Data secure transmission method and device, equipment, storage medium and program product
By setting different types of physical cores in the substrate management controller and calling the corresponding physical cores according to the relevant information types of the central processor for processing, the problem of low security in information transmission when BMC and CPU data interaction in the server is solved, and the security during data interaction is improved.
Patent Information
- Application Number
- CN202311668037.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-07
- Publication Date
- 2025-06-10
AI Technical Summary
When the BMC in the server interacts with the CPU, the information transmission is low security.
By obtaining the relevant information of the central processor and calling the physical core corresponding to the relevant information type in the substrate management controller, the relevant information is processed. Different physical cores are set up on the substrate management controller, which can flexibly call different physical verifications to process different types of related information in a targeted manner.
It improves the security of the relevant information of the central processor during interaction or transmission, ensuring the security of unsafe types of relevant information during data transmission or interaction.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and in particular, to a data security transmission method, apparatus, device, storage medium, and program product. Background Art
[0002] In a server, a Baseboard Management Controller (BMC) can interact with a CPU (Central Processing Unit) to obtain the configuration information, status information, and register information of the CPU, and can set the CPU status to manage various functions of the server.
[0003] Currently, the data interaction between the BMC and the CPU in a server is implemented through I2C (Inter-Integrated Circuit) as a physical link. However, this data interaction method has the problem of low information transmission security. Summary of the Invention
[0004] Based on this, it is necessary to provide a data security transmission method, apparatus, device, storage medium, and program product that can improve the security of information transmission for the above technical problems.
[0005] In a first aspect, this application provides a data security transmission method, including:
[0006] Obtain relevant information of a central processing unit;
[0007] Call a physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information.
[0008] In the above data security transmission method, by obtaining the relevant information of the central processing unit and calling the physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information. In the above method, different physical cores are provided on the baseboard management controller, and when data interaction occurs between the baseboard management controller and the central processing unit, the baseboard management controller can flexibly call different physical cores to perform targeted processing on different types of relevant information, that is, it can implement the processing of insecure types of relevant information using matching physical cores, thereby ensuring the security of insecure types of relevant information during data transmission or interaction.
[0009] In one embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core, and the calling the physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information includes:
[0010] If the type of the relevant information is a non-secure type, call the secure physical core to process the relevant information;
[0011] If the type of the relevant information is a secure type, call the non-secure physical core to process the relevant information.
[0012] In this embodiment, if the type of the relevant information is a non-secure type, call the secure physical core to process the relevant information; if the type of the relevant information is a secure type, call the non-secure physical core to process the relevant information. Therefore, when the present application performs data interaction between the baseboard management controller and the central processing unit, it can call different physical cores to perform targeted processing on different types of relevant information, that is, it can process non-secure relevant information in the secure physical core and process secure relevant information in the ordinary physical core, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0013] In one of the embodiments, the calling the secure physical core to process the relevant information includes:
[0014] Call the secure physical core to encrypt the relevant information to obtain encrypted information, and store the encrypted information in the secure area corresponding to the secure physical core.
[0015] In this embodiment, call the secure physical core to encrypt the relevant information to obtain encrypted information, and store the encrypted information in the secure area corresponding to the secure physical core. Therefore, it can encrypt and store non-secure relevant information in the secure physical core, that is, it can realize calling different physical cores to perform targeted processing on different types of relevant information, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0016] In one of the embodiments, the calling the non-secure physical core to process the relevant information includes:
[0017] Call the non-secure physical core to store the relevant information in the non-secure area corresponding to the non-secure physical core.
[0018] In this embodiment, call the non-secure physical core to store the relevant information in the non-secure area corresponding to the non-secure physical core. Therefore, it can store secure relevant information in the ordinary physical core, that is, it can realize calling different physical cores to perform targeted processing on different types of relevant information, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0019] In one of the embodiments, the method further includes:
[0020] When receiving a fetch request sent by a client, call the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client.
[0021] In this embodiment, when receiving a fetch request sent by a client, call the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client. Therefore, different physical cores can be called to transmit the relevant information requested by different types of fetch requests in a targeted manner, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0022] In one embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. The step of calling the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client includes:
[0023] If the type of the fetch request is a non-secure type, call the secure physical core and the non-secure physical core to send the relevant information requested by the fetch request to the client;
[0024] If the type of the fetch request is a secure type, call the non-secure physical core to obtain the relevant information requested by the fetch request from the corresponding non-secure area, and send the relevant information requested by the fetch request to the client.
[0025] In this embodiment, when the type of the fetch request is a non-secure type, the secure physical core and the non-secure physical core can be called to send the relevant information requested by the fetch request to the client; when the type of the fetch request is a secure type, the non-secure physical core can be called to obtain the relevant information requested by the fetch request from the corresponding non-secure area and send the relevant information requested by the fetch request to the client. Therefore, when data interaction or transmission is performed between the baseboard management controller and the central processing unit in this application, different physical cores can be called to transmit the relevant information requested by different types of fetch requests in a targeted manner, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0026] In one embodiment, the step of calling the secure physical core and the non-secure physical core to send the relevant information requested by the fetch request to the client includes:
[0027] Authenticate the client corresponding to the fetch request, and after the authentication passes, call the secure physical core to obtain the relevant information requested by the fetch request from the corresponding secure area, and send the relevant information requested by the fetch request to the non-secure physical core;
[0028] Invoke the non-secure physical core to decrypt the relevant information requested by the acquisition request, obtain the decrypted relevant information, and send the decrypted relevant information to the client.
[0029] In this embodiment, the client corresponding to the acquisition request can be authenticated, and only after the authentication is passed can the secure physical core be invoked to obtain the relevant information requested by the acquisition request from the corresponding secure area and send the relevant information requested by the acquisition request to the non-secure physical core. Therefore, if the client corresponding to the acquisition request is an attacker, the authentication cannot be passed, and thus the attacker cannot obtain the relevant information from the secure area. After that, since the relevant information stored in the secure physical core is encrypted, the non-secure physical core can be invoked to decrypt the relevant information requested by the acquisition request, obtain the decrypted relevant information, and send the decrypted relevant information to the client. Through the encryption and decryption processes, the security of the information transmission process can be further improved.
[0030] In one of the embodiments, the method further includes:
[0031] When receiving a setting request sent by the client, invoke the physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit.
[0032] In this embodiment, when receiving a setting request sent by the client, the physical core corresponding to the type of the setting request is invoked to send the setting information in the setting request to the central processing unit. Therefore, different physical cores can be invoked to transmit the setting information in different types of setting requests in a targeted manner, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0033] In a second aspect, the present application further provides a data security transmission device, including:
[0034] An acquisition module, configured to acquire relevant information of the central processing unit;
[0035] A processing module, configured to invoke the physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information.
[0036] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method in any one of the embodiments in the first aspect are implemented.
[0037] Fourthly, the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method in any one of the embodiments of the first aspect are implemented.
[0038] Fifthly, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the method in any one of the embodiments of the first aspect are implemented.
[0039] In the above data security transmission method, device, equipment, storage medium and program product, by obtaining relevant information of the central processing unit and calling the physical core corresponding to the type of the relevant information in the baseboard management controller, the relevant information is processed. In the above method, different physical cores are provided on the baseboard management controller, and when data interaction is performed between the baseboard management controller and the central processing unit, the baseboard management controller can flexibly call different physical cores to perform targeted processing on different types of relevant information, that is, it can use a matching physical core to process the relevant information of the insecure type, so as to ensure the security of the relevant information of the insecure type during data transmission or interaction. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0041] Figure 1 It is an application environment diagram of the data security transmission method in one embodiment;
[0042] Figure 2 It is a flowchart of the data security transmission method in one embodiment;
[0043] Figure 3 It is a flowchart of the calling step in one embodiment;
[0044] Figure 4 It is a flowchart of the step of obtaining relevant information in another embodiment;
[0045] Figure 5 It is a flowchart of the data security transmission method in another embodiment;
[0046] Figure 6 It is a flowchart of the step of setting relevant information in another embodiment;
[0047] Figure 7 It is a schematic flowchart of a data security transmission method in an optional embodiment;
[0048] Figure 8 It is an overall architecture diagram of a data security transmission method in an embodiment;
[0049] Figure 9 It is a structural block diagram of a data security transmission device in an embodiment;
[0050] Figure 10 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0051] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application.
[0052] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments, and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above drawings are intended to cover non-exclusive inclusion.
[0053] In the description of the embodiments of this application, technical terms such as "first" and "second" are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity, specific order or primary-secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "a plurality" is two or more, unless otherwise specifically defined.
[0054] Referring to "embodiment" herein means that a specific feature, structure or characteristic described in connection with the embodiment may be included in at least one embodiment of this application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0055] The Baseboard Management Controller (BMC) in the server can interact with the CPU (Central Processing Unit) to obtain the temperature information, configuration information, status information and register information of the CPU, and can set the CPU status to implement the management of various functions of the server.
[0056] Currently, the data interaction between the BMC and the CPU in the server is realized through I2C (Inter-Integrated Circuit) as the physical link. Exemplarily, the BMC can directly read the information of the CPU through the I2C communication protocol, and then forward the information of the CPU to the user side through the BMC. In addition, the BMC can also set the setting information sent by the user side to the server CPU. However, since the I2C communication protocol itself has no protection measures and is a plaintext communication, there are no protection measures in the process of realizing the interaction between the BMC and the CPU based on the I2C communication protocol. Therefore, if an attacker monitors the CPU information of the I2C on the BMC side, the CPU information can be maliciously intercepted. Therefore, the above data interaction method has the problem of low information transmission security. After introducing the background technology of the data security transmission method provided by the embodiments of the present application above, below, the implementation environment involved in the data security transmission method provided by the embodiments of the present application will be briefly described.
[0057] The data security transmission method provided by the embodiments of the present application can be applied to a server as shown in Figure 1 In the server shown. Among them, the baseboard management controller 11 (Baseboard Manager Controller, BMC) and the central processing unit 12 (Central Processing Unit, CPU) are both set on the server 1. The baseboard management controller 11 and the central processing unit 12 are communicatively connected. The baseboard management controller 11 includes multiple physical cores, and the baseboard management controller 11 and the central processing unit 12 perform data interaction to realize the various functions of the server 1. Among them, the server can be realized by an independent server or a server cluster composed of multiple servers.
[0058] Those skilled in the art can understand that Figure 1 the structure shown in is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the server to which the solution of the present application is applied. The specific server may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0059] In one embodiment, as shown in Figure 2 a data security transmission method is provided. Taking the method applied to the baseboard management controller in Figure 1 as an example, the method includes the following steps:
[0060] S201. Obtain relevant information of the central processing unit.
[0061] Among them, the relevant information of the central processing unit refers to the CPU information that the baseboard management controller can obtain from the central processing unit of the server. The relevant information of the central processing unit may include but is not limited to the temperature information, configuration information, status information, register information, etc. of the CPU. The temperature information refers to the current temperature information of the CPU. The configuration information may include but is not limited to the operating frequency, external frequency, multiplier frequency, etc. of the CPU. The status information may include but is not limited to whether the CPU is in a normal working state or an abnormal working state, etc. The register information refers to the relevant information of the registers included in the CPU.
[0062] In the embodiments of the present application, the baseboard management controller can obtain the relevant information of the central processing unit CPU. Exemplarily, the baseboard management controller BMC can read the relevant information of the central processing unit through the Secure I2C communication protocol. Among them, Secure I2C (Secure Inter-Integrated Circuit) is an improved I2C communication protocol that can add hardware functions such as security, reliability, and anti-misoperation on the basis of maintaining I2C standard compatibility. SecureI2C is set in the physical core of the baseboard management controller. Secure I2C can ensure that the data transmission is isolated from ordinary I2C, thereby ensuring the security of the communication between the baseboard management controller and the central processing unit. Optionally, the baseboard management controller can obtain the relevant information of the central processing unit by reading the values of the registers in the CPU; optionally, the baseboard management controller can also send an information query request to the CPU. The CPU obtains its own relevant information according to the information query request and sends the obtained relevant information to the baseboard management controller, and the baseboard management controller can receive the relevant information sent by the CPU.
[0063] S202. Invoke the physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information.
[0064] Among them, the types of relevant information include non-security types and security types. If the relevant information of the central processing unit is of a non-security type, the relevant information of the central processing unit may include, but is not limited to, data related to privacy. For example, data generated during processes such as fingerprint recognition, face recognition, password processing, data encryption, data decryption, and security authentication; if the relevant information of the central processing unit is of a security type, the relevant information of the central processing unit may include, but is not limited to, data not related to privacy. For example, data generated during processes such as the application user operating system and executing various application programs. The baseboard management controller includes multiple physical cores, and different physical cores correspond to the types of relevant information of the central processing unit. The security performance of different physical cores is different, and each physical core is used to process the relevant information of the corresponding type. The processing process may include at least one of encryption, decryption, storage, transmission, etc.
[0065] In the embodiment of the present application, a mapping relationship table or a mapping file is pre-stored in the server, which records the corresponding relationship between different types of CPU-related information and different physical cores; when the baseboard management controller needs to process the obtained relevant information, it can directly determine the physical core corresponding to the type of relevant information according to the corresponding relationship between different types of CPU-related information and different physical cores, and then call the physical core corresponding to the type of relevant information to perform at least one of encryption, decryption, storage, transmission, etc. on the relevant information. Exemplarily, after the baseboard management controller BMC obtains the relevant information of the central processing unit through Secure I2C, the baseboard management controller can determine the type of the relevant information of the central processing unit and determine the physical core corresponding to the type of relevant information according to the type of the relevant information of the central processing unit. Suppose the type of the relevant information of the central processing unit is a security type, then the baseboard management controller can determine the physical core corresponding to the type of relevant information and call the physical core corresponding to the security type in the baseboard management controller to process the obtained relevant information of the central processing unit.
[0066] It should be noted that the corresponding relationship between the above different types of CPU-related information and different physical cores can be determined in advance by the server. Specifically, the CPU-related information can be classified by type, and then the physical cores can be associated based on the types of the classified relevant information. For example, the relevant information of the security type and the relevant information of the non-security type, and if two physical cores are set in the baseboard management controller, the relevant information of the security type can be associated with one physical core, and the relevant information of the non-security type can be associated with the other physical core; optionally, the relevant information of the same type can be further refined, and the physical cores can be associated based on the types of the refined relevant information. For example, the relevant information of the security type is divided into the relevant information for identifying the security type, the relevant information for authenticating the security type, and the relevant information for encrypting the security type, and if there are three or more physical cores set in the baseboard management controller, the relevant information for identifying the security type is associated with one physical core, the relevant information for authenticating the security type is associated with another physical core, and the relevant information for encrypting the security type is associated with another physical core, that is, the relevant information for identifying the security type, the relevant information for authenticating the security type, and the relevant information for encrypting the security type are respectively associated with different physical cores.
[0067] In the above data security transmission method, by obtaining the relevant information of the central processing unit and calling the physical core corresponding to the type of the relevant information in the baseboard management controller, the relevant information is processed. In the above method, different physical cores are set on the baseboard management controller, and when data is exchanged between the baseboard management controller and the central processing unit, the baseboard management controller can flexibly call different physical cores to perform targeted processing on different types of relevant information, that is, it can use the matching physical core to process the relevant information of the insecure type, so as to ensure the security of the relevant information of the insecure type during data transmission or interaction.
[0068] In one embodiment, the baseboard management controller in any of the above embodiments may include a secure physical core and a non-secure physical core. Based on this, an implementation manner for processing relevant information is also provided, that is, "call the physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information" in S202 above, as Figure 3 shown, including:
[0069] S301. If the type of the relevant information is a non-secure type, call the secure physical core to process the relevant information.
[0070] S302. If the type of the relevant information is a secure type, call the non-secure physical core to process the relevant information.
[0071] Among them, the baseboard management controller includes a secure physical core and a non-secure physical core. That is to say, a processor TrustZone is set in the baseboard management controller. TrustZone is used to build a security framework to resist various possible attacks, thereby ensuring the security of the server. TrustZone can divide the physical core into a secure physical core (SecureCore) and a non-secure physical core (Non-secure Core, NS Core). The secure physical core and the non-secure physical core are switched through Monitor Mode, and the secure physical core and the non-secure physical core operate in a time-sliced manner.
[0072] In the embodiment of the present application, the baseboard management controller can determine the type of the relevant information of the central processing unit, and determine the physical core corresponding to the type of the relevant information according to the type of the relevant information of the central processing unit. If the type of the relevant information of the central processing unit is a non-secure type, the baseboard management controller can call the secure physical core to process the relevant information. That is to say, if the relevant information of the central processing unit is insecure CPU information, the secure physical core that can securely process data can be called to process the insecure relevant information. Optionally, the baseboard management controller can call the secure physical core to store the relevant information corresponding to the non-secure type; or, the baseboard management controller can also call the secure physical core to encrypt the relevant information corresponding to the non-secure type; or, the baseboard management controller can also call the secure physical core to encrypt and store the relevant information corresponding to the non-secure type; or, the baseboard management controller can also call the secure physical core to store and then encrypt the relevant information corresponding to the non-secure type. Of course, the embodiment of the present application does not limit the processing process of the secure physical core.
[0073] If the type of the relevant information of the central processing unit is a secure type, the baseboard management controller can call the non-secure physical core to process the relevant information. That is to say, if the relevant information of the central processing unit is secure CPU information, the ordinary non-secure physical core can be called to process the secure relevant information. Optionally, the baseboard management controller can call the non-secure physical core to store the relevant information corresponding to the secure type; or, the baseboard management controller can also call the non-secure physical core to transmit the relevant information corresponding to the secure type. Of course, the embodiment of the present application does not limit the processing process of the non-secure physical core either.
[0074] In this embodiment, if the type of the relevant information is a non-secure type, a secure physical core is called to process the relevant information; if the type of the relevant information is a secure type, a non-secure physical core is called to process the relevant information. Therefore, when data interaction is performed between the baseboard management controller and the central processing unit in this application, different physical cores can be called to perform targeted processing on different types of relevant information, that is, insecure relevant information can be processed in the secure physical core, and secure relevant information can be processed in the ordinary physical core, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0075] In one embodiment, an implementation method for calling a secure physical core to process information is provided. That is, when the baseboard management controller executes "call a secure physical core to process the relevant information" in the above S301, the specific execution steps are as follows:
[0076] Call a secure physical core to encrypt the relevant information to obtain encrypted information, and store the encrypted information in the secure area corresponding to the secure physical core.
[0077] Among them, the encrypted information is the information obtained by encrypting the relevant information of the central processing unit. The secure area corresponding to the secure physical core refers to the secure area Secure World in the processor Trustzone. The processor Trustzone includes the secure area Secure World and the non-secure area Normal World. The secure area Secure World corresponds to the secure physical core, and the non-secure area Normal World corresponds to the non-secure physical core. Trust OS refers to the operating system running on the processor Trustzone.
[0078] In the embodiment of this application, Secure I2C can be set in the secure area Secure World of the Trustzone in the baseboard management controller. Thus, the baseboard management controller can obtain the relevant information of the central processing unit through SecureI2C in the secure area Secure World. After that, if the type of the relevant information of the central processing unit obtained is a non-secure type, the baseboard management controller can call the secure physical core to encrypt the relevant information corresponding to the non-secure type using an encryption algorithm to obtain encrypted information, and store the encrypted information in the secure area Secure World corresponding to the secure physical core. Exemplarily, the encrypted information can be stored in the secure buffer Secure Buffer in the secure area Secure World. In addition, the key of the encryption algorithm can be stored in the tamper-proof secure memory in the secure area.
[0079] In this embodiment, the security physical core is called to encrypt relevant information to obtain encrypted information, and the encrypted information is stored in the secure area corresponding to the security physical core. Therefore, it is possible to encrypt and store insecure relevant information in a secure physical core, that is, it is possible to call different physical cores to perform targeted processing on different types of relevant information, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0080] In one embodiment, an implementation method for calling a non-secure physical core to process information is provided. That is, when the baseboard management controller executes "calling a non-secure physical core to process relevant information" in the above S302, the specific execution steps are as follows:
[0081] Call the non-secure physical core to store the relevant information in the non-secure area corresponding to the non-secure physical core.
[0082] In the embodiment of the present application, if the type of the relevant information of the obtained central processing unit is a secure type, the baseboard management controller can call the non-secure physical core to store the relevant information in the non-secure area Normal World corresponding to the non-secure physical core. Exemplarily, the relevant information corresponding to the secure type can be stored in the shared buffer in the secure area Secure World.
[0083] In this embodiment, the non-secure physical core is called to store the relevant information in the non-secure area corresponding to the non-secure physical core. Therefore, it is possible to store secure relevant information in a normal physical core, that is, it is possible to call different physical cores to perform targeted processing on different types of relevant information, thereby improving the security of the relevant information of the central processing unit during interaction or transmission.
[0084] In the above embodiment, an implementation method for processing relevant information is provided, that is, Figure 2 The data security transmission method of the embodiment, as Figure 4 shown, further includes:
[0085] S203. When receiving a fetch request sent by the client, call the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client.
[0086] Among them, the client can include but is not limited to various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The acquisition request refers to a request sent by the client for indicating to acquire relevant information from the central processing unit. The relevant information requested by the acquisition request refers to the relevant information carried in the acquisition request and needed to be acquired from the central processing unit.
[0087] In an embodiment of the present application, when a user needs to acquire relevant information of the central processing unit, the client corresponding to the user can send an acquisition request to the baseboard management controller, and the relevant information needed to be acquired from the central processing unit is carried in the acquisition request. Thus, when the baseboard management controller receives the acquisition request sent by the client, the baseboard management controller can determine the relevant information requested by the acquisition request and the type of the relevant information requested by the acquisition request, and then determine the physical core corresponding to the type of the acquisition request according to the type. After that, the baseboard management controller can call the physical core corresponding to the type of the acquisition request and send the relevant information requested by the acquisition request stored in the physical core to the client.
[0088] In this embodiment, when receiving the acquisition request sent by the client, the physical core corresponding to the type of the acquisition request is called to send the relevant information requested by the acquisition request to the client. Therefore, different physical cores can be called to transmit the relevant information requested by different types of acquisition requests in a targeted manner, so that the security of the relevant information of the central processing unit during interaction or transmission can be improved.
[0089] In one embodiment, the baseboard management controller in any of the above embodiments can include a secure physical core and a non-secure physical core. Based on this, an implementation manner of sending relevant information is further provided, that is, the above step "call the physical core corresponding to the type of the acquisition request to send the relevant information requested by the acquisition request to the client", as Figure 5 shown, includes:
[0090] S501. If the type of the acquisition request is a non-secure type, call the secure physical core and the non-secure physical core to send the relevant information requested by the acquisition request to the client.
[0091] In an embodiment of the present application, when the baseboard management controller receives an acquisition request sent by a client, the baseboard management controller may determine the relevant information requested by the acquisition request and the type of the relevant information requested by the acquisition request, and thus determine a physical core corresponding to the type of the acquisition request according to the type. If the type of the relevant information requested by the acquisition request is a non-secure type, that is, the type of the acquisition request is a non-secure type, the baseboard management controller may call a secure physical core and a non-secure physical core to send the relevant information requested by the acquisition request to the client. Exemplarily, the baseboard management controller may call the secure physical core to query the relevant information requested by the acquisition request, call the non-secure physical core to obtain the relevant information requested by the acquisition request from the secure physical core, and then call the non-secure physical core to send the relevant information requested by the acquisition request to the client.
[0092] S502. If the type of the acquisition request is a secure type, call the non-secure physical core to obtain the relevant information requested by the acquisition request from the corresponding non-secure area, and send the relevant information requested by the acquisition request to the client.
[0093] In an embodiment of the present application, if the type of the relevant information requested by the acquisition request is a secure type, that is, the type of the acquisition request is a secure type, the baseboard management controller may call the non-secure physical core to query the relevant information requested by the acquisition request from all the relevant information pre-stored in the non-secure area corresponding to the non-secure physical core, so as to obtain the relevant information requested by the acquisition request, and then send the relevant information requested by the acquisition request to the client. Additionally, assuming that the relevant information stored in the non-secure area is encrypted in advance when storing the relevant information, then, after the baseboard management controller obtains the encrypted relevant information requested by the acquisition request, the baseboard management controller may further decrypt the encrypted relevant information, and then send the decrypted relevant information to the client.
[0094] In this embodiment, in the case where the type of the acquisition request is a non-secure type, the secure physical core and the non-secure physical core may be called to send the relevant information requested by the acquisition request to the client; in the case where the type of the acquisition request is a secure type, the non-secure physical core may be called to obtain the relevant information requested by the acquisition request from the corresponding non-secure area, and send the relevant information requested by the acquisition request to the client. Therefore, when the present application performs data interaction or transmission between the baseboard management controller and the central processing unit, different physical cores can be called to specifically transmit the relevant information requested by different types of acquisition requests, thereby improving the security of the relevant information of the central processing unit during the interaction or transmission process.
[0095] In one embodiment, an implementation method for invoking a secure physical core and a non-secure physical core for information transmission is provided. That is, when the baseboard management controller executes "invoke the secure physical core and the non-secure physical core to send the relevant information requested by the acquisition request to the client" in the above S501, the specific execution steps are as follows:
[0096] Authenticate the client corresponding to the acquisition request. After the authentication is passed, invoke the secure physical core to obtain the relevant information requested by the acquisition request from the corresponding secure area, and send the relevant information requested by the acquisition request to the non-secure physical core. Invoke the non-secure physical core to decrypt the relevant information requested by the acquisition request to obtain the decrypted relevant information, and send the decrypted relevant information to the client.
[0097] In the embodiment of the present application, if the type of the acquisition request is a non-secure type, the baseboard management controller can authenticate the client corresponding to the acquisition request and authorize the client corresponding to the acquisition request that has passed the authentication. That is to say, after the baseboard management controller passes the authentication, the baseboard management controller can invoke the secure physical core to query the relevant information requested by the acquisition request from all the relevant information prestored in the secure area corresponding to the secure physical core to obtain the relevant information requested by the acquisition request, and send the relevant information requested by the acquisition request to the non-secure physical core through Monitor Mode (monitor mode). Then, the baseboard management controller can invoke the non-secure physical core to receive the relevant information requested by the acquisition request sent by the secure physical core. Since the relevant information stored in the secure physical core is all encrypted relevant information (i.e., the above-mentioned encrypted information), the baseboard management controller needs to decrypt the relevant information requested by the acquisition request to obtain the decrypted relevant information, and send the decrypted relevant information to the client.
[0098] In this embodiment, the client corresponding to the acquisition request can be authenticated, and only after the authentication is passed can the secure physical core be invoked to obtain the relevant information requested by the acquisition request from the corresponding secure area and send the relevant information requested by the acquisition request to the non-secure physical core. Therefore, if the client corresponding to the acquisition request is an attacker, the authentication cannot be passed, so the attacker cannot obtain the relevant information from the secure area. Then, since the relevant information stored in the secure physical core is all encrypted relevant information, the non-secure physical core can be invoked to decrypt the relevant information requested by the acquisition request to obtain the decrypted relevant information, and send the decrypted relevant information to the client. Through the encryption and decryption processes, the security of the information transmission process can be further improved.
[0099] In the above embodiment, an implementation method for transmitting relevant information is provided, that is Figure 2 the data security transmission method of the embodiment, such asFigure 6 As shown, it further includes:
[0100] S204. When receiving a setting request sent by a client, call the physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit.
[0101] Wherein, the setting request refers to a request for setting the status of the central processing unit, the setting request carries setting information, and the setting information may include but is not limited to the operating condition limit, configuration parameters, etc. of the central processing unit. The baseboard management controller includes multiple physical cores, and different physical cores correspond to different types of setting information.
[0102] In the embodiment of the present application, when a user needs to send setting information to the central processing unit in the server, the client corresponding to the user can send a setting request for the central processing unit to the baseboard management controller, and the setting request carries the setting information that needs to be set for the central processing unit. Thus, when the baseboard management controller receives the setting request sent by the client, the baseboard management controller can determine the setting information in the setting request and the type of the setting information in the setting request, and then determine the physical core corresponding to the type of the setting request according to the type. After that, the baseboard management controller can call the physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit. Among them, the specific process of calling the physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit can be understood as the reverse process of obtaining the relevant information above. Therefore, the specific implementation manner of sending the setting information can refer to the above embodiment and will not be elaborated here.
[0103] In this embodiment, when receiving a setting request sent by a client, call the physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit. Therefore, different physical cores can be called to transmit the setting information in different types of setting requests in a targeted manner, so as to improve the security of the relevant information of the central processing unit during interaction or transmission.
[0104] Combining all the above embodiments, the present application also provides a complete data security transmission method, as Figure 7 shown, the method includes:
[0105] S20. Obtain the relevant information of the central processing unit;
[0106] S21. If the type of the relevant information is a non-secure type, call the secure physical core to encrypt the relevant information to obtain encrypted information, and store the encrypted information in the secure area corresponding to the secure physical core;
[0107] S22. If the type of the relevant information is a security type, call the non-secure physical core to store the relevant information in the non-secure area corresponding to the non-secure physical core;
[0108] S23. When receiving a fetch request sent by the client, if the type of the fetch request is a non-security type, authenticate the client corresponding to the fetch request, and after successful authentication, call the secure physical core to fetch the relevant information requested by the fetch request from the corresponding secure area, and send the relevant information requested by the fetch request to the non-secure physical core;
[0109] S24. Call the non-secure physical core to decrypt the relevant information requested by the fetch request to obtain the decrypted relevant information, and send the decrypted relevant information to the client;
[0110] S25. When receiving a fetch request sent by the client, if the type of the fetch request is a security type, call the non-secure physical core to fetch the relevant information requested by the fetch request from the corresponding non-secure area, and send the relevant information requested by the fetch request to the client;
[0111] S26. When receiving a set request sent by the client, call the physical core corresponding to the type of the set request to send the setting information in the set request to the central processing unit.
[0112] The above steps are all described in the foregoing content. For detailed content, please refer to the foregoing description and will not be elaborated here.
[0113] It should be noted that as Figure 8 shown, Figure 8It is an overall architecture diagram of the data security transmission method in an embodiment. Among them, the Baseboard Manager Controller (BMC) 11 and the Central Processing Unit (CPU) 12 are both set on the server 1. The Baseboard Manager Controller 11 is communicatively connected to the Central Processing Unit 12, and data interaction between the Baseboard Manager Controller 11 and the Central Processing Unit 12 realizes various functions of the server 1. The Baseboard Manager Controller 11 includes a secure physical core and a non-secure physical core. The Baseboard Manager Controller 11 also includes a secure area SecureWorld and a non-secure area Normal World. The secure area Secure World corresponds to the secure physical core, and the non-secure area Normal World corresponds to the non-secure physical core. The Secure I2C communication protocol is set in the secure area Secure World of the processor Trustzone in the Baseboard Manager Controller. The secure physical core and the non-secure physical core are switched through MonitorMode (monitor mode). In addition, the non-secure area Normal World can also be communicatively connected to the client 13.
[0114] In the above data security transmission method, by obtaining relevant information of the central processing unit and invoking the physical core corresponding to the type of the relevant information in the baseboard management controller, the relevant information is processed. In the above method, different physical cores are set on the baseboard management controller, and when data interaction occurs between the baseboard management controller and the central processing unit, the baseboard management controller can flexibly invoke different physical cores to perform targeted processing on different types of relevant information, that is, it can use the matching physical core to process the relevant information of the insecure type, so as to ensure the security of the relevant information of the insecure type during data transmission or interaction.
[0115] The embodiment of the present application can implement the process of information interaction (including information acquisition and information setting) between the baseboard management controller BMC and the central processing unit CPU in the processor Trustzone in the baseboard management controller, and use the Secure I2C communication protocol to replace the I2C communication protocol in the related technology, which can fundamentally prevent malicious programs or attackers from monitoring important data (including privacy information) in the server CPU, thereby improving the security of the information interaction process, realizing hardware-level isolation and access control, and effectively ensuring the security of the privacy information of the server CPU. And the present application can encrypt information through the secure physical core, and perform client authentication and information decryption through the non-secure physical core, and can effectively prevent information leakage or information tampering through multiple protections.
[0116] It should be understood that although the steps in the flowcharts involved in the above embodiments are sequentially displayed according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, there is no strict order limit for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0117] Based on the same inventive concept, an embodiment of the present application further provides a data security transmission device for implementing the data security transmission method involved above. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the data security transmission device provided below can refer to the limitations on the data security transmission method in the above text, and will not be repeated here.
[0118] In an exemplary embodiment, as Figure 9 shown, a data security transmission device is provided, including: an acquisition module 90 and a processing module 91, where:
[0119] The acquisition module 90 is used to acquire relevant information of the central processing unit.
[0120] The processing module 91 is used to call the physical core corresponding to the type of relevant information in the baseboard management controller to process the relevant information.
[0121] In an exemplary embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. The above processing module 91 includes: a first call unit and a second call unit, where:
[0122] The first call unit is specifically used to, if the type of relevant information is a non-secure type, call the secure physical core to process the relevant information;
[0123] The second call unit is specifically used to, if the type of relevant information is a secure type, call the non-secure physical core to process the relevant information.
[0124] In an exemplary embodiment, the above first call unit is specifically used to call the secure physical core to encrypt the relevant information to obtain encrypted information, and store the encrypted information in the secure area corresponding to the secure physical core.
[0125] In an exemplary embodiment, the above-mentioned second calling unit is specifically configured to call a non-secure physical core to store relevant information in a non-secure area corresponding to the non-secure physical core.
[0126] In an exemplary embodiment, the above-mentioned data security transmission device further includes: a calling module, where:
[0127] The calling module is configured to, when receiving an acquisition request sent by a client, call a physical core corresponding to the type of the acquisition request to send the relevant information requested by the acquisition request to the client.
[0128] In an exemplary embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. The above-mentioned calling module includes: a third calling unit and a fourth calling unit, where:
[0129] The third calling unit is specifically configured to, if the type of the acquisition request is a non-secure type, call the secure physical core and the non-secure physical core to send the relevant information requested by the acquisition request to the client;
[0130] The fourth calling unit is specifically configured to, if the type of the acquisition request is a secure type, call the non-secure physical core to obtain the relevant information requested by the acquisition request from the corresponding non-secure area, and send the relevant information requested by the acquisition request to the client.
[0131] In an exemplary embodiment, the above-mentioned third calling unit includes:
[0132] The first sending subunit is specifically configured to authenticate the client corresponding to the acquisition request, and after the authentication is passed, call the secure physical core to obtain the relevant information requested by the acquisition request from the corresponding secure area, and send the relevant information requested by the acquisition request to the non-secure physical core;
[0133] The second sending subunit is specifically configured to call the non-secure physical core to decrypt the relevant information requested by the acquisition request to obtain the decrypted relevant information, and send the decrypted relevant information to the client.
[0134] In an exemplary embodiment, the above-mentioned data security transmission device further includes: a setting information sending module, where:
[0135] The setting information sending module is configured to, when receiving a setting request sent by a client, call a physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit.
[0136] Each module in the above data security transmission device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0137] In an exemplary embodiment, a computer device is provided. The computer device can be a terminal or a server, and its internal structure diagram can be as Figure 10 shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a data security transmission method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covered on the display screen, or a button, a trackball, or a touchpad set on the computer device housing, or an external keyboard, touchpad, or mouse, etc.
[0138] Those skilled in the art can understand that Figure 10 the structure shown in
[0139] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0139] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0140] Obtain relevant information of the central processing unit;
[0141] Invoke the physical core corresponding to the type of relevant information in the baseboard management controller to process the relevant information.
[0142] In one embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. When invoking the physical core corresponding to the type of relevant information in the baseboard management controller to process the relevant information, the processor also implements the following steps when executing a computer program:
[0143] If the type of relevant information is non-secure, then invoke the secure physical core to process the relevant information;
[0144] If the type of relevant information is secure, then invoke the non-secure physical core to process the relevant information.
[0145] In one embodiment, when invoking the secure physical core to process the relevant information, the processor also implements the following steps when executing a computer program:
[0146] Invoke the secure physical core to encrypt the relevant information to obtain encrypted information, and store the encrypted information in the secure area corresponding to the secure physical core.
[0147] In one embodiment, when invoking the non-secure physical core to process the relevant information, the processor also implements the following steps when executing a computer program:
[0148] Invoke the non-secure physical core to store the relevant information in the non-secure area corresponding to the non-secure physical core.
[0149] In one embodiment, the processor also implements the following steps when executing a computer program:
[0150] When receiving a fetch request sent by a client, invoke the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client.
[0151] In one embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. When invoking the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client, the processor also implements the following steps when executing a computer program:
[0152] If the type of the fetch request is non-secure, then invoke the secure physical core and the non-secure physical core to send the relevant information requested by the fetch request to the client;
[0153] If the type of the fetch request is secure, then invoke the non-secure physical core to obtain the relevant information requested by the fetch request from the corresponding non-secure area, and send the relevant information requested by the fetch request to the client.
[0154] In one embodiment, when the processor executes a computer program, the following steps are further implemented: The secure physical core and the non-secure physical core are called to send the relevant information requested by the acquisition request to the client.
[0155] Authenticate the client corresponding to the acquisition request, and after the authentication passes, call the secure physical core to obtain the relevant information requested by the acquisition request from the corresponding secure area, and send the relevant information requested by the acquisition request to the non-secure physical core;
[0156] Call the non-secure physical core to decrypt the relevant information requested by the acquisition request to obtain the decrypted relevant information, and send the decrypted relevant information to the client.
[0157] In one embodiment, when the processor executes a computer program, the following steps are further implemented:
[0158] When receiving a setting request sent by the client, call the physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit.
[0159] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the following steps are implemented:
[0160] Obtain the relevant information of the central processing unit;
[0161] Call the physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information.
[0162] In one embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. When the computer program is executed by the processor and calls the physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information, the following steps are further implemented:
[0163] If the type of the relevant information is non-secure, call the secure physical core to process the relevant information;
[0164] If the type of the relevant information is secure, call the non-secure physical core to process the relevant information.
[0165] In one embodiment, when the computer program is executed by the processor and calls the secure physical core to process the relevant information, the following steps are further implemented:
[0166] Call the secure physical core to encrypt the relevant information to obtain encrypted information, and store the encrypted information in the secure area corresponding to the secure physical core.
[0167] In one embodiment, when the computer program is executed by the processor and calls the non-secure physical core to process the relevant information, the following steps are further implemented:
[0168] Call the non-secure physical core to store the relevant information in the non-secure area corresponding to the non-secure physical core.
[0169] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0170] When receiving a fetch request sent by a client, call the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client.
[0171] In one embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. When calling the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client, when the computer program is executed by a processor, the following steps are further implemented:
[0172] If the type of the fetch request is a non-secure type, call the secure physical core and the non-secure physical core to send the relevant information requested by the fetch request to the client;
[0173] If the type of the fetch request is a secure type, call the non-secure physical core to obtain the relevant information requested by the fetch request from the corresponding non-secure area, and send the relevant information requested by the fetch request to the client.
[0174] In one embodiment, when calling the secure physical core and the non-secure physical core to send the relevant information requested by the fetch request to the client, when the computer program is executed by a processor, the following steps are further implemented:
[0175] Authenticate the client corresponding to the fetch request, and after the authentication passes, call the secure physical core to obtain the relevant information requested by the fetch request from the corresponding secure area, and send the relevant information requested by the fetch request to the non-secure physical core;
[0176] Call the non-secure physical core to decrypt the relevant information requested by the fetch request to obtain the decrypted relevant information, and send the decrypted relevant information to the client.
[0177] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0178] When receiving a setting request sent by a client, call the physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit.
[0179] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0180] Obtain the relevant information of the central processing unit;
[0181] Call the physical core corresponding to the type of relevant information in the baseboard management controller to process the relevant information.
[0182] In one embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. When the computer program is executed by a processor, calling the physical core corresponding to the type of relevant information in the baseboard management controller to process the relevant information further implements the following steps:
[0183] If the type of the relevant information is non-secure, call the secure physical core to process the relevant information;
[0184] If the type of the relevant information is secure, call the non-secure physical core to process the relevant information.
[0185] In one embodiment, when the computer program is executed by a processor, calling the secure physical core to process the relevant information further implements the following steps:
[0186] Call the secure physical core to encrypt the relevant information to obtain encrypted information, and store the encrypted information in the secure area corresponding to the secure physical core.
[0187] In one embodiment, when the computer program is executed by a processor, calling the non-secure physical core to process the relevant information further implements the following steps:
[0188] Call the non-secure physical core to store the relevant information in the non-secure area corresponding to the non-secure physical core.
[0189] In one embodiment, when the computer program is executed by a processor, it further implements the following steps:
[0190] When receiving a fetch request sent by a client, call the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client.
[0191] In one embodiment, the baseboard management controller includes a secure physical core and a non-secure physical core. When the computer program is executed by a processor, calling the physical core corresponding to the type of the fetch request to send the relevant information requested by the fetch request to the client further implements the following steps:
[0192] If the type of the fetch request is non-secure, call the secure physical core and the non-secure physical core to send the relevant information requested by the fetch request to the client;
[0193] If the type of the fetch request is secure, call the non-secure physical core to obtain the relevant information requested by the fetch request from the corresponding non-secure area, and send the relevant information requested by the fetch request to the client.
[0194] In one embodiment, when the computer program is executed by a processor, the secure physical core and the non-secure physical core are called to send the relevant information requested by the acquisition request to the client, and the following steps are further implemented:
[0195] Authenticate the client corresponding to the acquisition request, and after successful authentication, call the secure physical core to obtain the relevant information requested by the acquisition request from the corresponding secure area, and send the relevant information requested by the acquisition request to the non-secure physical core;
[0196] Call the non-secure physical core to decrypt the relevant information requested by the acquisition request to obtain the decrypted relevant information, and send the decrypted relevant information to the client.
[0197] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0198] When a setting request sent by the client is received, call the physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit.
[0199] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0200] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0201] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A data security transmission method, characterized in that, the method includes: obtaining relevant information of a central processing unit; invoking a physical core corresponding to the type of the relevant information in a baseboard management controller to process the relevant information.
2. The method according to claim 1, characterized in that, the baseboard management controller includes a secure physical core and a non-secure physical core, and the invoking a physical core corresponding to the type of the relevant information in the baseboard management controller to process the relevant information includes: if the type of the relevant information is a non-secure type, invoking the secure physical core to process the relevant information; if the type of the relevant information is a secure type, invoking the non-secure physical core to process the relevant information.
3. The method according to claim 2, characterized in that, the invoking the secure physical core to process the relevant information includes: invoking the secure physical core to encrypt the relevant information to obtain encrypted information, and storing the encrypted information in a secure area corresponding to the secure physical core.
4. The method according to claim 2, characterized in that, the invoking the non-secure physical core to process the relevant information includes: invoking the non-secure physical core to store the relevant information in a non-secure area corresponding to the non-secure physical core.
5. The method according to claim 1, characterized in that, the method further includes: when receiving an acquisition request sent by a client, invoking a physical core corresponding to the type of the acquisition request to send the relevant information requested by the acquisition request to the client.
6. The method according to claim 5, characterized in that, the baseboard management controller includes a secure physical core and a non-secure physical core, and the invoking a physical core corresponding to the type of the acquisition request to send the relevant information requested by the acquisition request to the client includes: if the type of the acquisition request is a non-secure type, invoking the secure physical core and the non-secure physical core to send the relevant information requested by the acquisition request to the client; if the type of the acquisition request is a secure type, invoking the non-secure physical core to obtain the relevant information requested by the acquisition request from a corresponding non-secure area, and sending the relevant information requested by the acquisition request to the client.
7. The method according to claim 6, characterized in that, the invoking the secure physical core and the non-secure physical core to send the relevant information requested by the acquisition request to the client includes: authenticating the client corresponding to the acquisition request, and after the authentication is passed, invoking the secure physical core to obtain the relevant information requested by the acquisition request from a corresponding secure area, and sending the relevant information requested by the acquisition request to the non-secure physical core; invoking the non-secure physical core to decrypt the relevant information requested by the acquisition request to obtain decrypted relevant information, and sending the decrypted relevant information to the client.
8. The method according to claim 1, characterized in that, the method further includes: When receiving a setting request sent by a client, call a physical core corresponding to the type of the setting request to send the setting information in the setting request to the central processing unit.
9. A data security transmission device, characterized in that the device includes: an acquisition module, configured to acquire relevant information of a central processing unit; a processing module, configured to call a physical core corresponding to the type of the relevant information in a baseboard management controller to process the relevant information.
10. A computer device, including a memory and a processor, where the memory stores a computer program, characterized in that when the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.
11. A computer-readable storage medium, on which a computer program is stored, characterized in that when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
12. A computer program product, including a computer program, characterized in that when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.