Server, data interaction method, device, storage medium and program product
By introducing complex programmable logic devices into the server, receiving and verifying the serial port authorization identifier of the target device and determining its access permissions, the problem of low server information security is solved, and fine control of the serial port access permissions of different target devices is achieved, and information security is improved.
Patent Information
- Application Number
- CN202510715834.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-05-30
AI Technical Summary
In the prior art, the server's serial port communication lacks an effective identity authentication mechanism, resulting in low information security. Unauthorized personnel can easily access the server through the serial port and obtain or tamper with data.
A server is designed that includes complex programmable logic devices that can receive the serial port authorization identifier of the target device, determine the target serial port and its access permissions that are allowed to be accessed, and control the target device to interact with the target server components for data.
By finely controlling the serial port access permissions of the target device, preventing unauthorized data leakage or configuration tampering, significantly improving the information security of the server.
Smart Images

Figure CN120234841A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of servers, and particularly to servers, data interaction methods, devices, storage media, and program products. Background Art
[0002] As one of the important interfaces for a server to communicate with external devices, the serial port of the server is widely used in scenarios such as device debugging, configuration management, and emergency maintenance. In some current technologies, the serial communication protocol lacks an effective identity authentication mechanism, resulting in some unauthorized personnel being able to easily access the server through the serial port, obtain data information in the server, or tamper with the server configuration, and the information security of the server is relatively low. Summary of the Invention
[0003] This application provides a server, a data interaction method, an electronic device, a computer-readable storage medium, and a computer program product to at least solve the problem of relatively low information security of the server in related technologies.
[0004] This application provides a server, including: At least one server component; A complex programmable logic device, including a device port and at least one serial port. The device port is used to connect to a target device, and each serial port is used to connect to one of the server components. The complex programmable logic device is used to receive the serial port authorization identifier of the target device, and based on the serial port authorization identifier, determine the target serial port allowed for the target device to access and the access permission of the target serial port, and connect the target device to the target serial port, and control the target server component connected to the target serial port by the target device to perform data interaction according to the access permission of the target serial port, where the access permission represents the data interaction operation allowed for the target device to perform through the target serial port.
[0005] This application also provides a data interaction method, including: Receiving the serial port authorization identifier of the target device, where the serial port authorization identifier is used to represent the permission range of the target device when accessing the serial port; Based on the serial port authorization identifier, determining the target serial port allowed for the target device to access and the access permission of the target serial port, where the access permission represents the data interaction operation allowed for the target device to perform through the target serial port; Connecting the target device to the target serial port, where the target serial port is connected to a target server component, and when the target device is connected to the target serial port, the target device is connected to the target server component; Control the data interaction between the target device and the target server component according to the access permission of the target serial port.
[0006] The present application also provides an electronic device, which includes a processor and a memory. The memory is used to store a computer program. When the computer program is executed by the processor, the steps of the above data interaction method are implemented.
[0007] The present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the above data interaction method are implemented.
[0008] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of the above data interaction method are implemented.
[0009] In the technical solutions of some embodiments of the present application, in the case of determining the target serial port allowed for the target device to access and the access permission of the target serial port based on the serial port authorization identifier, one or more serial port authorization identifiers can be set, and the permission ranges of at least some of the serial port authorization identifiers can be different. Furthermore, the serial port authorization identifiers can be allocated to each target device according to actual needs, so that the serial port access permissions of different target devices can be finely controlled, preventing unauthorized personnel from obtaining data information in the server or tampering with the server configuration through the serial port. In this way, the information security of the server can be improved, and the problem of relatively low information security of the server in the related art is solved. Description of the Drawings
[0010] In order to more clearly illustrate the embodiments of the present application, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0011] Figure 1 A schematic diagram of the server serial port design in some technologies; Figure 2 A schematic diagram of the architecture of the server provided by some embodiments of the present application; Figure 3 A specific switch circuit diagram between one of the serial ports and the device ports provided by some embodiments of the present application; Figure 4 A schematic diagram of the connection between the server and the target device provided by some embodiments of the present application; Figure 5 A schematic diagram of the flow of the data interaction method provided by some embodiments of the present application; Figure 6 Schematic diagram of modules of an electronic device provided for some embodiments of the present application. Detailed implementation manners
[0012] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part rather than all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0013] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements includes not only those elements but also other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0014] To enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific implementation manners.
[0015] With reference to Figure 1 , a schematic diagram of the serial port design of a server in some technologies. Figure 1 In, the target device 13 is an external device connected to the server (such as a laptop used by maintenance personnel, etc.). The server may include a central processing unit 12 (Central Processing Unit, CPU), a baseboard management controller 11 (Baseboard Management Controller, BMC), a management serial port 111, a system serial port 121, a system serial port connector 14, a management serial port connector 15, an eSPI (Embedded Serial Peripheral Interface) line 122, a first UART (Universal Asynchronous Receiver / Transmitter) line 141, and a second UART line 151. The system serial port connector 14 is connected to the baseboard management controller 11 through the first UART line 141, and the baseboard management controller 11 is connected to the system serial port 121 through the eSPI line 122. The management serial port connector 15 is connected to the management serial port 111 through the second UART line 151.
[0016] The system serial port connector 14 and the management serial port connector 15 can be used to transmit UART data. Since the target device 13 usually includes a USB (Universal Serial Bus) interface and does not include a UART interface, the target device 13 can be connected to the system serial port connector 14 and the management serial port connector 15 through a serial port conversion device 16. The serial port conversion device 16 converts the USB data output by the target device 13 into UART data, or converts the UART data sent by the server to the target device 13 into USB data.
[0017] The central processing unit 12 can be used to run the basic input / output system (i.e., BIOS, Basic Input / Output System) or the operating system. The system serial port 121 can serve as a communication channel for the central processing unit 12 to communicate externally. For example, serial port data (such as device debugging information, configuration instructions, etc.) generated during the operation of the basic input / output system or the operating system can be transmitted to the baseboard management controller 11 through the system serial port 121. After parsing these serial port data, the baseboard management controller 11 can send the parsed data to the system serial port connector 14, and then send the data to the target device 13 through the system serial port connector 14. Conversely, during the operation of the basic input / output system or the operating system, the target device 13 can also send data to the basic input / output system or the operating system through the system serial port connector 14, the baseboard management controller 11, and the system serial port 121.
[0018] The management serial port 111 can serve as a communication channel for the baseboard management controller 11 to communicate externally, and is mainly used for remote management and monitoring of the server. For example, after connecting the target device 13 to the serial port conversion device 16, maintenance personnel can send instructions to the baseboard management controller 11 through the management serial port connector 15 and the management serial port 111, so as to perform operations such as remote configuration and fault diagnosis on the server.
[0019] In Figure 1 the technology shown, as a serial port protocol, the UART protocol lacks an effective identity authentication mechanism, resulting in some unauthorized personnel being able to access the server relatively easily through the system serial port 121 or the management serial port 111, obtain the data information in the server or tamper with the server configuration, and the information security of the server is relatively low. For example, in some enterprise internal networks that do not adopt strict security protection measures, unauthorized personnel can take advantage of the convenience of the serial port physical connection to bypass the complex network security protection system and directly attack the server, seriously threatening the information security of the server.
[0020] In some other technologies, although control policies for serial port access are set in the server, these control policies are usually set based on the IP (Internet Protocol) address or MAC (Media Access Control) address of the target device 13, which is relatively crude and cannot finely divide the serial port access permissions of different users using the same target device 13. Therefore, there are also problems such as data leakage or system failures caused by excessive user permissions or user abuse of permissions.
[0021] To improve the information security of the server and solve the problem of relatively low information security of the server in related technologies, the present application first provides a server 200. Referring in combination to Figure 2 is a schematic diagram of the architecture of the server 200 provided by some embodiments of the present application. Figure 2 In, the server 200 includes a complex programmable logic device 27 and at least one server component 29. Among them, the server component 29 refers to a component that needs to perform data interaction with the target device 23, such as a baseboard management controller 21, a central processing unit 22, an OCP (Open Compute Project) network card (not shown), a smart network card (not shown), etc.
[0022] The complex programmable logic device 27 includes a device port 272 and at least one serial port 271. Among them, the device port 272 is used to connect to the target device 23. Similar to Figure 1 The target device 23 refers to an external device connected to the server 200. The target device 23 can be connected to the device port 272 through a serial port conversion device 26. Each serial port 271 is used to connect to one of the server components 29. For example, serial ports P1 and P2 are connected to the baseboard management controller 21, and serial port P3 is connected to the smart network card.
[0023] Specifically, taking Figure 2Taking the central processing unit 22 and the baseboard management controller 21 in it as an example. The server 200 may include a management serial port 211, a system serial port 221, a system serial port connector 24, a management serial port connector 25, an eSPI line 222, a first UART line 241, and a second UART line 251. The central processing unit 22 is connected to the baseboard management controller 21 through the system serial port 221 and the eSPI line 222. The baseboard management controller 21 is connected to the system serial port connector 24 through the first UART line 241. The system serial port connector 24 is connected to one of the serial ports 271 (such as serial port P2) of the complex programmable logic device 27. In this way, the connection between the serial port P2 and the central processing unit 22 is realized. Further, the baseboard management controller 21 is connected to the management serial port connector 25 through the management serial port 211 and the second UART line 251. The management serial port connector 25 is connected to another serial port 271 (such as serial port P1) of the complex programmable logic device 27. In this way, the connection between the serial port P1 and the baseboard management controller 21 is realized.
[0024] Based on the above serial port design architecture, a serial port authorization identifier can be pre-assigned to the target device 23 according to the serial port access permissions allowed for the maintenance personnel using the target device 23. The serial port authorization identifier is used to characterize the permission range of the target device 23 when accessing the serial port. The permission range characterizes the serial ports 271 that the devices with each serial port authorization identifier are allowed to access and the access permissions of the serial ports 271. Among them, access means that the target device 23 performs data interaction with the server component 29 connected to the serial port 271 through the serial port 271. The access permission characterizes the data interaction operations that the target device 23 is allowed to perform through the target serial port 271. The data interaction operations include reading data from the target server component 29 and writing data to the target server component 29. For example, when the serial port authorization identifier of the target device 23 is AA1, it can be indicated that the target device 23 is allowed to access the serial ports P1 and P2, and the target device 23 is not allowed to access the serial ports P3 and P4. And, during the access to the serial port P1, only the target device 23 is allowed to read data from the target server component 29 connected to the serial port P1, and during the access to the serial port P2, the target device 23 is allowed to read data and write data to the target server component 29 connected to the serial port P2. Another example is that when the serial port authorization identifier of the target device 23 is AA2, it can be indicated that the target device 23 is allowed to access the serial port P1, the target device 23 is not allowed to access the serial ports P2, P3, and P4, and during the access to the serial port P1, the target device 23 is allowed to read and write data in the server component 29 connected to the serial port P1.
[0025] When the maintenance personnel connect the target device 23 to the device port 272, the complex programmable logic device 27 can default to control each serial port 271 to disconnect from the device port 272. After the maintenance personnel input the assigned serial port authorization identifier in the target device 23, the target device 23 can send the serial port authorization identifier to the complex programmable logic device 27. The complex programmable logic device 27 is used to receive the serial port authorization identifier of the target device 23, determine the target serial port 271 allowed for the target device 23 to access and the access permission of the target serial port 271, connect the target device 23 to the target serial port 271, and control the target server component 29 connected to the target serial port 271 by the target device 23 to perform data interaction according to the access permission of the target serial port 271. In this way, fine-grained control of the serial port access permission of the target device 23 can be achieved, and the information security of the server 200 can be improved.
[0026] Continue to refer to Figure 1 。In some embodiments, a switch circuit 274 is included between the device port 272 of the complex programmable logic device 27 and each serial port 271. By controlling the switch circuit 274 between the device port 272 and the target serial port 271 to be closed or opened, the complex programmable logic device 27 can control the connection or disconnection between the target device 23 and the target serial port 271, and further control the server component 29 that performs data interaction with the target device 23.
[0027] For example, Figure 2 In, when the complex programmable logic device 27 controls the switch circuit 274 to connect the serial port P2 to the device port 272, the device port 272 of the complex programmable logic device 27, the serial port P2, the system serial port connector 24, the first UART line 241, the baseboard management controller 21, the eSPI line 222, and the system serial port 221 can form a first communication line. The target device 23 can perform data interaction with the central processing unit 22 through the first communication line, such as reading data or writing data in the central processing unit 22. On the contrary, when the complex programmable logic device 27 controls the switch circuit 274 to disconnect the serial port P2 from the device port 272, the target device 23 cannot perform data interaction with the central processing unit 22.
[0028] Similarly, when the complex programmable logic device 27 controls the switch circuit 274 to connect the serial port P1 to the device port 272, the device port 272, the serial port P1, the management serial port connector 25, the second UART line 251, and the management serial port 211 of the complex programmable logic device 27 can form a second communication line. Through the second communication line, the target device 23 can interact with the baseboard management controller 21, such as sending instructions to the baseboard management controller 21 for remote configuration, fault diagnosis, etc. of the server 200. Conversely, when the complex programmable logic device 27 controls the switch circuit 274 to disconnect the serial port P1 from the device port 272, the target device 23 cannot interact with the baseboard management controller 21.
[0029] Further, with reference to Figure 3 , a specific circuit diagram of one of the switch circuits 274 provided in some embodiments of the present application is shown. Figure 3 In , the switch circuit 274 includes a write switch circuit 2741 and a read switch circuit 2742. When the complex programmable logic device 27 controls the read switch circuit 2742 between the device port 272 and the target serial port 271 to close, the target device 23 reads data from the target server component 29 through the read switch circuit 2742; when the complex programmable logic device 27 controls the write switch circuit 2741 between the device port 272 and the target serial port 271 to close, the target device 23 writes data to the target server component 29 through the write switch circuit 2741. Specifically, when the access permission of the target serial port 271 includes the read permission, the complex programmable logic device 27 can control the read switch circuit 2742 between the device port 272 and the target serial port 271 to close. In this way, the target device 23 can read data from the target server component 29 through the read switch circuit 2742. Similarly, when the access permission of the target serial port 271 includes the write permission, the complex programmable logic device 27 can control the write switch circuit 2741 between the device port 272 and the target serial port 271 to close. In this way, the target device 23 can write data to the target server component 29 through the write switch circuit 2741.
[0030] Conversely, when the access permission of the target serial port 271 does not include the read permission, the complex programmable logic device 27 can control the read switch circuit 2742 between the target serial port 271 and the device port 272 to disconnect. In this way, the target device 23 cannot read data from the target server component 29. Similarly, when the access permission of the target serial port 271 does not include the write permission, the complex programmable logic device 27 can control the write switch circuit 2741 between the target serial port 271 and the device port 272 to disconnect. In this way, the target device 23 cannot write data to the target server component 29.
[0031] Figure 3 In this case, a write switch circuit 2741 and a read switch circuit 2742 are provided between the target serial port 271 and the device port 272, and based on the access permission of the target serial port 271, the on / off states of the write switch circuit 2741 and the read switch circuit 2742 are controlled, which can effectively prevent the target device 23 from performing data interaction operations outside the permissions in the target server component 29, thereby improving the information security of the server 200.
[0032] In some embodiments, when the target device 23 is allowed to access at least one target serial port 271, the complex programmable logic device 27 can display the target serial ports 271 allowed for the target device 23 to access through a display device. The maintenance personnel can select one of the displayed target serial ports 271 that needs to be accessed. In response to the target serial port selection operation, the complex programmable logic device 27 determines the selected target serial port 271 and connects the target device 23 to the selected target serial port 271. In this way, when the target device 23 is allowed to access multiple target serial ports 271, data conflicts at the device port 272 can be avoided.
[0033] Continue to refer to Figure 2 . In this embodiment, the complex programmable logic device 27 further includes a storage port 273. The storage port 273 is used to connect to the memory 28. The memory 28 includes a permission storage area, and the permission storage area is used to store at least one serial port authorization identifier and the permission range corresponding to each serial port authorization identifier. After receiving the serial port authorization identifier of the target device 23, the complex programmable logic device 27 can determine the permission range of the target device 23 based on the information in the permission storage area, that is, determine the target serial ports 271 allowed for the target device 23 to access and the access permissions of the target serial ports 271. Specifically, the serial port authorization identifier sent by the target device 23 can be used as the first serial port authorization identifier, and the first serial port authorization identifier is compared with the serial port authorization identifiers in the permission storage area. If there is a second serial port authorization identifier in the permission storage area that is the same as the first serial port authorization identifier, the permission range corresponding to the second serial port authorization identifier can be used as the permission range of the target device 23. If there is no second serial port authorization identifier in the permission storage area that is the same as the first serial port authorization identifier, it means that the target device 23 is not authorized to access any serial port 271 of the complex programmable logic device 27. In this case, the disconnection state between each serial port 271 and the device port 272 can be maintained. In this way, data information leakage in the server 200 or server configuration tampering can be prevented, and information security can be improved.
[0034] For example, assume that the serial port authorization identifiers and permission ranges stored in the permission storage area are as shown in Table 1.
[0035] Table 1 Serial Port Authorization Identification and Permission Scope
[0036] Based on Table 1, assume that maintenance personnel a1 connect the target device 23 to device port 272 and input the serial port authorization identification AA1 into the target device 23. Since the serial port authorization identification AA1 exists in the permission storage area, the write switch circuit 2741 and read switch circuit 2742 between the serial port P1 and the device port 272 can be controlled to be connected according to the permission scope corresponding to the serial port authorization identification AA1 in the permission storage area, and the read switch circuit 2742 between the serial port P2 and the device port 272 can be controlled to be connected, and the write switch circuit 2741 between the serial port P2 and the device port 272 can be controlled to be disconnected. In this way, the serial port access permission of the target device 23 can be accurately controlled to prevent data leakage of the server 200 or the server configuration from being tampered with.
[0037] Conversely, assume that maintenance personnel a2 connect the target device 23 to device port 272 and input the serial port authorization identification AA4 into the target device 23. Since the serial port authorization identification AA4 does not exist in the permission storage area, it can be controlled that the connection between each serial port 271 and the device port 272 continues to be in the disconnected state. In this way, unauthorized maintenance personnel can be prevented from accessing the server 200 through the serial port, ensuring the information security of the server 200.
[0038] In some embodiments, the memory 28 further includes a restricted instruction storage area for storing restricted instructions of each serial port 271. The so-called restricted instruction of the serial port 271 refers to an instruction that the target device 23 cannot send through the serial port 271. The complex programmable logic device 27 is also used to determine the target restricted instruction of the target serial port 271 based on the information in the restricted instruction storage area, and control the write switch circuit 2741 and read switch circuit 2742 between the target device 23 and the target serial port 271 to be disconnected when it monitors that the target device 23 sends a target restricted instruction through the target serial port 271. For example, a restricted instruction 1 can be set for the target serial port 271, and a storage address d1 can be specified in the restricted instruction 1 to restrict the target device 23 from writing data at the storage address d1. In response to the target device 23 sending the restricted instruction 1 through the target serial port 271, the complex programmable logic device 27 can control the write switch circuit 2741 and read switch circuit 2742 between the target device 23 and the target serial port 271 to be disconnected. In this way, on the one hand, by disconnecting the write switch circuit 2741, the data write operation of the target device 23 can be interrupted, ensuring the information security of the server 200. On the other hand, by disconnecting the read switch circuit 2742, it can be prevented that the target device 23 continues to send restricted instructions through the read switch circuit 2742, maximizing the information security of the server 200.
[0039] Based on the restricted instructions, when the target device 23 has the data read and write permissions in the target server component 29, more fine-grained control can also be performed on the specific attributes of reading and writing (such as the data writing / reading area), thereby greatly improving the information security of the server 200.
[0040] In some embodiments, after the write switch circuit 2741 and the read switch circuit 2742 are controlled to be disconnected, if the serial port authorization identifier of the target device 23 is received again, when it is determined that the access permission of the target serial port 271 includes the read permission according to the serial port authorization identifier, the read switch circuit 2742 is controlled to close, and when it is determined that the access permission of the target serial port 271 includes the write permission, the write switch circuit 2741 is controlled to close. In this way, it is ensured that the target device 23 can read and write data normally.
[0041] Specifically, in some embodiments, the restricted instructions can be divided according to the dimensions of the serial port authorization identifier and the target serial port. For example, the serial port authorization identifier and the restricted instructions stored in the restricted instruction storage area can be as shown in Table 2.
[0042] Table 2 Serial Port Authorization Identifier and Restricted Instructions
[0043] Dividing the restricted instructions according to the dimensions of the serial port authorization identifier and the target serial port can perform a more fine-grained division of the restricted instructions, thereby enabling more fine-grained control of the serial port access and improving the information security.
[0044] In some embodiments, the memory 28 further includes a log storage area for storing the data interaction logs of the target device 23, and the data interaction logs include one or more of the following information: The connection time between the target device 23 and the target serial port 271; The disconnection time between the target device 23 and the target serial port 271; The data interaction operations performed by the target device 23 through the target serial port 271 and the operation time; The target restricted instructions sent by the target device 23 through the target serial port 271 and the sending time of the target restricted instructions.
[0045] In this way, the data interaction operations of the target device 23 can be traced, and when a problem occurs in the server 200, the problem can be located based on the data interaction logs.
[0046] In some embodiments, the baseboard management controller 21 is connected to the complex programmable logic device 27. When the target device 23 is connected to the target serial port 271, the complex programmable logic device 27 can obtain the first current time in the baseboard management controller 21 as the connection time; when the target device 23 is disconnected from the target serial port 271, the complex programmable logic device 27 can obtain the second current time in the baseboard management controller 21 as the disconnection time; when the target device 23 performs a data interaction operation through the target serial port 271, the complex programmable logic device 27 can obtain the third current time in the baseboard management controller 21 as the operation time; when the target device 23 sends a target restricted instruction through the target serial port 271, the complex programmable logic device 27 can obtain the fourth current time in the baseboard management controller 21 as the sending time of the target restricted instruction. The baseboard management controller 21 usually has a real-time clock, and obtaining the time from the baseboard management controller 21 can be relatively accurate.
[0047] Based on the above description, the present application provides a permission setting method. Specifically, according to the serial port authorization identifier and the dimension of the serial port, 8-bit data bits can be allocated to each serial port under each serial port authorization identifier. In these 8-bit data bits, the meaning of each data bit can be as follows: bit0: indicates whether the target device 23 is allowed to read data from the server component 29 connected to the serial port 271. For example, a value of 0 indicates allowed, and a value of 1 indicates not allowed.
[0048] bit1~2: indicates whether the target device 23 is allowed to write data to the server component 29 connected to the serial port 271, and whether there is a restricted instruction when writing data is allowed. For example, a value of 00 indicates allowed, a value of 01 indicates allowed but there is a restricted instruction, and a value of 11 indicates not allowed.
[0049] bit3~4: indicates whether it is necessary to record the data interaction log of the target device 23, and the content that the data interaction log needs to include when it is necessary to record the data interaction log. For example, a value of 00 indicates only recording the connection time between the target device 23 and the serial port 271, a value of 01 indicates recording the connection time between the target device 23 and the serial port 271, and the restricted instructions sent by the target device 23 through the target serial port 271, and a value of 11 indicates not recording the data interaction log.
[0050] Bit5~7: Reserved, with a default value of 0.
[0051] In this way, under each serial port of each serial port authorization identifier, there is a permission setting of 8 bits. This permission setting can be stored in the permission storage area of the memory 28. For example, the serial port authorization identifier, the target serial port, and the permission setting stored in the permission storage area can be as shown in Table 3.
[0052] Table 3 Permission Setting
[0053] Setting permissions in the way of bit positions can reduce the storage space consumption of permission settings.
[0054] In Figure 3 In the illustrated embodiment, the device port 272 of the complex programmable logic device 27 is directly connected to the target device 23. In this case, the target device 23 can send the serial port authorization identifier to the complex programmable logic device 27.
[0055] With reference to Figure 4 , a connection schematic diagram of the server 300 and the target device 33 provided in some other embodiments of the present application is shown. Figure 4 In it, the device port 372 of the complex programmable logic device 37 is connected to the target device 33 through the trusted device 41. The trusted device 41 includes a preset serial port authorization identifier. This preset serial port authorization identifier can be regarded as the serial port authorization identifier of the target device 33. When the device port 372 is connected to the target device 33 through the trusted device 41, the trusted device 41 sends the serial port authorization identifier of the target device to the complex programmable logic device 37. Briefly speaking, in Figure 4 In the illustrated solution, if the maintenance personnel want to access the serial port 371 through the target device 33, they need to obtain the corresponding trusted device 41 first. In this way, the information security of the server 300 can be further improved.
[0056] Specifically, the server 300 may include a third connector 39. The third connector 39 is connected between the complex programmable logic device 37 and the trusted device 41. At the same time, the third connector 39 includes a first power supply terminal P3V3_STBY and a ground segment GND. The trusted device 41 may include a controller 414, a switch 412, a first connector 411, and a second connector 413. The first connector 411 is used to connect to the complex programmable logic device 37, the second connector 413 is used to connect to the target device 33, and the switch 412 is connected to the controller 414, the first connector 411, and the second connector 413. When the switch 412 is in the first switch state, the first connector 411 is connected to the controller 414, and the controller 414 sends the preset serial port authorization identifier to the complex programmable logic device 37. When the switch 412 is in the second switch state, the first connector 411 is connected to the second connector 413 to connect the target device 23 to the complex programmable logic device 37.
[0057] Specifically, between the controller 414 and the switch 412, there are a first line FM_UART_SW and a second line UART_MCU. When the first connector 411 is connected to the complex programmable logic device 37 and the second connector 413 is connected to the target device 33, the controller 414 controls the switch 412 to be in the first switch state through the first line FM_UART_SW, so that the first connector 411 is connected to the controller 414. When the first connector 411 is connected to the controller 414, the controller 414 sends a preset serial port authorization identifier to the complex programmable logic device 37 through the second line UART_MCU. When the response returned by the complex programmable logic device 37 to the controller 414 indicates that the target device 33 is allowed to access one or more target serial ports 371, the controller 414 controls the switch 412 to be in the second switch state through the first line FM_UART_SW, so that the first connector 411 is connected to the second connector 413. In this way, the serial port access permission control based on the trusted device 41 is realized.
[0058] Furthermore, the first connector 411 includes a second power supply terminal P3V3_INPUT. When the first connector 411 is connected to the third connector 39, the first power supply terminal P3V3_STBY and the second power supply terminal P3V3_INPUT are connected. In this way, the trusted device 41 can be powered by the first power supply terminal P3V3_STBY to ensure the normal operation of the trusted device 41.
[0059] In summary, the present application also provides a data interaction method. The data interaction method can be applied to Figure 2 the complex programmable logic device 27 in Figure 4 or the complex programmable logic device 37 in Figure 5 . Referring to Figure 5 , it is a schematic flowchart of the data interaction method provided by some embodiments of the present application. In , the data interaction method includes the following steps:
[0060] Step S501: Receive a serial port authorization identifier of the target device, where the serial port authorization identifier is used to characterize the permission range of the target device when accessing the serial port.
[0061] Step S502: Determine the target serial port allowed to be accessed by the target device and the access permission of the target serial port according to the serial port authorization identifier, where the access permission characterizes the data interaction operation allowed to be executed by the target device through the target serial port.
[0062] Step S504, control the target device to perform data interaction with the target server component according to the access permission of the target serial port.
[0063] In some embodiments, a write switch circuit and a read switch circuit are included between the target device and the target serial port; connecting the target device to the target serial port includes: When the access permission of the target serial port includes a read permission, control the read switch circuit to close, so that the target device reads data from the target server component through the read switch circuit; When the access permission of the target serial port includes a write permission, control the write switch circuit to close, so that the target device writes data to the target server component through the write switch circuit.
[0064] In some embodiments, the access permission also characterizes restricted instructions that the target device is not allowed to send through the target serial port; In response to the target device sending a target restricted instruction through the target serial port, control the target device to disconnect from the target serial port.
[0065] In some embodiments, the method further includes: According to the serial port authorization identifier, determine whether it is necessary to record the data interaction log of the target device. If so, record the data interaction log of the target device, where the data interaction log includes one or more of the following information: The connection time between the target device and the target serial port; The disconnection time between the target device and the target serial port; The data interaction operations performed by the target device through the target serial port and the operation time; The target restricted instructions sent by the target device through the target serial port and the sending time of the restricted instructions.
[0066] In some embodiments, the method is applied to a complex programmable logic device in a server, and the server further includes a baseboard management controller; the method further includes: When the target device is connected to the target serial port, obtain the first current time in the baseboard management controller as the connection time; When the target device is disconnected from the target serial port, obtain the second current time in the baseboard management controller as the disconnection time; When the target device performs a data interaction operation through the target serial port, obtain the third current time in the baseboard management controller as the operation time; When the target device sends a target restricted instruction through the target serial port, obtain the fourth current time in the baseboard management controller as the sending time of the target restricted instruction.
[0067] In some embodiments, when allowing a target device to access at least one target serial port, connecting the target device to the target serial port includes: Display the target serial ports allowed for the target device to access; In response to a target serial port selection operation, determine the selected target serial port; Connect the target device to the selected target serial port.
[0068] For the relevant description of the data interaction method, reference can be made to Figures 2 to 4 the relevant description, which will not be elaborated here.
[0069] In summary, in the technical solutions of some embodiments of the present application, when determining the target serial ports allowed for a target device to access and the access permissions of the target serial ports based on serial port authorization identifiers, one or more serial port authorization identifiers can be set, and the permission ranges of at least some of the serial port authorization identifiers can be different. Furthermore, serial port authorization identifiers can be allocated to each target device according to actual needs, so that the serial port access permissions of different target devices can be finely controlled, preventing unauthorized personnel from obtaining data information in the server or tampering with the server configuration through the serial port. In this way, the information security of the server can be improved, and the problem of relatively low information security of the server in the related art is solved.
[0070] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0071] In combination with reference to Figure 6 , an embodiment of the present application further provides an electronic device, including a memory 10 and a processor 20. A computer program is stored in the memory 10, and the processor 20 is configured to run the computer program to execute the steps in any one of the above data interaction method embodiments.
[0072] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any one of the above data interaction method embodiments when running.
[0073] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM for short), a random access memory (RAM for short), a mobile hard disk, a magnetic disk, or an optical disc that can store a computer program.
[0074] Embodiments of the present application also provide a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described data interaction method embodiments.
[0075] Embodiments of the present application also provide another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described data interaction method embodiments.
[0076] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0077] The above has introduced in detail a data interaction method, a server, and a storage medium provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A server, characterized in that, The server includes: At least one server component; A complex programmable logic device, including a device port and at least one serial port. The device port is used to connect to a target device, and each serial port is used to connect to one of the server components. The complex programmable logic device is configured to receive a serial port authorization identifier of the target device, and based on the serial port authorization identifier, determine a target serial port that allows the target device to access and the access permission of the target serial port, and connect the target device to the target serial port, and control a target server component to which the target device is connected to the target serial port to perform data interaction according to the access permission of the target serial port. Wherein, the access permission represents data interaction operations that the target device is allowed to execute through the target serial port.
2. The server according to claim 1, wherein, A switching circuit is included between the device port of the complex programmable logic device and each of the serial ports. The complex programmable logic device controls the connection or disconnection between the target device and the target serial port by controlling the closing or opening of the switching circuit between the device port and the target serial port.
3. The server according to claim 2, wherein The switching circuit includes a write switching circuit and a read switching circuit; When the complex programmable logic device controls the read switching circuit between the device port and the target serial port to be closed, the target device reads data from the target server component through the read switching circuit; When the complex programmable logic device controls the write switching circuit between the device port and the target serial port to be closed, the target device writes data to the target server component through the write switching circuit.
4. The server according to any one of claims 1 to 3, characterized in that, The complex programmable logic device further includes a storage port, which is used to connect to a memory. The memory includes a permission storage area, and the permission storage area is used to store at least one serial port authorization identifier and the permission range corresponding to each serial port authorization identifier; And / or, the memory further includes a restricted instruction storage area, and the restricted instruction storage area is used to store the restricted instructions of each serial port; And / or, the memory further includes a log storage area, and the log storage area is used to store the data interaction log of the target device.
5. The server according to claim 1, characterized in that The device port is connected to the target device through a trusted device. The trusted device includes a controller, a switching switch, a first connector, and a second connector. The first connector is used to connect to the device port of the complex programmable logic device, the second connector is used to connect to the target device, and the switching switch connects the controller, the first connector, and the second connector; The controller includes a preset serial port authorization identifier. When the switching switch is in a first switch state, the first connector is connected to the controller, and the controller sends the preset serial port authorization identifier to the complex programmable logic device. When the switching switch is in a second switch state, the first connector is connected to the second connector to enable the target device to be connected to the complex programmable logic device.
6. The server according to claim 5, wherein, A first line and a second line are included between the controller and the switching switch. When the first connector is connected to the complex programmable logic device and the second connector is connected to the target device, the controller controls the switching switch to be in the first switch state through the first line, so that the first connector is connected to the controller. When the first connector is connected to the controller, the controller sends the preset serial port authorization identifier to the complex programmable logic device through the second line; When the response returned by the complex programmable logic device to the controller indicates that the target device is allowed to access one or more target serial ports, the controller controls the switching switch to be in the second switch state through the first line, so that the first connector is connected to the second connector.
7. A data interaction method, characterized in that The method includes: Receiving a serial port authorization identifier of a target device, where the serial port authorization identifier is used to represent the permission range of the target device when accessing the serial port; Determining a target serial port allowed to be accessed by the target device and the access permission of the target serial port according to the serial port authorization identifier, where the access permission represents the data interaction operation allowed to be executed by the target device through the target serial port; Connecting the target device to the target serial port, where the target serial port is connected to a target server component. When the target device is connected to the target serial port, the target device is connected to the target server component; Controlling data interaction between the target device and the target server component according to the access permission of the target serial port.
8. The method according to claim 7, wherein A write switch circuit and a read switch circuit are included between the target device and the target serial port; The connecting the target device to the target serial port includes: When the access permission of the target serial port includes a read permission, controlling the read switch circuit to close, so that the target device reads data from the target server component through the read switch circuit; When the access permission of the target serial port includes a write permission, controlling the write switch circuit to close, so that the target device writes data to the target server component through the write switch circuit.
9. The method according to claim 7 or 8, characterized in that, The access permission also represents a target restricted instruction of the target serial port; the method further includes: In response to the target device sending the target restricted instruction through the target serial port, controlling the target device to be disconnected from the target serial port.
10. The method according to claim 9, wherein The method further includes: When it is determined according to the serial port authorization identifier that the data interaction log of the target device needs to be recorded, recording the data interaction log of the target device, where the data interaction log includes one or more of the following information: The connection time between the target device and the target serial port; The disconnection time between the target device and the target serial port; The data interaction operation executed by the target device through the target serial port and the operation time; The target restricted instruction sent by the target device through the target serial port and the sending time of the target restricted instruction.
11. The method according to claim 10, wherein The method is applied to a complex programmable logic device in a server, and the server further includes a baseboard management controller; the method further includes: When the target device is connected to the target serial port, obtaining a first current time in the baseboard management controller as the connection time; When the target device is disconnected from the target serial port, obtaining a second current time in the baseboard management controller as the disconnection time; When the target device performs a data interaction operation through the target serial port, obtaining a third current time in the baseboard management controller as the operation time; When the target device sends a target restricted instruction through the target serial port, obtaining a fourth current time in the baseboard management controller as the sending time of the target restricted instruction.
12. The method according to claim 7, characterized in that, When the target device is allowed to access at least one target serial port, the connecting the target device to the target serial port includes: Displaying the target serial ports allowed for the target device to access; Responding to a target serial port selection operation to determine the selected target serial port; Connecting the target device to the selected target serial port.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, the method described in any one of claims 7 to 12 is implemented.
14. An electronic device, characterized in that, The electronic device includes a processor and a memory, the memory is used to store a computer program, and when the computer program is executed by the processor, the method described in any one of claims 7 to 12 is implemented.
15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the method described in any one of claims 7 to 12 is implemented.
Citation Information
Patent Citations
Serial port path selection method and system based on BMC, terminal and storage medium
CN113760800A
Data transmission method and device, equipment and storage medium
CN116303176A
Marking and configuring devices deployed in communication network of vehicle
CN119892619A
Methods, apparatus, and systems for integrated management, graphics and I / O control of server systems
US20080282117A1
Method and system for combination wireless and smartcard authorization
US20170180987A1