Remote pre-configuration method, system, device and medium for BIOS password and login parameters
Through BMC Redfish, the BIOS password and login parameters are remotely preconfigured, and the dual SHA256 encryption algorithm and synchronization structure are used to solve the problem that the server needs to be restarted in the existing technology by setting the BIOS login password, realizing remote batch configuration without restart, and improving operational convenience and work efficiency.
Patent Information
- Application Number
- CN202211320294.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-26
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-10-26
AI Technical Summary
When setting the BIOS login password in the boot state, the existing server needs to restart the server, which affects normal business support. In addition, there are fewer prompts for the BIOS login process, and the user's operation convenience is low.
The BIOS password and login parameters are remotely preconfigured through BMC Redfish, and password encryption and parameter synchronization are used to use the dual SHA256 encryption algorithm and synchronization structure to achieve multiple login options such as batch presetting of BIOS passwords without restarting the server.
It realizes that Redfish can remotely query and package configuration of BIOS passwords and login parameters without restarting the server, saving operation and maintenance testing time, improving work efficiency, and improving the convenience of user settings verification.
Smart Images

Figure CN115640568B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and more particularly to a method, system, device and medium for remotely pre-configuring BIOS passwords and login parameters. Background Art
[0002] The BIOS setup program is stored in the BIOS chip and can only be set when the computer is booted. The BMC can implement functions such as server-related control and information monitoring, and is a platform for intuitively presenting server information. Server customers can access the server BMC through tools such as web, redfish, ipmitool, and snmp to obtain server information. Redfish is a more secure and flexible way compared to the traditional server management IPMI (Intelligent Platform Management Interface), and uses a human-readable interface for data display and information update.
[0003] To prevent others from modifying the motherboard CMOS settings and protecting the setup configuration information, the BIOS can set a login password, and the correct password must be entered to log in to the BIOS. In a server, the BIOS password and login parameters are separately stored on the BIOS side. If you want to modify the relevant information, you need to enter the correct password to enter the BIOS after booting, modify the relevant information and save it, and the set content will take effect after restarting the server.
[0004] For the existing servers to set the BIOS password and login parameters, they need to enter the BIOS at the initial stage of server startup, modify the setup interface information and save it, and then restart the server and enter the BIOS again to verify whether it takes effect. Currently, the method of setting the BIOS password through redfish can only configure a single password item, and this process cannot be displayed to the user through the BMC, and it cannot meet the user's requirement of setting multiple relevant parameters through a single package. Currently, when the user's server is running and supporting services, if you want to set the BIOS login password, you first need to restart the server for configuration, and then restart the server again after configuration to take effect, which affects the normal support of the server for services. Moreover, since there are few prompts during the BIOS login process, the user does not get comprehensive prompt information during misoperation, and the operation convenience is relatively low. Summary of the Invention
[0005] In view of the above problems, the object of the present invention is to provide a method, system, device and medium for remotely pre-configuring BIOS passwords and login parameters, which can batch pre-set multiple login options such as BIOS passwords through Redfish while maintaining the normal use of the server without restarting the server to enter the BIOS setup interface. When the user can stop the service and restart the server, it will take effect with the server restart.
[0006] To achieve the above object, the present invention is realized through the following technical solutions: A method for remotely pre-configuring BIOS passwords and login parameters, including:
[0007] The BMC and the BIOS encrypt the password by using the same dual SHA256 encryption algorithm;
[0008] The BMC and the BIOS synchronize the BIOS password and login parameters through a newly added process using a synchronization structure;
[0009] When the server is powered on for the first time, the BIOS writes the initial values of the password and login parameters into the EEPROM through IPMI commands, communicates with the BMC, initializes the content of the synchronization structure, and stores the content of the synchronization structure in the buffer;
[0010] Perform a simulated login to the BIOS through BMC Redfish;
[0011] Modify the BIOS login parameters through BMC Redfish;
[0012] When the synchronization structure in the EEPROM has not been modified, if a parameter reading operation is performed, directly read the corresponding parameter item stored in the buffer.
[0013] Further, the BMC and the BIOS encrypt the password by using the same dual SHA256 encryption algorithm, including:
[0014] Synchronize the first twelve bytes of the ciphertext obtained after encryption and compare and verify. After the verification passes, the corresponding verification requester obtains the operation permission.
[0015] Further, the synchronization structure includes:
[0016] Update flag updateFlag, lock duration LockTime, password check switch pwdCheck, fixed complexity switch pwdComplex, fixed password length pwdLen, retry times RetryTimes and ciphertext pwd.
[0017] Further, the update flag updateFlag, as the BMC update flag, has a resource quantity of 1. When the user updates the password or login parameters through the BMC, this flag bit is set to 1, indicating that the resource quantity to be fetched is 1; when the BIOS reads this flag bit as 1, it synchronizes the new option value provided by the BMC, and then sets this flag bit to 0, indicating that the resource has been fetched and the synchronization is completed.
[0018] Further, the lock duration LockTime is used to record the duration for which the user is locked after the number of times the user enters the wrong password exceeds the retry times; the password check switch pwdCheck, the fixed complexity switch pwdComplex, the fixed password length pwdLen, and the retry times RetryTimes are used to record the corresponding BIOS login parameters; the ciphertext pwd is used to record the first twelve bytes of the ciphertext generated after the BMC and the BIOS encrypt the password using the same double SHA256 encryption algorithm.
[0019] Further, the simulated login of the BIOS through BMC Redfish includes:
[0020] Performing a simulated login of the BIOS in the Postman interface through the Redfish method to query and modify relevant parameters;
[0021] During the simulated login, the retry times and the lock duration are tested and verified, and a new password is set and login verification is performed according to the password length limit and the password rules.
[0022] Further, the modification of the BIOS login parameters through BMC Redfish includes:
[0023] Modifying the BIOS login parameters through BMC Redfish according to the range of the modified parameter items;
[0024] After the modification is successful, the information of the synchronization structure in the EEPROM is synchronously modified, the modified parameters take effect immediately, and instant verification is supported;
[0025] After verifying the modified BIOS login parameters, optimize the modification according to the comparison result with the expected value;
[0026] The BMC will save the last finally modified BIOS login parameters as the content synchronized with the BIOS, which takes effect after the server restarts.
[0027] Correspondingly, the present invention also discloses a remote pre-configuration system for BIOS passwords and login parameters, including:
[0028] An encryption module for encrypting passwords by the BMC and the BIOS using the same dual SHA256 encryption algorithm;
[0029] A synchronization module for synchronizing the BIOS password and login parameters by the BMC and the BIOS through a new process using a synchronization structure;
[0030] An initialization module for, after the server is powered on for the first time, the BIOS writing information into the EEPROM through IPMI commands with the initial values of the password and login parameters, communicating with the BMC, initializing the content of the synchronization structure, and storing the content of the synchronization structure in a buffer;
[0031] A simulated login module for simulating a login to the BIOS through BMC Redfish;
[0032] A modification module for modifying the BIOS login parameters through BMC Redfish;
[0033] A cache reading module for, when the synchronization structure in the EEPROM has not been modified, directly reading the corresponding parameter item stored in the buffer if a parameter reading operation is performed.
[0034] Correspondingly, the present invention discloses a remote pre-configuration device for BIOS passwords and login parameters, including:
[0035] A memory for storing a remote pre-configuration program for BIOS passwords and login parameters;
[0036] A processor for implementing the steps of the remote pre-configuration method for BIOS passwords and login parameters as described in any one of the above when executing the remote pre-configuration program for BIOS passwords and login parameters.
[0037] Correspondingly, the present invention discloses a readable storage medium having stored thereon a remote pre-configuration program for BIOS passwords and login parameters, and the remote pre-configuration program for BIOS passwords and login parameters, when executed by a processor, implements the steps of the remote pre-configuration method for BIOS passwords and login parameters as described in any one of the above.
[0038] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention discloses a method, system, device and medium for remotely pre-configuring BIOS passwords and login parameters. By means of remotely pre-configuring BIOS passwords through BMC Redfish, it is possible to remotely batch query and package-configure BIOS passwords and login parameters through Redfish without the need to restart and enter the BIOS in advance. Compared with the traditional method of configuring in the BIOS setup interface, it is more flexible. The present invention can simulate the working status of various parameters during login verification, eliminating the need to verify parameters after restarting and entering the BIOS, saving operation and maintenance testing time and improving work efficiency.
[0039] By designing a synchronization structure, the present invention avoids conflicts caused by simultaneous writing by BMC and BIOS during the same boot phase. In addition to synchronizing password information, it can also synchronize other password parameters, enabling users to complete settings in a bundled manner.
[0040] The present invention can simulate the phenomena when various parameters take effect through redfish, facilitating users to quickly verify parameters without restarting, greatly improving the convenience of user setting verification, and avoiding manpower loss caused by restarting and entering the BIOS setup to view the configuration effect after setting.
[0041] The present invention caches at the code layer through a caching mechanism and quickly returns query values to reduce the BMC's reading of the EEPROM. Since there are various situations of modifying all and single parameters during parameter configuration through redfish, if all are directly read from the EEPROM, it will inevitably cause losses in program running time and device life. Therefore, when the information has not been modified by BMC-side users or BIOS-side, the previously cached parameter information can be reused, effectively reducing the direct reading times of the EEPROM.
[0042] It can be seen that compared with the prior art, the present invention has outstanding substantive features and significant progress, and the beneficial effects of its implementation are also obvious. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for description in the embodiments or the prior art. Obviously, the following drawings are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0044] Figure 1 It is the flowchart of the method for the specific implementation manner of the present invention.
[0045] Figure 2It is the system structure diagram of the specific implementation mode of the present invention.
[0046] In the figure, 1. Encryption module; 2. Synchronization module; 3. Initialization module; 4. Simulated login module; 5. Modification module; 6. Cache reading module. Specific implementation mode
[0047] The core of the present invention is to provide a method for remotely pre-configuring BIOS passwords and login parameters. In the prior art, when the user server is running and supporting services, if you want to set the BIOS login password, you first need to restart the server for configuration, and then restart the server again after the configuration takes effect, which affects the normal support of the server for services. Moreover, due to the few prompts during the BIOS login process, users do not get comprehensive prompt information during misoperations, and the operation convenience is relatively low.
[0048] The method for remotely pre-configuring BIOS passwords and login parameters provided by the present invention is as follows: First, the BMC and the BIOS encrypt the password using the same dual SHA256 encryption algorithm, and synchronize the BIOS password and login parameters using a synchronization structure through a newly added process. At this time, when the server is powered on for the first time, the BIOS writes the initial values of the password and login parameters into the EEPROM through the IPMI command, communicates with the BMC, initializes the content of the synchronization structure, and stores the content of the synchronization structure in the buffer. Then, perform simulated login of the BIOS and modification of the BIOS login parameters through BMC Redfish. In addition, when the synchronization structure in the EEPROM has not been modified, if a parameter reading operation is performed, directly read the corresponding parameter item stored in the buffer. It can be seen that the present invention can perform batch pre-setting of multiple login options such as BIOS passwords through redfish while maintaining the normal use of the server without restarting the server to enter the BIOS setup interface. When the user can stop the service and restart the server, it will take effect with the server restart.
[0049] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the drawings and specific implementation modes. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0050] Embodiment 1:
[0051] As Figure 1 shown, this embodiment provides a method for remotely pre-configuring BIOS passwords and login parameters, including the following steps:
[0052] S1: The BMC and the BIOS encrypt the password using the same dual SHA256 encryption algorithm.
[0053] Specifically, the BMC and the BIOS encrypt the password using the same dual SHA256 encryption algorithm, synchronize the first twelve bytes of the ciphertext, and compare and verify them. Only when the verification passes can the permission be obtained for subsequent operations.
[0054] S2: The BMC and the BIOS synchronize the BIOS password and login parameters through a newly added process using a synchronization structure.
[0055] The newly added processes in the BMC and the BIOS synchronize the BIOS password and login parameters. Using the concept of the integer semaphore mechanism, information synchronization is achieved through the synchronization structure.
[0056] Among them, the synchronization structure includes: update flag updateFlag, lock duration LockTime, password check switch pwdCheck, fixed complexity switch pwdComplex, fixed password length pwdLen, retry times RetryTimes, and ciphertext pwd.
[0057] The update flag updateFlag, as the BMC update flag, has a resource quantity of 1. When the user updates the password or login parameters through the BMC, this flag bit is set to 1, indicating that the resource quantity to be taken is 1; when the BIOS reads this flag bit as 1, it synchronizes the new option value provided by the BMC, and then sets this flag bit to 0, indicating that the resource has been taken and the synchronization is complete.
[0058] The lock duration LockTime is used to record the duration when the user is locked after the number of times of entering the wrong password exceeds the retry times.
[0059] The password check switch pwdCheck, fixed complexity switch pwdComplex, fixed password length pwdLen, and retry times RetryTimes are used to record the remaining login parameters, corresponding one by one to the BIOS login parameters.
[0060] The ciphertext pwd is used to record the first twelve bytes of the ciphertext generated after the BMC and the BIOS encrypt the password using the same dual SHA256 encryption algorithm.
[0061] S3: When the server is powered on for the first time, the BIOS writes the initial values of the password and login parameters into the EEPROM through the IPMI command, communicates with the BMC, initializes the content of the synchronization structure, and stores the content of the synchronization structure in the buffer.
[0062] Specifically, when the server is powered on for the first time, the BIOS writes the password and the initial values of the login parameters into the EEPROM through IPMI commands, communicates with the BMC, and initializes and synchronizes the content of the structure. At the same time, the content of the synchronization structure is stored in the buffer.
[0063] S4: Perform a simulated login to the BIOS through BMC Redfish.
[0064] Specifically, a simulated login is performed through BMC Redfish, and relevant parameters can be queried and modified. The simulated login function implements the BIOS login process through the Redfish method in the Postman interface. The number of retries and the lock duration can be tested and verified. New passwords can be set and login verified according to the password length limit and password rules, preventing the BIOS from being locked due to multiple incorrect password entries during BIOS verification, which affects the normal use of the server and the support of customer services.
[0065] S5: Modify the BIOS login parameters through BMC Redfish.
[0066] Specifically, when the user modifies any parameter using Redfish, the requirements such as the range of the modified parameter item need to be met. After the modification is successful, the information in the EEPROM changes according to the user's modification. The Redfish simulated login takes effect immediately for the modified parameters and supports instant verification. After the user verifies, multiple optimization modifications are made according to whether there is a discrepancy with the expectation. The BMC saves the last final modification as the content synchronized with the BIOS, which takes effect after the user decides to restart the server independently.
[0067] S6: When the synchronization structure in the EEPROM has not been modified, if a parameter reading operation is performed, directly read the corresponding parameter item stored in the buffer.
[0068] Since the number of times of execution of reading is much greater than the number of times of setting when this method is used normally, this method uses a cache mechanism with a flag bit to reduce the direct reading of the EEPROM. If the information in the EEPROM has not changed, that is, the user has not modified the parameters in Redfish or the BIOS and the current information has not changed, directly read the parameter item temporarily stored in this program.
[0069] This embodiment provides a method for remotely pre-configuring BIOS passwords and login parameters. By remotely pre-configuring BIOS passwords through BMC Redfish, it is possible to remotely batch query and package-configure BIOS passwords and login parameters via Redfish without the need to restart and enter the BIOS beforehand. Compared with the traditional method of configuring through the BIOS setup interface, it is more flexible. This method can simulate the working status of various parameters during login verification, eliminating the need for parameter verification after restarting and entering the BIOS, saving operation and maintenance testing time and improving work efficiency.
[0070] Embodiment 2:
[0071] Based on Embodiment 1, as Figure 2 shown, the present invention also discloses a system for remotely pre-configuring BIOS passwords and login parameters, including: an encryption module 1, a synchronization module 2, an initialization module 3, a simulated login module 4, a modification module 5, and a cache reading module 6.
[0072] The encryption module 1 is used for the BMC and the BIOS to encrypt the password using the same dual SHA256 encryption algorithm. It is also used to synchronize and compare the first twelve bytes of the ciphertext obtained after encryption. After the verification passes, the corresponding verification requester obtains the operation permission.
[0073] The synchronization module 2 is used for the BMC and the BIOS to synchronize the BIOS password and login parameters by adding a new process and using a synchronization structure.
[0074] The initialization module 3 is used, after the server is powered on for the first time, for the BIOS to write the initial values of the password and login parameters into the EEPROM through IPMI commands, communicate with the BMC, initialize the content of the synchronization structure, and store the content of the synchronization structure in the buffer.
[0075] The simulated login module 4 is used to perform a simulated login to the BIOS through BMC Redfish.
[0076] Specifically, the simulated login module 4 is used to perform a simulated login to the BIOS in the Postman interface through the Redfish method, query and modify relevant parameters; during the simulated login, test and verify the number of retry attempts and the lock duration, and set a new password and perform login verification according to the password length limit and password rules.
[0077] The modification module 5 is used to modify the BIOS login parameters through BMC Redfish.
[0078] The modification module 5 is specifically used for: modifying the BIOS login parameters through BMC Redfish according to the range of the modified parameter items; after the modification is successful, the information of the synchronization structure in the EEPROM is modified synchronously, the modified parameters take effect immediately, and support instant verification; after verifying the modified BIOS login parameters, optimize and modify them according to the comparison results with the expected ones; BMC will save the last final modification of the BIOS login parameters as the content synchronized with the BIOS, which will take effect after the server is restarted.
[0079] The cache reading module 6 is used to directly read the corresponding parameter items stored in the cache area when the synchronization structure in the EEPROM is not modified and a parameter reading operation is performed.
[0080] This embodiment provides a remote pre-configuration system for BIOS passwords and login parameters, and the specific technical effects are as follows:
[0081] 1. You don't need to restart the server to enter the BIOS setup interface. You can use redfish to batch pre-set BIOS passwords and other login options while maintaining normal server use. When the user stops the business and restarts the server, the settings will take effect as the server restarts.
[0082] 2. For managed devices, this system can complete batch password settings for multiple machines remotely.
[0083] 3. This system supports configuration and query of single parameter or multiple parameters through one operation;
[0084] 4. Through this system, BMC can perform remote simulation verification of BIOS passwords and login parameters at any time.
[0085] 5. Since EEPROM is needed as an intermediate medium, users may read it multiple times. Compared with the loss and time waste caused by reading EEPROM directly multiple times, this system proposes a cache mechanism with an update flag.
[0086] 6. When configuring parameters, this system uses the flexibility of BMC and redfish to provide users with more help and prompt information to help users complete the configuration work faster.
[0087] Embodiment three:
[0088] This embodiment discloses a remote pre-configuration device for BIOS passwords and login parameters, comprising a processor and a memory; wherein the processor implements the following steps when executing a remote pre-configuration program for BIOS passwords and login parameters stored in the memory:
[0089] 1. The BMC and the BIOS encrypt the password by using the same dual SHA256 encryption algorithm.
[0090] 2. The BMC and the BIOS synchronize the BIOS password and login parameters by using a new process to utilize a synchronization structure.
[0091] 3. When the server is powered on for the first time, the BIOS writes the initial values of the password and login parameters into the EEPROM through IPMI commands, communicates with the BMC, initializes the content of the synchronization structure, and stores the content of the synchronization structure in the buffer.
[0092] 4. Simulate the login to the BIOS through BMC Redfish.
[0093] 5. Modify the BIOS login parameters through BMC Redfish.
[0094] 6. When the synchronization structure in the EEPROM has not been modified, if a parameter reading operation is performed, directly read the corresponding parameter item stored in the buffer.
[0095] Furthermore, the remote pre-configuration device for the BIOS password and login parameters in this embodiment may further include:
[0096] An input interface, which is used to obtain the remote pre-configuration program of the BIOS password and login parameters imported from the outside world, save the obtained remote pre-configuration program of the BIOS password and login parameters to the memory, and can also be used to obtain various instructions and parameters transmitted by an external terminal device and transmit them to the processor so that the processor can perform corresponding processing by using the above various instructions and parameters. In this embodiment, the input interface may specifically include, but is not limited to, a USB interface, a serial interface, a voice input interface, a fingerprint input interface, a hard disk reading interface, etc.
[0097] An output interface, which is used to output various data generated by the processor to the terminal device connected thereto, so that other terminal devices connected to the output interface can obtain various data generated by the processor. In this embodiment, the output interface may specifically include, but is not limited to, a USB interface, a serial interface, etc.
[0098] A communication unit, which is used to establish a remote communication connection between the remote pre-configuration device for the BIOS password and login parameters and an external server, so that the remote pre-configuration device for the BIOS password and login parameters can mount the image file to the external server. In this embodiment, the communication unit may specifically include, but is not limited to, a remote communication unit based on wireless communication technology or wired communication technology.
[0099] A keyboard, which is used to obtain various parameter data or instructions input by the user by pressing the key caps in real time.
[0100] A display for real-time display of relevant information for running the short-circuit location process of the server power supply line.
[0101] A mouse that can be used to assist users in inputting data and simplify user operations.
[0102] Example 4:
[0103] This embodiment also discloses a readable storage medium. The readable storage medium mentioned here includes random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, removable hard disks, CD-ROMs, or any other form of storage medium well-known in the technical field. A remote pre-configuration program for BIOS passwords and login parameters is stored in the readable storage medium. When the remote pre-configuration program for BIOS passwords and login parameters is executed by a processor, the following steps are implemented:
[0104] 1. The BMC and the BIOS encrypt the password using the same dual SHA256 encryption algorithm.
[0105] 2. The BMC and the BIOS synchronize the BIOS password and login parameters through a newly added process using a synchronization structure.
[0106] 3. When the server is powered on for the first time, the BIOS writes the initial values of the password and login parameters into the EEPROM through IPMI commands, communicates with the BMC, initializes the content of the synchronization structure, and stores the content of the synchronization structure in a buffer.
[0107] 4. Simulate logging in to the BIOS through BMC Redfish.
[0108] 5. Modify the BIOS login parameters through BMC Redfish.
[0109] 6. When the synchronization structure in the EEPROM has not been modified, if a parameter reading operation is performed, directly read the corresponding parameter item stored in the buffer.
[0110] In summary, the present invention simulates the phenomena when various parameters take effect through redfish, which is convenient for users to quickly verify parameters without restarting, greatly improves the convenience of user setting verification, and avoids the manpower loss caused by restarting and entering the BIOS setup to view the configuration effect after setting.
[0111] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the methods disclosed in the embodiments, since they correspond to the systems disclosed in the embodiments, the description is relatively simple. For related parts, reference can be made to the description in the method section.
[0112] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0113] In several embodiments provided by the present invention, it should be understood that the disclosed systems, systems, and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the systems or units can be in electrical, mechanical, or other forms.
[0114] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0115] In addition, the functional modules in the various embodiments of the present invention can be integrated in a processing unit, or each module can exist physically separately, or two or more modules can be integrated in a unit.
[0116] Similarly, the processing units in the various embodiments of the present invention can be integrated in a functional module, or each processing unit can exist physically, or two or more processing units can be integrated in a functional module.
[0117] The steps of the methods or algorithms described in connection with the embodiments disclosed in this specification may be implemented directly in hardware, in software modules executed by a processor, or in a combination thereof. The software modules may be disposed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium well-known in the art.
[0118] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a series of elements includes not only those elements, but also other elements not expressly listed, or elements that are inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0119] The remote pre-configuration method, system, device and readable storage medium for BIOS passwords and login parameters provided by the present invention have been introduced in detail above. Specific examples are used in this document to illustrate the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.
Claims
1. A remote pre - configuration method for BIOS passwords and login parameters, characterized in that, it includes: The BMC and the BIOS encrypt the password by using the same double SHA256 encryption algorithm; The BMC and the BIOS synchronize the BIOS password and login parameters through a newly added process using a synchronization structure; When the server is powered on for the first time, the BIOS writes the initial values of the password and login parameters into the EEPROM through IPMI commands, communicates with the BMC, initializes the content of the synchronization structure, and stores the content of the synchronization structure in the buffer; Perform a simulated login to the BIOS through BMC Redfish; Modify the BIOS login parameters through BMC Redfish; When the synchronization structure in the EEPROM has not been modified, if a parameter reading operation is performed, directly read the corresponding parameter item stored in the buffer; The synchronization structure includes: Update flag updateFlag, lock duration LockTime, password check switch pwdCheck, fixed complexity switch pwdComplex, fixed password length pwdLen, retry times RetryTimes, and ciphertext pwd; The simulated login to the BIOS through BMC Redfish includes: Perform a simulated login to the BIOS in the Postman interface through the Redfish method to query and modify relevant parameters; During the simulated login, test and verify the retry times and lock duration, and set a new password and perform login verification according to the password length limit and password rules; The modification of the BIOS login parameters through BMC Redfish includes: Modify the BIOS login parameters through BMC Redfish according to the range of the modified parameter item; After the modification is successful, the information of the synchronization structure in the EEPROM is synchronously modified, the modified parameters take effect immediately, and instant verification is supported; After verifying the modified BIOS login parameters, perform an optimized modification according to the comparison result with the expected value; The BMC saves the last finally modified BIOS login parameters as the content synchronized with the BIOS, which takes effect after the server restarts.
2. The remote pre - configuration method for BIOS passwords and login parameters according to claim 1, characterized in that, The BMC and the BIOS encrypt the password by using the same double SHA256 encryption algorithm, including: Synchronize and compare the first twelve bytes of the ciphertext obtained after encryption, and after the verification passes, the corresponding verification requester obtains the operation permission.
3. The remote pre - configuration method for BIOS passwords and login parameters according to claim 2, characterized in that, The update flag updateFlag, as the BMC update flag, has a resource quantity of 1. When the user updates the password or login parameters through the BMC, this flag bit is set to 1, indicating that the resource quantity to be taken is 1; when the BIOS reads this flag bit as 1, it synchronizes the new option value provided by the BMC, and then sets this flag bit to 0, indicating that the resource has been taken and the synchronization has been completed.
4. The remote pre - configuration method for BIOS password and login parameters according to claim 2, characterized in that: the lock duration LockTime is used to record the duration for which the user is locked after the number of times the user enters the wrong password exceeds the retry times; the password check switch pwdCheck, the fixed complexity switch pwdComplex, the fixed password length pwdLen, and the retry times RetryTimes are used to record the corresponding BIOS login parameters; the ciphertext pwd is used to record the first twelve bytes of the ciphertext generated after the BMC and the BIOS encrypt the password using the same double SHA256 encryption algorithm.
5. A remote pre - configuration system for BIOS password and login parameters, characterized in that, it includes: an encryption module, which is used for the BMC and the BIOS to encrypt the password using the same double SHA256 encryption algorithm; a synchronization module, which is used for the BMC and the BIOS to synchronize the BIOS password and login parameters by using a new process and a synchronization structure; an initialization module, which is used after the server is powered on for the first time. The BIOS writes the initial values of the password and login parameters into the EEPROM through IPMI commands, communicates with the BMC, initializes the content of the synchronization structure, and stores the content of the synchronization structure in the buffer; a simulated login module, which is used for simulating the login of the BIOS through BMC Redfish; a modification module, which is used for modifying the BIOS login parameters through BMC Redfish; a cache reading module, which is used to directly read the corresponding parameter items stored in the buffer when a parameter reading operation is performed if the synchronization structure in the EEPROM has not been modified; the synchronization structure includes: an update flag updateFlag, a lock duration LockTime, a password check switch pwdCheck, a fixed complexity switch pwdComplex, a fixed password length pwdLen, retry times RetryTimes, and a ciphertext pwd; the simulated login module is specifically used for: simulating the login of the BIOS in the Postman interface through the Redfish method, querying and modifying relevant parameters; during simulated login, testing and verifying the retry times and the lock duration, and setting a new password and performing login verification according to the password length limit and password rules; the modification module is specifically used for: modifying the BIOS login parameters through BMC Redfish according to the range of the modified parameter items; after the modification is successful, the information of the synchronization structure in the EEPROM is synchronously modified, the modified parameters take effect immediately, and instant verification is supported; after verifying the modified BIOS login parameters, optimizing and modifying according to the comparison result with the expected value; the BMC saves the last finally modified BIOS login parameters as the content synchronized with the BIOS, which takes effect after the server restarts.
6. A remote pre - configuration device for BIOS password and login parameters, characterized in that, it includes: A memory for storing a remote pre - configuration program for BIOS passwords and login parameters; A processor for implementing the steps of the remote pre - configuration method of BIOS passwords and login parameters as described in any one of claims 1 to 4 when executing the remote pre - configuration program for BIOS passwords and login parameters.
7. A readable storage medium, characterized in that: The readable storage medium stores a remote pre - configuration program for BIOS passwords and login parameters, and when the remote pre - configuration program for BIOS passwords and login parameters is executed by a processor, it implements the steps of the remote pre - configuration method of BIOS passwords and login parameters as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Method, system and medium for counting BIOS login log
CN108984377A
BIOS option remote batch setting method and device, terminal and storage medium
CN109445865A