Server management system, method, apparatus and program product based on hardware encryption

By setting up an encryption device on the server's motherboard and setting the connection method between it and the motherboard as a detachable connection, the security problems existing in the existing server management system are solved, and the security management of the server is achieved to minimize external intrusions.

CN120145406APending Publication Date: 2025-06-13SUMA TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202311695039.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-11
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

While the existing server management system is convenient for management, there are security problems. External intruders can access the server in various ways, resulting in poor security management.

Method used

Provide a server management system based on hardware encryption. By setting up an encryption device on the motherboard of the server and setting the connection method between it and the motherboard to be detachable. Only when the motherboard is connected to the encryption device can the BMC chip call the BMC program through the encryption device and start the BMC function of the server.

Benefits of technology

Through pure hardware encryption, external intrusions can be avoided to the greatest extent, security management of the server is achieved, and security of the server is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145406A_ABST
    Figure CN120145406A_ABST
Patent Text Reader

Abstract

The invention relates to a server management system, method and device based on hardware encryption and a program product. The server management system comprises an encryption device, and the encryption device is detachably connected with a mainboard of a server. A baseboard management controller (BMC) chip is arranged on a mainboard of the server; the BMC chip is used for calling a BMC program through the encryption device under the condition that the mainboard is connected with the encryption device so as to start a BMC function of the server; the BMC function is used for managing the server. The encryption device is arranged to manage the BMC program, and the connection mode between the encryption device and the mainboard of the server is set to be detachable connection, so that only under the condition that the mainboard is connected with the encryption device, the BMC chip in the mainboard can successfully retrieve the BMC program through the encryption device to start the BMC function of the server and manage the server; through a pure hardware encryption mode, external invasion is avoided as much as possible, and safety management of the server is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of server management, and in particular, to a server management system, method, device, and program product based on hardware encryption. Background Art

[0002] With the rapid development of computer technology, the application of the Baseboard Management Controller (BMC) chip has become increasingly widespread.

[0003] Taking the BMC chip of a server as an example, in the related art, the management of the server can be achieved by logging in to the BMC management page on the server. However, while such a management method is convenient for management, it also brings security problems to the server.

[0004] Therefore, how to perform secure management of the server has become a technical problem to be solved urgently. Summary of the Invention

[0005] Based on this, in view of the above technical problems, it is necessary to provide a server management system, method, device, and program product based on hardware encryption, which can achieve secure management of the server.

[0006] In a first aspect, an embodiment of the present application provides a server management system based on hardware encryption. The server management system includes an encryption device that is detachably connected to the motherboard of the server; a Baseboard Management Controller (BMC) chip is provided on the motherboard of the server;

[0007] The BMC chip is configured to, when the motherboard is connected to the encryption device, call the BMC program through the encryption device to start the BMC function of the server; the BMC function is used for managing the server.

[0008] In the server management system provided by the embodiments of the present application, the server management system includes an encryption device, and the encryption device is detachably connected to the main board of the server; a baseboard management controller (BMC) chip is provided on the main board of the server; the BMC chip is configured to, when the main board is connected to the encryption device, call the BMC program through the encryption device to activate the BMC function of the server; the BMC function is used for managing the server. In this server management system, by providing an encryption device to manage the BMC program and setting the connection between the encryption device and the main board of the server as a detachable connection, only when the main board is connected to the encryption device, the BMC chip in the main board can successfully retrieve the BMC program through the encryption device to activate the BMC function of the server and manage the server; conversely, if the main board is not connected to the encryption device, the BMC chip cannot obtain the BMC program and cannot activate the BMC function of the server, that is, it cannot manage the server. Through the method of pure hardware encryption, external intrusion can be maximally avoided to achieve the secure management of the server.

[0009] In one embodiment, the encryption device further includes: a BMC program storage medium, and the BMC program storage medium stores the BMC program.

[0010] In the server management system provided by the embodiments of the present application, the encryption device further includes a BMC program storage medium, and the BMC program storage medium stores the BMC program. In this server management system, by setting the BMC program storage medium storing the BMC program in the encryption device, only when the main board 20 is connected to the encryption device 10, the BMC chip 21 can obtain the stored BMC program from the BMC program storage medium 11 and activate the BMC function of the server by executing the BMC program. In this way, by externalizing the BMC program storage medium, it is ensured that the BMC function is not activated when the server does not need to be managed, avoiding external intrusion and improving the security of the server.

[0011] In one embodiment, the encryption device further includes a printed circuit board; the BMC program storage medium is disposed on the printed circuit board.

[0012] In the server management system provided by the embodiments of the present application, the encryption device further includes a printed circuit board; the BMC program storage medium is disposed on the printed circuit board. In this server management system, by providing a printed circuit board in the encryption device and disposing the BMC program storage medium on the printed circuit board, on the one hand, it provides necessary mechanical support for the BMC program storage medium, and on the other hand, it provides electrical connection of the circuit, so that the main board of the server can obtain the BMC program in the BMC program storage medium on the printed circuit board through connection with the printed circuit board.

[0013] In one embodiment, the encryption device further includes a chip connector, which is soldered on the printed circuit board, and the BMC program storage medium is detachably connected to the chip connector.

[0014] In the server management system provided by the embodiments of the present application, the encryption device further includes a chip connector, which is soldered on the printed circuit board, and the BMC program storage medium is detachably connected to the chip connector. In this server management system, by setting a chip connector in the encryption device and detachably connecting the BMC program storage medium to the chip connector, the BMC program storage medium can be easily detached from and installed on the chip connector. A new BMC program can be burned using a burner, and the new BMC program can flexibly change the password, further improving the reliability of server security management.

[0015] In one embodiment, the chip connector includes a network socket connector.

[0016] In the server management system provided by the embodiments of the present application, the chip connector includes a network socket connector. In this server management system, the network socket connector is soldered on the printed circuit board, and the BMC program storage medium in the encryption device is placed on the printed circuit board in the form of a network socket connector, facilitating the easy detachment and installation of the BMC program storage medium.

[0017] In one embodiment, the encryption device includes a communication interface, which is provided at one end of the encryption device, and the encryption device is detachably connected to the communication interface on the motherboard through the communication interface.

[0018] In the server management system provided by the embodiments of the present application, the encryption device includes a communication interface, which is provided at one end of the encryption device, and the encryption device is detachably connected to the communication interface on the motherboard through the communication interface. In this server management system, by setting a communication interface in the encryption device, the detachable connection between the communication interface in the encryption device and the communication interface on the motherboard can be used to achieve the detachable connection between the encryption device and the motherboard of the server.

[0019] In one embodiment, the communication interface includes a universal serial bus interface.

[0020] In the server management system provided by the embodiments of the present application, the communication interface includes a universal serial bus interface. In this server management system, the universal serial bus interface is set at one end of the encryption device, and the detachable connection between the communication interface and the communication interface on the motherboard can be used to achieve the detachable connection between the encryption device and the motherboard of the server. In this way, when the communication interface of the encryption device is connected to the communication interface on the motherboard, the BMC chip in the motherboard can obtain the BMC program in the encryption device.

[0021] In a second aspect, an embodiment of the present application further provides a server management method based on hardware encryption, which is applied to a BMC chip. The BMC chip is disposed on the motherboard of the server. The method includes:

[0022] When the motherboard is connected to the encryption device, the BMC program is called through the encryption device; the encryption device is detachably connected to the motherboard;

[0023] Execute the BMC program to start the BMC function of the server; the BMC function is used for server management.

[0024] In the server management method provided by the embodiment of the present application, the BMC chip is disposed on the motherboard of the server. When the motherboard is connected to the encryption device, the BMC program is called through the encryption device. The encryption device is detachably connected to the motherboard, and then the BMC program is executed to start the BMC function of the server. The BMC function is used for the management of the server. In this method, the BMC program is managed through the encryption device, and the connection mode between the encryption device and the motherboard of the server is set to be detachable. In this way, only when the motherboard is connected to the encryption device, the BMC chip in the motherboard can successfully retrieve the BMC program through the encryption device to start the BMC function of the server and manage the server. On the contrary, if the motherboard is not connected to the encryption device, the BMC chip cannot obtain the BMC program and cannot start the BMC function of the server, that is, it cannot manage the server. Through the pure hardware encryption method, external intrusion is maximally avoided, and the security management of the server is realized.

[0025] In a third aspect, an embodiment of the present application further provides a server management device based on hardware encryption, including:

[0026] A calling module, configured to call the BMC program through the encryption device when the motherboard of the server is connected to the encryption device; the encryption device is detachably connected to the motherboard;

[0027] A starting module, configured to execute the BMC program to start the BMC function of the server; the BMC function is used for server management.

[0028] In a fourth aspect, an embodiment of the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps in the second aspect are implemented.

[0029] In a fifth aspect, an embodiment of the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the second aspect are implemented.

[0030] In a sixth aspect, an embodiment of the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps in the second aspect are implemented.

[0031] In the above server management system, method, device and program product based on hardware encryption, the server management system includes an encryption device, and the encryption device is detachably connected to the motherboard of the server; a baseboard management control (BMC) chip is provided on the motherboard of the server; the BMC chip is configured to, when the motherboard is connected to the encryption device, call the BMC program through the encryption device to start the BMC function of the server; the BMC function is used for managing the server. In this server management system, the BMC program is managed by setting an encryption device, and the connection mode between the encryption device and the motherboard of the server is set to be detachable. In this way, only when the motherboard is connected to the encryption device, the BMC chip in the motherboard can successfully retrieve the BMC program through the encryption device to start the BMC function of the server and manage the server; conversely, if the motherboard is not connected to the encryption device, the BMC chip cannot obtain the BMC program and cannot start the BMC function of the server, that is, it cannot manage the server. Through a pure hardware encryption method, external intrusion is maximally avoided, and the security management of the server is realized. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0033] Figure 1 It is a schematic diagram of a server management system based on hardware encryption in an embodiment;

[0034] Figure 2 It is a schematic diagram of a server management system based on hardware encryption in another embodiment;

[0035] Figure 3 It is a schematic diagram of a server management system based on hardware encryption in another embodiment;

[0036] Figure 4 It is a schematic diagram of a server management system based on hardware encryption in another embodiment;

[0037] Figure 5 It is a schematic diagram of a server management system based on hardware encryption in another embodiment;

[0038] Figure 6Schematic flowchart of a server management method based on hardware encryption in an embodiment;

[0039] Figure 7 Schematic diagram of the connection between the motherboard and the encryption device in an embodiment;

[0040] Figure 8 Schematic diagram of the non - connection between the motherboard and the encryption device in an embodiment;

[0041] Figure 9 Schematic structural diagram of a server management device based on hardware encryption in an embodiment. Detailed implementation manners

[0042] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above - mentioned drawings are intended to cover non - exclusive inclusion.

[0044] In the description of the embodiments of this application, technical terms such as "first" and "second" are only used to distinguish different objects and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity, specific order or primary - secondary relationship of the indicated technical features. In the description of the embodiments of this application, "a plurality of" means more than two unless otherwise specifically defined.

[0045] Referring to "embodiments" herein means that specific features, structures or characteristics described in connection with the embodiments can be included in at least one embodiment of this application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0046] With the rapid development of computer technology, the application of the Baseboard Management Controller (BMC) chip is becoming more and more extensive. Taking the BMC chip of a server as an example, the management of the server can be realized by logging in to the BMC management page of the server.

[0047] For example, a user can manage the entire server through a local area network, or a mainstream server that supports an out-of-band management communication protocol (NCSI, Network Controller Sideband Interface) can manage the server without using a local area network.

[0048] While such a management method is convenient for management, it also brings security problems to the server. For example, a competitor can easily log in to the customer's management page through NCSI, access the server by cracking the password, and maliciously manipulate the server, causing huge losses; even if NCSI is not used, there are still behaviors where hackers access the local area network, log in to the server, and perform malicious operations.

[0049] In related technologies, in response to the above problems, the following solutions are provided respectively:

[0050] (1) Turn off NCSI: Although mainstream servers are equipped with the NCSI function, it will be removed by default when leaving the factory. After the NCSI function fails, the BMC can only be accessed through the local area network in principle.

[0051] (2) Local area network + password: The BMC can generally only be accessed through the local area network, which will further increase the difficulty of intrusion. At the same time, the BMC will also set a login password when logging in, further improving the security factor.

[0052] However, the reliability of the above two security management methods is not high. In the first method, although the NCSI function is turned off, it can still be accessed through the local area network; in the second method, although a password is set, the server can still be accessed by cracking the password.

[0053] Based on this, the present application proposes a server management system based on hardware encryption. By setting an encryption device to manage the BMC program and setting the connection method between the encryption device and the motherboard of the server as a detachable connection, in this way, only when the motherboard is connected to the encryption device, the BMC chip in the motherboard can successfully retrieve the BMC program through the encryption device to start the BMC function of the server and manage the server; conversely, if the motherboard is not connected to the encryption device, the BMC chip cannot obtain the BMC program, cannot start the BMC function of the server, that is, cannot manage the server. Through the method of pure hardware encryption, external intrusion is avoided as much as possible to achieve the security management of the server.

[0054] It should be noted that the beneficial effects or the technical problems solved by the embodiments of the present application are not limited to this one, and there may be other implicit or related problems. For details, please refer to the description of the following embodiments.

[0055] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0056] In an exemplary embodiment, as Figure 1 shown, a server management system based on hardware encryption is provided. The server management system includes an encryption device 10, and the encryption device 10 is detachably connected to the main board 20 of the server; a baseboard management control (BMC) chip 21 is provided on the main board 20 of the server;

[0057] The BMC chip 21 is configured to, when the main board 20 is connected to the encryption device 10, call the BMC program through the encryption device 10 to start the BMC function of the server; the BMC function is used for managing the server.

[0058] Among them, the main board 20, also called the motherboard, is installed inside the computer main chassis and is one of the most basic and important components of the computer. The main board is generally a rectangular circuit board, on which the main circuit systems that make up the computer are installed, including but not limited to the Basic Input Output System (BIOS), input / output control chips, BMC chips, keyboard and panel control switch interfaces, indicator light plug-ins, expansion slots, DC power supply connectors for the main board and plug-in cards, and other components.

[0059] The BMC chip 21 refers to a baseboard management controller, which can perform remote monitoring and management of the server, including but not limited to operations such as allocation and configuration of hardware resources, power control, BIOS settings, and remote restart.

[0060] The encryption device 10 refers to a device for encrypting the BMC program of the BMC chip 21. In practical applications, the BMC chip needs to obtain the BMC program and can start the BMC function of the server to achieve server management only by executing the BMC program.

[0061] Based on this, in the embodiment of the present application, the encryption device 10 is used to manage the BMC program. When the BMC chip 21 successfully obtains the BMC program through the encryption device 10, the BMC function of the server can be started.

[0062] In the embodiments of the present application, in order to achieve the security management of the server, the connection mode between the encryption device 10 and the motherboard 20 of the server is set as a detachable connection mode. Only when the motherboard 20 is connected to the encryption device 10, the BMC chip 21 in the motherboard 20 can retrieve the BMC program through the encryption device 10, and start the BMC function of the server by executing the BMC program. In this way, the user can successfully manage the server. If the motherboard 20 is not connected to the encryption device 10, the BMC chip 21 in the motherboard 20 cannot obtain the BMC program, that is, it cannot start the BMC function of the server, and the user cannot manage the server.

[0063] In the server management system provided by the embodiments of the present application, the server management system includes an encryption device, and the encryption device is detachably connected to the motherboard of the server; a baseboard management control BMC chip is provided on the motherboard of the server; the BMC chip is used to call the BMC program through the encryption device to start the BMC function of the server when the motherboard is connected to the encryption device; the BMC function is used to manage the server. In this server management system, by setting the encryption device to manage the BMC program and setting the connection mode between the encryption device and the motherboard of the server as a detachable connection, in this way, only when the motherboard is connected to the encryption device, the BMC chip in the motherboard can successfully retrieve the BMC program through the encryption device to start the BMC function of the server and manage the server; on the contrary, if the motherboard is not connected to the encryption device, the BMC chip cannot obtain the BMC program and cannot start the BMC function of the server, that is, it cannot manage the server. Through the method of pure hardware encryption, external intrusion is maximally avoided, and the security management of the server is realized.

[0064] The BMC program of the BMC chip is usually stored in a storage medium. The BMC program belongs to software, while the encryption device belongs to hardware. If the encryption device is to manage the BMC program, a storage medium for storing the BMC program needs to be set in the encryption device. This will be described below through an embodiment.

[0065] In an exemplary embodiment, as Figure 2 shown, the encryption device 10 further includes: a BMC program storage medium 11, and the BMC program storage medium 11 stores the BMC program.

[0066] The BMC program storage medium 11 refers to the memory for storing the BMC program. In the embodiments of the present application, the BMC program storage medium 11 can be a storage medium based on the Serial Peripheral Interface (SPI) protocol.

[0067] Generally, the storage medium storing the BMC program is soldered to the main board of the server. The BMC chip in the main board can easily obtain the BMC program from the storage medium, and then start the BMC function based on the BMC program. In the embodiments of the present application, the BMC program storage medium 11 storing the BMC program is disposed in the encryption device. Only when the main board 20 is connected to the encryption device 10, the BMC chip 21 can obtain the stored BMC program from the BMC program storage medium 11, and start the BMC function of the server by executing the BMC program.

[0068] In the server management system provided by the embodiments of the present application, the encryption device further includes a BMC program storage medium, and the BMC program is stored in the BMC program storage medium. In this server management system, by disposing the BMC program storage medium storing the BMC program in the encryption device, only when the main board 20 is connected to the encryption device 10, the BMC chip 21 can obtain the stored BMC program from the BMC program storage medium 11, and start the BMC function of the server by executing the BMC program. In this way, by means of externalizing the BMC program storage medium, it is ensured that the BMC function is not started when the server does not need to be managed, avoiding external intrusion and improving the security of the server.

[0069] A printed circuit board is disposed in the encryption device, which can realize the circuit connection of various components. Based on this, in an exemplary embodiment, as Figure 3 shown, the encryption device 10 further includes a printed circuit board 12; the BMC program storage medium 11 is disposed on the printed circuit board 12.

[0070] Among them, the printed circuit board is one of the core technologies for electronic manufacturing of integrated circuits. It is a support for electronic components and a carrier for the electrical connection of electronic components. This technology can bond conductive lines and electronic components to the same non-conductive material to form a fixed electronic component. The connections between these lines and components are composed of conductor layers such as copper foils.

[0071] The printed circuit board can accommodate a large number of electrical components in a relatively small space and can be produced automatically. Compared with the traditional circuit board that uses wires to connect electronic components, the printed circuit board uses a printing method to complete the wiring of conductive channels on the board, making the circuit connection between electronic components faster, more accurate and reliable. Its main function is to connect various electronic component assemblies through circuits, playing the role of conduction and transmission.

[0072] The printed circuit board 12 may include circuit traces and patterns, dielectric layers, vias, solder mask, and silk screen, etc. It uses an insulating board as the base material, is cut into a certain size, and has at least one conductive pattern attached thereto, and holes (such as component holes, fastening holes, metallized holes, etc.) are provided thereon to install electronic components and achieve the interconnection between electronic components. According to the different number of circuit layers of the printed circuit board, the printed circuit board 12 may include single-sided boards, double-sided boards, and multi-layer boards, etc.

[0073] In the embodiment of the present application, the printed circuit board 12 is provided in the encryption device 10, and the BMC program storage medium 11 is provided on the printed circuit board 12. In this way, the main board 20 of the server can successfully obtain the BMC program in the BMC program storage medium 11 on the printed circuit board 12 through the connection with the printed circuit board 12.

[0074] In the server management system provided by the embodiment of the present application, the encryption device further includes a printed circuit board; the BMC program storage medium is provided on the printed circuit board. In this server management system, by providing the printed circuit board in the encryption device and setting the BMC program storage medium on the printed circuit board, on the one hand, it provides necessary mechanical support for the BMC program storage medium, and on the other hand, it provides electrical connection of the circuit, so that the main board of the server can obtain the BMC program in the BMC program storage medium on the printed circuit board through the connection with the printed circuit board.

[0075] In order to further improve the reliability of the encryption device, the BMC program storage medium may not be directly soldered on the printed circuit board, and a detachable connection method may be adopted. A burner can be used to burn a new BMC program, and the new BMC program can flexibly change the password. The following will illustrate this through an embodiment. In an exemplary embodiment, as Figure 4 shown, the encryption device 10 further includes a chip connector 13. The chip connector 13 is soldered on the printed circuit board 12, and the BMC program storage medium 11 is detachably connected to the chip connector 13.

[0076] Among them, the chip connector 13 is an electronic component for connecting a chip to a circuit board, providing electrical connection between the chip and the circuit board, and ensuring the reliability and stability of signal transmission. It can connect the pins of the chip to the pads on the circuit board to achieve signal transmission and power transfer between the chip and the circuit board. At the same time, it can also provide the mechanical support required in the electronic device to make the connection between the chip and the circuit board more firm and reliable.

[0077] The chip connector 13 may include, but is not limited to, different types of connectors such as pin connectors, header connectors, and socket connectors.

[0078] In the embodiment of the present application, a chip connector 13 is provided in the encryption device 10. The BMC program storage medium 11 is detachably connected to the chip connector 13, and the BMC program storage medium 11 can be removed from the chip connector 13 at any time to rewrite the BMC program in the BMC program storage medium. For example, when the user needs to use the NCSI function, a new BMC program can be burned using a burner, and the new BMC program can flexibly change the password. Since different passwords can be set each time, when the motherboard is connected to the encryption device and uses the NCSI function to access the BMC management page, the NCSI function can be used with higher security.

[0079] In the server management system provided by the embodiment of the present application, the encryption device further includes a chip connector, the chip connector is welded on the printed circuit board, and the BMC program storage medium is detachably connected to the chip connector. In this server management system, by providing a chip connector in the encryption device and detachably connecting the BMC program storage medium to the chip connector, the BMC program storage medium can be easily removed and installed from the chip connector, and a new BMC program can be burned using a burner. The new BMC program can flexibly change the password, further improving the reliability of server security management.

[0080] In an exemplary embodiment, the chip connector includes a network socket connector.

[0081] Among them, the network socket connector is a connector specific to the chip, usually welded on the printed circuit board. Placing the chip in it is equivalent to directly connecting the chip to the printed circuit board.

[0082] In the server management system provided by the embodiment of the present application, the chip connector includes a network socket connector. In this server management system, the network socket connector is welded on the printed circuit board, and the BMC program storage medium in the encryption device is placed on the printed circuit board in the form of a network socket connector, which facilitates the easy removal and installation of the BMC program storage medium.

[0083] To achieve the detachable connection between the encryption device and the motherboard of the server, an external interface can be provided in the encryption device, and it is connected to the corresponding interface in the motherboard of the server through this external interface, so that the BMC chip can obtain the BMC program from the BMC program storage medium in the encryption device. The following will illustrate this through an embodiment. In an exemplary embodiment, as Figure 5 shown, the encryption device 10 includes a communication interface 14. The communication interface 14 is provided at one end of the encryption device 10, and the encryption device 10 is detachably connected to the communication interface 22 on the motherboard through the communication interface 14.

[0084] The communication interface 14 is a specification for defining details such as the connection method, electrical characteristics, and protocol between communication devices. The types of communication interfaces can include, but are not limited to, serial interfaces, parallel interfaces, and universal serial bus interfaces, etc.

[0085] The communication interface 14 of the encryption device 10 is correspondingly connected to the communication interface 22 on the motherboard. Therefore, the interface type of the communication interface 22 on the motherboard needs to be consistent with the interface type of the communication interface 14 of the encryption device 10. For example, if the interface type of the communication interface 14 of the encryption device 10 is a universal serial bus interface, then the interface type of the communication interface 22 on the motherboard is also a universal serial bus interface.

[0086] In the embodiment of the present application, a communication interface 14 is provided in the encryption device 10. The encryption device 10 is detachably connected to the communication interface 22 on the motherboard through the communication interface 14, that is, the detachable connection between the encryption device 10 and the motherboard 20 of the server is realized. In this way, when the communication interface 14 of the encryption device 10 is connected to the communication interface 22 on the motherboard, the BMC chip in the motherboard 20 can obtain the BMC program in the encryption device 10.

[0087] In the server management system provided by the embodiment of the present application, the encryption device includes a communication interface. The communication interface is arranged at one end of the encryption device. The encryption device is detachably connected to the communication interface on the motherboard through the communication interface. In this server management system, by providing a communication interface in the encryption device, the detachable connection between the encryption device and the motherboard of the server can be realized through the detachable connection between the communication interface in the encryption device and the communication interface on the motherboard.

[0088] In an exemplary embodiment, the communication interface includes a universal serial bus interface.

[0089] Among them, the universal serial bus interface is a serial bus standard and also a technical specification for an input / output interface. It has the function of hot plugging and can be easily disassembled and connected.

[0090] In the server management system provided by the embodiment of the present application, the communication interface includes a universal serial bus interface. In this server management system, the universal serial bus interface is arranged at one end of the encryption device. Through the detachable connection between the communication interface and the communication interface on the motherboard, the detachable connection between the encryption device and the motherboard of the server can be realized. In this way, when the communication interface of the encryption device is connected to the communication interface on the motherboard, the BMC chip in the motherboard can obtain the BMC program in the encryption device.

[0091] It can be understood that the design of each structure in the server management system based on hardware encryption in the above embodiments is only one example for implementing the technical effects of the present application. In actual applications, it can also be adaptively deformed to achieve easily conceivable technical effects, and the present application embodiments do not limit its structure.

[0092] Next, the server management method based on hardware encryption provided in the embodiments of the present application will be described. The server management methods in the embodiments of the present application are all described by taking the server management system described above Figure 1 as the application object and taking the BMC chip as the execution subject.

[0093] In an exemplary embodiment, as Figure 6 shown, this embodiment includes the following steps:

[0094] S101, when the motherboard is connected to the encryption device, call the BMC program through the encryption device.

[0095] Among them, the BMC chip is disposed on the motherboard of the server, and the encryption device is detachably connected to the motherboard.

[0096] In the embodiments of the present application, in order to realize the security management of the server, the connection mode between the encryption device and the motherboard of the server is set as a detachable connection mode. Only when the motherboard is connected to the encryption device, the BMC chip in the motherboard can call the BMC program through the encryption device.

[0097] For example, as Figure 7 shown, it is a schematic diagram of the connection between the motherboard of the server and the encryption device. Among them, the motherboard 20 is connected to the encryption device 10, and the BMC chip 21 in the motherboard 20 calls the BMC program through the encryption device 10.

[0098] As Figure 8 shown, it is a schematic diagram of the motherboard of the server not connected to the encryption device. The motherboard 20 is not connected to the encryption device 10, and the BMC chip 21 in the motherboard 20 cannot obtain the BMC program, that is, the BMC function of the server cannot be started, and the user cannot manage the server.

[0099] S102, execute the BMC program to start the BMC function of the server.

[0100] Among them, the BMC function is used for server management.

[0101] After the BMC chip calls the BMC program through the encryption device, by executing the BMC program, the BMC function of the server can be started, that is, the user can manage the server.

[0102] In the server management method provided by the embodiments of the present application, the BMC chip is disposed on the main board of the server. When the main board is connected to the encryption device, the BMC program is called through the encryption device. The encryption device is detachably connected to the main board, and then the BMC program is executed to start the BMC function of the server. The BMC function is used for managing the server. In this method, the BMC program is managed through the encryption device, and the connection mode between the encryption device and the main board of the server is set to be detachably connected. In this way, only when the main board is connected to the encryption device, the BMC chip in the main board can successfully retrieve the BMC program through the encryption device to start the BMC function of the server and manage the server. On the contrary, if the main board is not connected to the encryption device, the BMC chip cannot obtain the BMC program and cannot start the BMC function of the server, that is, it cannot manage the server. Through the pure hardware encryption method, external intrusion is avoided to the greatest extent, and the security management of the server is realized.

[0103] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are displayed in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps does not have a strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.

[0104] Based on the same inventive concept, the embodiments of the present application also provide a server management device for implementing the above-mentioned server management method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the server management device provided below can refer to the limitations on the server management method in the above text, and will not be repeated here.

[0105] In an exemplary embodiment, as Figure 9 shown, a server management device 1 based on hardware encryption is provided, including: a calling module 30 and a starting module 40, where:

[0106] The calling module 30 is configured to call the BMC program through the encryption device when the main board of the server is connected to the encryption device; the encryption device is detachably connected to the main board;

[0107] The startup module 40 is used to execute the BMC program to start the BMC function of the server; the BMC function is used for server management.

[0108] Each module in the above server management device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0109] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:

[0110] When the motherboard is connected to the encryption device, the BMC program is called through the encryption device; the encryption device is detachably connected to the motherboard;

[0111] Execute the BMC program to start the BMC function of the server; the BMC function is used for server management.

[0112] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0113] When the motherboard is connected to the encryption device, the BMC program is called through the encryption device; the encryption device is detachably connected to the motherboard;

[0114] Execute the BMC program to start the BMC function of the server; the BMC function is used for server management.

[0115] In an embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0116] When the motherboard is connected to the encryption device, the BMC program is called through the encryption device; the encryption device is detachably connected to the motherboard;

[0117] Execute the BMC program to start the BMC function of the server; the BMC function is used for server management.

[0118] It should be noted that the data involved in this application (including but not limited to data for analysis, stored data, displayed data, etc.) are all information and data that have been authorized or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0119] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0120] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0121] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A server management system based on hardware encryption, characterized in that, the server management system includes an encryption device, and the encryption device is detachably connected to the main board of the server; a baseboard management controller (BMC) chip is provided on the main board of the server; the BMC chip is used to call the BMC program through the encryption device to activate the BMC function of the server when the main board is connected to the encryption device; the BMC function is used for managing the server.

2. The server management system according to claim 1, characterized in that, the encryption device further includes: a BMC program storage medium, and the BMC program is stored in the BMC program storage medium.

3. The server management system according to claim 2, characterized in that, the encryption device further includes a printed circuit board; the BMC program storage medium is arranged on the printed circuit board.

4. The server management system according to claim 3, characterized in that, the encryption device further includes a chip connector, the chip connector is soldered on the printed circuit board, and the BMC program storage medium is detachably connected to the chip connector.

5. The server management system according to claim 4, characterized in that, the chip connector includes a network socket connector.

6. The server management system according to any one of claims 1-5, characterized in that, the encryption device includes a communication interface, the communication interface is arranged at one end of the encryption device, and the encryption device is detachably connected to the communication interface on the main board through the communication interface.

7. The server management system according to claim 6, characterized in that, the communication interface includes a universal serial bus interface.

8. A server management method based on hardware encryption, characterized in that, applied to a BMC chip, the BMC chip is arranged on the main board of the server, and the method includes: calling the BMC program through the encryption device when the main board is connected to the encryption device; the encryption device is detachably connected to the main board; executing the BMC program to activate the BMC function of the server; the BMC function is used for managing the server.

9. A server management device based on hardware encryption, characterized in that, the server management device includes: a calling module, used to call the BMC program through the encryption device when the main board of the server is connected to the encryption device; the encryption device is detachably connected to the main board; a starting module, used to execute the BMC program to activate the BMC function of the server; the BMC function is used for managing the server.

10. A computer program product, including a computer program, characterized in that, when the computer program is executed by a processor, the steps of the method described in claim 8 are implemented.

Citation Information

Patent Citations

  • BMC chip, server side and remote monitoring management method thereof

    CN107528829A

  • Server starting method and system, electronic equipment and storage medium

    CN111399919A

  • Trusted starting method for multi-core BMC (Baseboard Management Controller) firmware system

    CN114462050A

  • BMC controller, information security system and information interaction method

    CN116821020A

  • Encryption card, electronic device, and encryption service method

    WO2019209997A1