Identity authentication method and device

By encrypting user information on the BMC client and transmitting access ciphertext information between the BMC client and the BMC server, the problem of BMC remote access identity authentication security risks in the prior art is solved, and higher access security is achieved.

CN120165889APending Publication Date: 2025-06-17SUGON INFORMATION IND +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311723427.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

In the prior art, the remote access identity authentication method of BMC poses security risks, and user information is easily stolen or tampered during transmission.

Method used

By encrypting user information on the BMC client, access ciphertext information is generated and transmitted between the BMC client and the BMC server, the security of user information is ensured. After receiving the access ciphertext information, the BMC server performs decryption verification to determine the user's identity authentication result.

Benefits of technology

It improves the security of BMC access, ensures the security of user information during transmission, reduces the risk of identity authentication failure, and enhances the overall access security of BMC.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165889A_ABST
    Figure CN120165889A_ABST
Patent Text Reader

Abstract

The invention relates to an identity authentication method and device, and the method comprises the steps: enabling a BMC client to respond to an access request of a BMC, carrying out the encryption of user information carried in the access request, generating access ciphertext information, and transmitting a resource request to a BMC server; the resource request carries access ciphertext information and is used for indicating the BMC server to verify and authorize the identity of the user; and determining an identity authentication result of the user according to a response message of the resource request sent by the BMC server. By adopting the method, the accuracy of identity authentication can be improved, so that the access security of the BMC is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer security technology, and in particular, to an identity authentication method and device. Background Art

[0002] The Baseboard Management Controller (BMC) is a controller that can intelligently manage a server.

[0003] In the related art, the BMC provides a management interface for remote access during the operation of the server. Users can remotely access the BMC management interface through the network. After the BMC authenticates the user's identity, it can manage and monitor the running status of the entire server system in real time.

[0004] However, the user identity authentication method in the related art brings great security risks to the access of the BMC. Summary of the Invention

[0005] Based on this, in view of the above technical problems, it is necessary to provide an identity authentication method and device to improve the security during the access to the BMC.

[0006] In a first aspect, this application provides an identity authentication method, which is applied to a BMC client of a baseboard management controller. The method includes:

[0007] In response to an access request from the BMC, encrypt the user information carried in the access request to generate access ciphertext information;

[0008] Send a resource request to the BMC server; the access ciphertext information is carried in the resource request, which is used to instruct the BMC server to verify and authorize the user's identity;

[0009] Determine the user's identity authentication result according to the response message of the resource request sent by the BMC server.

[0010] In the technical solution provided by the embodiment of the present application, the BMC client encrypts the user information carried in the access request in response to the access request of the BMC, generates access ciphertext information, and sends a resource request to the BMC server; the resource request carries the access ciphertext information, which is used to instruct the BMC server to authenticate and authorize the user's identity; then, according to the response message of the resource request sent by the BMC server, the user's identity authentication result is determined. In this method, when accessing the BMC through the BMC client, the BMC client encrypts the user information input by the user, which ensures the security of the user information during the transmission between the BMC client and the BMC server, improves the accuracy of identity authentication, ensures the security and accuracy of the subsequent verification and authorization of the access ciphertext information by the BMC server, reduces the risk of user information leakage, and thus improves the access security of the BMC.

[0011] In one embodiment, determining the user's identity authentication result according to the response message of the resource request sent by the BMC server includes:

[0012] When the response message includes user credential information, determining that the user's identity authentication result is authentication successful;

[0013] When the response message includes error prompt information, determining that the user's identity authentication result is authentication failed.

[0014] In the technical solution provided by the embodiment of the present application, when the response message includes user credential information, determining that the user's identity authentication result is authentication successful; when the response message includes error prompt information, determining that the user's identity authentication result is authentication failed. In this method, the BMC client directly determines the user's identity authentication result through the content in the response message sent by the BMC server, without further inference, which improves the accuracy and rapidity of user identity authentication.

[0015] In one embodiment, the method further includes:

[0016] When the response message includes user credential information, obtaining the user's permission information from the user credential information;

[0017] According to the permission information, opening the access permission of the BMC for the user.

[0018] In the technical solution provided by the embodiment of the present application, when the response message includes user credential information, the permission information of the user is obtained from the user credential information, and according to the permission information, the access permission to the BMC is opened for the user. In this method, the access permission of the user is managed through the permission information of the user, and the permission management of the refined feature functions can be carried out according to the user role, realizing fine-grained access control, thereby improving the access security of the BMC.

[0019] In one embodiment, the method further includes:

[0020] When the response message includes user credential information, obtain the session identifier and access token of the user from the user credential information;

[0021] Store the session identifier and access token in a preset cache.

[0022] In the technical solution provided by the embodiment of the present application, when the response message includes user credential information, the session identifier and access token of the user are obtained from the user credential information, and the session identifier and access token are stored in a preset cache. In this method, storing the session identifier and access token in the cache can be used for subsequent page persistent request access, reducing the repeated authentication process, reducing the network overhead and latency, and improving the overall access performance and efficiency of the BMC.

[0023] In a second aspect, the present application provides an identity authentication method, which is applied to a BMC server, and the method includes:

[0024] Receive a resource request sent by a BMC client; the resource request carries access ciphertext information; the access ciphertext information is obtained by encrypting the user information of the user by the BMC client;

[0025] According to the access ciphertext information, verify and authorize the identity of the user to determine the response message of the resource request;

[0026] Send a response message to the BMC client; the response message is used to instruct the BMC client to determine the identity authentication result of the user.

[0027] In the technical solution provided by the embodiment of the present application, the BMC server receives a resource request sent by the BMC client; wherein, the resource request carries encrypted access information, and the encrypted access information is obtained by the BMC client encrypting the user information of the user; according to the encrypted access information, the identity of the user is verified and authorized to determine the response message of the resource request, and then the response message is sent to the BMC client; the response message is used to instruct the BMC client to determine the identity authentication result of the user. In this method, the encrypted access information in the resource request received by the BMC server is encrypted, and the encrypted access information is obtained by encrypting the user information of the BMC client, which improves the security of transmitting user information between the BMC client and the BMC server; the BMC server verifies and authorizes the user's identity through the encrypted access information, further improving the reliability of user identity authentication, thereby improving the access security of the BMC.

[0028] In one embodiment, according to the encrypted access information, verifying and authorizing the identity of the user to determine the response message of the resource request includes:

[0029] Performing decryption processing on the encrypted access information to obtain plaintext access information;

[0030] Verifying the plaintext access information to obtain an information verification result;

[0031] Generating a response message for the resource request according to the information verification result.

[0032] In the technical solution provided by the embodiment of the present application, performing decryption processing on the encrypted access information to obtain plaintext access information, then verifying the plaintext access information to obtain an information verification result, and finally generating a response message for the resource request according to the information verification result. In this method, verifying the obtained plaintext access information after decryption can effectively prevent security problems caused by data tampering during the transmission process, and improve the access reliability and security of the BMC.

[0033] In one embodiment, verifying the plaintext access information to obtain an information verification result includes:

[0034] If the plaintext access information matches the pre-stored user information in the database, it is determined that the information verification result is passed;

[0035] If the plaintext access information does not match the pre-stored user information in the database, it is determined that the information verification result is not passed.

[0036] In the technical solution provided by the embodiment of the present application, if the accessed plaintext information matches the pre-stored user information in the database, it is determined that the information verification result passes; if the accessed plaintext information does not match the pre-stored user information in the database, it is determined that the information verification result fails. In this method, by performing consistency matching between the accessed plaintext information and the preset user information in the database, it is possible to prevent invalid or illegal requests from affecting the BMC, which helps to prevent unauthorized access and attack behaviors and improves the access security of the BMC.

[0037] In one embodiment, according to the information verification result, a response message for the resource request is generated, including:

[0038] If the information verification result passes, according to the accessed plaintext information, obtain the user's user name, permission information, session identifier, and access token;

[0039] Generate user credential information based on the user name, permission information, session identifier, and access token, and determine the response message according to the user credential information.

[0040] In the technical solution provided by the embodiment of the present application, if the information verification result passes, according to the accessed plaintext information, obtain the user's user name, permission information, session identifier, and access token, generate user credential information based on the user name, permission information, session identifier, and access token, and determine the response message according to the user credential information. In this method, by setting permission information for users, it is possible to precisely control the access of users. Different user roles correspond to different permissions, ensuring the access security of the BMC; in addition, the session identifier and access token can manage the session state of the user, ensuring the security of the user's continuous access and operations in the BMC.

[0041] In one embodiment, according to the information verification result, a response message for the resource request is generated, including:

[0042] If the information verification result fails, generate an error prompt message;

[0043] Determine the response message according to the error prompt message.

[0044] In the technical solution provided by the embodiment of the present application, if the information verification result fails, generate an error prompt message; determine the response message according to the error prompt message. In this method, by generating a response message through the error prompt message, it is possible to clearly explain the reason for the failed authentication and the potential risks encountered, which helps to quickly assist the user in locating and solving the problem.

[0045] In a third aspect, the present application further provides an identity authentication device, including:

[0046] An information encryption module, configured to encrypt the user information carried in the access request in response to an access request from the BMC, and generate access ciphertext information;

[0047] A request sending module, configured to send a resource request to the BMC server; the access ciphertext information is carried in the resource request, and is used to instruct the BMC server to authenticate and authorize the user's identity;

[0048] A result determination module, configured to determine the user's identity authentication result according to the response message of the resource request sent by the BMC server.

[0049] In a fourth aspect, the present application further provides an identity authentication device, including:

[0050] A request receiving module, configured to receive a resource request sent by a BMC client; access ciphertext information is carried in the resource request; the access ciphertext information is obtained by encrypting the user information of the user by the BMC client;

[0051] An authentication module, configured to authenticate and authorize the user's identity according to the access ciphertext information, and determine the response message of the resource request;

[0052] A message sending module, configured to send a response message to the BMC client; the response message is used to instruct the BMC client to determine the user's identity authentication result.

[0053] In a fifth aspect, the present application further provides a computer device, including a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps of the method in any one of the above first aspect and second aspect embodiments are implemented.

[0054] In a sixth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method in any one of the above first aspect and second aspect embodiments are implemented.

[0055] In a seventh aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the method in any one of the above first aspect and second aspect embodiments are implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0057] Figure 1 It is an application environment diagram of the identity authentication method in an embodiment;

[0058] Figure 2 It is a schematic flowchart of the identity authentication method in an embodiment;

[0059] Figure 3 It is a schematic flowchart of the identity authentication method in another embodiment;

[0060] Figure 4 It is a schematic flowchart of the identity authentication method in another embodiment;

[0061] Figure 5 It is a schematic flowchart of the identity authentication method in another embodiment;

[0062] Figure 6 It is a schematic flowchart of the identity authentication method in another embodiment;

[0063] Figure 7 It is a schematic flowchart of the identity authentication method in another embodiment;

[0064] Figure 8 It is a schematic flowchart of the identity authentication method in another embodiment;

[0065] Figure 9 It is a schematic flowchart of the identity authentication method in another embodiment;

[0066] Figure 10 It is a schematic flowchart of the identity authentication method in another embodiment;

[0067] Figure 11 It is a schematic flowchart of the identity authentication method in another embodiment;

[0068] Figure 12 It is a structural block diagram of the identity authentication device in an embodiment;

[0069] Figure 13 It is a structural block diagram of the identity authentication device in another embodiment;

[0070] Figure 14 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0071] In order to make the objectives, technical solutions and advantages of this application clearer, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.

[0072] The identity authentication method provided by the embodiments of this application can be applied to, for exampleFigure 1 in the application environment shown. Among them, the BMC client 102 communicates with the BMC server 104 through the network.

[0073] During the operation of the server, BMC provides a remote access management interface for server operation and maintenance personnel to manage and monitor the running status of the entire server in real time. When remotely accessing the BMC management interface through the network, for security reasons, BMC needs to authenticate the identity of remote access personnel to prevent hackers from attacking and illegally accessing the BMC management interface, which may cause security risks such as data leakage, information theft, and abnormal tampering in the operation of the entire server, seriously affecting the secure operation of the server. Therefore, the access security of BMC is crucial.

[0074] In the related art, when remotely accessing BMC through the management interface, first, a login page will be presented on the management interface, allowing the access personnel to enter the username and password. The entered username and password will be transmitted through the network to the BMC server for verification. The BMC server verifies whether the username and password transmitted through the network are correct and then returns the verification result.

[0075] However, in the identity authentication process of the related art, the transmitted username and password are easily stolen and tampered with by black cards, posing a security risk.

[0076] Considering the above factors, the embodiment of the present application provides an identity authentication method. The BMC client encrypts the user information carried in the access request in response to the access request of BMC, generates access ciphertext information, and sends a resource request to the BMC server; the resource request carries the access ciphertext information, which is used to instruct the BMC server to verify and authorize the user's identity; then, according to the response message of the resource request sent by the BMC server, the identity authentication result of the user is determined. By sending the encrypted user information to the BMC server, the security of the user information transmitted between the BMC client and the BMC server is ensured, the security of identity authentication is improved, the risk of user information leakage is reduced, and thus the access security of BMC is improved.

[0077] The following uses specific embodiments to elaborate in detail on the technical solution of the present application and how the technical solution of the present application solves the above technical problems. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0078] In an exemplary embodiment, as Figure 2 shown, an identity authentication method is provided, and this method is applied to Figure 1Taking the Baseboard Management Controller (BMC) client as an example, the following steps are included:

[0079] S201: In response to the access request from the BMC, encrypt the user information carried in the access request to generate access ciphertext information.

[0080] Among them, the BMC client can be the web management end of a browser or an application on a computer device or a terminal device.

[0081] Taking the BMC client as the web management end of a browser as an example, when accessing the BMC, the Internet Protocol (IP) address of the BMC can be entered in the browser to enter the login page of the network management end. The user enters the user information on the login page of the network management end, triggering the access request of the BMC.

[0082] The access request carries user information. The BMC management end will encrypt the user information in the access request and then determine the encrypted user information as the access ciphertext information; among them, the user information can include information such as the username and password.

[0083] The method of encrypting the user information can be a pre-configured encryption algorithm; for example, the Blowfish algorithm, the Advanced Encryption Standard (AES) algorithm, the Data Encryption Standard (DES) algorithm, etc. The embodiments of the present application do not limit the encryption algorithm for user information.

[0084] In another embodiment, the method of encrypting the user information can be to use a neural network model. The user information is used as the input of the neural network model, and after training of the neural network model, the access ciphertext information is finally output.

[0085] In still another embodiment, the method of encrypting the user information can be to use a pre-configured encryption program. The user information is used as the input data of the encryption program, and after running the pre-configured encryption program, the access ciphertext information is obtained.

[0086] S202: Send a resource request to the BMC server; the resource request carries the access ciphertext information, which is used to instruct the BMC server to verify and authorize the user's identity.

[0087] After the BMC client obtains the access ciphertext information, it can generate a resource request based on the request data format for accessing the BMC and the access ciphertext information; among them, the resource request can be a uniform resource locator (URL) request, and the format is: https: / / <bmcip> / securelogin。

[0088] Among them, the data format of the resource request includes a request header part and a request body part. The request header part includes the request method, the response content type Accept that the BMC client can accept, the content encoding method supported by the BMC client, the language type that the BMC client hopes to receive, the management method between the BMC client and the BMC server, the length of the request body, the type of the request body, the target host name of the request, the request source, the request source page, the request header for browser security and privacy control, and the user agent information of the BMC client. The request body part may include access ciphertext information.

[0089] Specifically, the request method can be post or get; the response content type Accept that the BMC client can accept can be application / json, indicating that the BMC client hopes to receive a response message in JSON format; the content encoding methods supported by the BMC client can include gzip, deflate, br, etc.; the management method between the BMC client and the BMC server can be a long connection; the length of the request body can be 72 bytes; the type of the request body can be application / json, indicating that the request body is data in JSON format; the request header for browser security and privacy control is used to indicate the destination, mode, site, and user agent information of the request; the user agent information of the BMC client can include information such as the operating system and browser.

[0090] The BMC client fills the access ciphertext information into the request body of the URL request to obtain a resource request. After generating the resource request, the BMC client sends the resource request to the BMC server.

[0091] After receiving the resource request sent by the BMC client, the BMC server can verify and authorize the user's identity through the access ciphertext information carried in the resource request to verify whether the user's identity is legal and generate a response message for the resource request.

[0092] S203, determine the user's identity authentication result according to the response message of the resource request sent by the BMC server.

[0093] After the BMC server verifies and authorizes the user's identity through the access ciphertext information carried in the resource request, it generates a response message for the resource request and sends the response message of the resource request to the BMC client. The BMC client determines the user's identity authentication result according to the received response message.

[0094] In one embodiment, the response message of the resource request includes the user's identity authentication result, and the BMC server directly obtains the user's identity authentication result from the response message. Among them, the identity authentication result includes authentication failure and authentication success; authentication success means that the user's identity is legal, and authentication failure means that the user's identity is illegal.

[0095] In an embodiment of the present application, the BMC client encrypts the user information carried in the access request in response to the access request of the BMC, generates access ciphertext information, and sends a resource request to the BMC server; the access ciphertext information is carried in the resource request to instruct the BMC server to verify and authorize the user's identity; then, according to the response message of the resource request sent by the BMC server, the user's identity authentication result is determined. In this method, when accessing the BMC through the BMC client, the BMC client encrypts the user information input by the user, which ensures the security of the user information transmission between the BMC client and the BMC server, improves the accuracy of identity authentication, ensures the security and accuracy of the subsequent BMC server's verification and authorization of the access ciphertext information, reduces the risk of user information leakage, and thus improves the access security of the BMC.

[0096] In an exemplary embodiment, as Figure 3 shown, determining the user's identity authentication result according to the response message of the resource request sent by the BMC server includes the following steps:

[0097] S301, when the response message includes user credential information, determine that the user's identity authentication result is authentication success.

[0098] After receiving the response message of the resource request sent by the BMC server, parse the response message to obtain the content carried in the response message. If the response message includes user credential information, it means that the user's identity authentication result is authentication success, that is, the user's information is legal and the user can log in to the BMC client.

[0099] S302, when the response message includes error prompt information, determine that the user's identity authentication result is authentication failure.

[0100] If the response message includes error prompt information, it means that the user's identity authentication result is authentication failure, that is, the user's information is illegal and the user cannot log in to the BMC client.

[0101] In an embodiment of the present application, when the response message includes user credential information, it is determined that the user's identity authentication result is authentication successful; when the response message includes error prompt information, it is determined that the user's identity authentication result is authentication failed. In this method, the BMC client directly determines the user's identity authentication result based on the content in the response message sent by the BMC server, without further inference, improving the accuracy and speed of user identity authentication.

[0102] The user credential information can be the credential when the user accesses the BMC. Therefore, the BMC client can control the user's access to the BMC based on the user credential information. The following provides a detailed description through an embodiment. In an exemplary embodiment, as Figure 4 shown, this embodiment includes the following steps:

[0103] S401, when the response message includes user credential information, obtain the user's permission information from the user credential information.

[0104] The user credential information can include the user's permission information. Therefore, when the response message includes user credential information, the BMC client can obtain the user's permission information from the user credential information.

[0105] Among them, the user's permission information includes the user's ability to be authorized to perform specific operations on the server through the BMC, and the permission information includes the user's permission to access or operate the BMC.

[0106] S402, according to the permission information, open the access permission of the BMC for the user.

[0107] The BMC client can open the corresponding access permission for the user according to the permission information. For example, the user can only access the BMC through the BMC client under this access permission.

[0108] Among them, the access permission can include reading sensor data of the sensor, remotely powering on and off, monitoring the system status of the server, and so on.

[0109] In an embodiment of the present application, when the response message includes user credential information, obtain the user's permission information from the user credential information, and according to the permission information, open the access permission of the BMC for the user. In this method, the access permission of the user is managed through the user's permission information, which can perform fine-grained permission management of feature functions for the user role, realize fine-grained access control, and thus improve the access security of the BMC.

[0110] To ensure that users can persistently access the BMC client, the BMC server can create a session identifier and a token for the user, so that the user remains logged in when logging in to the BMC client. The following is a detailed description. In an exemplary embodiment, as Figure 5 shown, this embodiment includes the following steps:

[0111] S501, in the case where the response message includes user credential information, obtain the user's session identifier and access token from the user credential information.

[0112] Among them, the session identifier is the unique identifier of the session established between the BMC client and the BMC server; the access token is a credential for authentication and authorization, usually containing information about the user's identity and permissions.

[0113] The user credential information includes the user's session identifier and access token. Therefore, the user's session identifier and access token can be directly obtained from the user credential information.

[0114] S502, store the session identifier and access token in a preset cache.

[0115] In a web application, the session identifier can be implemented by using cookies or URL rewriting. The session identifier can be sent to the BMC server in each request of the user, so that the BMC server can identify and track the user's session status. The session identifier can be used to maintain the user's identity status after logging in, authenticate the user when performing sensitive operations, and can also be used to track the user's activities and record the user's preference settings.

[0116] In a web application, the access token is usually used to access protected application programming interfaces (APIs) or resources. The access token can be used to transfer the user's identity and permission information between different systems, so as to perform unified authentication and authorization management when the user performs cross-system operations. Therefore, the session identifier and access token can be stored in the preset cache of the browser.

[0117] In the embodiment of the present application, in the case where the response message includes user credential information, obtain the user's session identifier and access token from the user credential information, and store the session identifier and access token in a preset cache. In this method, storing the session identifier and access token in the cache can be used for subsequent page persistent request access, reducing the repeated authentication process, reducing network overhead and latency, and improving the overall access performance and efficiency of BMC.

[0118] The above is the description of related embodiments with the BMC client as the execution entity. On this basis, the embodiments of the present application also provide corresponding embodiments of the above process with the BMC server as the execution entity. Since all the implementation principles, detailed processes, and achievable technical effects of the following embodiments with the BMC server as the execution entity are the same as those of the above embodiments with the BMC client as the execution entity, for the sake of simplicity and clarity, the following embodiments will not be described in detail one by one, and the implementation process and implementation effects of each embodiment can be referred to the description of the foregoing embodiments.

[0119] As Figure 6 shown, the present application provides an identity authentication method applied to the BMC server, and the method includes the following steps:

[0120] S601, receiving a resource request sent by the BMC client; the resource request carries access ciphertext information; the access ciphertext information is obtained by the BMC client encrypting the user's user information.

[0121] Among them, the resource request is sent by the BMC client based on the communication interface with the BMC server; after the BMC server receives the resource request sent by the BMC client, the BMC server can parse the resource request according to the interface routing between the BMC client and the BMC server to obtain the access ciphertext information in the resource request.

[0122] Specifically, after the BMC server receives the resource request and determines that the resource request is an access request, the resource request can be processed through the processing function corresponding to the access request to obtain the access ciphertext information in the resource request.

[0123] S602, verifying and authorizing the user's identity according to the access ciphertext information, and determining the response message of the resource request.

[0124] Among them, the response message of the resource request may include user credential information and error prompt information. The BMC server verifies and authorizes the user's identity through the access ciphertext information, and determines the response message of the resource request according to the result of the verification and authorization.

[0125] Specifically, the access ciphertext information can be directly compared with the trusted access ciphertext information pre-stored in the database. If there is a trusted access ciphertext in the trusted access ciphertext information that is the same as the access ciphertext information, the user credential information corresponding to the trusted access ciphertext that is the same as the access ciphertext information is obtained; then the user credential information is determined as the response message of the resource request.

[0126] If there is no trusted access ciphertext in the trusted access ciphertext information that is the same as the access ciphertext information, an error prompt message for the access ciphertext information is generated, and the error prompt message is determined as the response message of the resource request; the error prompt message can indicate that the user's access ciphertext information is illegal.

[0127] S603, send a response message to the BMC client; the response message is used to instruct the BMC client to determine the user's identity authentication result.

[0128] After the BMC server generates the response message of the resource request, it can send the response message of the resource request to the BMC client. After receiving the response message, the BMC client can determine the user's identity authentication result based on the response message.

[0129] In the embodiment of the present application, the BMC server receives a resource request sent by the BMC client; among them, the access ciphertext information is carried in the resource request, and the access ciphertext information is obtained by the BMC client encrypting the user information of the user; according to the access ciphertext information, the identity of the user is verified and authorized to determine the response message of the resource request, and then a response message is sent to the BMC client; the response message is used to instruct the BMC client to determine the user's identity authentication result. In this method, the access ciphertext information in the resource request received by the BMC server is encrypted, and the access ciphertext information is obtained by encrypting the user information of the BMC client, which improves the security of transmitting user information between the BMC client and the BMC server; the BMC server verifies and authorizes the user's identity through the access ciphertext information, further improving the reliability of user identity authentication, thereby improving the access security of the BMC.

[0130] The process of directly verifying and authorizing the access ciphertext information is described in the above embodiments. Below, through an embodiment, another implementation manner of verifying and authorizing the user's identity according to the access ciphertext information is described.

[0131] In an exemplary embodiment, as Figure 7 shown, verifying and authorizing the user's identity according to the access ciphertext information to determine the response message of the resource request includes the following steps:

[0132] S701, perform decryption processing on the access ciphertext information to obtain access plaintext information.

[0133] The information obtained after performing decryption processing on the access ciphertext information is the access plaintext information.

[0134] In one embodiment, the BMC server decrypts the access ciphertext information according to a preset decryption algorithm to obtain the access plaintext information. The preset decryption algorithm can be the inverse algorithm of the encryption algorithm used for encrypting the user information above.

[0135] In another embodiment, the way to decrypt the access ciphertext information can be to use a neural network model. The access ciphertext information is used as the input of the neural network model. After training the neural network model, the access plaintext information is finally output.

[0136] In still another embodiment, the way to decrypt the access ciphertext information can be to use a pre-configured decryption program. The access ciphertext information is used as the input data of the decryption program. After running the pre-configured decryption program, the access plaintext information is obtained.

[0137] S702, verify the access plaintext information to obtain an information verification result.

[0138] Among them, the information verification result includes passed and not passed.

[0139] The access plaintext information can be hashed to obtain hash data. The hash data is compared with the hash password stored in the database. If the hash data is consistent with the hash password in the database, it is determined that the access plaintext information verification is passed; otherwise, the verification fails.

[0140] It is also possible to directly check and match the access plaintext information with the pre-stored user information in the database. Specifically, in an exemplary embodiment, as Figure 8 shown, verifying the access plaintext information to obtain an information verification result includes the following steps:

[0141] S801, if the access plaintext information matches the pre-stored user information in the database, it is determined that the information verification result is passed.

[0142] Among them, the pre-stored user information can be the user information authorized to access the BMC.

[0143] If the access plaintext information matches the pre-stored user information in the database, that is, there is pre-stored user information in the database that is the same as the access plaintext information, it is determined that the information verification result is passed.

[0144] S802, if the access plaintext information does not match the pre-stored user information in the database, it is determined that the information verification result is not passed.

[0145] If the access plaintext information does not match the pre-stored user information in the database, indicating that there is no pre-stored user information in the database that is the same as the access plaintext information, it is determined that the information verification result is not passed.

[0146] In this embodiment, if the accessed plaintext information matches the pre-stored user information in the database, it is determined that the information verification result passes; if the accessed plaintext information does not match the pre-stored user information in the database, it is determined that the information verification result fails. In this method, by performing a consistency match between the accessed plaintext information and the preset user information in the database, it is possible to prevent invalid or illegal requests from affecting the BMC, which helps to prevent unauthorized access and attack behaviors and improves the access security of the BMC.

[0147] S703. Generate a response message for the resource request according to the information verification result.

[0148] The BMC server has pre-stored the corresponding response messages when the information verification result passes and fails.

[0149] Therefore, the response message corresponding to the information verification result can be directly used as the response message for the resource request.

[0150] In the embodiment of the present application, the accessed ciphertext information is decrypted to obtain the accessed plaintext information, and then the accessed plaintext information is verified to obtain the information verification result. Finally, a response message for the resource request is generated according to the information verification result. In this method, verifying the accessed plaintext information obtained after decryption can effectively prevent security problems caused by data being tampered with during transmission, and improves the access reliability and security of the BMC.

[0151] In an exemplary embodiment, as Figure 9 shown, generating a response message for the resource request according to the information verification result includes the following steps:

[0152] S901. If the information verification result passes, obtain the user name, permission information, session identifier, and access token of the user according to the accessed plaintext information.

[0153] If the information verification result passes, the accessed plaintext information is the user information of the user, and the accessed plaintext information may include the user name and password. Therefore, the user name of the user can be directly obtained from the accessed plaintext information.

[0154] In addition, the permission information of the user corresponding to the user name can be queried from the database, and then a session identifier (SESION ID) and an access token are created for the user. Among them, the access token can be a cross-site request forgery token (Cross-siterequest forgery-TOKEN, XSRF-TOKEN).

[0155] S902. Generate user credential information according to the user name, permission information, session identifier, and access token, and determine the response message according to the user credential information.

[0156] After the BMC server obtains the user name, permission information, session identifier, and access token, it can use the user name, permission information, session identifier, and access token as user credential information, and the user credential information is used to authorize the user to access the BMC.

[0157] Then, based on the user name, permission information, session identifier, and access token, and based on the response data format of the response to the BMC client, a response message for the resource request is generated; wherein, the response message includes a response header and a response body.

[0158] The user name and permission information can be filled into the response body of the response message, and the session identifier and access token can be filled into the response header of the response message.

[0159] Among them, the response header includes the Hyper Text Transfer Protocol (HTTP) version, response status code, session identifier, access token, transport security policy type, BMC client settings, cross-site scripting attack protection mechanism, prohibiting the browser from inferring the response content type according to the response Multipurpose Internet Mail Extensions (MIME) type, security content policy, etc.; the response body includes the user name, permission information, response status, etc. Among them, the response status code is 200, indicating that the request is successful.

[0160] In the embodiment of the present application, if the information verification result is passed, the user name, permission information, session identifier, and access token of the user are obtained according to the access plaintext information, and the user credential information is generated according to the user name, permission information, session identifier, and access token, and the response message is determined according to the user credential information. In this method, by setting permission information for users, the access of users can be precisely controlled, and different user roles correspond to different permissions, ensuring the access security of the BMC; in addition, the session identifier and access token can manage the session state of the user, ensuring the security of the user's continuous access and operations in the BMC.

[0161] The above embodiment describes how to generate a response message for a resource request when the information verification result is passed. The following describes how to generate a response message for a resource request when the information verification result is not passed through an embodiment.

[0162] In an exemplary embodiment, as Figure 10 shown, generating a response message for a resource request according to the information verification result includes the following steps:

[0163] S1001, if the information verification result is not passed, an error prompt message is generated.

[0164] S1002. Determine the response message according to the error prompt information.

[0165] If the information verification result fails, an error prompt message is generated. The error prompt message is used to prompt corresponding page prompts on the BMC client. The error prompt message may include authentication failure and unauthorized.

[0166] Then, according to the error prompt message and the response data format, a response message is generated. Specifically, the response message includes a response header and a response body. The response header includes the HTTP protocol version, the response status code, etc. Among them, the response status code is 400, indicating that the request is invalid or illegal. The response body includes an error code and an error prompt message.

[0167] In the embodiment of the present application, if the information verification result fails, an error prompt message is generated; the response message is determined according to the error prompt message. In this method, generating a response message through the error prompt message can clearly explain the reason for the failed authentication and the potential risks encountered, which helps users quickly locate and solve problems.

[0168] In an exemplary embodiment, as Figure 11 shown, this embodiment includes the following steps:

[0169] S1101. The user enters the IP address of the BMC in the browser of the BCM client, jumps to the login page, and enters the username and password on the login page.

[0170] S1102. The BCM client calls a preset algorithm library to encrypt the username and password, generates a URL request according to the encrypted username and password, and sends the URL request to the BMC server; the URL request includes the encrypted username and password.

[0171] S1103. The BMC server receives the URL request, determines the processing function of the URL request through the routing interface, and obtains the encrypted username and password in the URL request.

[0172] S1104. Decrypt the encrypted username and password through a preset algorithm library to obtain the plaintext username and password.

[0173] S1105. Check and match the plaintext username and password with the username and password pre-stored in the database of the BMC server.

[0174] S1106, if the consistency match is successful, query the user permissions of the corresponding user, create a session identifier and an access token; and return information such as the authenticated username and user permissions in the response body of the login authentication URL request, and return information such as the session identifier and access token in the response header of the URL request, and send the response message to the BMC client.

[0175] S1107, if the consistency match fails, return unauthorized authentication failure in the response body of the login authentication URL request, and send the response message to the BMC client.

[0176] S1108, the BMC client receives the response message of the URL request returned by the BMC server and performs corresponding operations according to the response message.

[0177] Among them, if the consistency match is successful, read the user permissions from the response message, and according to the user permissions, determine the permissions that the user can view or operate on the BMC access page, and save the session identifier and access token saved in the response header to the browser's cookie; if the consistency match fails, perform corresponding page prompts according to the error return information of the backend.

[0178] In the embodiments of the present application, a method for secure identity authentication and secure authorized access of the BMC system WEB interface is provided. When the BMC client browser accesses by entering the IP address of the BMC, a login page will first pop up for entering the login username and password, and sensitive important information such as the username and password entered by the user will be encrypted in the front-end code, and then passed to the BMC server. After receiving the encrypted data, the BMC server decrypts it reversely to obtain the actual plaintext information, and then verifies and matches the received username and password with the user password preset in the BMC server. After passing the match, access authorization is performed to ensure the secure authentication and authorized access of the BMC and improve the security of BMC access.

[0179] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.

[0180] Based on the same inventive concept, an embodiment of the present application further provides an identity authentication device for implementing the above-mentioned identity authentication method. The implementation solution provided by this device to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the identity authentication device provided below can refer to the limitations on the identity authentication method in the above text, and will not be elaborated here.

[0181] In an exemplary embodiment, as Figure 12 shown, an identity authentication device is provided, including: an information encryption module 1201, a request sending module 1202, and a result determination module 1203, where:

[0182] The information encryption module 1201 is configured to encrypt the user information carried in the access request in response to the access request of the BMC, and generate access ciphertext information;

[0183] The request sending module 1202 is configured to send a resource request to the BMC server; the access ciphertext information is carried in the resource request, and is used to instruct the BMC server to verify and authorize the user's identity;

[0184] The result determination module 1203 is configured to determine the identity authentication result of the user according to the response message of the resource request sent by the BMC server.

[0185] In an exemplary embodiment, the result determination module 1203 includes:

[0186] The first determination unit is configured to determine that the identity authentication result of the user is authentication successful when the response message includes user credential information;

[0187] The second determination unit is configured to determine that the identity authentication result of the user is authentication failed when the response message includes error prompt information.

[0188] In an exemplary embodiment, the device further includes:

[0189] The first acquisition module is configured to acquire the user's permission information from the user credential information when the response message includes user credential information;

[0190] The permission opening module is configured to open the access permission of the BMC for the user according to the permission information.

[0191] In an exemplary embodiment, the device further includes:

[0192] The second acquisition module is configured to acquire the user's session identifier and access token from the user credential information when the response message includes user credential information;

[0193] A storage module for storing a session identifier and an access token in a preset cache.

[0194] In an exemplary embodiment, as Figure 13 shown, an identity authentication device is further provided, including: a request receiving module 1301, a verification module 1302, and a message sending module 1303, where:

[0195] The request receiving module 1301 is configured to receive a resource request sent by a BMC client; the resource request carries access ciphertext information; the access ciphertext information is obtained by encrypting the user information of the user by the BMC client;

[0196] The verification module 1302 is configured to verify and authorize the identity of the user according to the access ciphertext information, and determine a response message of the resource request;

[0197] The message sending module 1303 is configured to send a response message to the BMC client; the response message is used to instruct the BMC client to determine the identity authentication result of the user.

[0198] In an exemplary embodiment, the verification module 1302 includes:

[0199] A decryption unit for decrypting the access ciphertext information to obtain access plaintext information;

[0200] A verification unit for verifying the access plaintext information to obtain an information verification result;

[0201] A generation unit for generating a response message of the resource request according to the information verification result.

[0202] In an exemplary embodiment, the verification unit includes:

[0203] A first matching subunit for determining that the information verification result is passed if the access plaintext information matches the pre-stored user information in the database;

[0204] A second matching subunit for determining that the information verification result is not passed if the access plaintext information does not match the pre-stored user information in the database.

[0205] In an exemplary embodiment, the generation unit includes:

[0206] An obtaining subunit for obtaining the user name, permission information, session identifier, and access token of the user according to the access plaintext information if the information verification result is passed;

[0207] A first determination subunit, configured to generate user credential information according to a user name, permission information, a session identifier, and an access token, and determine a response message according to the user credential information.

[0208] In an exemplary embodiment, the generation unit includes:

[0209] A generation subunit, configured to generate an error prompt message if the information verification result fails;

[0210] A second determination subunit, configured to determine a response message according to the error prompt message.

[0211] Each module in the above identity authentication device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0212] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 14 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store identity authentication data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements an identity authentication method.

[0213] Those skilled in the art can understand that Figure 14 the structure shown in

[0214] is only a block diagram of a part of the structure related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout. In an embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0215] In this embodiment, the steps implemented by the processor have similar implementation principles and technical effects to those of the above identity authentication method, which will not be elaborated here.

[0216] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0217] In this embodiment, the steps implemented when the computer program is executed by the processor have similar implementation principles and technical effects to those of the above identity authentication method, which will not be elaborated here.

[0218] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0219] In this embodiment, the steps implemented when the computer program is executed by the processor have similar implementation principles and technical effects to those of the above identity authentication method, which will not be elaborated here.

[0220] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0221] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memories can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0222] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0223] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.< / bmcip>

Claims

1. An identity authentication method, characterized in that, Applied to the Baseboard Management Controller (BMC) client, the method includes: In response to an access request from the BMC, encrypt the user information carried in the access request to generate access ciphertext information; Send a resource request to the BMC server; the access ciphertext information is carried in the resource request, which is used to instruct the BMC server to authenticate and authorize the user's identity; Determine the user's identity authentication result according to the response message of the resource request sent by the BMC server.

2. The method according to claim 1, characterized in that, The determining the user's identity authentication result according to the response message of the resource request sent by the BMC server includes: When the response message includes user credential information, determine that the user's identity authentication result is successful authentication; When the response message includes error prompt information, determine that the user's identity authentication result is failed authentication.

3. The method according to claim 1 or 2, characterized in that, The method further includes: When the response message includes user credential information, obtain the user's permission information from the user credential information; Open the access permission of the BMC for the user according to the permission information.

4. The method according to claim 1 or 2, characterized in that, The method further includes: When the response message includes user credential information, obtain the user's session identifier and access token from the user credential information; Store the session identifier and the access token in a preset cache.

5. An identity authentication method, characterized in that, Applied to the BMC server, the method includes: Receive a resource request sent by the BMC client; the access ciphertext information is carried in the resource request; the access ciphertext information is obtained by encrypting the user information of the user by the BMC client; Authenticate and authorize the user's identity according to the access ciphertext information to determine the response message of the resource request; Send the response message to the BMC client; the response message is used to instruct the BMC client to determine the user's identity authentication result.

6. The method according to claim 5, characterized in that, The authenticating and authorizing the user's identity according to the access ciphertext information to determine the response message of the resource request includes: Decrypt the access ciphertext information to obtain access plaintext information; Verify the access plaintext information to obtain an information verification result; Generate the response message of the resource request according to the information verification result.

7. The method according to claim 6, characterized in that, The verifying the access plaintext information to obtain an information verification result includes: If the access plaintext information matches the pre-stored user information in the database, determine that the information verification result is passed; If the access plaintext information does not match the pre-stored user information in the database, determine that the information verification result is not passed.

8. The method according to claim 6 or 7, characterized in that, The generating the response message of the resource request according to the information verification result includes: If the information verification result is passed, obtain the user's user name, permission information, session identifier and access token according to the access plaintext information; Generate user credential information according to the user name, the permission information, the session identifier and the access token, and determine the response message according to the user credential information.

9. The method according to claim 6 or 7, characterized in that, Generating a response message for the resource request according to the information verification result includes: If the information verification result fails, generating an error prompt message; Determining the response message according to the error prompt message.

10. An identity authentication device, characterized in that, The device includes: An information encryption module, configured to encrypt the user information carried in the access request in response to an access request from the BMC, and generate an access ciphertext message; A request sending module, configured to send a resource request to the BMC server; the resource request carries the access ciphertext message, and is used to instruct the BMC server to verify and authorize the identity of the user; A result determination module, configured to determine the identity authentication result of the user according to the response message of the resource request sent by the BMC server.

Citation Information

Cited By

  • Authentication management method of BMC of server and related device

    CN121396669A