IP Library › Granted Patent US 12,182,580
Granted Patent B2
US 12,182,580 · App. 18/170,574 · Granted Dec 31, 2024

Peripheral component interconnect express device startup method and apparatus, and storage medium

Inventor: Yutao Li (Shenzhen, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
G06F9/4403G06F13/4221G06F21/85G06F2213/0026
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,182,580
App. No.
18/170,574
Granted
Dec 31, 2024
Kind
B2
Abstract

A method, apparatus and storage medium for starting up peripheral component interconnect express (PCIE) device are provided. According to the method, a basic input/output system (BIOS) attempts to verify firmware of a PCIE device to determine whether the firmware of the PCIE device is tampered with. Moreover, the BIOS may only start up a PCIE device with firmware that succeeds in the verification. Therefore, a computer device is prevented from starting up a PCIE device with firmware that is tampered with, thereby reducing the security risk caused by the PCIE device to the computer device.

Claims (56)

1. A peripheral component interconnect express (PCIE) device startup method, applied to a computer device comprising a PCIE device, wherein the method comprises:

obtaining, by a basic input/output system (BIOS) of the computer device, firmware of the PCIE device;

verifying, by the BIOS, the firmware to generate a verification result; and

starting up, by the BIOS based on the verification result, the PCIE device when the verification result indicates that the verification for the firmware succeeds,

wherein the firmware comprises firmware code and signature data of the firmware code; and

the obtaining by a basic input/output system (BIOS) of the computer device, firmware of the PCIE device comprises:

obtaining, by the BIOS, the signature data of the firmware code from a driver of the PCIE device; and

reading, by the BIOS, the firmware code from the PCIE device.

2. The method according to claim 1 , further comprising:

skipping, by the BIOS, starting up the PCIE device when the verification result indicates that the verification for the firmware fails.

3. The method according to claim 2 , wherein the skipping, by the BIOS, starting up the PCIE device comprises:

controlling, by the BIOS, the PCIE device to be in a reset state or a power-off state; or

marking, by the BIOS, the PCIE device as a startup disabled state, wherein the startup disabled state indicates to skip starting up the PCIE device.

4. The method according to claim 1 , wherein the obtaining, by a basic input/output system (BIOS) of the computer device, firmware of the PCIE device comprises:

reading, by the BIOS, an image of the firmware from an expansion read-only memory (ROM) of the PCIE device.

5. The method according to claim 4 , wherein, before the reading, by the BIOS, an image of the firmware from an expansion read-only memory (ROM) of the PCIE device, the method further comprises:

reading, by the BIOS, an image type of the image and a certificate type of the signature data from the expansion ROM, wherein the image type indicates a code type of the image, and the certificate type indicates an encryption algorithm for calculating the signature data.

6. The method according to claim 1 , wherein the reading, by the BIOS, the firmware code from the PCIE device comprises:

reading, by the BIOS, an image of the firmware code from an expansion ROM of the PCIE device.

7. The method according to claim 6 , wherein before the reading, by the BIOS, an image of the firmware code from an expansion ROM of the PCIE device, the method further comprises:

reading, by the BIOS, an image type of the image and a certificate type of the signature data from the expansion ROM, wherein the image type indicates a code type of the image, and the certificate type indicates an encryption algorithm for calculating the signature data.

8. The method according to claim 7 , wherein the obtaining, by the BIOS, the signature data of the firmware code from a driver of the PCIE device comprises:

reading, by the BIOS, an image of the driver from the expansion ROM of the PCIE device; and

obtaining, by the BIOS, signature data of the firmware code from the image of the driver.

9. The method according to claim 1 , further comprising:

attempting, by the BIOS, to verify the driver; and

when the verification for the driver succeeds, performing, by the BIOS, the reading of the firmware code from the PCIE device.

10. The method according to claim 1 , wherein the BIOS stores a public key of the PCIE device, and the public key is for attempting to verify the firmware.

11. The method according to claim 10 , further comprising:

modifying, by the BIOS, the stored public key of the PCIE device based on a public key modification instruction.

12. A computer device, comprising a basic input/output system (BIOS) and a peripheral component interconnect express (PCIE) device, wherein the BIOS is configured to:

obtain firmware of the PCIE device;

verify the firmware to generate a verification result; and

start up, based on the verification result, the PCIE device when the verification result indicates that the verification for the firmware succeeds,

wherein the firmware comprises firmware code and the BIOS is further configured to:

obtain signature data of the firmware code from a driver of the PCIE devices; and

read the firmware code from the PCIE device.

13. The computer device of claim 12 , wherein the BIOS is further configured to:

skip starting up the PCIE device when the verification result indicates that the verification for the firmware fails.

14. The computer device of claim 13 , wherein the BIOS is further configured to:

control the PCIE device to be in a reset state or a power-off state; or

mark the PCIE device as a startup disabled state, wherein the startup disabled state indicates to skip starting up the PCIE device.

15. The computer device of claim 12 , wherein the BIOS is further configured to:

read an image of the firmware from an expansion read-only memory (ROM) of the PCIE device.

16. The computer device of claim 15 , wherein the firmware comprises the signature data and the BIOS is further configured to:

read an image type of the image and a certificate type of the signature data from the expansion ROM, wherein the image type indicates a code type of the image, and the certificate type indicates an encryption algorithm for calculating the signature data.

17. The computer device of claim 12 , wherein the BIOS is further configured to:

read an image of the firmware code from an expansion ROM of the PCIE device.

18. A non-transitory computer readable storage medium, storing at least one computer program that, when executed by a basic input/output system (BIOS), causes the BIOS to perform a peripheral component interconnect express (PCIE) device startup method comprising:

obtaining firmware of the PCIE device;

verifying the firmware to generate a verification result; and

starting up, based on the verification result, the PCIE device when the verification result indicates that the verification for the firmware succeeds,

wherein the firmware comprises firmware code and signature data of the firmware code; and

the obtaining firmware of the PCIE device comprises:

obtaining the signature data of the firmware code from a driver of the PCIE device; and

reading the firmware code from the PCIE device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: LI, YUTAO
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 068701/0945 →
Priority Claims (1)
CN 202010849505.0 · Aug 21, 2020 · national
Continuity (2)
Continuation PCTCN2021106710 · Jul 16, 2021
Related Publication 20230195473A1 · Jun 22, 2023
Cited By (1)
US 12,314,397