Method, device and equipment for secure communication between BIOS (Basic Input Output System) and BMC (Baseboard Management Controller) and readable storage medium

By using standard arrays between BIOS and BMC to process and store data and perform state verification, the security and efficiency problems in data transmission are solved, and the complete and secure data transmission is achieved.

CN119939640APending Publication Date: 2025-05-06ZIGUANG HENGYUE TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510436344.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

There are security and efficiency problems in data transmission between BIOS and BMC, especially when DIMM state is passed, data is prone to errors and fragmentation, resulting in insecurity and inefficiency.

Method used

The data to be sent by the BIOS are processed through the preset standard array, forming the array to be sent, and when transmitted between the BIOS and the BMC, the data is stored in another standard array with the same format, and the communication security is verified by comparing the array state.

Benefits of technology

It realizes one-time complete and secure transmission of data between BIOS and BMC, avoids data transfer errors and fragmentation problems, and improves communication security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939640A_ABST
    Figure CN119939640A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data communication security, and particularly provides a method, device and equipment for secure communication between a BIOS and a BMC and a readable storage medium, the method comprises the following steps: processing to-be-sent data of an input / output system BIOS by adopting a preset standard array to obtain a to-be-sent array, the to-be-sent data comprising function data of the BIOS; when an array to be sent is transmitted between the BIOS and a baseboard management controller (BMC), data in the array to be sent are stored in another standard array in the BMC, and the format of the standard array is the same as that of the another standard array; and the communication security between the BIOS and the BMC is verified by comparing the current array state and the previous array state of the other standard array. By means of the method, the effect of the safe communication process between the BIOS and the BMC can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data communication security, and in particular to a method, apparatus, device and readable storage medium for secure communication between a BIOS and a BMC. Background Art

[0002] During the operation of the server system, a large amount of data is transferred and communicated between the input and output system BIOS and the baseboard management controller BMC. How to make this data transfer between each other safely, stably and reliably has always been a major difficulty. When the existing BIOS and BMC data are transmitted, when the BIOS sends the storage status of the dual in-line memory module DIMM, it sends it directly to the BMC by issuing a command without processing the command style. Each DIMM sends a command, and a total of 32 commands are sent; after receiving the DIMM status, the BMC directly uses the data as display data.

[0003] However, every time the BIOS is started, this type of data must be sent to the BMC. If a DIMM is damaged, the BIOS will restart continuously, and the BMC will continue to send the same alarm, and the log will record a large number of identical records, which is very unfriendly; or the BMC side needs to perform complex algorithm processing. Multiple data transmission protocols and methods are intertwined, and data transmission is seriously fragmented. A complete piece of data content often needs to be sent to each other multiple times; this is not only inefficient, but also prone to data transmission errors and very unsafe.

[0004] Therefore, how to achieve secure communication between BIOS and BMC is a technical problem that needs to be solved. Summary of the invention

[0005] The purpose of the embodiments of the present application is to provide a method for secure communication between BIOS and BMC. The technical solution of the embodiments of the present application can achieve the effect of the secure communication process between BIOS and BMC.

[0006] In a first aspect, an embodiment of the present application provides a method for secure communication between a BIOS and a BMC, comprising: using a preset standard array to process data to be sent of an input / output system BIOS to obtain an array to be sent, wherein the data to be sent includes functional data of the BIOS; when transmitting the array to be sent between the BIOS and a baseboard management controller BMC, storing the data in the array to be sent in another standard array in the BMC, wherein the format of the standard array and the other standard array are the same; and verifying the communication security between the BIOS and the BMC by comparing the current array state and the previous array state of the other standard array. In the above embodiment of the present application, before data is transmitted between BIOS and BMC, the data to be sent can be preprocessed in the form of an array to achieve one-time transmission of data, and complete and safe transmission of data. When the data in the array to be sent is stored in another standard array with the same format, the data and status of the two arrays are matched one by one, which is convenient for subsequent security verification and analysis, and the effect of the process of secure communication between BIOS and BMC is achieved.

[0007] In some embodiments, a preset standard array is used to process the data to be sent of the input and output system BIOS to obtain the array to be sent, including: storing the data to be sent through multiple dual in-line memory modules; arranging the data to be sent of the multiple dual in-line memory modules according to position through the standard array to obtain the array to be sent.

[0008] In the above embodiments of the present application, by arranging the data to be sent according to the positions where the data to be sent are stored in multiple dual in-line memory modules, an array to be sent can be obtained, preprocessing of the data to be sent can be achieved, and one-time complete and secure sending of the data can be achieved.

[0009] In some embodiments, a preset standard array is used to process the data to be sent of the input / output system BIOS to obtain the array to be sent, including: using the standard array to process the data to be sent of the BIOS to obtain an initial array to be sent; detecting whether the current state and the previous state of the dual in-line memory module in the BIOS have changed; when it is detected that the current state and the previous state of the dual in-line memory module have changed, modifying the array state of the initial array to be sent to obtain the array to be sent.

[0010] In the above embodiments, the present application detects changes in the current state and the previous state of the dual in-line memory module, modifies the array state of the initial array to be sent, and achieves the effect of timely modification and safe sending of the dual in-line memory module array in the BIOS.

[0011] In some embodiments, detecting whether the current state and the previous state of the dual in-line memory module in the BIOS have changed includes: detecting whether the current state of the dual in-line memory module is abnormal; when detecting that the current state of the dual in-line memory module is not abnormal, detecting whether the previous state of the dual in-line memory module is abnormal; when detecting that the previous state of the dual in-line memory module is not abnormal, detecting whether the array value of the initial array to be sent is correct.

[0012] In the above embodiments of the present application, whether the array to be sent needs to be modified can be determined by respectively detecting whether the current state, the previous state and the array value of the initial array to be sent of the dual in-line memory module are correct, thereby achieving accurate transmission of the array to be sent.

[0013] In some embodiments, when it is detected that the current state and the previous state of the dual in-line memory module have changed, the array state of the initial array to be sent is modified to obtain the array to be sent, including: when it is detected that the current state of the dual in-line memory module is abnormal or the previous state of the dual in-line memory module is abnormal or the array value of the initial array to be sent is incorrect, the array state of the initial array to be sent is modified to obtain the array to be sent.

[0014] In the above embodiments of the present application, when the current state of the dual in-line memory module is abnormal, the previous state is abnormal, or the array value of the initial array to be sent is inaccurate, the array state of the array to be sent is modified in time to achieve accurate transmission of the array to be sent.

[0015] In some embodiments, storing the data in the array to be sent in another standard array in the BMC includes: storing the data in the array to be sent in another standard array according to the format correspondence between the array to be sent and the another standard array.

[0016] In the above-mentioned embodiment of the present application, the data in the array to be sent is stored according to the format correspondence between the array to be sent and another standard array, so as to achieve the unification of data format and subsequent security analysis and verification.

[0017] In some embodiments, the communication security between the BIOS and the BMC is verified by comparing the current array state and the previous array state of another standard array, including: comparing the last stored and currently stored array states and array values ​​of another standard array respectively to obtain a comparison result; and verifying the communication security between the BIOS and the BMC based on the comparison result.

[0018] In the above embodiments of the present application, by comparing the states and values ​​stored in the array before and after the transmission of the data to be sent, the communication security between the BIOS and the BMC can be accurately verified.

[0019] In a second aspect, an embodiment of the present application provides a device for secure communication between a BIOS and a BMC, including: A processing module, used for processing the data to be sent of the input and output system BIOS by using a preset standard array to obtain an array to be sent, wherein the data to be sent includes the function data of the BIOS; A storage module, used for storing data in the array to be sent in another standard array in the BMC when transmitting the array to be sent between the BIOS and the baseboard management controller BMC, wherein the format of the standard array and the other standard array is the same; The verification module is used to verify the communication security between the BIOS and the BMC by comparing the current array state and the previous array state of another standard array.

[0020] Optionally, the processing module is specifically used for: The data to be sent is stored via multiple dual in-line memory modules; The data to be sent of multiple dual in-line memory modules are arranged according to positions through a standard array to obtain an array to be sent.

[0021] Optionally, the processing module is specifically used for: The standard array is used to process the data to be sent of the BIOS to obtain the initial array to be sent; Detect whether the current state and the previous state of the dual inline memory module in the BIOS have changed; When it is detected that the current state and the previous state of the dual in-line memory module change, the array state of the initial array to be sent is modified to obtain the array to be sent.

[0022] Optionally, the processing module is specifically used for: Detect whether the current state of the dual in-line memory module is abnormal; When detecting that the current state of the dual in-line memory module is normal, detecting whether the previous state of the dual in-line memory module is abnormal; When it is detected that the last state of the dual in-line memory module is not abnormal, it is detected whether the array value of the initial array to be sent is correct.

[0023] Optionally, the processing module is specifically used for: When the current state of the dual inline memory module is detected to be abnormal, the previous state of the dual inline memory module is detected to be abnormal, or the array value of the initial array to be sent is detected to be incorrect, the array state of the initial array to be sent is modified to obtain the array to be sent.

[0024] Optionally, the storage module is specifically used for: According to the format correspondence between the array to be sent and another standard array, the data in the array to be sent is stored in the other standard array.

[0025] Optionally, the verification module is specifically used for: Compare the last stored array state and the currently stored array value of another standard array respectively to obtain a comparison result; Based on the comparison results, verify the communication security between BIOS and BMC.

[0026] In a third aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method provided in the first aspect are performed.

[0027] In a fourth aspect, an embodiment of the present application provides a readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps in the method provided in the first aspect are performed.

[0028] Other features and advantages of the present application will be described in the subsequent description, and in part will become apparent from the description, or will be understood by implementing the embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0030] Figure 1 A flowchart of a method for secure communication between BIOS and BMC provided in an embodiment of the present application; Figure 2 A schematic diagram of a communication principle between a BIOS and a BMC provided in an embodiment of the present application; Figure 3 A flowchart of a method for BMC to receive data provided in an embodiment of the present application; Figure 4 A schematic block diagram of a device for secure communication between a BIOS and a BMC provided in an embodiment of the present application; Figure 5 A schematic block diagram of the structure of a device for secure communication between BIOS and BMC provided in an embodiment of the present application. DETAILED DESCRIPTION

[0031] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application usually described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0032] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0033] First, some terms involved in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.

[0034] BIOS (Basic Input / Output System) is the first software loaded when the computer starts. It is a set of programs fixed on the motherboard ROM chip, which is responsible for initializing the hardware and guiding the operating system into working state.

[0035] BMC (Baseboard Management Controller) is a hardware management controller specifically used for servers and other computer systems. It is mainly used to monitor and manage hardware status to ensure system stability and maintainability.

[0036] ‌DIMM Status‌ refers to the working status or performance indicator of a Dual-Inline Memory Module (DIMM). DIMM is a computer memory module that is mainly used for fast data transfer.

[0037] ‌IPMItool is a command line tool for managing and monitoring devices that support the Intelligent Platform Management Interface (IPMI). ‌ IPMItool can be used in Linux systems, supports the IPMI 1.5 specification, and can perform a variety of management tasks, such as obtaining sensor information, displaying system log content, and remotely turning the machine on and off.‌

[0038] ‌Redfish data‌ refers to data about IT infrastructure obtained through the Redfish protocol. Redfish is a RESTful API standard developed by DMTF (Distributed Management Task Force), which is mainly used for intelligent management of modern IT infrastructure (such as servers, storage, and network devices), supporting hybrid IT environments and software-defined data centers.

[0039] The present application is applied to the scenario of data transmission. The specific scenario is that before data transmission is performed between BIOS and BMC, the data to be sent can be preprocessed in the form of an array to realize one-time sending of data. When the data in the array to be sent is stored in another standard array with the same format, the data and status of the two arrays are corresponded one by one to facilitate security verification.

[0040] During the operation of the server system, a large amount of data is transmitted and communicated between the input and output system BIOS and the baseboard management controller BMC. How to make this data be transmitted to each other safely, stably and reliably has always been a major difficulty. When the existing BIOS and BMC data are transmitted, when the BIOS sends the storage status of the dual in-line memory module DIMM, it is sent directly to the BMC by issuing the ‌IPMItool command without processing the command style. Each DIMM sends a command, and a total of 32 commands are sent; after receiving the DIMM status, the BMC directly uses the data as display data. However, this type of data must be sent to the BMC every time the BIOS is started. If a DIMM is damaged, the BIOS will restart continuously, and the BMC will continue to send the same alarm, and the log will record a large number of identical records, which is very unfriendly; or the BMC side needs to perform complex algorithm processing. Multiple data transmission protocols and methods are intertwined, and data transmission is seriously fragmented. A complete data content often needs to be sent to each other multiple times; this is not only inefficient, but also prone to data transmission errors, and data transmission is very unsafe.

[0041] To this end, the present application uses a preset standard array to process the data to be sent of the input and output system BIOS to obtain the array to be sent, wherein the data to be sent includes the functional data of the BIOS; when the array to be sent is transmitted between the BIOS and the baseboard management controller BMC, the data in the array to be sent is stored in another standard array in the BMC, wherein the format of the standard array and the other standard array is the same; by comparing the current array state and the previous array state of the other standard array, the communication security between the BIOS and the BMC is verified. Before data transmission between the BIOS and the BMC, the data to be sent can be preprocessed in the form of an array to achieve one-time transmission of the data, and to achieve complete and safe transmission of the data. When storing the data in the array to be sent through another standard array with the same format, the data and status of the two arrays are matched one by one, which is convenient for subsequent security verification and analysis, and the effect of the process of secure communication between the BIOS and the BMC is achieved.

[0042] In the embodiment of the present application, the execution subject can be a secure communication device between BIOS and BMC in a secure communication system between BIOS and BMC. In actual applications, the secure communication device between BIOS and BMC can be electronic devices such as terminal devices and servers, which is not limited here.

[0043] Combine the following Figure 1 The method for secure communication between the BIOS and the BMC in the embodiment of the present application is described in detail.

[0044] Please see Figure 1 , Figure 1 A flowchart of a method for secure communication between BIOS and BMC provided in an embodiment of the present application is shown in FIG. Figure 1 The method for secure communication between BIOS and BMC shown includes: Step 110: Use a preset standard array to process the data to be sent of the input / output system BIOS to obtain an array to be sent.

[0045] The data to be sent includes the functional data of the BIOS. It may also include the command, type, size, ID and DIMM status of the array to be sent in the BIOS. The functional data includes system functional data, functional data of applications in the system and running data. The standard array may be a template array with a preset format, for example, (Ipmitool raw BIOSID, array type, array size, BIOS functional ID, DIMM0ID, 0-15 DIMM status, 16-31 DIMM status). Before the BIOS sends the data to be sent of the DIMM to the BMC, it processes the data and arranges the status of the 32 DIMMs by position in an array mode. The DIMMID number only needs to record the first ID, and the subsequent ID numbers are incremented and do not need to be sent. The DIMM status is recorded using a status bit array. If a hexadecimal number is used to represent it, only two hexadecimal numbers are needed to represent the 32 DIMM statuses, and the status array is optimized into two hexadecimal numbers. In this way, one command can complete the sending of all DIMM statuses from the BIOS to the BMC, and data transmission is safe and simple. The corresponding BMC receives the array to be sent and splits it into another corresponding standard array. All DIMM states are taken from the corresponding standard array position. If the standard array state comparison value has not changed, no processing is required. If there is a change, the log is recorded. In this way, there will be no duplication or errors in alarms and logs.

[0046] Optionally, when receiving a command from BIOS to send data to be sent to BMC, after obtaining the array to be sent through preprocessing, the command is modified to a command to send the array to be sent. The array can send all the data to be sent. At the same time, another standard array in the BMC is constructed to store the data to be sent.

[0047] In some embodiments, a preset standard array is used to process the data to be sent of the input and output system BIOS to obtain the array to be sent, including: storing the data to be sent through multiple dual in-line memory modules; arranging the data to be sent of the multiple dual in-line memory modules according to position through the standard array to obtain the array to be sent.

[0048] In the above process, the present application arranges the data to be sent according to the positions where the data to be sent are stored in multiple dual in-line memory modules, so as to obtain an array to be sent, implement preprocessing of the data to be sent, and realize one-time complete and secure sending of the data.

[0049] The position may be the order or storage position of storing the BIOS function data.

[0050] In some embodiments of the present application, a preset standard array is used to process the data to be sent of the input and output system BIOS to obtain the array to be sent, including: using the standard array to process the data to be sent of the BIOS to obtain an initial array to be sent; detecting whether the current state and the previous state of the dual in-line memory module in the BIOS have changed; when it is detected that the current state and the previous state of the dual in-line memory module have changed, modifying the array state of the initial array to be sent to obtain the array to be sent.

[0051] In the above process, the present application detects changes in the current state and the previous state of the dual in-line memory module, modifies the array state of the initial array to be sent, and achieves the effect of timely modification and safe sending of the dual in-line memory module array in the BIOS.

[0052] The initial array to be sent stores the initially arranged data to be sent. Detecting whether the current state and the previous state of the dual inline memory module in the BIOS have changed includes detecting whether the current state and the previous state of each dual inline memory module in the BIOS have changed. If the state of one dual inline memory module has changed, it is considered that the current state and the previous state of the dual inline memory module have changed. The current state and the previous state can represent the start state or the operation state of the dual inline memory module in the BIOS.

[0053] In some embodiments of the present application, detecting whether the current state and the previous state of a dual in-line memory module in a BIOS have changed includes: detecting whether the current state of the dual in-line memory module is abnormal; when detecting that the current state of the dual in-line memory module is not abnormal, detecting whether the previous state of the dual in-line memory module is abnormal; when detecting that the previous state of the dual in-line memory module is not abnormal, detecting whether the array value of the initial array to be sent is correct.

[0054] In the above process, the present application can determine whether the array to be sent needs to be modified by respectively detecting whether the current state, the previous state and the array value of the initial array to be sent of the dual in-line memory module are correct, thereby achieving accurate transmission of the array to be sent.

[0055] Among them, the status abnormality judgment includes abnormal judgment of information such as BIOS version, PCIE (Extension Bus Standard) card status and information, DIMM status and information, and CPU (Central Processing Unit) status and information.

[0056] Specifically, you can Figure 2 The communication principle between the BIOS and the BMC shown explains the communication process between the BIOS and the BMC.

[0057] Please see Figure 2 , Figure 2 A schematic diagram of a communication principle between a BIOS and a BMC provided in this application, the communication principle between the BIOS and the BMC includes: The function program of BIOS generates transmission data, a first standardized processing program and different protocol transmission data; The data received by the protocol different from that of the BMC, the second standardized processing program and the function program call the corresponding data.

[0058] The function program generates the sending data as the data to be sent, including information such as BIOS version, PCIE card status and information, DIMM status and information, and CPU status and information.

[0059] The first standardization processing procedure includes processing of an information standardization array, and obtains an array to be sent by using a preset standard array to process the data to be sent of the input and output system BIOS.

[0060] The data sent by different protocols are arrays to be sent, including data sent by IPMI, shared memory, and Redflsh. They include data to be sent and DIMM status.

[0061] The data received by different protocols of BMC include data received by IPMI, shared memory and Redflsh.

[0062] The second standard processing procedure includes standard receiving array data verification, and verifies the communication security between the BIOS and the BMC by comparing the current array state and the previous array state of another standard array.

[0063] The data corresponding to the function program call includes BIOS version information display function, PCIE card position and information display function, DIMM, COU status alarm and CPU, DIMM static information display, etc. These data correspond to the information obtained after verifying the communication security between BIOS and BMC.

[0064] also, Figure 2 The specific communication principle shown can be found in Figure 1 The communication method shown will not be described in detail here.

[0065] In some embodiments of the present application, when it is detected that the current state and the previous state of the dual in-line memory module have changed, the array state of the initial array to be sent is modified to obtain the array to be sent, including: when it is detected that the current state of the dual in-line memory module is abnormal or the previous state of the dual in-line memory module is abnormal or the array value of the initial array to be sent is incorrect, the array state of the initial array to be sent is modified to obtain the array to be sent.

[0066] In the above process, when the current state of the dual in-line memory module is abnormal, the previous state is abnormal, or the array value of the initial array to be sent is inaccurate, the array state of the array to be sent is modified in time to achieve accurate transmission of the array to be sent.

[0067] Step 120: When the array to be sent is transmitted between the BIOS and the baseboard management controller BMC, the data in the array to be sent is stored in another standard array in the BMC.

[0068] Among them, the format of the standard array and the other standard array is the same.

[0069] In some embodiments of the present application, storing the data in the array to be sent in another standard array in the BMC includes: storing the data in the array to be sent in another standard array according to the format correspondence between the array to be sent and the other standard array.

[0070] In the above process, the present application stores the data in the array to be sent according to the format correspondence between the array to be sent and another standard array, so as to achieve the unification of data format and subsequent security analysis and verification.

[0071] The format correspondence may be a position correspondence or a data correspondence between the array to be sent and another standard array, and may be specifically obtained based on data position and type analysis in the standard array and another standard array.

[0072] Optionally, when transmitting the array to be sent between the BIOS and the baseboard management controller BMC, before storing the data in the array to be sent in another standard array in the BMC, a standard array needs to be constructed, which can be specifically accomplished by Figure 3 The process of the BMC receiving data is described in detail.

[0073] Please see Figure 3 , Figure 3 A flowchart of a method for BMC to receive data provided by the present application includes: Step 301: The BMC receives a DIMM status instruction sent by the BIOS.

[0074] Specifically: The BMC receives an instruction from the BIOS to send data to be sent and DIMM status.

[0075] Step 302: Whether it is the first time to construct a standard array.

[0076] Specifically: determine whether another standard array is constructed in the BIOS, if yes, proceed to step 306, otherwise proceed to step 330.

[0077] Step 303: construct a standard array corresponding to the BMC system according to the command received by the BIOS to send data to the BMC.

[0078] Specifically: construct another standard array corresponding to the standard array stored in the BIOS.

[0079] Step 304: Determine whether the DIMM status and the data to be sent have changed.

[0080] Specifically: determine whether the DIMM status and data to be sent sent by the BIOS and the DIMM status and data last received by the BMC have changed. If so, proceed to step 306. Otherwise, proceed to step 305.

[0081] Step 305: Modify the corresponding data of the standard array.

[0082] Specifically: modify the DIMM status and data received last by the BMC to the DIMM status and data currently received to form an array.

[0083] Step 306: directly construct a standard array containing DIMM status and data to be sent according to the command parameters.

[0084] Specifically: another standard array in the BMC containing the DIMM status and the data in the array to be sent is constructed according to the DIMM status sent by the BIOS and the data in the array to be sent.

[0085] Step 307: Determine the final standard array.

[0086] Specifically: the modified array or another directly constructed standard array is used as the final standard array.

[0087] also, Figure 3 The specific method shown can be found in Figure 1 The communication method shown will not be described in detail here.

[0088] Step 130: Verify the communication security between the BIOS and the BMC by comparing the current array state and the previous array state of another standard array.

[0089] In some embodiments of the present application, the communication security between the BIOS and the BMC is verified by comparing the current array state and the previous array state of another standard array, including: comparing the last stored and currently stored array states and array values ​​of another standard array respectively to obtain a comparison result; and verifying the communication security between the BIOS and the BMC based on the comparison result.

[0090] In the above process, the present application can accurately verify the communication security between the BIOS and the BMC by comparing the states and values ​​stored in the array before and after the transmission of the data to be sent.

[0091] The comparison results include the comparison results of array status and array value. When the last stored and currently stored array status of another standard array changes or the last stored and currently stored array data of another standard array changes, timely records and alarms are required to notify relevant personnel to make corrections in time, so as to realize the security verification and communication between BIOS and BMC.

[0092] In the above Figure 1 In the process shown, the present application obtains the array to be sent by processing the data to be sent of the input and output system BIOS by using a preset standard array, wherein the data to be sent includes the functional data of the BIOS; when the array to be sent is transmitted between the BIOS and the baseboard management controller BMC, the data in the array to be sent is stored in another standard array in the BMC, wherein the format of the standard array and the other standard array is the same; by comparing the current array state and the previous array state of the other standard array, the communication security between the BIOS and the BMC is verified. Before data transmission between the BIOS and the BMC, the data to be sent can be preprocessed in the form of an array to achieve one-time transmission of the data, and to achieve complete and safe transmission of the data. When storing the data in the array to be sent through another standard array with the same format, the data and status of the two arrays are matched one by one, which is convenient for subsequent security verification and analysis, and the effect of the process of secure communication between the BIOS and the BMC is achieved.

[0093] Previous article Figure 1-Figure 3 Describes the secure communication method between BIOS and BMC. Figure 4-Figure 5 Describes a mechanism for secure communication between BIOS and BMC.

[0094] Please refer to Figure 4 , is a schematic block diagram of a device 400 for secure communication between BIOS and BMC provided in an embodiment of the present application, the device 400 may be a module, program segment or code on an electronic device. Figure 1 The method embodiment corresponds to and can be executed Figure 1 The various steps involved in the method embodiment and the specific functions of the device 400 can be found in the description below. To avoid repetition, the detailed description is appropriately omitted here.

[0095] Optionally, the device 400 includes: The processing module 410 is used to process the data to be sent of the input and output system BIOS by using a preset standard array to obtain an array to be sent, wherein the data to be sent includes the function data of the BIOS; The storage module 420 is used to store the data in the array to be sent in another standard array in the BMC when the array to be sent is transmitted between the BIOS and the baseboard management controller BMC, wherein the format of the standard array and the other standard array is the same; The verification module 430 is used to verify the communication security between the BIOS and the BMC by comparing the current array state and the previous array state of another standard array.

[0096] Optionally, the processing module is specifically used for: The data to be sent are stored through multiple dual in-line memory modules; the data to be sent of the multiple dual in-line memory modules are arranged according to positions through a standard array to obtain an array to be sent.

[0097] Optionally, the processing module is specifically used for: The standard array is used to process the data to be sent of the BIOS to obtain the initial array to be sent; whether the current state and the previous state of the dual in-line memory module in the BIOS have changed; when it is detected that the current state and the previous state of the dual in-line memory module have changed, the array state of the initial array to be sent is modified to obtain the array to be sent.

[0098] Optionally, the processing module is specifically used for: Detect whether the current state of the dual in-line memory module is abnormal; when detecting that the current state of the dual in-line memory module is not abnormal, detect whether the previous state of the dual in-line memory module is abnormal; when detecting that the previous state of the dual in-line memory module is not abnormal, detect whether the array value of the initial array to be sent is correct.

[0099] Optionally, the processing module is specifically used for: When the current state of the dual inline memory module is detected to be abnormal, the previous state of the dual inline memory module is detected to be abnormal, or the array value of the initial array to be sent is detected to be incorrect, the array state of the initial array to be sent is modified to obtain the array to be sent.

[0100] Optionally, the storage module is specifically used for: According to the format correspondence between the array to be sent and another standard array, the data in the array to be sent is stored in the other standard array.

[0101] Optionally, the verification module is specifically used for: The array state and array value stored last time and currently stored in another standard array are compared respectively to obtain a comparison result; and the communication security between the BIOS and the BMC is verified according to the comparison result.

[0102] Please refer to Figure 5 The structure schematic block diagram of a device for secure communication between BIOS and BMC provided in an embodiment of the present application, the device may include a memory 510 and a processor 520. Optionally, the device may also include: a communication interface 530 and a communication bus 540. The device and the above Figure 1 The method embodiment corresponds to and can be executed Figure 1 The various steps involved in the method embodiment and the specific functions of the device can be found in the description below.

[0103] Specifically, the memory 510 is used to store computer-readable instructions.

[0104] Processor 520, configured to process readable instructions stored in the memory, capable of executing Figure 1 The steps in the method.

[0105] The communication interface 530 is used for signaling or data communication with other node devices, for example, for communication with a server or a terminal, or for communication with other device nodes, but the embodiments of the present application are not limited thereto.

[0106] The communication bus 540 is used to realize direct connection and communication among the above components.

[0107] The communication interface 530 of the device in the embodiment of the present application is used to communicate with other node devices for signaling or data. The memory 510 can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The memory 510 can also be at least one storage device located away from the aforementioned processor. The memory 510 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 520, the electronic device executes the aforementioned Figure 1The method process shown. The processor 520 can be used on the device 400 and used to perform the functions in the present application. Exemplarily, the above-mentioned processor 520 can be a general-purpose processor, a digital signal processor (Digital Signal Processor, DSP), an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, and the embodiments of the present application are not limited thereto.

[0108] The embodiment of the present application also provides a readable storage medium, when the computer program is executed by a processor, Figure 1 The method process in the method embodiment shown is executed by the electronic device.

[0109] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.

[0110] In summary, the embodiments of the present application provide a method, device, equipment and readable storage medium for secure communication between BIOS and BMC, the method comprising: using a preset standard array to process the data to be sent of the input and output system BIOS to obtain the array to be sent, wherein the data to be sent includes the functional data of the BIOS; when transmitting the array to be sent between the BIOS and the baseboard management controller BMC, the data in the array to be sent is stored in another standard array in the BMC, wherein the format of the standard array and the other standard array is the same; by comparing the current array state and the previous array state of the other standard array, the communication security between the BIOS and the BMC is verified. The effect of the process of secure communication between the BIOS and the BMC can be achieved by this method.

[0111] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0112] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0113] If the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program codes.

[0114] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.

[0115] The above description is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.

[0116] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

Claims

1. A method for secure communication between BIOS and BMC, characterized in that: include: Using a preset standard array to process the data to be sent of the input and output system BIOS to obtain an array to be sent, wherein the data to be sent includes the functional data of the BIOS; When transmitting the array to be sent between the BIOS and a baseboard management controller BMC, storing the data in the array to be sent in another standard array in the BMC, wherein the format of the standard array and the another standard array is the same; By comparing the current array state and the previous array state of the other standard array, the communication security between the BIOS and the BMC is verified.

2. The method according to claim 1, characterized in that The method of using a preset standard array to process the data to be sent of the input / output system BIOS to obtain the array to be sent includes: Storing the data to be sent through a plurality of dual in-line memory modules; The data to be sent of the plurality of dual in-line memory modules are arranged according to position through the standard array to obtain the array to be sent.

3. The method according to claim 1 or 2, characterized in that: The method of using a preset standard array to process the data to be sent of the input / output system BIOS to obtain the array to be sent includes: Processing the data to be sent of the BIOS using the standard array to obtain an initial array to be sent; Detecting whether a current state and a previous state of a dual in-line memory module in the BIOS have changed; When it is detected that the current state and the previous state of the dual in-line memory module change, the array state of the initial array to be sent is modified to obtain the array to be sent.

4. The method according to claim 3, characterized in that The detecting whether the current state and the previous state of the dual in-line memory module in the BIOS have changed includes: Detecting whether a current state of the dual in-line memory module is abnormal; When detecting that the current state of the dual in-line memory module is not abnormal, detecting whether the previous state of the dual in-line memory module is abnormal; When it is detected that the last state of the dual in-line memory module is not abnormal, it is detected whether the array value of the initial array to be sent is correct.

5. The method according to claim 4, characterized in that When detecting that the current state and the previous state of the dual in-line memory module change, modifying the array state of the initial array to be sent to obtain the array to be sent, comprises: When it is detected that the current state of the dual in-line memory module is abnormal, or the previous state of the dual in-line memory module is abnormal, or the array value of the initial array to be sent is incorrect, the array state of the initial array to be sent is modified to obtain the array to be sent.

6. The method according to claim 1 or 2, characterized in that: The step of storing the data in the array to be sent in another standard array in the BMC includes: According to the format correspondence between the array to be sent and the other standard array, the data in the array to be sent is stored in the other standard array.

7. The method according to claim 1 or 2, characterized in that: The verifying the communication security between the BIOS and the BMC by comparing the current array state and the previous array state of the other standard array includes: Compare the last stored array state and the currently stored array state and array value of the other standard array respectively to obtain a comparison result; According to the comparison result, the communication security between the BIOS and the BMC is verified.

8. A device for secure communication between BIOS and BMC, characterized in that: include: A processing module, used for processing the data to be sent of the input and output system BIOS by using a preset standard array to obtain an array to be sent, wherein the data to be sent includes the functional data of the BIOS; A storage module, used for storing the data in the array to be sent in another standard array in the BMC when the array to be sent is transmitted between the BIOS and the baseboard management controller BMC, wherein the format of the standard array and the another standard array is the same; The verification module is used to verify the communication security between the BIOS and the BMC by comparing the current array state and the previous array state of the other standard array.

9. An electronic device, characterized in that: include: A memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method according to any one of claims 1 to 7 are executed.

10. A computer-readable storage medium, characterized in that: include: A computer program, when the computer program is run on a computer, causes the computer to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Memory detection methods

    CN102280142A

  • Method and system for rapidly locating anomaly of memory banks on mainboard

    CN106055438A

  • Data transmission method, sending device and receiving device

    CN113810471A

  • Server starting method and device, equipment and storage medium

    CN114428963A

  • Data exception processing method and device, equipment and storage medium

    CN117312034A