××ך ×€×֞ךש××Öž×× ×Š× ×××× ×ַך×Öž×€ÖŒ ×Š× ×Ö· × ××עך×ק ××ך×× ××××עך ××× ×š×¢×× ×××¢×× ×× ×××עך×××× ×€×× ×€×ך××××ַךע ×€Ö¿×ַך קס86 ק×Ö·××€ÖŒ×Ö·××Ö·××Ö·× ×§×Öž××€ÖŒ×××עך ×€ÖŒ××Ö·××€×֞ך×ס. ××֞ס ××Öž×, ×× ××××€ÖŒ× ×× ×ך××××Ö·× × ×€×× ××¢× ××¢×š× ×¢× ××× Intel Boot Guard (× ×× ×Š× ×××× ×Š×¢×××©× ××× Intel BIOS Guard!) - ×Ö· ××Ö·×× ×××ַך×-×עש×××Š× ×ך×ַס××× ××××Öž×ס ש××××× ××¢×× ×Öž××Öž×××¢ ×××֞ס ×× ×§×Öž××€ÖŒ×××עך ס×ס××¢× ×€×ַךק××׀עך ×§×¢× ×¢× ×€ÖŒ×¢×š××Ö·× ×Ö·× ××× ××¢×× ×Öž×עך ××ס××××Ö·× ××× ×× ×€ÖŒ×š×Öž××ק׊××¢ ××× ×¢. × ×, ×עך ×€×֞ךש×× × ×š×¢×Š×¢×€ÖŒ× ××× ×©××× ××ַק×Ö·× × ×Š× ××× ××: ׊ע××Ö·×§× ×× ×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×€×× ××¢× ××¢×× ×Öž××Öž×××¢ ××× ×€×Ö·×š×§×¢×š× ×× ××©×¢× ×עך××¢, ××ַשך××Ö·×× ×××Ö·× ×ַךק×Ö·×עק×שעך, ×€ÖŒ××Öž××××š× ×¢×¡ ××× ×Ö·× ××ַק××Ö·××¢× ×× ××¢××Ö·××ס, סע××Öž× ×¢×¡ ××× ×Ö·××ַק ××עק××֞ךס ×Š× ×עש××ַק ××× ××ש×. ××Öž××ך ××××× ××š×¢× ×××Ö·×š× ×Š× ×עך ×עש××××¢ ×€×× ââ××× ×Ö· ×ש×ק ×××֞ס ××× ××¢×××¢× ×§××Öž×× × ×€Ö¿×ַך ××Öž×š× ××× ×× ×€ÖŒ×š×Öž××ק׊××¢ ×€×× ââââ×¢×××¢××¢ ×××¢× ××֞ךס ×Ö·××Ö·×× ×Ö· ×€ÖŒ×Öž××¢× ×Š××¢× ×Ö·××ַקעך ×Š× × ××Š× ××¢× ××¢×× ×Öž××Öž×××¢ ×Š× ×©×Ö·×€Ö¿× ×Ö· ×€×ַך××֞ך×× ×š×Öž×Öž×ק×× ××× ×× ×¡×ס××¢× ×××֞ס ×§×¢× ×¢× × ×× ×××× ×Ö·××עק××¢× ×××¢× (××€××× ××× ×Ö· ׀֌ך×Öž×ך×Ö·××ס×).
×××š× ××¢× ×××¢×, ×עך ×ַך×××§× ××× ×××××š× ××××£ ×× ×š××€ÖŒ×֞ךץ "On Guard of Rootkits: Intel BootGuard" ×€Ö¿×× ×עך ××׊×× ×
×€×ך××××ַךע ×€Ö¿×ַך ×Ö· ק×Öž××€ÖŒ×××עך ×€ÖŒ××Ö·××€×֞ך××¢ ××× Intel 64 ×ַךק×Ö·×עק×שעך
עךש×עך, ××Öž×× ××× ×× ×¢× ××€Ö¿×¢×š× ×× ×§×©××: ×××֞ס ××× ×× ×€×ך××××ַךע ×€×× ââ×Ö· ××Öž××¢×š× ×§×Öž××€ÖŒ×××עך ×€ÖŒ××Ö·××€×֞ך××¢ ××× ×× ××¢× 64 ×ַךק×Ö·×עק×שעך? ×€×× ×§×ךס, UEFI BIOS. ×Öž×עך ×Ö·××Ö· ×¢× ×׀עך ×××¢× × ××©× ×××× ×€ÖŒ×× ×××¢×. ××× ×¡ × ×¢××¢× ×Ö· ק×ק ××× ×× ××××, ×××֞ס ×××××× ×× ×עסק××Ö·×€ÖŒ (××Ö·×€ÖŒ××Ö·×€ÖŒ) ××עךס××¢ ×€×× ââ××¢× ×ַךק×Ö·×עק×שעך.
×עך ×ס×× ××× ×× ××× ×§:
- ׀֌ך×ַסעסעך (ק׀֌×, ×¡×¢× ×ך×Ö·× ×€ÖŒ×š×ַסעס×× × ××× ××), ×××֞ס, ××× ×Ö·××ש×Ö·× ×Š× ×× ××××€ÖŒ× ×§×֞ךעס, ××× ×Ö· ××¢××××-××× ×ך×Ö·×€×קס ××ַךץ (× ×× ××× ×Ö·××¢ ××Öž××¢×ס) ××× ×Ö· ××֌ך×× ×§×Öž× ×ך×Öž××עך (××ק, ×× ××¢×ך×Ö·××¢× ××֌ך×× ×§×Öž× ×ך×Öž××עך);
- ×ש××€ÖŒ×¡×¢× (PCH, Platform Controller Hub), ××× ×€×ַךש××× ×§×Ö·× ×ך×Öž×××¢×š× ×€Ö¿×ַך ×× ×עך×ַק××× × ××× ×€ÖŒ×¢×š×׀עך×Ö·× ××¢×××סעס ××× ×Öž× ×€×ך×× × ×¡×Ö·×ס×ס××Ö·××. ׊××××©× ××× ××× ×עך ××ק×× ×עך Intel Management Engine (ME), ×××֞ס ×××× ××× ×€×ך××××ַךע (Intel ME ×€×ך××××ַךע).
××Ö·×€ÖŒ××֞׀֌ס, ××× ×Ö·××ש×Ö·× ×Š× ×× ×××××, ××Ö·×š×€× ×Ö· ××¢××××-××× ×§×Öž× ×ך×Öž××עך (ACPI EC, Advanced Control ××× Power Interface Embedded Controller), ×××֞ס ××× ×€×ַך×Ö·× ××××֞ך×××¢× ×€Ö¿×ַך ×× ×֞׀֌עך×ַ׊××¢ ×€×× ââ×× ××Ö·×× ×¡×Ö·×ס×ס××Ö·×, ××Öž××ש׀֌×Ö·×, ק××Ö·××××Ö·××ך, Fn ש××ס××¢× (×€×ַךש××¢×× ×ך×××× ×ַס, ××¢××× × ××Ö·× ×) , ק××Ö·××××Ö·××ך ××ַק××××, ×××"× ×) ××× ×× ×עךע ××××. ××× ×¢×¡ ×××× ××× ×××Ö·× ×××××¢× ×¢ ×€×ך××××ַךע.
×Ö·×××, ×× ××Öž×××Ö·××Ö·×× ×€×× ×× ×€×ך××××ַךע ××××× ××× ×× ×€×ך××××ַךע ×€×× ââ×× ×§×Öž××€ÖŒ×××עך ×€ÖŒ××Ö·××€×֞ך××¢ (ס×ס××¢× ×€×ך××××ַךע), ×××֞ס ××× ×¡××Öž×š× ××××£ ×Ö· ׀֌ך×Öž×¡× ×¡×€ÖŒ× ××××¥ ××֌ך××. ×Ö·××× ×Ö·× ×× × ×׊עךס ×€×× ××¢× ××֌ך×× ××Öž× × ×× ×Š×¢×××©× ×××¢×× ××× ×¢×¡ ×××, ×× ××× ××Ö·×× ×€×× ××¢× ××֌ך×× ××× ×Š×¢××××× ××× ×× ×€××××¢× ××¢ ×ק×××ת (××× ××¢××××× ××× ×× ×€×××ך):
- UEFI BIOS;
- ACPI EC ×€×ך××××ַךע (×Ö· ××Ö·××× ×עך ××¢×× × ××× ×ך××ס ××× ×× Skylake ׀֌ך×ַסעסעך ××קך×Öž×ַך×ש××עק××ךע (2015), ×Öž×עך ×××-××-××××× ××ך ××Öž×× × ×Öž× × ××©× ××¢××¢× ×××ש׀××× ×€×× ×××Ö·× × ×׊×, ×Ö·××× ×× ×€×ך××××ַךע ×€×× ââ×× ××¢××××-××× ×§×Öž× ×ך×Öž××עך ××× × ×Öž× ×ַך××Ö·× ×עךע×× × ××× ×× UEFI ××××Öž×ס) ;
- ×× ××¢× ××ך ×€×ך××××ַךע;
- ק×Ö·× ×€×××עך××ש×Ö·× (××ַק ×Ö·×ךעס, ×××"× ×) ×€×× ×× ××¢××××-××× ×××¢ (××××Ö·××× ×¢×××¢×š× ×¢×) × ×¢×¥ ×Ö·××Ö·×€ÖŒ×עך;
- ×€××ַש ×עסקך××€ÖŒ××֞ךס ××¢× ×¢× ×× ××××€ÖŒ× ××¢×× × ×€×× ××××¥ ××֌ך×× ×××֞ס ×ÖŒ××× ×€ÖŒ××× ××¢×š× ×Š× ×× ×עךע ×ק×××ת, ××× ××¢××× × ××× ×€ÖŒ×¢×š××ש×Ö·× × ×Š× ×ַקסעס ×××.
×× SPI ××××Öž××ס ××¢×, ×Ö· SPI ק×Öž× ×ך×Öž××עך ××¢×××× ××× ×× ×ש×׀֌סע×, ×××š× ×××֞ס ××¢× ××֌ך×× ××× ×ַקסעס×, ××× ×€×ַך×Ö·× ××××֞ך×××¢× ×€Ö¿×ַך ××××××Ö·××× × ×ַקסעס ×Š× ×ק×××ת (××× ×××× ××× ×× ×¡×€ÖŒ×¢×¡××€××¢× ×€ÖŒ×¢×š××ש×Ö·× ×). ×××× ×€ÖŒ×¢×š××ש×Ö·× × ××¢× ×¢× ××ַש×××× ×Š× ×× ××¢× ×¡ ךעק×Ö·××¢× ××× (×€Ö¿×ַך ×××עך×××× ×¡×××ת) ×××Ö·××עס, ××¢×עך SPI ××××¥ ××Ö·× ×׊עך ××× ×€×× ×ַקסעס (××××¢× ×¢× / שך××Ö·××) ××××× ×Š× ×××עך ××¢×× ×. ××× ×× ×× ××× ××¢× ×¢× ×Öž×עך ××××× ××××¢× ×¢× ×Öž×עך ×× ×ַקסעס×Ö·××Ö·×. × ×××××ס×עך ×€×ַק×: ××××£ ×€×××¢ ס×ס××¢××¢×, ×× ×§×€ÖŒ× ××× ×€×× ×ַקסעס ×Š× ×× UEFI ××××Öž×ס ××× GbE, ××××¢× ×¢× ×ַקסעס ××××× ×Š× ××××¥ ××סקך××€ÖŒ××֞ךס ××× ×§××× ×ַקסעס ×Š× ×× Intel ME ××¢×× ×. ×€×ך×××ס ××××£ ×€×××¢, ××× × ××©× ××××£ ×Ö·××¢? ×××֞ס ××× ×š×¢×§×Ö·××¢× ××× ××× × ××©× ×€×ך××× ××. ××ך ×××¢× ××Öž×× ××ך ×עך ××× ××¢××Ö·× ×©×€ÖŒ×¢×עך ××× ××¢× ×ַך××ק×.
×עק×Ö·× ×××Ö·×× ×€Ö¿×ַך ׀֌ך×Ö·×עק××× × ×§×Öž××€ÖŒ×××עך ×€ÖŒ××Ö·××€×֞ך××¢ ×€×ך××××ַךע ×€×× ââ××Öž×××€×ק×Ö·×××Öž×
××Öž×, ×× ×€×ך××××ַךע ×€×× ââ×Ö· ק×Öž××€ÖŒ×××עך ×€ÖŒ××Ö·××€×֞ך××¢ ××Öž× ×××× ×€ÖŒ×š×Öž×עק××¢× ×€×× ××¢×××¢× ×§×Öž×׀֌ך×Öž××ס, ×××֞ס ×××Öž×× ××Öž×× ×Ö· ×€ÖŒ×Öž××¢× ×Š××¢× ×Ö·××ַקעך ×Š× ××ַק×××¢× ×Ö· ×€××××Öž××× ××× ×¢×¡ (××××Ö·×× ××¢×× ×ַס ×עך×××Ö·× ××ק×× ××¢× / ך××× ×¡××Ö·××××ש×Ö·× ×), ××ס׀××š× ×××עך ק×Öž× ××× ×× ××¢×š×¡× ×€ÖŒ×š××××××××©× ××Öž×עס, ×××"× ×. ××× ×š×ס×ך×ק××× × ×ַקסעס ×Š× SPI ××××¥ ××֌ך×× ×ק×××ת ×××, ×€×× ×§×ךס, × ××©× ××¢× ××. ×עך××עך, ×Š× ××ַש××Š× ×× ×€×ך××××ַךע ×€×× ââ××Öž×××€×ק×Ö·×××Öž× ×¡, ×€×ַךש××× ×עק×Ö·× ×××Ö·×× ×¡×€ÖŒ×¢×Š××€×ש ×Š× ××¢×עך ×ַ׀֌עך××××× × ×¡××××××¢ ××¢× ×¢× ××¢× ×׊×.
××××, ×× Intel ME ×€×ך××××ַךע ××× ××¢×ת××¢× ×Š× ×§×Öž× ×ך×Öž×××š× ×Öž×š× ×××¢×ק××Ö·× ××× ×Öž××Ö·× ××ס×××, ××× ××× ×Öž×€ÖŒ×עש××¢×× ×××š× ×× ME ק×Öž× ×ך×Öž××עך ××¢×עך ××Öž× ×¢×¡ ××× ××Öž×××× ××× ×× ME UMA ××֌ך××. ×עך ××עך×Ö·×€×ַק××ש×Ö·× ×€ÖŒ×š×֞׊עס ××× ×©××× ××סק×Ö·×¡× ×××š× ××× ×× ××× ×××× ×¢×š ×€××
××× ACPI EC ×€×ך××××ַךע, ××× ×Ö· ×עךש×, ××× ×Öž×€ÖŒ×עש××¢×× ××××× ×€Ö¿×ַך ×Öž×š× ×××¢×ק××Ö·×. ×Öž×עך, ךע×× ×Š× ××¢× ×€×Ö·×§× ×Ö·× ×× ×××× ×¢×š× ××× ×ַך××Ö·× ×עךע×× × ××× ×× UEFI ××××Öž×ס, עס ××× ×ÖŒ××¢× ×©××¢× ××ק ××× ×עך××¢× ×ק ×Š× ×× ××¢×××¢ ש××¥ ×עק×Ö·× ×××Ö·×× ×Ö·× ×× UEFI ××××Öž×ס × ×׊×. ××Öž××ך ךע×× ×××¢×× ×××.
×× ×עק×Ö·× ×××Ö·×× ×§×¢× ×¢× ×××× ×Š×¢××××× ××× ×Š×××× ×§×Ö·××¢××֞ך×עס.
שך××× ×©××¥ ××× ×× UEFI BIOS ××¢×× ×
- ×ש×××ת ש××¥ ×€×× ×× ××× ××Ö·×× ×€×× SPI ××××¥ ××֌ך×× ××× ×Ö· שך××Ö·××-××ַש××Š× ××ש×Ö·×׀֌עך;
- ׀֌ך×Ö·×עק××× × ×× ×€ÖŒ×š××עק׊××¢ ×€×× ââ×× UEFI ××××Öž×ס ××¢×× × ××× ×× ×§×€ÖŒ× ×Ö·×ךעס ×€ÖŒ××Ö·×¥ × ××Š× PRx ×ש××€ÖŒ×¡×¢× ×š×¢××ש×ס×עךס;
- ×××ַק×× × ×€×š×××× ×Š× ×©×š××Ö·×× ×Š× ×× UEFI ××××Öž×ס ××¢×× × ×××š× ×××©×¢× ×¢×š××××× × ××× ×€ÖŒ×š×ַסעס×× × ×× ×§×֞ך×ַס׀֌×Ö·× ××× × ×¡×× ××עךך××ַס ×××š× ××ַש××¢×××§× ×× BIOS_WE/BLE ××× SMM_BWP ×××× ××× ×× ×ש××€ÖŒ×¡×¢× ×š×¢××ש×ס×עךס;
- × ×עך ×Ö·×××Ö·× ×¡×ך××¢ ××עךס××¢ ×€×× ââââ××¢× ×©××¥ ××× Intel BIOS Guard (PFAT).
××× ×Ö·××ש×Ö·× ×Š× ×× ×עק×Ö·× ×××Ö·××, ×××¢× ××֞ךס ×§×¢× ×¢× ×Ö·× ××××ק××¢× ××× ×× ×¡×ך×××¢× × ×××עך ×××××¢× ×¢ ×××עך×××× ×××××¢× (××ש×, ס××× ×× × ×§×ַ׀֌ס×Ö·×× ××× UEFI BIOS ×עך×××Ö·× ××ק×× ××¢×).
עס ××× ××××××ק ×Š× ××Öž× ×Ö·× ××××£ ×Ö· ס׀֌ע׊××€×ש ס×ס××¢× (×××€ÖŒ×¢× ××× × ××××£ ×× ×€×ַךק××׀עך), × ×× ×Ö·××¢ ×€×× ââ×× ××××× ×©××¥ ×עק×Ö·× ×××Ö·×× ×§×¢× ×××× ××¢×××¢× ××, ××× ×§×¢× × ××©× ×××× ××¢×××¢× ×× ××× ×Ö·××¢, ×Öž×עך ××× ×§×¢× ×××× ×××€ÖŒ××Ö·××¢× ×Ö·× ××× ×Ö· ש׀֌×ךע××××ק ש××××עך. ××ך ×§×¢× × ××××¢× ×¢× ×עך ×××¢×× ×× ×עק×Ö·× ×××Ö·×× ××× ×× ×¡××××ַ׊××¢ ××× ×××עך ×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×××
UEFI BIOS ×Öž××¢× ××ַק××ש×Ö·×
×××¢× ××ך ךע×× ×××¢×× ×ך×ַס××× ×©××××× ××¢×§× ×Ö·××Ö·××ש××, ×עך עךש×עך ××Ö·× ×××֞ס ק××× ×Š× ×××× ×× × ××× ×××עך ש×××××. ×Öž×עך, ×ַךק×Ö·×עק×שעך×Ö·×× ×¢×¡ ××× ×××××× × ×Š× ××ַש××¢×××§× ×× ×Öž××Ö·× ××ס××× ×€×× ×§×Ö·××€ÖŒ×Öž×× ×Ö·× ×¥ ×€×× ×ך×××¡× ××ק ×Š× ×× UEFI ××××Öž×ס (×ך×××עךס, ××Öž×Öž×××Öž×Ö·×עךס, ×××"× ×) ××× × ××©× ×× ×€×ך××××ַךע ×××.
×עך××עך, Intel, ××× SoCs ××× Bay Trail ××קך×Öž×ַך×ש××עק××ךע (2012), ×××€ÖŒ××Ö·××¢× ×Ö·× ×Ö· ××Ö·×× ×××Ö·×š× × ××-×€×ַךקך××€ÖŒ×× ×××עך ש××××× (××עך××€××¢× ×©×××××), ×××֞ס ××× ××Öž×š× ××©× ××× ×€ÖŒ×š×Öž×¡× ××× ×× ×××××-×עך××× × ×¡×¢×§×ךע ××Öž×Öž× ××¢×× ×Öž××Öž×××¢. ש׀֌ע×עך (2013), ××¢× ×עק×Ö·× ×××Ö·× ××× ××׀֌ך×××× ××× ××׀ך××× ××× ×עך ×× × ×Öž××¢× Intel Boot Guard ×€Ö¿×ַך ×עסק××ַ׀֌ס ××× Haswell ××קך×Öž×ַך×ש××עק××ךע.
××××עך ××סקך××××× × Intel Boot Guard, ××Öž×× ××× ×× ×§×ק ××× ×× ××ך××€×ך×× × ×× ××××ך×Ö·× ××Ö·× ×¥ ××× ×× Intel 64 ×ַךק×Ö·×עק×שעך, ×××֞ס, ××× ×§×Öž×××× ×ַ׊××¢, ××¢× ×¢× ×× ×š××¥ ×€×× ×Š××ך×× ×€Ö¿×ַך ××¢× ×ך×ַס××× ×©××××× ××¢×× ×Öž××Öž×××¢.
×× ××¢× ×§×€ÖŒ×
ק×Ö·×€ÖŒ ס×Ö·×××שעסץ ×Ö·× ×עך ׀֌ך×ַסעסעך ××× ×× ××××€ÖŒ× ××ך××€×ך×× × ×¡××××××¢ ××× ×× ×× ××¢× 64 ×ַךק×Ö·×עק×שעך. ×€×ך×××ס ××× ×¢×¡ ×עך ×××Öž×š×Š× ×€×× ×Š××ך××? עס ××ײַ×× ××× ×××ס, ×Ö·× ××֞ס, ×××֞ס ××Ö·×× ××× ×Ö·××Ö·, ××× ××֞ס ×€Ö¿×ַך××Öž× ×€Ö¿×× ×× ××Öž××קע ×¢××¢××¢× ××:
- ××קך×֞ק×Öž××¢ ך×Ö·× ××× ×Ö· × ××-×××Ö·××Ö·××Ö·×, × ××-ך×ך××××Ö·××Ö·× ××֌ך×× ×€Ö¿×ַך ס××֞ך×× × ××קך×֞ק×Öž××¢. עס ××× ××¢×××× × ×Ö·× ××קך×֞ק×Öž××¢ ××× ×× ×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×€×× ×× ×€ÖŒ×š×ַסעסעך ××Ö·×€Ö¿×¢×× ×¡×ס××¢× ××× ×× ×¡×××€ÖŒ××Ö·×¡× ×× ×¡×ך×ַקש×Ö·× ×. ××Ö·×€ÖŒ×Ö·× × ×××× ××× ××קך×֞ק×Öž××¢
××Ö·×× . ×Ö·××× ××× ×× ××××Öž×ס ××ך ×§×¢× ×¢× ××¢×€Ö¿×× ×¢× ××× ×ַך×עס ××× ××קך×֞ק×Öž××¢ ×עך×××Ö·× ××ק×× ××¢× (×Öž×××עך×××× ×עש×ַס ש×××××, ××××Ö·× ×š×Ö·× ×§×¢× ×¢× × ×× ×××× ×Öž×××עךך×××Ö·×). ×עך ××× ××Ö·×× ×€×× ×× ××× ×ַך×עס ××× ×× ×§×š××€ÖŒ×××, ×××֞ס ק×Ö·××€ÖŒ××ק×××¥ ×××עך ×Ö·× ×Ö·××ס×ס (×עך××עך, ×עך ס׀֌ע׊××€×ש ××× ××Ö·×× ×€×× ×× ××קך×֞ק×Öž××¢ ××× ××ק×× × ××××× ×Š× ×× ×××ס ×Ö·× ××××ק××¢× ×¢×¡), ××× ××¢×ת××¢× ×Š× ×§×Öž× ×ך×Öž×××š× ×Öž×š× ×××¢×ק××Ö·× ××× ×Öž××Ö·× ××ס×××; - ×ַעס ש×××¡× ×€Ö¿×ַך ×עקך××€ÖŒ××× × ×× ××× ××Ö·×× ×€×× ××קך×֞ק×Öž××¢ ×עך×××Ö·× ××ק×× ××¢×;
- ××ַש ×€×× ×× RSA ×¢×€× ×××¢× ×©×××¡× ××¢× ××Š× ×Š× ××ַש××¢×××§× ×× ×ס×××¢ ×€×× ââ××קך×֞ק×Öž××¢ ×עך×××Ö·× ××ק×× ××¢×;
- RSA ×¢×€× ×××¢× ×©×××¡× ××ַש, ×××֞ס ××עך×Ö·×€××× ×× ×ס×××¢ ×€×× ââ×× ××¢×-××¢×××¢××Öž×€ÖŒ×¢× ×Ö·×§× (×Ö·××××¢× ××ק×Ö·××¢× ×§×Öž×× ××Öž××××¢) ק×Öž× ××Ö·××ש×××, ×××֞ס ×× ×§×€ÖŒ× ×§×¢× ×¢× ×§×Ö·×עך ××××עך ××××Öž×ס ××ך××€×ך×× × (××¢×× ××קך×֞ק×Öž××¢) ×Öž×עך ×עש×ַס ×××Ö·× ×֞׀֌עך×ַ׊××¢, ×××¢× ×××עך ××¢×©×¢×¢× ××©× ×€ÖŒ×ַס×ך×.
Intel ME
××× ××עך ×××Öž× ××× ××¢××ַק××××Ö·× ×Š× ××¢× ×¡×Ö·×ס×ס××Ö·×
×ך×Öž×¥ ×××× ×עס×Öž××ק××Ö·×, Intel ME ××× ×××× ×Ö· ×××Öž×š×Š× ×€×× ×Š××ך×× ××××Ö·× ×¢×¡ ×××:
- ME ROM - × ××-×××Ö·××Ö·××Ö·×, × ××-ך×ך××××Ö·××Ö·× ××֌ך×× (ק××× ×עך×××Ö·× ×××§× ×××€Ö¿× ××× ×Š××עש××¢××) ××× ×× ×Öž× ×××× ×§×Öž×, ××× ××¢××× × ××× ×× SHA256 ××ַש ×€×× ×× RSA ×¢×€× ×××¢× ×©××ס×, ×××֞ס ××עך×Ö·×€××× ×× ×ס×××¢ ×€×× ââ×× Intel ME ×€×ך××××ַךע;
- ×ַעס ש×××¡× ×€Ö¿×ַך ס××֞ך×× × ×¡×× ××× ×€Ö¿×֞ך××ַ׊××¢;
- ×ַקסעס ×Š× ×Ö· ××Ö·× × ×€×× ×€×סעס (×€×€×£, ×€××¢×× ×€ÖŒ×š×Öž×ך×Ö·×××Ö·×××¢ ×€×סעס) ×× ×Ö·×ך××××× ××× ×× ×ש××€ÖŒ×¡×¢× ×€Ö¿×ַך ש××¢× ××ק ס××֞ך×××ש ×€×× ×¢×××¢××¢ ××× ×€Ö¿×֞ך××ַ׊××¢, ×ַך××Ö·× ×עךע×× × ×× ×¡×€ÖŒ×¢×¡××€××¢× ×××š× ×× ×§×Öž××€ÖŒ×××עך ס×ס××¢× ×€×ַךק××׀עך.
Intel Boot Guard 1.x
× ×§×××× ×Öž×€ÖŒ××××§×¢× ×× ×. ×× ×× ××¢× ××Öž×Öž× ××Ö·×š× ××¢×× ×Öž××Öž×××¢ ××עךס××¢ × ×××¢×š× ×××֞ס ××ך × ××Š× ××× ××¢× ×ַך×××§× ××¢× ×¢× ×ַך×××ך×ַך×ש ××× ×§×¢× ××Öž×× ××Öž×š× ××©× ×Š× ××Öž× ××× ×× × ××עך×× × ××¢× ××Š× ××× ×× ××¢× ×¡ ×× ×¢×š××¢× ××ַק××××¢× ×××ש×Ö·×. ××× ×Ö·××ש×Ö·×, ×× ××× ×€Ö¿×֞ך××ַ׊××¢ ׊××עש××¢×× ××Öž ×××¢×× ×× ×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×€×× ××¢× ××¢×× ×Öž××Öž×××¢ ××× ××ק×××¢× ×עש×ַס ×€×Ö·×š×§×¢×š× ×× ××©×¢× ×עך××¢, ××× ×§×¢× ×Ö·× ×××Ö·××× ×× ×ַק×עך×ַס×× ×§×Ö·××€ÖŒ×¢×š× ××× ×× ×¡×€ÖŒ×¢×¡×Ö·×€×ַק××ש×Ö·× × ×€Ö¿×ַך Intel Boot Guard, ×××֞ס ××× ×Ö·× ×××ק×× ×Š× ×××× ×ך××ס.
×Ö·×××, Intel Boot Guard (BG) ××× ×Ö· ××Ö·×× ×××ַך×-×עש×××Š× UEFI ××××Öž×ס ×Öž××¢× ××ַק××ש×Ö·× ××עך×Ö·×€×ַק××ש×Ö·× ××¢×× ×Öž××Öž×××¢. ×××× ×ש׀×× ×××× ×××× ×§×ךץ ××ַשך××Ö·××× × ××× ××¢× ××× [×€ÖŒ××Ö·××€×Öž×š× ×¢×××¢××× ×××עך×××× ××¢×× ×Öž××Öž×××¢ ×××××, ק×Ö·×€ÖŒ××× ×©××××× ××× ×Öž×š× ×××¢×ק××Ö·×, ×Öž×עך × ×× ×©×××××], עס ×ַך××¢× ××× ×Ö· ×ך×ַס××× ×©××××× ×§×××. ××× ×עך עךש×עך ××× ×§ ××× ×¢×¡ ××× ×× ×©××××× ×§×Öž× (××קך×֞ק×Öž××¢) ×× ×× ×§×€ÖŒ×, ×××֞ס ××× ×ך×××¢×š× ×××š× ×× RESET ××¢×©×¢×¢× ×ש (× ×× ×Š× ×××× ×Š×¢×××©× ××× ×× RESET ××עק××֞ך ××× ×× ××××Öž×ס!). ×× ×§×€ÖŒ× ××¢×€×× × ×Ö· ק×Öž× ××Öž××××¢ ××¢×××¢××Öž×€ÖŒ×¢× ××× ××¢×ת××¢× ×××š× Intel (Intel BG ס××ַך××Ö·×€ÖŒ ACM) ××××£ ×× SPI ××××¥ ××֌ך××, ××Öž××× ×¢×¡ ××× ×××× ×§×ַש, ××עך×Ö·×€××× (עס ××× ×©××× ××××¢×š×§× ××××× ×Ö·× ×× ×§×€ÖŒ× ××× ×Ö· ××ַש ×€×× ×× ×Š×××ך ש×××¡× ×××֞ס ××עך×Ö·×€××× ×× ACM ×ס×××¢) ××× ××Öž× ×ש××.
×עך ק×Öž× ××Öž××××¢ ××× ×€×ַך×Ö·× ××××֞ך×××¢× ×€Ö¿×ַך ××עך×Ö·×€×××× × ×Ö· ק×××× ×¡××ַך××× × ×××× ×€×× ×× UEFI BIOS - Initial Boot Block (IBB), ×××֞ס, ××× ×§×¢×š, ×ÖŒ××× ×€×Ö·× ×קש×Ö·× ×Ö·×××× ×€Ö¿×ַך ××עך×Ö·×€×××× × ×× ××××€ÖŒ× ×××× ×€×× ×× UEFI ××××Öž×ס. ××××, Intel BG ×Ö·××Ö·×× ××ך ×Š× ××ַש××¢×××§× ×× ×Öž××Ö·× ××ס××× ×€×× ×× ××××Öž×ס ××××עך ××Öž×××× × ×× ×ַס (×××֞ס ×§×¢× ×¢× ×××× ××ך××עק×Öž×× ××× ×עך ×× ×ש××× ×€×× ×××עך ××Öž×Öž× ××¢×× ×Öž××Öž×××¢).
Intel BG ××¢×× ×Öž××Öž×××¢ ××× ×Š×××× ×֞׀֌עך××××× × ××Öž×עס (××× ×××× ×¢×š ××× × ××©× ×ַך××Ö·× ×××©× ××× ××× ×× ×× ×עךע, ×"× ×××××¢ ××Öž×עס ×§×¢× ×¢× ×××× ×¢× ××××Ö·×× ××××£ ×× ×¡×ס××¢×, ×Öž×עך ×××××¢ ×§×¢× ×¢× ×××× ×€×ַךקך××€ÖŒ××).
××¢××ס×× ×©×××××
××× ××¢××ס×× ×©××××× (MB) ××Öž××¢, ××¢×עך ש××××× ×§×Öž××€ÖŒ×Öž× ×¢× × (ס××ַך××× × ××× ×× ×§×€ÖŒ× ×©××××× ×š×Ö·×) "×××××¢×" ×× ××××Ö·×עך ××× ×× ×§×××€ÖŒ×Ö·××××Ö·××× ×€×× ×× TPM (×ך×ַס××¢× ×€ÖŒ××Ö·××€×Öž×š× ××Öž××××¢). ×€Ö¿×ַך ×× ×××ס ××¢× ×¢× × ××©× ××× ×עך ×××ס×, ××Öž×× ××ך ×עךק×עך×.
××€ÖŒ× ××× ×€ÖŒ×§×š×¡ (×€ÖŒ××Ö·××€×Öž×š× ×§×Öž× ×€×××ך×Ö·×××Öž× ×š×¢××ש×ס×עךס), ××× ×××֞ס ×עך ךע×××××Ö·× ×€×× ×× ××ַש×× × ×֞׀֌עך×ַ׊××¢ ××× ×עשך××× ×××× ×× ×€×֞ך××××¢:
××¢× ×¢. ×× ×§×š×Ö·× × ×€ÖŒ×§×š ×××¢×š× ××¢×€ÖŒ×¢× ×ס ××××£ ×× ×€×š×עך××קע, ××× ×× ×š×¢××ש×ס××¢×š× ××¢× ×¢× ××ַש××¢××ק ××××× ×××¢× ×× ×¡×ס××¢× ××× ××ַש××¢××ק.
××××, ××× MB ××Öž××¢, ××× ×¢×××¢××¢ ×€×× × ××× ×Š×××, PCRs ×€×ַך×ך×Ö·××× ××× ×Ö· ××× ×Š×ק (××× ×× ×§×××€ÖŒ×Ö·××××Ö·××× ×€×× ×× ××ַש×× × ×֞׀֌עך×ַ׊××¢) ×××¢× ×××€×עך ×€×× ×× ×§×Öž× ×Öž×עך ××Ö·×× ×××֞ס ××× ××¢×××¢× "××¢××ס××." PCR ×××Ö·××עס ×§×¢× ×¢× ×××× ××¢××××× × ××× ×¢×××¢××¢ ××Ö·×× ×¢× ×§×š×׀֌ש×Ö·× (TPM_Seal) ×֞׀֌עך×ַ׊××¢. × ×Öž× ××¢×, ×××עך ×עקך××€ÖŒ×××Öž× (TPM_Unseal) ×××¢× ×××× ××¢×××¢× ××××× ×××× ×× ×€ÖŒ×§×š ×××Ö·××עס ××Öž×× × ××©× ××××©× ××× ×Ö· ךע×××××Ö·× ×€×× ××Öž×××× × (×"×, ק××× ×××× "××¢××ס××" ק×Öž××€ÖŒ×Öž× ×¢× × ××× ××¢×××¢× ××Ö·××Ö·×€×××).
××עך×Ö·×€××× ×©×××××
×× ×¢×š××¡× ××Ö·× ×€Ö¿×ַך ×× ×××ס ××× ×Š× ××Öž×××€×׊××š× ×× UEFI ××××Öž×ס ××× ×× ××עך××€××¢× ×©××××× (VB) ××Öž××¢, ××× ×××֞ס ××¢×עך ש××××× ×§×Öž××€ÖŒ×Öž× ×¢× × ×§×š××€ÖŒ××Öž×ך×Ö·×€×ק×Ö·××× ××עך×Ö·×€××× ×× ×Öž×š× ×××¢×ק××Ö·× ××× ×Öž××Ö·× ××ס××× ×€×× ×עך ××××Ö·×עך ×××× ×¢×š. ××× ××× ×€×Ö·× ×€×× ×Ö· ××עך×Ö·×€×ַק××ש×Ö·× ××¢×ת, (×××× ×¢×š ×€××) ××Ö·×€ÖŒ×Ö·× ×:
- ש×Ö·×××Ö·×× ×××š× ×××××Ö·×× ×€×× 1 ××× ×× ×Š× 30 ××× ×× (×Ö·××× ×Ö·× ×עך ××Ö·× ×׊עך ××× ×Š××Ö·× ×Š× ×€Ö¿×ַךש×××× ×××֞ס ×××× ×§×Öž××€ÖŒ×××עך ××× × ××©× ×©×××××, ×××, ×××× ××¢×××¢×, ׀ך×××× ×Š× ×××§×¢×š× ×× ××××Öž×ס);
- ××Ö·×××ק ש×Ö·×××Ö·×× (×Ö·××× ×Ö·× ×עך ××Ö·× ×׊עך ××× × ××©× ××Öž×× ×Š××Ö·× ×Š× ×€Ö¿×ַךש××××, ×€×× ××××× ×קעך ××Öž× ×¢×€ÖŒ×¢×¡);
- ×€×֞ך××¢×Š× ×Š× ×ַך××¢×× ××× ×Ö· ך××ק ×××ס×ך×ק (×Ö·× ×€×Ö·× ×××¢× ×¢×¡ ××× ×§××× ×Š××× ×€Ö¿×ַך ×××עךק××Ö·×, ××××Ö·× ×¢×¡ ××¢× ×¢× ×עך ××××××ק ×××× ×Š× ××Öž×).
×× ×ך××š× ×€×× ×§×Ö·××£ ××¢×€ÖŒ×¢× ×ס ××××£ ×× ×¡×€ÖŒ×¢×¡××€××¢× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× (× ××××× ××××£ ×× ×Ö·××× ×עך××€×¢× ×¢ ×¢× ×€×֞ךס××Ö·× × ×€ÖŒ×Öž××××ק), ×××֞ס ××× ×€ÖŒ×¢×š××Ö·× ×Ö·× ××× ×š×¢×§×֞ך××¢× ×××š× ×× ×§×Öž××€ÖŒ×××עך ×€ÖŒ××Ö·××€×֞ך××¢ ×€×ַךק××׀עך ××× ×Ö· ס׀֌עש×× ×××××× × ×¡××֞ך×××ש - ×ש××€ÖŒ×¡×¢× ×€×סעס (×€×€×£). ××ך ×××¢×× ××××× ×¢× ××××£ ××¢× ×€×× × ××× ×עך ××¢××Ö·× ×©×€ÖŒ×¢×עך.
××× ×Ö·××ש×Ö·× ×Š× ×× ×§×Ö·× ×€×××עך××ש×Ö·×, ×עך ×€×ַךק××׀עך ×××©×¢× ×¢×š×××¥ ׊×××× RSA 2048 ש××ס××¢× ××× ×§×š××××¥ ׊×××× ××Ö·×× ×¡×ך×ַק××©×¢×š× (××¢××××× ××× ×× ×€×××ך):
- ×× ×××Öž×š×Š× ×©×××¡× ××Ö·× ×ַ׀עס×××ש×Ö·× ×€×× ×× ×€×ַךק××׀עך (KEYM, OEM Root Key Manifest), ×××֞ס ×ÖŒ××× ×× SVN (סעק×ך××× ××עךס××¢ × ××עך) ×€×× ××¢× ××Ö·× ×׀עס××Öž, ×× SHA256 ××ַש ×€×× ×× ×¢×€× ×××¢× ×©×××¡× ×€×× ×עך ××××Ö·×עך ××Ö·× ×׀עס××Öž, ×× RSA ×¢×€× ×××¢× ×©×××¡× (×"× ×עך ׊×××ך ×××× ×€×× ×× ××Ö·× ×׀עס××Öž×). ×€×ַךק××׀עך ס ×××Öž×š×Š× ×©××ס×) ×Š× ××ַש××¢×××§× ×× ×ס×××¢ ×€×× ââ××¢× ××Ö·× ×׀עס××Öž ××× ×× ×ס×××¢ ×××;
- IBB Manifest (IBBM, Initial Boot Block Manifest), ×××֞ס ×ÖŒ××× ×× SVN ×€×× ××¢× ××Ö·× ×׀עס×, ×× SHA256 ××ַש ×€×× IBB, ×עך ׊×××ך ש×××¡× ×€Ö¿×ַך ××עך×Ö·×€×××× × ×× ×ס×××¢ ×€×× ââ××¢× ××Ö·× ××€×¢×¡× ××× ×× ×ס×××¢ ×××.
×× SHA256 ××ַש ×€×× ×× ×Öž×¢× ×××Öž×š×Š× ×§×× ×¢×€× ×××¢× ×©×××¡× ××× ×€ÖŒ×¢×š××Ö·× ×Ö·× ××× ×š×¢×§×֞ך××¢× ××× ×ש××€ÖŒ×¡×¢× ×€×סעס (FPFs), ×€ÖŒ×× ×§× ××× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·×. ×××× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ××× ×× ×× ×§×××ש×Ö·× ×€×× ××¢× ××¢×× ×Öž××Öž×××¢, ×€Ö¿×× ×××Š× ××××£ ××××× ×× ××Ö·××׊עך ×€×× ×× ×€ÖŒ×š××××Ö·× ×××× ×€×× ×× ×Öž×¢× ×××Öž×š×Š× ×©×××¡× ×§×¢× ×¢× ×עך×××Ö·× ×××§× ×× ××××Öž×ס ××××£ ××¢× ×¡×ס××¢× (×"× ×§×¢× ×¢× ×š×ק×Ö·×ק××Ö·×××× ×× ××Ö·× ×׀עסץ), ×"×. ×€×ַךק××׀עך.
×××¢× ××ך ק×ק ××× ×× ××××, ××× ×××׀ש×××× ×¡×€×§×ת ×××¢×× ×× × ××× ×€Ö¿×ַך ×Ö·××Ö· ×Ö· ××Ö·× × ××עך×Ö·×€×ַק××ש×Ö·× ×§××× - ××× ×§×¢× ××Öž×× ××¢× ××Š× ×××× ××ַש××Ö·×׀֌עך××¢×. ×€×ך×××ס ק×Öž××€ÖŒ××׊××š× ××××?
××× ×€×ַק×, ×× ××¢× ××× ×× ×€×ַךק××׀עך ×× ××¢××¢×× ×××× ×Š× × ××Š× ×€×ַךש×××¢× ×¢ IBB ש××ס××¢× ×€Ö¿×ַך ×€×ַךש×××¢× ×¢ ש×ך×ת ×€×× ×××Ö·× ×€ÖŒ×š×Öž××ק×× ××× ×××× ×¢×š ××× ×עך ×××Öž×š×Š× ×©××ס×. ×××× ×× ×€ÖŒ×š××××Ö·× ×××× ×€×× ×× IBB ש×××¡× (××× ×××֞ס ×× ×š××¢ ××Ö·× ×ַ׀עס×××ש×Ö·× ××× ××¢×ת××¢×) ××קס, ×עך ××× ×Š×××¢× × ×××¢× ××××š×§× ××××× ×××× ×€ÖŒ×š×Öž×××§× ×©××š× ××× ××××× ××× ×עך ×€×ַךק××׀עך ×××©×¢× ×¢×š×××¥ ×Ö· × ××Ö·×¢ ×€ÖŒ×֞ך ××× ×× ×§×××× ×× ×š×ק×Ö·×ק××Ö·×××××× ××Ö·× ×ַ׀עס×××ש×Ö·× × ××× ×עך ××××Ö·×עך ××××Öž×ס ×עך×××Ö·× ××ק×.
×Öž×עך ×××× ×עך ×××Öž×š×Š× ×©×××¡× (××× ×××֞ס ×עך עךש×עך ××ַש××Ö·×׀֌עך××¢× ××× ××¢×ת××¢×) ××× ×§×Ö·×׀֌ך×Ö·×××××, עס ××× × ×× ××¢×××¢× ×Š× ×€×ַך×××Ö·×× ×¢×¡; עס ××× ×§××× ×š×¢×××֞ק×Ö·×××Öž× ×€ÖŒ×š×֞׊ע××ך. ×× ××ַש ×€×× ××¢× ×Š×××ך ×××× ×€×× ××¢× ×©×××¡× ××× ×€ÖŒ×š×Öž××ך×Ö·×× ××× FPF ×Ö·××Öž× ××× ×€Ö¿×ַך ×Ö·××¢.
×× ××¢× ××Öž×Öž× ××Ö·×š× ×§×Ö·× ×€×××עך××ש×Ö·×
×××Š× ××Öž×× ××× ×× × ×¢××¢× ×Ö· × ×¢×¢× ×עך ק×ק ××× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ××× ×עך ׀֌ך×֞׊עס ×€×× ×§×š×××××× × ×¢×¡. ×××× ××ך ק×ק ××× ×× ×§×֞ך×ַס׀֌×Ö·× ××× × ×§××××× ××× ×× GUI ×€×× ×× ×€××ַש ×××× ××× × ××Š× ×€×× ×× Intel System Tool Kit (STK), ××ך ×××¢× ××Ö·××¢×š×§× ×Ö·× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ×××× ×Ö· ××ַש ×€×× ×× ×Š×××ך ×××× ×€×× ×× ×××Öž×š×Š× ×©×××¡× ×€×× ×× ×€×ַךק××׀עך, ×Ö· ×€ÖŒ×֞ך ×€×× ×××ק××ךע ××עך×× ×××'. Intel BG ׀֌ך×Öž×€××.
×× ×¡×ך×ק××ך ×€×× ××¢× ×€ÖŒ×š×Öž×€××:
typedef struct BG_PROFILE
{
unsigned long Force_Boot_Guard_ACM : 1;
unsigned long Verified_Boot : 1;
unsigned long Measured_Boot : 1;
unsigned long Protect_BIOS_Environment : 1;
unsigned long Enforcement_Policy : 2; // 00b â do nothing
// 01b â shutdown with timeout
// 11b â immediate shutdown
unsigned long : 26;
};
××× ×Ö·×××¢××××, ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ××× ×Ö· ×××עך ×€×עקס×Ö·××Ö·× ×¢× ××××. ××Ö·×ך×Ö·×××, ×€Ö¿×ַך ×××ַש׀֌××, ×× Force_Boot_Guard_ACM ×€×Öž×. ×××¢× ×¢×¡ ××× ×Ö·××עק××¢× ×××¢×, ×××× ×× BG ס××ַך××Ö·×€ÖŒ ×Ö·×§× ××Öž××××¢ ××××£ ×× SPI ××××¥ ××× × ××©× ××¢×€Ö¿×× ×¢×, ק××× ×ך×ַס××× ×©××××× ×××¢× ×€ÖŒ×ַס×ך×. ×× ×××¢× ×××× ×Ö·× ×ך×ַס×.
××ך ש××× ×עשך××× ××××× ×Ö·× ×× ×¢× ×€×֞ךס××Ö·× × ×€ÖŒ×Öž××××ק ×€Ö¿×ַך VB ××Öž××¢ ×§×¢× ×¢× ×××× ×§×Ö·× ×€××××¢×š× ×Ö·××× ×Ö·× ×××× ×¢×¡ ××× ×Ö· ××עך×Ö·×€×ַק××ש×Ö·× ××¢×ת, ×Ö·× ×Ö·× ×ך×ַס××× ×ך×׀ק××€××¢ ×××¢× ×€ÖŒ×ַס×ך×.
××Öž×× ×Ö·××Ö· ×××× ××× ×× ××סקךעש×Ö·× ×€×× ×× ×××¢× ××֞ךס ...
×× GUI × ××Š× ××× ×× ×€××××¢× ××¢ "×€×ַך××ק" ׀֌ך×Öž××€××××:
× ××
××Öž××¢
××ַשך××Ö·××× ×
0
No_FVME
Intel BG ××¢×× ×Öž××Öž×××¢ ×€×ַךקך××€ÖŒ××
1
VE
××× ××Öž××¢ ××× ×¢× ××××Ö·××, ש×Ö·×××Ö·×× ×××š× ×××××Ö·××
2
VME
×××××¢ ××Öž×עס ××¢× ×¢× ×¢× ××××Ö·×× (VB ××× MB), ש×Ö·×××Ö·×× ×××š× ×××××Ö·××
3
VM
×××××¢ ××Öž×עס ××¢× ×¢× ×¢× ××××Ö·××, ×Öž× ×××ס××¢×ך××× ×Ö·××עק ×× ×¡×ס××¢×
4
FVE
××× ××Öž××¢ ×¢× ××××Ö·××, ××Ö·×××ק ש×Ö·×××Ö·××
5
FVME
×××××¢ ××Öž×עס ×¢× ××××Ö·××, ××Ö·×××ק ש×Ö·×××Ö·××
××× ×©××× ×עך××× ×, ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ×××× ×××× ×עשך××× ×Ö·××Öž× ××× ×€Ö¿×ַך ×Ö·××¢ ×××š× ×× ×¡×ס××¢× ×€×ַךק××׀עך ××× ×ש××€ÖŒ×¡×¢× ×€×סעס (FPFs) - ×Ö· ק×××× (×××× ×Š× ×Ö·× ××עך×Ö·×€××× ××× ×€Ö¿×֞ך××ַ׊××¢, ××××× 256 ×××עס) ××Ö·×× ×××Ö·×š× ×¡××֞ך×××ש ×€×× ××× ×€Ö¿×֞ך××ַ׊××¢ ××× ×× ×ש×׀֌סע×, ×××֞ס ×§×¢× ×¢× ×××× ×€ÖŒ×š×Öž××ך×Ö·××. ×ַך××ס ×× ××¢× ×¡ ׀֌ך×Öž××ק׊××¢ ×€×ַס×××Ö·××× (×Ö·× ×¡ ×××֞ס ×€ÖŒ×× ×§× ×€×¢×× ×€ÖŒ×š×Öž×ך×Ö·×××Ö·×××¢ ×€×סעס).
עס ××× ×ך××ס ×€Ö¿×ַך ס××֞ך×× × ×§×Ö·× ×€×××עך××ש×Ö·× ××××Ö·×:
- ××× ×Ö· ××××-׊××Ö·× ×€ÖŒ×š×Öž×ך×Ö·×××Ö·×××¢ ××¢×× × ×€Ö¿×ַך ס××֞ך×× × ××Ö·×× (×€ÖŒ×× ×§× ××× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ××× ×עשך×××);
- ××××× Intel ME ×§×¢× ×¢× ××××¢× ×¢× ××× ×€ÖŒ×š×Öž×ך×Ö·× ×¢×¡.
×Ö·×××, ××× ×¡×ך ×Š× ×©××¢×× ×× ×§×Ö·× ×€×××עך××ש×Ö·× ×€Ö¿×ַך Intel BG ××¢×× ×Öž××Öž×××¢ ××××£ ×Ö· ס׀֌ע׊××€×ש ס×ס××¢×, ×עך ×€×ַךק××׀עך ××× ×× ×€××××¢× ××¢ ×עש×ַס ׀֌ך×Öž××ק׊××¢:
- × ××Š× ×× Flash Image Tool × ××Š× (×€×× Intel STK), עס קך××××¥ ×Ö· ×€×ך××××ַךע ×××× ××× ×Ö· ××¢××¢×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ××× ×× ×€×Öž×š×¢× ×€×× ××עך××Ö·××Ö·×× ××× ×× Intel ME ××¢×× × (×× ×Ö·××× ×עך××€×¢× ×¢ ׊××Ö·×××××Ö·××ק ש׀֌××× ×€Ö¿×ַך FPFs);
- × ××Š× ×× ×€××ַש ׀֌ך×Öž×ך×Ö·×××× × ××× × ××Š× (×€Ö¿×× Intel STK), עס שך×××× ××¢× ×××× ×Š× ×× SPI ××××¥ ××֌ך×× ×€×× ×× ×¡×ס××¢× ××× ×§××Öž×××× ×× ×Ö·××× ×עך××€×¢× ×¢. ××Ö·× ××€×ַק××ך×× × ××Öž××¢ (××× ××¢× ×€×Ö·×, ×× ×§×֞ך×ַס׀֌×Ö·× ××× × ××Ö·×€Ö¿×¢× ××× ×עש××§× ×Š× Intel ME).
××× ×Ö· ךע×××××Ö·× ×€×× ×× ×ַ׀֌עך××ש×Ö·× ×, Intel ME ×××¢× ××עך××¢×× ×× ×¡×€ÖŒ×¢×¡××€××¢× ×××Ö·××עס ×€×× ×עך ש׀֌××× ×€Ö¿×ַך FPFs ××× ×× ME ××¢×× × ×Š× FPFs, ש××¢×× ×× ×š×¢××Ö·××ש×Ö·× × ××× SPI ××××¥ ××סקך××€ÖŒ××֞ךס ×Š× ×× ×××Ö·××עס ךעק×Ö·××¢× ××× ×××š× Intel (××סקך×××× ××× ×× ×Öž× ×××× ×€×× ×× ×ַך××ק×) ××× ××ך××€××š× ×Ö· ס×ס××¢× ××ַש××¢××ק.
×Ö·× ×Ö·××ס×ס ×€×× ×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×€×× Intel Boot Guard
××× ×¡×ך ×Š× ×Ö·× ×Ö·×××× ×× ×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×€×× ××¢× ××¢×× ×Öž××Öž×××¢ ××× ×Ö· ס׀֌ע׊××€×ש ×××ַש׀֌××, ××ך ×Öž×€ÖŒ×עש××¢×× ×× ×€××××¢× ××¢ ס×ס××¢××¢× ×€Ö¿×ַך ×ך×ַסעס ×€×× Intel BG ××¢×× ×Öž××Öž×××¢:
ס×ס××¢×
××Öž×
×××××××× GA-H170-D3H
Skylake, עס ××× ×©××׊×
×××××××× GA-Q170-D3H
Skylake, עס ××× ×©××׊×
×××××××× GA-B150-HD3
Skylake, עס ××× ×©××׊×
MSI H170A Gaming Pro
Skylake, ק××× ×©××׊×
Lenovo ××× ×ק׀֌×Ö·× 460
Skylake, ×עש××׊×, ××¢×× ×Öž××Öž×××¢ ×¢× ××××Ö·××
Lenovo ××Öž××Ö· 2 Pro
××ַס×××¢×, ק××× ×©××׊×
Lenovo U330p
××ַס×××¢×, ק××× ×©××׊×
××× "ש××׊×" ××ך ×××× ×¢× ×× ×××Ö·×××Ö·× ×€×× ×× Intel BG ס××ַך××Ö·×€ÖŒ ×Ö·×§× ××Öž××××¢, ×× ××Ö·× ×ַ׀עסץ ×עך××× × ××××× ××× ×× ×§×֞ך×ַס׀֌×Ö·× ××× × ×§×Öž× ××× ×× ××××Öž×ס, ×.×¢. ×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×€Ö¿×ַך ×Ö·× ×Ö·××ס×ס.
××× ×Ö· ×××ַש׀֌××, ××Öž×× ××× ×× × ×¢××¢× ×× ××Ö·×× ××Öž×××× ×€×× ×× ×Öž×€×ס. ×€×ַךק××׀עך ×××¢×××××× ×××× ×€×× SPI ××××¥ ××֌ך×× ×€Ö¿×ַך Gigabyte GA-H170-D3H (××עךס××¢ F4).
×× ××¢× ×§×€ÖŒ× ×©××××× ×š×Ö·×
עךש×עך ×€×× ×Ö·××¢, ××Öž×× ×¡ ךע×× ×××¢×× ×× ×ַקש×Ö·× × ×€×× ×× ×€ÖŒ×š×ַסעסעך ×××× Intel BG ××¢×× ×Öž××Öž×××¢ ××× ×¢× ××××Ö·××.
עס ××× × ×× ××¢×××¢× ×Š× ××¢×€Ö¿×× ×¢× ×¡×Ö·××€ÖŒ×Ö·×× ×€×× ×עקך××€ÖŒ××× ××קך×֞ק×Öž××¢, ×Ö·××× ××× ×× ×ַקש×Ö·× × ××סקך×××× ××× ×× ××¢× ×¢× ×××€ÖŒ××Ö·××¢× ×Ö·× (××× ××קך×֞ק×Öž××¢ ×Öž×עך ××Ö·×× ×××ַך×) ××× ×Ö·× ×Öž×€Ö¿× ×§×©××. ×Öž×עך, עס ××× ×Ö· ×€×Ö·×§× ×Ö·× ××Öž××¢×š× ×× ××¢× ×€ÖŒ×š×Ö·×¡×¢×¡×¢×š× "×§×¢× ×¢×" ××ך××€××š× ×× ×ַקש×Ö·× ×.
× ×Öž× ×ַך××ס××Ö·× × ×× RESET ש××Ö·×, ×עך ׀֌ך×ַסעסעך (×× ××× ××Ö·×× ×€×× ×× ××××¥ ××֌ך×× ××× ×©××× ××Ö·×€ÖŒ× ××× ×× ×Ö·×ךעס ×€ÖŒ××Ö·×¥) ××¢×€×× × ×× FIT (Firmware Interface Table) ××ש. עס ××× ×ך×× × ×Š× ××¢×€Ö¿×× ×¢×; ×עך ×××Ö·×× ×Š× ×¢×¡ ××× ×עשך××× ××× ×Ö·×ךעס FFFF FFC0h.
××× ××¢× ×××ַש׀֌×× ××× ×עך ××Ö·×ך×Ö·×××× ×, ×× ×××¢×š× FFD6 9500h ××× ×××× ××× ××¢× ×Ö·×ךעס. ×××š× ×ַקסעס ××¢× ×Ö·×ךעס, ×עך ׀֌ך×ַסעסעך ××¢× ×× FIT ××ש, ×× ××× ××Ö·×× ×€×× ×××֞ס ××× ×Š×¢××××× ××× ×š×¢×§×֞ך×ס. ×עך עךש×עך ×€ÖŒ×Öž××׊××¢ ××× ×× ××¢×עך ×€×× ×× ×€××××¢× ××¢ ס×ך×ק××ך:
typedef struct FIT_HEADER
{
char Tag[8]; // â_FIT_ â
unsigned long NumEntries; // including FIT header entry
unsigned short Version; // 1.0
unsigned char EntryType; // 0
unsigned char Checksum;
};
×€Ö¿×ַך ×¢×××¢××¢ ×××××ַק×Ö·× × ×¡×××, ×× ×שעקקס×× ××× × ×× ×©××¢× ××ק ק×Ö·×ק××Ö·×××××× ××× ×× ×××©× (×× ×€×¢×× ××× ××× ×§×¡ × ××).
×× ×××עך×קע ×××× ×¡× ×××××× ××××£ ×€×ךש×××¢× ×¢ ×××× ×¢×š×עס ×××ס ×××š×€× ×××× ×€×ךש××¢××/×××ס××¢×€××š× ××××עך ×× ××××Öž×ס ××× ×¢×§×¡×ַק××××Ö·×, ×.×. ××××עך ××ך ××ַש××××¢× ×Š× ×× ××¢××Ö·× ×š×¢×¡×¢× ××עק××֞ך (FFFF FFF0h). ×× ×¡×ך×ק××ך ×€×× ××¢×עך ×Ö·××Ö· ×€ÖŒ×Öž××׊××¢ ××× ××× ××××:
typedef struct FIT_ENTRY
{
unsigned long BaseAddress;
unsigned long : 32;
unsigned long Size;
unsigned short Version; // 1.0
unsigned char EntryType;
unsigned char Checksum;
};
×× EntryType ×€×¢×× ×עך׊×××× ××ך ××¢× ×××€ÖŒ ×€×× ×××֞ק ××¢× ×€ÖŒ×Öž××׊××¢ ×××××× ×Š×. ××ך ××××¡× ×¢×××¢××¢ ×××׀֌ס:
enum FIT_ENTRY_TYPES
{
FIT_HEADER = 0,
MICROCODE_UPDATE,
BG_ACM,
BIOS_INIT = 7,
TPM_POLICY,
BIOS_POLICY,
TXT_POLICY,
BG_KEYM,
BG_IBBM
};
×××Š× ×¢×¡ ××× ×§××֞ך ××× ×עך ××Öž× ×Ö·× ×××× ×¢×š ×€×× ×× ×××× ×¡× ×××××× ×Š× ×× ×Öž×š× ×€×× ×× Intel BG ס××ַך××Ö·×€ÖŒ ×Ö·×§× ×××× ×¢×š×. ×× ××¢×עך ס×ך×ק××ך ×€×× ××¢× ×××× ×¢×š× ××× ×××€ÖŒ×ש ×€Ö¿×ַך ק×Öž× ××Ö·××ש××× ××¢×××¢××Öž×€ÖŒ×¢× ×××š× Intel (ACMS, ××קך×֞ק×Öž××¢ ×עך×××Ö·× ××ק×× ××¢×, Intel ME ק×Öž× ×¡×¢×§×©×Ö·× ×, ...).
typedef struct BG_ACM_HEADER
{
unsigned short ModuleType; // 2
unsigned short ModuleSubType; // 3
unsigned long HeaderLength; // in dwords
unsigned long : 32;
unsigned long : 32;
unsigned long ModuleVendor; // 8086h
unsigned long Date; // in BCD format
unsigned long TotalSize; // in dwords
unsigned long unknown1[6];
unsigned long EntryPoint;
unsigned long unknown2[16];
unsigned long RsaKeySize; // in dwords
unsigned long ScratchSize; // in dwords
unsigned char RsaPubMod[256];
unsigned long RsaPubExp;
unsigned char RsaSig[256];
};
×עך ׀֌ך×ַסעסעך ××Öž××× ××¢× ×××× ×¢×š× ××× ×××× ×§×ַש, ××עך×Ö·×€××× ×¢×¡ ××× ××××€× ×¢×¡.
Intel BG ס××ַך××Ö·×€ÖŒ ×ַק×
××× ×Ö· ךע×××××Ö·× ×€×× ×Ö·× ×Ö·×××××× × ×× ×ַך××¢× ×€×× ××¢× ACM, עס ××× ××¢××××š× ×§××֞ך ×Ö·× ×¢×¡ ××× ×× ×€××××¢× ××¢:
- ××ק××× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ×€×× Intel ME, ×עשך××× ××× ×ש××€ÖŒ×¡×¢× ×€×סעס (FPFs);
- ××¢×€×× × KEYM ××× IBBM ××Ö·× ×׀עסץ ××× ××עך×Ö·×€××× ×××.
×Š× ××¢×€Ö¿×× ×¢× ×× ××Ö·× ×׀עסץ, ACM ×××× × ××Š× ×× FIT ××ש, ×××֞ס ××× ×Š×××× ×€ÖŒ×Öž××׊××¢ ×××׀֌ס ×Š× ×Öž× ××××Ö·×× ×¡×ך×ק××ך ××Ö·×× (××¢× FIT_ENTRY_TYPES ×××××).
××Öž××ך × ×¢××¢× ×Ö· × ×¢×¢× ×עך ק×ק ××× ××Ö·× ×׀עס××֞ס. ××× ×עך ס×ך×ק××ך ×€×× ×עך עךש×עך ××ַש××Ö·×׀֌עך××¢×, ××ך ××¢× ×¢×××¢××¢ ××ק ק×Ö·× ×¡××Ö·× ×¥, ×Ö· ××ַש ×€×× ×× ×Š×××ך ש×××¡× ×€×× ×× ×š××¢ ××ַש××Ö·×׀֌עך××¢×, ××× ×עך ׊×××ך ×Öž×¢× ×××Öž×š×Š× ×§×× ××¢×ת××¢× ××× ×Ö· × ×¢×¡××¢× ×¡×ך×ק××ך:
typedef struct KEY_MANIFEST
{
char Tag[8]; // â__KEYM__â
unsigned char : 8; // 10h
unsigned char : 8; // 10h
unsigned char : 8; // 0
unsigned char : 8; // 1
unsigned short : 16; // 0Bh
unsigned short : 16; // 20h == hash size?
unsigned char IbbmKeyHash[32]; // SHA256 of an IBBM public key
BG_RSA_ENTRY OemRootKey;
};
typedef struct BG_RSA_ENTRY
{
unsigned char : 8; // 10h
unsigned short : 16; // 1
unsigned char : 8; // 10h
unsigned short RsaPubKeySize; // 800h
unsigned long RsaPubExp;
unsigned char RsaPubKey[256];
unsigned short : 16; // 14
unsigned char : 8; // 10h
unsigned short RsaSigSize; // 800h
unsigned short : 16; // 0Bh
unsigned char RsaSig[256];
};
×Š× ××ַש××¢×××§× ×× ×Öž×¢× ×××Öž×š×Š× ×§×× ×¢×€× ×××¢× ×©××ס×, ××ך ׊×ך×קך××€× ×Ö·× ××ך × ××Š× ×× SHA256 ××ַש ×€×× ×€×סעס, ×××֞ס ××× ××¢× ×€×× × ××× ×©××× ××ק×××¢× ×€×× Intel ME.
××Öž××ך ××²× ×°×²Ö·×עך ׊×× ×Š×°×²×× ××Ö·× ×׀עס××Öž. עס ××ש×××× ×€×× ×ך××Ö· ס×ך×ַק×שעך×:
typedef struct IBB_MANIFEST
{
ACBP Acbp; // Boot policies
IBBS Ibbs; // IBB description
IBB_DESCRIPTORS[];
PMSG Pmsg; // IBBM signature
};
×עך עךש×עך ×ÖŒ××× ×¢×××¢××¢ ק×Ö·× ×¡××Ö·× ×¥:
typedef struct ACBP
{
char Tag[8]; // â__ACBP__â
unsigned char : 8; // 10h
unsigned char : 8; // 1
unsigned char : 8; // 10h
unsigned char : 8; // 0
unsigned short : 16; // x & F0h = 0
unsigned short : 16; // 0 < x <= 400h
};
×× ×š××¢ ×ÖŒ××× ×× SHA256 ××ַש ×€×× ×× IBB ××× ×× × ××עך ×€×× ××סקך××€ÖŒ××֞ךס ×××֞ס ××ַשך××Ö·×× ×× ××× ××Ö·×× ×€×× ×× IBB (×"×, ×××֞ס ×× ××ַש ××× ×§×Ö·×ק××Ö·×××××× ×€××):
typedef struct IBBS
{
char Tag[8]; // â__IBBS__â
unsigned char : 8; // 10h
unsigned char : 8; // 0
unsigned char : 8; // 0
unsigned char : 8; // x <= 0Fh
unsigned long : 32; // x & FFFFFFF8h = 0
unsigned long Unknown[20];
unsigned short : 16; // 0Bh
unsigned short : 16; // 20h == hash size ?
unsigned char IbbHash[32]; // SHA256 of an IBB
unsigned char NumIbbDescriptors;
};
×× IBB ××סקך××€ÖŒ××֞ךס × ×Öž××××× ××¢× ×¡×ך×ק××ך, ×××× ×¢×š × ×Öž× ×× ×× ×עךע. ×××עך ××× ××Ö·×× ××× ×× ×€××××¢× ××¢ ×€Ö¿×֞ך××Ö·×:
typedef struct IBB_DESCRIPTOR
{
unsigned long : 32;
unsigned long BaseAddress;
unsigned long Size;
};
עס ××× ×€ÖŒ×©××: ××¢×עך ××סקך××€ÖŒ××֞ך ×ÖŒ××× ×× ×Ö·×ךעס / ×ך××ס ×€×× ×× IBB ×€ÖŒ××Ö·××¢. ××××, ×× ×§×Ö·× ×§×Ö·××Ö·× ××ש×Ö·× ×€×× ×× ×××ַקס ש׀֌×׊×ק ×Š× ×××š× ×× ××סקך××€ÖŒ××֞ךס (××× ×עך ס×ך ×€×× ×× ××סקך××€ÖŒ××֞ךס ×××) ××× ×××. ×××, ××× ×Ö· ×עךש×, IBB ××× ×× ××Ö·×××× × ×€×× ×Ö·××¢ ××Ö·××ש××× ×€×× ×× SEC ××× PEI ×€×ַסעס.
×× ×Š××××××¢ ××Ö·× ×ַ׀עס×××ש×Ö·× ××× ××¢×¢× ×××§× ×××š× ×Ö· ס×ך×ק××ך ××× ×× IBB ×¢×€× ×××¢× ×©×××¡× (××עך×Ö·×€××× ×××š× ×× SHA256 ××ַש ×€Ö¿×× ×עך עךש×עך ××ַש××Ö·×׀֌עך××¢×) ××× ×× ×ס×××¢ ×€×× ââ××¢× ××ַש××Ö·×׀֌עך××¢×:
typedef struct PMSG
{
char Tag[8]; // â__PMSG__â
unsigned char : 8; // 10h
BG_RSA_ENTRY IbbKey;
};
×Ö·×××, ××€××× ××××עך ×× UEFI ××××Öž×ס ס××ַךץ עקס×ַק××××× ×, ×עך ׀֌ך×ַסעסעך ×××¢× ×§×Ö·×עך ACM, ×××֞ס ×××¢× ××ַש××¢×××§× ×× ×Öž××Ö·× ××ס××× ×€×× ×× ××× ××Ö·×× ×€×× ×× ×¡×¢×§×©×Ö·× × ××× ×× SEC ××× PEI ×€×ַסע ק×Öž×. ××¢×š× ×Öž×, ×עך ׀֌ך×ַסעסעך ×קס××× ACM, ×××× ×× RESET ××עק××֞ך ××× ××××× ×Š× ××ך××€××š× ×× ××××Öž×ס.
×× ××עך×Ö·×€××× PEI ׊ע×××××× × ×××× ×Ö·× ×××Ö·××× ×Ö· ××Öž××××¢ ×××֞ס ×××¢× ×§×Öž× ×ך×Öž×××š× ×× ×š×¢×©× ×€×× ×× ××××Öž×ס (DXE ק×Öž×). ×עך ××Öž××××¢ ××× ×©××× ××¢×××¢××Öž×€ÖŒ×¢× ×××š× IBV (×× ××¢×€ÖŒ×¢× ××¢× × ××××Öž×ס ×€×ַךק××׀עך) ×Öž×עך ×× ×¡×ס××¢× ×€×ַךק××׀עך ×××. ××××Ö·× ××××× Lenovo ××× Gigabyte ס×ס××¢××¢× ××¢× ×¢× ××¢×××¢× ××× ××× ××עך ××Ö·×××Ö·××ק×× × ××× ××Öž×× ×× ××¢× ×× ×©××׊×; ××Öž××ך ק××§× ××× ×× ×§×Öž× ×קס×ך×ַק××× ×€×× ×× ×¡×ס××¢××¢×.
UEFI ××××Öž×ס ××Öž××××¢ LenovoVerifiedBootPei
××× ××¢× ×€×Ö·× ×€×× Lenovo, עס ××× ××¢×××¢× ×× LenovoVerifiedBootPei ××Öž××××¢ {B9F2AC77-54C7-4075-B42E-C36325A9468D}, ××¢×××¢××Öž×€ÖŒ×¢× ×××š× Lenovo.
×××× ×ַך××¢× ××× ×Š× ×§××§× ×ַך×××£ (×××š× GUID) ×× ××ַש ××ש ×€Ö¿×ַך ×× DXE ××× ××ַש××¢×××§× ×× DXE.
if (EFI_PEI_SERVICES->GetBootMode() != BOOT_ON_S3_RESUME)
{
if (!FindHashTable())
return EFI_NOT_FOUND;
if (!VerifyDxe())
return EFI_SECURITY_VIOLATION;
}
Ð¥ÐµÑ ÑаблОÑа {389CC6F2-1EA8-467B-AB8A-78E769AE2A15} ÐžÐŒÐµÐµÑ ÑлеЎÑÑÑОй ÑПÑЌаÑ:
typedef struct HASH_TABLE
{
char Tag[8]; // â$HASHTBLâ
unsigned long NumDxeDescriptors;
DXE_DESCRIPTORS[];
};
typedef struct DXE_DESCRIPTOR
{
unsigned char BlockHash[32]; // SHA256
unsigned long Offset;
unsigned long Size;
};
UEFI ××××Öž×ס ××Öž××××¢ BootGuardPei
××× ××¢× ×€×Ö·× ×€×× ××××××××, עס ××× ××¢×××¢× ×× BootGuardPei ××Öž××××¢ {B41956E1-7CA2-42DB-9562-168389F0F066}, ××¢×××¢××Öž×€ÖŒ×¢× ×××š× AMI, ×עך××עך, ×€×֞ךש××¢×× ××× ×§××× ×Ö·×× ××××Öž×ס ××× Intel BG ש××׊×.
×××× ×ַ׀֌עך××××× × ×Ö·××עך×××Ö·× ××× ×¢×€ÖŒ×¢×¡ ×Ö·× ×עךש, ×Öž×עך, עס ××××× ×ַך×Öž×€ÖŒ ×Š× ×× ××¢×××¢ ××Ö·×:
int bootMode = EFI_PEI_SERVICES->GetBootMode();
if (bootMode != BOOT_ON_S3_RESUME &&
bootMode != BOOT_ON_FLASH_UPDATE &&
bootMode != BOOT_IN_RECOVERY_MODE)
{
HOB* h = CreateHob();
if (!FindHashTable())
return EFI_NOT_FOUND;
WriteHob(&h, VerifyDxe());
return h;
}
×× ××ַש ××ש {389CC6F2-1EA8-467B-AB8A-78E769AE2A15} עס ××× ×§××§× ×€Ö¿×ַך ××× ×× ×€××××¢× ××¢ ×€Ö¿×֞ך××Ö·×:
typedef HASH_TABLE DXE_DESCRIPTORS[];
typedef struct DXE_DESCRIPTOR
{
unsigned char BlockHash[32]; // SHA256
unsigned long BaseAddress;
unsigned long Size;
};
Intel Boot Guard 2.x
××× ×¡ ×עק×׊עך ךע×× ×××¢×× ×× ×× ×עך ×××€ÖŒ××Ö·××¢× ×××ש×Ö·× ×€×× Intel Boot Guard, ×××֞ס ××× ××¢×€Ö¿×× ×¢× ××× ×Ö· × ××ַעך ס×ס××¢× ×××××š× ××××£ Intel SoC ××× Apollo Lake ××קך×Öž×ַך×ש××עק××ךע - ASRock J4205-IT.
××Öž×ש ×× ××עךס××¢ ×××¢× ×××× ××¢××××× × ××××× ××× ×¡×֞קס (× ××Ö· ס×ס××¢××¢× ××× ×§×Ö·×× ×××ק ׀֌ך×ַסעסעך ××קך×Öž×ַך×ש××עק××ךע ×€×֞ך××¢×Š× ×Š× × ××Š× Intel Boot Guard 1.x), עס ××× ×€×× ×ך××ס ××× ×עךעס ×Š× ××¢×š× ×¢× ×× × ××Ö·×¢ ×ַךק×Ö·×עק×שעך ×֞׀֌׊××¢ ×€Ö¿×ַך Intel SoC ×€ÖŒ××Ö·××€×֞ך×ס, ×××֞ס ××Öž×× ××¢××¢× ××Ö·×××Ö·××ק ×¢× ×עך×× ××¢×, ××ש×:
- ×× ××××Öž×ס ××× Intel ME ×ק×××ת (×Öž×עך ××Ö·× ×¥ Intel TXE, ×××× ×× ×עך××× ×Öž××Öž×××¢ ×€Ö¿×ַך Intel SoC) ××¢× ×¢× ×××Š× ×××× IFWI ××¢×× ×;
- ××Öž×ש Intel BG ××× ××¢×××¢× ×¢× ××××Ö·×× ××××£ ×עך ×€ÖŒ××Ö·××€×֞ך××¢, ס×ך×ַק××©×¢×š× ×Ö·××Ö· ××× FIT, KEYM, IBBM ××¢× ×¢× × ××©× ××¢×€Ö¿×× ×¢× ××× ××××¥ ××֌ך××;
- ××× ×Ö·××ש×Ö·× ×Š× ×× TXE ××× ISH ק×֞ךעס (קס86), ×Ö· ×ך×× ××ַךץ ××× ×Š×××¢××¢×× ×Š× ×× ×ש××€ÖŒ×¡×¢× (×ַךק ××××עך, ×××š× ××¢× ×××¢×) - PMC (Power Management Controller), ×€Ö¿×ַך××× ×× ××× ×× ×©×ך×× × ×× ×֞׀֌עך×Ö·×××××× ×€×× ×× ××Ö·×× ×¡×Ö·×ס×ס××Ö·× ××× ×€×֞ךש××¢××× × ××Öž× ×××֞ך×× ×.
×עך ××× ××Ö·×× ×€×× ×× × ××Ö·×¢ IFWI ××¢×× × ××× ×Ö· ס××× ×€×× ×× ×€××××¢× ××¢ ××Ö·××ש×××:
×€×֞ך×ך××××
× ×Öž××¢×
××ַשך××Ö·××× ×
0000 2000 ×
SMIP
×Ö· ×××עך ×€ÖŒ××Ö·××€×֞ך××¢ ק×Ö·× ×€×××עך××ש×Ö·×, ××¢×ת××¢× ×××š× ×× ×€×ַךק××׀עך
0000 6000 ×
RBEP
Intel TXE ×€×ך××××ַךע ק×Öž× ×Öž×€ÖŒ×××××× ×, x86, ××¢×ת××¢× Intel
0001 0000 ×
PMCP
Intel PMC ×€×ך××××ַךע ק×Öž× ×Öž×€ÖŒ×××××× ×, ARC, ××¢×ת××¢× Intel
0002 0000 ×
FTPR
Intel TXE ×€×ך××××ַךע ק×Öž× ×Öž×€ÖŒ×××××× ×, x86, ××¢×ת××¢× Intel
0007 × 000 ×
UCOD
××קך×֞ק×Öž××¢ ×עך×××Ö·× ××ק×× ××¢× ×€Ö¿×ַך ק׀֌×, ××¢×ת××¢× ×××š× ×× ××¢×
0008 0000 ×
××××€ÖŒ
UEFI BIOS, SEC/PEI ×€×ַסעס, x86, ××¢×ת××¢× ×××š× ×× ×€×ַךק××׀עך
0021 8000 ×
ISHC
Intel ISH ×€×ך××××ַךע ק×Öž× ×Öž×€ÖŒ×××××× ×, x86, ××¢×ת××¢× ×××š× ×× ×€×ַךק××׀עך
0025 8000 ×
× ×€××€ÖŒ
Intel TXE ×€×ך××××ַךע ק×Öž× ×Öž×€ÖŒ×××××× ×, x86, ××¢×ת××¢× Intel
0036 1000 ×
IUNP
××× ×××××ַק×Ö·× ×
0038 1000 ×
OBBP
UEFI BIOS, DXE Phase, x86, ×Ö·× ×¡××× ×
×עש×ַס ×× ×Ö·× ×Ö·××ס×ס ×€×× ×× TXE ×€×ך××××ַךע, עס ××× ××¢×××¢× ×§××֞ך ××× ×עך ××Öž× ×Ö·× × ×Öž× ×Ö· RESET, ×× TXE ×××× ×× ×€ÖŒ×š×ַסעסעך ××× ××¢× ×©××Ö·× ××× ×¢×¡ ׀֌ך××€ÖŒ×¢×š× ×× ×קעך××ק ××× ××Ö·×× ×€×× ×× ×Ö·×ךעס ×€ÖŒ××Ö·×¥ ×€Ö¿×ַך ×× ×§×€ÖŒ× (FIT, ACM, RESET ××עק××֞ך ...). ×עך׊×, TXE ××××× ×× ××Ö·×× ××× ×××× SRAM, × ×Öž× ×××֞ס עס ××¢×׀֌עךעך×Ö·×× ××× ×× ×€ÖŒ×š×ַסעסעך ×ַקסעס ××Öž×š× ××× "ך×××ס××" עס ×€Ö¿×× RESET.
××××£ ×××× ×§×¢×× ×š×Öž×Öž×ק××¥
× ×, ×××Š× ××Öž×× ×¡ ××Ö·× ××××£ ×Š× ×× "×××ס" ש××Öž×€ÖŒ×. ××ך ×Ö·××Öž× ××סק×Ö·×××¢×š× ×Ö·× ××××£ ×€×××¢ ס×ס××¢××¢×, SPI ××××¥ ××סקך××€ÖŒ××֞ךס ×Ö·× ×××Ö·××× ×€ÖŒ×¢×š××ש×Ö·× × ×Š× ×ַקסעס ×ק×××ת ×€×× SPI ××××¥ ××֌ך×× ×Ö·××× ×Ö·× ×Ö·××¢ × ×׊עךס ×€×× ××¢× ××֌ך×× ×§×¢× ×¢× ×©×š××Ö·×× ××× ××××¢× ×¢× ×§××× ××¢×× ×. ××¢× ×¢. ק××× ×××¢×.
× ×Öž× ×§×Öž× ×ך×Öž××ך×× × ××× ×× MEinfo × ××Š× (×€Ö¿×× Intel STK), ××ך ××¢××¢× ×Ö·× ×× ××Ö·× ××€×ַק××ך×× × ××Öž××¢ ××××£ ×× ×¡×ס××¢××¢× ××× × ××©× ×€Ö¿×ַך××Ö·××, ×עך××עך, ×× ×ש××€ÖŒ×¡×¢× ×€×סעס (×€×€×£) ××¢× ×¢× ××× ×§×¡ ××× ×Ö· ×Ö·× ×××€××× × ×©××Ö·×. ××Öž, Intel BG ××× × ×× ×××ס××¢×ך××× ××××£ ××עך ×Ö·××עק ××× ×Ö·××Ö· ק×ַסעס.
××ך ךע×× ×××¢×× ×× ×€××××¢× ××¢ ס×ס××¢××¢× (××× ×ך×ס ×Š× Intel BG ××× ×××֞ס ×××¢× ×××× ××סקך×××× ×©×€ÖŒ×¢×עך ××× ××¢× ×ַך××ק×, ××ך ×××¢×× ×š×¢×× ×××¢×× ×¡×ס××¢××¢× ××× Haswell ׀֌ך×ַסעסעך ××קך×Öž×ַך×ש××עק××ךע ××× ××¢×עך):
- ×Ö·××¢ ×××××××× ×€ÖŒ×š×Öž××ק××;
- ×Ö·××¢ ××¡× ×€ÖŒ×š×Öž××ק××;
- 21 ××Öž××¢×ס ×€×× ××¢× ×Öž×××Öž ××Ö·×€ÖŒ××ַ׀֌ס ××× 4 ××Öž××¢×ס ×€×× ××¢× ×Öž×××Öž סעך××עךס.
×€×× ×§×ךס, ××ך ××¢××××× ×× ××€×עק×× × ×Š× ×× ×××¢× ××֞ךס, ××× ××¢××× × ××× ×Š× Intel.
× ××××× ×š×¢×ק׊××¢ ××× ×עק×××¢× ××××× ×€×× ××¢× ×Öž×××Öž××עך ××¢×š×§×¢× × ×× ×€ÖŒ×š×Öž×××¢× ×××
××××Ö·×××× ××× ×¡××× ×Š× ×Öž× × ×¢××¢× ×× ××× ×€Ö¿×֞ך××ַ׊××¢ ×××¢×× ×× ×××Ö·×× ×¢×š×Ö·××××××, ×Öž×עך × ××©× ×§×Ö·××¢× ××Ö·× ××× ×§××× ×××¢×.
ק×Öž××× ×ק×ַ׊××¢ ××× ××¡× ××֞ך ס××Öž×× ××××£ ××× ××עך ××§×©× ×Š× ×©××§× ×××× ×¢×€× ×××¢× PGP ש×××¡× (×Š× ×©××§× ××× ×Ö· ×××עך×××× ×Ö·×××××××¢×š× ××× ×× ×§×š××€ÖŒ××× ×€×֞ךע×). ××× ×¡×××××× ×Ö·× ××× "××¢× ×¢× ×Ö· ××Ö·×× ×××Ö·×š× ×€×Ö·×ך×ק×Ö·× × ××× ××Öž× × ×× ×€ÖŒ×š×Öž××׊××š× ×€ÖŒ××€ÖŒ ש××ס××¢×."
××עך ××××ך ×× ×§×××¢× ×Š× ×× × ×§×××. ××× × ×× ×€×סעס ××¢× ×¢× ××× ×§×¡ ××× ×Ö·× ×× ×¡×€ÖŒ×¢×¡××€××¢× ×©××Ö·×, ×עך ××Ö·× ×׊עך (×Öž×עך ×Ö·××ַקעך) ×§×¢× ×¢× ×€ÖŒ×š×Öž×ך×Ö·× ××× ×× ×××€ÖŒ×¢× ××Ö·× ××× (×× ××¢×š×¡× ×©××עך ××Ö·× ×××
1. ש××××× ××× Windows OS (××× ×Ö·×××¢××××, ×× ×ַקש×Ö·× × ××סקך×××× ××× ×× ×§×¢× ×¢× ×××× ×××× ××¢××× ××× ×עך ××× ×קס ×××× ××ך ×Ö·× ××××ק××¢× ×Ö·× ×Ö·× ×Ö·××Öž× ×€×× Intel STK ×€Ö¿×ַך ×× ××¢××¢×× ×ַס). × ××Š× ×× MEinfo × ×׊×, ××Ö·×× ×××עך ×Ö·× ×€×סעס ××¢× ×¢× × ××©× ×€ÖŒ×š×Öž××ך×Ö·×× ××××£ ××¢× ×¡×ס××¢×.
2. ××××¢× ×¢× ×× ××× ××Ö·×× ×€×× ××××¥ ××֌ך×× × ××Š× ×× ×€××ַש ׀֌ך×Öž×ך×Ö·×××× × ×××.
3. ×¢×€Ö¿×¢× ×¢× ×× ××××¢× ×¢× ×××× ××× ×§××× UEFI ××××Öž×ס ×¢××××× × ×ע׊××Ö·×, ××Ö·×× ×× × ××××ק ×¢× ×עך×× ××¢× (××Ö·×€××š× ×Ö· ך×Öž×Öž×ק××, ××ש×), ש×Ö·×€Ö¿× / ךע××Ö·×××š× ××××ס××× × KEYM ××× IBBM ס×ך×ַק××©×¢×š× ××× ×× ××ך ××¢×× ×.
×× ×××× ×××××××¥ ×× ×¢×€× ×××¢× ×××× ×€×× ×× RSA ש××ס×, ×× ××ַש ×€×× ×××֞ס ×××¢× ×××× ×€ÖŒ×š×Öž××ך×Ö·×× ××× ×× ×ש××€ÖŒ×¡×¢× ×€×סעס ׊×××××¢× ××× ×× ×š×¢×©× ×€×× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·×.
4. × ××Š× ×× ×€××ַש ×××× ×××, ××××¢× ×Ö· × ××Ö· ×€×ך××××ַךע ×××× (×××š× ××ַש××¢×××§× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·×).
5. שך××× ×Ö· × ××Ö·×¢ ×××× ×Š× ××××¥ ××֌ך×× × ××Š× ×× ×€××ַש ׀֌ך×Öž×ך×Ö·×××× × ×××, ××× ××ַש××¢×××§× ××× MEinfo ×Ö·× ×× ME ××¢×× × ×××Š× ×ÖŒ××× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·×.
6. × ××Š× ×× ×€××ַש ׀֌ך×Öž×ך×Ö·×××× × ××× ×Š× ×€×ַך××Ö·×× ××Ö·× ××€×ַק××ך×× × ××Öž××¢.
7. ×× ×¡×ס××¢× ×××¢× ×š×¢××Öž×Öž×, × ×Öž× ×××֞ס ××ך ×§×¢× ×¢× × ××Š× MEinfo ×Š× ××ַש××¢×××§× ×Ö·× ×× FPFs ××¢× ×¢× ×××Š× ×€ÖŒ×š×Öž××ך×Ö·××.
×× ×ַקש×Ö·× × ×Ö·×€ ש××¢× ××ק ××¢×× Intel BG ××××£ ××¢× ×¡×ס××¢×. ×× ×ַק׊××¢ ×§×¢× ×¢× × ×× ×××× ×Ö·× ×××××× ×, ×××֞ס ××××:
- ××××× ×× ××Ö·××׊עך ×€×× ×× ×€ÖŒ×š××××Ö·× ×××× ×€×× ×× ×××Öž×š×Š× ×©×××¡× (×"× ×עך ×××× ×¢×š ×××֞ס ×¢× ××××Ö·×× Intel BG) ×××¢× ×§×¢× ×¢× ×Š× ×עך×××Ö·× ×××§× ×× UEFI ××××Öž×ס ××××£ ××¢× ×¡×ס××¢×;
- ×××× ××ך ׊×ך×קק×××¢× ×× ×֞ך×××× ×¢× ×€×ך××××ַךע ×Š× ××¢× ×¡×ס××¢×, ×€Ö¿×ַך ×××ַש׀֌××, × ××Š× ×Ö· ׀֌ך×Öž×ך×Ö·××ס×, עס ×××¢× × ××©× ××€××× ×§×¢×š ××××£ (×Ö· ק×Ö·× ×¡×ַק×××Ö·× ×¡ ×€×× ×× ×¢× ×€×֞ךס××Ö·× × ×€ÖŒ×Öž××××ק ××× ×€×Ö·× ×€×× ×Ö· ××עך×Ö·×€×ַק××ש×Ö·× ××¢×ת);
- ×Š× ××ַק×××¢× ××ַ׀ך××Ö·×¢× ×€×× ×Ö·××Ö· ×Ö· UEFI ××××Öž×ס, ××ך ××Ö·×š×€Ö¿× ×Š× ×€×ַך×××Ö·×× ×× ×ש××€ÖŒ×¡×¢× ××× ×€ÖŒ×š×Öž××ך×Ö·×× FPFs ××× ×Ö· "ך×××" (×"×, ך×ס×Öž××× ×× ×ש××€ÖŒ×¡×¢× ×××× ××ך ××Öž×× ×Š××ך×× ×Š× ×Ö· ×× ×€×š×¢×š×¢× ×¡×Ö·×עך×× × ×¡××Ö·× ×Š××¢ ×× ×€ÖŒ×š××Ö·× ×€×× ×Ö· ××ַש××, ×Öž×עך ׀ש×× ×€×ַך×××Ö·×× ×× ××Öž××עך××Öž×Ö·×š× ).
×Š× ×€Ö¿×ַךש×××× ×××֞ס ×Ö·××Ö· ×Ö· ך×Öž×Öž×ק×× ×§×¢× ×¢× ××Öž×, ××ך ××Ö·×š×€Ö¿× ×Š× ×֞׀֌ש×Ö·×Š× ×××֞ס ×××× ×¢×¡ ××¢×××¢× ×Š× ××ס׀××š× ×××× ×§×Öž× ××× ×× UEFI ××××Öž×ס ס××××××¢. ××× ×¡ ××Öž××, ××× ×× ××¢×š×¡× ×€ÖŒ×š××××××××©× ×€ÖŒ×š×ַסעסעך ××Öž××¢ - SMM. ×Ö·××Ö· ×Ö· ך×Öž×Öž×ק×× ×§×¢× ××Öž×× ×× ×€××××¢× ××¢ ׀֌ך×֞׀֌עך××עס:
- עקס×ַק××××Ö·× ××× ×€ÖŒ×ַך×Ö·××¢× ××× ×× ×ַס (××ך ×§×¢× ×¢× ×§×Ö·× ×€×××עך ׀֌ך×ַסעס×× × ×Š× ×××©×¢× ×¢×š××× ×Ö· SMI ××עךך××ַס, ×××֞ס ×××¢× ×××× ×ך×××¢×š× ×××š× ×Ö· ×××Ö·×עך);
- ××Öž×× ×Ö·××¢ ×× ×Ö·××××Ö·× ××××ש×× ×€×× ×××Ö·×¢× ××ק ××× SMM ××Öž××¢ (×€×× ×ַקסעס ×Š× ×× ××× ××Ö·×× ×€×× ××ַך×Ö·× ××× ××Ö·×× ×××Ö·×š× ×š×¢×¡×ךס×, ×עס×Öž××ק××Ö·× ×€×× ×× ×ַס);
- ×עך ׀֌ך×Öž×ך×Ö·× ×§×Öž× ×€×× ×× ×š×Öž×Öž×ק×× ×§×¢× ×¢× ×××× ×× ×§×š××€ÖŒ××× ××× ×עקך××€ÖŒ××× ×××¢× ××Öž× ××©× ××× SMM ××Öž××¢. ק××× ××Ö·×× ×× ×××Š× ××××× ××× SMM ××Öž××¢ ×§×¢× ×¢× ×××× ××¢××××× × ××× ×Ö· ×¢× ×§×š×׀֌ש×Ö·× ×©××ס×. ×€Ö¿×ַך ×××ַש׀֌××, ×Ö· ××ַש ×€×× ×Ö· ס××× ×€×× ×Ö·×ךעסעס ××× SMRAM. ×Š× ××ַק×××¢× ××¢× ×©××ס×, ××ך ××Ö·×š×€Ö¿× ×Š× ×ַך××Ö·× SMM. ××× ××֞ס ×§×¢× ×××× ××¢××× ××× ×Š×××× ×××¢××. ××¢×€Ö¿×× ×¢× RCE ××× ×× SMM ק×Öž× ××× ××××ךע עס, ×Öž×עך ××××× ×××× ×××××¢× ×¢ SMM ××Öž××××¢ ×Š× ×× ××××Öž×ס, ×××֞ס ××× ×××××¢×××¢× ××× × ××ך ×¢× ××××Ö·×× Boot Guard.
××××, ××¢× ×××Ö·×× ×¢×š×Ö·×××××× ×Ö·××Ö·×× ×Ö· ×Ö·××ַקעך ׊×:
- ש×Ö·×€Ö¿× ×Ö· ×€×ַך××֞ך××, ×Ö·× ××¢××¢××Ö·×××¢ ך×Öž×Öž×ק×× ×€×× ×××××ַק×Ö·× × ×Š×× ××× ××¢× ×¡×ס××¢×;
- ××ס׀××š× ×××× ×§×Öž× ××××£ ×××× ×¢×š ×€×× ×× ×ש××€ÖŒ×¡×¢× ×§×֞ךעס ×× ×× Intel SoC, × ×××××, ××××£ ×× Intel ISH (× ×¢××¢× ×Ö· ×Öž×€ÖŒ××¢××× ×§×ק ××× ×× ××××).
××Öž×ש ×× ×§×××€ÖŒ×Ö·××××Ö·××× ×€×× ×× Intel ISH ס×Ö·×ס×ס××¢× ××¢× ×¢× × ××©× × ×Öž× ×קס׀֌××֞ך×, עס ××× ×Ö· ×ש×ק×Ö·×××¢ ××Ö·×€×Ö·×× ××עק××֞ך ×€Ö¿×ַך Intel ME.
×€××× ××× ××
- ×עך ××¢×š× ×¢× ××¢×××× ×¢×¡ ××¢×××¢× ×Š× ××ַק×××¢× ×Ö· ××¢×× ×ש ××ַשך××Ö·××× × ×€×× ×× ×֞׀֌עך×ַ׊××¢ ×€×× ââIntel Boot Guard ××¢×× ×Öž××Öž×××¢. ××× ×ס ×Ö· ×€ÖŒ×֞ך ×€×× ×¡×קך××¥ ××× Intel ס ×××עך×××× ×××š× ×Ö·×סק××ך××× ××Öž××¢×.
- ×Ö· ××Ö·×€×Ö·×× ×¡×Š×¢× ×ַך ××× ×עך××× ×× ×××֞ס ×Ö·××Ö·×× ××ך ×Š× ×©×Ö·×€Ö¿× ×Ö· ×× ×× ×¡××Ö·×××Ö·×××¢ ך×Öž×Öž×ק×× ××× ×× ×¡×ס××¢×.
- ××ך ××¢××¢× ×Ö·× ××Öž××¢×š× ×× ××¢× ×€ÖŒ×š×Ö·×¡×¢×¡×¢×š× ××¢× ×¢× ×××××¢××××ק ×€×× ×¢×§×¡×ַק××××× × ×Ö· ×€ÖŒ××Ö·×¥ ×€×× ×€ÖŒ×š×ַ׀֌ך×××Ö·××¢×š× ×§×Öž× ××€××× ××××עך ×× ××××Öž×ס ס××ַךץ ×€×××¡× ××ק.
- ×€ÖŒ××Ö·××€×֞ך×ס ××× Intel 64 ×ַךק×Ö·×עק×שעך ×××¢×š× ××××× ×קעך ××× ××××× ×קעך ×€ÖŒ×ַס×ק ×€Ö¿×ַך ×€×××¡× ××ק ׀ך×× ××××××××ך×: ××Ö·×× ×××Ö·×š× ××עך×Ö·×€×ַק××ש×Ö·×, ×Ö· ×× ×§×š×ס×× × × ××עך ×€×× ×€ÖŒ×š×ַ׀֌ך×××Ö·××¢×š× ××¢×§× ×Ö·××Ö·××ש×× ××× ×¡×Ö·×ס×ס××Ö·×× (×ך×× ×§×֞ךעס ××× ×× SoC ×ש×׀֌סע×: x86 ME, x86 ISH ××× ARC PMC).
××××××׊×עס
×××¢× ××֞ךס ×××֞ס ×עק×××× ××Öž×× ××Ö·× ××€×ַק××ך×× × ××Öž××¢ ×Öž×€× ××Öž× ×××× ×××עך ×Š× ×€×ַך××Ö·×× ×¢×¡. ××× ××׊×, ××××× ×××עך ××××× ××¢× ×¢× ×€×ך××××, ××× ×× × ××Ö·×¢ Kaby Lake ס×ס××¢××¢× ××××Ö·×× ××֞ס.
××××¢×š× ×§×¢× ×¢× ××ס××××Ö·× Intel BG ××××£ ×××עך ס×ס××¢××¢× (×××֞ס ××¢× ×¢× ×¡×ַסע׀֌××Ö·××Ö·× ×Š× ×× ××סקך×××× ×××Ö·×× ×¢×š×Ö·××××××) ×××š× ××××€× ×× ×€××ַש ׀֌ך×Öž×ך×Ö·×××× × ××× ××× ×× -closemnf ×€ÖŒ×ַך×Ö·××¢×עך. עךש×עך, ××ך ××Öž× ××Ö·×× ×××עך (× ××Š× MEinfo) ×Ö·× ×× Intel BG ק×Ö·× ×€×××עך××ש×Ö·× ××× ×× ME ××¢×× × ××× ×Š× ××ס××¢×§× ××¢× ××¢×× ×Öž××Öž×××¢ × ×Öž× ×€ÖŒ×š×Öž×ך×Ö·×××× × ××× FPFs.
×ק×ך: www.habr.com