其中,所述微型板卡通过所述FPGA对所述主板进行可信验证,包括:当对所述主板上的外围设备和预设的主板信息进行可信验证通过之后,所述FPGA,对所述主板上的操作系统的代码进行可信验证。
- 如权利要求3所述的系统,其中,所述FPGA还用于,获取所述主板的内存中的信息,对所述内存中的信息进行监测。
- 如权利要求17所述的系统,其中,所述FPGA还用于,对所述内存中的信息进 行监测,包括:确定获取得到的内存中的信息的哈希值;将所述内存中的信息的哈希值与FPGA中预存的哈希值进行匹配。
- 如权利要求5所述的系统,其中,所述微型板卡通过所述其它部件控制所述主板中的第二TPCM对所述主板进行可信验证,包括:所述第二TPCM,读取所述主板中的固件,并对所述主板中的固件进行可信验证,其中主板中的固件包括所述主板的基本输入输出系统BIOS的固件和所述主板的基板管理控制器BMC的固件。
- 如权利要求19所述的系统,其中,所述第二TPCM还用于,对所述主板中的固件进行可信验证通过之后,控制所述主板的BIOS和BMC脱离复位状态。
- 如权利要求19所述的系统,其中,所述微型板卡通过所述其它部件控制所述主板中的第二TPCM对所述主板进行可信验证,包括:所述第二TPCM,切换为串行外围设备接口SPI从模式,对所述主板中的外围设备和预设的主板信息进行可信验证。
- 如权利要求21所述的系统,其中,所述微型板卡通过所述其它部件控制所述主板中的所述第二TPCM对所述主板进行可信验证,包括:当对所述主板中的外围设备和预设的主板信息进行可信验证通过之后,所述第二TPCM,对所述主板上的操作系统的代码进行可信验证。
- 如权利要求1所述的系统,其中,当所述系统通电启动时,包括:当所述系统通电启动时,所述微型板卡先于所述主板通电启动,且,在所述微型板卡的可信验证通过之前,所述主板保持复位状态;相应的,在所述微型板卡的可信验证通过后,所述微型板卡控制所述通过主板脱离复位状态。
- 如权利要求1所述的系统,其中,所述主板为服务器主板。
- 一种可信验证的主板,所述主板中包括复杂可编程逻辑器件CPLD和第二可信平台控制模块TPCM;所述CPLD接收来自于已经通过可信验证的微型板卡的控制信号,并控制第二TPCM脱离复位状态;所述第二TPCM对所述主板进行可信验证。
- 一种可信验证的微型板卡,所述微型板卡连接主板,所述微型板卡中包括第一可信平台控制模块TPCM;当设备通电启动时,第一TPCM,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
- 如权利要求26所述的微型板卡,其中,所述主板验证部件包括现场可编程逻辑 门阵列FPGA,和/或,复杂可编程逻辑器件CPLD。
- 一种服务器,包括:如权利要求25所述的主板。
- 如权利要求28所述的服务器,其中,所述服务器还包括:如权利要求26或27所述的微型板卡。
- 一种可信验证的方法,应用于包含主板和微型板卡的系统中,所述方法包括:当所述系统通电启动时,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
- 一种计算机存储介质,其上存储有计算机程序,该程序被处理器执行时实现如权利要求30所述的可信验证的方法。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US18/026,582 US12393692B2 (en) | 2020-09-16 | 2021-09-09 | Trusted authentication system, method, mainboard, micro board, and storage medium |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202010982939.8 | 2020-09-16 | ||
| CN202010982939.8A CN113420297B (zh) | 2020-09-16 | 2020-09-16 | 一种可信验证的系统、方法、主板、微型板卡及存储介质 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022057720A1 true WO2022057720A1 (zh) | 2022-03-24 |
Family
ID=77711557
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2021/117387 Ceased WO2022057720A1 (zh) | 2020-09-16 | 2021-09-09 | 一种可信验证的系统、方法、主板、微型板卡及存储介质 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US12393692B2 (zh) |
| CN (1) | CN113420297B (zh) |
| WO (1) | WO2022057720A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116467721A (zh) * | 2023-05-25 | 2023-07-21 | 合芯科技(苏州)有限公司 | Cpld的校验方法、装置、服务器启动方法及服务器 |
| CN118860507A (zh) * | 2024-09-23 | 2024-10-29 | 山东云海国创云计算装备产业创新中心有限公司 | 业务交互系统、方法、存储介质、电子设备 |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114692159A (zh) * | 2020-12-29 | 2022-07-01 | 华为技术有限公司 | 计算机系统、可信功能组件及运行方法 |
| CN114090488A (zh) * | 2021-11-11 | 2022-02-25 | 深圳市同泰怡信息技术有限公司 | 可信度量扩展板、基本输入输出系统以及可信度量方法和装置 |
| CN114185526B (zh) * | 2021-11-15 | 2025-06-10 | 山东浪潮科学研究院有限公司 | 多微波源板卡的控制方法及系统 |
| CN114357536A (zh) * | 2021-12-24 | 2022-04-15 | 锋微固件(深圳)有限公司 | 一种基于国产飞腾平台板卡bios防护系统 |
| CN115391769A (zh) * | 2022-08-09 | 2022-11-25 | 支付宝(杭州)信息技术有限公司 | 一种用于安全验证的主板以及安全验证方法、装置及介质 |
| CN116340953A (zh) * | 2023-03-20 | 2023-06-27 | 南京南瑞继保电气有限公司 | 多cpu板卡的嵌入式装置的可信应用方法及嵌入式装置 |
| CN121188799B (zh) * | 2025-11-20 | 2026-03-03 | 苏州元脑智能科技有限公司 | 基板管理控制器、电子设备及启动方法 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20060224878A1 (en) * | 2005-03-31 | 2006-10-05 | Intel Corporation | System and method for trusted early boot flow |
| CN109753804A (zh) * | 2018-12-26 | 2019-05-14 | 北京可信华泰信息技术有限公司 | 一种可信系统 |
| CN111008379A (zh) * | 2019-11-22 | 2020-04-14 | 腾讯科技(深圳)有限公司 | 电子设备的固件安全检测方法及相关设备 |
Family Cites Families (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8245053B2 (en) * | 2009-03-10 | 2012-08-14 | Dell Products, Inc. | Methods and systems for binding a removable trusted platform module to an information handling system |
| CN102279914B (zh) * | 2011-07-13 | 2014-08-06 | 中国人民解放军海军计算技术研究所 | 一种uefi可信支撑系统及其控制方法 |
| US20140292475A1 (en) * | 2011-10-31 | 2014-10-02 | Jun Guo | Personal mini-intelligent terminal with combined verification electronic lock |
| KR102253592B1 (ko) * | 2014-12-23 | 2021-05-18 | 삼성전자주식회사 | 초기 문턱 전압 분포 변화를 보상할 수 있는 데이터 저장 장치, 이의 작동 방법, 및 이를 포함하는 데이터 처리 시스템 |
| CN105930732B (zh) * | 2016-04-12 | 2018-11-06 | 中国电子科技集团公司第五十四研究所 | 一种适合vpx设备业务板卡的可信启动方法 |
| CN106022137B (zh) * | 2016-05-10 | 2018-11-13 | 北京新云东方系统科技有限责任公司 | 由tpcm控制power平台可信的实现方法及系统 |
| CN110119623A (zh) * | 2018-02-06 | 2019-08-13 | 北京可信华泰信息技术有限公司 | 一种利用tpcm实现固件主动度量的可信主板实现方法 |
| CN110119638A (zh) * | 2018-02-06 | 2019-08-13 | 威海创事特信息科技发展有限公司 | 一种可信度量方法 |
| CN109670349B (zh) * | 2018-12-13 | 2021-10-01 | 英业达科技有限公司 | 可信计算机的硬件架构及计算机的可信启动方法 |
| CN111625831B (zh) * | 2019-02-28 | 2023-05-30 | 阿里巴巴集团控股有限公司 | 可信安全的度量方法和装置 |
| CN110096887B (zh) * | 2019-03-22 | 2020-06-30 | 阿里巴巴集团控股有限公司 | 一种可信计算方法及服务器 |
| CN110321715A (zh) * | 2019-07-08 | 2019-10-11 | 北京可信华泰信息技术有限公司 | 可信度量方法、装置及处理器 |
| CN114428958A (zh) * | 2021-12-17 | 2022-05-03 | 阿里巴巴(中国)有限公司 | 具有外接板卡的主机的可信度量方法和主机 |
-
2020
- 2020-09-16 CN CN202010982939.8A patent/CN113420297B/zh active Active
-
2021
- 2021-09-09 WO PCT/CN2021/117387 patent/WO2022057720A1/zh not_active Ceased
- 2021-09-09 US US18/026,582 patent/US12393692B2/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20060224878A1 (en) * | 2005-03-31 | 2006-10-05 | Intel Corporation | System and method for trusted early boot flow |
| CN109753804A (zh) * | 2018-12-26 | 2019-05-14 | 北京可信华泰信息技术有限公司 | 一种可信系统 |
| CN111008379A (zh) * | 2019-11-22 | 2020-04-14 | 腾讯科技(深圳)有限公司 | 电子设备的固件安全检测方法及相关设备 |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116467721A (zh) * | 2023-05-25 | 2023-07-21 | 合芯科技(苏州)有限公司 | Cpld的校验方法、装置、服务器启动方法及服务器 |
| CN116467721B (zh) * | 2023-05-25 | 2023-11-24 | 合芯科技(苏州)有限公司 | Cpld的校验方法、装置、服务器启动方法及服务器 |
| CN118860507A (zh) * | 2024-09-23 | 2024-10-29 | 山东云海国创云计算装备产业创新中心有限公司 | 业务交互系统、方法、存储介质、电子设备 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20240028738A1 (en) | 2024-01-25 |
| CN113420297A (zh) | 2021-09-21 |
| US12393692B2 (en) | 2025-08-19 |
| CN113420297B (zh) | 2025-07-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2022057720A1 (zh) | 一种可信验证的系统、方法、主板、微型板卡及存储介质 | |
| US11579893B2 (en) | Systems and methods for separate storage and use of system BIOS components | |
| US8544092B2 (en) | Integrity verification using a peripheral device | |
| US9886580B2 (en) | Method for optimizing boot time of an information handling system | |
| CN101438241B (zh) | 具有桥支持的平台引导 | |
| US11263326B2 (en) | Method and apparatus for secure system boot | |
| CN114817105B (zh) | 设备枚举的方法、装置、计算机设备以及存储介质 | |
| CN101221509B (zh) | 可信嵌入式系统总线仲裁启动方法 | |
| CN106462711B (zh) | 经验证启动 | |
| US20210365563A1 (en) | Split chain of trust for secure device boot | |
| CN119861985B (zh) | 服务器的启动方法、设备、存储介质及程序产品 | |
| CN114008617A (zh) | 固件防回滚 | |
| US8140835B2 (en) | Updating a basic input/output system (‘BIOS’) boot block security module in compute nodes of a multinode computer | |
| EP4172828B1 (en) | Static configuration of accelerator card security modes | |
| CN114077738A (zh) | 快速外设组件互联设备启动方法、装置以及存储介质 | |
| CN113901473B (zh) | 一种服务器安全启动的方法、装置、设备及可读介质 | |
| CN118567728A (zh) | 获取热键信息的方法及装置、计算机程序产品 | |
| CN115421793A (zh) | 一种启动状态的显示方法及计算设备 | |
| US8056127B2 (en) | Accessing password protected devices | |
| CN116881929B (zh) | 安全防护方法、装置、电子设备以及基板控制器芯片 | |
| CN118626110A (zh) | 一种固件升级系统、方法及相关设备 | |
| CN113626792B (zh) | PCIe Switch固件安全执行方法、装置、终端及存储介质 | |
| HK40059916A (zh) | 一种可信验证的系统、方法、主板、微型板卡及存储介质 | |
| US12572189B2 (en) | Customized thermal and power policies in computers | |
| WO2024045828A1 (zh) | 操作系统安全启动方法、操作系统安装方法及相关装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21868545 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18026582 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21868545 Country of ref document: EP Kind code of ref document: A1 |
|
| WWG | Wipo information: grant in national office |
Ref document number: 18026582 Country of ref document: US |