WO2022057720A1 - 一种可信验证的系统、方法、主板、微型板卡及存储介质 - Google Patents

一种可信验证的系统、方法、主板、微型板卡及存储介质 Download PDF

Info

Publication number
WO2022057720A1
WO2022057720A1 PCT/CN2021/117387 CN2021117387W WO2022057720A1 WO 2022057720 A1 WO2022057720 A1 WO 2022057720A1 CN 2021117387 W CN2021117387 W CN 2021117387W WO 2022057720 A1 WO2022057720 A1 WO 2022057720A1
Authority
WO
WIPO (PCT)
Prior art keywords
board
verification
mainboard
micro
tpcm
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2021/117387
Other languages
English (en)
French (fr)
Inventor
王晖
李志超
陈继承
黄子龙
吕涛
刘方
王志谦
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Priority to US18/026,582 priority Critical patent/US12393692B2/en
Publication of WO2022057720A1 publication Critical patent/WO2022057720A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/575Secure boot
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/572Secure firmware programming, e.g. of basic input output system [BIOS]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/85Protecting input, output or interconnection devices interconnection devices, e.g. bus-connected or in-line devices

Definitions

  • the embodiments of the present application relate to the field of computer technology, and in particular, to a system, method, motherboard, micro board, and storage medium for trusted verification.
  • the basic architecture of the current device is shown in Figure 1A.
  • the trusted platform control module (TPCM) on the main board is powered on first, and the firmware in the main board is credibly verified, and the high-speed serial expansion bus (peripheral component interconnect express, PCIE) has not been powered up yet.
  • PCIE peripheral component interconnect express
  • the embodiments of the present application provide a system, method, main board, micro board and storage medium for credible verification, so as to at least partially solve the above problems.
  • a trusted verification system including:
  • the miniature board is connected to the main board, and the miniature board includes a first trusted platform control module TPCM;
  • the first TPCM When the system is powered on and started, the first TPCM performs credible verification on the micro-board; and after the credible verification of the micro-board is passed, it controls other components of the system to leave the reset state, The mainboard is credibly verified by the mainboard verification component used for credible verification of the mainboard.
  • a mainboard for credible verification wherein the mainboard includes a complex programmable logic device CPLD and a second trusted platform control module TPCM;
  • the CPLD receives the control signal from the micro card that has passed the credible verification, and controls the second TPCM to leave the reset state;
  • the second TPCM performs credible verification on the motherboard.
  • a trusted verification mini-board is connected to a main board, and the mini-board includes a first trusted platform control module TPCM;
  • the first TPCM When the device is powered on and started, the first TPCM performs credible verification on the micro-board, and after the credible verification of the micro-board is passed, controls other components to leave the reset state, and is used to verify the main board.
  • the mainboard verification component that performs credible verification performs credible verification on the mainboard.
  • a server which includes the motherboard according to the second aspect.
  • a credible verification method is provided, which is applied to a system including a main board and a micro board, and the method includes:
  • a computer storage medium is provided on which a computer program is stored, and when the program is executed by a processor, the aforementioned method for trusted verification is implemented.
  • the micro-board when the system is powered on and started, firstly, based on the first trusted platform control module TPCM on the micro-board, the micro-board itself is credibly verified, and after the verification is passed, the micro-board is controlled. Other components in the card leave the reset state to work normally, and then the mainboard is authenticated credibly by the mainboard verification component in the system, so as to realize the comprehensive credible verification of the system when the system is started.
  • 1A is a schematic diagram of the architecture involved in the current system
  • 1B is a schematic diagram of a trusted verification system provided by an embodiment of the present application.
  • 1C is a schematic diagram of another trusted verification system provided by an embodiment of the present application.
  • FIG. 1D is a schematic structural diagram of a motherboard for credible verification provided by an embodiment of the present application.
  • FIG. 1E is a schematic structural diagram of a micro-board card for credible verification provided by an embodiment of the present application.
  • FIG. 2 is a schematic flowchart of trusted verification performed by a system according to an embodiment of the present application
  • FIG. 3 is a schematic flowchart of a credible verification method provided by an embodiment of the present application.
  • TPCM Trusted Platform Control Module, Trusted Platform Control Module.
  • the relevant information of the device can be pre-stored in the TPCM and used for trusted verification.
  • FPGA Field Programmable Logic Gate Array, Field Programmable Gate Array. It appears as a semi-custom circuit in the field of Application Specific Integrated Circuit (ASIC), with programmable and storable functions.
  • ASIC Application Specific Integrated Circuit
  • CPLD Complex Programmable Logic Device, Complex Programmable Logic Device. Users can construct digital integrated circuits with logic functions in CPLD according to their needs. For example, with the help of the integrated development software platform, the corresponding target files are generated by methods such as schematic diagram and hardware description language, and the code is transferred to the target chip to realize the designed digital system.
  • PCIE High-speed serial expansion bus standard, Peripheral Component Interconnect Express.
  • PCIE card is connected to the motherboard through the specification of PCIE.
  • FIG. 1A is a schematic diagram of the architecture involved in the current system.
  • the TPCM in the motherboard will be powered on first, but the PCIE card will not be powered on.
  • the firmware in the mainboard the system is started, but the firmware in the PCIE cannot be credibly verified.
  • Micro board It is a physical board device with its own CPU and ROM/RAM, which can run an independent operating system and can be connected to other hardware through the system bus to provide virtual input and output IO devices on the hardware. , IO request processing and forwarding services, the micro board can also contain programmable components CPLD, FPGA and so on.
  • CPLD programmable components
  • FPGA field-programmable gate array
  • MOC Microserver On Card
  • the first TPCM the TPCM in the mini board
  • Second TPCM TPCM in the motherboard.
  • the embodiments of the present application provide a system for trusted verification, which implements more comprehensive trusted verification during startup.
  • the system includes:
  • a mainboard a mainboard
  • a microserver microboard on the card the microboard is connected to the mainboard, and the microboard includes a first trusted platform control module TPCM;
  • the first TPCM When the system is powered on and started, the first TPCM performs credible verification on the micro board, and controls other components in the system to leave the reset state after the micro board passes the credible verification , and the mainboard is credibly verified through the mainboard verification component used for credible verification of the mainboard.
  • the micro board when the system is powered on and started, the micro board is powered on and started before the main board. Before the micro board completes the authentic verification, the main board (including the components in the main board) is kept in a reset state.
  • the first TPCM in the mini-board starts to work first, and other components in the mini-board are also in the reset state, waiting for the first TPCM to verify the micro-board. letter verification.
  • the first TPCM can directly control the components on the micro board (including other components in the micro board and the mainboard verification component) to disengage Reset state and perform trusted verification of the motherboard through the motherboard verification component.
  • the first TPCM can also indirectly control the components on the mainboard (including other components in the mainboard and the mainboard verification component) to leave the reset state through a corresponding control signal, so that the mainboard verification component starts to verify the mainboard. Carry out feasibility verification.
  • the first TPCM may enable the main board verification component in the main board through the programmable components located in the other components in the micro board, so as to The mainboard is credibly verified by the mainboard verification component in the mainboard.
  • the programmable components in the other components in the micro board can be complex programmable logic devices CPLD and/or field programmable logic gate array FPGA arranged in the micro board, and they can send commands to the CPLD in the main board.
  • the power signal enables the CPLD in the mainboard to activate the mainboard verification component in the mainboard, and perform credible verification of the mainboard.
  • the mainboard verification component that performs credible verification on the mainboard may be a component in a micro board, or a component in the mainboard.
  • the first TPCM can send an enable signal through the programmable component CPLD or FPGA in the micro board to control the CPLD on the main board to activate the second TPCM in the main board, so that the second TPCM can perform credible verification on the main board.
  • the mainboard verification component that performs credible verification on the mainboard may be an FPGA module disposed in a micro board.
  • FIG. 1B is a schematic diagram of a trusted verification system provided by an embodiment of the present application, and the device includes:
  • the FPGA is connected to the main board; specifically, the FPGA can be connected to all the Describe the CPU and CPLD in the motherboard.
  • the first TPCM When the system is powered on, the first TPCM performs credible verification on the micro-board, and controls other components in the micro-board to disengage after passing the credible verification of the micro-board reset state;
  • the FPGA is used to perform credible verification on the main board after the credible verification of the micro board is passed.
  • the first TPCM in the micro card will be powered on first, and act as a component for performing trusted authentication on the micro card.
  • other components including FPGA) on the micro board and components on the main board are in the reset state.
  • firmware in the micro board includes systems such as System on Chip (SOC), Basic Input Output System (BIOS), Baseboard Manager Controller (BMC), etc.
  • SOC System on Chip
  • BIOS Basic Input Output System
  • BMC Baseboard Manager Controller
  • some firmware or some system codes may exist in each component, and the trusted verification of the first TPCM to the micro board may include the trusted verification of the firmware or system codes of these components.
  • the first TPCM when the first TPCM is powered on, it is first in the Serial Peripheral Interface (SPI) master mode.
  • SPI Serial Peripheral Interface
  • the BIOS and BMC of the micro board can be read based on the SPI master interface. firmware, and perform trusted verification of firmware in BIOS and BMC.
  • the first TPCM may pre-store a trusted metric root in a register of the first TPCM (for example, a hash value of firmware pre-obtained by trusted hardware, or a pre-stored trusted partial code of a specified location of firmware)
  • the specific verification method can be that the first TPCM confirms the firmware metric value of the firmware (that is, the hash value of the firmware, or the code of the specified position of the firmware), and matches the firmware metric value with the pre-stored trusted metric root, if If the two are consistent, it is confirmed that the firmware is trustworthy.
  • the first TPCM can send the SOC reset failure signal and the BMC reset failure signal, so that the SOC and the BMC leave the reset state and start to work normally, and the SOC starts to load the BIOS
  • the firmware in the BMC starts to load the firmware in the BMC.
  • the first TPCM switches to the SPI slave mode, starts to communicate with the SPI master process of the SOC, and passively accepts the peripheral devices connected to the micro board and the preset micro board information. And information about peripherals and preset micro boards.
  • the specific peripheral devices may include the model, unique identifier, name, etc. of the peripheral devices connected to the mini-board, and the mini-board information may include firmware codes and SOC versions of the peripherals connected to the mini-board.
  • the first TPCM can perform credible verification on the system code of the SOC. After the system code of the operating system of the SOC is credibly verified, it means that the micro board itself is trusted. At this time, the SOC loads the system code of the SOC to complete the startup of the micro board. .
  • the manner of performing credible verification on peripheral devices, preset micro-board card information, and the system code of the SOC is similar to the manner in which trusted verification is performed on firmware in the micro-board card, and will not be repeated here.
  • the FPGA After the trusted verification is completed for the micro board, the FPGA has been instructed by the first TPCM to leave the reset state, and starts to work normally, and is used as the main function module to realize the trusted verification of the motherboard. Components are still in reset.
  • the mainboard includes the BIOS and BMC in the mainboard, and components such as the operating system that exist on the mainboard.
  • the FPGA performs credible verification on the mainboard, which may include operations on the BIOS, BMC and the mainboard.
  • the system performs trusted verification.
  • the SPI master device on the FPGA can obtain the firmware in the main board, and the The firmware in the main board is credibly verified, wherein the firmware in the main board includes the firmware of the basic input output system BIOS of the main board and the firmware of the baseboard management controller BMC of the main board.
  • the specific verification method is similar to the previous one.
  • the FPGA can pre-store a trusted measurement root (for example, the hash value of the firmware pre-obtained by the trusted hardware, or the pre-stored trusted partial code of the specified location of the firmware),
  • the specific verification method can be that the FPGA confirms the firmware metric value of the firmware on the motherboard (that is, the hash value of the firmware, or the code of the specified location of the firmware), and matches the firmware metric value with the pre-stored trusted metric root, if If the two are consistent, it is confirmed that the firmware on the motherboard is credible.
  • the FPGA After the FPGA carries out credible verification to the firmware in the mainboard, the FPGA sends a reset failure signal of the BMC and BIOS on the mainboard, and controls the BIOS and BMC of the mainboard to leave the reset state, while the platform of the mainboard Controller hub (Platform Controller Hub, PCH, also known as integrated south bridge) loads the firmware in the BIOS of the mainboard, and the BMC of the mainboard loads the firmware in the BMC of the mainboard.
  • PCH Planform Controller Hub
  • the FPGA switches to the serial peripheral device interface SPI slave mode, and performs credible verification on the peripheral devices in the mainboard and preset mainboard information.
  • the peripheral devices in the motherboard may include the model, unique identifier, name, etc. of the peripheral devices connected to the motherboard, and the preset motherboard information may include the firmware code of each peripheral device connected to the motherboard, the version of the operating system on the motherboard, etc. Wait.
  • the FPGA performs credible verification on the peripheral devices in the mainboard and the preset mainboard information
  • the FPGA performs credible verification on the code of the operating system on the mainboard, and after the verification is passed, the mainboard
  • the code of the operating system on the motherboard is loaded, thereby constructing the hardware trusted environment of the entire system.
  • FIG. 1C A schematic diagram of a system comprising:
  • micro-server micro-board card on the card, the micro-board card includes a first trusted platform control module TPCM, and the main board includes a second trusted platform control module TPCM;
  • the first TPCM When the system is powered on, the first TPCM performs credible verification on the micro-board, and controls other components in the micro-board to disengage after passing the credible verification of the micro-board reset state, and enable the mainboard verification component in the mainboard through the programmable components (for example, the CPLD in the micro board) in the other components after leaving the reset state, so as to pass the mainboard verification component in the mainboard.
  • the second TPCM performs credible verification on the motherboard.
  • the BMC on the micro board that has been out of the reset state can generate a main board control signal, and the control signal passes through the programmable components provided in the micro board. It is sent to the mainboard, and the mainboard controls the second TPCM to leave the reset state according to the control instruction, and the second TPCM performs credible verification on the mainboard.
  • the programmable components in the micro board can be a complex programmable logic device CPLD or a field programmable logic gate array FPGA arranged in the micro board.
  • the control command received in the mainboard may be a complex programmable logic device CPLD disposed in the mainboard, and then the CPLD on the mainboard controls the second TPCM to leave the reset state according to the control signal, and starts to perform credible verification on the mainboard.
  • the process of the second TPCM's credible verification of the motherboard is as follows:
  • the second TPCM reads the firmware in the mainboard, and performs credible verification on the firmware in the mainboard, wherein the firmware in the mainboard includes the firmware of the basic input output system BIOS of the mainboard and the baseboard management of the mainboard The firmware of the controller BMC.
  • the calculated firmware metric value is consistent with the value pre-stored in the second TPCM, the verification is passed.
  • the second TPCM sends out a control signal to control the BIOS and BMC of the mainboard to leave the reset state and start loading the verified firmware. Further, the second TPCM is switched to the serial peripheral device interface SPI slave mode, the main board communicates with the SPI master control of the PCH, and the peripheral devices in the main board and the preset main board information are credibly verified , after the verification of the peripheral device and the mainboard information is passed, the second TPCM performs credible verification on the code of the operating system on the mainboard, and starts the system after the verification is passed.
  • the micro-board when the system is powered on and started, firstly based on the first trusted platform control module TPCM on the micro-board, the micro-board itself is trusted to verify, and after the verification is passed, the micro-board is controlled
  • the other components in the device are released from the reset state to work normally, and then the mainboard is credibly verified by the mainboard verification component used for credible verification of the mainboard, so as to realize the comprehensive credible verification of the system when the system is started.
  • the startup process of the system can be interrupted to maintain the safe operating environment of the system.
  • the FPGA in the micro board can also monitor the information in the memory of the main board to determine whether the content running in the main board is credible.
  • the information in the memory of the motherboard may include the name of the running process, the number of the process, the space occupied by the process, the interface called by the process, and so on.
  • monitoring the information in the memory by the FPGA may include determining the obtained hash value of the information in the memory; and matching the hash value of the information in the memory with the hash value pre-stored in the FPGA.
  • the pre-stored hash value may be a hash value corresponding to the names or identifiers of some dangerous processes that adversely affect the security of data or programs on the motherboard, which is equivalent to a blacklist. Therefore, if the relevant hash value of a process in the memory on the motherboard is the same as the pre-stored hash value, it can be considered that some processes with security risks are running on the device where the motherboard is located; or, the pre-stored hash value is The value can also be the hash value corresponding to the name or identifier of the confirmed security process, which is equivalent to a white list, so if the relevant hash value of a process exists in the memory on the motherboard and the pre-stored hash value is different.
  • the process can be considered to be a process with a security risk. Further, corresponding monitoring can be performed on the process that has security risks, or the micro-board can be called to forcibly close the process, so as to realize the maintenance of a dynamic security environment.
  • the motherboard in the system may be a server motherboard.
  • the FPGA module in the micro board of the system is used to perform credible verification on the main board, which specifically includes:
  • the system is powered on and starts;
  • the system includes a micro board and a main board.
  • the first TPCM in the micro board is powered on and works, and the rest of the components are in a reset state;
  • the first TPCM verifies the BIOS of the micro board and the firmware in the BMC;
  • the verification is passed, the SOC and BMC on the micro board are out of the reset state, and the SOC and BMC on the micro board are loaded with firmware;
  • the first TPCM switches to the slave mode, and verifies the peripherals of the micro board and the information of the micro board;
  • the verification is passed, and the first TPCM verifies the system code of the SOC;
  • the verification is passed, and the FPGA on the micro board verifies the BIOS of the main board and the firmware in the BMC;
  • the verification is passed, the BIOS and BMC on the motherboard are out of the reset state, and the BIOS and BMC on the motherboard are loaded with firmware;
  • the FPGA is switched to the slave mode, and the peripherals and mainboard information of the mainboard are verified;
  • the verification is passed, and the FPGA verifies the code of the operating system on the motherboard;
  • the verification is passed, the mainboard loads the code of the operating system on the mainboard, and the device starts.
  • the FPGA can also monitor the memory information in the mainboard to realize dynamic monitoring of the security environment of the system.
  • FIG. 1D is a schematic structural diagram of a credibly verified mainboard provided by an embodiment of the application, and the mainboard includes complex Programmable logic device CPLD and second trusted platform control module TPCM;
  • the CPLD receives the control signal from the micro card that has passed the credible verification, and controls the second TPCM to leave the reset state;
  • the second TPCM performs credible verification on the motherboard.
  • FIG. 1E is a schematic structural diagram of a trusted verification micro board provided by an embodiment of the application, and the The micro board is connected to the main board (not shown in the figure), and the micro board includes a first trusted platform control module TPCM;
  • the first TPCM When the device is powered on and started, the first TPCM performs credible verification on the micro-board, and after the credible verification of the micro-board is passed, controls other components to leave the reset state, and is used to verify the main board.
  • the mainboard verification component that performs credible verification performs credible verification on the mainboard.
  • the main board verification component includes a field programmable logic gate array FPGA arranged in a micro board, and/or a complex programmable logic device CPLD.
  • a server including: the main board for credible verification as described in the second aspect;
  • the server it also includes the trusted verification micro board as described in the third aspect.
  • a fifth aspect of the embodiments of the present application further provides a credible verification method, which is applied to a system including a main board and a micro board, as shown in FIG. 3 , which is a reliable verification method provided by the embodiments of the present application.
  • a schematic flowchart of a method for letter verification, the method specifically includes:
  • the trusted verification of the micro board may be performed by using the first TPCM in the micro board to perform trusted verification on the micro board;
  • the first TPCM controls other components in the micro board and the mainboard verification component to leave the reset state after the trusted verification of the micro board is passed, and passes all the components after leaving the reset state.
  • the motherboard verification component performs credible verification on the motherboard;
  • the main board verification component in the micro board includes a field programmable logic gate array FPGA arranged in the micro board, and the FPGA is connected to the main board; the micro board passes the The FPGA performs credible verification of the motherboard.
  • FPGA field programmable logic gate array
  • the first TPCM controls other components in the micro board to leave the reset state after passing the trusted verification of the micro board, and controls other components in the other components after leaving the reset state.
  • the programming component enables the mainboard verification component in the mainboard to perform credible verification on the mainboard through the mainboard verification component in the mainboard.
  • the mainboard verification component in the mainboard includes the second TPCM in the mainboard; the micro-board card performs an enabling operation on the mainboard verification component in the mainboard through the programmable component to pass all
  • the second TPCM in the motherboard performs credible verification on the motherboard.
  • the micro board sends a control instruction to the main board through a programmable component provided in the micro board; the main board controls the second TPCM to leave the reset state according to the control instruction, and The main board is credibly verified through the second TPCM.
  • the programmable components include: a complex programmable logic device CPLD and/or a field programmable logic gate array FPGA.
  • the micro board also includes a basic input output system BIOS and a baseboard management controller BMC, and performing credible verification on the micro board includes reading firmware, and performing credible verification on the firmware, wherein , the firmware includes the firmware in the basic input output system BIOS of the micro board and the firmware in the BMC of the micro board.
  • performing credible verification on the firmware includes: confirming that the hash value of the firmware is matched with a pre-stored hash value, and if the two are consistent, confirming that the firmware is credible.
  • the SOC and the BMC are controlled to leave the reset state; correspondingly, the SOC loads the firmware in the BIOS, and the BMC loads the Firmware in BMC;
  • performing credible verification on the micro board includes: switching the first TPCM to the serial peripheral device interface SPI slave mode, and verifying the peripheral devices on the micro board and the preset micro board. information for trusted verification.
  • the peripheral devices on the micro-board and the preset micro-board information pass the credible verification; perform credible verification on the system code of the SOC, and after the verification is passed, the SOC loads the Describe the system code of the SOC.
  • performing credible verification on the mainboard includes: obtaining firmware in the mainboard, and performing credible verification on the firmware in the mainboard, wherein the firmware in the mainboard includes the basic input output system of the mainboard The firmware of the BIOS and the firmware of the baseboard management controller BMC of the motherboard.
  • controlling the mainboard to get out of the reset state includes: after the firmware in the mainboard is credibly verified and passed, controlling the BIOS and BMC of the mainboard to get out of the reset state
  • the platform controller hub PCH of the mainboard loads the firmware in the BIOS of the mainboard
  • the BMC of the mainboard loads the firmware in the BMC of the mainboard.
  • performing credible verification on the mainboard includes: performing credible verification on peripheral devices in the mainboard and preset mainboard information.
  • the information in the memory of the motherboard is acquired, and the information in the memory is monitored.
  • monitoring the information in the memory includes: determining a hash value of the code of the information in the memory obtained; comparing the hash value of the code of the information in the memory with a pre-stored hash value. to match.
  • the micro board when the system is powered on and started, the micro board is powered on and started before the main board, and before the trusted verification of the micro board is passed, the main board remains in a reset state; accordingly, After the credible verification of the micro-board card is passed, the micro-board card controls the passing mainboard to leave the reset state.
  • the motherboard is a server motherboard.
  • the micro-board when the system is powered on and started, firstly based on the first trusted platform control module TPCM on the micro-board, the micro-board itself is trusted to verify, and after the verification is passed, the micro-board is controlled
  • the other components in the system are out of the reset state to work normally, and then the mainboard is credibly verified by the mainboard verification component used for credible verification of the mainboard, so as to realize the comprehensive credible verification of the system when the system is started.
  • a computer storage medium is further provided on which a computer program is stored, and when the program is executed by a processor, the method for trusted verification as described in FIG. 3 is implemented.
  • each component/step described in the embodiments of the present application may be split into more components/steps, or two or more components/steps or part of operations of components/steps may be combined into New components/steps to achieve the purpose of the embodiments of the present application.
  • the above-mentioned methods according to the embodiments of the present application can be implemented in hardware, firmware, or as software or computer codes that can be stored in a recording medium (such as CD ROM, RAM, floppy disk, hard disk, or magneto-optical disk), or implemented through Network downloaded computer code originally stored in a remote recording medium or non-transitory machine-readable medium and will be stored in a local recording medium so that the methods described herein can be stored on a computer using a general purpose computer, special purpose processor or programmable or such software processing on a recording medium of dedicated hardware such as ASIC or FPGA.
  • a recording medium such as CD ROM, RAM, floppy disk, hard disk, or magneto-optical disk
  • Network downloaded computer code originally stored in a remote recording medium or non-transitory machine-readable medium and will be stored in a local recording medium so that the methods described herein can be stored on a computer using a general purpose computer, special purpose processor or programmable or such software processing on a recording medium of dedicated hardware such as A
  • a computer, processor, microprocessor controller or programmable hardware includes storage components (eg, RAM, ROM, flash memory, etc.) that can store or receive software or computer code, when the software or computer code is executed by a computer, When accessed and executed by a processor or hardware, a method of trusted authentication as described herein is achieved. Furthermore, when a general purpose computer accesses code for implementing the method of trusted verification shown herein, execution of the code converts the general purpose computer into a special purpose computer for performing the method of trusted verification shown herein.
  • storage components eg, RAM, ROM, flash memory, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Stored Programmes (AREA)

Abstract

本申请实施例提供了一种可信验证的系统、方法、主板、微型板卡及存储介质。根据本申请实施例提供的方案,系统在通电启动时,首先基于微型板卡上的第一可信平台控制模块TPCM对微型板卡本身进行可信验证,在验证通过之后,控制所述微型板卡中的其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。

Description

一种可信验证的系统、方法、主板、微型板卡及存储介质
本申请要求2020年09月16日递交的申请号为202010982939.8、发明名称为“一种可信验证的系统、方法、主板、微型板卡及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请实施例涉及计算机技术领域,尤其涉及一种可信验证的系统、方法、主板、微型板卡及存储介质。
背景技术
随着对信息安全要求的不断提高,在设备启动时对设备中的相关信息进行可信验证已经很有必要。当前的设备的基本架构如图1A所示。在启动时,主板上的可信平台控制模块(trusted platform control module,TPCM)首先上电工作,并对主板中的各固件进行可信验证,而同时高速串行扩展总线(peripheral component interconnect express,PCIE)还没有上电工作。在这种方式下,设备启动时仍然存在一些固件(例如,PCIE中的各固件)没有进行可信验证。
基于此,需要一种在设备启动时更为全面的可信验证方案。
发明内容
有鉴于此,本申请实施例提供一种可信验证的系统、方法、主板、微型板卡及存储介质,以至少部分解决上述问题。
根据本申请实施例的第一方面,提供了一种可信验证的系统,包括:
主板;和,
微型板卡,所述微型板卡连接所述主板,所述微型板卡中包括第一可信平台控制模块TPCM;
当所述系统通电启动时,所述第一TPCM,对所述微型板卡进行可信验证;并在所述微型板卡的可信验证通过后,控制所述系统的其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
根据本申请实施例的第二方面,提供了一种可信验证的主板,所述主板中包括复杂可编程逻辑器件CPLD和第二可信平台控制模块TPCM;
所述CPLD接收来自于已经通过可信验证的微型板卡的控制信号,并控制所述第二TPCM脱离复位状态;
所述第二TPCM对所述主板进行可信验证。
根据本申请实施例的第三方面,提供了一种可信验证的微型板卡,所述微型板卡连接主板,所述微型板卡中包括第一可信平台控制模块TPCM;
当设备通电启动时,所述第一TPCM,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制其它部件脱离复位状态,并通过用于对主板进行可信验 证的主板验证部件对所述主板进行可信验证。
根本本申请的第四方面,提供了一种服务器,所述服务器中包括如第二方面所述的主板。
根据本申请实施例的第五方面,提供了一种可信验证的方法,应用于包含主板和微型板卡的系统中,所述方法包括:
当所述系统通电启动时,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态;并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
根据本申请实施例的第六方面,提供了一种计算机存储介质,其上存储有计算机程序,该程序被处理器执行时实现如前述的可信验证的方法。
根据本申请实施例提供的方案,系统在通电启动时,首先基于微型板卡上的第一可信平台控制模块TPCM对微型板卡本身进行可信验证,在验证通过之后,控制所述微型板卡中的其它部件脱离复位状态,以正常工作,然后通过系统中的主板验证部件对主板进行可信验证,从而实现在系统启动时对于系统的全面的可信验证。
附图说明
为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请实施例中记载的一些实施例,对于本领域普通技术人员来讲,还可以根据这些附图获得其他的附图。
图1A为当前系统所涉及的架构示意图;
图1B为本申请实施例所提供的一种可信验证的系统的示意图;
图1C为本申请实施例所提供的另一种可信验证的系统的示意图;
图1D为本申请实施例所提供的一种可信验证的主板的结构示意图;
图1E为本申请实施例所提供的一种可信验证的微型板卡的结构示意图;
图2为本申请实施例所提供的一种系统进行可信验证的流程示意图;
图3为本申请实施例所提供的一种可信验证的方法的流程示意图。
具体实施方式
为了使本领域的人员更好地理解本申请实施例中的技术方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅是本申请实施例一部分实施例,而不是全部的实施例。基于本申请实施例中的实施例,本领域普通技术人员所获得的所有其他实施例,都应当属于本申请实施例保护的范围。
首先,在对本申请实施例进行描述的过程中出现的部分名词或术语适用于如下解释:
TPCM:可信平台控制模块,Trusted Platform Control Module。TPCM中可以预先存 储设备的相关信息,并用于可信验证。
FPGA:现场可编程逻辑门阵列,Field Programmable Gate Array。它是作为专用集成电路(Application Specific Integrated Circuit,ASIC)领域中的一种半定制电路而出现的,具备可编程和可存储功能。
CPLD:复杂可编程逻辑器件,Complex Programmable Logic Device。用户可以在CPLD中根据需要而自行构造逻辑功能的数字集成电路。例如,借助集成开发软件平台,用原理图、硬件描述语言等方法,生成相应的目标文件,将代码传送到目标芯片中,实现设计的数字系统。
PCIE:高速串行扩展总线标准,Peripheral Component Interconnect Express。在常规设备中,PCIE卡通过PCIE的规范与主板连接。
如图1A所示,图1A为当前系统所涉及的架构示意图。在这种情形下,系统通电启动时,主板中的TPCM会先上电工作,而PCIE卡不会上电。主板中的TPCM对于主板中的固件验证完毕之后,即启动系统,对于PCIE中的固件则无法进行可信验证。
微型板卡:即为自带CPU和ROM/RAM的物理板卡设备,能够运行独立的操作系统,同时可以通过系统总线连入到另外的硬件上,对该硬件上提供输入输出IO设备的虚拟、IO请求的处理和转发等服务,微型板卡上还可以包含可编程部件CPLD、FPGA等等。例如,卡上微型服务器(Microserver On Card,MOC)即为微型板卡的一种。
第一TPCM:处于微型板卡中的TPCM;
第二TPCM:处于主板中的TPCM。
基于前述,本申请实施例提供一种可信验证的系统,在启动时实现更为全面的可信验证。所述系统包括:
主板;和,卡上微型服务器微型板卡,所述微型板卡连接所述主板,所述微型板卡中包括第一可信平台控制模块TPCM;
当所述系统通电启动时,所述第一TPCM,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制所述系统中的其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
具体而言,在系统通电启动时,微型板卡先于主板进行通电启动。在微型板卡完成可信验证之前,所述主板(包括主板中的各部件)一直保持复位状态。
在微型板卡进行可信验证的流程中,微型板卡中的第一TPCM最先开始工作,此时微型板卡中的其它部件也处于复位状态,并等待第一TPCM对微型板卡进行可信验证。
在一种实施例中,在对于所述微型板卡的可信验证通过后,所述第一TPCM可以直接控制微型板卡上的部件(包括微型板卡中的其它部件和主板验证部件)脱离复位状态,并通过主板验证部件执行对主板的可信验证。
在一种实施例中,第一TPCM也可以通过相应的控制信号,来间接的控制主板上的 部件(包括主板中的其它部件和主板验证部件)脱离复位状态,以使得主板验证部件开始对主板进行可行验证。
例如,第一TPCM在控制微型板卡中的其它部件脱离复位状态之后,即可以通过位于微型板卡中的其它部件中的可编程部件对所述主板中的主板验证部件进行使能操作,以通过所述主板中的主板验证部件对所述主板进行可信验证。
所述位于微型板卡中的其它部件中的可编程部件可以是设置于微型板卡中的复杂可编程逻辑器件CPLD和/或现场可编程逻辑门阵列FPGA,它们可以向主板中的CPLD发送使能信号,使得主板中的CPLD激活主板中的主板验证部件,并执行对主板的可信验证。
对所述主板进行可信验证的主板验证部件可以是微型板卡中的部件,也可以是主板中的部件。例如,第一TPCM可以通过微型板卡中的可编程部件CPLD或者FPGA发送使能信号,控制主板上的CPLD激活主板中的第二TPCM,使得第二TPCM进行对主板的可信验证。又例如,对所述主板进行可信验证的主板验证部件可以是设置于微型板卡中的FPGA模块。
如图1B所示,图1B为本申请实施例所提供的一种可信验证的系统的示意图,所述设备包括:
主板;和,卡上微型服务器微型板卡,所述微型板卡中第一TPCM和现场可编程逻辑门阵列FPGA,所述FPGA连接所述主板;具体而言,所述FPGA可以通过PCIE连接所述主板中的CPU和CPLD。
当所述系统通电启动时,所述第一TPCM,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态;
所述FPGA用于,在所述微型板卡的可信验证通过后,对所述主板进行可信验证。
换言之,当该系统通电启动时,微型板卡中的第一TPCM会先上电工作,充当对于微型板卡执行可信验证的部件。此时,微型板卡上的其它部件(包括FPGA)和主板上的部件均处在复位状态。
如图1B所示,由于微型板卡中的固件包括诸如片上系统(System on Chip,SOC)、基本输入输出系统(Basic Input Output System,BIOS)、基板管理控制器(Baseboard Manager Controller,BMC)等多个部件,各部件中可能存在一些固件或者一些系统代码,第一TPCM对于微型板卡的可信验证可以包括对这些部件的固件或者系统代码的可信验证。
具体而言,第一TPCM在通电工作时,首先处于串行外围设备接口(Serial Peripheral Interface,SPI)主模式,在该模式下,可以基于SPI主接口读取微型板卡的BIOS中和BMC中的固件,并对BIOS和BMC中的固件进行可信验证。
第一TPCM可以在第一TPCM的寄存器中预先存储一份可信度量根(例如,由可信 硬件预先得到的固件的哈希值,或者预先存储的固件的指定位置的可信的部分代码),具体的验证方式可以是第一TPCM确认所述固件的固件度量值(即固件的哈希值,或者固件的指定位置的代码),将固件度量值与预存的可信度量根进行匹配,若二者一致,则确认所述固件可信。
在确定了BIOS和BMC中的固件可信之后,此时,第一TPCM即可以发出SOC复位失效信号和BMC复位失效信号,使得SOC和BMC脱离复位状态,开始正常工作,SOC开始加载所述BIOS中的固件,所述BMC开始加载所述BMC中的固件。
在SOC和BMC加载固件完毕之后,第一TPCM切换为SPI从模式,开始与SOC的SPI主控进程进行通信,被动地接受连接到微型板卡上的外围设备和预设的微型板卡信息,并对外围设备和预设的微型板卡信息。具体的外围设备可以包括连接于微型板卡的外围设备的型号、唯一标识、名称等等,微型板卡信息可以包括连接于微型板卡的各外围设备中的固件代码以及SOC的版本等等。
在对于所述微型板卡上的外围设备和预设的微型板卡信息进行可信验证通过后,此时第一TPCM即可以对所述SOC的系统代码进行可信验证。在SOC的操作系统的系统代码进行可信验证之后,此时即说明了微型板卡本身已经是可信的了,此时所述SOC加载所述SOC的系统代码,完成对于微型板卡的启动。
对于外围设备、预设的微型板卡信息和SOC的系统代码进行可信验证的方式,与对于微型板卡中的固件进行可信验证的方式类似,此处不再赘述。
在对于微型板卡完成可信验证之后,此时FPGA已经被第一TPCM指示脱离了复位状态,开始正常工作,并作为主要的实现对主板实现可信验证的功能模块,此时,主板中的部件仍然均处于复位状态。
主板中包含有主板中的BIOS和BMC,以及存在于主板上的操作系统等部件,具体而言,所述FPGA对于主板进行可信验证,可以包括对于主板中的BIOS、BMC和主板上的操作系统进行可信验证。
具体而言,当微型板卡已经完成可信验证,而主板上的部件仍然均处于复位状态时,此时可以通过FPGA上的SPI主设备,对获取所述主板中的固件,并对所述主板中的固件进行可信验证,其中主板中的固件包括所述主板的基本输入输出系统BIOS的固件和所述主板的基板管理控制器BMC的固件。
具体的验证方式与前述类似,FPGA可以预先存储一份可信度量根(例如,由可信硬件预先得到的固件的哈希值,或者预先存储的固件的指定位置的可信的部分代码),具体的验证方式可以是FPGA确认所述主板上的固件的固件度量值(即固件的哈希值,或者固件的指定位置的代码),将固件度量值与预存的可信度量根进行匹配,若二者一致,则确认所述主板上的固件可信。
在FPGA对所述主板中的固件进行可信验证通过之后,FPGA即发送出主板上的 BMC和BIOS的复位失效的信号,控制所述主板的BIOS和BMC脱离复位状态,同时所述主板的平台控制器集线器(Platform Controller Hub,PCH,又称为集成南桥)加载所述主板的BIOS中的固件,所述主板的BMC加载所述主板的BMC中的固件。
在BIOS和BMC中的固件被加载完毕之后,所述FPGA,切换为串行外围设备接口SPI从模式,对所述主板中的外围设备和预设的主板信息进行可信验证。主板中的外围设备可以包括连接于主板的外围设备的型号、唯一标识、名称等等,预设的主板信息可以包括各连接于主板的外围设备中的固件代码、主板上的操作系统的版本等等。
进而,所述FPGA对所述主板中的外围设备和预设的主板信息进行可信验证通过之后,FPGA对所述主板上的操作系统的代码进行可信验证,在验证通过后,所述主板加载所述主板上的操作系统的代码,从而构建了整个系统的硬件可信环境。
此外,需要说明的是,前述对于微型板卡的可信验证的过程中具体顺序的实现和相关复位信号的传递可以通过在CPLD中进行编程而可以实现。
在另一种实施例中,对所述主板进行可信验证的其它部件可以是主板中的第二TPCM,如图1C所示,图1C为本申请实施例所提供的另一种可信验证的系统的示意图,所述系统包括:
主板;和,卡上微型服务器微型板卡,所述微型板卡中包括第一可信平台控制模块TPCM,所述主板中包括第二可信平台控制模块TPCM;
当所述系统通电启动时,所述第一TPCM,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态,并通过脱离复位状态后的所述其它部件中的可编程部件(例如,微型板卡中的CPLD)对所述主板中的主板验证部件进行使能操作,以通过所述主板中的第二TPCM对所述主板进行可信验证。
第一TPCM对于微型板卡的可信验证过程在前述部分已经进行了说明,此处不再赘述。
在第一TPCM对于微型板卡的可信验证通过后,此时,微型板卡上已经脱离复位状态的BMC可以产生主板控制信号,该控制信号经过设置于所述微型板卡中的可编程部件发送至所述主板,所述主板根据所述控制指令,控制所述第二TPCM脱离复位状态,所述第二TPCM对所述主板进行可信验证。
具体而言,所述微型板卡中的可编程部件可以是设置于微型板卡中的复杂可编程逻辑器件CPLD或者现场可编程逻辑门阵列FPGA。
在主板中接收该控制指令的可以是设置于主板中的复杂可编程逻辑器件CPLD,进而主板上的CPLD根据该控制信号控制所述第二TPCM脱离复位状态,并开始对主板执行可信验证。此时的第二TPCM对主板进行可信验证的流程具体如下:
第二TPCM,读取所述主板中的固件,并对所述主板中的固件进行可信验证,其中 主板中的固件包括所述主板的基本输入输出系统BIOS的固件和所述主板的基板管理控制器BMC的固件。当计算得到的固件度量值与预存在第二TPCM中的值一致时,验证通过。
然后所述第二TPCM发出控制信号,控制所述主板的BIOS和BMC脱离复位状态并开始加载已经验证过的固件。进而,所述第二TPCM,切换为串行外围设备接口SPI从模式,主板中的与PCH的SPI主控进行通信,并对所述主板中的外围设备和预设的主板信息进行可信验证,在对于外设和主板信息的验证通过之后,第二TPCM即对所述主板上的操作系统的代码进行可信验证,并在验证通过之后启动系统。
根据本申请实施例提供的方案,系统在通电启动时,首先基于微型板卡上的第一可信平台控制模块TPCM对微型板卡本身可信验证,在验证通过之后,控制所述微型板卡中的其它部件脱离复位状态,以正常工作,然后再通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证,从而实现在系统启动时对于系统的全面的可信验证。
需要说明的是,在前述的可信验证过程中,如果存在任一部件的可信验证失败,即可以中断系统的启动过程,以维护系统的安全运行环境。
此外,在一种实施例中,当启动以后主板在正常运行的过程中,微型板卡中的FPGA还可以对于主板的内存中的信息进行监测,以确定所述主板中运行的内容是否可信。主板的内存中的信息可以包括运行的进程的名称、进程的数量、进程占用的空间、进程调用的接口等等。
进一步地,FPGA对所述内存中的信息进行监测可以包括确定获取得到的内存中的信息的哈希值;将所述内存中的信息的哈希值与FPGA中预存的哈希值进行匹配。
预存的哈希值可以是一些对主板上的数据或程序的安全性产生不良影响的危险进程的名称或者标识所对应的哈希值,相当于黑名单。从而如果主板上的内存中存在某个进程的相关的哈希值与预存的哈希值相同,则可以认为主板所处的设备上运行了某些存在安全风险的进程;或者,预存的哈希值也可以是已经被确认的安全进程的名称或者标识所对应的哈希值,相当于白名单,从而如果主板上的内存中存在某个进程的相关哈希值与预先存储的哈希值不相同,则可以认为该进程是存在安全风险的进程。进而可以对存在安全风险的进程实施相应的监控,或者可以调用微型板卡强制关闭该进程,以实现动态的安全环境的维护。
在一种实施例中,该系统中的主板可以是服务器主板。
为使本申请的方案更为浅显易懂,以下给出一个更为具体的示例,如图2所示,图2为本申请实施例所提供的一种系统进行可信验证的流程示意图,在该示意图中,采用了系统的微型板卡中的FPGA模块对于主板进行可信验证,其具体包括:
201,系统通电,开始启动;
其中,所述系统中包含有微型板卡和主板。
202,微型板卡中的第一TPCM上电工作,其余部件均处于复位状态;
203,第一TPCM验证微型板卡的BIOS和BMC中的固件;
204,验证通过,微型板卡上的SOC和BMC脱离复位状态,微型板卡上的SOC和BMC加载固件;
205,第一TPCM切换为从模式,验证微型板卡的外设和微型板卡信息;
206,验证通过,第一TPCM验证SOC的系统代码;
207,验证通过,微型板卡上的FPGA验证主板的BIOS及BMC中的固件;
208,验证通过,主板上的BIOS和BMC脱离复位状态,主板上的BIOS和BMC加载固件;
209,FPGA切换为从模式,验证主板的外设和主板信息;
210,验证通过,FPGA验证主板上的操作系统的代码;
211,验证通过,主板加载所述主板上的操作系统的代码,设备启动。
前述任一可信验证失败,均可以中断系统的启动过程。
在系统启动之后,FPGA还可以监测主板中的内存信息,实现对于系统的安全环境的动态的监测。
本申请的第二方面,还提供一种可信验证的主板,如图1D所示,图1D为本申请实施例所提供的一种可信验证的主板的结构示意图,所述主板中包括复杂可编程逻辑器件CPLD和第二可信平台控制模块TPCM;
所述CPLD接收来自于已经通过可信验证的微型板卡的控制信号,并控制所述第二TPCM脱离复位状态;
所述第二TPCM对所述主板进行可信验证。
本申请的第三方面,还提供一种可信验证的微型板卡,如图1E所示,图1E为本申请实施例所提供的一种可信验证的微型板卡的结构示意图,所述微型板卡连接主板(图中未示出),所述微型板卡中包括第一可信平台控制模块TPCM;
当设备通电启动时,所述第一TPCM,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
其中,主板验证部件包括设置于微型板卡中的现场可编程逻辑门阵列FPGA,和/或,复杂可编程逻辑器件CPLD。
本申请实施例的第四方面,还提供一种服务器,包括:如第二方面所述的可信验证的主板;
进一步地,在所述服务器中,还包括如第三方面所述的可信验证的微型板卡。
本申请实施例的第五方面,还提供一种可信验证的方法,应用于包含主板和微型板卡的系统中,如图3所示,图3为本申请实施例所提供的一种可信验证的方法的流程示意图,所述方法具体包括:
S301,当所述系统通电启动时,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态;
S303,通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。可选地,对所述微型板卡进行可信验证可以采用微型板卡中的第一TPCM对所述微型板卡进行可信验证;
可选地,所述第一TPCM在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件和所述主板验证部件脱离复位状态,并通过脱离复位状态后的所述主板验证部件对所述主板进行可信验证;
可选地,所述微型板卡中的所述主板验证部件包括设置于所述微型板卡中的现场可编程逻辑门阵列FPGA,所述FPGA连接所述主板;所述微型板卡通过所述FPGA对所述主板进行可信验证。
可选地,所述第一TPCM在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态,并通过脱离复位状态后的所述其它部件中的可编程部件对所述主板中的主板验证部件进行使能操作,以通过所述主板中的主板验证部件对所述主板进行可信验证。
可选地,所述主板中的主板验证部件包括所述主板中的第二TPCM;所述微型板卡通过所述可编程部件对所述主板中的主板验证部件进行使能操作,以通过所述主板中的第二TPCM对所述主板进行可信验证。
可选地,所述微型板卡通过设置于所述微型板卡中的可编程部件发送控制指令至所述主板;所述主板根据所述控制指令,控制所述第二TPCM脱离复位状态,并通过所述第二TPCM对所述主板进行可信验证。
可选地,所述可编程部件包括:复杂可编程逻辑器件CPLD和/或现场可编程逻辑门阵列FPGA。
可选地,所述微型板卡中还包括基本输入输出系统BIOS和基板管理控制器BMC,对所述微型板卡进行可信验证包括,读取固件,对所述固件进行可信验证,其中,所述固件包括所述微型板卡的基本输入输出系统BIOS中的固件和所述微型板卡的BMC中的固件。
可选地,对所述固件进行可信验证,包括:确认所述固件的哈希值,与预存的哈希值进行匹配,若二者一致,则确认所述固件可信。
可选地,当对所述固件进行可信验证通过后,控制所述SOC和所述BMC脱离复位状态;相应的,所述SOC加载所述BIOS中的固件,以及,所述BMC加载所述BMC中的固件;
可选地,对所述微型板卡进行可信验证,包括:所述第一TPCM切换为串行外围设备接口SPI从模式,对所述微型板卡上的外围设备和预设的微型板卡信息进行可信验证。
可选地,所述微型板卡上的外围设备和预设的微型板卡信息进行可信验证通过后;对所述SOC的系统代码进行可信验证,在验证通过后,所述SOC加载所述SOC的系统代码。
可选地,对所述主板进行可信验证,包括:获取所述主板中的固件,并对所述主板中的固件进行可信验证,其中主板中的固件包括所述主板的基本输入输出系统BIOS的固件和所述主板的基板管理控制器BMC的固件。
可选地,在所述主板的可信验证通过之后,控制所述主板脱离复位状态,包括:对所述主板中的固件进行可信验证通过之后,控制所述主板的BIOS和BMC脱离复位状态;所述主板的平台控制器集线器PCH加载所述主板的BIOS中的固件,所述主板的BMC加载所述主板的BMC中的固件。
可选地,对所述主板进行可信验证,包括:对所述主板中的外围设备和预设的主板信息进行可信验证。
可选地,对所述主板中的外围设备和预设的主板信息进行可信验证通过之后,对所述主板上的操作系统的代码进行可信验证,在验证通过后,所述主板加载所述主板上的操作系统的代码。
可选地,获取所述主板的内存中的信息,对所述内存中的信息进行监测。
可选地,对所述内存中的信息进行监测,包括:确定获取得到的内存中的信息的代码的哈希值;将所述内存中的信息的代码的哈希值与预存的哈希值进行匹配。
可选地,当所述系统通电启动时,所述微型板卡先于所述主板通电启动,且,在所述微型板卡的可信验证通过之前,所述主板保持复位状态;相应的,在所述微型板卡的可信验证通过后,所述微型板卡控制所述通过主板脱离复位状态。
可选地,所述主板为服务器主板。
根据本申请实施例提供的方案,系统在通电启动时,首先基于微型板卡上的第一可信平台控制模块TPCM对微型板卡本身可信验证,在验证通过之后,控制所述微型板卡中的其它部件脱离复位状态,以正常工作,然后通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证,从而实现在系统启动时对于系统的全面的可信验证。
本申请实施例的第六方面,还提供一种计算机机存储介质,其上存储有计算机程序,该程序被处理器执行时实现如图3所述的可信验证的方法。
需要指出,根据实施的需要,可将本申请实施例中描述的各个部件/步骤拆分为更多部件/步骤,也可将两个或多个部件/步骤或者部件/步骤的部分操作组合成新的部件/步骤,以实现本申请实施例的目的。
上述根据本申请实施例的方法可在硬件、固件中实现,或者被实现为可存储在记录介质(诸如CD ROM、RAM、软盘、硬盘或磁光盘)中的软件或计算机代码,或者被实现通过网络下载的原始存储在远程记录介质或非暂时机器可读介质中并将被存储在本地记录介质中的计算机代码,从而在此描述的方法可被存储在使用通用计算机、专用处理器或者可编程或专用硬件(诸如ASIC或FPGA)的记录介质上的这样的软件处理。可以理解,计算机、处理器、微处理器控制器或可编程硬件包括可存储或接收软件或计算机代码的存储组件(例如,RAM、ROM、闪存等),当所述软件或计算机代码被计算机、处理器或硬件访问且执行时,实现在此描述的可信验证的方法。此外,当通用计算机访问用于实现在此示出的可信验证的方法的代码时,代码的执行将通用计算机转换为用于执行在此示出的可信验证的方法的专用计算机。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及方法步骤,能够以电子硬件、或者计算机软件和电子硬件的结合来实现。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请实施例的范围。
以上实施方式仅用于说明本申请实施例,而并非对本申请实施例的限制,有关技术领域的普通技术人员,在不脱离本申请实施例的精神和范围的情况下,还可以做出各种变化和变型,因此所有等同的技术方案也属于本申请实施例的范畴,本申请实施例的专利保护范围应由权利要求限定。

Claims (31)

  1. 一种可信验证的系统,包括:
    主板;和,
    微型板卡,所述微型板卡连接所述主板,所述微型板卡中包括第一可信平台控制模块TPCM;
    当所述系统通电启动时,第一TPCM,对所述微型板卡进行可信验证;并在所述微型板卡的可信验证通过后,控制所述微型板卡的其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
  2. 如权利要求1所述的系统,其中,所述第一TPCM在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件和所述主板验证部件脱离复位状态,并通过脱离复位状态后的所述主板验证部件对所述主板进行可信验证。
  3. 如权利要求2所述的系统,其中,所述微型板卡中的所述主板验证部件包括设置于所述微型板卡中的现场可编程逻辑门阵列FPGA,所述FPGA连接所述主板;
    所述微型板卡通过所述FPGA对所述主板进行可信验证。
  4. 如权利要求1所述的系统,其中,所述第一TPCM在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态,并通过脱离复位状态后的所述其它部件中的可编程部件对所述主板中的主板验证部件进行使能操作,以通过所述主板中的主板验证部件对所述主板进行可信验证。
  5. 如权利要求4所述的系统,其中,所述主板中的主板验证部件包括所述主板中的第二TPCM;
    所述微型板卡通过所述可编程部件对所述主板中的主板验证部件进行使能操作,以通过所述主板中的第二TPCM对所述主板进行可信验证。
  6. 如权利要求5所述的系统,其中,
    所述微型板卡通过设置于所述微型板卡中的可编程部件发送控制指令至所述主板;
    所述主板根据所述控制指令,控制所述第二TPCM脱离复位状态,并通过所述第二TPCM对所述主板进行可信验证。
  7. 如权利要求4-6任一项所述的系统,其中,所述可编程部件包括:复杂可编程逻辑器件CPLD和/或现场可编程逻辑门阵列FPGA。
  8. 如权利要求1所述的系统,其中,所述微型板卡中还包括基本输入输出系统BIOS和基板管理控制器BMC;
    所述第一TPCM,对所述微型板卡进行可信验证,包括:所述第一TPCM读取固件,对所述固件进行可信验证,其中,所述固件包括所述微型板卡的基本输入输出系统BIOS中的固件和所述微型板卡的BMC中的固件。
  9. 如权利要求8所述的系统,其中,所述第一TPCM读取固件,对所述固件进行可信验证,包括:
    所述第一TPCM读取固件,确认所述固件的哈希值,与预存于所述第一TPCM中的哈希值进行匹配,若二者一致,则确认所述固件可信。
  10. 如权利要求8所述的系统,其中,所述微型板卡中还包括片上系统SOC;
    当对所述固件进行可信验证通过后,所述第一TPCM控制所述SOC和所述BMC脱离复位状态;
    相应的,所述SOC加载所述BIOS中的固件,以及,所述BMC加载所述BMC中的固件。
  11. 如权利要求10所述的系统,其中,所述第一TPCM,对所述微型板卡进行可信验证,包括:
    所述第一TPCM切换为串行外围设备接口SPI从模式,对所述微型板卡上的外围设备和预设的微型板卡信息进行可信验证。
  12. 如权利要求11所述的系统,其中,当所述微型板卡上的外围设备和预设的微型板卡信息进行可信验证通过后,
    所述第一TPCM对所述SOC的系统代码进行可信验证,在验证通过后,所述SOC加载所述SOC的系统代码。
  13. 如权利要求3所述的系统,其中,所述微型板卡通过所述FPGA对所述主板进行可信验证包括:
    所述FPGA,获取所述主板中的固件,并对所述主板中的固件进行可信验证,其中主板中的固件包括所述主板的基本输入输出系统BIOS的固件和所述主板的基板管理控制器BMC的固件。
  14. 如权利要求13所述的系统,其中,所述FPGA还用于,对所述主板中的固件进行可信验证通过之后,控制所述主板的BIOS和BMC脱离复位状态;
    相应的,所述主板的平台控制器集线器PCH加载所述主板的BIOS中的固件,所述主板的BMC加载所述主板的BMC中的固件。
  15. 如权利要求14所述的系统,其中,所述微型板卡通过所述FPGA对所述主板进行可信验证,包括:
    所述FPGA,切换为串行外围设备接口SPI从模式,对所述主板上的外围设备和预设的主板信息进行可信验证。
  16. 如权利要求15所述的系统,其中,所述微型板卡通过所述FPGA对所述主板进行可信验证,包括:
    当对所述主板上的外围设备和预设的主板信息进行可信验证通过之后,所述FPGA,对所述主板上的操作系统的代码进行可信验证。
  17. 如权利要求3所述的系统,其中,所述FPGA还用于,获取所述主板的内存中的信息,对所述内存中的信息进行监测。
  18. 如权利要求17所述的系统,其中,所述FPGA还用于,对所述内存中的信息进 行监测,包括:
    确定获取得到的内存中的信息的哈希值;
    将所述内存中的信息的哈希值与FPGA中预存的哈希值进行匹配。
  19. 如权利要求5所述的系统,其中,所述微型板卡通过所述其它部件控制所述主板中的第二TPCM对所述主板进行可信验证,包括:
    所述第二TPCM,读取所述主板中的固件,并对所述主板中的固件进行可信验证,其中主板中的固件包括所述主板的基本输入输出系统BIOS的固件和所述主板的基板管理控制器BMC的固件。
  20. 如权利要求19所述的系统,其中,所述第二TPCM还用于,对所述主板中的固件进行可信验证通过之后,控制所述主板的BIOS和BMC脱离复位状态。
  21. 如权利要求19所述的系统,其中,所述微型板卡通过所述其它部件控制所述主板中的第二TPCM对所述主板进行可信验证,包括:
    所述第二TPCM,切换为串行外围设备接口SPI从模式,对所述主板中的外围设备和预设的主板信息进行可信验证。
  22. 如权利要求21所述的系统,其中,所述微型板卡通过所述其它部件控制所述主板中的所述第二TPCM对所述主板进行可信验证,包括:
    当对所述主板中的外围设备和预设的主板信息进行可信验证通过之后,所述第二TPCM,对所述主板上的操作系统的代码进行可信验证。
  23. 如权利要求1所述的系统,其中,当所述系统通电启动时,包括:
    当所述系统通电启动时,所述微型板卡先于所述主板通电启动,且,在所述微型板卡的可信验证通过之前,所述主板保持复位状态;
    相应的,在所述微型板卡的可信验证通过后,所述微型板卡控制所述通过主板脱离复位状态。
  24. 如权利要求1所述的系统,其中,所述主板为服务器主板。
  25. 一种可信验证的主板,所述主板中包括复杂可编程逻辑器件CPLD和第二可信平台控制模块TPCM;
    所述CPLD接收来自于已经通过可信验证的微型板卡的控制信号,并控制第二TPCM脱离复位状态;
    所述第二TPCM对所述主板进行可信验证。
  26. 一种可信验证的微型板卡,所述微型板卡连接主板,所述微型板卡中包括第一可信平台控制模块TPCM;
    当设备通电启动时,第一TPCM,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
  27. 如权利要求26所述的微型板卡,其中,所述主板验证部件包括现场可编程逻辑 门阵列FPGA,和/或,复杂可编程逻辑器件CPLD。
  28. 一种服务器,包括:如权利要求25所述的主板。
  29. 如权利要求28所述的服务器,其中,所述服务器还包括:如权利要求26或27所述的微型板卡。
  30. 一种可信验证的方法,应用于包含主板和微型板卡的系统中,所述方法包括:
    当所述系统通电启动时,对所述微型板卡进行可信验证,并在所述微型板卡的可信验证通过后,控制所述微型板卡中的其它部件脱离复位状态,并通过用于对主板进行可信验证的主板验证部件对所述主板进行可信验证。
  31. 一种计算机存储介质,其上存储有计算机程序,该程序被处理器执行时实现如权利要求30所述的可信验证的方法。
PCT/CN2021/117387 2020-09-16 2021-09-09 一种可信验证的系统、方法、主板、微型板卡及存储介质 Ceased WO2022057720A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US18/026,582 US12393692B2 (en) 2020-09-16 2021-09-09 Trusted authentication system, method, mainboard, micro board, and storage medium

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202010982939.8 2020-09-16
CN202010982939.8A CN113420297B (zh) 2020-09-16 2020-09-16 一种可信验证的系统、方法、主板、微型板卡及存储介质

Publications (1)

Publication Number Publication Date
WO2022057720A1 true WO2022057720A1 (zh) 2022-03-24

Family

ID=77711557

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/117387 Ceased WO2022057720A1 (zh) 2020-09-16 2021-09-09 一种可信验证的系统、方法、主板、微型板卡及存储介质

Country Status (3)

Country Link
US (1) US12393692B2 (zh)
CN (1) CN113420297B (zh)
WO (1) WO2022057720A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116467721A (zh) * 2023-05-25 2023-07-21 合芯科技(苏州)有限公司 Cpld的校验方法、装置、服务器启动方法及服务器
CN118860507A (zh) * 2024-09-23 2024-10-29 山东云海国创云计算装备产业创新中心有限公司 业务交互系统、方法、存储介质、电子设备

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114692159A (zh) * 2020-12-29 2022-07-01 华为技术有限公司 计算机系统、可信功能组件及运行方法
CN114090488A (zh) * 2021-11-11 2022-02-25 深圳市同泰怡信息技术有限公司 可信度量扩展板、基本输入输出系统以及可信度量方法和装置
CN114185526B (zh) * 2021-11-15 2025-06-10 山东浪潮科学研究院有限公司 多微波源板卡的控制方法及系统
CN114357536A (zh) * 2021-12-24 2022-04-15 锋微固件(深圳)有限公司 一种基于国产飞腾平台板卡bios防护系统
CN115391769A (zh) * 2022-08-09 2022-11-25 支付宝(杭州)信息技术有限公司 一种用于安全验证的主板以及安全验证方法、装置及介质
CN116340953A (zh) * 2023-03-20 2023-06-27 南京南瑞继保电气有限公司 多cpu板卡的嵌入式装置的可信应用方法及嵌入式装置
CN121188799B (zh) * 2025-11-20 2026-03-03 苏州元脑智能科技有限公司 基板管理控制器、电子设备及启动方法

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060224878A1 (en) * 2005-03-31 2006-10-05 Intel Corporation System and method for trusted early boot flow
CN109753804A (zh) * 2018-12-26 2019-05-14 北京可信华泰信息技术有限公司 一种可信系统
CN111008379A (zh) * 2019-11-22 2020-04-14 腾讯科技(深圳)有限公司 电子设备的固件安全检测方法及相关设备

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8245053B2 (en) * 2009-03-10 2012-08-14 Dell Products, Inc. Methods and systems for binding a removable trusted platform module to an information handling system
CN102279914B (zh) * 2011-07-13 2014-08-06 中国人民解放军海军计算技术研究所 一种uefi可信支撑系统及其控制方法
US20140292475A1 (en) * 2011-10-31 2014-10-02 Jun Guo Personal mini-intelligent terminal with combined verification electronic lock
KR102253592B1 (ko) * 2014-12-23 2021-05-18 삼성전자주식회사 초기 문턱 전압 분포 변화를 보상할 수 있는 데이터 저장 장치, 이의 작동 방법, 및 이를 포함하는 데이터 처리 시스템
CN105930732B (zh) * 2016-04-12 2018-11-06 中国电子科技集团公司第五十四研究所 一种适合vpx设备业务板卡的可信启动方法
CN106022137B (zh) * 2016-05-10 2018-11-13 北京新云东方系统科技有限责任公司 由tpcm控制power平台可信的实现方法及系统
CN110119623A (zh) * 2018-02-06 2019-08-13 北京可信华泰信息技术有限公司 一种利用tpcm实现固件主动度量的可信主板实现方法
CN110119638A (zh) * 2018-02-06 2019-08-13 威海创事特信息科技发展有限公司 一种可信度量方法
CN109670349B (zh) * 2018-12-13 2021-10-01 英业达科技有限公司 可信计算机的硬件架构及计算机的可信启动方法
CN111625831B (zh) * 2019-02-28 2023-05-30 阿里巴巴集团控股有限公司 可信安全的度量方法和装置
CN110096887B (zh) * 2019-03-22 2020-06-30 阿里巴巴集团控股有限公司 一种可信计算方法及服务器
CN110321715A (zh) * 2019-07-08 2019-10-11 北京可信华泰信息技术有限公司 可信度量方法、装置及处理器
CN114428958A (zh) * 2021-12-17 2022-05-03 阿里巴巴(中国)有限公司 具有外接板卡的主机的可信度量方法和主机

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060224878A1 (en) * 2005-03-31 2006-10-05 Intel Corporation System and method for trusted early boot flow
CN109753804A (zh) * 2018-12-26 2019-05-14 北京可信华泰信息技术有限公司 一种可信系统
CN111008379A (zh) * 2019-11-22 2020-04-14 腾讯科技(深圳)有限公司 电子设备的固件安全检测方法及相关设备

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116467721A (zh) * 2023-05-25 2023-07-21 合芯科技(苏州)有限公司 Cpld的校验方法、装置、服务器启动方法及服务器
CN116467721B (zh) * 2023-05-25 2023-11-24 合芯科技(苏州)有限公司 Cpld的校验方法、装置、服务器启动方法及服务器
CN118860507A (zh) * 2024-09-23 2024-10-29 山东云海国创云计算装备产业创新中心有限公司 业务交互系统、方法、存储介质、电子设备

Also Published As

Publication number Publication date
US20240028738A1 (en) 2024-01-25
CN113420297A (zh) 2021-09-21
US12393692B2 (en) 2025-08-19
CN113420297B (zh) 2025-07-25

Similar Documents

Publication Publication Date Title
WO2022057720A1 (zh) 一种可信验证的系统、方法、主板、微型板卡及存储介质
US11579893B2 (en) Systems and methods for separate storage and use of system BIOS components
US8544092B2 (en) Integrity verification using a peripheral device
US9886580B2 (en) Method for optimizing boot time of an information handling system
CN101438241B (zh) 具有桥支持的平台引导
US11263326B2 (en) Method and apparatus for secure system boot
CN114817105B (zh) 设备枚举的方法、装置、计算机设备以及存储介质
CN101221509B (zh) 可信嵌入式系统总线仲裁启动方法
CN106462711B (zh) 经验证启动
US20210365563A1 (en) Split chain of trust for secure device boot
CN119861985B (zh) 服务器的启动方法、设备、存储介质及程序产品
CN114008617A (zh) 固件防回滚
US8140835B2 (en) Updating a basic input/output system (‘BIOS’) boot block security module in compute nodes of a multinode computer
EP4172828B1 (en) Static configuration of accelerator card security modes
CN114077738A (zh) 快速外设组件互联设备启动方法、装置以及存储介质
CN113901473B (zh) 一种服务器安全启动的方法、装置、设备及可读介质
CN118567728A (zh) 获取热键信息的方法及装置、计算机程序产品
CN115421793A (zh) 一种启动状态的显示方法及计算设备
US8056127B2 (en) Accessing password protected devices
CN116881929B (zh) 安全防护方法、装置、电子设备以及基板控制器芯片
CN118626110A (zh) 一种固件升级系统、方法及相关设备
CN113626792B (zh) PCIe Switch固件安全执行方法、装置、终端及存储介质
HK40059916A (zh) 一种可信验证的系统、方法、主板、微型板卡及存储介质
US12572189B2 (en) Customized thermal and power policies in computers
WO2024045828A1 (zh) 操作系统安全启动方法、操作系统安装方法及相关装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21868545

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 18026582

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21868545

Country of ref document: EP

Kind code of ref document: A1

WWG Wipo information: grant in national office

Ref document number: 18026582

Country of ref document: US