首页> 外国专利> MICROCODE SIGNATURE SECURITY MANAGEMENT SYSTEM AND METHOD BASED ON TRUSTZONE TECHNOLOGY

MICROCODE SIGNATURE SECURITY MANAGEMENT SYSTEM AND METHOD BASED ON TRUSTZONE TECHNOLOGY

机译:基于信任区技术的微码签名安全管理系统和方法

摘要

The present invention relates to the field of data security storage, and provides a microcode signature security management system based on a Trustzone technology. The method comprises: start a common operating system after a hardware device is started; the common operating system obtains a signature-encrypted microcode file and outputs the signature-encrypted microcode file and a switching signal; a microprocessor receives the switching signal and starts a monitoring mode to start a secure operating system; the secure operating system receives the signature-encrypted microcode file, performs signature verification on the signature-encrypted microcode file, loads the file if the signature verification is successful, and outputs microcode error information if the signature verification fails. By means of the present invention, the security of microcode is ensured on the basis of a secure operating system (secure os) safety environment to which a system layer is inaccessible. A cryptography tool measure is adopted, so that the security, integrity and correctness of loaded microcode are ensured, and the risk of breaking, modifying and replacing an existing microcode management mechanism is lowered.
机译:本发明涉及数据安全存储领域,并提供一种基于Trustzone技术的微码签名安全管理系统。该方法包括:在硬件设备启动后启动通用操作系统;通用操作系统获取签名加密的微码文件,并输出签名加密的微码文件和切换信号;微处理器接收切换信号并启动监视模式以启动安全操作系统;安全操作系统接收签名加密的微码文件,对签名加密的微码文件执行签名验证,如果签名验证成功,则加载文件,如果签名验证失败,则输出微码错误信息。通过本发明,基于系统层不可访问的安全操作系统(secure os)安全环境来确保微代码的安全性。采用密码学手段,保证了加载微码的安全性,完整性和正确性,降低了破坏,修改和替换现有微码管理机制的风险。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号