Password management method and device of BMC system, electronic equipment and storage medium

By equiping the BMC system with TCM modules and adding logical functions to the PAM modules, the problem that the BMC system cannot flexibly limit special symbols and cannot effectively compare historical passwords in password management, and a comprehensive upgrade and security improvement of password management is achieved.

CN120105447APending Publication Date: 2025-06-06天固信息安全系统(深圳)有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510016870.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

In password management, the BMC system faces the problem of not being able to flexibly limit the use of special symbols in passwords, unable to meet the needs of specific security policies, and unable to effectively implement the comparison strategy of historical passwords.

Method used

The BMC system is equipped with a TCM module. The initial password is encrypted and stored in the database through the encryption module of the TCM module. Logical functions are added to the PAM module of the BMC system. The logic functions are used to determine whether the new password meets the complexity requirements when modifying the password, and process it by comparing the similarity between the new password and the initial password.

Benefits of technology

It has achieved significant enhancement in password management, and the encryption function of the TCM module ensures the high security of the initial password, effectively prevents the risk of data leakage, and improves the complexity and unpredictability of the password through automatic complexity judgment and historical password comparison.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105447A_ABST
    Figure CN120105447A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a password management method and device of a BMC (Baseboard Management Controller) system, electronic equipment and a storage medium, and relates to the technical field of information security, the method comprises the following steps: configuring a TCM (Trusted Cryptography Module) for the BMC system, encrypting an initial password through an encryption module of the TCM and then storing the encrypted initial password in a database, adding a logic function in a PAM module of the BMC system, the logic function is used for judging whether the new password meets the complexity requirement or not when the password is changed, obtaining the new password when the password is changed, calling the decryption module of the TCM module through the PAM module to obtain the initial password, comparing the new password with the initial password through the logic function to obtain a comparison result, and sending the comparison result to the password storage module; and when the comparison result meets the set requirement, the new password is encrypted and stored in the database. The problems that in the prior art, use of special symbols in passwords cannot be flexibly limited, the requirements of specific security policies cannot be met, and comparison policies of historical passwords cannot be effectively achieved are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a password management method, device, electronic device and storage medium for a BMC system. Background Art

[0002] As the mainstream management system of servers, BMC has developed into a key component of server management and maintenance, providing a wealth of functions. As the functions of BMC are continuously strengthened, its importance is becoming increasingly prominent, but the security issues that come with it cannot be ignored.

[0003] At present, the security management function of the mainstream open source BMC system openbmc mainly follows the password management strategy of the basic user BMC system of the Linux system. For BMC user password and login management, openbmc uses the standard Linux BMC system password management and authentication module PAM.

[0004] However, PAM's password policy has limitations. It stores the password plaintext after hashing it. After the user's password is changed, the system cannot obtain the plaintext of the historical password due to the irreversibility of the hash operation, making it impossible to implement some complex password complexity policies. For example, when changing a password, the requirement that the new password cannot have too many consecutive identical characters with the previous passwords cannot be met.

[0005] Currently, the difficulties faced by the BMC system in password management are mainly: first, it is impossible to flexibly restrict the use of special symbols in passwords and meet the needs of specific security policies; second, it is impossible to effectively implement the historical password comparison strategy and prevent users from reusing passwords with high similarity.

[0006] Therefore, there is a need for a password management method for a BMC system that can support flexible configuration of special symbols in passwords, achieve effective comparison of historical passwords, and improve the security of the BMC system. Summary of the invention

[0007] The embodiments of the present invention provide a password management method for a BMC system to solve the problems that the prior art cannot flexibly limit the use of special symbols in passwords, cannot meet the requirements of specific security policies, and cannot effectively implement the comparison strategy of historical passwords. The technical solution is as follows:

[0008] According to one aspect of the present invention, a password management method for a BMC system includes: equipping the BMC system with a TCM module, encrypting an initial password through an encryption module of the TCM module and storing the encrypted password in a database; adding a logic function in a PAM module of the BMC system; the logic function is used to determine whether a new password meets complexity requirements when modifying a password; obtaining a new password when modifying a password, and obtaining the initial password by calling a decryption module of the TCM module through the PAM module; comparing the new password with the initial password through the logic function to obtain a comparison result, and encrypting the new password and storing it in the database when the comparison result meets the set requirements.

[0009] In one embodiment, the database is a sqlite3 database.

[0010] In one of the embodiments, the logic function is used to judge a regular expression.

[0011] In one of the embodiments, the new password is compared with the initial password through the logic function to obtain a comparison result, which is achieved by the following steps: if the comparison result does not meet the set requirements, the request to change the password is rejected; if the comparison result meets the set requirements, the encryption module of the TCM module is used to encrypt the new password and store it in the database.

[0012] In one embodiment, the new password is compared with the initial password through the logic function to obtain a comparison result by the following steps: the new password and the initial password are matched by the logic function to obtain similarity, if the similarity exceeds a set value, the comparison result is that it does not meet the set requirements; if the number of consecutive identical characters between the new password and the initial password exceeds a set value, the comparison result is that it does not meet the set requirements.

[0013] In one of the embodiments, the new password is encrypted and stored in the database through the following steps: if the user records corresponding to the new password exceed the set value, the earliest record of the user is deleted and a new record is added; the fields of the database include a primary key id, a user name, and data in binary format.

[0014] In one of the embodiments, the BMC system and the TCM module are connected via an SPI interface.

[0015] According to one aspect of the present invention, a password management device for a BMC system includes: a password encryption module, used to equip the BMC system with a TCM module, and encrypt an initial password through the encryption module of the TCM module and store it in a database; a logic function configuration module, used to add a logic function in the PAM module of the BMC system; the logic function is used to determine whether the new password meets the complexity requirement when modifying the password; a password modification module, used to obtain a new password when modifying the password, and call the decryption module of the TCM module through the PAM module to obtain the initial password; a password comparison module, used to compare the new password with the initial password through the logic function to obtain a comparison result, and when the comparison result meets the set requirement, encrypt the new password and store it in the database.

[0016] According to one aspect of the present invention, an electronic device includes at least one processor and at least one memory, wherein the memory stores computer-readable instructions; the computer-readable instructions are executed by one or more of the processors, so that the electronic device implements the password management method of a BMC system as described above.

[0017] According to one aspect of the present invention, a storage medium stores computer-readable instructions, and the computer-readable instructions are executed by one or more processors to implement the password management method of a BMC system as described above.

[0018] The beneficial effects brought by the technical solution provided by the present invention are:

[0019] In the above technical scheme, the present invention first equips the BMC system with a TCM module, encrypts the initial password through the encryption module of the TCM module and stores it in the database, adds a logic function in the PAM module of the BMC system, and the logic function is used to determine whether the new password meets the complexity requirements when modifying the password, obtain the new password when modifying the password, and call the decryption module of the TCM module through the PAM module to obtain the initial password, compare the new password with the initial password through the logic function to obtain a comparison result, and encrypt the new password when the comparison result meets the set requirements and store it in the database, thereby significantly enhancing the password management, and ensuring the initial password through the encryption function of the TCM module. The high security in the storage process effectively prevents the risk of data leakage. At the same time, the logic function added in the PAM module can automatically perform complexity judgment when the user changes the password to ensure that the new password complies with the established security policy. This mechanism not only improves the complexity and unpredictability of the password, but also prevents users from repeating overly simple password changes by comparing the new password with the encrypted and stored initial password. Through the collaborative work of TCM and PAM, a comprehensive upgrade of the BMC system password management is achieved, which can effectively solve the problems that the existing technology cannot flexibly limit the use of special symbols in passwords, cannot meet the needs of specific security policies, and cannot effectively implement the comparison strategy of historical passwords. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in describing the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention, and those skilled in the art can obtain other drawings based on these drawings without creative work.

[0021] Figure 1 is a flow chart of a password management method for a BMC system according to an exemplary embodiment;

[0022] Figure 2 It is a structural diagram of a password management method for a BMC system shown in an exemplary embodiment;

[0023] Figure 3 yes Figure 2 Schematic diagram of the process of a user changing a password in the corresponding embodiment;

[0024] Figure 4 yes Figure 2 Schematic diagram of the process of matching regular expressions in the corresponding embodiment;

[0025] Figure 5 is a block diagram of a password management device for a BMC system according to an exemplary embodiment;

[0026] Figure 6 is a hardware structure diagram of an electronic device according to an exemplary embodiment;

[0027] Figure 7 It is a block diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION

[0028] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be interpreted as limiting the present invention.

[0029] It will be understood by those skilled in the art that, unless expressly stated, the singular forms "one", "said", and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present disclosure refers to the presence of the features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we refer to an element as being "connected" or "coupled" to another element, it may be directly connected or coupled to the other element, or there may be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The term "and / or" used herein includes all or any unit and all combinations of one or more associated listed items.

[0030] BMC: Baseboard Management Controller, a core component of the server management system defined by the IPMI (Intelligent Platform Management Interface) protocol, is a hardware manager integrated into servers, network devices, and other computer systems. Its function is to monitor the hardware status of the device, perform remote management operations, and provide monitoring and control functions for the device.

[0031] Regular expression: Regular expression is a powerful text processing tool used to match, find, replace, or extract specific patterns in strings. It consists of common characters and special characters (metacharacters), where metacharacters have special meanings and are used to define matching rules.

[0032] The present invention provides a password management method for a BMC system. The logic function added in the PAM module automatically performs complexity judgment when the user modifies the password, ensuring that the new password complies with the established security policy. The method can effectively solve the problem that the prior art cannot flexibly limit the use of special symbols in the password, cannot meet the requirements of specific security policies, and cannot effectively implement the comparison strategy of historical passwords. The password management method for a BMC system is applicable to a password management device for a BMC system, and the password management device for a BMC system can be an electronic device. The password management method for a BMC system in an embodiment of the present invention can be applied to a variety of scenarios, such as password management of a BMC system.

[0033] See also Figure 1 An embodiment of the present invention provides a password management method for a BMC system, which is applicable to electronic devices.

[0034] In the following method embodiments, for ease of description, the execution subject of each step of the method is taken as an electronic device as an example for illustration, but this does not constitute a specific limitation.

[0035] like Figure 1 As shown, the method may include the following steps:

[0036] Step 110: equip the BMC system with a TCM module, encrypt the initial password through the encryption module of the TCM module and store it in the database.

[0037] Among them, the database is sqlite3 database.

[0038] Step 130: Add a logic function in the PAM module of the BMC system.

[0039] The logic function is used to determine whether the new password meets the complexity requirements when changing the password.

[0040] In a possible implementation, a logic function is used to judge a regular expression.

[0041] Step 150, when changing the password, obtain the new password, and call the decryption module of the TCM module through the PAM module to obtain the initial password.

[0042] Step 170, compare the new password with the initial password through a logic function to obtain a comparison result, and when the comparison result meets the set requirements, encrypt the new password and store it in the database.

[0043] In a possible implementation, if the comparison result does not meet the set requirements, the request to change the password is rejected. If the comparison result meets the set requirements, the encryption module of the TCM module is used to encrypt the new password and store it in the database.

[0044] In one possible implementation, a logic function is used to perform a similarity match between the new password and the initial password to obtain a similarity. If the similarity exceeds a set value, the comparison result is that the set requirement is not met. If the number of consecutive identical characters between the new password and the initial password exceeds a set value, the comparison result is that the set requirement is not met.

[0045] In a possible implementation, if the number of user records corresponding to the new password exceeds a set value, the earliest record of the user is deleted and a new record is added.

[0046] The fields of the database include the primary key id, user name, and data in binary format.

[0047] In a possible implementation, the BMC system and the TCM module are connected via an SPI interface.

[0048] Through the above process, the embodiment of the present invention first equips the BMC system with a TCM module, encrypts the initial password through the encryption module of the TCM module and stores it in the database, adds a logic function in the PAM module of the BMC system, the logic function is used to determine whether the new password meets the complexity requirement when modifying the password, obtain the new password when modifying the password, and call the decryption module of the TCM module through the PAM module to obtain the initial password, compare the new password with the initial password through the logic function to obtain a comparison result, and encrypt the new password when the comparison result meets the set requirements and store it in the database, thereby significantly enhancing the password management, and ensuring the initial password through the encryption function of the TCM module. The high security of the password during storage effectively prevents the risk of data leakage. At the same time, the logic function added in the PAM module can automatically perform complexity judgment when the user changes the password to ensure that the new password complies with the established security policy. This mechanism not only improves the complexity and unpredictability of the password, but also prevents users from repeating overly simple password changes by comparing the new password with the encrypted and stored initial password. Through the collaborative work of TCM and PAM, a comprehensive upgrade of the BMC system password management is achieved, which can effectively solve the problems that the existing technology cannot flexibly limit the use of special symbols in passwords, cannot meet the needs of specific security policies, and cannot effectively implement the comparison strategy of historical passwords.

[0049] In an exemplary embodiment, the present invention provides a password management method for a BMC system to perform password management for the BMC system.

[0050] The embodiment of the present invention is based on TCM security chip technology and sqlite3 database programming technology. The user's password is encrypted by the TCM chip and stored in the sqlite3 database. When the plain text of the historical password is needed for matching, the plain text of the password is decrypted by the TCM chip and then matched with the new password for similarity to achieve a certain password complexity strategy. In addition, the code of the original PAM module of Linux is modified, the configuration function of special symbols is added, and the regular expression method is used so that when the user modifies the password, the special symbols appearing in the new password must satisfy the regular expression.

[0051] Among them, PAM is responsible for the management of password complexity. When a user changes his password, the PAM module will call the TCM encryption module for encryption processing according to the current configuration, and then call the database interface to store the encrypted data in the database for subsequent password modification, such as matching the similarity between the new password and the historical password; the TCM chip is initialized by the BMC before use, and a key is generated according to the user's needs. The hardware design is connected to the BMC through the SPI interface; the database is used to store the password data after TCM encryption, and uses the embedded commonly used database sqlite3 database software.

[0052] The database uses id as the primary key, name is the user name, and the data field is in binary format, which is used to store encrypted password data. The PAM module performs database operations according to the set password policy. For example, when changing a password, it cannot have more than 3 consecutive identical characters with the last 5 passwords. At this time, the PAM module stores the encrypted password data in the table. If there are more than 5 records for the same user, the record with the smallest id for the same user will be deleted, and then a new record will be added.

[0053] Furthermore, for the design of the PAM code module, the original code is modified to add two functions, one of which is to store encrypted password data, which can be decrypted to obtain the password plain text (the original password storage of PAM is to save the hash value of the password, and the password plain text cannot be reversely calculated after saving). After the password ciphertext is saved, the next time the user changes the password, the encrypted password ciphertext is decrypted to obtain the password plain text, and then it is matched with the new password for similarity to determine whether the new password meets the complexity requirements; the other function is to add a logic function that supports regular expressions and insert it into the original code of the PAM module. When the user changes the password, it determines whether the new password entered by the user meets the complexity requirements.

[0054] like Figure 2As shown, the embodiment of the present invention adds two modules to the original code of the PAM module, one regular expression judgment module is responsible for the judgment of the regular expression, and the other password encryption and decryption, access module is responsible for the encryption and decryption, access of the password and the judgment of the similarity matching between the most recently used password and the new password.

[0055] like Figure 3 As shown, when the user tries to change the password, the process starts, the user enters a new password, and the regular expression judgment module is called. The module receives the new password entered by the user and matches the new password according to the pre-configured regular expressions (these expressions define the specific requirements for special symbols in the password, such as only containing the "@" symbol). If the new password meets the requirements of the regular expression, the process continues to the next step. If the new password does not meet the requirements of the regular expression, an error message is displayed (for example, "The special symbols in the password do not meet the requirements"), and the user is allowed to re-enter the password. If the new password passes the regular expression match, the system believes that the password meets the complexity requirements in terms of special symbols. After completing the regular expression judgment, the process enters the next stage of historical password similarity matching, or continues to execute the subsequent password modification process.

[0056] The regular expression is configured in advance by the system administrator based on security requirements to define the complexity requirements for special symbols in the password. When a user changes a password, the system immediately matches it based on the regular expression to ensure that the password meets the complexity requirements.

[0057] like Figure 4 As shown, when the user tries to change the password after judging by the regular expression, the process starts, and the system retrieves the user's previous password records from the sqlite3 database (these passwords have been encrypted by TCM). According to the requirements (for example, comparing the 5 most recent passwords), the system selects the historical passwords that need to be matched for similarity, and uses the TCM module to decrypt the selected historical passwords to obtain the passwords in plain text. The system compares the new password with the decrypted historical passwords for similarity. The comparison rules can be configured according to the requirements. For example, the new password cannot have more than 3 consecutive identical characters with the 5 most recently used passwords. If the similarity between the new password and any historical password exceeds the configured limit, an error message is displayed (for example, "the new password is too similar to the previous password"), and the user is allowed to re-enter the password. If the similarity between the new password and all historical passwords is within the allowed range, the password modification process continues.

[0058] Furthermore, if the new password passes the similarity match, the system will encrypt the new password and store it in the sqlite3 database. If the stored password records exceed the preset number (for example, 5), the earliest record will be deleted to maintain the size of the database, completing the password modification process and the user password is updated successfully.

[0059] Among them, storage and retrieval of historical passwords: use sqlite3 database to store encrypted historical passwords for retrieval and decryption when needed; real-time matching: when the user changes the password, the system will immediately perform similarity matching with the historical password to ensure that the new password meets the complexity requirements; configuration flexibility: similarity matching rules can be configured according to specific needs, such as the number of similar characters in the password, the number of historical password comparisons, etc.

[0060] Through the above process, the embodiment of the present invention stores the BMC user password in the database through TCM encryption difference, so that the PAM module can obtain the old password when the user changes the password, thereby restricting the password complexity policy; by modifying the code execution logic of the PAM module, the PAM module supports password complexity restriction by means of regular expressions, which solves the problem that the PAM module cannot obtain the user's previously used password when the user changes the password, and ensures the security of the password through the encryption function of the TCM chip. At the same time, by changing the execution logic of PAM and adding some code functions, a function of matching whether the password meets the rules according to the regular expression in the configuration file is realized.

[0061] The following is an embodiment of the device of the present invention, which can be used to execute a password management method for a BMC system involved in the present invention. For details not disclosed in the embodiment of the device of the present invention, please refer to the method embodiment of the password management method for a BMC system involved in the present invention.

[0062] See also Figure 5 , an embodiment of the present invention provides a password management device 800 for a BMC system.

[0063] The device 800 includes but is not limited to: a password encryption module 810 , a logic function configuration module 830 , a password modification module 850 and a password comparison module 870 .

[0064] The password encryption module 810 is used to equip the BMC system with a TCM module, and encrypt the initial password through the encryption module of the TCM module and store it in the database.

[0065] The logic function configuration module 830 is used to add a logic function in the PAM module of the BMC system. The logic function is used to determine whether the new password meets the complexity requirement when modifying the password.

[0066] The password modification module 850 is used to obtain a new password when modifying a password, and to obtain an initial password by calling a decryption module of a TCM module through a PAM module.

[0067] The password comparison module 870 is used to compare the new password with the initial password through a logic function to obtain a comparison result. When the comparison result meets the set requirements, the new password is encrypted and stored in the database.

[0068] It should be noted that the password management of the BMC system provided in the above embodiment is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the password management device of the BMC system will be divided into different functional modules to complete all or part of the functions described above.

[0069] In addition, the password management device for a BMC system provided in the above embodiment and an embodiment of a password management method for a BMC system belong to the same concept, wherein the specific manner in which each module performs operations has been described in detail in the method embodiment and will not be repeated here.

[0070] Figure 6 The present invention schematically illustrates the structure of an electronic device according to an exemplary embodiment.

[0071] It should be noted that the electronic device is only an example adapted to the present invention and cannot be considered to provide any limitation on the scope of use of the present invention. The electronic device cannot be interpreted as requiring dependence on or having Figure 6 One or more components of exemplary electronic device 2000 are shown.

[0072] The hardware structure of the electronic device 2000 may vary greatly due to differences in configuration or performance, such as Figure 6 As shown, the electronic device 2000 includes: a power supply 210 , an interface 230 , at least one memory 250 , and at least one central processing unit (CPU) 270 .

[0073] Specifically, the power supply 210 is used to provide operating voltage for each hardware device on the electronic device 2000 .

[0074] The interface 230 includes at least one wired or wireless network interface 231 for interacting with external devices. Of course, in other examples adapted by the present invention, the interface 230 may further include at least one serial-to-parallel conversion interface 233, at least one input-output interface 235, and at least one USB interface 237, etc. Figure 6 As shown, this is not intended to be a specific limitation.

[0075] The memory 250 is a carrier for storing resources, which may be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon include an operating system 251, an application 253 and data 255, etc. The storage method may be temporary storage or permanent storage.

[0076] Among them, the operating system 251 is used to manage and control various hardware devices and application programs 253 on the electronic device 2000 to enable the central processor 270 to calculate and process the massive data 255 in the memory 250. It can be WindowsServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0077] The application program 253 is a computer-readable instruction that performs at least one specific task based on the operating system 251, and may include at least one module ( Figure 6 (not shown), each module may respectively contain computer-readable instructions for the electronic device 2000. For example, the password management device of the BMC system may be regarded as an application 253 deployed on the electronic device 2000.

[0078] The data 255 may be signal information, etc., stored in the memory 250 .

[0079] The central processor 270 may include one or more processors, and is configured to communicate with the memory 250 through at least one communication bus to read the computer-readable instructions stored in the memory 250, thereby realizing the operation and processing of the mass data 255 in the memory 250. For example, a password management method for a BMC system is completed by the central processor 270 reading a series of computer-readable instructions stored in the memory 250.

[0080] In addition, the present invention can also be implemented by hardware circuits or hardware circuits combined with software. Therefore, the implementation of the present invention is not limited to any specific hardware circuits, software, or a combination of the two.

[0081] See also Figure 7 In an embodiment of the present invention, an electronic device 4000 is provided. The electronic device 400 may include: a desktop computer, a laptop computer, a server, etc. with sensor recognition capability.

[0082] exist Figure 7 In the embodiment, the electronic device 4000 includes at least one processor 4001 and at least one memory 4003.

[0083] The data interaction between the processor 4001 and the memory 4003 can be realized through at least one communication bus 4002. The communication bus 4002 may include a path for transmitting data between the processor 4001 and the memory 4003. The communication bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. The communication bus 4002 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0084] Optionally, the electronic device 4000 may further include a transceiver 4004, which may be used for data interaction between the electronic device and other electronic devices, such as data transmission and / or data reception, etc. It should be noted that in actual applications, the transceiver 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation on the embodiments of the present invention.

[0085] Processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It may implement or execute various exemplary logic blocks, modules and circuits described in conjunction with the disclosure of the present invention. Processor 4001 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0086] The memory 4003 can be a ROM (Read Only Memory) or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory) or other types of dynamic storage devices that can store information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, optical disk storage (including compressed optical disk, laser disk, optical disk, digital versatile disk, Blu-ray disk, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program instructions or codes in the form of instructions or data structures and can be accessed by the electronic device 400, but is not limited to this.

[0087] Computer-readable instructions are stored in the memory 4003 , and the processor 4001 can read the computer-readable instructions stored in the memory 4003 through the communication bus 4002 .

[0088] The computer-readable instructions are executed by one or more processors 4001 to implement a password management method for a BMC system in the above-mentioned embodiments.

[0089] In addition, an embodiment of the present invention provides a storage medium on which computer-readable instructions are stored. The computer-readable instructions are executed by one or more processors to implement the password management method of a BMC system as described above.

[0090] A computer program product is provided in an embodiment of the present invention. The computer program product includes computer-readable instructions. The computer-readable instructions are stored in a storage medium. One or more processors of an electronic device read the computer-readable instructions from the storage medium, load and execute the computer-readable instructions, so that the electronic device implements the password management method of a BMC system as described above.

[0091] Compared with the related art, the present invention has the following beneficial effects:

[0092] 1. The present invention first equips the BMC system with a TCM module, encrypts the initial password through the encryption module of the TCM module and stores it in a database, adds a logic function in the PAM module of the BMC system, the logic function is used to determine whether the new password meets the complexity requirement when modifying the password, obtain the new password when modifying the password, and call the decryption module of the TCM module through the PAM module to obtain the initial password, compare the new password with the initial password through the logic function to obtain a comparison result, and encrypt the new password and store it in the database when the comparison result meets the set requirements, thereby significantly enhancing password management, and ensuring that the initial password is stored in the encryption function of the TCM module. The high security of the process effectively prevents the risk of data leakage. At the same time, the logic function added in the PAM module can automatically perform complexity judgment when the user changes the password to ensure that the new password complies with the established security policy. This mechanism not only improves the complexity and unpredictability of the password, but also prevents users from repeating overly simple password changes by comparing the new password with the encrypted and stored initial password. Through the collaborative work of TCM and PAM, a comprehensive upgrade of the BMC system password management is achieved, which can effectively solve the problems that the existing technology cannot flexibly limit the use of special symbols in passwords, cannot meet the needs of specific security policies, and cannot effectively implement the comparison strategy of historical passwords.

[0093] 2. The present invention can enhance password security: through the encryption function of the TCM module, a high degree of password security is achieved during storage and transmission, effectively preventing password leakage and cracking.

[0094] 3. The present invention can improve password complexity: the logic function added in the PAM module can automatically determine whether a new password meets the complexity requirements, thereby preventing users from setting overly simple passwords.

[0095] 4. The present invention can prevent password reuse: by comparing a new password with encrypted and stored historical passwords, the solution can prevent users from reusing the same password or passwords that are too similar, thereby improving the security of the system.

[0096] 5. The present invention can be flexibly configured: the solution supports matching whether the password complies with the rules through regular expressions in the configuration file, making the configuration of the password policy more flexible and convenient.

[0097] 6. The present invention can comprehensively upgrade password management: through the collaborative work of TCM and PAM, the solution realizes a comprehensive upgrade of BMC system password management and improves the overall security of the system.

[0098] It should be understood that, although the steps in the flowchart of the accompanying drawings are displayed in sequence as indicated by the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a part of the sub-steps or stages of other steps.

[0099] The above descriptions are only some embodiments of the present invention. It should be pointed out that, for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A password management method for a BMC system, characterized in that: The method comprises: The BMC system is equipped with a TCM module, and the initial password is encrypted by the encryption module of the TCM module and then stored in the database; Adding a logic function in the PAM module of the BMC system; the logic function is used to determine whether the new password meets the complexity requirement when modifying the password; When changing the password, a new password is obtained, and the decryption module of the TCM module is called by the PAM module to obtain the initial password; The new password is compared with the initial password through the logic function to obtain a comparison result. When the comparison result meets the set requirements, the new password is encrypted and stored in the database.

2. A password management method for a BMC system as claimed in claim 1, characterized in that: The database is a sqlite3 database.

3. A password management method for a BMC system as claimed in claim 1, characterized in that: The logic function is used for judging the regular expression.

4. A password management method for a BMC system as claimed in claim 1, characterized in that: The comparing the new password with the initial password by the logic function to obtain a comparison result includes: If the comparison result does not meet the set requirements, the request to modify the password is rejected. If the comparison result meets the set requirements, the encryption module of the TCM module is used to encrypt the new password and store it in the database.

5. A password management method for a BMC system as claimed in claim 1, characterized in that: The comparing the new password with the initial password by the logic function to obtain a comparison result includes: The new password and the initial password are matched by the logic function to obtain a similarity, and if the similarity exceeds a set value, the comparison result is that the new password does not meet the set requirements; If the number of consecutive identical characters between the new password and the initial password exceeds a set value, the comparison result is that the new password does not meet the set requirements.

6. A password management method for a BMC system as claimed in claim 1, characterized in that: The step of encrypting the new password and storing it in the database comprises: If the user records corresponding to the new password exceed the set value, the earliest record of the user is deleted and a new record is added; the fields of the database include the primary key id, the user name name and the data in binary format.

7. A password management method for a BMC system as claimed in claim 1, characterized in that: The BMC system and the TCM module are connected via an SPI interface.

8. A password management device for a BMC system, characterized in that: The device comprises: A password encryption module is used to equip the BMC system with a TCM module, and to encrypt the initial password through the encryption module of the TCM module and store it in the database; A logic function configuration module, used to add a logic function in the PAM module of the BMC system; the logic function is used to determine whether the new password meets the complexity requirement when modifying the password; A password modification module, used to obtain a new password when modifying a password, and to obtain the initial password by calling the decryption module of the TCM module through the PAM module; The password comparison module is used to compare the new password with the initial password through the logic function to obtain a comparison result, and when the comparison result meets the set requirements, the new password is encrypted and stored in the database.

9. An electronic device, characterized in that: include: at least one processor and at least one memory, wherein: The memory has computer-readable instructions stored thereon; The computer-readable instructions are executed by one or more of the processors, so that the electronic device implements the password management method for a BMC system according to any one of claims 1 to 7.

10. A storage medium having computer-readable instructions stored thereon, characterized in that: The computer-readable instructions are executed by one or more processors to implement a password management method for a BMC system according to any one of claims 1 to 7.