Uyenza njani iVBS kwi-UEFI kwiWindows inyathelo ngenyathelo

Uhlaziyo lokugqibela: 17/03/2025

  • Ukhuseleko olusekwe kwiVirtualization (VBS) luphucula ukhuseleko lwenkqubo.
  • Ukwenza i-VBS isebenze ifuna i-UEFI kunye ne-TPM 2.0 yehardware ehambelanayo.
  • Ingenziwa ukuba isebenze kwi-BIOS, iRegistry yeWindows, kunye nePolisi yeQela.
  • Kukho iindlela zokuqinisekisa ukuba iVBS yenziwe ngokuchanekileyo.
VSB

La ukhuseleko olusekwe kwinyani (VBS) kwi-Windows luphawu oluphucula ukhuseleko lwenkqubo ngokudala indawo ekhuselekileyo nekwanti. Kodwa ngenxa vumela iVBS kwi-UEFI kwaye ukuthatha ithuba loluphawu, kuyafuneka ukuhlangabezana nehardware ethile kunye neemfuno zoqwalaselo kwinkqubo yokusebenza.

Kweli nqaku siphonononga ngokweenkcukacha indlela yokuvula Ukhuseleko oluSekwe kwiVirtualization ukusuka kwi-UEFI, ngawaphi amanyathelo okufuneka uwalandele ukujonga isimo sayo kunye nendlela yokusombulula imiba enokwenzeka ngexesha loqwalaselo.

Yintoni uKhuseleko oluSekwe kwiVirtualization (VBS)?

Ukhuseleko oluSekwe kwiVirtualization (VBS) yi Itekhnoloji yokhuseleko yeWindows esetyenziswa sisixokelelwano se-hypervisor ukwenza imeko-bume ekhuselekileyo ngaphakathi kwinkumbulo. Ngale ndlela, idatha yenkqubo ebalulekileyo ikhuselwe kwiingozi ezinokubakho. Olu phawu ryomeleza ukhuseleko lwe-kernel kwaye inciphisa ukufikelela kwiinkqubo ezingagunyaziswanga.

Enye yezinto eziphambili zeVBS yi Ingqibelelo Yenkumbulo, ethintela ukuphunyezwa kwekhowudi enobungozi ngokujonga ukunyaniseka kwabaqhubi kunye neefayile zenkqubo phambi kokubavumela ukuba baqhube.

Umxholo okhethekileyo- Cofa Apha  Uyisebenzisa njani iBanco Azteca App

Iimfuno zokuvula iVBS

Ngaphambi kokuba uvule iVBS kwi-UEFI, qiniseka ukuba ikhomputha yakho ihlangabezana nezi mfuno zilandelayo:

  • I-Firmware ye-UEFI: : Kuyimfuneko ukuba i-BIOS imiselwe kwimo ye-UEFI endaweni yeLifa.
  • TPM 2.0: IModyuli yeQonga eliThenjiweyo kufuneka yenziwe ukuba isebenze kwi-BIOS.
  • Khusela i-Boot: Olu khetho lwe-BIOS kufuneka luvulwe.
  • Ukhuseleko lwe-DMA: Ukuphucula ukhuseleko ngokunciphisa ukufikelela kwizixhobo zangaphandle.

Ngaphandle koku, ukujonga ukuba inkqubo yakho iyahambelana neVBS, kufuneka ulandele la manyathelo:

  1. Sebenzisa indlela emfutshane yebhodi yezitshixo Yinqoba + RUbhala msinfo32 kwaye cinezela faka.
  2. Jonga icandelo «Ukhuseleko olusekwe kwinyani«. Ukuba ibonisa njenge "Ibaleka," ngoko sele ivuliwe.

Ukuba ufuna ukufunda ngakumbi malunga nendlela yokwenza virtualization kwinkqubo yakho, ungajonga isikhokelo sethu Yenza i-virtualization yehardware ngaphakathi Windows 11.

iintlobo ze-bios

Uyenza njani iVBS kwiBIOS (UEFI)

Ukwenza iVBS isebenze kwi-UEFI (ukusuka kwi-BIOS), landela la manyathelo:

  1. Qala kabusha ikhompyuter yakho kwaye ufikelele kwi-BIOS ngokucofa F2, F10, Del okanye Esc, kuxhomekeke kumenzi.
  2. Kwisetingi semenyu, khangela ukhetho "Indlela yokuQalisa»kwaye utshintsho kwi UEFI ukuba usekwimowudi yeLifa.
  3. Fumana ukhetho "TPM 2.0» kwaye uyivule ukuba ayivulwanga.
  4. Yenza ukhetho «Khusela i-Boot«.
  5. Gcina utshintsho kwaye uqale kabusha ikhompyuter.
Umxholo okhethekileyo- Cofa Apha  Ndingalijonga njani ixesha eliqikelelweyo lokufika kukaloliwe kwi-app kaloliwe?

Yenza iVBS isebenze kwiRejistri yeWindows

Ukuba ukhetha ukwenza iVBS isebenze usebenzisa i Ubhaliso lweWindows, yenza la manyathelo alandelayo:

  1. Cinezela Yinqoba + RUbhala regedit kwaye cinezela faka.
  2. Yiya kule ndlela ilandelayo:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard
  3. Fumana okanye wenze ixabiso leDWORD elinegama "Yenza iVirtualizationBasedSecurity»kwaye inika ixabiso 1.
  4. Kwindawo enye, lungisa "I-RequirePlatformSecurityFeatures"ku 3 (ukukhusela i-boot kunye nokhuseleko lwe-DMA).
  5. Gcina utshintsho kwaye uqalise kwakhona ikhompyuter yakho.

Ukuqwalasela iVBS Ukusebenzisa uMgaqo-nkqubo weQela

Abalawuli benkqubo banokwenza iVBS isebenzise uMgaqo-nkqubo weQela:

  1. Vula Umhleli woMgaqo-nkqubo weQela Ukubhala gpedit.msc kwimenyu yokuqala.
  2. Emva koko yiya ku Ukuseta iqela.
  3. Apho sikhetha Izakhelo zolawulo > Inkqubo > IsiGada sesixhobo.
  4. Vula ukhetho «Yenza ukhuseleko olusekwe kwinyani"Kwaye ukhethe"Kwenziwe«.
  5. Kuluhlu oluhlayo, khetha "Yenziwe nge-UEFI lock«.
  6. Gcina utshintsho kwaye uqale kabusha ikhompyuter.

Uyijonga njani ukuba iVBS iyasebenza

Kukho iindlela ezininzi zokuqinisekisa ukuba iVBS yenziwe ngokuchanekileyo:

  • Ukusebenzisa i-msinfo32, ukukhangela icandelo elithi "Virtualization-Based Security". Ukuba ikwimowudi "YokuSebenza", ngoko iyasebenza.
  • Ukusebenzisa iPowerShell, usebenzisa lo myalelo ulandelayo kwiPowerShell ngeemvume zomlawuli: (Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard).SecurityServicesRunning.Ukuba imveliso ibonisa "2«, kuthetha ukuba iVBS iyasebenza.
  • NgoMjongi weMsitho. Vula umcimbivwr.msc kwaye uye kwi "Windows Logs > System". Hlunga nge "WinInit" ukubona ukuba iVBS yenziwe ngempumelelo na.
Umxholo okhethekileyo- Cofa Apha  Ngaba i-app ye-VRV isebenza kwizixhobo ezihlakaniphile?
vumela iVBS kwi-UEFI
Uyenza njani iVBS kwi-UEFI kwiWindows

Ukusombulula iVBS Activation

Ukuba ufumana iingxaki xa uzama ukwenza iVBS isebenze kwi-UEFI, zama ezi zisombululo zilandelayo:

  • TPM 2.0 ikhubazekile: Ngenisa i-BIOS kwaye uqinisekise ukuba yenziwe.
  • Imo yelifa kwi-BIOS: Guqula useto kwi-UEFI.
  • Inkqubo ayilayishi emva kokusebenza: Khubaza i-VBS kwiRejistri okanye iPolisi yeQela kwaye uqalise kwakhona.
  • abaqhubi abangahambelaniyo: Hlaziya abaqhubi kuMphathi weSixhobo.

Ngokulandela la manyathelo ngokuchanekileyo, kufuneka ukwazi ukwenza iVBS isebenze kwi-UEFI, o.k ukhuseleko olusekwe kwinyani ngaphandle kweengxaki. Le teknoloji sisixhobo esibalulekileyo sokwandisa ukhuseleko lwenkqubo yakho kwizoyikiso eziphezulu.