[{"data":1,"prerenderedAt":440},["ShallowReactive",2],{"\u002Fzh\u002Fblogs\u002Fsecure-and-reliable-application":3,"content-doc-\u002Fen\u002Fblogs\u002Fsecure-and-reliable-application":243,"surround-\u002Fen\u002Fblogs\u002Fsecure-and-reliable-application":438},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"date":10,"archives":11,"category":12,"author":13,"body":17,"_type":235,"_id":236,"_source":237,"_file":238,"_stem":239,"_extension":240,"coverImage":91,"plainText":241,"authorNames":242},"\u002Fzh\u002Fblogs\u002Fsecure-and-reliable-application","blogs",false,"","基于openUBMC的可信安全应用","在当前复杂多变的网络安全形势下，固件安全威胁日益加剧，成为攻击者的重要目标。固件作为计算系统的基础层，其安全性直接影响到整个系统的安全韧性。在新的安全形势下，固件成为了攻击者的关键目标。由于固件位于计算系统的底层，拥有较高的权限，一旦被攻击，上层系统将无法有效防护。因此，提升固件的安全韧性显得尤为重要。","2025\u002F06\u002F25","2025-06","essentials",[14],{"name":15,"description":16},"李小川","华为技术有限公司计算硬件安全技术专家",{"type":18,"children":19,"toc":232},"root",[20,28,49,54,59,64,84,93,98,103,108,115,120,125,131,138,143,150,155,160,165,170,177,182,187,194,199,204,211,216,221,226],{"type":21,"tag":22,"props":23,"children":25},"element","h1",{"id":24},"基于openubmc的可信安全应用",[26],{"type":27,"value":8},"text",{"type":21,"tag":29,"props":30,"children":34},"pre",{"className":31,"code":32,"language":33,"meta":7,"style":7},"language-desc shiki shiki-themes github-light github-dark monokai","本篇文章来源于第二届固件技术峰会的议题《基于openUBMC的可信安全应用》。\n","desc",[35],{"type":21,"tag":36,"props":37,"children":38},"code",{"__ignoreMap":7},[39],{"type":21,"tag":40,"props":41,"children":44},"span",{"class":42,"line":43},"line",1,[45],{"type":21,"tag":40,"props":46,"children":47},{},[48],{"type":27,"value":32},{"type":21,"tag":22,"props":50,"children":52},{"id":51},"固件安全威胁的严峻性",[53],{"type":27,"value":51},{"type":21,"tag":55,"props":56,"children":57},"p",{},[58],{"type":27,"value":9},{"type":21,"tag":55,"props":60,"children":61},{},[62],{"type":27,"value":63},"计算系统具有以下特点：",{"type":21,"tag":65,"props":66,"children":67},"ul",{},[68,74,79],{"type":21,"tag":69,"props":70,"children":71},"li",{},[72],{"type":27,"value":73},"权限约束：下层可以约束上层的权限，而上层无法约束下层的权限。这意味着固件层的攻击可以对上层系统造成严重影响。",{"type":21,"tag":69,"props":75,"children":76},{},[77],{"type":27,"value":78},"攻击防护：下层对上层发起的攻击，上层无法有效防护。一旦固件被攻破，整个系统将面临巨大的安全风险。",{"type":21,"tag":69,"props":80,"children":81},{},[82],{"type":27,"value":83},"权限层级：越往下层，权限越高，硬件权限最高。固件作为接近硬件的一层，其安全防护尤为重要。",{"type":21,"tag":55,"props":85,"children":86},{},[87],{"type":21,"tag":88,"props":89,"children":92},"img",{"alt":90,"src":91},"image","\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg0.webp",[],{"type":21,"tag":55,"props":94,"children":95},{},[96],{"type":27,"value":97},"根据BMC CVE漏洞统计表，从2012年到2021年，BMC固件的漏洞数量呈现逐年上升的趋势。其中，2021年漏洞数量达到39个，远高于往年。这些漏洞主要涉及执行代码（Exec Code）、远程攻击（Remote）等高危类型。例如，CVE-2013-1945、CVE-2012-2959等漏洞允许远程攻击者执行任意代码，对系统安全构成严重威胁。",{"type":21,"tag":55,"props":99,"children":100},{},[101],{"type":27,"value":102},"随着AI基础设施的极速发展，内外置硬件可信根形态各异，各设备的安全能力参差不齐，协同困难，数据中心整体的安全性面临挑战，TPM、SGX、ARM Trust Zone、TPCM，业界有各种形态不一的硬件可信根，或内嵌于SoC中，或外置于单板之上。",{"type":21,"tag":55,"props":104,"children":105},{},[106],{"type":27,"value":107},"因此，内外置硬件可信根成为固件信任的锚点。可信计算化体系中，信任链传递的源头，就是硬件可信根。一般主要用于保障平台的完整性。硬件可信根由密码学引擎、硬件真随机数、一次性烧写介质、安全SRAM等硬件和对应的安全固件软件构成。",{"type":21,"tag":55,"props":109,"children":110},{},[111],{"type":21,"tag":88,"props":112,"children":114},{"alt":90,"src":113},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg1.webp",[],{"type":21,"tag":55,"props":116,"children":117},{},[118],{"type":27,"value":119},"一些常见的硬件可信根包括：TPM\u002FTCM中的RTM、RTS、RTR、安全启动中的BSBC启动代码和EFUSE中烧写的根公钥hash；可信计算3.0中的TPCM；微软的Caliptra开源可信根，含平台信任根(pROT)；",{"type":21,"tag":55,"props":121,"children":122},{},[123],{"type":27,"value":124},"基于内置或外置硬件可信根，采用信任链技术实现系统防篡改，防供应连替换，防窜货等安全能力。云厂商基于可信根芯片构筑安全启动、硬件身份保护，基于内外置可信根实现数据中心基础设施智能部件可信度量和身份认证。国产CPU厂家普遍采用内置TPCM方案，实现服务器平台的可信计算3.0启动度量控制和运行度量控制。",{"type":21,"tag":22,"props":126,"children":128},{"id":127},"openubmc的可信安全应用实践",[129],{"type":27,"value":130},"openUBMC的可信安全应用实践",{"type":21,"tag":55,"props":132,"children":133},{},[134],{"type":21,"tag":88,"props":135,"children":137},{"alt":90,"src":136},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg2.webp",[],{"type":21,"tag":55,"props":139,"children":140},{},[141],{"type":27,"value":142},"openUBMC基于Hi171x系列芯片的可信安全应用实践，已在计算服务器、存储设备、电信计算平台及边缘计算等多类场景中得到充分验证，为软硬件安全防护提供完整解决方案。",{"type":21,"tag":55,"props":144,"children":145},{},[146],{"type":21,"tag":88,"props":147,"children":149},{"alt":90,"src":148},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg3.webp",[],{"type":21,"tag":55,"props":151,"children":152},{},[153],{"type":27,"value":154},"基于硬件可信根，分层可信链传递，建立系统级的全栈高安防护。openUBMC围绕固件韧性、可信启动、安全升级、安全启动、安全运行、数据安全等维度构建可信计算、机密计算能力。",{"type":21,"tag":55,"props":156,"children":157},{},[158],{"type":27,"value":159},"通过组件化架构，将BMC功能合理地分配到不同的组件中，通过规范化交互接口、数据存储、权限管理等方式，最大化地看护组件间的交互。",{"type":21,"tag":55,"props":161,"children":162},{},[163],{"type":27,"value":164},"同时，根据数据自身业务属性，设置不同的安全等级，利用数据分区能力保护不同数据的安全性，尽可能的减少数据泄露扩散风险。",{"type":21,"tag":55,"props":166,"children":167},{},[168],{"type":27,"value":169},"openUBMC引入沙箱功能，根据组件的业务，设置不同的权限风险和最小韧性系统范围，建立多层防护体系。",{"type":21,"tag":55,"props":171,"children":172},{},[173],{"type":21,"tag":88,"props":174,"children":176},{"alt":90,"src":175},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg4.webp",[],{"type":21,"tag":55,"props":178,"children":179},{},[180],{"type":27,"value":181},"围绕不同的可信分区，openUBMC制定了不同的数据恢复流程、接口权限降级流程，实现芯片级可信根启动安全，固件韧性保障篡改固件自动恢复。",{"type":21,"tag":55,"props":183,"children":184},{},[185],{"type":27,"value":186},"openUBMC同样提供完整的签名身份认证能力，提供端到端的固件包签名、校验解密、秘钥管理等能力，最大化地保障固件完整性，保护防篡改。",{"type":21,"tag":55,"props":188,"children":189},{},[190],{"type":21,"tag":88,"props":191,"children":193},{"alt":90,"src":192},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg5.webp",[],{"type":21,"tag":55,"props":195,"children":196},{},[197],{"type":27,"value":198},"openUBMC社区同时建立了透明的研发流程，从需求接纳管理，需求实现设计，代码编写，社区自动化构建，到社区正式发布。同时围绕社区源码，以及社区依赖的三方库，openUBMC建立了完整的漏洞管理体系，流程化地管理软件漏洞和风险，最大化保障软件安全。",{"type":21,"tag":22,"props":200,"children":202},{"id":201},"总结",[203],{"type":27,"value":201},{"type":21,"tag":55,"props":205,"children":206},{},[207],{"type":21,"tag":88,"props":208,"children":210},{"alt":90,"src":209},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg6.webp",[],{"type":21,"tag":55,"props":212,"children":213},{},[214],{"type":27,"value":215},"外置可信根标准化（硬件设计+接口）+内置可信根开源成为未来硬件可信根的趋势。异构可信计算体系下，内存池化增大了暴露面，传统的TPM可信启动技术、DICE的环境保护技术、可信根互联技术将深度融合统一，成为智能部件的必备基础安全能力。",{"type":21,"tag":55,"props":217,"children":218},{},[219],{"type":27,"value":220},"信任链的传递、安全签名、代码交叉审计是国内安全生态建设中最缺失的；安全技术的复杂性导致推广落地缓慢，微软的徽标认证和OCP S.A.F.E固件签名体系值得国内固件安全生态借鉴。如何利用openUBMC社区，联合产业上下游共同打造国内的固件安全生态体系，是社区接下来的重点工作之一。",{"type":21,"tag":55,"props":222,"children":223},{},[224],{"type":27,"value":225},"在此，openUBMC社区诚邀业界同行，共同建设固件领域新生态，打造国内一流的固件安全生态体系。",{"type":21,"tag":227,"props":228,"children":229},"style",{},[230],{"type":27,"value":231},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html .sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}html.sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}",{"title":7,"searchDepth":233,"depth":233,"links":234},4,[],"markdown","content:zh:blogs:secure-and-reliable-application.md","content","zh\u002Fblogs\u002Fsecure-and-reliable-application.md","zh\u002Fblogs\u002Fsecure-and-reliable-application","md","基于openUBMC的可信安全应用 本篇文章来源于第二届固件技术峰会的议题《基于openUBMC的可信安全应用》。\n 固件安全威胁的严峻性 在当前复杂多变的网络安全形势下，固件安全威胁日益加剧，成为攻击者的重要目标。固件作为计算系统的基础层，其安全性直接影响到整个系统的安全韧性。在新的安全形势下，固件成为了攻击者的关键目标。由于固件位于计算系统的底层，拥有较高的权限，一旦被攻击，上层系统将无法有效防护。因此，提升固件的安全韧性显得尤为重要。 计算系统具有以下特点： 权限约束：下层可以约束上层的权限，而上层无法约束下层的权限。这意味着固件层的攻击可以对上层系统造成严重影响。 攻击防护：下层对上层发起的攻击，上层无法有效防护。一旦固件被攻破，整个系统将面临巨大的安全风险。 权限层级：越往下层，权限越高，硬件权限最高。固件作为接近硬件的一层，其安全防护尤为重要。  根据BMC CVE漏洞统计表，从2012年到2021年，BMC固件的漏洞数量呈现逐年上升的趋势。其中，2021年漏洞数量达到39个，远高于往年。这些漏洞主要涉及执行代码（Exec Code）、远程攻击（Remote）等高危类型。例如，CVE-2013-1945、CVE-2012-2959等漏洞允许远程攻击者执行任意代码，对系统安全构成严重威胁。 随着AI基础设施的极速发展，内外置硬件可信根形态各异，各设备的安全能力参差不齐，协同困难，数据中心整体的安全性面临挑战，TPM、SGX、ARM Trust Zone、TPCM，业界有各种形态不一的硬件可信根，或内嵌于SoC中，或外置于单板之上。 因此，内外置硬件可信根成为固件信任的锚点。可信计算化体系中，信任链传递的源头，就是硬件可信根。一般主要用于保障平台的完整性。硬件可信根由密码学引擎、硬件真随机数、一次性烧写介质、安全SRAM等硬件和对应的安全固件软件构成。  一些常见的硬件可信根包括：TPM\u002FTCM中的RTM、RTS、RTR、安全启动中的BSBC启动代码和EFUSE中烧写的根公钥hash；可信计算3.0中的TPCM；微软的Caliptra开源可信根，含平台信任根(pROT)； 基于内置或外置硬件可信根，采用信任链技术实现系统防篡改，防供应连替换，防窜货等安全能力。云厂商基于可信根芯片构筑安全启动、硬件身份保护，基于内外置可信根实现数据中心基础设施智能部件可信度量和身份认证。国产CPU厂家普遍采用内置TPCM方案，实现服务器平台的可信计算3.0启动度量控制和运行度量控制。 openUBMC的可信安全应用实践  openUBMC基于Hi171x系列芯片的可信安全应用实践，已在计算服务器、存储设备、电信计算平台及边缘计算等多类场景中得到充分验证，为软硬件安全防护提供完整解决方案。  基于硬件可信根，分层可信链传递，建立系统级的全栈高安防护。openUBMC围绕固件韧性、可信启动、安全升级、安全启动、安全运行、数据安全等维度构建可信计算、机密计算能力。 通过组件化架构，将BMC功能合理地分配到不同的组件中，通过规范化交互接口、数据存储、权限管理等方式，最大化地看护组件间的交互。 同时，根据数据自身业务属性，设置不同的安全等级，利用数据分区能力保护不同数据的安全性，尽可能的减少数据泄露扩散风险。 openUBMC引入沙箱功能，根据组件的业务，设置不同的权限风险和最小韧性系统范围，建立多层防护体系。  围绕不同的可信分区，openUBMC制定了不同的数据恢复流程、接口权限降级流程，实现芯片级可信根启动安全，固件韧性保障篡改固件自动恢复。 openUBMC同样提供完整的签名身份认证能力，提供端到端的固件包签名、校验解密、秘钥管理等能力，最大化地保障固件完整性，保护防篡改。  openUBMC社区同时建立了透明的研发流程，从需求接纳管理，需求实现设计，代码编写，社区自动化构建，到社区正式发布。同时围绕社区源码，以及社区依赖的三方库，openUBMC建立了完整的漏洞管理体系，流程化地管理软件漏洞和风险，最大化保障软件安全。 总结  外置可信根标准化（硬件设计+接口）+内置可信根开源成为未来硬件可信根的趋势。异构可信计算体系下，内存池化增大了暴露面，传统的TPM可信启动技术、DICE的环境保护技术、可信根互联技术将深度融合统一，成为智能部件的必备基础安全能力。 信任链的传递、安全签名、代码交叉审计是国内安全生态建设中最缺失的；安全技术的复杂性导致推广落地缓慢，微软的徽标认证和OCP S.A.F.E固件签名体系值得国内固件安全生态借鉴。如何利用openUBMC社区，联合产业上下游共同打造国内的固件安全生态体系，是社区接下来的重点工作之一。 在此，openUBMC社区诚邀业界同行，共同建设固件领域新生态，打造国内一流的固件安全生态体系。 html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html .sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}html.sepia .shiki span {color: var(--shiki-sepia);background: var(--shiki-sepia-bg);font-style: var(--shiki-sepia-font-style);font-weight: var(--shiki-sepia-font-weight);text-decoration: var(--shiki-sepia-text-decoration);}",[15],{"_path":244,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":245,"description":246,"date":10,"archives":11,"category":12,"author":247,"body":250,"_type":235,"_id":433,"_source":237,"_file":434,"_stem":435,"_extension":240,"coverImage":295,"plainText":436,"authorNames":437},"\u002Fen\u002Fblogs\u002Fsecure-and-reliable-application","Trusted Security Applications Based on openUBMC","In today's complex and evolving network security landscape, firmware has become a prime target for attackers, with security threats on the rise. As the foundational layer of a computing system, firmware plays a critical role in the overall security and resilience of the system. Given its position at the lowest layer and its high-level privileges, a compromised firmware can render upper-layer protections ineffective. Therefore, enhancing the security and resilience of firmware is of paramount importance in the current threat environment.",[248],{"name":15,"description":249},"Computing hardware security technology expert at Huawei Technologies Co., Ltd.",{"type":18,"children":251,"toc":431},[252,257,263,267,272,290,297,302,307,312,319,324,329,335,342,347,354,359,364,369,374,381,386,391,398,403,409,416,421,426],{"type":21,"tag":22,"props":253,"children":255},{"id":254},"trusted-security-applications-based-on-openubmc",[256],{"type":27,"value":245},{"type":21,"tag":22,"props":258,"children":260},{"id":259},"firmware-security-risks",[261],{"type":27,"value":262},"Firmware Security Risks",{"type":21,"tag":55,"props":264,"children":265},{},[266],{"type":27,"value":246},{"type":21,"tag":55,"props":268,"children":269},{},[270],{"type":27,"value":271},"Computing systems exhibit the following characteristics:",{"type":21,"tag":65,"props":273,"children":274},{},[275,280,285],{"type":21,"tag":69,"props":276,"children":277},{},[278],{"type":27,"value":279},"Privilege restriction: Lower layers can limit the privileges of upper layers, whereas upper layers cannot constrain lower layers. Consequently, attacks targeting the firmware layer have a significant impact on upper-level systems.",{"type":21,"tag":69,"props":281,"children":282},{},[283],{"type":27,"value":284},"Attack vulnerability: Upper layers cannot effectively defend against attacks originating from lower layers. If the firmware is compromised, the entire system becomes highly vulnerable.",{"type":21,"tag":69,"props":286,"children":287},{},[288],{"type":27,"value":289},"Privilege hierarchy: Lower layers possess greater privileges, with hardware holding the highest level. Since firmware operates close to the hardware, ensuring its security is especially critical.",{"type":21,"tag":55,"props":291,"children":292},{},[293],{"type":21,"tag":88,"props":294,"children":296},{"alt":90,"src":295},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg0.png",[],{"type":21,"tag":55,"props":298,"children":299},{},[300],{"type":27,"value":301},"According to the BMC CVE vulnerability statistics, the number of BMC firmware vulnerabilities has steadily increased from 2012 to 2021. In 2021, the count reached 39, significantly higher than in previous years. These vulnerabilities are predominantly high-risk, including types such as remote exploitation and arbitrary code execution. For instance, vulnerabilities like CVE-2013-1945 and CVE-2012-2959 enable remote attackers to execute arbitrary code, posing a serious threat to system security.",{"type":21,"tag":55,"props":303,"children":304},{},[305],{"type":27,"value":306},"With the rapid advancement of AI infrastructure, hardware roots of trust (RoTs) vary in design. Some are built-in, while others are external, leading to differences in security capabilities across devices. This variation makes collaboration challenging and poses risks to data center security. Industry implementations include TPM, SGX, Arm TrustZone, and TPCM, some embedded within SoCs and others placed externally on the board.",{"type":21,"tag":55,"props":308,"children":309},{},[310],{"type":27,"value":311},"Therefore, both built-in and external hardware RoTs form the basis of firmware trust. In a trusted computing system, the trust chain begins with the hardware RoT, which plays a key role in maintaining platform integrity. A hardware RoT generally includes components such as a cryptographic engine, hardware true random number generator, one-time programmable memory, secure SRAM, and corresponding secure firmware.",{"type":21,"tag":55,"props":313,"children":314},{},[315],{"type":21,"tag":88,"props":316,"children":318},{"alt":90,"src":317},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg1.png",[],{"type":21,"tag":55,"props":320,"children":321},{},[322],{"type":27,"value":323},"Common hardware RoTs include RTM, RTS, and RTR in TPM\u002FTCM, BSBC boot code in secure boot, root public key hashes stored in eFuse, TPCM in Trusted Computing 3.0, and Microsoft's open-source Caliptra RoT, which includes a platform root of trust (pRoT).",{"type":21,"tag":55,"props":325,"children":326},{},[327],{"type":27,"value":328},"Based on built-in or external hardware RoTs, trust chain technologies are used to implement security features such as tamper resistance, protection against supply chain replacement, and prevention of unauthorized channel distribution. Cloud providers leverage RoT chips to enable secure boot and hardware identity protection, and they use both internal and external RoTs to perform trusted measurements and identity authentication for intelligent data center components. Chinese CPU manufacturers typically adopt built-in TPCM solutions to achieve trusted computing 3.0 boot and runtime measurement control for server platforms.",{"type":21,"tag":22,"props":330,"children":332},{"id":331},"trusted-security-application-practices-of-openubmc",[333],{"type":27,"value":334},"Trusted Security Application Practices of openUBMC",{"type":21,"tag":55,"props":336,"children":337},{},[338],{"type":21,"tag":88,"props":339,"children":341},{"alt":90,"src":340},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg2.png",[],{"type":21,"tag":55,"props":343,"children":344},{},[345],{"type":27,"value":346},"The trusted security applications of openUBMC, based on the Hi171x series chips, have been thoroughly validated across various scenarios, including computing servers, storage devices, telecom computing platforms, and edge computing. This provides a comprehensive solution for both hardware and software security protection.",{"type":21,"tag":55,"props":348,"children":349},{},[350],{"type":21,"tag":88,"props":351,"children":353},{"alt":90,"src":352},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg3.png",[],{"type":21,"tag":55,"props":355,"children":356},{},[357],{"type":27,"value":358},"Building on the hardware RoT, hierarchical trust chain transfer is implemented to achieve system-level, full-stack, high-security protection. openUBMC establishes trusted and confidential computing capabilities through features such as firmware resilience, trusted boot, secure upgrade, secure boot, secure runtime, and data protection.",{"type":21,"tag":55,"props":360,"children":361},{},[362],{"type":27,"value":363},"Its component-based architecture distributes BMC functions across different modules. It optimizes interactions between components through standardized interfaces, unified data storage, and permission management.",{"type":21,"tag":55,"props":365,"children":366},{},[367],{"type":27,"value":368},"In addition, openUBMC defines different security levels according to the service attributes of data. Its data partitioning capabilities protect data of varying sensitivity to minimize the risk of data leakage.",{"type":21,"tag":55,"props":370,"children":371},{},[372],{"type":27,"value":373},"openUBMC incorporates a sandbox mechanism that defines varying permission levels and minimal resilience scopes based on component services, establishing a multi-layered protection system.",{"type":21,"tag":55,"props":375,"children":376},{},[377],{"type":21,"tag":88,"props":378,"children":380},{"alt":90,"src":379},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg4.png",[],{"type":21,"tag":55,"props":382,"children":383},{},[384],{"type":27,"value":385},"Based on different trusted partitions, openUBMC designs dedicated data recovery and interface permission degradation processes to achieve chip-level RoT boot security and firmware resilience. This ensures the automatic firmware recovery from tampering.",{"type":21,"tag":55,"props":387,"children":388},{},[389],{"type":27,"value":390},"openUBMC also offers comprehensive signature and identity authentication capabilities, including end-to-end firmware package signing, verification, decryption, and key management. These features maximize firmware integrity and help prevent tampering.",{"type":21,"tag":55,"props":392,"children":393},{},[394],{"type":21,"tag":88,"props":395,"children":397},{"alt":90,"src":396},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg5.png",[],{"type":21,"tag":55,"props":399,"children":400},{},[401],{"type":27,"value":402},"The openUBMC community has established a transparent R&D process that encompasses requirement acceptance, implementation design, coding, automated community building, and official releases. In addition, openUBMC has developed a comprehensive vulnerability management system based on the community's source code and third-party libraries. This system enables process-driven management of software vulnerabilities and risks to maximize software security.",{"type":21,"tag":22,"props":404,"children":406},{"id":405},"summary",[407],{"type":27,"value":408},"Summary",{"type":21,"tag":55,"props":410,"children":411},{},[412],{"type":21,"tag":88,"props":413,"children":415},{"alt":90,"src":414},"\u002Fcategory\u002Fblog\u002Fsecure-and-reliable-application\u002Fimg6.png",[],{"type":21,"tag":55,"props":417,"children":418},{},[419],{"type":27,"value":420},"The standardization of external RoTs, including hardware design and interfaces, and the open-sourcing of built-in RoTs are expected to be the future trend. In heterogeneous trusted computing systems, memory pooling increases the attack surface. Traditional TPM-based trusted boot technology, DICE environment protection, and RoT interconnection technologies will be integrated and unified. They will become essential security capabilities for smart components.",{"type":21,"tag":55,"props":422,"children":423},{},[424],{"type":27,"value":425},"In China, trust chain transfer, secure signatures, and code cross-auditing are major gaps in the security ecosystem. The complexity of security technologies slows down adoption and implementation. Systems like Microsoft's logo certification and the OCP S.A.F.E firmware signing framework provide useful examples for China. The openUBMC community aims to work with upstream and downstream industry partners to build a strong firmware security ecosystem in China.",{"type":21,"tag":55,"props":427,"children":428},{},[429],{"type":27,"value":430},"The openUBMC community invites industry peers to join in creating a new firmware ecosystem and establishing a first-class firmware security environment in China.",{"title":7,"searchDepth":233,"depth":233,"links":432},[],"content:en:blogs:secure-and-reliable-application.md","en\u002Fblogs\u002Fsecure-and-reliable-application.md","en\u002Fblogs\u002Fsecure-and-reliable-application","Trusted Security Applications Based on openUBMC Firmware Security Risks In today's complex and evolving network security landscape, firmware has become a prime target for attackers, with security threats on the rise. As the foundational layer of a computing system, firmware plays a critical role in the overall security and resilience of the system. Given its position at the lowest layer and its high-level privileges, a compromised firmware can render upper-layer protections ineffective. Therefore, enhancing the security and resilience of firmware is of paramount importance in the current threat environment. Computing systems exhibit the following characteristics: Privilege restriction: Lower layers can limit the privileges of upper layers, whereas upper layers cannot constrain lower layers. Consequently, attacks targeting the firmware layer have a significant impact on upper-level systems. Attack vulnerability: Upper layers cannot effectively defend against attacks originating from lower layers. If the firmware is compromised, the entire system becomes highly vulnerable. Privilege hierarchy: Lower layers possess greater privileges, with hardware holding the highest level. Since firmware operates close to the hardware, ensuring its security is especially critical.  According to the BMC CVE vulnerability statistics, the number of BMC firmware vulnerabilities has steadily increased from 2012 to 2021. In 2021, the count reached 39, significantly higher than in previous years. These vulnerabilities are predominantly high-risk, including types such as remote exploitation and arbitrary code execution. For instance, vulnerabilities like CVE-2013-1945 and CVE-2012-2959 enable remote attackers to execute arbitrary code, posing a serious threat to system security. With the rapid advancement of AI infrastructure, hardware roots of trust (RoTs) vary in design. Some are built-in, while others are external, leading to differences in security capabilities across devices. This variation makes collaboration challenging and poses risks to data center security. Industry implementations include TPM, SGX, Arm TrustZone, and TPCM, some embedded within SoCs and others placed externally on the board. Therefore, both built-in and external hardware RoTs form the basis of firmware trust. In a trusted computing system, the trust chain begins with the hardware RoT, which plays a key role in maintaining platform integrity. A hardware RoT generally includes components such as a cryptographic engine, hardware true random number generator, one-time programmable memory, secure SRAM, and corresponding secure firmware.  Common hardware RoTs include RTM, RTS, and RTR in TPM\u002FTCM, BSBC boot code in secure boot, root public key hashes stored in eFuse, TPCM in Trusted Computing 3.0, and Microsoft's open-source Caliptra RoT, which includes a platform root of trust (pRoT). Based on built-in or external hardware RoTs, trust chain technologies are used to implement security features such as tamper resistance, protection against supply chain replacement, and prevention of unauthorized channel distribution. Cloud providers leverage RoT chips to enable secure boot and hardware identity protection, and they use both internal and external RoTs to perform trusted measurements and identity authentication for intelligent data center components. Chinese CPU manufacturers typically adopt built-in TPCM solutions to achieve trusted computing 3.0 boot and runtime measurement control for server platforms. Trusted Security Application Practices of openUBMC  The trusted security applications of openUBMC, based on the Hi171x series chips, have been thoroughly validated across various scenarios, including computing servers, storage devices, telecom computing platforms, and edge computing. This provides a comprehensive solution for both hardware and software security protection.  Building on the hardware RoT, hierarchical trust chain transfer is implemented to achieve system-level, full-stack, high-security protection. openUBMC establishes trusted and confidential computing capabilities through features such as firmware resilience, trusted boot, secure upgrade, secure boot, secure runtime, and data protection. Its component-based architecture distributes BMC functions across different modules. It optimizes interactions between components through standardized interfaces, unified data storage, and permission management. In addition, openUBMC defines different security levels according to the service attributes of data. Its data partitioning capabilities protect data of varying sensitivity to minimize the risk of data leakage. openUBMC incorporates a sandbox mechanism that defines varying permission levels and minimal resilience scopes based on component services, establishing a multi-layered protection system.  Based on different trusted partitions, openUBMC designs dedicated data recovery and interface permission degradation processes to achieve chip-level RoT boot security and firmware resilience. This ensures the automatic firmware recovery from tampering. openUBMC also offers comprehensive signature and identity authentication capabilities, including end-to-end firmware package signing, verification, decryption, and key management. These features maximize firmware integrity and help prevent tampering.  The openUBMC community has established a transparent R&D process that encompasses requirement acceptance, implementation design, coding, automated community building, and official releases. In addition, openUBMC has developed a comprehensive vulnerability management system based on the community's source code and third-party libraries. This system enables process-driven management of software vulnerabilities and risks to maximize software security. Summary  The standardization of external RoTs, including hardware design and interfaces, and the open-sourcing of built-in RoTs are expected to be the future trend. In heterogeneous trusted computing systems, memory pooling increases the attack surface. Traditional TPM-based trusted boot technology, DICE environment protection, and RoT interconnection technologies will be integrated and unified. They will become essential security capabilities for smart components. In China, trust chain transfer, secure signatures, and code cross-auditing are major gaps in the security ecosystem. The complexity of security technologies slows down adoption and implementation. Systems like Microsoft's logo certification and the OCP S.A.F.E firmware signing framework provide useful examples for China. The openUBMC community aims to work with upstream and downstream industry partners to build a strong firmware security ecosystem in China. The openUBMC community invites industry peers to join in creating a new firmware ecosystem and establishing a first-class firmware security environment in China.",[15],[439,439],null,1784971460900]