Research and Implementation of EFI OS Loader Security Reinforcement Technology

WU Wei-min, CHEN Dong-xin, LAI Wen-xin and SU Qing   

Abstract: By analyzing the safety of architecture and boot procedure of unified extensible firmware interface (UEFI),it is found that the credibility verification of EFI OS Loader has security risks,which can lead to the hijack of Windows startup process.To avoid the security risks,considering from the three layers of file isolation protection,boot authentication and system critical region protection,a three-layer security reinforcement plan based on USB Key,the dynamic password cell phone token and EFI antivirus software was proposed.Storing the EFI OS Loader file in the USB Key and encrypting it can achieve the file protection.The dynamic password authentication server is placed in the USB Key,and the combination of both mechanism can achieve a high intensity boot authentication.Designing and developing an EFI application security software following the UEFI specification can achieve the protection of the key region of system.The results show that the dual authentication and security mechanism of the program make up the relevant security vulnerabilities,and enhance the security of computer systems during startup.

Key words: EFI OS loader,Credibility verification,Security reinforcement,Identity authentication

