Multi-level security protection and auditing system based on BMC

By designing a multi-level security protection and audit system in the BMC system, the problem of the existing BMC security mechanism lacking multi-level security protection and operational audit is solved, and the BMC security and operational transparency have been significantly improved.

CN120128381APending Publication Date: 2025-06-10BEIJING TIANDI CHAOYUN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510287078.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing BMC security mechanism lacks multi-level security protection and effective operational auditing functions, and cannot effectively prevent unauthorized access and potential intrusions.

Method used

A multi-level security protection and audit system based on BMC was designed, including identity authentication module, encrypted communication module, behavior analysis and exception detection module, firmware integrity verification module and audit module. Through multi-factor identity authentication, encrypted communication, behavior analysis and firmware integrity verification, a comprehensive security protection framework is built and detailed audit functions are built-in.

Benefits of technology

It significantly improves the security and operation transparency of BMC, effectively prevents unauthorized access and system attacks, enhances abnormal behavior detection and early warning functions, and ensures timely tracking and handling of system security incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128381A_ABST
    Figure CN120128381A_ABST
Patent Text Reader

Abstract

According to the multi-level security protection and auditing system based on the BMC, through the identity authentication module, the encryption communication module, the behavior analysis and anomaly detection module, the firmware integrity verification module and the auditing module, the security and the operation transparency of the BMC in the server management process can be improved. A detailed auditing function is built in the system, all operation behaviors are recorded and analyzed, a real-time alarm and auditing report is generated, and it is ensured that system safety events can be tracked and processed in time. The system is suitable for enterprise-level server management, and is especially suitable for application scenes with high security requirements, such as the fields of finance, medical treatment, government and military.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer security technologies, and particularly to a multi-level security protection and auditing system based on BMC. Background Art

[0002] In modern data centers and enterprise environments, the remote management of servers has become an important part of ensuring the efficient and reliable operation of systems. As the hardware management controller of servers, BMC provides functions such as remote monitoring, management, and maintenance of servers. However, with the popularization of remote management, the security issues of BMC have gradually emerged. Unauthorized access or operations may cause damage to the core hardware of servers, leakage of sensitive data, or system interruption. In addition, existing BMC security mechanisms often lack sufficient security authentication and operation auditing functions, and cannot effectively prevent potential intrusions or monitor all operation behaviors. Summary of the Invention

[0003] The purpose of this application is to provide a multi-level security protection and auditing system based on BMC, so as to improve the security and operation transparency of BMC during the server management process.

[0004] In a first aspect, the present application provides a multi-level security protection and auditing system based on BMC. The system includes: an identity authentication module, an encrypted communication module, a behavior analysis and anomaly detection module, a firmware integrity verification module, and an auditing module; The identity authentication module is used to adopt a two-factor or multi-factor identity authentication mechanism, combined with traditional username and password authentication or time-based one-time password, to ensure that only users who have passed multiple verifications can access the BMC; and allocate different permissions to users based on RBAC, restrict the operation scope, and ensure that key functions can only be operated by authorized users; The encrypted communication module is used to adopt the TLS / SSL encryption protocol to ensure that the communication between the BMC and the management end is carried out through a secure encrypted channel, prevent data from being eavesdropped or tampered with during transmission, and manage the encryption key through a hardware security module to ensure the data security during the communication process; The behavior analysis and anomaly detection module is used to monitor the daily operation behaviors of users and establish a baseline of normal operations through machine learning technology; when the system detects an operation that does not conform to the baseline, it will mark it as a suspicious behavior and trigger an alarm; it is also used to monitor unusual access patterns, and unusual access patterns include: abnormally frequent login attempts, access from unexpected locations; The firmware integrity verification module is used to verify the integrity of the firmware when the BMC starts up, and ensure that the digital signature and hash value of the firmware are consistent with the expected values; once it is found that the firmware has been tampered with, the BMC startup will be blocked and a warning will be issued; The auditing module is used to record all operation information of the BMC, and the operation information includes each login, each command execution, and changes in system configuration; the operation information will be encrypted and stored, and remote backup is supported; The auditing module is also used to generate regular reports and provide a real-time alarm function, which is convenient for administrators and security auditors to conduct retrospective checks, and once suspicious behaviors or abnormal operations are detected, relevant administrators will be notified immediately.

[0005] Further, the above-mentioned identity authentication module includes: a role permission dynamic adjustment unit, a behavior anomaly verification unit, and a multi-level permission mapping module; The role permission dynamic adjustment unit is used to introduce a role permission dynamic adjustment mechanism on the basis of two-factor or multi-factor authentication. When a user logs in to the BMC through two-factor or multi-factor authentication, the operation permissions of the user are dynamically adjusted according to the authentication method and strength; The behavior anomaly verification unit is used to analyze and verify the user's behavior on the basis of the two-factor or multi-factor authentication process; the user's behavior at least includes: the user's login behavior; The multi-level permission mapping module is used to provide a permission mapping mechanism based on task stratification, and divide the permissions into three levels: global permissions, module permissions, and task permissions, to ensure that the permission allocation is more refined and controllable.

[0006] Furthermore, the above encryption communication module includes: a hardware security unit, a dynamic encryption unit, and a communication integrity monitoring unit; the hardware security unit is used to manage key generation, storage, and usage, avoid potential risks of key storage in software, and enhance the security of keys and confidentiality during the communication process; the dynamic encryption unit is used to dynamically adjust the encryption protocol and encryption intensity according to the sensitivity of the communication content and the security of the operating environment; the communication integrity monitoring unit is used for the real-time monitoring function of communication integrity, and prevents man-in-the-middle attacks or data tampering by periodically verifying the data integrity in encrypted communication.

[0007] Furthermore, the above hardware security module is implemented by integrating an HSM in the BMC system, and is used for key generation and storage, digital certificate management, and encryption and decryption operations.

[0008] Furthermore, the above audit module is used to capture all user operations and system events through a logging program; the log file is encrypted using the AES encryption algorithm, and the log file is uploaded to a remote server for storage through a periodic task.

[0009] Furthermore, the above behavior analysis and anomaly detection module includes: a data collection unit, a data preprocessing unit, a baseline model establishment unit, and a behavior detection unit; the data collection unit is used to collect and store the operation logs and system activity data of users in the BMC, specifically including: user login information, operation behavior records, and system events; the data preprocessing unit is used to format the collected raw data and synchronize timestamps, and use feature extraction technology to convert the operation logs into feature vectors available for analysis; the baseline model establishment unit is used to automatically establish a baseline model based on the feature vectors processed by the data preprocessing unit through machine learning algorithms; the behavior detection unit is used to perform user behavior analysis and anomaly detection based on multiple baseline models established by the baseline model establishment unit.

[0010] Furthermore, the above user login information includes: login time, login location, login device, and IP address; the operation behavior records include: accessed module, executed commands, and operation frequency; the system events include: permission changes, firmware updates, and communication establishment.

[0011] Furthermore, the above baseline models include: a login behavior baseline model, an operation path baseline model, and an operation frequency baseline model.

[0012] Furthermore, the above firmware integrity verification module is used to verify the integrity of the firmware when the BMC starts, and ensure that the digital signature and hash value of the firmware are consistent with the expected values; once it is found that the firmware has been tampered with, the BMC startup is blocked and a warning is issued.

[0013] Further, the firmware integrity verification module includes: a digital signature generation unit, a trusted root loading unit, a firmware loading and hash calculation unit, a digital signature verification unit, and a measure response unit; The digital signature generation unit is used to generate a digital signature for the firmware using the developer's private key during the firmware development stage; in combination with a hash function, calculate the hash value of the firmware, and encrypt the hash value with the private key to form a digital signature; the signature is released together with the firmware, and the developer's public key is stored by a trusted third party; The trusted root loading unit is used to embed a trusted root in the BMC, and the public key of the firmware developer is stored in the trusted root for decrypting the digital signature; The firmware loading and hash calculation unit is used to load the firmware file during the BMC startup process and calculate the hash value of the current firmware file using the same hash function; The digital signature verification unit is used to read the digital signature attached to the firmware, decrypt the digital signature using the embedded developer's public key to obtain the original hash value, and compare the decrypted hash value with the currently calculated firmware hash value; if the two are consistent, the firmware is complete and trusted; if the two are inconsistent, it indicates that the firmware has been tampered with and the verification fails; The measure response unit is used to allow the firmware to be loaded and the BMC startup to complete when the verification passes; when the verification fails, prevent the firmware from being loaded and trigger a security alert to notify the administrator or enter the security mode.

[0014] A multi-level security protection and auditing system based on BMC provided by this application can improve the security and operation transparency of the BMC during the server management process. Through measures such as multi-factor identity authentication, encrypted communication, anomaly detection based on behavior analysis, and firmware integrity verification, a comprehensive multi-level security protection framework is constructed. At the same time, the system has a built-in detailed auditing function to record and analyze all operation behaviors, generate real-time alerts and audit reports, and ensure that system security events can be traced and processed in a timely manner. This system is applicable to enterprise-level server management, especially suitable for application scenarios with high security requirements, such as the financial, medical, government, and military fields. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the specific embodiments of this application or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0016] Figure 1 It is a schematic structural diagram of a multi-level security protection and auditing system based on BMC provided by an embodiment of this application;

[0017] Figure 2 It is a specific unit structure diagram of an identity authentication module provided by an embodiment of this application;

[0018] Figure 3 This is the specific unit structure diagram of an encryption communication module provided by an embodiment of the present application;

[0019] Figure 4 This is the specific unit structure diagram of a behavior analysis and anomaly detection module provided by an embodiment of the present application;

[0020] Figure 5 This is the specific unit structure diagram of a firmware integrity verification module provided by an embodiment of the present application. Detailed implementation manners

[0021] Next, the technical solutions of the present application will be clearly and completely described in conjunction with the embodiments. Obviously, the described embodiments are some, rather than all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0022] The deficiencies of the BMC security mechanism in the prior art are mainly reflected in the following aspects:

[0023] 1. The identity authentication mechanism is relatively single and difficult to resist complex attack means;

[0024] 2. The communication security between the BMC and the management end is insufficient and vulnerable to man-in-the-middle attacks;

[0025] 3. Lack of effective operation log auditing and real-time alarm functions;

[0026] 4. Unable to dynamically detect and respond to abnormal behaviors and difficult to warn of potential attacks.

[0027] Based on this, an embodiment of the present application provides a multi-level security protection and auditing system based on BMC. Through the identity authentication module, encryption communication module, behavior analysis and anomaly detection module, firmware integrity verification module and auditing module, it can improve the security and operation transparency of the BMC during the server management process. The system has a built-in detailed auditing function, records and analyzes all operation behaviors, generates real-time alarms and auditing reports, and ensures that system security events can be tracked and processed in a timely manner. This system is applicable to enterprise-level server management, especially suitable for application scenarios with high security requirements, such as the financial, medical, government and military fields.

[0028] Figure 1 This is the structure diagram of a multi-level security protection and auditing system based on BMC provided by an embodiment of the present application. The system includes: an identity authentication module 11, an encryption communication module 12, a behavior analysis and anomaly detection module 13, a firmware integrity verification module 14 and an auditing module 15.

[0029] The identity authentication module 11 is used to adopt a two-factor or multi-factor identity authentication mechanism, combined with traditional username and password authentication or time-based one-time password, to ensure that only users who have passed multiple verifications can access the BMC; and to assign different permissions to users based on RBAC, restrict the operation scope, and ensure that key functions can only be operated by authorized users.

[0030] The encrypted communication module 12 is used to adopt the TLS / SSL encryption protocol to ensure that the communication between the BMC and the management end is carried out through a secure encrypted channel, prevent data from being eavesdropped or tampered with during transmission, and manage the encryption key through a hardware security module to ensure the data security during the communication process.

[0031] The behavior analysis and anomaly detection module 13 is used to monitor the daily operation behaviors of users and establish a baseline of normal operations through machine learning technology; when the system detects an operation that does not conform to the baseline, it will mark it as a suspicious behavior and trigger an alarm; it is also used to monitor unusual access patterns, and the unusual access patterns include: abnormally frequent login attempts, accesses from unexpected locations.

[0032] The firmware integrity verification module 14 is used to verify the integrity of the firmware when the BMC starts up, ensure that the digital signature and hash value of the firmware are consistent with the expected values; once it is found that the firmware has been tampered with, prevent the BMC from starting up and issue a warning; the audit module is used to record all operation information of the BMC, and the operation information includes each login, each command execution, and changes in system configuration; the operation information will be encrypted and stored, and remote backup is supported.

[0033] The audit module 15 is also used to generate regular reports and provide a real-time alarm function, which is convenient for administrators and security auditors to conduct retrospective checks, and once it detects suspicious behaviors or abnormal operations, it will immediately notify the relevant administrators.

[0034] The implementation processes of the above multiple modules will be elaborated in detail respectively as follows:

[0035] (1) The identity authentication module 11

[0036] See Figure 2 As shown, the above identity authentication module 11 integrates an open-source two-factor authentication library with the BMC, and combines the time-based one-time password with the user authentication process. The above identity authentication module 11 includes: a role permission dynamic adjustment unit 111, a behavior anomaly verification unit 112, and a multi-level permission mapping module 113.

[0037] The role authority dynamic adjustment unit 111 is used to introduce a dynamic adjustment mechanism for role authorities based on two-factor or multi-factor authentication. When a user logs in to the BMC through two-factor or multi-factor authentication, the user's operation authority is dynamically adjusted according to the method and strength of identity authentication. For example: 1) Basic operation authority (such as viewing system logs): only password verification is required. 2) High-risk operation authority (such as restarting the server or changing the firmware configuration): multi-factor authentication (such as TOTP+password) must be completed. 3) In high-risk environments (such as abnormal login behavior or sensitive operation time periods), limit users' high-authority operations. 4) For users who have passed multi-factor authentication, temporarily increase permissions in specific scenarios (such as emergency server maintenance).

[0038] 1) The multi-factor authentication process is designed as follows:

[0039] 1. The user accesses the BMC management interface and enters the user name and password (the first factor).

[0040] 2. The system sends the identity information to the identity authentication module 11 through an encrypted communication channel (such as TLS).

[0041] 3. The identity authentication module 11 calls the TOTP generator to verify the dynamic verification code (second factor) provided by the user. The TOTP generator uses the HMAC-SHA1 algorithm to calculate the one-time password based on the user's seed key and current timestamp.

[0042] 4. If both the first factor and the second factor are successfully verified, the system enters the RBAC permission allocation module and grants corresponding permissions based on the user role.

[0043] 2) Dynamic permission adjustment combined with RBAC:

[0044] After successful multi-factor authentication, the system dynamically adjusts the user's operating permissions based on the following conditions:

[0045] 1. User identity authentication method: For example, a user who has only completed password verification can only perform low-privilege operations.

[0046] 2. User behavior risk level: User behavior is detected through the behavior analysis module. If the risk score is high, high-authority operations are automatically restricted.

[0047] Technical implementation: The system configures a permission matrix to define the permission ranges corresponding to different authentication methods and risk levels. Every time a user initiates an operation request, the RBAC module queries the permission matrix in real time and dynamically updates the allowed operation set.

[0048] The behavior anomaly verification unit 112 is used to analyze and verify the user behavior based on the two-factor or multi-factor authentication process; the user behavior at least includes: the user's login behavior.

[0049] The system monitors the behavioral characteristics (such as time, location, device) of users during login through the behavior analysis module. If an anomaly is detected, that is, the user fails to pass the additional verification, the abnormal operation will be recorded and an alarm will be triggered to restrict account access.

[0050] For example, when the user's login behavior is significantly different from their normal usage pattern (such as login time, IP address, operation frequency), even if multi-factor authentication is completed, the system will still require additional verification (such as a one-time verification code) or directly lock high-privilege operations.

[0051] The multi-level permission mapping module 113 is used to provide a permission mapping mechanism based on task stratification, dividing permissions into three levels: global permissions, module permissions, and task permissions, ensuring more refined and controllable permission allocation. For example:

[0052] 1) Global permissions: Manage the overall functions of the server.

[0053] 2) Module permissions: Only access certain service modules (such as log viewing, firmware management).

[0054] 3) Task permissions: Execute specific tasks (such as a single firmware update operation).

[0055] (2) Encryption communication module 12

[0056] See Figure 3 As shown, the above encryption communication module 12 is based on an open-source implementation of TLS / SSL, combined with the hardware security unit on the BMC to generate and manage encryption keys, ensuring the secure storage of keys. The above encryption communication module 12 includes: a hardware security unit 121, a dynamic encryption unit 122, and a communication integrity monitoring unit 123.

[0057] The hardware security unit 121 is used to manage key generation, storage, and use, avoiding the potential risks of key storage in software, and enhancing the security of keys and confidentiality during the communication process.

[0058] Furthermore, the above hardware security unit 121 is implemented by integrating the HSM in the BMC system, and is used for key generation and storage, digital certificate management, and encryption and decryption operations. That is, the HSM is integrated in the BMC system for the following tasks:

[0059] 1. Key generation and storage: The HSM uses dedicated hardware to generate random keys and stores the keys in the HSM to prevent leakage.

[0060] 2. Digital certificate management: Use the HSM to generate and sign digital certificates required for communication.

[0061] 3. Encryption and decryption operations: Encryption and decryption are completed inside the HSM to prevent the key from being exposed to external memory or programs.

[0062] The dynamic encryption unit 122 is used to dynamically adjust the encryption protocol and encryption strength according to the sensitivity of the communication content and the security of the operating environment;

[0063] For example: For communications of sensitive operations (such as firmware updates), enable a higher-level encryption algorithm (such as AES-256-GCM); for the transmission of low-sensitivity data, use lightweight encryption to reduce resource consumption. For instance, the system dynamically adjusts the encryption strength according to the communication content and the operating environment. When a communication is established, the system calls the encryption policy module to automatically select the encryption protocol and key length according to the current scenario.

[0064] The communication integrity monitoring unit 123 is used for the real-time monitoring function of communication integrity. By periodically verifying the data integrity in encrypted communications, it prevents man-in-the-middle attacks or data tampering.

[0065] For example, the system generates a data integrity verification code during each data packet transmission and verifies it at the receiving end: Use the session key transmitted by TLS to generate an HMAC verification code; after receiving the data packet, the receiving end recalculates the HMAC value using the same key and compares it with the original value; if the verification fails, the system immediately interrupts the communication and triggers an alarm.

[0066] Furthermore, the system monitors the communication status in real time and detects the following anomalies:

[0067] 1. TLS handshake anomalies: Such as digital certificate expiration or incomplete certificate chain.

[0068] 2. Data packet loss or tampering: Based on the HMAC verification result.

[0069] After detecting an anomaly, the system immediately: interrupts the communication, records the anomaly event in the audit log, and notifies the administrator through the security alert module.

[0070] (3) Behavior analysis and anomaly detection module 13

[0071] See Figure 4 As shown, the above-mentioned behavior analysis and anomaly detection module 13 classifies user behaviors using a machine learning framework by recording user operation logs, and analyzes in real time whether the operation behaviors conform to the normal mode. Specifically, it includes: a data collection unit 131, a data preprocessing unit 132, a baseline model establishment unit 133, and a behavior detection unit 134.

[0072] The data collection unit 131 is used to collect and store the operation logs and system activity data of users in the BMC, specifically including: user login information, operation behavior records, and system events; the above user login information includes: login time, login location, login device, and IP address; the operation behavior records include: accessed module, executed commands, and operation frequency; the system events include: permission changes, firmware updates, and communication establishment.

[0073] The data preprocessing unit 132 is used to perform formatting processing and timestamp synchronization on the collected raw data, and use feature extraction technology to convert the operation logs into feature vectors (such as operation type, frequency, duration, etc.) that can be used for analysis;

[0074] The baseline model establishment unit 133 is used to automatically establish a baseline model based on the feature vectors processed by the data preprocessing unit through machine learning algorithms; the above baseline models include: login behavior baseline model, operation path baseline model, and operation frequency baseline model.

[0075] The baseline refers to the statistical characteristics and laws of user operation behaviors when the system is in a normal operation state. The process of establishing the baseline model is as follows:

[0076] Training data: Based on the normal behavior samples in the historical operation logs;

[0077] Algorithm selection: Use supervised learning;

[0078] Modeling content:

[0079] 1) User operation frequency distribution: For example, under normal circumstances, a user logs in no more than 3 times a day.

[0080] 2) Operation path pattern: For example, a user usually first accesses the "System Information" module and then accesses the "Firmware Update" module.

[0081] 3) Time and location association: For example, user logins usually occur between 9:00 - 18:00 on weekdays and are accessed from a specific geographical location.

[0082] The behavior detection unit 134 is used to perform user behavior analysis and anomaly detection based on multiple baseline models established by the baseline model establishment unit.

[0083] The baseline is a description of the normal operation range and behavior rules established by the system through statistical analysis of user historical behaviors and operation patterns. For example, it defines the characteristics of "normal" operations of a certain user in a specific scenario.

[0084] Example:

[0085] 1. Login behavior baseline:

[0086] Normal: The number of user logins per day does not exceed 3 times. The login IP address is mainly the company's office network, and the time period is from 9:00 to 18:00 on weekdays.

[0087] Abnormal: The same user fails to log in 5 times consecutively and then successfully logs in from an unknown IP address.

[0088] 2. Operation path baseline:

[0089] Normal: Users usually first access the "Hardware Monitoring" module and then enter the "Log Management" module to view historical records.

[0090] Abnormal: The user directly jumps to the "Permission Management" module and attempts to change the administrator account.

[0091] 3. Operation frequency baseline:

[0092] Normal: The system firmware is updated once a month.

[0093] Abnormal: The same account triggers 3 firmware updates within one day.

[0094] (4) Firmware integrity verification module 14

[0095] The above firmware integrity verification module 14 is used to verify the integrity of the firmware when the BMC starts, ensuring that the digital signature and hash value of the firmware are consistent with the expected values; once it is found that the firmware has been tampered with, it prevents the BMC from starting and issues a warning.

[0096] See Figure 5 As shown, the above firmware integrity verification module 14 includes: a digital signature generation unit 141, a trusted root loading unit 142, a firmware loading and hash calculation unit 143, a digital signature verification unit 144, and a measure response unit 145.

[0097] The digital signature generation unit 141 is used to generate a digital signature for the firmware using the developer's private key during the firmware development stage; in combination with a hash function (such as SHA-256), calculate the hash value of the firmware, and encrypt the hash value with the private key to form a digital signature; the signature is released together with the firmware, and the developer's public key is stored by a trusted third party;

[0098] The trusted root loading unit 142 is used to embed a trusted root (Root of Trust) in the BMC, usually a hardware trust module (such as TPM). The public key of the firmware developer is saved in the trusted root TPM and is used to decrypt the digital signature;

[0099] The firmware loading and hash calculation unit 143 is used to load the firmware file during the BMC startup process and calculate the hash value of the current firmware file using the same hash function (such as SHA-256);

[0100] The digital signature verification unit 144 is used to read the digital signature attached to the firmware, decrypt the digital signature using the embedded developer public key to obtain the original hash value, and compare the decrypted hash value with the currently calculated firmware hash value; if the two are consistent, the firmware is complete and trustworthy; if the two are inconsistent, it indicates that the firmware has been tampered with and the verification fails.

[0101] The measure response unit 145 is used to allow the firmware to be loaded and the BMC startup to complete when the verification passes; when the verification fails, it blocks the firmware from being loaded and triggers a security alert to notify the administrator or enter the safe mode.

[0102] In the embodiment of the present application, when the BMC starts up, a preset digital signature algorithm is called to verify whether the firmware has been tampered with. Once the verification fails, the system startup is blocked and an alarm is triggered.

[0103] 1) Firmware release stage:

[0104] a) The firmware developer completes the firmware compilation to generate a binary file (firmware.bin).

[0105] b) Calculate the hash value of the firmware through SHA-256. For example: Hash_A = SHA256(firmware.bin) = "3a5f6728d9...".

[0106] c) Encrypt the hash value using the developer's private key to generate a digital signature: Signature = Encrypt(PrivateKey_Dev, Hash_A).

[0107] d) Package and release the firmware file and the signature file.

[0108] 2) BMC startup stage:

[0109] a) Load the trusted root: The TPM module in the BMC loads the developer public key: PublicKey_Dev.

[0110] b) Load the firmware and the signature: The BMC loads firmware.bin and its corresponding signature file Signature.

[0111] c) Calculate the current firmware hash value:

[0112] Hash_B = SHA256(firmware.bin) = "3a5f6728d9...".

[0113] d) Verify the digital signature:

[0114] Decrypt the signature file:

[0115] Hash_A' = Decrypt(PublicKey_Dev, Signature).

[0116] Comparison result: Hash_A' == Hash_B.

[0117] e) Result judgment:

[0118] If Hash_A' == Hash_B:

[0119] The firmware verification is successful, and continue to start the BMC.

[0120] If Hash_A'!= Hash_B:

[0121] The firmware verification fails, prevent the startup and trigger the following response:

[0122] Display an error message: "Firmware integrity verification failed. Please contact the administrator."

[0123] Enter the safe mode or enable the backup firmware.

[0124] (5) Audit module 15

[0125] Furthermore, the above-mentioned audit module 15 is used to capture all user operations and system events through a logging program; the log file is encrypted using the AES encryption algorithm and uploaded to a remote server for storage through a periodic task.

[0126] The system provides a comprehensive audit function, recording all operations of the BMC, including each login, each command execution, and changes to the system configuration. These audit logs will be encrypted and stored, and remote backup is supported. The audit system can generate periodic reports to facilitate retrospective checks by administrators and security auditors. At the same time, the system provides a real-time alert function, and once suspicious behavior or abnormal operations are detected, relevant administrators will be notified immediately.

[0127] The multi-level security protection and audit system based on BMC provided by the embodiments of the present application has the following

[0128] Beneficial effects:

[0129] 1. Significantly improve the security of the BMC:

[0130] Through means such as multi-factor authentication, encrypted communication, and firmware integrity check, unauthorized access and system attacks are effectively prevented, and the overall security of the BMC is improved.

[0131] 2. Enhanced abnormal behavior detection and early warning function:

[0132] The anomaly detection module based on behavior analysis can detect and respond to abnormal operations in real time, preventing potential security threats.

[0133] 3. Comprehensive auditing and operation traceability:

[0134] The system's auditing module records all operations and generates audit reports, providing complete operation tracking and analysis for security incidents, facilitating post-event investigation and accountability.

[0135] 4. Adaptable modular design:

[0136] This system can be easily integrated into the existing enterprise security system and ensure future scalability and compatibility through modular design.

[0137] Through this multi-level security protection and auditing mechanism, the BMC system can manage servers more securely and efficiently, greatly enhancing the transparency and security during the management process. Through the identity authentication module, encrypted communication module, behavior analysis and anomaly detection module, firmware integrity verification module, and auditing module, the security and operation transparency of the BMC during the server management process can be improved. The system has a built-in detailed auditing function that records and analyzes all operation behaviors, generating real-time alerts and audit reports to ensure that system security incidents can be tracked and processed in a timely manner. This system is applicable to enterprise-level server management, especially suitable for application scenarios with high security requirements, such as the financial, medical, government, and military fields.

[0138] The embodiment of this application also provides a computer-readable storage medium that stores computer-executable instructions. When these computer-executable instructions are called and executed by a processor, the computer-executable instructions cause the processor to implement the above method. For specific implementation, reference can be made to the foregoing system embodiment, which will not be elaborated here.

[0139] The computer program product of the system provided by the embodiment of this application includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the method described in the system embodiment. For specific implementation, reference can be made to the system embodiment, which will not be elaborated here.

[0140] Unless otherwise specifically stated, the relative steps, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of this application.

[0141] When the above-mentioned functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0142] In the description of this application, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing this application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to this application. In addition, the terms "first", "second", "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.

[0143] Finally, it should be noted that: the above-mentioned embodiments are only specific implementation manners of this application, used to illustrate the technical solutions of this application, rather than limiting it. The protection scope of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed in this application can still modify the technical solutions recorded in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A multi-level security protection and audit system based on BMC, characterized in that: The system includes: an identity authentication module, an encryption communication module, a behavior analysis and anomaly detection module, a firmware integrity verification module and an audit module; The identity authentication module is used to adopt a two-factor or multi-factor identity authentication mechanism, combined with traditional username and password authentication or time one-time password, to ensure that only users who have passed multiple verifications can access the BMC; and to assign different permissions to users based on RBAC, limit the scope of operation, and ensure that key functions can only be operated by authorized users; The encryption communication module is used to adopt the TLS / SSL encryption protocol to ensure that the communication between the BMC and the management end is carried out through a secure encryption channel to prevent data from being eavesdropped or tampered with during transmission, and to manage encryption keys through a hardware security module to ensure data security during the communication process; The behavior analysis and anomaly detection module is used to monitor the daily operation behavior of users and establish a baseline of normal operation through machine learning technology; when the system detects an operation that is inconsistent with the baseline, it will mark it as suspicious behavior and trigger an alarm; it is also used to monitor unusual access patterns, including: abnormally frequent login attempts, access from unexpected locations; The firmware integrity verification module is used to verify the integrity of the firmware when the BMC is started to ensure that the digital signature and hash value of the firmware are consistent with the expected values; once the firmware is found to be tampered with, the BMC is prevented from starting and a warning is issued; The audit module is used to record all operation information of the BMC, including each login, each command execution and system configuration change; the operation information will be encrypted and stored, and remote backup is supported; the audit module is also used to generate regular reports and provide real-time alarm functions to facilitate administrators and security auditors to conduct retrospective inspections, and once suspicious behavior or abnormal operations are detected, the relevant administrators will be notified immediately.

2. The system according to claim 1, characterized in that The identity authentication module includes: a role authority dynamic adjustment unit, a behavior anomaly verification unit and a multi-level authority mapping module; The role authority dynamic adjustment unit is used to introduce a role authority dynamic adjustment mechanism based on two-factor or multi-factor authentication. When a user logs in to the BMC through two-factor or multi-factor authentication, the user's operation authority is dynamically adjusted according to the mode and strength of identity authentication; The abnormal behavior verification unit is used to analyze and verify the user behavior based on the two-factor or multi-factor authentication process; the user behavior at least includes: the user's login behavior; The multi-level permission mapping module is used to provide a permission mapping mechanism based on task hierarchy, dividing permissions into three levels: global permissions, module permissions and task permissions, to ensure that permission allocation is more refined and controllable.

3. The system according to claim 1, characterized in that The encryption communication module includes: a hardware security unit, a dynamic encryption unit and a communication integrity monitoring unit; The hardware security unit is used to manage key generation, storage and use, avoid potential risks of key storage in software, and enhance key security and confidentiality during communication; The dynamic encryption unit is used to dynamically adjust the encryption protocol and encryption strength according to the sensitivity of the communication content and the security of the operating environment; The communication integrity monitoring unit is used for real-time monitoring of communication integrity and prevents man-in-the-middle attacks or data tampering by periodically checking the integrity of data in encrypted communications.

4. The system according to claim 3, characterized in that The hardware security module is implemented by an HSM integrated in the BMC system and is used for key generation and storage, digital certificate management, and encryption and decryption operations.

5. The system according to claim 1, characterized in that The audit module is used to capture all user operations and system events through a log recording program; the log file is encrypted using the AES encryption algorithm, and the log file is uploaded to a remote server for storage through a periodic task.

6. The system according to claim 1, characterized in that The behavior analysis and anomaly detection module includes: a data collection unit, a data preprocessing unit, a baseline model building unit and a behavior detection unit; The data collection unit is used to collect and store the user's operation log and system activity data in the BMC, specifically including: user login information, operation behavior records and system events; The data preprocessing unit is used to format and synchronize the timestamp of the collected raw data, and use feature extraction technology to convert the operation log into a feature vector that can be used for analysis; The baseline model establishment unit is used to automatically establish a baseline model through a machine learning algorithm based on the feature vector processed by the data preprocessing unit; The behavior detection unit is used to perform user behavior analysis and anomaly detection based on the multiple baseline models established by the baseline model establishment unit.

7. The system according to claim 6, characterized in that The user login information includes: login time, login location, login device and IP address; the operation behavior record includes: access module, executed commands and operation frequency; the system events include: permission changes, firmware updates and communication establishment.

8. The system according to claim 6, characterized in that The baseline model includes: a login behavior baseline model, an operation path baseline model and an operation frequency baseline model.

9. The system according to claim 1, characterized in that The firmware integrity verification module is used to verify the integrity of the firmware when the BMC is started to ensure that the digital signature and hash value of the firmware are consistent with the expected values; once the firmware is found to be tampered with, the BMC is prevented from starting and a warning is issued.

10. The system according to claim 1, characterized in that The firmware integrity verification module includes: a digital signature generation unit, a trusted root loading unit, a firmware loading and hash calculation unit, a digital signature verification unit and a measure response unit; The digital signature generation unit is used to generate a digital signature for the firmware using the developer's private key during the firmware development phase; calculate the hash value of the firmware in combination with the hash function, and encrypt the hash value with the private key to form a digital signature; the signature is published together with the firmware, and the developer's public key is stored by a trusted third party; The trusted root loading unit is used to embed a trusted root in the BMC, and the public key of the firmware developer is stored in the trusted root for decrypting the digital signature; The firmware loading and hash calculation unit is used to load the firmware file during the BMC startup process and calculate the hash value of the current firmware file using the same hash function; The digital signature verification unit is used to read the digital signature attached to the firmware, decrypt the digital signature using the embedded developer public key to obtain the original hash value, and compare the decrypted hash value with the currently calculated firmware hash value; if the two are consistent, the firmware is complete and credible; if the two are inconsistent, it means that the firmware has been tampered with and the verification fails; The action response unit is used to allow firmware loading and BMC startup to complete when verification is passed; when verification fails, it blocks firmware loading and triggers a security alarm to notify the administrator or enter a safe mode.