Method and apparatus for password processing based on BIOS system

CN117235706BActive Publication Date: 2026-09-29INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311278547.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-28
Publication Date
2026-09-29
Estimated Expiration
2043-09-28

AI Technical Summary

Technical Problem

[0004]本申请实施例提供了一种基于BIOS系统的密码处理方法及装置,以至少解决相关技术中未对BIOS密码的有效时长进行检测,不能对BIOS密码进行及时的更新,不能保证服务器的信息安全的问题

Benefits of technology

[0020]根据本申请的又一个实施例,还提供了一种电子设备,包括存储器和处理器,所述存储器中存储有计算机程序,所述处理器被设置为运行所述计算机程序以执行上述任一项方法实施例中的步骤。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117235706B_ABST
    Figure CN117235706B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a BIOS system-based password processing method and device, the method comprising: in the process of starting and running the BIOS system of a server, obtaining a first account password of the BIOS system and a first time period of the first account password; in the case that the end time of the first time period is before the current time, deleting the first account password; generating a second account password according to the current time, the first time period and a second time period; sending the second account password to a target account to instruct the target account to log in to the BIOS system according to the second account password to obtain configuration information in the BIOS system. Through the present application, the problem that the effective time length of the BIOS password is not detected in the related art, the BIOS password cannot be updated in time, and the information security of the server cannot be ensured is solved, achieving the effects of ensuring the information security of the server and ensuring the normal operation of the computer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computers, and more specifically, to a password processing method and apparatus based on a BIOS system. Background Technology

[0002] In today's era of rapid technological advancements, especially in server technology, the powerful computing capabilities, reliable operational stability, and strong security of the Central Processing Unit (CPU) have placed it at the forefront of the technological field. Information security is of paramount importance to the nation. Given the security characteristics of modern server products, users have high security requirements for servers. The Basic Input / Output System (BIOS) is the fundamental software of a computer, responsible for configuring hardware. Therefore, the BIOS password becomes the first line of defense for computer security. However, current technology does not detect the validity period of the BIOS password, cannot update the BIOS password in a timely manner, and cannot guarantee the information security of the server.

[0003] No effective solutions have yet been proposed in the relevant technologies to address the aforementioned technical problems. Summary of the Invention

[0004] This application provides a password processing method and apparatus based on a BIOS system, which at least solves the problems in related technologies where the validity period of the BIOS password is not detected, the BIOS password cannot be updated in a timely manner, and the information security of the server cannot be guaranteed.

[0005] According to one embodiment of this application, a password processing method based on a BIOS system is provided, comprising: during the process of a server booting and running a BIOS system, obtaining a first account password and a first time period of the first account password, wherein the first account password is used by a target account to log in to the BIOS system to obtain configuration information in the BIOS system, and the first time period is used to represent the validity duration of the first account password; deleting the first account password if the expiration time of the first time period is before the current time; generating a second account password according to the current time, the first time period, and a second time period, wherein the second time period is used to represent the validity duration of the second account password, the current time is the start time of the second time period, and the validity duration of the second time period is determined based on the validity duration of the first time period; and sending the second account password to the target account to instruct the target account to log in to the BIOS system according to the second account password to obtain configuration information in the BIOS system.

[0006] In one exemplary embodiment, during the process of the server starting and running the BIOS system, obtaining the first account password and the first time period of the first account password of the BIOS system includes: during the process of the server starting and running the BIOS system, searching for the TSE variable set in the BIOS system in the POST interface; extracting the first account password from the TSE variable and obtaining the first time period from the memory, wherein the TSE variable and the first time period are both stored in the memory.

[0007] In an exemplary embodiment, deleting the first account password when the deadline of the first time period is before the current time includes: obtaining self-test information from the POST interface when the deadline of the first time period is before the current time, wherein the self-test information is generated during the server self-test startup process; and deleting the first account password if the self-test information has been stored.

[0008] In an exemplary embodiment, after deleting the first account password when the self-test information has been stored, the method further includes: restoring the self-test information in the POST interface and jumping to the startup interface to start the server.

[0009] In an exemplary embodiment, before generating the second account password according to the current time, the first time period, and the second time period, the method further includes: during the process of the server starting and running the BIOS system, searching for the TSE variable set in the BIOS system in the POST interface; determining whether the TSE variable is used to set the account password for logging into the BIOS system; if the TSE variable is used to set the account password for logging into the BIOS system, obtaining the first time sequence number of the first time period, wherein the first time sequence number is used to indicate the order in which the first time period is generated within a preset time period; if the first time sequence number is less than the preset time sequence number, accumulating the first time sequence number to obtain a second time sequence number; generating the second time period according to the second time sequence number and the effective duration of the first time period, wherein the effective duration of the second time period is less than or equal to the effective duration of the first time period.

[0010] In one exemplary embodiment, generating a second account password according to the current time, the first time period, and the second time period includes: generating a time key parameter using the current time, the first time period, and the second time period; obtaining character information input by the target account, wherein the character information includes the target account's account information and other characters, the other characters including at least one of the following: numbers, letters, and symbols; and generating the second account password using the character information and the time key parameter if it is determined using the target account's account information that the target account has permission to log in to the BIOS system.

[0011] In an exemplary embodiment, after generating the second account password according to the current time, the first time period, and the second time period, the method further includes: storing the second account password in a TSE variable, wherein the TSE variable is set in the BIOS system; and storing the TSE variable and the second time period in a memory.

[0012] According to another embodiment of this application, a password processing device based on a BIOS system is provided, comprising: a first acquisition module, configured to acquire a first account password and a first time period of the first account password during the process of a server booting and running a BIOS system, wherein the first account password is used for a target account to log in to the BIOS system, and the first time period is used to represent the validity duration of the first account password; a first deletion module, configured to delete the first account password if the expiration time of the first time period is before the current time; a first generation module, configured to generate a second account password according to the current time, the first time period, and a second time period, wherein the second time period is used to represent the validity duration of the second account password, the current time is the start time of the second time period, and the validity duration of the second time period is determined based on the validity duration of the first time period; and a first sending module, configured to send the second account password to the target account to instruct the target account to log in to the BIOS system according to the second account password to obtain configuration information in the BIOS system.

[0013] In one exemplary embodiment, the first acquisition module includes: a first search unit, configured to search for a TSE variable set in the BIOS system in the POST interface during the startup and operation of the BIOS system on the server; a first extraction unit, configured to extract the first account password from the TSE variable and obtain the first time period from the memory, wherein both the TSE variable and the first time period are stored in the memory; a first storage unit, configured to store the first account password into the TSE variable, wherein the TSE variable is set in the BIOS system; and a second storage unit, configured to store the TSE variable and the first time period into the memory, wherein the start time of the first time period is the time when the first account password is stored in the TSE variable, and the effective duration of the first time period is set according to the instruction of the target account.

[0014] In an exemplary embodiment, the first deletion module includes: a first acquisition unit, configured to acquire self-test information in the POST interface when the deadline of the first time period is before the current time, wherein the self-test information is generated during the server self-test startup process; and a first deletion unit, configured to delete the first account password when the self-test information has been stored.

[0015] In one exemplary embodiment, the apparatus further includes a first recovery module, configured to, after deleting the first account password in the case of stored self-test information, restore the self-test information in the POST interface and jump to the startup interface to start the server.

[0016] In an exemplary embodiment, the first generation module includes: a first generation unit, configured to generate a time key parameter using the current time, the first time period, and the second time period; a first acquisition unit, configured to acquire character information input by the target account, wherein the character information includes account information of the target account and other characters, the other characters including at least one of the following: numbers, letters, and symbols; and a second generation unit, configured to generate a second account password using the character information and the time key parameter, provided that the target account has the permission to log in to the BIOS system based on the account information of the target account.

[0017] In one exemplary embodiment, the apparatus further includes: a first lookup module, configured to look up a TSE variable set in the BIOS system in the POST interface before generating a second account password according to the current time, the first time period, and the second time period, during the process of the server starting and running the BIOS system; a first judgment module, configured to judge whether the TSE variable is used to set an account password for logging into the BIOS system; a second acquisition module, configured to acquire a first time sequence number of the first time period when the TSE variable is used to set an account password for logging into the BIOS system, wherein the first time sequence number is used to indicate the order in which the first time period is generated within a preset time period; a first accumulation module, configured to accumulate the first time sequence number to obtain a second time sequence number when the first time sequence number is less than a preset time sequence number; and a second generation module, configured to generate the second time period according to the second time sequence number and the effective duration of the first time period, wherein the effective duration of the second time period is less than or equal to the effective duration of the first time period.

[0018] In one exemplary embodiment, the apparatus further includes: a first storage module, configured to generate a second account password according to the current time, the first time period, and the second time period, and then store the second account password in a TSE variable, wherein the TSE variable is set in the BIOS system; and a second storage module, configured to store the TSE variable and the second time period in a memory.

[0019] According to yet another embodiment of this application, a computer-readable storage medium is also provided, wherein a computer program is stored therein, and the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0020] According to yet another embodiment of this application, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0021] This application addresses the issue of insufficient BIOS password validity and inability to update passwords in a timely manner during server startup. By monitoring the first account password and its expiration time in real-time during server operation, a second account password is generated based on the current time, the first time period, and the second time period. Upon entering the BIOS system, the target account accesses the configuration interface by entering the second account password to obtain configuration information. Therefore, this solution resolves the problems in related technologies where the validity period of the BIOS password is not monitored, timely updates are not possible, and server information security is compromised. This approach effectively ensures server information security and the normal operation of the computer. Attached Figure Description

[0022] Figure 1 This is a hardware structure block diagram of a mobile terminal based on a password processing method of a BIOS system according to an embodiment of this application;

[0023] Figure 2 This is a flowchart of a password processing method based on a BIOS system according to an embodiment of this application;

[0024] Figure 3 This is a flowchart of the password lifecycle detection process according to this specific embodiment;

[0025] Figure 4 This is a flowchart illustrating the process of detecting whether the account password of the BIOS system has been updated, according to this embodiment.

[0026] Figure 5 This is a structural block diagram of a password processing device based on a BIOS system according to an embodiment of this application. Detailed Implementation

[0027] The embodiments of this application will be described in detail below with reference to the accompanying drawings and examples.

[0028] First, the relevant technologies involved in this invention will be explained:

[0029] Basic Input-Output System (BIOS).

[0030] Power On Self Test (POST) interface.

[0031] Setup interface (SETUP).

[0032] Text Setup Environment (TSE)

[0033] Advanced Reduced Instruction Set Machine (ARM).

[0034] A reduced instruction set architecture central processing unit (Performance Optimization with Enhanced RISC Performance Computing, or PowerPC for short).

[0035] Scalable Processor Architecture (SPARC)

[0036] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0037] The methods and embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Taking running on a mobile terminal as an example, Figure 1 This is a hardware structure block diagram of a mobile terminal based on a BIOS system password processing method according to an embodiment of this application. Figure 1 As shown, a mobile terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the mobile terminal described above. For example, the mobile terminal may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0038] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to a password processing method based on a BIOS system in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thus implementing the aforementioned method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to a mobile terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0039] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the mobile terminal's communication provider. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0040] This embodiment provides a password processing method based on a BIOS system. Figure 2 This is a flowchart of a password processing method based on a BIOS system according to an embodiment of this application, such as... Figure 2 As shown, the process includes the following steps:

[0041] Step S202: During the process of the server starting and running the BIOS system, the first account password and the first time period of the first account password of the BIOS system are obtained. The first account password is used by the target account to log in to the BIOS system to obtain the configuration information in the BIOS system, and the first time period is used to indicate the validity period of the first account password.

[0042] Step S204: If the deadline of the first time period is before the current time, delete the password of the first account;

[0043] Step S206: Generate a second account password according to the current time, the first time period, and the second time period. The second time period is used to represent the validity period of the second account password. The current time is the start time of the second time period, and the validity period of the second time period is determined based on the validity period of the first time period.

[0044] Step S208: Send the second account password to the target account to instruct the target account to log in to the BIOS system using the second account password to obtain the configuration information in the BIOS system.

[0045] The entity performing the above steps can be a terminal, a server, a specific processor set in the terminal or server, or a processor or processing device set up relatively independently of the terminal or server, but is not limited to these.

[0046] Optionally, the server in this embodiment includes, but is not limited to, a web page server, a Hypertext Transfer Protocol (HTTP) server, and an application server.

[0047] Optionally, the server booting BIOS system process in this embodiment includes: First, performing a restart operation via command line or graphical interface. During the server boot process, a corresponding key needs to be pressed during power-on to enter the BIOS system. Different server manufacturers and models may have different key combinations. After pressing the corresponding key combination, the server will enter the BIOS interface. In the BIOS interface, the user can perform some hardware settings, boot order adjustments, and other operations.

[0048] Optionally, in this embodiment, the password formats of the first and second account passwords are automatically generated based on the password attribute type. For example, when the password attribute type is textPassword, the first account password format is a plain text password format, allowing the input of any characters, such as "568825g@780w4". The first account password must be at least eight characters long to increase the possibility of password combinations and improve the encryption strength. The first account password can be a combination of uppercase and lowercase letters, numbers, and special symbols, which increases the complexity of the password, makes it more difficult to crack, and enhances the security of server information. The second account password has the same password format as the first account password.

[0049] Optionally, this embodiment does not limit the method for setting the validity duration of the first and second time periods. Users can customize the settings flexibly, or the server can set a fixed duration. For example, the user can customize the validity duration of the first time period to 3 days and the validity duration of the second time period to 5 days. The server can set a fixed duration of one week. After determining the start time of the second account password, the end time is determined according to the set validity duration.

[0050] Through the above steps, the system monitors the first account password and its first time period in the BIOS system in real time during server startup. It checks the expiration time of the first account password; if it has expired, a second account password is generated based on the current time, the first time period, and the second time period. When entering the BIOS system, the target account enters the second account password to access the BIOS configuration interface and obtain configuration information. Therefore, this solves the problem in related technologies where the validity period of the BIOS password is not checked, the BIOS password cannot be updated in a timely manner, and server information security cannot be guaranteed, thus achieving the effect of ensuring server information security and the normal operation of the computer.

[0051] In one exemplary embodiment, during the process of the server starting and running the BIOS system, obtaining the first account password and the first time period of the first account password of the BIOS system includes: during the process of the server starting and running the BIOS system, searching for the TSE variable set in the BIOS system in the POST interface; extracting the first account password from the TSE variable and obtaining the first time period from the memory, wherein the TSE variable and the first time period are both stored in the memory.

[0052] Optionally, in this embodiment, each time the server starts up, a restart operation is first performed via command line or graphical interface. The corresponding key is pressed during startup to enter the BIOS system, then the POST interface is accessed. The POST interface sends a GET data request to the server to obtain the TSE variable. From the TSE variable code field, the encryption method of the first account password is decrypted to obtain the first account password information, including but not limited to the password value, the time period, the expiration time, and the setting time. The TSE variable and the first time period are stored in non-volatile memory for fast retrieval and to prevent data loss. This embodiment achieves the goal of real-time effective monitoring of account passwords by obtaining the first account password information each time the BIOS system is accessed.

[0053] In one exemplary embodiment, deleting the first account password when the deadline of the first time period is before the current time includes: obtaining self-test information from the POST interface when the deadline of the first time period is before the current time, wherein the self-test information is generated during the server self-test startup process; and deleting the first account password if the self-test information has been stored.

[0054] Optionally, in this embodiment, to prevent the loss of operation information before entering the BIOS system SETUP settings interface when the first account password expires, the self-test information of the POST interface is backed up to the memory. The self-test information of the POST interface includes, but is not limited to, key operations, such as the delete operation. Only after backing up the self-test information of the POST interface is the first account password stored in the TSE variable deleted. If the expired first account password information is not cleared simultaneously, non-users can log in to the BIOS system using expired passwords, easily leading to data loss. This embodiment achieves the purpose of real-time processing of expired passwords and preserving valid information by clearing expired password data.

[0055] In an exemplary embodiment, after deleting the first account password when the self-test information has been stored, the method further includes: restoring the self-test information in the POST interface and jumping to the startup interface to start the server.

[0056] Optionally, in this embodiment, the POST interface retrieves backed-up self-test information from memory via a GET data request to restore the self-test information and enter the BIOS system's boot interface. The boot interface includes, but is not limited to, the POST interface and the SETUP interface. The SETUP interface allows modification of memory and processor-related information. The POST interface, in addition to key operations, also includes server hardware information, including but not limited to memory module information, processor information, and chip information. This embodiment achieves the purpose of maintaining the security of critical server data by restricting the information displayed on the interface after the entered password is deemed compliant.

[0057] In an exemplary embodiment, before generating the second account password according to the current time, the first time period, and the second time period, the method further includes: during the process of the server starting and running the BIOS system, searching for the TSE variable set in the BIOS system in the POST interface; determining whether the TSE variable is used to set the account password for logging into the BIOS system; if the TSE variable is used to set the account password for logging into the BIOS system, obtaining the first time sequence number of the first time period, wherein the first time sequence number is used to indicate the order in which the first time period is generated within a preset time period; if the first time sequence number is less than the preset time sequence number, accumulating the first time sequence number to obtain a second time sequence number; generating the second time period according to the second time sequence number and the effective duration of the first time period, wherein the effective duration of the second time period is less than or equal to the effective duration of the first time period.

[0058] Optionally, in this embodiment, since the longer a password exists, the greater the possibility of brute-force attacks, attackers gaining general knowledge of the user, or users sharing the password being compromised, this embodiment not only sets a time period for the account password but also sets a time sequence number according to the order of the time period. For example, if the preset time period is one month, and the account password needs to be updated 4 times within this month, then the preset time sequence number is set to 4. After generating the first account password, the first time period of the first account password is set to 7 days. Since the first account password is the first account password generated within one month, the first time sequence number of the first time period is 1. After the first account password expires, a second account password needs to be generated. First, since the first time sequence number is less than 4, the second time sequence number corresponding to the second account password is 2 (the second time sequence number is obtained by adding 1 to the first time sequence number), and the second time period of the second account password is set to 5 days (the second time period is obtained by subtracting the second time sequence number 2 from the first time period of 7 days). Thus, the validity period of the second account password is determined to be 5 days. When the second account password expires, this process continues. In other words, the later the account password is generated within the preset time sequence, the shorter its time period. After the preset time sequence expires, the numbering restarts, and the above operation is repeated cyclically. This embodiment, by setting a first time sequence for the first account password and a second time sequence for the second account password, can periodically update the account passwords. Furthermore, setting a time period for the account passwords further ensures the security of configuration information in the BIOS system.

[0059] In one exemplary embodiment, generating a second account password according to the current time, the first time period, and the second time period includes: generating a time key parameter using the current time, the first time period, and the second time period; obtaining character information input by the target account, wherein the character information includes the target account's account information and other characters, the other characters including at least one of the following: numbers, letters, and symbols; and generating the second account password using the character information and the time key parameter if it is determined using the target account's account information that the target account has permission to log in to the BIOS system.

[0060] Optionally, in this embodiment, the time key parameter can be generated according to different encryption algorithms, such as symmetric encryption algorithms, asymmetric encryption algorithms, hybrid encryption algorithms, etc. The character information includes the target account's account information, such as account ID, account name, etc. The character information and the time key parameter are combined to generate a second account password, forming an irregular password string. This embodiment increases the complexity of generating the account password, thereby increasing the difficulty of cracking the account password and effectively protecting the security of configuration information in the BIOS system.

[0061] In one exemplary embodiment, after generating the second account password according to the current time, the first time period, and the second time period, the method further includes: storing the second account password in a TSE variable, wherein the TSE variable is set in the BIOS system; and storing the TSE variable and the second time period in a memory. This embodiment reduces the risk of password theft by storing the first account password in a TSE variable.

[0062] The present invention will now be described in conjunction with specific embodiments:

[0063] This specific embodiment includes the detection of password lifecycle and the process of detecting whether the password has been updated. The detection of password lifecycle includes detecting whether the account password in the BIOS system has expired, such as... Figure 3 As shown, Figure 3 The flowchart for detecting the password lifecycle according to this specific embodiment includes the following steps:

[0064] S301: Entering the POST interface during server startup;

[0065] S302: Retrieve the current time, the first account password, and the expiration time of the first account password from the POST interface;

[0066] S303: Determine if the expiration time of the first account password is less than the current time. If the expiration time of the first account password is less than the current time, proceed to S304; otherwise, proceed to S307.

[0067] S304: The BIOS system automatically updates the first account password and backs up the current POST screen content;

[0068] S305: A pop-up window prompts you to update the password for your primary account;

[0069] S306: Restore the POST interface content using the backed-up current POST screen content;

[0070] S307: Enter the SETUP settings interface;

[0071] S308: Enters the POST interface during server startup.

[0072] Optionally, checking whether the password has been updated includes checking whether the account password in the BIOS system has been updated, such as... Figure 4 As shown, Figure 4 This is a flowchart for detecting whether the account password of the BIOS system has been updated, according to this embodiment, including the following steps:

[0073] S401: Start;

[0074] S402: Check whether the current TSE variable includes the second account password. If the TSE variable includes the second account password, proceed to S403; otherwise, proceed to S407.

[0075] S403: Get the current time;

[0076] S404: Check if the password for the second account is empty;

[0077] S405: If the second account password is empty, then set the time period of the second account password to zero and store it in the memory;

[0078] S406: If the second account password is not empty, then the time period for setting the second account password is two weeks, and it is stored in the memory;

[0079] S407: End.

[0080] In summary, this embodiment, during server startup, enters the BIOS system's POST interface and checks if the current time has exceeded the time period of the first account password. If it has, the first account password is automatically updated, and the time period of the second account password is set. Before setting the second account password, the operation information of the POST interface is saved. Simultaneously, the BIOS system performs real-time checks on whether the second account password has been successfully updated. If the second account password is not successfully saved in the TSE variable, the BIOS system sets the time period of the second account password to zero. This ensures server information security and the normal operation of the computer.

[0081] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0082] This embodiment also provides a password processing device based on a BIOS system, which is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0083] Figure 5 This is a structural block diagram of a BIOS-based cryptographic processing device according to an embodiment of this application, such as... Figure 5 As shown, the device includes:

[0084] The first acquisition module 52 is used to acquire the first account password of the BIOS system and the first time period of the first account password during the process of the server starting and running the BIOS system. The first account password is used by the target account to log in to the BIOS system to obtain the configuration information in the BIOS system, and the first time period is used to indicate the validity period of the first account password.

[0085] The first deletion module 54 is used to delete the first account password when the deadline of the first time period is before the current time.

[0086] The first generation module 56 is used to generate a second account password according to the current time, the first time period and the second time period, wherein the second time period is used to represent the validity period of the second account password, the current time is the start time of the second time period, and the validity period of the second time period is determined based on the validity period of the first time period.

[0087] The first sending module 58 is used to send the second account password to the target account, so as to instruct the target account to log in to the BIOS system according to the second account password to obtain the configuration information in the BIOS system.

[0088] In one exemplary embodiment, the first acquisition module includes: a first search unit, configured to search for a TSE variable set in the BIOS system in the POST interface during the startup and operation of the BIOS system on the server; a first extraction unit, configured to extract the first account password from the TSE variable and obtain the first time period from the memory, wherein both the TSE variable and the first time period are stored in the memory; a first storage unit, configured to store the first account password into the TSE variable, wherein the TSE variable is set in the BIOS system; and a second storage unit, configured to store the TSE variable and the first time period into the memory, wherein the start time of the first time period is the time when the first account password is stored in the TSE variable, and the effective duration of the first time period is set according to the instruction of the target account.

[0089] In an exemplary embodiment, the first deletion module includes: a first acquisition unit, configured to acquire self-test information in the POST interface when the deadline of the first time period is before the current time, wherein the self-test information is generated during the server self-test startup process; and a first deletion unit, configured to delete the first account password when the self-test information has been stored.

[0090] In one exemplary embodiment, the apparatus further includes a first recovery module, configured to, after deleting the first account password in the case of stored self-test information, restore the self-test information in the POST interface and jump to the startup interface to start the server.

[0091] In an exemplary embodiment, the first generation module includes: a first generation unit, configured to generate a time key parameter using the current time, the first time period, and the second time period; a first acquisition unit, configured to acquire character information input by the target account, wherein the character information includes account information of the target account and other characters, the other characters including at least one of the following: numbers, letters, and symbols; and a second generation unit, configured to generate a second account password using the character information and the time key parameter, provided that the target account has the permission to log in to the BIOS system based on the account information of the target account.

[0092] In one exemplary embodiment, the apparatus further includes: a first lookup module, configured to look up a TSE variable set in the BIOS system in the POST interface before generating a second account password according to the current time, the first time period, and the second time period, during the process of the server starting and running the BIOS system; a first judgment module, configured to judge whether the TSE variable is used to set an account password for logging into the BIOS system; a second acquisition module, configured to acquire a first time sequence number of the first time period when the TSE variable is used to set an account password for logging into the BIOS system, wherein the first time sequence number is used to indicate the order in which the first time period is generated within a preset time period; a first accumulation module, configured to accumulate the first time sequence number to obtain a second time sequence number when the first time sequence number is less than a preset time sequence number; and a second generation module, configured to generate the second time period according to the second time sequence number and the effective duration of the first time period, wherein the effective duration of the second time period is less than or equal to the effective duration of the first time period.

[0093] In one exemplary embodiment, the apparatus further includes: a first storage module, configured to generate a second account password according to the current time, the first time period, and the second time period, and then store the second account password in a TSE variable, wherein the TSE variable is set in the BIOS system; and a second storage module, configured to store the TSE variable and the second time period in a memory.

[0094] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0095] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0096] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0097] Embodiments of this application also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0098] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0099] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.

[0100] Obviously, those skilled in the art should understand that the modules or steps of this application described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this application is not limited to any particular hardware and software combination.

[0101] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.

Claims

1. A password processing method based on a BIOS system, characterized in that, include: During the process of the server starting and running the BIOS system, the first account password of the BIOS system and the first time period of the first account password are obtained. The first account password is used by the target account to log in to the BIOS system to obtain the configuration information in the BIOS system, and the first time period is used to indicate the validity period of the first account password. If the deadline of the first time period is before the current time, delete the password of the first account; A second account password is generated according to the current time, the first time period, and the second time period, wherein the second time period is used to represent the validity period of the second account password, the current time is the start time of the second time period, and the validity period of the second time period is determined based on the validity period of the first time period; Send the second account password to the target account to instruct the target account to log in to the BIOS system using the second account password to obtain the configuration information in the BIOS system; Before generating the second account password according to the current time, the first time period, and the second time period, the method further includes: during the process of the server starting and running the BIOS system, searching for the TSE variable set in the BIOS system in the POST interface; determining whether the TSE variable is used to set the account password for logging into the BIOS system; if the TSE variable is used to set the account password for logging into the BIOS system, obtaining the first time sequence number of the first time period, wherein the first time sequence number is used to indicate the order in which the first time period is generated within a preset time period; if the first time sequence number is less than the preset time sequence number, accumulating the first time sequence number to obtain a second time sequence number; generating the second time period according to the second time sequence number and the effective duration of the first time period, wherein the effective duration of the second time period is less than or equal to the effective duration of the first time period.

2. The method according to claim 1, characterized in that, During the server startup and operation of the BIOS system, the first account password of the BIOS system and the first time period of the first account password are obtained, including: During the server startup process of the BIOS system, the TSE variable set in the BIOS system is searched in the POST interface; The first account password is extracted from the TSE variable, and the first time period is obtained from the memory, wherein both the TSE variable and the first time period are stored in the memory.

3. The method according to claim 1, characterized in that, If the deadline of the first time period is before the current time, delete the password of the first account, including: If the deadline of the first time period is before the current time, obtain the self-check information in the POST interface, wherein the self-check information is generated during the server self-check startup process; If the self-test information has already been stored, delete the password for the first account.

4. The method according to claim 3, characterized in that, If the self-test information has already been stored, after deleting the first account password, the method further includes: The self-test information is restored in the POST interface, and the user is redirected to the startup interface to start the server.

5. The method according to claim 1, characterized in that, Generate a second account password according to the current time, the first time period, and the second time period, including: Time key parameters are generated using the current time, the first time period, and the second time period; Obtain character information input from the target account, wherein the character information includes account information of the target account and other characters, and the other characters include at least one of the following: numbers, letters, and symbols; If it is determined that the target account has the permission to log in to the BIOS system using the account information of the target account, the second account password is generated using the character information and the time key parameter.

6. The method according to claim 1, characterized in that, After generating the second account password according to the current time, the first time period, and the second time period, the method further includes: The second account password is stored in a TSE variable, wherein the TSE variable is set in the BIOS system; The TSE variable and the second time period are stored in memory.

7. A cryptographic processing device based on a BIOS system, characterized in that, include: The first acquisition module is used to acquire the first account password of the BIOS system and the first time period of the first account password during the process of the server starting and running the BIOS system. The first account password is used by the target account to log in to the BIOS system to obtain the configuration information of the BIOS system, and the first time period is used to represent the validity period of the first account password. The first deletion module is used to delete the password of the first account if the deadline of the first time period is before the current time. The first generation module is used to generate a second account password according to the current time, the first time period, and the second time period, wherein the second time period is used to represent the validity period of the second account password, the current time is the start time of the second time period, and the validity period of the second time period is determined based on the validity period of the first time period; The first sending module is used to send the second account password to the target account, so as to instruct the target account to log in to the BIOS system according to the second account password to obtain the configuration information in the BIOS system; The device is further configured to, before generating the second account password according to the current time, the first time period, and the second time period, during the process of the server starting and running the BIOS system, search for the TSE variable set in the BIOS system in the POST interface; determine whether the TSE variable is used to set the account password for logging into the BIOS system; if the TSE variable is used to set the account password for logging into the BIOS system, obtain the first time sequence number of the first time period, wherein the first time sequence number is used to indicate the order in which the first time period is generated within a preset time period; if the first time sequence number is less than the preset time sequence number, accumulate the first time sequence number to obtain the second time sequence number; generate the second time period according to the second time sequence number and the effective duration of the first time period, wherein the effective duration of the second time period is less than or equal to the effective duration of the first time period.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the method according to any one of claims 1 to 6.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • BIOS startup password setting method, system and device

    CN111339525A

  • Password resetting method and device, computer system and storage medium

    CN115577343A