Netinfo Security ›› 2021, Vol. 21 ›› Issue (5): 67-73.doi: 10.3969/j.issn.1671-1122.2021.05.008

Previous Articles     Next Articles

Research on Trusted Server Startup Method Based on BMC

XU Wanshan, ZHANG Jianbiao(), YUAN Yilin, LI Zheng   

  1. School of Computer Science, Department of Information Science, Beijing University of Technology, Beijing 100124, China
  • Received:2020-10-20 Online:2021-05-10 Published:2021-06-22
  • Contact: ZHANG Jianbiao E-mail:zjb@bjut.edu.cn

Abstract:

Based on hardware security, trusted computing technology can effectively realize the security of local and remote computing systems through trust chain, remote attestation and other technologies, and has been widely used in system security startup and measurement attestation. At present, the secure startup technology of terminal equipment has been relatively mature, but the research on trusted server startup technology is still less. Aiming at the problems of server BIOS firmware and operating system kernel image being tampered with, trust loss and low efficiency caused by long trust chain during server startup, this paper proposes a trusted server startup method based on BMC (baseboard manager controller). In this method, BMC is taken as the trusted root, and the star trust chain structure is used to construct the trust chain to realize the trusted start of the server. At the same time, combining with the information flow non-interference theoretical model, this paper gives a formal description of the trusted server startup. BMC is a common component on the server. The trusted startup method proposed in this paper takes BMC as the trusted root, which does not need additional hardware and has better versatility. At the same time, because of the star structure, this method reduces the trust transmission in the server startup process, and can effectively improve the security and efficiency of the server startup process.

Key words: BMC, trusted startup, active measurement, star chain

CLC Number: